++ Salvation Army - Katrina & Rita - Red Cross ++
  New User? Need help? Click here to register for free! Registering removes the advertisements.

CastleCops            Microsoft MVP
image image image image image image

StartupList Index

Currently 12015 startuplist entries and growing...
Last updated on 2005-11-29 19:58:41 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   


    Full List

    NameStatusFilenameDescription
    WinCheckXservices.exeAdded by the W32.Sober.V WORM! Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.
    WindowsXservices.exeAdded by the W32.Sober.X WORM! Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.) This worm file is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
    !1_pgaccountYpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
    !1_ProcessGuard_StartupYprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks.
    !NoLoadUwinrecon.exeWinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    $EnterNetUEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOE
    $sys$cmpX$sys$xp.exeAdded by the Backdoor.Ryknos.B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
    $sys$drvX$sys$drv.exeAdded by the Backdoor.Ryknos TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
    $WindowsRegKey%updateXIEXPLORE.EXEAdded by a W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually!
    %cmpmixtitle%?%cmpmixstr%Possibly related to C-Media Mixer Control panel?
    %FP%012-L2TP fts.exe?fts.exe012.Net ISP software - what does it do and is it required?
    %FP%012-L2TP FWPortal.exe?FWPortal.exe012.Net ISP software - what does it do and is it required?
    %FP%1776 Internet fts.exe?fts.exe1776 Internet ISP software - what does it do and is it required?
    %FP%1776 Internet FWPortal.exe?FWPortal.exe1776 Internet ISP software - what does it do and is it required?
    %FP%Barak013 fts.exe?fts.exe Barak013 ISP software - what does it do and is it required?
    %FP%Barak013 FWPortal.exe?FWPortal.exe Barak013 ISP software - what does it do and is it required?
    %FP%Friendly fts.exe?fts.exeFriendly ISP software - what does it do and is it required?
    (*)API MachineXwinSOCKS.exeHomepage hijacker, see here (* = any digit)
    (*)RunXwin32API.exeHomepage hijacker, see here (* = any digit)
    (default)X(random filename).exeAdded by the BLACKMAL VIRUS!
    (Default)XSystrsy.exe Added by the Trojan.Cdtray TROJAN! Note: This trojan file is found in the Internet Explorer folder.
    (default)Xllsass.exeAdded by the TROJ/PROXY-GG TROJAN!
    (Default)Xwebcam.exeAdded by the Troj/Monad-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    (Entry name)XSystem.exeAdded by the Troj/Nethief-N Trojan!
    (L4r1$$4) (4nt1) (V1ruz)XSP00Lsv32.pifAdded by the ASSIRAL.B WORM!
    (no name)Xpathex.exeAdded by the TROJ/MKMOOSE-A WORM!
    (Original file name)Xsvchost.scrAdded by Troj/Bancban-CX and Troj/Bancban-DA TROJANS!
    (Original filename)Xxphost.scrAdded by the Troj/Bancban-HM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    (Original Trojan filename)XInstall.exeAdded by the Troj/Bancban-FS TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    (random 12 digit number)Xactxprxy.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavicap32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbrowser8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavifile5.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcdmodem4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xacctres8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xautodisc.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcabview1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xatitvo32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadvpack1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbatmeter.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbidispl2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xasferror.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcatsrvps.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xaudiosrv.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadmparse.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcmpbk321.exe Adsrv.com/IeDriver adware variant
    (Random characters)Xsecurewinload32x.exeAdded by the Troj/OptixP-N TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted.
    (random name)X(random filename)Added by the Troj/StartPa-GL Trojan! Found in the WINDOWS or Winnt directory.
    (Random number)Xexplorer.exeAdded by the Troj/Keylog-AN TROJAN! Note: This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder.
    (random)Xlsass.scrAdded by Troj/Bancban-CW Trojan!
    (random)Xsvchost.scrAdded by Troj/Bancban-CY Trojan!
    (Random)Xsvshost.exeAdded by the W32/Kelvir-AX WORM! Note: This worm\trojan file is found in the System\(random folder name) (95/98/ME) or System32\(random folder name) (NT/2000/XP) folder.
    (Randomly chosen existing folder name)X_cfg.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_login.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_start.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_config.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_autorun.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_loader.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_env.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_setup.exeAdded by the W32/Antinny-L WORM!
    (Registry Value Name)Xroses.exeAdded by the W32/Rbot-AFT Worm!
    (Unknown)Xcharmapnt.exeAdded by the Troj/Bancos-DR TROJAN!
    (User name) configX(Path to Trojan exe)Added by the Troj/Mosuck-H TROJAN!
    (various file names)Xmediaplayer32.exeAdded by a variant of the WIN32.RBOT WORM!
    (various file names)Xbling.exeAdded by the W32/RBOT-NI WORM!
    (various names)Xwin32snd.exeAdded by the W32/RBOT-DQ WORM!
    (various names)Xsvchostss.exeAdded by a variant of the WIN32.RBOT WORM!
    (various names)XPasswdMon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    (various names)Xrunload32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    *JanisRuckenbrodIIXjanis.comAdded by the POPS VIRUS!
    *Microsoft UpdateXwucxt.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwuytc.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXctxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwstcl.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXcxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *microsoft updateXcxma.exeAdded by the W32.HLLW.STMU TROJAN
    *MS SetupX[random file name]Virtumondo adware, also known as the VUNDO TROJAN!
    *Security CenterXsecctr.exeAdded by the SDBOT.BRO WORM!
    *StateMgrYstatemgr.exeWindows ME default for System Restore. Do NOT disable!
    *windows updateXwurauclt.exeAdded by the W32/RBOT-SY WORM!
    *windows updateXwsctl.exeAdded by the SPYBOT.PR WORM!
    *windows updateXwscxt.exeAdded by the RBOT.AOS WORM!
    *windows updateXwkmst.exeAdded by the SDBOT.AVD WORM!
    *windows updateXwuaucrlt.exeAdded by the SPYBOT.HUR WORM!
    *windows updateXwaurclt.exeAdded by a variant of the WIN32.RBOT WORM!
    *WinLogonX[trojan path] ren time:[random number]Added by the VUNDO TROJAN!
    *winstatsXwinstats.exeAdded by the Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
    *wuauclt.exeXw****.exe (* = random char)Added by a variant of the W32/RBOT-UG WORM! - NOTE: * in the file name represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
    *wuauclt.exeXwmsvc.exeAdded by the W32/RBOT-UG WORM!
    ,main drive LoaderXwininfo.exeSuspected malware as it appears in 3 different registry locations - see here
    .mscdrXlassa.exeAdded by the WEBUS.C TROJAN!
    .mscdrXlsvchost.exeAdded by the WEBUS.D TROJAN!
    .mscdsrXlsvchost.exeAdded by the Troj/Bdoor-CR Trojan!
    .mscsblXsvhost.exeAdded by the BACKDOOR-CMQ TROJAN!
    .msfupdateXmsveup.exeAdded by the W32.ALLOCUP.A WORM!
    .mssecureXmssecure.exeAdded by the DDOS_BOXED.X TROJAN!
    .mssecureXmssecure.exeAdded by the Troj/Borobot-B Trojan!
    .NET config?sysmon32.exe??
    .nortonXrchost.exeAdded by a variant of the BOXED-A TROJAN!
    .ProgXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process
    .ProgXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    .svchostXCSRSS.EXEAdded by the WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    .TEXTCONVXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    .WMAudioXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process" which provides text window support, shutdown, and hard-error handling
    .WMAudioXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    /l:engNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup
    000Upit.exeAdded by the PrivateEye SPYWARE! **Note - If you did not intentionally install this remove it.
    000hpdllhosXhpdllhost.exe LZIO.com adware downloader
    000StTHKU000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
    0050726-007-i32-1X0050726-007-i32-1.exeAdded by the Troj/Bancban-EC TROJAN!
    00DSKSVR00Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00DSKSVR01Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00THotkeyU00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    0190 WarnerUWARN0190.EXEAnti-dialer program (Germany)
    0900 WarnerUWARN0900.EXEAnti-dialer program (Germany)
    0utlook ExpressX*****.exe (where * = random char)Added by the W32/RBOT-CC WORM!
    1X1.exeAdded by the ESTEEMS TROJAN!
    1Xsvchost.scrAdded by PWSteal.Bancos.X Trojan.
    1Xlsass.scrAdded by the PWSteal.Bancos.V TROJAN!
    11Xfaxcomdos.exeAdded by the Tuimer TROJAN!
    1111swapmgr.exeX1111swapmgr.exeAdded by the BDOOR-IC TROJAN!
    123456Xrundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) VIRUS! 123456 can be any random 3 to 6 digit number
    12Ghosts Popup-KillerU12popup.exe12Ghosts Popup-Killer
    17779Proj2002?N/A??
    180adsolutionX180adsolution.exe 180Solutions/N-Case adware variant
    180axX180ax.exe 180Solutions/N-Case adware variant
    180ClientStubInstallXstubinstaller****.exe (* = digit) 180Solutions adware related
    180ClientStubInstallX******.exe (* = random digit/character) 180Solutions adware related
    180ClientStubInstallX******.tmp (* = random digit/character) 180Solutions adware related
    1:Nhpdrv.exeHP utility for monitoring when and how many recoveries have been done
    1A:MacVisionTrayMonitorNTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
    1A:Stardock MCPYmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
    1A:Stardock TrayMonitorYTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
    1CmailS?NETMAIL.EXE??
    1on1X1on1.exeAdult content dialler
    1Srv32USpyAgent4.exeSpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
    1Win32CfgUSpyBuddy.exeSpyBuddy monitoring software
    1Win32CfgUKeyloggerpro.exeKeyloggerPro - monitoring software
    1WinCfg32X"\WebMailSpy.exeAdded by WebMailSpy SPYWARE!
    2020DownloaderXmssvr.exe2020Search Toolbar related. Reported to be auto-installed
    252Xwinmgr.exeAdded by the Troj/LegMir-AT TROJAN!
    27Xslsorve.exeAdded by the SLSORVE-A TROJAN!
    27Xcsrss32.exeAdded by the TROJ/SLSORVE-D TROJAN!
    27Xmsm32.exeAdded by the TROJ/SLSORVE-E TROJAN!
    2kadirasY2kadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    2thousandbuckX(path to file)Added by the RANKY.L TROJAN!
    2wSysTrayU2portalmon.exe2Wire Homeportal user interface
    32-bit Thunking serviceXthunk32.exeAdded by the W32.Derdero.A WORM!
    357AA41A-B7A8-4632-A27D-5B980B25CF43X[path to svchost.exe]Added by the SMALL-AQ TROJAN!
    357AA41A-B7A8-4632-A27D-5B980B25CF43Xservices.exeAdded by FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    3c1807pdY3cmlink.exe 3cpipe-3c1807pd3Com WinModem driver. See here for more WinModem information
    3capplnkY3capplnk.exeUS Robotics Modem driver
    3cdminicN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3CM LinkY3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it.
    3CmlinkY3CmlinkW.exeFor a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
    3ComDMIAgentN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3D TextN3D Text.scrAdded by the JERMY.A VIRUS!
    3Deep Control PanelU3DeepCTL.EXEFrom LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games
    3Dfx AccXGFXACC.EXEAdded by the GIBE VIRUS!
    3dfx Task ManagerN3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
    3dfx ToolsY3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
    3dfxv2ps.dllY3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
    3Dlabs Taskbar Display Manager?3DLman.exe3DLabs graphics driver related. System Tray access to display settings?
    3DLabsHelperDemonU3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
    3DMouse.EXEY3DMouse.EXEDritek System Inc. 3D Mouse driver
    3d_soundX3d_sound.exeAdded by the Troj/Riados-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    3qdctl.exeU3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
    3ware 3DMY3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
    4wd!!!XNatal!.pifAdded by the OPASERV.AI VIRUS!
    5-1-61-96Xmembers-area.exeAdult content dialler
    5-2-46-112X5-2-46-112.exeAdult content pop-up dialler. Removal instructions here
    55278Xgrepclient1.exeAdded by the Troj/Lineage-S Trojan!
    5p4mX(Path to Trojan)Added by the Troj/Litebot-C TROJAN!
    666XSka.exeAdded by the Troj/Pipes TROJAN!
    678Xlsas32.exeAdded by the Troj/Slsorve-C TROJAN!
    98D0CE0C16B1Xrundll32.exe D0CE0C16B1,D0CE0C16B1 BrowserAid/Startium parasite related
    9xadirasY9xadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    9xHtProtectXAVprotect9x.exeAdded by the W32.NETSKY.M WORM!
    ;RundllX(random filename)Added by the PWSLEGMIR.E VIRUS!
    XRegsrv32.comAdded by the SOUTHGHOST VIRUS!
    XApp.exeAdded by the WAXPOW VIRUS! where <filename> is the executed filename
    Xwincpu.exeAdded by an unidentified VIRUS!
    Xelf.exeElf is a hacker program, tied to a trojan server
    ?ekio StartupsX?nksvc32.exeAdded by the W32/AGOBOT-OV WORM!
    @Xregedit -s ..win.dllAdded by the SEEKER.K VIRUS!
    @Hoc ToolbarNAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
    @lohaNreminder.exeRegistration reminder for @loha@home E-mail utility
    @tour_wwX@tour_ww[1].exeAdult content dialler
    aXa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
    aXjesse.exeAdded by the W32/Melo-A WORM! Note: This worm file is found in the system32\drivers\etc folder.
    A New Windows UpdaterXw32NTupdt.exeAdded by W32.Mytob.BM WORM!
    a-squaredUa2guard.exe a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the a˛ 'Background Guard' real time protection feature
    a-winpoet-serviceYwinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
    A1000 Settings UtilityUcpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
    A4ProxyUA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
    A70F6A1D-0195-42a2-934C-D8AC0F7C08EBXrundll32.exe E6F1873B.DLL,D9EBC318C BrowserAid/Startium parasite related
    AAACLEAN?AAACLEAN.INF??
    AAAKeyboard?????
    AAATraySaverNTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
    AAKUaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
    AaouXamee.exe PurityScan/Clickspring adware
    AappXadprot AdBlaster adware
    aauclient?ACNUpdater.exeAppears to be related to software from Accenture.com - what does it do and is it required?
    ab EazyScheduler?ezsched.exe??
    ABBYY Community AgentNCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
    ABCXkeylogger.exeMonitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by SpyCop in their FAQ
    abcdefghXabcdefgh.exeMalware - detected by Panda antivirus as the DOWNLOADER.EPJ TROJAN!
    ABITEQNabiteq.exeMonitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds.
    Absolute ShieldUdseraser.exeAbsolute Shield/Evidence Eliminator - iternet history eraser
    Absolute StartUp monitorUASMon.exeAbsolute Startup - startup monitor from F-Group Software
    ABsrXabsr.exeAdded by the AUTOUPDER VIRUS!
    absrXmwsvm.exeSeekSeek search hijacker related - as seen here
    abtuXmp3serch.exeLoads the executable for Lop.com. mp3serch.exe is the final version whilst lopsearch.exe is the beta version
    abtuXlopsearch.exeLoads the executable for LOP adware - mp3serch.exe is the final version whilst lopsearch.exe is the beta version
    AbyssWebServerUabyssws.exeAbyss web server
    AcBtnMgr_XxxYAcBtnMgr_Xxx.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    accUacc.exeAdvanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem"
    ACCDEFRAGINFOX(path to file)Added by the W32/Darby-O WORM!
    AccelerateUaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
    Access Ramp MonitorNarmon32.exeMonitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
    Access WebControlX[path to file]Added by the TROJ/PPDOOR-M TROJAN!
    AccessManagerUAccessMgr.exePart of SmartPipes SecureSite software - "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"
    AccessMedia P2P LoaderXamp2pl.exeMy AccessMedia toolbar related, stealth installed!
    AccessoriesPlusUclockplus.exe"Clock Plus", part of Accessories_Plus allows you to select from dozens of alternatives for the Windows clock.
    AccessRamp Monitor01NARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
    AccessRampLAN01NARUpld32.exeVersion of the above for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
    AcctMgrUAcctMgr.exeNorton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities—all from the safety of your own PC
    AccuWeather.com® DesktopN??Desktop weather from AccuWeather.com
    accwizz.exeXaccwizz.exeAdded by the W32.Ruland.A WORM!
    accwizzz.exeXaccwizzz.exeAdded by the W32.Ruland.A WORM!
    Acecad.WtxploadYWtxpload.exe Acecaddriver for an AceCad USB Graphics Tablet
    AceGain LiveUpdateNLiveUpdate.exe AceGain_LiveUpdate . "AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences."
    AcerGotoUAcerGoto.exeAcer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer.
    AcerNotebookManagerUalmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
    AcerPowerkeyUPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn F3
    AceuX[random file name] PurityScan/Clickspring adware
    AceUtilsNau.exeRelated to Ace Utilities from Acelogix_Software Note: this is NOT to be confused with the au.exe used by the BEAGLE.B worm!
    AClntUsrUAClntUsr.exeAltiris AClient Service Windows Tray Icon
    Acme.PCHButtonNpchbutton.exeUsed by HP Instant Support
    ACMonitor_XxxYACMonitor_Xxx.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    acocashXfastdown.exe, fastfown.exeAdult content dialler
    Acombo3dmouseUAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
    AcontiXaconti.exeAdult content dialler
    acousticUacoustic.exeControl panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained
    acpartNagpart11.exeProgram for finding trucks on-line
    Acrobat AssistantUACROTRAY.EXEUsed to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation
    Acronis Scheduler2 ServiceUschedhlp.exePart of Acronis True Image - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images
    Acronis True Image MonitorNTrueImageMonitor.exePart of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
    Acronis TrueImage MonitorNTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImage
    AcronisTrueImage MonitorNTrueImageMonitor.exePart of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
    Action Manager 32Nam32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
    ActionAgent?actionagent.exe"A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required?
    ActivationNActivation.exePart of Microsoft Money
    ActivboardUMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys
    Active Bit StationXabs.exeAdded by the W32.MYTOB.BZ WORM!
    Active Email MonitorUaem25.exe Active_Email_Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email.
    Active shieldUActiveshield.exe Active_Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses["
    ActiveDesktopXsystray32.exeAdded by the DABOOM VIRUS!
    ACTIVEDSXACTIVEDS.EXEAdded by the OPASERV.T VIRUS!
    ActiveEyesNActiveEyes.exeActiveEyes from TFI Technology
    ActiveMenuUActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    ActivePlusUactiveplus.exeInteractive Agents Plugin for Messenger Plus! (MSN Messenger add-on)
    ActiveShieldYMCVSSHLD.EXEMcAfee VirusScan On-line. See also McAgentExe entry.
    ActiveSpeedUAS.exeAscentive ActiveSpeed Internet Optimizer
    ActiveX StreamerXmsgfix.exeAdded by the SDBOT.NQ WORM!
    ActiveXUpdateXsvcss.exeAdded by a variant of the DEDLER.C TROJAN!
    ActivityUactik.exe ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself!
    ActivSurfNbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
    ActMakerUActMak25.exeThe ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer.
    ACUUACU.exe Atheros wireless Client Utility For HP Compaq
    ACU_QSBUACU.exe Atheros wireless Client Utility For HP Compaq
    Ad BlockerUblocker.exeAd Blocker - blocks popups, and also removes banners, image ads and flash ads
    Ad Blocker ProUAd Blocker Pro.exe"Ad Away" popup and banner remover
    Ad MuncherUAdMunch.exeAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    Ad Online Guide?adonlineguide.exe??
    Ad-awareNAd-aware.exeAd-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
    Ad-AwareXAd-Aware.exeAdded by the W32/Rbot-ADJ Worm!
    Ad-Aware-6XWINDOWSUPDATER.EXEAdded by an unidentified WORM or TROJAN!
    Ad-MuncherUADMUNCH.EXEAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    Ad-watchUAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    AD2KClientUAD2KClient.exeExecutable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk
    Adaptec DirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    AdaptecDirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    AdAwareXwini.exeAdded by the W32/RBOT-XN WORM!
    Adaware BootupNad-aware.exeAd-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
    Adaware lptt01 or Adaware ml097eXadaware.exeVariant of the RapidBlaster parasite (in a "Adaware" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware
    Add**.exe (* = random char)XAdd**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Add**32.exe (* = random char)XAdd**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log.
    AddClassX(Path to Trojan)Added by the Troj/SecDl-A TROJAN!
    AdDeleteUAdDelete.exeBanner advertisment blocker
    AdDestroyerXAdDestroyer.exeLike VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code
    ADG?ADG.exe SoundBlaster Audigy related?
    ADGJdetNADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
    AdirasYAdiras.exeADSL USB modem related
    ADM Library LoaderXadmlib32.exeAdded by a variant of the SDBOT WORM!
    Admanager ControllerXAdManCtl.exeWindUpdates ADW_WINAD.M adware
    Admilli ServiceXAdmilliServ.exeWindUpdates AdmilliServ adware
    AdministratorXsvchost.scrAdded by the Backdoor.Novacal TROJAN! Note: This trojan file is found in the Windows\Fonts or Winnt\Fonts folder.
    AdminSoftXsysfile.vbsAdded by the VBS/STARGRUB-A WORM!
    AdobeXAdobe.exeAdded by an unidentified VIRUS!
    AdobeXsysconfig.exeAdded by an unidentified WORM or TROJAN!
    AdobeXsysbat32.exeAdded by the TROJ_LOWZONES.T TROJAN!
    adobeXgam.exeAdded by an unidentified WORM or TROJAN!
    AdobeXzteam.exeAdded by an unidentified TROJAN!
    Adobe Acrobat Distiller ApplicationXacrotray.exeAdded by the W32.RANDEX.DFJ WORM!
    Adobe Acrobat Reader CFGX[random file name]Added by a variant of the WIN32.RBOT WORM!
    Adobe Gamma LoaderUAdobe Gamma Loader.exeAdjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
    Adobe Photoshop 7.0XAdobePhotoshop.exeAdded by a variant of the W32/SDBOT WORM! - NOTE: Do NOT confuse with the Adobe photo editing software of the same name!
    Adobe Reader Speed LauchNreader_sl.exeSpeeds up the lauch of Adobe (Acrobat) Reader 7
    Adobe Reader Speed LauchNREADER~1.EXESpeeds up the lauch of Adobe (Acrobat) Reader 7
    Adobe Reader Speed LaunchNreader_sl.exeSpeeds up the time it takes to load the Adobe_Reader application. Your choice, but not required for Adobe Reader to function properly
    AdobeAXadobes.exeAdded by the FLOOD.BA VIRUS!
    AdobeFontsXfonts.htaBrowser hijacker - redirecting to Hugesearch.net
    AdobeReaderProXmsnxpsp.exeAdded by the W32/Rbot-ASK or W32/Rbot-AUS WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
    AdobeReaderProXntkernell32.exeAdded by W32/RBOT-ATY WORM!
    AdobeVersionCueNVersionCueTray.exe"An exclusive feature of the Adobe(r) Creative Suite, Version_ Cue(tm) helps you find files fast, track multiple versions of your files, and share your files for creative collaboration"
    Adope File ManagerXlsasv.exeAdded by an unidentified WORM or TROJAN!
    adpXadp.exeSpyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc
    AdPopupXdcf5678.exeAdded by the Troj/Agent-FZ TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    adprotXadprot.exe AdBlaster adware variant
    ADQuickAccessNAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
    AdRoarUpdateXARUpdate.exeAdRoar adware updater
    AdRotator.ApplicationXcsrss.exe AdRotator adware variant - Note - do NOT be confuse with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt\System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    AdRotator.ApplicationXservices.exeAdded by FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    ADServiceUADService.exePart of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk
    AdsGoneUAdsgone.exeAdsGone - pop-up stopper
    ADSL Diagnostic ToolsNmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
    ADSLSYSTEMTRAY?SystemtrayV100B.exeApparently Annex A ADSL modem related - what does it do and is it required?
    AdslTaskBarYrundll32.exe stmctrl.dll, TaskBarISP software, initializes DSL modem
    AdslTaskBarsXtaskmng.exeAdded by the W32/Rbot-AXZ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ADSL_A2?A2InstalledAssociated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?
    ADSSYADSS.exeADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied
    adstartupXautomove.exe Adlogix adware variant
    adstartupXAdstartup.exe Adlogix adware
    AdStatus ServiceXAdStatServ.exeWindUpdates AdStatus_Service adware
    AdSubtractUadsub.exeAdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via Start -> Programs
    adtech2005Xadtech2005.exeReported as Trojan.Win32.StartPage.aw by Kaspersky Anti-Virus.
    Adtools ServiceXAdTools.exe Windupdates Adware
    AdultXXAdultX.exeAdult content dialler and hijacker
    Adult_ChatXAdult_Chat.exeAdult content dialler
    Adult_Chat1XAdult_Chat1.exeAdult content dialler
    AdUpdaterXsysupudt.exeUnidentified adware downloader/updater
    ADUserMonUADUserMon.exePart of Iomega's Active Disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk
    Advanced Internet ProtocolXcerf.exe W32.SpyBot worm variant
    Advanced Protection SystemXadvpsys.exeAdded by a variant of the WIN32.RBOT WORM!
    Advanced Tool ChecksXadvchks.exeAdded by a variant of the WIN32.RBOT WORM!
    Advanced Tools Check or ADVCHKNADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
    Advanced Uninstaller PRO Installation MonitorUmonitor.exeInnovative Solutions The user can choose whether or not to monitor installs.
    AdvapiXAdvapi.exeAdded by the NETDEVIL.12 (NetDevil 1.2) VIRUS!
    Advertising KillerUAkiller.exeAKiller - pop-up stopper
    advmon32Xadvmon32.exeAdded by a Crypter.C trojan variant infection
    Adware AgentUadware agent.exeAdware Agent popup blocker
    Adware SpyNAdwareSpy.exeAdware remover - not recommended, see Rogue/Suspect_list
    AdwareAlertXAdwareAlert.Exe"Spyware remover" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
    Aeiwlsta.exe?Aeiwlsta.exeIBM High Rate Wireless LAN Adapter driver. Is it required?
    AELaunchNAELaunch.exeAudio Applications Launcher for the Philips Acoustic Edge soundcard
    AERVICESNXAERVICESN.exeAdded by the W32/RANDON-AO WORM!
    AeXAgentLogonNAeXAgentActivate.exe Altiris Agent transmits information about your machine for the purpose of asset management and deployment
    AeXSWDUsr?AeXSWDUsr.exeAltiris Express NS Client Manager software. Is it required?
    AEZBProcUaptezbp.exeIBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions
    AFAFilterUwindefault.exeAFAFilter - internet filter software
    AgentNAgent.exeCyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start -> Programs
    Agent BrowserX[random file name]Added by the PPdoor.M-bdr backdoor TROJAN!
    Agent ExplorerX[random file name]Unidentified adware
    Agente?Remupd.exePart of Panda Antivirus Titanium. Is this an update reminder (guess because of the name), virus definition update reminder or something similar?
    agentsvrXagentsvr.exeMalware, detected by Kaspersky antivirus as AdWare.Monker.a - NOTE: do NOT confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder.
    AgfaCLnkUAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
    agpXagp32.exeAdded by the W32.Gaobot.SY worm
    AGRSMMSGYAGRSMMSG.exeIBM AMR modem driver
    AGSatelliteNAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
    AGSeyAppXAGSeyApp.exeAdded by the GoldenEye SPYWARE!
    ahfpor and ahfprogNahfp.exeAdvanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view, delete or modify them either"
    AHNSDUAhnSD.exeAhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis
    AHNUE?AHNUE.exe??
    AHQInitNahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
    AhstXiebs.exe PurityScan/Clickspring adware
    AicaXtuaa.exe PurityScan/Clickspring adware
    AidaXttuh.exe PurityScan/Clickspring adware
    AidaXeetu.exe PurityScan/Clickspring adware
    aiepkUaiepk2.exeAnother IE Popup Killer - pop-up stopper
    AIMNaim.exeAOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start -> Programs
    AIM Instant Message CookiesX(random filename)Added by the W32/RBOT-AFV WORM!
    Aim PluginXaimplugin.exeAdded by the W32/Guap-F WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Aim Quick StartXAim.exeAdded by a W32/Forbot-BB worm infection
    AIM reminderXAIM reminder.exeAdded by the BUDDY VIRUS!
    AIM95 StartupXaim95.exeAdded by the AGOBOT.AEE WORM!
    aimaol lptt01 or aimaol ml097eXaimaol.exeVariant of the RapidBlaster parasite (in a "Aimaol" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    aimb.exeUaimb.exe IMSufSentinel is a Spyware program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it.
    AimingClickNAimingClick.exeAimingClick from AimingTech. Web searching tool. Available via Start -> Programs
    AIMsterN??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
    AIMWDInstallNAIMWDInstall.exe WildTangent on-line games installer as part of AOL Instant Messenger. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case
    Aiptek Graphics Tablet (USB)Yatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
    aircityXaircity.exeRelated to "Prutect" malware from e2Give
    AKEYNAMEXWinServ.exeAdded by the EVILBOT.C TROJAN!
    AKillerUakiller.exeBuyPin Advertising Killer - popup killer
    ala.exeUala.exe Access_Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer.
    Alarm ManagerUAlarm.app.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
    AlarmWatcher?AlarmWatcher.exeAssociated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?
    Album Fast StartNABMTSR.EXEScanner software, not required for scanner to work
    AlcFDMonitor?ALCFDRTM.EXERealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?
    ALCFDRTM16?ALCFDRTM16.comRealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?
    AlchemXAlchem.exe Transponder parasite updater/installer
    alcmtrXALCMTR.EXERealtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers
    Alcohol or Alcohol AutorunUAlcohol.exeAlcohol 120% - CD/DVD emulation/writing/copying software
    Alcom PCL Capture?FMW_PCAP.EXE??
    AlcWzrdNALCWZRD.EXERealTek High Definition audio driver related - detects new devices when plugged in, then pops up a dialog box. If everything works as expected you should be able to disable this one.
    AlcxMonitorXAlcxmntr.exeRealtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers
    aldefr ere serviceXtay0x.exeAdded by the W32/RBOT-XS WORM!
    AlevirXAlevir.exeAdded by the OPASERV.A VIRUS!
    AlevirXAlevir.exeAdded by the OPASERV.F or OPASERV.G VIRUSES!
    AlevirOldX(worm filename)Added by the OPASERV.G VIRUS!
    AlexaNAlexa.exe?Alexa Toolbar"is a downloadable toolbar that helps you navigate the Internet as you surf, by instantly providing you with related information about the site you're viewing". Available via Start -> Programs
    alexaUalexa.exeRelated to Alexa Note: COLLECTS AND STORES INFORMATION ABOUT THE WEB PAGES YOU VIEW, THE DATA YOU ENTER IN ONLINE FORMS AND SEARCH FIELDS, AND, WITH VERSIONS 5.0 AND HIGHER, THE PRODUCTS YOU PURCHASE ONLINE WHILE USING THE TOOLBAR SERVICE. Although Alexa state's they do not attempt to analyze the data it may collect about you to determine who you are, some of your information collected by the software is personally identifiable. Please read the Privacy_Policy Not Recommended.
    ALFY Accellerator?AlfyAC~1.exe??
    ALG.EXEXiexplorer .exeAdded by the W32/DEMOTRY-B WORM!
    ALG32XALG32.EXEAdded by the StartPage.K TROJAN!
    ALGUXALGU.EXEAdded by the TROJ/CWS-I TROJAN!
    Alias SketchBook SnapshotNALIASS~2.EXEScreen-capture utility for Alias Sketchbook
    AlienAutopsyNTest_BS.exeAlienware computer technical support software
    ALiSndMgrYALiSndMg.exeALi AC97 Sound driver
    AliUSBfix?GREENMK.exeMay be realted to a USB 2.0 PCI card - the IOgear GIC220OU?
    Alive SYstemXscchost.exeAdded by the Troj/Tofdrop-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Alive SYstemXscchostc.exeAdded by the Troj/Tofdrop-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    alkasrXÎäŇíŃ.exeAdded by the BALKART VIRUS
    All Aboard StatusUstswin.exeAll Aboard! Internet Connection Sharing status icon
    All Sea screen saverXTaskTray.exe"Free screensaver", installs lots of foistware. See here. Get rid of it
    All Sea web linkXFWLink.exe"Free screensaver", installs lots of foistware. See here. Get rid of it
    AllerCalcNAllerCalc.exe AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually.
    AllSeeingEyeUase.exe All-Seeing_Eye security software - "monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions."
    allSnapUallSnap.exe"allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"
    Alogrithm Link QueueXalq.exeAdded by a variant of the W32/SDBOT WORM!
    AlogservUAlogserv.exeFrom McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up
    ALPassUALPass.exe ALPass password manager
    Alps Electric USB ServerYMonserv.exeAlps Electric USB Server - required according to this article
    AlpsPointUApoint.exeTouchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
    ALServ?ALServ.exeAltec Lansing AMS speaker related. What does it do and is it required?
    AltnetNpoints manager.exeAltnet TopSearch adware
    Altnet Points ManagerNpoints manager.exeAltnet TopSearch adware
    AltnetPointsManagerXpoints manager.exeAltnet TopSearch adware
    AltoMB_serviceUAltoMBsrv.exeAlto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management
    ALUAlertUALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
    Aluria Security CenterNSecurityCenter.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
    Aluria's Pop-Up StopperUeps.exeAluria Pop-Stopper
    Aluria's Spyware EliminatorNASE.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
    AlwaysOnTopMakerUAlwaysOnTopMaker.exeAlways On Top Maker - utilty to enable an application to always be displayed "on top" of others on the desktop
    AmazingTensXAmazingTens.exePremium rate adult content dialer
    America Online *.* Tray IconNaoltray.exePuts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
    AME_CSANrundll32 amecsa.cpl, RUN_DLLLoads ADSL modem Control Panel applet
    AModemLockDownUModemLockDown.exe start ModemLockDown allows you to supervise internet access by disabling the modem, protects againt dialers accessing dial-up connections, etc
    AmonYAMON.EXEMonitoring part of Eset's NOD32 virus-scanner
    AmonitorYamon.exeTiny Personal Firewall
    AMP WinOFFUwinoff.exe WinOFF is " a utility designed to shut down Windows computers automatically, in a fully configurable way."
    AMSNUamsn.exe aMSN P2P client - can be started manually
    anbv32Xnabv32.exeAdded by the TITOG.C VIRUS!
    ANIWZCS2ServiceYWZCSLDR2.exe ALPHA_Networks wireless driver
    ANIWZCSService?WZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
    AnnotateCheck?AnnCheck.exeGenius Wizard Pen Tablet driver related. Is it required?
    AnnouncementsNAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    AnntextNAnntext.exeCaere Pagekeeper text annotation server
    Anonymizer Total Net ShieldUAnonTns.exeAnonymizer Total_Net_Shield
    ANONYMIZER_SPYWAREKILLERUSpyWareKiller.exeAnonymizer Spyware Killer; see here
    ANONYMIZER_SPYWAREKILLERUAnonAntiSpyware.exeAnonymizer Spyware Killer; see here
    Another Internet Explorer Popup KillerUaiepk.exeAnother IE Popup Killer - pop-up stopper
    ansjavaX(Path to mIRC application)Added by the W32/Randon-AN Worm!
    AnskyaXPYSKY.NET.exeAdded by the TROJ/DLOADER-MW TROJAN!
    Answer ProblemXdSAFsqs.exeAdded by the W32/SDBOT-SC WORM!
    AntiXIsass.exeAdded by the WIN32.BROPIA.K WORM!
    Anti Spam ServiceXspamsvc.exeAdded by the W32/Mytob-BK Worm!
    Anti Trojan EliteUTJEnder.exe Anti_Trojan_Elite trojan remover
    Anti-keylogger checkUantikey.exeAnti-keylogger - protects against keylogger programs monitoring your keystrokes
    Anti-Spyware BlockerXAnti-Virus.exeAnti-Spyware Blocker by Your-Soft , bogus "Spyware remover" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "anti-spyware blocker"
    Anti-Trojan-WatchUATWatch.exeAnti-Trojan Watch - trojan detector
    Anti-Virus Product SyncX[AN UNPRINTABLE CHARACTER][3 CHARACTERS]log.exeAdded by the W32.Kedebe.D WORM!
    Anti-Virus Update SchedulerX[various file names]Added by a variant of the HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more...
    Anti-Virus Update SchedulerXwinsp3.exeMalware - detected by Kaspersky antivirus as TrojanProxy.Agent.fp - A Proxy Trojan is a backdoor which allows a remote hacker to connect to other systems via the compromised system.
    Anti-Virus Update Scheduler V1.39.12RX[various file names]Added by the HEPLANE or STAPREW.B TROJANS! - different file names have been spotted; examples: msvc.exe, kaspersky.exe, nrton.exe, wins.exe, gah32.exe, 1.tmp, syste.exe, alg.exe, socks.exe, winxpsp2.exe, tek9.exe, sks.exe, hihi.exe, s.exe, xps2.exe, dns2.exe, ikav32.exe and more...
    antidialer.co.ukUDialer_Watcher.exe Dialer_Watcher is an application that allows you to detect Dialers on your computer.
    AntiPopUpUAntiPopUp.exeAntiPopUp for IE - pop-up stopper
    AntiVir XPYAVwin.exe AntiVir antivirus
    AntivirusXav.exeAdded by the SINKIN VIRUS! Resets IE start page to realphx.com
    AntivirusXmaja.exeAdded by the W32.NETSKY.H WORM!
    AntivirusXiexpl0res.exeAdded by an unidentified WORM or TROJAN!
    AntiVirusXkaspery.exeAdded by a variant of the WIN32.RBOT WORM!
    Antivirus InstallerX(Pathname of the Trojan executable)Added by the Troj/Badgent-A Trojan!
    antivirus32Xantivirus.exeAdded by the W32.Spybot.KAI WORM!
    AntivirusGoldXAntivirusGold.exe Malware masquerading as an antivirus - also installs the Winnook TROJAN!
    AntiVirusProtection?qumk.exe??
    antiwareXelite***32.exeAdded by the Troj/Dloader-HW TROJAN!
    AntiWindowsMessengerUAntiMsMsg.exe Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory.
    anti_trojXanti_troj.exeAdded by the Lodear.D TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    AnVirYAnVir.exeAnVir Task Manager - protects computer against viruses and manages running processes and startup files
    anvshellUanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
    anycom bluetooth?ftflauncher.exeAssociated with an Anycom bluetooth wireless card. What does it do and is it required?
    AnyDVDNAnyDVD.exe AnyDVD is a driver, which descrambles DVD-Movies automatically in the background. This DVD appears unprotected and region code free for all applications and the Windows operating system as well
    AO Tray or AOTrayNAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
    AOL 9.0 OptimizedXAOLClient.exeAdded by the Backdoor.Spyboter.A TROJAN!
    AOL 9.0 OptimizedXAOLClient.exeAdded by the Backdoor.Spyboter.gen TROJAN!
    AOL Broadband Check-UpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
    AOL CompanionNcompanion.exePart of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process, and is installed for ease of use.
    Aol Configuration LoaderXaimsng.exeAdded by the W32/SDBOT-XE WORM!
    AOL Fast Start?AOL.exeAOL ISP software related - what does it do and is it required?
    AOL Instant MessangerXaim.exeAdded by the W32/Sdbot-YT Worm!
    AOL Instant MessengarXaol.exeAdded by the W32/AGOBOT-FN WORM!
    AOL Instant Messenger?AlM.EXEThat is an L between the A and M, the start up location is wrong for AIM. what does this relate to?
    Aol Instant MessengerXaolmsg.exeAdded by W32.Kelvir.AL WORM!
    AOL Instant Messenger 7.213Xaim9283.exeAdded by the W32/Sdbot-ZF Worm!
    AOL Instant Messenger dll runtimeXMSAOL32dll.exeAdded by the W32/Rbot-ATA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Aol Instant Messenger FixXaolfix.exeAdded by the W32/Sdbot-ABJ WORM!
    AOL MessengerXTGRCNLUD.EXE, random file namesUnidentified worm or trojan
    AOL MessengerXaolmsngr.exeAdded by the W32/SDBOT-JF WORM!
    AOL Services HostsXaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
    AOL Spyware ProtectionUAOLSP Scheduler.exeAOL's spyware protection program
    AOL TopSpeedMonitorUaoltsmon.exeAOL's TopSpeed web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up.
    AolAcsDaemon1UAcsd.exeAOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
    AolAcsDaemon1YAOLACSD.EXEAOLacsd.exe is a part of the AOL Internet Software and relates to the connection driver, essential to Internet connection. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems
    AOLCC?ACCAgnt.exeAOL ISP software related, file located in a "AOL Computer Check-Up" folder - what does it do and is it required?
    AolConXconfig.comAdded by the TAPLAK VIRUS!
    AOLDialerNAOLDial.exeAOL ISP software dialer; can be activated through a desktop shortcut
    AolFixNAolFix.exeRun on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL  to run correctly. Not seen much any more and should only run once
    AornumXaornum.exeInstalled along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware
    APC UPS StatusYDisplay.exeAPC PowerChute Personal Edition status icon
    APC_SERVICEUmainserv.exePowerChute® Personal Edition - "safe system shutdown software with sophisticated power management functions"
    apc_trayYapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
    APD123XAPD123.exe PacerD_Media/Pacimedia.com adware component
    Api**.exe (* = random char)XApi**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Api**32.exe (* = random char)XApi**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    API32Xapi32.exeAdded by the IRCBOT-B TROJAN!
    APIClassXlexplore_.exeAdded by the Troj/MSNOpt-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    APIMonXapimonx.exeAdded by the TIBSER.A downloader TROJAN!
    APIMonXwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
    APIMonXmsreg.exeAdded by the TROJ_DROPPER.Z TROJAN!
    apisvc.exeXapisvc.exeAdded by a variant of the Lamebot TROJAN!
    APLUAPL.exe Sage_Software's_ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application.
    Apmsrv9x?APMSRV9X.EXEIntel AnyPoint Wireless II Home Network related. What does it do and is it required?
    ApointUApoint.exeTouchpad software for laptop PC\'s. For instance it is found on the Panasonic machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
    App**32.exe (* = random char)XApp**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    App**exe (* = random char)XApp**exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    App.EXENameX(path to worm)\.exeAdded by the BODIRU VIRUS!
    App32dllXmsnavc32.exe VX2 adware related
    AppconUvAppCon.exeVital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established
    appconnXappconn.exeAdded by the CARGAO trojan
    AppExtenderUAppExtCB.exeLoads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received
    appis.exeXappis.exeAdded by the AGENT-BC TROJAN!
    ApplicationYmdmsetsp.exeAztech Labs modem driver
    Application ExplorerUNaldesk.exeNovell Zenworks Application Explorer Executable; "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."
    Application Layer Gateway ServiceXalgs.exeAdded by the W32.LINKBOT.M WORM!
    AppPlusUAppPlus.exeAppPlus - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)"
    Apvxd or ApvxdwinYAPVXDWIN.EXEPart of Panda Anti-Virus. Required to enable permanent virus protection
    ApwheelYApwheel.exeWheel support for an Alps mouse 
    apyginapyginXsimenu.exeAdded by the SDBOT.BTR WORM!
    AQ3HelperStartUpXAQ3HEL~1.EXEScreenScenes "Aquatica Water Worlds" screensaver. Comes with GAIN spyware
    aqadcupXaqadcup.exe Backdoor.Agent.bg worm
    AqujyjaxXaqujyjax.exeAdded by the W32/SDBOT-YC WORM!
    AqujyjaxX[path to file]Added by the TROJ/RANCK-CQ TROJAN!
    ara-keyXAdded by the ANTINNY VIRUS! where <random> is a random program name with random characters
    ArchiveXarchive.exeAdware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Centim.a
    ARCHIVE CONTROLXfixupdattr.exeAdded by the W32.MYTOB.GU WORM!
    ARCSolo RecoveryNN/ABackup software by Computer Associates - no longer supported
    aresNares.exe Ares is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"
    aresliteNAresLite.exe Ares Lite Edition is "a Windows program that enables peer-to-peer file-sharing on the Ares P2P network. As a member of the P2P community you can search and download any file shared by other users. You can meet new friends in Ares chatrooms while you download"
    AritimaXaritima.exeAdded by the ARITIMA VIRUS!
    ArteraUarteraui.exeArtera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance
    AS00_Gear511?Gear511.exeSoftware for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. is it at all required?
    AS00_WPN511?WPN511.exeNetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?
    ASDPLUGINXfullgames.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXcanada.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXfrance.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXuk_nm.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXdbaccess.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXgeaccess.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXnetherlands.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXbelgium_nm.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXdsldbaccess.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXadult1.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXFinland.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXAustria.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINX100171be.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXXadult1.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXczech.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINX100176br.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXdslgeaccess.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXmexico.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXturkey.exe AsdPlug premium rate adult content dialer variant
    ASDPLUGINXtemp532.exe AsdPlug premium rate adult content dialer variant
    asdxXxwinrpc32.exeAdded by the AGOBOT.VO WORM!
    ASE SchedulerNASE Scheduler.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
    Ashampoo PopUpBlockerUPopUpKiller.exeAshampoo popup blocker, part of Privacy Protector Plus; see here
    ashAvastYashAvast.exePart of Avast antivirus
    ASHLTXAshlt.exe Ashlt adware
    ashMaiSvYashmaisv.exePart of Avast! anti-virus software
    AsioRegUregsvr32.exe ctasio.dllASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
    ASKUrundll32.exe [path] ASK.dll rdlAdded by the StealthKeylog surveillance software. Uninstall this software unless you put it there yourself.
    aslXAslru.exeAdded by the TROJ/BANCOS-CU TROJAN!
    Asmw Soft Popups BurnerUpopups burner.exePopup blocker, part of Asmw Soft PC_Optimizer
    ASP.NET State ServiceXcsrss.exeAdded by the TROJ/DLOADER-QI TROJAN! NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    ASP.NET State ServiceXcrsass.exeAdded by the Troj/Banload-M TROJAN! Note: This is not the legitimate Windows process crss.exe (Notice the difference in the spelling.) This trojan file (crsass.exe) is found in the Windows or Winnt folder.
    ASP.NET State ServiceXservicos..exeAdded by the Troj/Dadobra-I TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    asp4trayNasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    AspireTimeMachineYacertmb.exeSystem recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry
    assistseXASSISTSE.EXECnsMin (Chinese_Keywords) related
    ASTXASTAdded by the WIN32.VB.AH TROJAN!
    ASTXAST.exe AutoStarter parasite
    ASTARTUastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
    AStartXAStartAdded by the WIN32.VB.AH TROJAN!
    asTrayNAstray.exeVoyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer
    AstroNAstro.exeChecks for updates to Quicken on a system reboot
    ASUS Live UpdateNALU.exeASUS Live Update utility - reportedly not required
    ASUS ProbeNAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
    ASUS SmartDoctorUVGAProbe.exeASUS video card fan/thermal monitor
    ASUS TweakEnableUastart.exeRestores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
    ASUSKeyNV38SHELL.EXESystem tray Icon for quickly changing video modes
    asustweakenableUATweak.exeAsus Tweaking Utility - for fine tuning the settings of your ASUS display card
    ASWDPNASWDP.exeMLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market
    ASWnkXaswnk.exeAdult content dialler
    AT&T DSL Service PCA Program?dslpca.exeAT&T DSL related - what does it do and is it required?
    AT-WatchUATWatch.exeAnti-Trojan Watch - trojan detector
    atapidrvXatapidrv.exeAdded by the W32/AGOBOT-SL WORM!
    AthanUAthan.exe Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world.
    ATI CATALYSTNCLI.exeSystem Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLE.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
    ATI CATALYST System TrayNCLI.exe SystemTraySystem Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLI.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
    Ati Control PanelXatiphexx.exeAdded by a SDBOT.CC worm infection
    ATI DeviceDetectNATIDtct.EXEThis utility was meant for future use of the ATI TV WONDER™ USB 2.0 video driver and can be disabled.
    ATI GART Set-up UtilityNAtigart.exeProgram that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed
    ATI LaunchpadUlaunchpd.exeConvenient way to start all your Multimedia Center applications (DVD, Video CD, CD Audio, File Player). You can right-click LaunchPad, and uncheck Load on Startup in the menu
    ATI Rage3d ProXAtiRage4dPro.exeAdded by the W32/AGOBOT-OG WORM!
    ATI Remote ControlYATIRW.exeDriver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
    ATI Remote ControlYATIX10.exeDriver for the ATI_REMOTE_WONDER_(tm) RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it
    ATI SchedulerNAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
    ATI Task ApplicationNAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    ATI Task Application (Atikey)NAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    ATI Technology StartupXtechstart.exeAdded by the W32/Rbot-AEU Worm!
    ATI VIDEO REGKEYXati2vid.exeAdded by the SDBOT.UR WORM!
    Ati2cwxx?Ati2cwxx.exeFor some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it 
    Ati2mdxxNAti2mdxx.exeFor ATI video cards. System Tray access to display mode changing
    ATICCCNCLI.exeSystem Tray access to ATI's CATALYST™ CONTROL CENTER. Note that this has "SystemTray" appended to CLE.exe in the "Command" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop
    ATICCCUcli.exe runtimeATI's CATALYST(tm) CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has "runtime" appended to cli.exe in the "Command" column of MSCONFIG. If not you can start the program manually via Start -> Programs -> ATI Catalyst Control Center -> Advanced -> Restart Runtime
    AtiCpanelXatiphexx.exeAdded by a AGOBOT.IL worm infection
    aticpaxx.exeXaticpaxx.exeAdded by the W32/RBOT-XP WORM!
    AtiCwd or AtiCwd32UAtiCwd.exe AtiCwd32.exe Ati2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
    AtiDisplayDrvXatidrvxx.exeAdded by the W32/RBOT-VZ WORM!
    atidriverXreaIplayer.exeAdded by W32/WarPigs-E WORM!
    AtiKeyNAtikey32.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    AtiKeyNatiptkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    AtikeyNAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
    ATIModeChangeUAti2mdxx.exeSystem Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
    atipatxxXatipatxx.exeAdded by the TROJ/SMALL-ED TROJAN!
    ATIPOLABUati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
    ATIPOLAB or ATIPOLLUati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resournces  on some computers, but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
    AtiPTA or AtiPTAAA or atiptaxxUAti2ptxx.exe, Atiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
    atiptextXatiptext.exeAdded by the COSIAM-A TROJAN!
    AtiQiPclUAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
    ATISmartUati2s9ag.exeATI's "SMARTGART", which is included with the "Catalyst" drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings
    AtiSoundUcsrss.exeAdded by the WinSpy surveillance software. Uninstall this software unless you put it there yourself - NOTE - this file is placed in a %System%\ComRoot folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    atisrc2Xwindfind.exeAdult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), mmxrun (msosa.exe) and RegCompres (REGCPM32.EXE), otherwise they return
    ATITechXActive.exeAdded by the Troj/Roamer-A TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    atitray or AtiTrayToolsNatitray.exeATI Tray Tool - allows quick access to ATI graphics card settings
    atiupdateXATIUPDATE5.EXE, msupdateQ********.exe (* = random digit)Added by the DEBESKI.A VIRUS!
    atiupdateXmsshed32.exeAdded by the DELF.EP downloader TROJAN!
    ATIUpdaterXatiupdxx.exeAdded by the W32/RBOT-ABX WORM!
    AtiupdplXatiupdpl.exeAdded by the TROJ_SMALL.AOS TROJAN!
    ativopenXativopen.exePremium rate adult material dialer
    ATIX10Uatix10.exeATI Remote Wonder - PC wireless remote control
    Atl**.exe (* = random char)XAtl**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Atl**32.exe (* = random char)XAtl**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    ATM ControlXadpn.exeAdded by the MMS.A VIRUS!
    ATnotesNatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
    Atomic-x27XAtomic-x27.exeAdded by the W32/Katomik-A WORM!
    Atomic-x27CXAtomicpartC.exeAdded by the W32/Katomik-A WORM!
    Atomic.exeUAtomic.exe Atomic_Clock_Sync synchronizes your computer's time with the NIST time server.
    AtomicaNatomica.exeAtomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key
    AtomicTimeUATOMICTIME.EXEAtomicTime - utility that synchronizes your PC clock to an atomic clock
    AtrackUatrack.exeNew feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert
    AtrayUAtray.exeActive Tray is a utility which lets you configure the system tray. You can also create your own tray icons
    ATSpoolerUAppsTraka.exeAdded by the AppsTraka surveillance software. Uninstall this software unless you put it there yourself.
    ATTBroadbandUpdateUSAUpdate.exeBig Brother from Quest Software. System and network monitor
    ATTRedUpdateUAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
    AttuneClientEngineXattune_ce.exe"Attune is a revolutionary service that provides you with targeted Intelligram messages to help you avoid common computer problems. Attune may also let you know when you need a specific product, service, or upgrade to optimise the use of your computer". Not required - treated as adware
    AttuneContentUpdaterXattune_cu.exeRelated to the above. All needed for the program to do its job properly
    AttuneDiscoveryXattune_di.exeRelated to the above. All needed for the program to do its job properly
    AttuneSystrayXattune_st.exeRelated to the above. All needed for the program to do its job properly
    aTunerNatuner.exeaTuner - tweak tool for GeForce based graphics cards
    atwtusbYatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
    AtxBrwXIexplor.exe"Pop Marketing" adware
    AU AgentUAUagent.exeAu Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon
    au.exeXau.exeAdded as the result of the BEAGLE.B WORM!
    AUCBPNPYaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
    AucompatXAucompat.exeAdded by the GEMA TROJAN!
    AudcntrXaudcntr.exeAdded by the WIN32.GEMA TROJAN!
    AudCtrl?RunDll32 AudCtrl.dll, RCMonitorAudio control panel?
    AUDIOXSOUND.exeAdded by the Dial/Ployb-A TROJAN!
    AudiocntlXaudiocntl.exeAdded by a Crypter.C trojan variant infection
    AudioDeckNADeck.exeADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items.
    AudiodrvXaudiodrv.exeAdded by the CRYPTER-C TROJAN!
    AudioHQNAhqtb.exeFor Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
    audioinfXaudioinf.exeAdded by a Crypter.C trojan variant infection
    AUNPS2XRUNDLL32 AUNPS2.DLL,_Run@16AlwaysUpdatedNews.com parasite related - More_information
    aupdXsymcsvc.exeAdded by the ABWIZ.D TROJAN!
    aupdXsysvcs.exeAdded by the ABWIZ.C TROJAN!
    aupdXsymcsvc.exeAdded by the Troj/Orse-H TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Aureal A3D Interactive AudioYsa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
    Aureal A3D Interactive Audio InitYA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
    ausvcXausvc.exeAdded by the AUTOUPDER VIRUS!
    Auth Starter IdentXstartauth.exeAdded by the W32/RBOT-WP WORM!
    AuthConsoleStartUAuthStart.exeSecurity Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private.
    authzXauthz.exeunidentified virus
    Auto CD-ROM StartupXcdaccess.exeAdded by the SPYBOT.BLA WORM!
    auto repair systemXqualityx.exeUnidentified worm, probably a W32.SpyBot variant
    Auto SwitchUTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
    Auto T Bar or autotbarNautotbar.exeIf you disable the HP VIEW toolbar in IE and rarrange the toolbars on a reboot they will be back as they were before if this is left enabled
    Auto updatXSysDebug.exeAdded by a W32/Forbot-BA worm infection
    Auto updatXcrsrs.exeAdded by the W32/FORBOT-BP WORM!
    Auto UpdatXWindowsSys32.exeAdded by a variant of the W32/FORBOT WORM!
    Auto updatXcrsrs.exeAdded by the W32/FORBOT-BP WORM!
    Auto updatXcrcss.exeAdded by the SDBOT.AAG WORM!
    Auto updat, various other namesXcrsrs.exeAdded by a W32/Forbot-AK worm infection
    Auto UpdateXAUP.exeAdded by an unididentified WORM or TROJAN!
    Auto UpdateXsvchost.exeAdded by the TROJ/DUMARDL-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Auto UpdateXdma.exeAdded by the W32/Rbot-AVO WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Auto UpdatesXsvchost.exeAdded by the Troj/Cheuko-A TROJAN!
    Auto WinUpdateXtaskmrg.exeAdded by the W32/Rbot-AFA Worm!
    AutobarUautobar.exeConnect buttons on the keyboard for internet direct access, etc. on HP computers
    AutoCAD Startup AcceleratorUacstart16.exePreloads some libraries that are used by AutoCAD in order to make the software load faster
    autoclkYautoclk.exeSagem Modem driver. Installed and required on systems running Windows 98 or ME
    AutoEANAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
    AUTOEXEXAUTOEXE.exeAdded by the W32/SEMAPI-A WORM
    AutoInsQyuleXQyuleInstall.exeAdded by the Troj/Dloader-ZM TROJAN!
    AutoloaderaproposclientXApropos_Client_Loader.exeAproposMedia adware
    AutoloaderaproposclientXcxtpls_loader.exe AproposMedia adware
    AutoLoaderEnvoloAutoUpdaterXauto_update_loader.exe Envolo/AproposMedia adware updater
    AutoMate Task ServiceNautomate.exeTask scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs
    Automatic Defrag ManagerXdefrag.exeAdded by the W32/Rbot-AKE WORM!
    Automatic Microsoft Windows UpdaterXsuchost.exeAdded by the W32/RBOT-EQ WORM!
    Automatic Windows UpdaterXUpdate.exeAdded by the GAOBOT.AO WORM!
    Automatically launches the United Devices AgeNUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
    AutopdateXAutopdate.exeAdded by the W32/Rbot-AGL WORM!
    AUTOPROPNREGPROP.EXE, WMPADDIN.DLLBoth the files are in the MS Office/Bots/FP_WMP directory. Apparently, it registers the FrontPage WiMP extension
    AUTOPROTECTUXnavapq32.exeAdded by an unidentified WORM or TROJAN!
    autorepairXdexs.exeAdded by a variant of the W32/SDBOT WORM!
    AutoShutdown?pssvc.exeUtility to fix vCard Export in MS Outlook 2000 - although why are these together?
    AutoSizerUAUTOSIZER.EXEAutoSizer - utility that automatically maximizes windows when they're opened
    AutoSpell 5NASWATC32.EXEAutoSpell - spell checker
    AutoTKitNAUTOTKIT.EXEOn HP PC\'s. Unclear what purpose it serves - but there\'s a known issue with Internet Explorer Toolbar settings not being saved with it enabled
    autoupdNautoupd.exeRaxco Software Auto Update utility."Used to keep your software up-to-date"
    autoupdXautoupd.exeVIRUS! - found in a folder of the same name
    autoupdateXWINUP2DATE.DLL,SHStartUnidentified adware - detected by Panda antivirus as Trj/Clicker.CY
    autoupdateXrundll32 [path] SUPDATE.DLL,SHStartAdded by a variant of the QOOLOGIC TROJAN!
    autoupdateXrundll32 [path] DATADX.DLL,SHStartAdded by a variant of the QOOLOGIC TROJAN!
    Autoupdate ServiceXkaka.exeAdded by the TROJ/SYMPE-B TROJAN!
    AutoUpdaterXaupdate.exeAupdate, Tinybar variant. Spyware
    AutoUpdaterXAutoUpdate.exePeopleonPage foistware
    autoupdatev2Xautoupdatev2.exeReported by Kaspersky Anti-Virus as Clicker.Win32.Agent.fq TROJAN!
    autoupdatev2X(Path of Executable)Added by the Troj/Dropper-BM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    AutoVirusProtectionXciscv.exeAdded by a variant of the WIN32.RBOT WORM!
    auto__antiav__keyXantiav_exe.exeAdded by the Lodav.A TROJAN!
    auto__hloader__keyXhloader_exe.exeAdded by the following TROJANS: BAGLE.AB - Troj/BagleDL-W - Troj/BagleDL-Y - Troj/BagleDl-Z
    aux.exeXaux.exeAdded by the BACKDOOR.ZINS TROJAN!
    auxAudioDeviceXaux32.exeAdded by the W32/Zusha-C WORM!
    AUXXTRAYNau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    AVXUPDATE-28062004.exe(25 blank spaces).vbsAdded by the MIDFIN WORM!
    AV UpDateXUpdate.exeAdded by theTROJ/FUROOT-A TROJAN!
    Avast!Yashserv.exeAvast! anti-virus software
    avast!YashDisp.exePart of Avast! anti-virus software
    avast! Web ScannerYAshwebsv.exe Avast! antivirus
    Avast32YAstart32.exePart of Avast! anti-virus software
    avcXavmon.exeAdded by an unidentified TROJAN!
    AvconsoleEXEUAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
    AveoAttuneXatmdlusr.exeRelated to AttuneClientEngine above
    AvGXsvchost323.exeAdded by the W32/RBOT-ZA WORM!
    AVG Grisoft UpdaterXupdater.exeAdded by the W32/AGOBOT-OT WORM!
    AVG7_AMSVRYAvgamsvr.exe AVG antivirus related
    AVG7_CCYAVGCC.exeAVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
    AVG7_EMCYAVGEMC.exeAVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
    AVG7_RunYavgw.exePart of AVG Anti-Virus 7.0
    avgamsvr.exeYAvgamsvr.exe AVG antivirus related
    AVGCtrlYAVGCTRL.EXEBackground task of the AntiVir antivirus program which scans files transparently in the background
    AVGCtrlYAVGNT.EXEBackground task of the AntiVir antivirus program which scans files transparently in the background
    avgmsvr.exeYavgmsvr.exeRequired for AVG Anti-Virus 7.0 to function
    Avgserv9.exeYAvgserv9.exeBackground monitoring program for AVG anti-virus
    AVGuardYAVGNT.EXEBackground task of the AntiVir antivirus program which scans files transparently in the background
    AVGuardYAVGUARD.EXEBackground task of the AntiVir antivirus program which scans files transparently in the background
    AVG_CC or avgcc32Yavgcc32.exeAVG anti-virus control center. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates
    AVG_EMCYAVGEMC.exeAVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
    AVG_RegCleanerYAVGREGCL.exeAVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems
    avidrvXdrvsc.exeDetected as the Trojan-Downloader.Win32.Agent.ph TROJAN! by Kaspersky Anti-Virus. Note: No URL available at this time.
    AvimgtXAvimgt.exeAdded by the GEMA TROJAN!
    Avimgt32XAvimgt32.exeAdded by the GEMA TROJAN!
    avinitYAVINIT9X.EXE Command antivirus related
    AVK Mail CheckerYAVKPop.exe eXtendia AVK AntiVirus email checker
    AVKBarYAVKBar.exeGData AntiVirusKit Anti-virus
    AvMaiSrvYAvmaisrv.exeAvast32 anti-virus - E-mail scanner
    avnortXmsmbw.exeAdded by the W32.Serflog.A WORM!
    avnortXformatsys.exeAdded by the W32.Serflog.A WORM!
    avnortXserbw.exeAdded by the W32.Serflog.A WORM!
    AVPX(Path to trojan EXE)Added by the Troj/Mutbo-A TROJAN!
    avpccYavpcc.exeKaspersky Labs anti-virus
    avpmYavpm.exeKaspersky antivirus
    AvprXavpr.exeAdded by the W32.Mydoom.AF WORM!
    Avril Lavigne - MuseX(random filename)Added by the AVRIL-A VIRUS!
    AVSCHED32YAVSched32.exeAntiVir anti-virus from H BDEV
    AVSchedScanYSCHSC9X.EXE Command antivirus related
    AvSerXsysup.exeAdded by the W32.Serflog.B WORM!
    AvSerXsvosm.exeAdded by the W32.Serflog.B WORM!
    AvSerXmsmpatch.exeAdded by the W32.Serflog.B WORM!
    AvSerXdsm.exeAdded by the W32.Serflog.B WORM
    avserve.exeXavserve.exeAdded by the SASSER VIRUS!
    avserve2.exeXavserve2.exeAdded by the SASSER.B or SASSER.C VIRUSES!
    avserve3.exeXavserve3.exeAdded by the SASSER.G worm
    AvtrayUAvtray.exe Command_Antivirus tray icon - NOTE: do NOT confuse with the rogue WinAntivirus startup/process as described here
    AVTrayXAVTray.exeWinAntivirus : a bogus, stealth installed "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites - NOTE: do NOT confuse with the legitimate Command Antivirus startup/process as described here
    AVWUpd32UAVWUPD32.EXEAntiVir updater. Useful, but can be run manually
    avx communicatorYxcommsur.exeAnti-virus part of BitDefender virus scanner/firewall
    AvxliveYavxlive.exeBullguard or BitDefender antivirus
    avxlniYavxinit.exeAnti-virus part of BitDefender virus scanner/firewall
    AWatchUAwatch.exeDiagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products.
    awhost32Nawhost32.exePart of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended
    AWMONUAd-Watch.exePart of Lavasoft Ad-aware SE Plus and Pro - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    AWMONUAd-Monitor.exe F-Secure_Anti-Spyware
    AWUSGSTA.exe?AWUSGSTA.exeReportedly related to a USB Wifi Adapter - is it required at startup?
    awxDToolsUawxDTools.dll,awxRegisterDll AwxDTools related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools. (i.e.: *.cue, *.iso, *.ccd ...)
    AxFilterXRundll32 AXFILTER.DLL, Rundll32CnsMin (Chinese_Keywords) related
    azmodemYazexe.exe Aztech_Labs modem driver
    Ua2guard.exe a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the a˛ 'Background Guard' real time protection feature
    B'sCLiPNBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
    B.ReaderNremin.exeBirthday Reminder 5.0 - as the name implies
    b3dXBDEsecureinstall.exeB3d Projector - installed along with the KaZaA file sharing utility. Causes a program called "ZUPDATE.EXE" to periodically try to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
    b3dUpdateXZupdate.exeSame as above but not installed via KaZaA
    b9UB9.exeFireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"
    b99Xmsmm.exeClientMan parasite variant
    babeieXrundll32 cnbabe.dll, dllstartupCommonName Toolbar spyware. To uninstall see here
    Babylon ClientNBabylon.exe Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
    Babylon TranslatorNBabylon.exe"Babylon-Pro is a powerful information tool that instantly provides relevant information, translations & conversions for any word or value you click on"
    Back UpdatesXUninstall.log.vbsAdded by the VBS.YPSAN.D WORM!
    Backdoor.NuAgentXagent.exeAdded by the AGENT-DP TROJAN!
    Background Intelligent Transfer ServiceXrundll32.exeAdded by the TROJ/VB-ZD TROJAN! - Note: this file is located in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file!
    BackgroundSwitcherUbgswitch.exeBackground Switcher Powertoy. Included with the last beta version of the XP Powertoys. Whenever a user right clicked his desktop and chose properties he could see a new tab which allowed him to enable a "Desktop Slide Show." This would automatically change the Windows Desktop at an interval specified by the user. Available here
    Backpack UDFNbpudfmon.exeBackpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk
    Backup ServiceXbackup.svcUnidentified adware
    BackupExecSchedulerUbesch.exeVeritas "Back Up My PC" software
    BackupNotify?backupnotify.exeHP Digital Imaging related. What does it do and is it required?
    BackWebNbackweb.exeAutomatically detects an internet connection and downloads any available updates. Typical on Compaq and HP PC's but not restricted to those OEM's. Resource hog and often causes malfunctions. Available via Start -> Programs
    BackworkNBackwork.exeBackwork trojan detector
    BACPI10Ubacpi10a.exeKnown as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray
    BacsTrayNBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
    BADDATEXBADDATE.EXEAdded by an unidentified VIRUS!
    BagleAVXcsrss.exeAdded by the W32.NETSKY.AB WORM! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    BakraXIEHost.EXE IEDriver adware variant
    BakraXIEHost.exeAdded by the Troj/Multidr-AH TROJAN!
    Band-AidX(path to file)Added by the BACKDOOR.RANKY.O TROJAN!
    BandookXali.exeAdded by the TROJ/EXEMAS-B TROJAN!
    Banpopup by PratikUBanpopup.exeBanpopup - popup killer
    Bar Ding loltXAnaliz.exeAdded by the RBOT-RP WORM!
    bargainsXbargains.exe, bargainbuddy.exeBargain Buddy - advertising spyware installed with Net2Phone & LimeWire amongst others. Some further information here
    Bart Station?station.sbrtRelated to PeoplePC ISP. May be a dialler for dial-up accounts?
    bascstrayNBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems
    BatXsecure2.batAdded by the ZCREW.C VIRUS!
    Batchreg1NN/APart of the Windows System Recovery process. Added to the registry via Msbatch.inf. The existence of this key or process after the last reboot during installation indicates an unsuccessful installation, as that key should be deleted automatically. See here
    BatInfExUrundll32.exeDisplays battery status information on an IBM Thinkpad
    Battery ScopeUbatmgr.exeMonitors battery levels on a notebook/laptop PC
    BatteryBarUbatterybar.exeBatteryBar - displays battery usage, and the current percentage of battery power left
    BatzBackXBatzBack.scrAdded by the BACKZAT VIRUS!
    BAUSBUBAUSB.exeBoston Acoustics Audio, USB driver
    bawindoXbawindo.exeAdded by the BEAGLE.AR WORM!
    bawindoXbawindo.exeAdded by the W32.BEAGLE.AU WORM!
    BayMgrUDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices 
    BayswapUbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
    Bayswap2UTbUpdate.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices
    BBC News alertsUskinkers.exeBBC News Desktop Alerts service; see here - The BBC News desktop alert and breaking news e-mail services let you find out about all the latest news as it happens.
    bbSysTrayNbbSysTray.exePhilips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"
    bbuiUbbui.exeAOL DSL status monitor displaying a red/green icon indicating if you have a connection
    bcaUbca.exeBeClean Agent - registry, history, temp files, etc cleaner
    BCDetectUbcdetect.exeBcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see
    BCMDMMSGYbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
    BCMHalUrundll32.exe bcmhal9x.dll, bcinitBlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
    BCMSMMSGYBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modems
    bcmwltry?bcmwltry.exeBroadcom Corporation Wireless Network Tray Applet.Is it required?
    bcnswSXX(path to file)Added by a Ranck-AJ trojan infection
    BCNTNbcnt.exeAWS Weatherbug related. What does it do?
    BCPCXbcpc.exe BroadcastPC adware variant
    bcpc_cXbcpc_c.exe BroadcastPC adware variant
    BCTweakUbctweak.exeBlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings
    Bcvsrv32Xbcvsrv32.exeAdded by the W32/AGOBOT-TD WORM!
    BCWipeTMNbcwipetm.exeBCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed
    BDXdc.exeAdded by the Troj/Rasdoor-A TROJAN!
    BDMConYBdmcon.exeEither BitDefender or BullGuard antivirus
    BDNewsAgentYbdnagent.exeBitDefender antivirus - updater
    BDOESRVYbdoesrv.exe Bitdefender 8 antivirus and firewall
    BDSwitchAgentYbdswitch.exe Bitdefender 8 antivirus and firewall
    BearShareNbearshare.exeBearShare file sharing client. Versions known to include spyware - see here
    BeatNik Internet ClockUBeatNik.exe BeatNik_Internet_Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with the atomic clock.
    Beegees UpdateXbeegees.exeAdded by the W32/Sdbot-ADK WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    BeFasterUbefaster3.exe BeFaster internet connection optimization tool
    Belkin PCMCIA WLAN MonitorNmonitorbk.exeBelkin USB Network Adapter Management utility - can be started manually
    BelNotifyU[path] NPBelv32.dll,RunDll32_BelNotify BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service.
    Belsta.exe?Belsta.exeConfiguration tool for Belkin wireless network cards. Required to change the card’s configuration. Is it required for correct operation once the confuiguration is changed?
    BeltXBelt.exe Transponder parasite updater/installer
    Benadril Alert ToolXbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril
    BestPopUpKillerNBestPopupKiller.exePopup killer by Swanksoft - not recommended, see Rouge/Suspect_list
    BeSysX[path to the adware program]Added by BeSys ADWARE!
    bgYbullguard.exeBullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster
    BGInfoUBginfo.exe BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more.
    BGNewsAgentYbgnewsag.exe BullGuard antivirus updater
    bgsmsndNbgsmsnd.exePrinter driver to generate PDF files from any program
    BHOCopNBHOCop.exeZDNet's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware
    BHODemon 2.0UBHODemon.exeBHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on demand.
    BI1HelperStartUpUBI1HEL~1.EXE Beach_Islands Screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    BIEXRundll32.exe BDSrHook.dll, Rundll32BDplugin parasite
    BigDogPath?VM_STI.EXEBundled with some software for digital cameras that use a USB connection. - what does it do and is it required?
    bigfixNBIGFIX.EXEBigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog
    BigPond ToolbarUbpumTray.exeTelstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"
    BigPondCableNbpcable.exeTelstra Bigpond Cable login software. Can be started manually.
    BillminderNBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start -> Programs
    bin32hpuXppstub.exePrecisionPop adware
    bingdianXBingdian.vbsAdded by the BINGD VIRUS!
    Bingo Charm?charms.exeSome kind of screen icon kind of like desk flag, but it gives you a choice of icons?
    BiosXBios32.exeAdded by an unidentified VIURS!
    BIOS XP LoaderX[random file name]Added by the W32/RBOT-IC, ~http://www.sophos.com/virusinfo/analyses/w32rbotic.html WORM!
    BIOS1XBIOS1.EXEAdded by the OPASERV.T VIRUS!
    BIOVCIP?BIOVCIP.exe??
    BitCometNBitComet.exe BitComet P2P client - can be launched from Start Menu > Programs
    BitDefender AntivirusXBITDEFENDERX.EXEAdded by a variant of the W32.SPYBOT WORM!
    BitDefender CommunicatorYxcommsvr.exeBitDefender antivirus
    BitDefender for MSN MessengerUmsnmon.exeBitdefender anti-virus for MSN Messenger. Unless you have MSN Messenger running all the time start it manually
    BitDefender for Yahoo! MessengerUyahmon.exeBitDefender Antivirus for Yahoo! Messenger - free AV add-on for Yahoo! Messenger
    BitDefender Live! InitYbdinit.exeBitDefender antivirus
    BitDefender Scan ServerYbdss.exeBitDefender antivirus
    BitDefender Virus ShieldYvsserv.exeBitDefender antivirus
    bitdefenderliveYavxlive.exeMain program of BitDefender virus scanner/firewall
    BitDefender_P2P_StartupUBitDefender_P2P_Startup.exeBitdefender anti-virus for file transfers via internet messaging clients such as ICQ and MSN Messenger. Unless you have these running all the time start it manually
    BitWare Print MonitorNbwprnmon.exeFaxServe network fax software
    BJ Printer Status MonitorNCjstsr.exeCanon BJ printer status monitor
    BJ Status Monitor 5xxNCJSTRxx.EXECanon printer status monitor - where "xx" is different depending upon the version. Not required as you can check the printer status via My Computer -> Printers
    bjcfdNCFD.exeBroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
    BlackICE PC Protection or BlackIce UtilityNblackice.exeLoads the user interface for the BlackICE PC Protection (was Defender) firewall program. From the parent site - \'(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.\' See also LoadBlackD
    blah serviceXwinupdate.exeAdd by the GAOBOT.BIA WORM!
    blah serviceXwinsysengine.exeAdded by a W32/Rbot-KI worm infection
    blah serviceXsmnp.exeAdded by the RBOT.IZ WORM!
    blah serviceXinternet.exeAdded by a variant of the WIN32.RBOT WORM!
    blah serviceXmsnmsgrr.exeAdded by the RBOT.PZ WORM!
    blah serviceXtazkmgr.exeAdded by the RBOT.UA WORM!
    blah serviceXFaLeH.exeAdded by the W32/Rbot-AES Worm!
    blah serviceXmicrosoft.exeAdded by a variant of the WIN32.RBOT WORM!
    Blah serviceXCCAPPS32.EXEAdded by the RBOT.TV WORM!
    blah serviceXevosys.exeAdded by a variant of the WIN32.RBOT WORM!
    blah serviceXwin32.exeAdded by the W32/Rbot-AXO WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    blahh serviceXmsengine.exeAdded by a variant of the WIN32.RBOT WORM!
    blahx serviceXmsnjompa.exeAdded by the SDBOT.AML WORM!
    BlazeChangerNFBZPaper.exeEmber graphic file viewer, manager, and touch-up system
    bldbubgNbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
    BlesXbles.exeAdded by the TROJ/BLESH-A TROJAN!
    blinkxUblinkx.exe Blinkx_Desktop "Smart Folders" software
    BLMessagingIntegrationXblengine.exeBuddyLinks adware
    BlockAdsUblads.exeA Tweak-XP component, blocks advertisement banners in Internet Explorer. Can be enabled/disabled via Tweak-XP / Internet Tweaks
    BlockCheckerXBlock-checker.exe BlockChecker adware
    Blocker System611 MonitoringXPopUpBlocker611.exeAdded by the RBOT.BLJ WORM!
    BlockTrackerNBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt file
    blsloaderUblsloader.exeBellSouth ISP Internet_Tools
    blssXblss.exeAdded by the Backdoor.Blarul TROJAN!
    BLSTAPPNblstapp.exePuts access to Creative's BlasterControl in the System Tray
    BlubsterNBlubster.exeRelated to Blubster Music sharing service.
    bluestartXrraut.exeAdded by the VB.GY.2 downloader TROJAN!
    BlueToothAuthentication AgentUrundll32.exe irprops.cpl,,BluetoothAuthenticationAgentAssociated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup.
    BluetoothAuthenticationAgentUrundll32.exe bthprops.cpl,,BluetoothAuthenticationAgentAssociated with BlueTooth software, designed to allow bluetooth mobile devices to authenticate to the computer, when connecting a PDA to your computer - necessary for the computer and the PDA to communicate.
    Blueyonder Instant Support ToolUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". Blueyonder Instant Support is required to run with the Help and Support program. If you uncheck it and and then run Help and Support it will add another Blueyonder Instant Support in the startup menu. If you remove Blueyonder Instant Support in add/remove programs some help menus in help and support will not be available. You decide
    BMail InstallationNFTP_back.exePart of iMesh - a file sharing system. Reported by Norton AntiVirus as a trojan. Once deleted does not prevent file sharing working. Older versions of iMesh re-instate this but the newer versions do not
    BManXBMan1.exeAbcsearch.com/DealHelper adware variant
    BMMGAGURundll32 PWRMONIT.DLL, StartPwrMonitorDisplays a battery gauge icon in the Taskbar (not the System Tray). Provides shortcuts to IBM's proprietary power saving settings and to a battery information window
    BMMLREFUBMMLREF.EXEBattery Manager for IBM ThinkPad laptops
    BMO MasterCard WalletUEWALLET.EXEThe wallet conveniently stores billing, shipping and payment information on your PC
    BMupdateNBMupdate.exeRelated to BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install
    BMZXbmz.exenCase adware
    Bndt32XBndt32.exeAdded by the LACON VIRUS!
    BnexeX(random filename)Added by the KITRO.D (or ARGEN.A) VIRUS!
    BO1HelperStartUpUBO1HEL~1.EXEScreenScenes Butterfly_Oasis screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    BO1HelperStartUpUBo1helper.exeScreenScenes Butterfly_Oasis screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    BoarddataX[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    BOC412YBOC412.exeVersion 4.12 of NSClean's BOClean anti-trojan software
    BOCleanautostartYBoclean.exeNSClean's BOClean anti-trojan software
    bombshelUBOMB32.EXEPart of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems
    Bonzi BuddyX??Spyware - read here for information and here for removal instructions
    booXboo.exeAdware downloader - detected by Kaspersky antivirus as Trojan.Win32.Favadd.o
    BookedSpaceXbs2.dll,DllRunAdware, related to the Remanent parasite
    BookmarkCentralNBMLauncher.exeBookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use"
    Boost XP ServiceUbxservice.exeBoost XP from Systweak - WinXP tweaking utility 
    bootXboot.exeAdded by the Troj/Puppet-A Trojan!
    Boot ManagerXNjgal.exeAdded by the KILO VIRUS!
    Boot ManagerXbootmng.exeAdded by a variant of the W32.SPYBOT WORM!
    BootCfgXInstall.log.vbsAdded by the VBS.YPSAN.D WORM!
    BootCTRLXbootctrl.exeAdded by an unidentified WORM or TROJAN!
    BootLoaderXBootLoader.exe.vbsAdded by the WATERWORKS VIRUS!
    bootpd.exeXbootpd.exeHijacker - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.vk
    bootpd.exeXbootpd.exeAdded by the Troj/Agent-DT Trojan!
    BootsCfgXDate.POP.vbsAdded by the VBS.KUULLIO WORM!
    BootsCfgXwscript.exe [path] All Users.vbsAdded by the VBS.SPILTRON WORM!
    BootsCfgXwscript.exe [path] All Users.vbeAdded by the VBS.SPILTRON WORM!
    BootsCfgXwscript.exe[path] Install.log.vbsAdded by the VBS.YPSAN.E WORM!
    BootSkin Startup JobsUBootSkin.exe Stardock_BootSkin is a program that allows users to change their Windows 2000 and Windows XP boot screens, free for non-commercial use.
    BootStatusUBOOTST~1.EXEVisual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day.  Once you exit it, it has no more effect on resources
    BootWarnUBootWarn.exeFrom here : "Norton AntiVirus Boot Warning. This program is installed as a startup item when you install Norton AntiVirus, and also sometimes when you do a LiveUpdate which updates Norton AntiVirus significantly enough that a reboot is needed to complete the installation. We believe its purpose to be to warn the end-user that he must reboot his PC before using Norton AntiVirus in those cases when a reboot did not happen with the result that Norton AntiVirus did not fully complete its installation or software updating. Recommendation : Start Norton AntiVirus from “Start \ Programs \ Norton AntiVirus”. If Norton AntiVirus comes up without problems, then fix this entry from the Msconfig Startup tab – it was left behind by mistake and is no longer needed now that Norton AntiVirus is fully installed and opens without error messages."
    boot_regX[path to file]Added by the TROJ/BANCBAN-CA TROJAN!
    Bose Wave/PC MonitorNwavepcmonitor.exeSystem Tray access for this system (more info on the system here). Available via Start -> Programs
    BossIdeaXwinlogin.exeAdded by the TROJ/LINEAGE-I TROJAN!
    Boston?Boston.exePart of the Boston Acoustics USB speaker systems. - What does it do and is it required?
    Bot LoaderXsvchostt.exeAdded by the W32.GAOBOT.ALV WORM!
    Bouncer RunStartupXbouncer.exe VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
    Bouncer RunStartupXLiveUpdate.exe VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
    boy lovers of bsdXilikeboys.exeAdded by the MYTOB.LY WORM!
    bpcpost.exeUbpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    BPCv2XBPCv2.exe BroadcastPC adware
    BPCv2_reXbpc2_re_inst.exe BroadcastPC adware variant
    BPKUbpk.exe, nvsr32.exeBlazing Tools Perfect Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
    BPServerNG6FTPSrv.exeBulletProof FTP Server
    BPTXbpt.exe BroadcastPC adware
    BQTray.exeUBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
    BrasilXBrasil.exeAdded by the OPASERV.E VIRUS!
    BrasilXBRASIL.PIFAdded by the OPASERV.E VIRUS!
    BrasilOldX(worm filename)Added by the OPASERV.P VIRUS!
    BrctXtrdb.exeReported as Win32.PurityScan.y TROJAN! by Kaspersky Anti-Virus. Class: Trojan-Downloader. Note: Lowers Internet Explorer security settings and downloads unwanted files.
    Break_ReminderUBREAK REMINDER.exeBreak Reminder - Remind yourself to take breaks to prevent computer related injuries. See here
    BregXbcre.exe BroadcastPC adware variant
    BregXbreg.exe BroadcastPC adware variant
    BregXbptre.exe BroadcastPC adware variant
    BridgeXrundll32.exe ...Bridge.dllFlingstone.com browser hijacker
    Brindys BriTrayYBRITRAY.EXEMain process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired
    BrmfRmPAUBrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copier/scanner and PC to properly communicate
    Broadband WizardNbbwiz.exeStarts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start -> Programs
    Bron-SpizaetusXCVT.exeAdded by the W32.Rontokbro WORM! Note: This worm\trojan file is found in the Windows\PIF or Winnt\PIF folder.
    Bron-SpizaetusXnorBtok.exeAdded by the RONTOKBRO.B WORM!
    Bron-SpizaetusXElnorB.exeAdded by the RONTOKBRO.D WORM!
    Bron-SpizaetusXbronstab.exeAdded by the RONTOKBRO.C WORM!
    Bron-SpizaetusXsempalong.exeAdded by the W32/Brontok-E WORM! Note: This worm\trojan file is found in the Windows\ShellNew or Winnt\ShellNew folder.
    Bron-SpizaetusXeksplorasi.exeAdded by the RONTOKBRO.J WORM!
    Bron-SpizaetusX[path to file]Added by W32/Brontok-F WORM!
    BrowseProxyNFindService.exeActual Names - "It is now possible to enter a particular word or keyword phrase that is associated with your business, and immediately be directed to YOUR WEBSITE! The Actual Names technology can do this for you"
    browserXmsgaol.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    browserXs_menu.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    browser aidXbrowseraid.exeBrowserAid/BrowserPal foistware
    Browser Help SvcXBHSV.EXEAdded by the W32/Rbot-AVQ WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Browser Hijack BlasterYbhblaster.exeBrowser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings
    Browser LauncherUCommandr.exeLogitech internet keyboard "Commander" software - loads the software for the shortcut keys on the keyboard. Not required unless you want to use the short cut keys
    Browser PalXadblck.exeBrowserAid/BrowserPal foistware
    Browser SentinelUBrowserSentinel.exeBrowser Sentinel. Notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page. See here
    BrowserWebCheckNloadwc.exeChecks to make sure that IE is still your default browser
    BS PlayerNbsplayer.exe BSplayer - A video player used to play avi, mpg, wmv and other multimedia files.
    BsCLiPNBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't required
    Bsoft lppt01XBsoft.exeNew variant of the RapidBlaster parasite (in a "BelmontSoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Bsx3XRundll32.exe bs3.dll, DllRunBookedSpace parasite variant
    BTX(Original Trojan filename)Added by the Troj/Litebot-B TROJAN!
    BT Broadband HelpUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". BT Broadband Help is required to run with the Help and Support program. If you uncheck BT Broadband Help and and then run Help and Support it will add another BT Broadband Help in the startup menu. If you remove the BT Broadband Help in the add/remove program some help menus in help and support will not be available. You decide
    BT00003(2 or 3 or 4)Xhiklmnop27.exeAdded by the Troj/VB-VT TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    BT00003(5 or 6 or 7)Xabcdefg23.exeAdded by the Troj/VB-VT TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    btinst?btinst.exeAssociated with an Anycom bluetooth wireless card. What does it do and is it required?
    BTModemProtectionUBTModemProtection.lnkBT Privacy Online modem protection software, see here
    BTSETBOOTKEY?BTSetBootKey.exeRelated to a USB Bluetooth adaptor - what does it do and is it required?
    BtStartUbtstart.exe Broadcorp (formerly WIDCOMM) Bluetooth Connectivity Software
    bttrayUbttray.exeSystem tray icon which shows the status of a BlueTooth wireless module. Most systems with such a module installed can enable/disable the module. The system tray icon changes from blue/white to blue/red when the module is turned off. Allows access to explore bluetooth places, setup wizard, advanced configuration, quick connect and shutdown device
    BTUSRBDGYBtUsrBdg.exeUsed with a Mitsumi_USB_Bluetooth adaptor (and maybe others)
    BTUSRBDGFYBtUsrBdg.exeUsed with a Mitsumi USB Bluetooth adaptor
    BTVXbtv.exe BroadcastPC adware
    BuddyizerNBuddyizer.exePart of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network
    bugwatcher serviceUbugwatcher.exeBugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures
    BuildBUNbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her system
    BuildLabXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    BuildLabsXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    BuildLabsXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    Bulldog ServiceUupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
    BullGuardYmgui.exePart of Bullguard antivirus
    BullGuard UpdateUavxlive.exePart of Bullguard antivirus. Leave enabled unless you manually update virus definitions
    BullGuard XCommYXCOMMSVR.EXEPart of Bullguard antivirus
    BullGuardInitYAVXINIT.EXEPart of Bullguard antivirus
    BullguardoptInYbulldownload.exePart of Bullguard antivirus
    BullsEyeXbargains.exeeXact Advertising BargainBuddy/Bullseye adware
    BullsEye NetworkXbargains.exeeXact Advertising BargainBuddy/Bullseye adware
    BullsEye Tracker?BeTrack.exeBullseye - intelligent research assistant
    BunxXbeagle.exeAdded by the W32/Lebreat-E WORM!
    BurnQuick QueueNBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually
    Button ServerUbttnserv.exeFound on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required
    ButtonKeyNButtonKey.exeCyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut
    BuzmeNBmui.exeBuzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
    BuzMeURCUI.exeDisplay Client for the BuzMe Internet Call Waiting Service.
    Buzof.exeUbuzof.exeBuzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"
    bxsx5XRunDLL32.EXE bsx5.dllBookedSpace parasite variant
    bxxs5XRunDLL32.EXE bxxs5.dll, dllrunBookedSpace parasite
    Bymer.ScannerXWininit.exeAdded by the BYMER WORM!
    Bymer.ScannerXMsinit.exeAdded by the BYMER WORM!
    cXc:\archiv~1\win.comAdded by the CUYDOC VIRUS!
    C-Media Echo ControlUEchoCtrl.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. You may need it if you use the echo control feature of C-Media Mixer
    C-Media MixerNMixer.exeC-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
    C2KUCYB2K.EXECYBERsitter 2000 or 2001 -  anti-porn filter primarily. Required if you want the sites you visit filtered without having to load the software every time you launch your browser
    c32cs2Uc32cs2.exe Cyber_Sentinel Internet filtering software
    C7X[name of worm]Added by the W32.MEDIAKILL.A WORM!
    C:\WINDOWS\IEXPLOR.EXEXIEXPLOR.EXE"Pop Marketing" adware
    C:\WINDOWS\VCMnet11.exeXVCMnet11.exe"Windows AFA Internet Enhancement" - a browser hijacker, redirecting to adsourcecorp.com - see here
    C:\WINDOWS\WinTask.exeXWinTask.exe"Pop Marketing" adware
    CA-AMAgentUamagent.exe Unicenter_Asset_Management is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting.
    CaAvTrayYCAVTray.exeeTrust™ EZ_Antivirus system tray application from Computer Associates
    CabchkXCabchk.exeAdded by the GEMA TROJAN!
    Cabchk32XCabchk32.exeAdded by the GEMA TROJAN!
    CABCInstallXCABCInstall.exeCABC content delivery software
    CacheBoostUtrayicon.exe CacheBoost "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost"
    CacheLoaderX(path of filename)Added by the Troj/Dloader-NZ TROJAN!
    CachemanNCacheman.exeFreeware disk cache tweaker from Outer Technologies. Should only be run once and not loaded at start-up
    CacheMgrYCacheMgr.exeSophos Antivirus Remote Update
    CACStarterNcacstart.exeCash A Check - check writing software
    Caddais BackupOnDemandUBODMon.exeCaddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"
    CadenzaUCdzSvc.exeCadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices
    CADSUcads.exeCyber Sentinel internet filtering software
    CAgentNCAgent.exeAbbyy Fine Reader OCR (Optical Character Recognition) software for scanning and converting documents
    cAgOuX(filename).htaAdded by the KAKWORM VIRUS!
    CahootWebcardNCahootWebcard.exe"The Cahoot Webcard is a virtual card that allows you to use your Cahoot credit card online without ever having to expose your real card numbers over the web. It works by generating one-off transaction numbers as a substitute for your real cahoot credit card details". Run manually when needed
    CAISafeYisafe.exePart of Computer Associates eTrust EZAntivirus
    Cal Reminder ShortcutNcalrem.exeProduces a pop-up reminder of events scheduled using the MS Office Calendar
    Calc Microsoft WindowsXwincalc.exeAdded by an unidentied WORM or TROJAN!
    CALC32XCALC32.EXEAdded by the W32/Spybot-EC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Calendar 200X ReminderNcalendar.exe Calendar200X - shows holidays, reminders of various anniversaries,tasks etc
    CalendarscopeUcs.exe Calendarscope calendar software
    calkXcalk.exeAdded by the TROJ/STARTPA-FH TROJAN!
    CallBumping?cbpopw.exe??
    CallCenter Main ApplicationUV3calmcp.exe"V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Main application
    CallCenter Printer InterfaceUV3faxecp.exe"V3 Inc. CallCenter is a free 32-bit, integrated fax, voicemail and data communications application with a simple to use interface providing fax send and receive functionality, basic (single mailbox) answering machine capability, and sophistcated data communications." Fax printer
    CallControlNftctrl32.exeFaxTalk Messenger Pro is a Windows TAPI based 32-bit application. When installed, the software automatically loads FaxTalk CallControl when you start Windows. When FaxTalk CallControl is running, any TAPI compliant application can request to use the modem from Windows
    CamCheckNCamCheck.exeNuCam camera software related
    CamenoUCameno.exe Cameno is a program which brings tabbed windows to MSN Messenger 6.0 and above
    Camera DetectorNCamdetect.exe ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
    Camera DetectorNCAMDET~*.EXE ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
    Camera DetectorNDEVDET~*.EXE ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically.
    Camio Viewer xNIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
    CamMonitor?hpqcmon.exeFrom HP and related to digital imaging
    CanadaNCanada.exeKnown to be a dialler - but is it maliscous or clean?
    CanaryNcanary-std.exeCanary monitoring program. Keylogger, monitors all computer activity
    candyXcommand32.exeAdded by the W32/Rbot-LV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    candynetXTaskmsg.exeAdded by the W32/Rbot-NA WORM!
    Canon MultiPASS Status MonitorUmonitr32.exeCannon Multi-Pass status monitor - your choice.
    Canon PC1200 iC D600 iR1200G Status Window?CAPM1LAK.EXECannon printer related - is it required in startup?
    Canon Printer Monitor BJCxxxNCjstlst.exeTrayicon for Canon printer. xxx denotes model. Available via Start -> Programs
    CAP3ON?CAP3ONN.EXECanon driver, purpose unknown - is it required in startup?
    CapfaxNcapfax.exePhoneTools fax software
    CaponYCapon.exeCanon printer driver
    CaponYCaponn.exeCanon printer driver
    CaptionMgr32Xcrssr.exeAdded by the W32.ZAR.A WORM!
    Capture Express 2000Ncapexp.exeCapture Express - screen capture utility
    Card MonitorNREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
    Care20XCare20.exe TopMoxie adware
    Care2GTUUCare2GTU.exeCare2 Green Thumbs-Up (from the Care2 site). Every online purchase helps environmental causes; tells you how eco-friendly a company really is, thanks to over 200 company profiles from Coop America. Saves 1 square foot of rainforest every day you use it. If it works and you like it keep it
    CARPserverXCARPserver.exeAdded by the TROJ/BANKER-AN TROJAN!
    CARPserviceUcarpserv.exeAssociated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
    cartaoX[path to file]Added by the TROJ/DLOADER-QD TROJAN!
    cartaoXconflicted.exeAdded by the TROJ/DADOBRA-DV TROJAN!
    cartaoXkilling.exeAdded by the TROJ/DLOADER-QN TROJAN!
    CAS ClientXcasclient.exe CasinoClient adware
    CasAgntUCasAgnt.exeProgram by Extended Systems which allows you to sync your Casio PDA with your PC
    CasdvqwaXbmqnzkg.exeAdded by the RANDEX.BE VIRUS!
    caseyvideoXCaseyVideo.exemalware causing p0rn popups
    caseyvideo[*] (* = digit)Xcaseyvideo[*].exe (* = digit)malware causing p0rn popups
    CashBackXcashback.exeeXact Advertising BargainBuddy/CashBack adware
    CashFiestaXCashfiesta.exe CASHFIESTA.A pay-per-surf adware
    Cashsurfers Cashbar NavigatorNCashbar.ExeCashsurfers CashBar Navigator - "The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"
    CashToolbarXCD_Load.exe"CashToolbar" Downloader-MY TROJAN!
    CashToolbarXsvchost.exe"CashToolbar" Downloader-MY TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    CassandraXcassandra.exe Melkosoft_Cassandra adware - also detected as a variant of the WIN32.KREPPER TROJAN!
    Cassandra and or Control handlerX(10 to 14 random)THD.EXEAdded by the Troj/Krepper-AI Trojan!
    CasStubXcasstub.exeAdded by the Troj/Cass-A TROJAN!
    CAVRIDYCAVRID.exeeTrust™ EZ_Antivirus Real Time Infection Report from Computer Associates
    CAVSYCAVS.exeCheyenne, ( now eTrust ) antivirus
    CAZNOVASXCAZNOVAS.exeAdded by the CAZNO VIRUS!
    CBACK.EXEXCBACK.EXEAdded by the Troj/Penta-A TROJAN!
    CBWAttnUCBWAttn.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problems
    CBWHostUCBWHost.exeRequired for Bitware to answer incoming faxes, can cause sleep mode problems
    CBWUser?CBWDial.exeAssociated with Bitware that integrates fax, voice, pager, and data communications on your desktop
    CC2KUIXcomet.exeComet Cursor - displays different mouse pointers dependent upon the site your visiting. Malware because it automatically installs. See here for more information and for the uninstall procedure
    ccAppYccApp.exePart of Norton AntiVirus 2003. Auto-protect and E-mail check will not function without this
    ccAppX(random filename)Added by the OBSORB VIRUS! Note the random filename compared to the valid Norton AntiVirus entry above
    ccAppXWMADZ.EXEAdded by the W32/RBOT-LJ WORM!
    ccAppX.EXEAdded by the W32/RBOT-LJ WORM!
    ccAppXgcasServ.exeAdded by a variant of the WIN32.RBOT WORM! - do NOT confuse with the Microsoft AntiSpyware executable of the same name as described here
    ccApprXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccApprXoutIook.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccApprXexpIorer.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccApprXsvcshost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccAppsXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    ccAppsXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    ccAppsXccApps.exeAdded by the W32/KANGAROO-B WORM!
    CCD ManagerUDDS.EXEProject Labs Century CD manager for their CD/DVD storage device
    CcdecodeNrundll32.exe streamci, StreamingDeviceSetupPart of the closed caption decdoder/MS VBI codec. Should only run once
    CCDoctorLogonTestingYccdoctor.exeChecks your system to make sure it's configured properly for running Rational ClearCase, a source code management tool. ClearCase is fairly sophisticated so there are a lot of system-related things that can cause it grief. If you run ClearCase you should not disable this as it provides a valuable service, but technically it isn't required to use the ClearCase product
    ccenterYCCenter.exe RAV AntiVirus
    CcEvtMgrYccEvtMgr.exePart of Norton AntiVirus 2003.Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via "ccApp" and was not required as a seperate entry but a recent update changed this
    ccEvtMrg.exeXccEvtMrg.exeAdded by the RBOT.GZ WORM!
    ccExecuteXbootcfg1.exeAdded by the W32/NEMSI-B VIRUS!
    ccHelpXccHelp.hta "Searchq" adware
    ccpAppsXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    ccpAppsXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    ccProxyUCCPROXY.EXEPart of Norton Internet Security, proxy server that is used to support the parental controls. If you turn parental controls off at user level the process is not loaded. Reported to cause excessive CPU usage.
    CcPxySvcYCCPXYSVC.exePart of Norton's AntiVirus 2003, Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall
    ccregXexplorer.exeAdded by the ZCREW VIRUS! Note - this is not the valid explorer.exe
    CcRegVfyYccRegVfy.exePart of Norton AntiVirus 2003. "ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"
    ccRegVfYXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccRegVfYXoutIook.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccRegVfYXexpIorer.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccRegVfYXsvcshost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    ccSetMgrYccSetMgr.exePart of Norton AntiVirus 2004. What does it do?
    ccsvit.exeXccsvit.exeAdded by the Troj/StartPa-HP TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ccUpdateXccUpdate.exeAdded by the AGOBOT.YS WORM!
    ccWasherUaolwasher.exeWebroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL
    CCWC7aUac.exeCache, Cookie & Windows Cleaner Ver. 7, Auto clean. Created by moleculesoft
    CCWC7IUidxl.exeCache, Cookie & Windows Cleaner 7 created by moleculesoft.com
    CCWC7sUstealth.exeCache, Cookie & Windows Cleaner 7, stealth mode. Created by moleculesoft
    CD Storage MasterNcdstorager.exe CD_Storage_Master - a program designed to catalog CD information, boasts a number of handy features for organizing your collection.
    cd1Xcd1.exePremium rate adult content dialer
    CDANTSRVNCDANTSRV.exeC-Dilla License Management software. Used for any program that uses C-dilla Protection, example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually
    CdcompatXCdcompat.exeAdded by the GEMA TROJAN!
    cddrv32Xcddrv32.exeAdded by a Crypter.C trojan variant infection
    CDInterceptorNcdi.exeCD indexer for measuring the speed of CD players
    Cdrom ControllerXcdromcntrl.exeAdded by the TROJ/BATTRY-A TROJAN!
    cdsXcds.exeAdded by the Backdoor.Spymon TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    CDTrayNCDTray.exeOn HP PCs, this is the small CD icon next to the time
    CeEKEY?CeEKey.exeToshiba Satellite E-Key related. Is it required?
    CeEPOWERUcepmtray.exeToshiba\'s Power Management Utility - allows the user to setup different profiles for both AC power and Battery Power on laptops. Contols CPU speed, Monitor Shut Off, Hard Drive Shut-Off, Monitor Brightness, System Stand-by and System Hibernate times
    Ceic?Ceic.exe??
    CekirgeX(path to worm)Added by the KERGEZ.A VIRUS!
    centerX[random name]32.exeAdded by the W32.BOFRA.A WORM!
    CentralProcessorXtaskimgr.exeAdded by the BANCOS.J VIRUS!
    CEPA?wsot.exe??
    cesmain.dllXcmail.dll, Rundll32CnsMin (Chinese_Keywords) related
    CEventMgrXCell.exeAdded by the Troj/Bifrose-AK TROJAN!
    CFDNCFD.exeBroadJump Client Foundation. Broadband troubleshooting software installed by various companies. Not required and you can remove it via Add/Remove programs
    CFDStartXWinMuschi.exeWINMUSCHI dialler
    cfgboostXcfgboot.exeAdded by an unidentified WORM or TROJAN!
    cfgintprYcfgintpr.exeConfiguration Interpreter - part of Tiny Personal Firewall V4
    cfgmgr51XRunDLL32.EXE [path] cfgmgr51.dll,DllRun BookedSpace adware variant
    cfgmgr52XRunDLL32.EXE [path] cfgmgr52.dll,DllRun BookedSpace adware variant
    cfgwizNcfgwiz.exeIntroduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
    cFosDNT?cFosDNT.execFos DSL Modem driver related. What does it do and is it required?
    cFosInst_Check?cfosinst.execFos DSL Modem driver related. What does it do and is it required?
    cFosSpeedUcFosSpeed.exe cFos_Software Internet acceleration program related. Note: May be necessary for the software to work properly.
    cftmon32Xtaskmgr#.exeAdded by the SOWSAT.C and SOWSAT.J VIRUSES! where # is a number greater than or equal to zero
    cfyXcfy.exeSurfenhance.com SearchForIt adware variant
    CGServerUcgserver.exeAssociated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs
    Cgtask ServicesXcgtask.exeAdded by the LALA.B VIRUS!
    CgywinXcgywin32.exeAdded by the W32/Rbot-AEI Worm!
    ChamClockUChamClock.exeChameleon Clock - system tray clock replacement
    change-me-nowXmsgfix1.exeAdded by the SDBOT.ZD WORM!
    ChangeICONUSPMSMON.EXECard reader related program. Note: May cause problems with My Computer loading at startup. Disabling through MsConfig seems to solve the problem.
    ChangeLines?chngline.exe??
    ChatangoNChatango.exe Chatango "allows people to be connected in real time through their Web browsers. Include your Chatango contact link or button when you create eBay auctions, blogs, personal websites, Friendster profiles, and your visitors will be able to contact you instantly, without downloading anything, or registering. Alo use it to send email to your friends, allowing them to respond to you in real time!." The 'MessageCatcher' icon in the System Tray notifies you when you get a message. When you get a message, a little alert pops up, which you can click on and start chatting immediately.
    ChcenterNchcenter.exeIMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"
    che32Xche.ocx.vbsAdded by the WM97/Adenu-B VIRUS!
    CheatleXGigaByte.exeAdded by the SHODI.B VIRUS!
    Check for One Touch UpdateNwiseupdt.exeChecks for updates for Visioneer OneTouch scanners
    Check for TWS UpdatesNWiseUpdt.exeInteractive Brokers - check for update to their standalone Java-based trading platform
    Check MessengerUcmesseng.exeCheck Messenger from Qchex.com - program that helps you manage the activity of your Qchex account
    CheckCustomWorksUpdateNCheckCWupdate.exeUpdate checker, part of CustomWorks - "customize any embroidery designs to design your own unique creations"
    CheckdiskXmscas.exeAdded by the Troj/Vagon-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    CheckdiskXmscas.exeAdded by the W32/VAGON.A-TR downloader TROJAN!
    CheckItUToolBox.exeCheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify
    CheckIt 86UCheckIt86.exe CheckIt_86 popup blocker
    CheckMsgPlusYMsgPlusH.dll, VerifyInstallationAdded by MSN Messenger Plus, a third party extension to MSN Messenger. This is the auto-update feature - see here for more info.
    checkrunXelite***32.exe (* = random char) EliteBar adware
    checkrunXelitelsj32.exeAdded by the Troj/Multidr-ER TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    CheckScan32Xregload16.exeAdded by the AEBOT.K WORM!
    checktime?ct.exeFound in the \HPSelect\Frontend\ directory on a HP machine. What is it's purpose and is it required?
    CheckVCRYIOMagic.exeDriver for the I/OMagic Personal Video Recorder (DR-PCTV100)
    CherryKeyManUKeyMan.exeMultimedia keyboard manager for the Cherry keyboard series. Only required if you use any of the special keys
    china11msnXCHINA11MSN.EXEAdded by the W32.ENVID.O WORM!
    ChineseStarUcstar.exeChinese language support software
    CHIPDRIVEPinManagerUsokscmpn.exe ChipDrive Smartcard software
    CHIPDRIVESmartcardManagerUSCMgr.exe ChipDrive Smartcard software
    CHKADMINNCHKADMIN.EXECompaq Network Management System. When running, it places an icon in the system tray titled "Intelligent Manageability"
    chkhbciNchkhbci.exeSmart Card reader software for Omnikey readers
    ChokeXChoke.exe-blahhAdded by the CHOKE VIRUS!
    chopeXrunlli32.exeAdded by the Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    chostsvXchostsv.exeAdded by the BANPAES.C VIRUS!
    CHotKeyUmhotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
    CHotKeyUzHotkey.exeEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
    CHotKeyUMK9805.EXEEnables special keys on Chicony keyboards. Special combinations include Internet, E-mail, vol , vol-, mute, etc. Only required for extended features
    Christmas Music PlayerNTTEST6.EXE"Christmas Music Playerbrings the music of the Christmas Holiday to your desktop"
    ChromeMark?keysh.exeRelated to this. Don't know what keysh.exe does though and if it's required
    ChronitelInitTV?CHTVINIT.EXE??
    CiaBackdoorXmsldr.comAdded by a VIRUS!
    cihost.exeXcihost.exeAdded by the LINST VIRUS!
    CIJxP2PSERVERNCIJxP2PS.EXECompaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model, ie, for IJ300 x=3, for IJ700 x=7
    Cisco Systems VPN ClientUipsecdialer.exeThe Cisco VPN_Client Lets local users gain Administrator privileges on the operating system
    Cisco Systems VPN ClientUvpngui.exeSets up IPSec communications for Cisco's VPN_Client
    CISrvr ProgramNCISRVR.EXERelated to internet setup on Compaq PC's
    CissiXCissi.exeAdded by the CISSI.A VIRUS!
    CitiUCSUCitiUCS.exeCitibank Virtual_Account_Numbers
    CitiVANNCitiVAN.exeOption from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again
    CJETXCJet.exeAdded by the Adware.FFToolBar adware toolbar.
    CjstcomYCjstcom.exeCanon printer BJ status language monitor
    ClamWinYClamTray.exe ClamWin antivirus
    ClassesXintl.exe "Switch" adult content dialler
    ClassesXrun_21.exe "Switch" adult content dialler
    ClassesXint1.exe "Switch" adult content dialler
    ClassesXsrv.exe "Switch" adult content dialler
    ClassesXsrv2.exe "Switch" adult content dialler
    ClassesXmstart.exe "Switch" adult content dialer
    ClassesXMSTAR2.EXE "Switch" adult content dialer
    CLBOOT32UCLBOOT32.EXE PC-Duo_Remote_Control from Vector. "System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!". For tech support users to provide remote assistance
    CLCLSetUCLCL.exeCLCL clipboard caching utility
    CleanEasyImg?cleanall.exe??
    CleanRegPath?CleanReg.exeApparently Annex A ADSL modem related - what does it do and is it required?
    CleanSweep Smart Sweep- Internet SweepUCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
    CleanSweep Useage WatchNCSUSEM32.EXEQuarterdeck/Norton CleanSweep component - tracks how often you use files and alerts you to files that have not been used for a specified period of time
    CleanTempUCLEANT~1.EXEBCleanTemp.exeCleanTemp - deletes the contents of the TEMP directory when Windows starts and then closes - using no memory
    CleanupNONICTASK.EXEInternet Cleanup from Aladdin Systems (used to be by OnTrack) - cleans up tracks left by browsing the internet
    CleanUpYmcappins.exeUsed by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled.
    CleanupProgram?cleanup.exeIn a C:\Sonysys folder - Sony Vaio related?
    clean_serviceXclean_service.cmdAdded by the W32.Refaz WORM!
    clfmon.exeXclfmon.exeAdded by the TROJ/AGENT-BJ TROJAN!
    Click Radio TunerNclickr~1.exeClickRadio - subscription service playing radio music via the internet
    Click Tray CalendarNClickT~1.EXEClickTray Calendar - shows holidays, reminders of various anniversaries,tasks etc
    ClickMeNClickMe.exe ClickM "JOKE" program
    ClickoffUClickoff.exeClickoff automatically dismisses annoying dialog boxes
    ClickTheButtonXcsrss.exe"ClickTheButton" Downloader-MY TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    ClickTheButtonXMSCStat.exe"ClickTheButton" Downloader-MY TROJAN!
    ClickTheButtonXCTB.exe"ClickTheButton" Downloader-MY TROJAN!
    CLICONFGXCLICONFG.EXEAdded by the OPASERV.T VIRUS!
    Client Access API DaemonUcwbappcd.exeIBM iSeries Client Access, see here
    Client Access Check VersionNcwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
    Client Access Express Welcome?cwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
    Client Access Help UpdateNcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
    Client Access ServiceNCwbSvStr.ExePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
    Client Access TaskbarUcwbuitsk.exeIBM iSeries Client Access taskbar, see here
    Client AgentX(Path To random filename)Added by the Troj/PPdoor-J TROJAN!
    Client AgentXipxwping.exeAdded by the Troj/PPdoor-N TROJAN!
    Client AgentXphotes.exeAdded by the Troj/PPdoor-P TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Client agent for ARCserve?W95AGENT.EXEPart of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?
    Client for Microsoft NetworksXmsclient32.exeAdded by the W32/Sdbot-BXQ Worm!
    Client Server Runtime ProcessXcsrsss.exeAdded by the W32/SDBOT-LD WORM!
    Client Server Runtime ProcessXcsrs.exeAdded by the W32.LINKBOT.M WORM!
    Client Server Runtime ProcessXsmmss.exeBackdoor TROJAN!, possible W32/Sdbot-gen variant.
    Client UpdateXwup.exeAdded by a variant of the W32/OPANKI-A WORM!
    ClientMan1Xmscman.exeSpyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,  "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
    Clik Status MonitorNtoolsclickstat.exePart of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed
    Clipbook ServiceNClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
    ClipMate5xNClipMt5x.exeClip Mate 5.x by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
    Clipmate6NCLIPMT60.EXEClip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs
    ClipomaticNClipomatic.exeMike Lin's Clipomatic is a clipboard cache program - it remembers what was copied to the clipboard even after new data is copied, and allows you to retrieve the old data
    ClipsrvNClipsrv.exeSupports Windows XP ClipBook Viewer, which allows pages to be seen by remote ClipBooks
    ClipSrvXclipserv.exeAdded by the W32/SDBOT-AAV and W32/Sdbot-AFE WORM!
    ClipTrakUClipTrak.exeClipTrak clipboard extender
    ClipTrakkerNClipTrakker.exeCliptrakker - clipboard extender
    CLMFrontPanelUclmpanel.exeSystem tray status/display/configuration utility for a number of modems. Can be disabled by right-clicking on the tray icon. If disabled, connection status is lost
    clnwall?rundll.exe setupx.dll, InstallHinfSection ..delwall.inf??
    clockX(various file names) LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe
    ClockSyncXSync.exeClockSynck - synchronizes your system clock with an internet time server. It's by WhenU, the makers of the Save Now spyware, and they're usually seen in tandem, so it's advised to replace it with one of may spyware free alternatives available
    ClockWiseUCLOCKWISE.EXEClockWise - produced by R J Software - a time utility. It is a schedueler not only for dates, but you can choose it to run programs at any time. It also updates the time by connecting to an atomic clock server. This is a spyware-free alternative to ClockSync
    Clock_ManagerXamsngr.exeAdded by the TROJ/SDBOT-XM TROJAN!
    CloneCD or CloneCDTrayUCloneCDTray.exeSystem tray for CloneCD - the only useful option is "Hide CDR Media" only available via this tray. Has additional unknown functions in later versions
    CloneCDElbyCDFLUElbyCheck.exeFrom Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
    Clotus or greg0?prtStart.exe Orgprt.exeLotus SmartSuite related. In a Lotus\OrgReg folder. Unclear what exactly it does?
    ClreXmmdc.exeAdded by the Troj/PurScan-AI TROJAN! Note: This trojan file is found in the Program Files\oace folder.
    ClrSchLoaderXLoader.exe Lycos/IGetNet.ClearSearch parasite
    CLSIDXsed.exeAdult content dialler
    CLSIDXmsgplus.exePremium rate adult content dialer - NOTE: this is NOT the MSN Messenger 'MessengerPlus' extension, as described here
    CLSIDXcom.exeAdult content dialler
    CLSIDXdll.exeAdult content dialler
    CLSIDXplugin.exeAdult content dialler
    CM-SmWizard?SmWizard.exeSmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
    cmaUcma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
    CMAPPXcmappclient.exeCasClient adware - also detected as Trojan.Cmapp
    CmaudioNRundll32 cmicnfg.cpl, CMICtrlWndSystem tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
    CmdXcmd32.exeAdded by the P2P.TANKED VIRUS!
    cmd32Xconfigs.exeHijacker, also detected as the QURL-2 TROJAN!
    cmdconXcmdcon.exeAdded by the CRYPTER.A TROJAN!
    CmdPrompt32.pifXCmdPrompt32.pifAdded by the W32.Assiral.B WORM!
    CMEXcme.exePart of Gator advertising spyware - see here for removal instructions
    CmeSYSXCMEsys.exePart of Gator advertising spyware - see here for removal instructions
    CmeUPDXCMEupd.exePart of Gator advertising spyware - see here for removal instructions
    CMGrdian?CMGrdian.exeOne of the McAfee shared components. What does it do and is it required?
    Cmmon32SysXcmmon32.exeAdded by the Troj/Clicker-I TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    CmPCIaudioURunDll32 CMICNFG3.CPL,CMICtrlWndRegisters the Control Panel applet for a C-Media PCI sound card
    CMPDPSRVUCMPDPSRV.EXEPrinter Driver Plus from ViewAhead Technology (formerly DeviceGuys, Inc.). "Printer Driver Plus seamlessly integrates all the necessary components of a printer driver, plus more." Installed with some Compaq and Lexmark printers
    CmpntXDevices2.exeAdded by the Troj/Tompai-D TROJAN!
    CmpntXmainsv.exeAdded by the Troj/Tompai-C TROJAN!
    cmrssXcmrss.exeAdded by the DELF.DU and Troj/Dloader-NK TROJANS!
    cmrssXcrmss.exeAdded by the DLOADER-EK TROJAN!
    cmrssX(Path of Trojan EXE)Added by the Troj/Dloader-QQ TROJAN!
    cmrssXcmrss.exeAdded by Troj/BankDl-S TROJAN!
    cmrstXcmrst.exeAdded by the PWSteal.Bancos.S TROJAN!
    cmrstXcmrst.scrAdded by the Troj/Dloader-FP TROJAN!
    cmsXiserver.exeAdded by the Troj/Dloader-WK TROJAN!
    CMSETTINGSUctmn.exePart of NetNanny Chat_Monitor
    cmsoundXvcpdll.exeAdded by the TCXMEDI-D downloader TROJAN!
    cmsoundXvcsystem.exeAdded by the TCXMEDI-D downloader TROJAN!
    cmssXsystem.exeAdded by a variant of the WIN32.RBOT WORM!
    cmssappXiexplore_.exeAdded by Troj/Bancban-CQ Trojan!
    cmssappXiexplore.exeAdded by the Troj/Bancban-GF TROJAN! Note: This is not the legitimate Windows process Iexplore.exe (Which should be found in the Program Files\Internet Explorer folder.) This worm\trojan file (iexplore.exe) is found in the Windows or Winnt folder.
    cmssSystemProcessXcsmss.exeAdded by the TROJ/AGENT-CO TROJAN!
    cmssSystemProcessXmcsmss.exeAdded by the REPSAMO TROJAN!
    cmssSystemProcessXcsms.exeAdded by the AGENT-Y TROJAN!
    CMSystemXCMSystem.exe CASClient adware variant
    CMS_UpdateXms_update.exe eBoard adware variant
    cmt101Xcmt101.exeAdded by a Crypter.C trojan variant infection
    cmx32Xcmx32.exeAdded by the W32.GEMA.D TROJAN!
    Cn323Xcnfrm33.exeAdded by the W32.MIMAIL.G WORM!
    CNBABEXCNBABE.EXEAppears to be spyware added by KAZAA (and maybe others) that displays pop-up ads whilst you\'re browsing
    cnetNkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    Cnfrm32Xcnfrm.exeAdded by the W32.MIMAIL.D WORM!
    CnsMaxXInternat.exeAdded by the POINTEX VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
    CnsMinXRundll32.exe CNSMIN.DLL, Rundll32CnsMin (Chinese_Keywords) related
    CnxAdslLYCnxAdslL.exeDLink, Zoom, or Conexant modem driver
    CnxDslTaskBarNCnxDslTb.exeConnexant DSL Taskbar as used on Acess Runner and Samsung AHT-E310 ADSL modems
    Codename DashboardUdashboard.exeCodename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"
    Coldlife -icmpXSystray.exeAdded by the IRC/FLOOD.AV TROJAN! Note - this is not the legitimate systray.exe process
    colorealUcoloreal.exeMakes colours sharper and brighter, but will only work with coloreal capable monitors
    Colorific Control PanelNHgcctl95.exeFrom E_Color. Colorific delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor
    COM ServiceXmscom32.comAdded by the BEASTY.H VIRUS!
    COM ServiceXmsynvr.comAdded by the BEASTY.G VIRUS!
    COM ServiceXmsjclh.comAdded by the PLUX VIRUS!
    COM ServiceXmsdrce.comBEASTY.I trojan
    COM ServiceXmsflyx.comAdded by the Troj/BeastDo-O TROJAN! Note: This trojan file is found in the msagent folder. .
    com servoce
    COM+ Event SystemXDRWTSN16.EXEAdded by a variant of the LOVGATE WORM!
    COM+ EventSystem ServicesXECSERVER.EXEAdded by a variant of the W32/SDBOT WORM!
    Com+ SysXcsrs.exeAdded by the W32/FORBOT-BT WORM!
    COM+ System ApplicationsXlsas.exeAdded by the AGOBOT.SE WORM!
    COM++ SystemXsvchost.exeAdded by a variant of the LOVGATE WORM!
    COM++ SystemXexploier.exeAdded by a variant of the LOVGATE WORM!
    COM++ SystemXsuchost.exeAdded by a variant of the LOVGATE WORM!
    COM-IPNCOMIP.EXECOM-IP Virtual Modem Driver (COM-IP Creates a Fake Serial Port that allows you to use older DOS Based Communications Programs over Telnet. Type atdt host.domain.com instead of atdt 5551212)
    ComAgentUComAgent.exeComAgent, MDaemon's instant messaging client
    combo.exeXcombo.exeAdded by the Troj/Chimo-C TROJAN!
    combop.exeXcombop.exeAdded by the Troj/Bckdr-CSJ TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. When run, this file together with its little friend combo.exe send spam from your machine.
    combop.exeXcombop.exeAdded by the Troj/Bowfeed-A TROJAN!
    Comcast NetworkXribiva.exeAdded by an IRC_TROJAN variant!
    ComcastSUPPORTXtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
    COMCFGXcomcfg.exeAdded by the TOADCOM.A VIRUS!
    comctl32Xcomctl32.exeAdware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am
    COMDRV32Usvdhost.exeOrvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/
    Comm DriverUcommh32.exeG Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!
    CommandXsystem.exeAdded by the GATECRASH.A or GATECRASH.B VIRUSES!
    CommandXGotit.exeAdded by the TITOG VIRUS!
    COMMANDXcommand.exeAdded by the QQPASS.E VIRUS!
    commandXjavaw.exeAdded by the W32/Agobot-LG WORM!
    command32Xcommand32.exeAdded by the Troj/LineaDl-A TROJAN!
    CommCtrNcommctr.exe"Net2Phone CommCenter is the latest in Internet voice technology allowing you to place calls easily all over the world right from your PC!". Available via Start -> Programs
    Compaq AlerterUCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information
    Compaq Computer Corp SCCenter ModuleNSCCENTER.EXEFor Compaq PC's. Part of Backweb
    Compaq Computer Security?Rundll32.exe SECURE32.CPL, Service??
    Compaq DMINcpqdmi.exeCompaq version of the Desktop Management Interface
    Compaq DriversXF1rewalls.exeAdded by the W32/SDBOT-WD WORM!
    Compaq Internet SetupNinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
    Compaq Jes DriversXwinjes.exeAdded by the W32/SDBOT-XR WORM!
    Compaq Knowledge CenterUsilent.exe & matcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file while silent.exe executes matcli.exe quietly in the background. Compaq Knowledge Center is required to run with the Help and Support program. If you uncheck Compaq Knowledge Center and and then run help and Support it will add another Compaq Knowledge Center in the startup menu. If you remove the Compaq Knowledge Center in the add/remove program some help menus in help and support will not be available like Fix my Presario, Preference, and Contact Technical Support". You decide
    Compaq Message ServerNCOMPAQ-RBA.EXEApplies to CPQBootPerfDB below as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans, but fairly harmless. They send information on the "Compaq Advisor/Compaq Message Screener" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the "advanced" tab. Not required and can cause problems
    Compaq PK DaemonUcpqkl.exeFor Compaq laptops for programming user configurable keys. Not required unless you use them
    Compaq Print FaxXcpqa1000.exeAdded by the W32/SDBOT-WL WORM!
    Compaq Service DriversXsysteminfos.exeAdded by the W32/SDBOT-XC WORM!
    Compaq Service DriversXmsnsvc.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXnavapqwa.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXcompq.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXwincmd.exeAdded by the RBOT.ATV WORM!
    Compaq Service DriversXmsnt.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXwind32.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXwinmsn.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXNtKernelSystem.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXamsn.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXcompqs.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DriversXntdat32.exeAdded by the W32/Sdbot-CNW WORM!
    Compaq Service Drivers 32Xcompq32.exeAdded by a variant of the W32/SDBOT WORM!
    Compaq Service DrivrsXcopq.exeAdded by a variant of the WIN32.RBOT WORM!
    Compaq Sound Drivers For WINDOWSXsounddr.exeAdded by the W32/SDBOT-XG WORM!
    Compaq Video CD WatcherN??For Compaq PC's. MPEG viewer
    Compaq32 Service DriversXms32.exeAdded by the SDBOT.BWH WORM!
    Compaq32 Service DriversXmsconfig32.exeAdded by the W32/SDBOT-ADC WORM!
    Compaq32 Service DriversXmsnt32.exeAdded by a variant of the WIN32.RBOT WORM!
    CompaqHW Comp ManagerNcpqhcm.exe Compaq_Intelligent_Managability agent; "a solution that simplifies inventory management by automating the collection of hardware asset data for Compaq servers running in a NetWare environment".
    CompaqPrinTrayNprintray.exePuts printer icon in the System Tray. When this option is disabled you will no longer be able to access the Control Program or Printer Driver directly from your desktop
    Compaqs Service DriversXcompqs.exeAdded by a variant of the W32/SDBOT WORM!
    CompaqSystrayNcpqpscp.exeCompaq System Tray icon
    Compatibility Service ProcessXregsvs.exeAdded by the GAOBOT.YN WORM!
    Compd Service DrivrsXcodq.exeAdded by a variant of the W32/SDBOT WORM!
    Computing Technologie FirewallXlsauth.exeAdded by the W32/SDBOT-WX WORM!
    COMSMDEXENcomsmd.exe3Com tray icon
    ComTry Web SearcherXwstray.exeComtry MP3 Downloader related - spyware
    comxtXcomxt.exeAdded by a Comxt trojan infection
    ConfigXservice.exeAdded by the ISRAZ.B VIRUS!
    Config LoadationXiEEexplore.exeAdded by the SDBOT.H WORM!
    Config LoadatiorinXI3Explorer.exeAdded by the SDBOT.H WORM!
    Config LoaderXsvchosl.exeAdded by the GAOBOT.P WORM!
    Config LoaderXsysldr32.exeAdded by the GAOBOT WORM!
    Config LoaderXscvhost.exeAdded by the GAOBOT.AE or GAOBOT.AO WORMS!
    Config LoaderXsvhost.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Config Loader for Microsoft WindowsXmwincfg32.exeAdded by the AGOBOT.BD WORM!
    Config Loader2Xexplores.exeAdded by the GAOBOT.BT WORM!
    Config LoadrXwinsys32.exeAdded by the AGOBOT-HN WORM!
    Config33.exeXConfig33.exeAdded by the SDBOT.T backdoor TROJAN!
    ConfiggLoaderXcart322.exeAdded by the GAOBOT.DJ WORM!
    ConfigSafeUCFGSAFE.EXE, AUTOCHK.EXEConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice
    ConfigServicesNConfig.exePart of initial setup on a Compaq PC
    configsetupXconfigsetup32.exeAdded by the W32/AGOBOT-AFP WORM!
    ConfigurationX(different file names)Added by the W32/SDBOT-ML WORM!
    ConfigurationXntsys32.exeAdded by the W32/SDBOT-LN WORM!
    configurationXapphost.exeAdded by the W32/SDBOT-VP WORM!
    Configuration DefaultXWuxat.exeAdded by the W32/SPYBOT-CA WORM!
    Configuration FileXWinset32.exeAdded by the BackDoor.Flux.101 TROJAN!
    Configuration LoadedXwupdated.exeAdded by the MOEGA or MOEGA.AG or MOEGA.AP VIRUSES!
    Configuration LoadedXlssas.exeAdded by a variant of the W32/SDBOT WORM!
    Configuration LoaderXaim95.exeAdded by the LOADCFG or SDBOT TROJANS
    Configuration LoaderXservice5.exeAdded by the GAOBOT.AF WORM!
    Configuration Loader?lfass.exe??
    Configuration LoaderXsycfg34.exeAdded by the GAOBOT.AN WORM!
    Configuration LoaderXwincrt32.exeAdded by the GAOBOT.BF WORM!
    Configuration LoaderXwindex.exeAdded by the GAOBOT.BM WORM!
    Configuration LoaderXwindex.exeAdded by the GAOBOT.BZ WORM!
    Configuration LoaderXdosrun32.exeAdded by the GAOBOT.AO WORM!
    Configuration LoaderXService.exeAdded by the GAOBOT.AO WORM!
    Configuration LoaderXServicess.exeAdded by the GAOBOT.AO WORM!
    Configuration LoaderXsw32.exeAdded by the AGOBOT.BQ WORM!
    Configuration LoaderXSystem.exeAdded by the GAOBOT.AO WORM!
    Configuration LoaderXWinreg.exeAdded by the GAOBOT.AO WORM!
    Configuration LoaderXsysinfo.exeAdded by the GAOBOT.FQ WORM!
    Configuration LoaderXmicrosoft.exeAdded by the GAOBOT.JB WORM!
    Configuration LoaderXconfgldr.exeAdded by the POLYBOT VIRUS!
    configuration loaderXwinicfg32.exeAdded by the GAOBOT.GEN!POLY WORM!
    Configuration LoaderXsvhst.exeAdded by the GAOBOT.YC WORM!
    Configuration LoaderXsyscfg32.exeAdded by the SDBOT.B WORM!
    Configuration LoaderXmsgcfgsrv.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Configuration LoaderXmsnss.exeGAOBOT.AUS worm
    Configuration LoaderXmsgfix.exeAdded by the W32/SDBOT-QG and W32/Sdbot-BTE WORMS!
    Configuration LoaderXsystemry.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Configuration LoaderXccSort.exeAdded by the AGOBOT.SR WORM!
    Configuration LoaderXwincffg.exeAdded by the AGOBOT.A3 WORM!
    Configuration LoaderXsmss32.exeAdded by the AGOBOT.MB WORM!
    Configuration LoaderXcmd32.exeAdded by the LOADCFG or SDBOT TROJAN!. Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "iexplore.exe" (IE) resides in C:\Program Files
    Configuration LoaderXIEXPL0RE.EXEAdded by the LOADCFG or SDBOT TROJAN!. Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "iexplore.exe" (IE) resides in C:\Program Files
    Configuration LoaderXMSTasks.exeAdded by the LOADCFG or SDBOT TROJAN!. Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "iexplore.exe" (IE) resides in C:\Program Files
    Configuration LoaderXseru32.exeAdded by the W32/SDBOT-VR WORM!
    Configuration LoaderXbotss.exeAdded by the W32/SDBOT-XS WORM!
    Configuration LoaderXldasp.exeAdded by the AGOBOT.BH WORM!
    Configuration LoaderXsmsai.exeAdded by the W32/SDBOT-YE WORM!
    Configuration LoaderXsvupdate.exeAdded by the W32.RANDEX.DXP WORM!
    Configuration LoaderXsvchost2.exeAdded by the AGOBOT.JR WORM!
    Configuration LoaderXcrcss.exeAdded by the AGOBOT.ADG WORM!
    Configuration LoaderXscvhost.exeAdded by the W32/AGOBOT-AAE and Backdoor.Sdbot.AR WORMS!
    Configuration LoaderXsvchost.exeAdded by the W32/ParaDrop-A WORM!
    Configuration LoaderXlexplore.exeAdded by the W32/RBOT-AGX WORM!
    Configuration LoaderXdezi.exeAdded by the W32/SDBOT-OB WORM!
    Configuration LoaderXWinHelper.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Configuration LoaderXmouse.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Configuration LoaderXmsg.exeAdded by the SDBOT.BT WORM!
    Configuration LoaderXextrac.exeAdded by the W32/Sdbot-AFP WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Configuration Loader ServiceXWinsys32.exeAdded by the W32/RBOT-YV WORM!
    Configuration Loader ServiceXdevl32.exeAdded by the W32/SDBOT-XY WORM!
    Configuration Loader ServiceXwinsys32.exeAdded by the W32/RBOT-YV WORM!
    Configuration Loader10Xip7.exeAdded by the W32/AGOBOT-ANZ WORM!
    Configuration LoadingXsvchos1.exeAdded by the GAOBOT.DK WORM!
    Configuration LoadingXconfigldr.exeAdded by the AGOBOT-EC WORM!
    Configuration Loading ServiceXwscel.exeAdded by the W32/SDBOT-WJ WORM!
    Configuration ManagerXCNFGLD32.EXE, Cnfgldr.exeAdded by the SDBOT WORM!
    Configuration ServiceXsuchost.exeAdded by the Troj/Daemoni-R TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Configuration ServicesXmswords.exeAdded by the W32/SDBOT-YM WORM!
    Configuration UtilityNCONFIG.EXEControls linksys wireless connection. Available from the Desktop
    Configuration UtilityUwlanutil.exeNetGear Wireless LAN configuration utility for the MA311 802.11b (and maybe other cards)
    Configuration WizardNCfgwiz32.exeAdded by a variation of the HACKTACK VIRUS! Not to be confused with the valid MS "ISDN Configuration Wizard" (Cfgwiz32.exe) in C:\Windows\System
    Configuration32 Loader32Xwinamp32.exeAdded by the W32/Sdbot-BIC WORM!
    ConfLoaderXsysconf16.exeAdded by the TROJ/SDBOT-FB TROJAN!
    ConmgrNconmgr.exeStarts Winfax pro at startup
    ConMgr.exeUconmgr.exeConnection Manager as used by Earthlink and others. If you need this to ensure a proper connection but don't want to connect at startup try creating your own shortcut 
    Connect2PartyXconnect2party.exeAdult content dialler
    Connection ManagerNCManager.exeSBC Yahoo DSL service connection manager. You can connect from the network connections. Users having problems with this have been advised to uninstall the connection manager via Add/Remove Programs and it won't affect the service
    Connectivity ToolX(Path to Trojan file)Added by the Troj/Litebot-E TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    ConnectorXSYS.EXEAdded by the Dialer.Nunci premium dialer.
    ConnectorXsms.EXEAdded by the Dial/ExDial-B Dialer! Note: Dial/ExDial-B is a premium rate porn dialer.
    ConsXconsol32.exeHijacker - redirects to a p0rn portal, where foistware like ISTBar gets stealth installed
    conscorrXconscorr.exe Transponder parasite updater/installer
    Console de Gerenciamento MicrosoftXcsrss.exeAdded by the Troj/Bancban-ET TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Contacte?contacte.exeSome kind of driver?
    ContentDownloadXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    ContentServiceXwinservn.exeHomepage hijacker
    ContinueInstallXbpsinstall.exeBrowserAid parasite
    ControlXrundll32.exe ctrlpan.dll, Restore ControlPanel CoolWebSearch parasite related
    Control handlerX***********.exe (* = random char) CoolWebSearch parasite variant
    Control handlerXahjinst.exe CoolWebSearch parasite variant
    control panelNsmctrlw.exeSystem Tray icon for a Silicon Motion LynxEM based PCI Graphics Card
    Control PanelXSystem.exeAdded by the DANI VIRUS!
    ControladoresX(path to Trojan)Added by the Troj/Telefo-A Trojan!
    ControlCenter2.0Nbrctrcen.exeBrother scanner 'Control Center' application; can be started manually
    ControlCentreTrayNXWCTray.exeSystem Tray access for the Xerox ControlCentre 2.0 software for their range of printers, copiers, faxes, etc
    Controlled Resource System ServiceXcrss.exeAdded by a variant of the AGOBOT.GEN WORM! **Note - this is NOT the legitimate crss.exe process, which should NOT figure in Msconfig/Startup!
    ControllerNWFXCTL32.EXEFrom Symantec's TalkWorks Pro and WinFax. Appears if you chose to have the program appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
    ControlPanelXrundll32 internat.dll, LoadKeyboardProfile, [path] twink64.exe internat.dll,LoadKeyboardProfile CoolWebSearch parasite related
    ControlPanelXhost32.exe internat.dll,LoadKeyboardProfileAdded by a DELF.DW Downloader TROJAN variant!
    ControlPanelX[path] cmd32.exe internat.dll,LoadKeyboardProfileAwmcash.biz foistware
    ControlPanelXsystemctrl.exe internet.dll,LoadNetworkProfileBrowser hijacker, also detected as TROJ/STARTPA-FX
    ControlPanelXpopcorn72.exe rundll.dll,LoadMouseProfileAdded by the TROJ/DLOADER-RA TROJAN!
    ControlPanelXinternat.dll,LoadKeyboardProfileAdded by the Troj/Bizves-A TROJAN!
    ControlPanelXpopcorn64.exe rundll.dll,LoadMouseProfileAdded by the Troj/Dloader-OI TROJAN!
    ControlPanelXpopcorn.exe internat.dll,LoadKeyboardProfileAdded by the Troj/Bizves-B Trojan!
    ControlPanelXsvcc.exe WorldSearch adware
    ControlPanelXpopcorn320.exe rundll.dll,LoadMouseProfileAdded by a variant of the TROJ/DLOADER-RA TROJAN!
    ControlServiceMgrXcsmsv.exeAdded by the TROJ/AGENT-XC TROJAN!
    Cookie Cop 2UCookieCop.exeCookie Cop 2 from PC Magazine - cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    Cookie PalUCPBRWTCH.EXEKookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    CookieJarUCookiejar.exeCookie Jar cookie manager from Jason's Toolbox. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    CookiePatrolUCookiePatrol.exeCookiePatrol - PestPatrol's cookie interceptor stopping spyware cookies
    CookieWallUcookie.exeCookieWall from Analog X. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    Cool DeskUcdesk.exeCool Desk is a virtual desktops manager. "Ever you wished to have several screens on your computer? Cool Desk creates up to 9 virtual desktops and offers you to have different windows on each of them". Not required but may be of use to you
    CoolDownloadsXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    CoolMP3Xrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    CoolSwitchUtaskswitch.exeALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
    CoolwallpaperNcwm_tray.exe Cool_Wallpaper software allows you to manage high quality photos as desktop wallpaper and screen savers
    coolwebprogramXclrssn.exe CoolWebSearch parasite related
    Copernic Desktop SearchUCopernicDesktopSearch.exeCopernic Desktop_Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures."
    CopernicPerUserTaskMgrUCopernicPerUserTaskMgr.exeAutomatic tasking feature of Copernic Pro multi-search engine tool
    Copy handlerUCopy Handler.exe Copy_Handler lets you copy between hard disks, floppies, local networks, CDs, and many other storage media. Copy Handler gives you the power to pause, resume, restart, and cancel during the copying and moving processes.
    CopyrightNmwcpyrt.exeDisplays copyright information on IBM ThinkPads
    Corel Colleagues & Contacts RemindersNcffrem.exeCorel Colleagues & Contracts - all-in-one organizer for scheduling meetings, maintaining addresses, etc. Part of Corel Print Office
    Corel Desktop Application DirectorNdadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
    Corel Family & Friends remindersNCFFREM.EXECorel Family & Friends - all-in-one calender, address book and list manager. Part of Corel Print House Magic
    Corel Registration or Corel Registration RemiNRemind32.exeIf you don\'t want to register Corel products and be reminded about it every 2 weeks disable it
    Corel ReminderNNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
    CorelCENTRAL 10NI_26dadCC.exeCorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
    CorelDraw ToolboxXCorelDraw.exeAdded by the W32/SDBOT-VZ WORM!
    CorelMedia FoldersIndexer8NMFindexer.exe MFINDE~1.EXEPart of CorelDraw bundles for indexing media files - similar to "fast find" in MS Office
    CoreSrvXcoresrv.exeSome IRC trojans/worms use this - see here for more information
    CORESYS?coresys.exe??
    CorrectConnectNCConnect.exeBroadband ISP diagnostic tool - as used by NTL and Cox Communications. Shortcut available
    cosineXcosine.exeAdded by the W32/RBOT-SW WORM!
    CostAwareUniIPCApp.exeNetInternals CostAware - download quota measuring tool
    CountrySelection or Country SelectNpctptt.exeCountry selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you\'ve set the modem up to the chosen country it\'s not required
    Coupon Offers?????
    couponicaXcouponica.exeAdware - see here
    CP?CopyProtectionNotifier.exeRelated to Emuzed Systems and Middleware. Comes included with Windows XP Media Edition
    CP32NOTUCP32BTN.EXEFor the programmable "one-touch" buttons on HP laptops (and others?). Safe to disable if you don't use these buttons
    CP4HPOTUOneTouch.EXEOne Touch keyboard driver. Required if you use the additional keys
    CPA9P2PSERVER?CPA9P2PS.exeFound on a Compaq Presario but what is it?
    CPATR10UCPATR10.EXEDritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba, Compaq) to translate special hotkeys such as Play/Pause and Constrast
    CPBrWtchUCPBrWtch.exeKookaburra Softwares Cookie Pal cookie manager. Allows you to decide which internet sites can add "cookies" related to their sites for the next time you return
    CPD_EXEYCPD.EXEFirewall bundled with McAfee VirusScan 6.*
    cplXdeamon.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    cplXmsgaol.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    cplXs_menu.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    CplBTQ00NCplBTQ00.EXERelated to the EZbutton quick launcher
    CPLDBL10NCPLDBL10.exeRelated to the EZbutton quick launcher
    cpntmgcXwincomp.exe, winmgts.exeRemote-control trojan from Electronic Group - see here
    cpntmgcXsimcss.exe, navpmc.exeMagicControl downloader trojan variant
    CPortPatch?cppatch.exeCPortPatch is a utility is required for Dell laptops that are using a docking station. Is it needed though?
    CPQAcDcYCPQAcDc.exeCompaq PowerCon power management software for laptops
    CPQAlertUCPQAlert.exeCompaq's Insight Manager Agent - a tool that allows for "fault, performance, and configuration management". Recommended for corporate users only. It's best removed if installed but not wanted, rather than disabled at startup. See here for more information
    CPQBootPerfDBNCPQBootPerfDB.EXESee the entry for Compaq Message Server
    CPQCalibYCPQCalib.exeCompaq PowerCon power management software for laptops
    CPQDFWAGNCpqDfwAg.exeFor Compaq PC's. Runs Compaq diagnostics on every boot
    CPQEASYACCUcpqeadm.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    CPQEASYACCUStartEAK.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    cpqeauiUcpqeaui.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    cpqekUkcpqek.exeFor Compaq PC's. Easy Access button support for the keyboard
    CPQHotkeysXhotkeysvc.exeAdded by the W32.Kelvir.A or W32.Kelvir.B WORM!
    CPQInet Runtime ServiceUCpqInet.exeFor Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers
    CPQINKAGENTNcpqinkag.exeThat is the Compaq Ink Agent for some inkjet printers, it lets users know when their ink cartridges are getting close to empty (by how many pages they have printed)
    cpqnsUcpqnpcss.exeRelated to Compaq.Net - not required if you don't use that
    CpqsetNCpqset.exeDefault settings software in Hewlett Packard notebook
    CPQSTUTFIXYstutfix.exeFor Compaq PC's. Fixes audio stutter problems for ESS Maestro soundcards. You can download it here. This is a Compaq originated file and has been verified as free from viruses by McAfree/Norton
    cprXcprAdroar.com adware downloader
    CPU ManagerXcpumgr.exeAdded by the PANDEM.B VIRUS!
    CPU Temp ControlXwuitgurd.exeAdded by the W32/RBOT-AHV WORM!
    CPU WatcherXrundll32.exe [path] cpu.dll,loadAdded by the TROJ/DLOADER-LO TROJAN!
    CPU Windows StatusXcpustats.exeAdded by a variant of the WIN32.RBOT WORM!
    CPUcoolUCpucool.exeProgram to keep the processor cool when idle in "overclocked" systems. Also available via Start -> Settings -> Control Panel
    CpusaveXCpusave.exeAdded by the GEMA TROJAN!
    Cpusave32XCpusave32.exeAdded by the GEMA TROJAN!
    cpytXhidep.exeAdded by the Troj/Mirjack-A Trojan!
    cqlygXworld_cup_.batAdded by the WCUP VIRUS!
    CQSCP2P SERVER???"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed
    Cr**.exe (* = random char)XCr**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Cr**32.exe (* = random char)XCr**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    cracked_windows1Ucracked_windows1.exeCracked Windows popup killer
    CrazyTalk ServeNrundll32.exe CrazyTalk.dll, DIIServeMediaFileCrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph, complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS
    CRC Value VerifierXcrsss32.exeAdded by a variant of the WIN32.RBOT WORM!
    CRC Value VerifierXCrsss64.exeAdded by the W32/Rbot-NY WORM!
    CRC Value VerifierXsvchost32.exeAdded by the W32/RBOT-OA WORM!
    CRC Value VerifierXcrsss.exeAdded by the SPYBOT.UK WORM!
    Crc32stats DependenciesXCrc32stats.exeAdded by the W32.MYTOB.GT WORM!
    Creata MailUJMSrvr.exe Creata_Mail . Smileys, stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express.
    Create A MonsterXcreateAMonster.exeKudd.com CreateAMonster. Reportedly stealth installed and Look2Me adware related
    CreateCDNCreatecd.exeAdaptec Easy CD Creator system tray application (pre version 5). Available via Start -> Programs
    CreateCD50NCreatecd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
    Creative AGP WizardNagpwiz.exePart of Creative's BlasterControl
    Creative LauncherNCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
    Creative MediaSource GoNCTCMSGo.exe"Creative MediaSource playbacks music in DVD-Audio, MP3, WMA, WAV and other media formats"
    Creative PCI Audio Configuration UtilityNstarter.exeSystem Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer
    Creative Service for CDROM AccessNCtsvccda.exeResident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
    Creative WebCam TrayNCamtray.exeCreative WebCam tray control; can be started manually.
    Creative.exeXCreative.exeAdded by the PROLIN VIRUS!
    CreativeDiscNotifierNCTNOTIFY.EXEFor Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM, DVD-ROM, etc. Available via Start -> Settings -> Control Panel
    CreativeMixerUCTMIX32.EXECreative soundcard System Tray access to, for example, volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon
    Critical Update CheckXbattlenet.exeAdded by the Troj/Delf-LB TROJAN!
    CriticalUpdateNWucrtupd.exeMS Windows Critical Update Notification. If you want to keep Windows up-to-date, check the Windows Update site
    CriticalUpdateXwucrtupd.exeAdded by the W32/NOALA.B WORM! - NOTE: this file is located in the Windows or Winnt folder, and must not be confused with the legitimate Windows process of the same name as described here
    CrnsavaXscrnsave.pifAdded by the W32/Sdbot-ZV WORM!
    cronosXMARCO!.SCRAdded by the OPASERV.G VIRUS!
    CrossMenuUCrossMenuToshiba CrossMenu Utility - allows the user to create their own menus
    crsXcrs.exeAdded by the W32/Agobot-TJ WORM! Note: This worm\trojan file is found in the Root folder. Example: ( C:\ )
    CrustyXdmcpl.exeAdded as the result of the RUSTY VIRUS!
    cryptdlgXcryptdlg.exeAdded by an unidentified TROJAN!
    Cryptographic ServiceX******.exe (* = random char)Win32.Korgo.AB worm
    Crystal 3D Audio Control?CWD3DSND.EXECrystal 3D Audio sound driver. Is it required?
    csaRemNspqmdmui.exeCompaq modem country selection
    CSAV_CheckVirusesYvchk.exePart of Command AntiVirus
    csc?csc.exe??
    CSCRS ValueXcscrs.exeAdded by the W32/RBOT-AAA WORM!
    CSCRS Value CheckXMsPMSPSd.exeAdded by a variant of the W32/SDBOT WORM!
    CSINJECT.EXEUCSINJECT.EXEPart of Quarterdeck/Norton CleanSweep. For a full description see here. An excerpt - "Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes."
    csm Win UpdatesXcsm.exeAdded by the W32/ZOTOB.B WORM!
    csoftokXsoftok.exeAdded by the TROJAN.PWS.QQPASS.G TROJAN!
    csrscXcsrsc.exeAdded by an unidentified VIRUS!
    csrse.exeXcsrse.exeAdded by the Backdoor.Hesive TROJAN! Note: This trojan file is found in the Windows\temp or Winnt\temp folder.
    CSRSSXCSRSS.EXESearch page hijacker, redirecting to http://www.search-aide.com/. Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling
    CsrssXcsrss.exeAdded by the W32.Chod WORM! Note - This will be installed in a random folder and is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    CsrssXcsrss.exeAdded by the W32.CHOD.B WORM! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!
    csrssUcsrss.exeAdded by the Spyware.BeyondKeylog surveillance software. Uninstall this software unless you put it there yourself. - NOTE - this file is placed in the Program Files\Supremtec folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    csrssXcsrss.exeAdded by W32/Chode-J WORM! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    csrssXnwiz.exe /installquietAdded by W32/Chode-J WORM!
    csrssXmsmsgs.exeAdded by W32/Chode-J WORM!
    csrssXcsrss.exeAdded by the Troj/Keylog-AQ KEYLOGGER! NOTE - This file is placed in the Windows (95/98/ME/XP) or WINNT (NT/2000) directory and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process always located in the Winnt\System32 or Windows\System32 folder.
    CSRSS LoaderXcsrsss.exeAdded by the AGOBOT.TX WORM!
    csrssLevel4Xcsrss.exeUnidentified malware - NOTE - this file is placed in a C:\Windows\System\Level4 folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    CSRSSUXCSRSSU.exe CoolWebSearch parasite related - hijacking to Slawsearch.com. Also see here
    CSRSSWXCSRSSW.EXEAdded by the TROJ/CWS-F TROJAN!
    CSRSWINX(trojan filename)Added by the WINSHELL.50 VIRUS!
    CSRSXX(trojan filename)Added by the WINSHELL.50.B VIRUS!
    CSS ServerUCSSServer.exeAdded by the ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself.
    CSScheduleCheckYSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
    cssrsXcssrs.exeAdded by the Troj/Bancban-DW TROJAN!
    csssXCsss.exeAdded by the BALICK VIRUS!
    CSS_CentralUCSS_1631.EXECSS Communication Agent (95 Host) from Command Software Systems"CSS Central™ provides administrators with a powerfully proactive tool to effectively manage and maintain the anti-virus strategy from a centralized console."
    CSV10P70XCSv10P070.exe ClearSearch adware related
    CSV7P26XCSV7P26.exe ClearSearch adware related
    CSV7P70XCSV7P070.exe ClearSearch adware related
    CSV7P91XCSV7P91.exe ClearSearch adware related
    csvdeaUcsvdea.exeAdded by the SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself.
    ctYct.exect.exe is a file is for the HP Learning Adventure software and if you use this software it is required to run it
    CT Control SettingsXCTSVCCD.EXEAdded by the W32/RBOT-YS WORM!
    CTAVTrayNCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
    CTCMonitorUCTCMonitor.exe Click-to-Convert - document-to-HTML or doc-to-PDF converter. Only required if you are going to use the File -> Print method of using Click-to-Convert. If converting directly from MS Office, it is not required
    CTDVDDetNCTDVDDet.exe, CTDetect.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player, selecting Tools, then uncheck the Auto Start box. It should not start up automatically again
    ctflog managerXctflog.exeAdded by the DONBOMB.A TROJAN!
    CTFM0N.exeXCTFM0N.exeAdded by the STARTPAGE.P TROJAN!
    ctfmonXtaskmgr32#.exeAdded by the SOWSAT.B VIRUS! where # is a number from 0 to 9
    ctfmonXcftmon.exeAdded by the TROJ/DELIVE-A TROJAN!
    ctfmonXctfmon.exeAdded by Troj/SDBot-06 Trojan!
    ctfmonXWinConst.exeAdded by the Troj/Assasin-G Trojan!
    ctfmonXmIRC.dllAdded by the Troj/Delbot-E Trojan!
    ctfmonXctfmon.exeAdware responsible for tenmonkey.com popups - file located in the Winnt or Windows folder - NOTE: do not confuse with the MS Office file of the same name as described here |
    ctfmonXmsnmsgr.exeAdded by the Troj/Bdoor-JV TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    CTFMonUctfmon.exe Family_Keylogger is a program that lets you record to a special file and then view all the keystrokes typed by everyone using your computer. Remember if you did not put this on your computer then someone else did! This Keylogging file is found in the System\CTF (95/98/ME) or System32\CTF (NT/2000/XP) folder.
    ctfmon.exeUctfmon.exeCTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don\'t need these features. For more info on ctfmon see here;en-us;282599 . CTFMON can be disabled from Control Panel, Text & Speech Services. NOTE: The file will always be located in the System32 folder. If it is located elsewhere, it will likely be a worm or trojan!
    Ctfmon.exeXctfmon32.exeCoolWebSearch parasite related
    ctfmon.exeXctfmon.exeAdded by the PWSteal.Raidys TROJAN!
    ctfmon.exeXmsupdate32.exeSpy Sheriff/SpywareNO malware component, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
    CTFMON32XCTFMON32.EXE CoolWebSearch parasite related - also detected as the TROJ/CWS-E TROJAN!
    CTFMONSSXCTFMONSS.EXEAdded by the TROJ/CWS-F TROJAN!
    ctfnomXrundIl32.exeAdded by the Troj/LegMir-AW TROJAN! Note: This is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling). This trojan file (rundIl32.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    ctfnom.exe XSVOHOST.exeAdded by the Troj/Digidor-A or Troj/StartPa-HA TROJAN!
    ctfnom.exeXOSRSS.exeAdded by the Troj/Lewor-H TROJAN! Note: This trojan file (OSRSS.exe) is found in the Windows or Winnt folder.
    cthelpXcthelp.exeAdded by the SDBOT TROJAN!
    CTHELPERNCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
    CTHelperXcthelper.exeAdded by the W32/RBOT-XB WORM! - NOTE - do NOT confuse with the Creative application of the same name described here
    CTimeX(path to trojan) CoolWebSearch parasite related
    CTin10XCTin10.exeAdded by the BANCOS.E VIRUS!
    CTPDPSRV?CTPDPSRV.EXEPrinter driver (in the WINDOWS\System32\spool\DRIVERS\W32X86 folder). Is it required?
    CTRegRunNCTRegRun.exeFor Creative Soundblaster Live! series soundcards. Reminds you to register your card with Creative
    CtrlVolUCtrlVol.exeAcer's on screen volume control using the Fn key
    CTStartupNCTEaxSpl.exeSplash screen with sound on every boot up. Installed with a Sound Blaster Audigy soundcard
    CTsysVolUCTSYSVOL.exeCreative sound card volume controls
    cttdpsrv?cttdpsrv.exe??
    CTUpdateXctupdclt.exeAdded by the W32/RBOT-ABG WORM!
    CtykdX[path to file] TSPY_SMALL.SN spyware
    cuagentExeYCuagent.exeCommand Antivirus related
    CUCore AgentUConfAgent.exeFirst Virtual Communications, Inc., Now RADVISION Ltd Click_to_Meet videoconferencing software
    cuoXcuo.exeAdded by the BUGBEAR VIRUS!
    Current Security ConfigXcsecure.exeAdded by the W32/Rbot-AMO WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    cursorNScreendragon_VS_Taskbar.exe ScreenDragon video player
    CursorXPNCursorXP.exeCursorXP from Stardock - tool for creating mouse cursors
    CurtainsSysSvcUAuthSL.exeSecurity Manager - part of a ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private.
    Customizer2000Ulogon.exeAutomatic logon feature of Customizer 2000 - "a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows, and make changes"
    CuteMXNCuteMX.EXEFile sharing utility
    cvmonitor.exeXcvmonitor.exe WORM_SDBOT.BV
    CVPNDYcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
    CWUcw4.exe Chat_Watch "is a monitoring and logging software for online chat and instant messaging programs"
    CWatchUcw.exeChatWatch - chat monitoring tool
    cwbckverNcwbckver.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources
    cwbinhlpNcwbinhlp.exeClient Access Help Registry Update Function - part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. It only updates the help files on your PC to match the level of the attached iSeries
    cwbsvstrNcwbsvstr.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources
    cwbwlwiz?cwbwlwiz.exeWelcome wizard launcher - Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. What does it do and is it required?
    Cwcdschk.exe?Cwcdschk.exeIBM Thinkpad related?
    cwupdateUcwupdate.exeContentProtect, from ContentWatch - http://www.contentwatch.com/products/contentprotect.phpinternet filter
    CXMonNHpi_Monitor.exeAutodetects when a HP camera is attached to the computer and launches the "HP Photoimaging Software". Available via Start -> Programs
    CyberNcyberchk.exePart of Belkins "Multimedia Cleaning Kit" and is automatically installed when you run their optical disk drive cleaning utility - to remind you to clean your drive after "x" amount of time has passed
    Cyber TrioUshowmode.exeFrom G-Tek Technologies. Allows you to set the PC in one of three modes, Standard, Enhanced and Kiddo. Standard is full function, Enhanced prevents accidental damage and Kiddo is a play environment for kids. Pre-installed on some Packard Bell PCs
    Cyber-Defender 2003Uuwcdsvr.exeCyber Defender 2003
    cyberfree.exeX****.dat (* = random char)Unidentified adware
    CyberLat Ram CleanerUCLRamCleaner.exeCyberLat RAM Cleaner is a program that Frees, Optimizes and Defrags your system\'s wasted memory (RAM). Some users swear by programs such as this but I suggest you read this article and make up your own mind
    CyberMedia AgentNCMAGENT.EXEPart of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge, CyberMedia Agent may attach itself to TextBridge and cause TextBridge to crash everything if this is disabled
    CyberWolfXCyberWolf.exeAdded by the KICKIN.A (or CYDOG.C) VIRUS!
    CyDoor or CydoorUpdateXCD_Load.exeAdware. Check here for information about Cy-Door and here for a program that can remove it
    CyphTrayNCyphTray.exeCypherus - encryption software
    D SYSTEMXdd.exeAdded by the W32/Mytob-FN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    D-Link Air USB UtilityYAirCFG.exeD-Link wireless PCI adapter related
    D-Link Air UtilityYAirCFG.exeD-Link wireless PCI adapter related
    D-Link AirPlus DWL-650+ UtilityNWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
    D-Link AirPlus GYAirGCFG.exeD-Link Airplus Wireless Router driver
    D066UUtilityND066UUTY.EXETWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
    D3**.exe (* = random char)XD3**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    D3**32.exe (* = random char)XD3**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    d3dupdate.exeXbbeagle.exeAdded by the BEAGLE.A WORM!
    D4UD4.exeDimension 4 - network time synchronization software
    DACONFIGEXENdaconfig.exe3Com NIC Diagnostics. Available via Start -> Programs
    DadAppYdadapp.exe"DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell
    DaemonNDAEMON32.EXEPre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
    DaemonXdaemon.exe c daemon2.exeAdded by the W32.Selotima.A WORM!
    Daemon or DAEMON Tools-1033UDaemon.exeDaemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
    Daily PlannerNdayplan.exeDaily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them
    Daily Weather ForecastXweather.exeAdded by the DLOADER-IP TROJAN!
    DamedWare ServicesXdwdrce.exeAdded by the W32/Rbot-AOJ WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    DancerUDncLE.exePart of Microsoft Plus! Digital Media Edition - see here
    DantonX(random filename)Added by the DANTON VIRUS!
    DapNDAP.exeDownload Accelerator Plus from SpeedBit - download manager/accelerator
    darkXimgst.scrAdded by the PWSTEAL.BANCOS.U TROJAN!
    darkXimgrt.scrAdded by the Troj/Bancban-FH TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    darkXcsrs.scrAdded by TROJ/BANCBAN-GT or TROJ/BANCBAN-GU TROJAN!
    DarkDevil.Grasiele.BRXGrasiele.VBSAdded by the LEMBRA VIRUS!
    DarKNesS LsasSXLsasS23.exeAdded by an unidentified WORM or TROJAN!
    DashIE?dashIE.exe systrayCould be related to "Dash Power Shopping" tool bar in IE?
    dasxdadsXfsdqd.exeAdd by the GAOBOT.BIQ WORM!
    DataXSystem.dat.vbsAdded by the BISCUIT.A VIRUS!
    dataXmsngs.exeAdded by the W32/RBOT-ADQ WORM!
    Data LifeGuardNBACKWE~1.EXEData LifeGuard diagnostic tools for Western Digital\'s series of hard drives
    Data LifeGuard LifeLine Lite installerNDLGLI.EXEBackweb installer - see here
    Data Restore ServiceXprq8.exeAdded by the W32.Kelvir.AI WORM!
    Data789XRegedit.exe ....data789.tmpHomepage hijacker
    DATABASE MySqlX[path] repcale.exe [path] beird.exeAdded by a variant of the RANDON.AN WORM!
    DataCachingNFlashKsk.exeSmartMedia Card management from the installation of a SanDisk reader for a camera\'s SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon
    DataLayerUDataLayer.exeNokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
    DataViz Inc MessengerUDvzIncMsgr.exeInstalled with DataViz "Documents to Go" software
    DataViz MessengerNDvzMsgr.exeDataViz Documents to Go - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"
    DatcheckXdatcheck.exeAdded by the KEYPANIC VIRUS!
    Date ManagerXdatemanager.exe DateManager - calendar program. Contains Gain adware
    Datechecker?N/ACould be related to this?
    DateMakerIntlXDateMakerIntl.exePremium rate dialler also referred to as the PORNSPA.F VIRUS!
    DaudiXdaudi.exeMalware, as yet unidentified
    DAupdateXDAupdate.exeNavEnhance adware
    DAW9532.exe?DAW9532.EXELoaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required?
    DayTodayUDAYTODAY.EXEDayToday from RoboMagic Software Corp. Displays the date on the taskbar
    DAZEL Delivery AgentUDcDaemon.exeControl and send documents, etc, to any destination - see here
    dbservNdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
    DBTMONNdbtmon.exeDell button monitor for 9XX series printer most commonly associated with 922. Can safely be turned off does not hamper printer operations. Can be accessed from the start menu
    DCE ManagerXdcemgr.exeAdded by the TUMAG.A TROJAN!
    DCfssvc or dcfssveUdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can\'t load pictures from your camera/dock - Kodak\'s dock is an example
    Dcom System PatchXMicrosoft.exeAdded by the RANDEX.MS WORM!
    DDCActiveMenuUDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    DDCM or DDCManXDDCMan.exeDigital Distribution Channel from Wild Tangent - adware
    ddeprocXddeproc.exeAssociated with Webcelerator - spyware. Read eAcceleration's privacy statement here
    DDiallerXDDialler.exeAdult content dialler
    DDT?N/A??
    de32genXde32gen.exeAdded by a CRYPTER.C trojan variant infection
    DeadAIMNrundll32.exe DeadAIM.ocm, ExportedCheckODLsDeadAIM - feature enhancing product for AOL\'s Instant Messenger program
    DealHelperBrwsrXdhbrwsr.exe DealHelper adware
    DealHelperDownXdownload.exe DealHelper adware
    DealHelperUpdateXDHUpdt.exe DealHelper adware
    DebugXDebugW32.exeAdded by the GUBED VIRUS!
    DebugMonitorXdebugmonitor.exeAdded by the W32.Mydoom.BG WORM!
    DeeEnEsUDeeEnEs.exe DeeEnEs - automatically updates a dynamic IP address when it changes.
    deejayXforboo.exeAdded as result of a Forbot-AY worm infection
    DefaultXexplore.vbsAdded by the VBS.Allem WORM!
    DefaultXmtask.vbeAdded by the VBS.Allem WORM!
    defaultXshell32.exeAdded by the Backdoor.Binghe TROJAN!
    Default System ResearchXvhchost.exeAdded by the TARNO.I VIRUS!
    Default web browserXIexpIore.exeAdded by the OBLIVION.B VIRUS! Note - don not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L"
    Default_Page_URLXhttp://find.naupoint.com Naupoint browser hijacker
    Default_Search_URLXhttp://find.naupoint.com Naupoint browser hijacker
    defragm_checkXdefragment.exe CoolWebSearch parasite related
    defwatchUdefwatch.exeDetects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
    Delay or DelayrunUdelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computers
    Delete MeXworm.exeAdded as the result of the DOOMHUNTER VIRUS!
    Dell AIO Printer A*** (*** = model)Ndlbabmgr.exe Dell AIO Printer A940 related. Not Required at Startup
    Dell AIO Printer A920?dlbkbmgr.exeButton manager for the Dell AIO Printer A920?
    Dell AIO Printer A960?dlbfbmgr.exeDell A960 All-In-One Printer related - what does it do and is it required?
    Dell AlertNDAMon.exe"Dell Alert" utility, that's supposed to make interaction with Support easier
    Dell Photo AIO Printer 922?dlbtbmgr.exeDell Photo AIO Printer related - what does it do and is it required?
    Dell Photo AIO Printer 962?dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor - is it required?
    Dell QuickSetNquickset.exeell taskbar icon allowing you to quickly change settings
    DellDMI?delldmi.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?
    DELLMMKB or DellTouchUDELLMMKB.EXEMultimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
    DellSCNdellsc.exeDell Solution Center - web-based troubleshooting tools and educational offerings
    DellSupportUDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptop.
    DellTouchUMMKeybd.exeDell multimedia keyboard manager. Required if you use the additional keys
    delmsbbXdelmsbb.exenCase adware
    delsaapXdelsaap.exe nCase adware
    delstart?delstart.exeReportedly part of BT ISP software - what does it do and is it required in startup?
    delsubmitXrundll32.exe advpack.dll, DelNodeRunDLL32 submit.exe CoolWebSearch parasite related
    DelTmp?DelTemp.exeAdded to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?
    DeltTrayNdeltray.exeSystem Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
    demon?demon.exePart of the French Wanadoo ADSL extense pack. What does it do and is it required?
    DenecaXVirus salvadoAdded by the W97M.DELUZ VIRUS!
    DepFrezUfrzstate.exeDeep Freeze from Hyper Technologies. "Freezes" the current software configuration so that an a re-boot all changes made refer back to their original settings. Not required for most users - more likely to be used by system administrators, for example
    Description of Shortcuts?*.exe* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e., 4EBD23F5 is actually Works Calender Reminder (found via a registry search)
    DesireXdesires.exeAdult content dialler
    desk-top-service?desk-top-service.exe??
    DeskAd ServiceXDeskAdServ.exe DeskAd.Service adware
    DeskColorNDESKCOLOR.EXEProvides transparent icon text backgrounds and coloured icon text
    DeskflagNDeskflag.exeDeskFlag - animated USA flag on the desktop
    DeskMateAutoUpdateNDeskMateAutoUpdate.exeDeskMates: Virtual scantily clad girls enhance your desktop - according to PestPatrol BargainBuddy adware related
    DeskMateAutoUpdateXDeskMateAutoUpdate.exeDeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related
    Desksite CMAUcma.exeDeskSite CMA siftware - "retrieves new content from the DeskSite Data Center"
    DesktopXrundll32.exe msconfd.dll, Restore ControlPanelAdded by the BOOKMARKER VIRUS!
    desktopXdesktop.exeAdded by the SDBOT.MD WORM!
    desktopXdesktop.exeAdded by the W32.Kobot.L WORM!
    Desktop ArchitectNDATRAY.EXEDesktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc
    Desktop PlantNAZARE10S.PLTVritual plant from here - this version is an Azalea, there are others so the filename may be different
    Desktop SearchXdesktop.exe iSearch "Desktop Search" hijacker
    Desktop Service Centre?DSC.exeOptusNet DSL or Dial-Up connection software - is it required?
    Desktop WeatherNTHE WEATHER CHANNEL.exeDesktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc
    Desktop Weather 3NTHE WEATHER CHANNEL.exe or THEWEA~1.EXEDesktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc
    desktopmgrNdesktopmgr.exeSynchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry"
    DesktopUpdateXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    DesktopXUDESKTOPX.EXEA program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
    deskupNdeskup.exeAdds Iomega Zip drive icons to the desktop
    destroyb11Xdestroyb11.exeAdded by the Troj/Delf-KO TROJAN!
    detectUidetect.exeiNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
    detect?turbodetect.exe??
    DetectorNdetector.exeUSB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
    DEventAgentUeventagt.exeDEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
    Device Configuration LoaderXmsdvc32.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Device DetectorUDevDetect.exeWatches for external digital imaging products being connected from ACD Systems
    Device Detector 2NDevDtct2.exeInstalled by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resources
    DeviceDiscoveryUhpotdd01.exeDetection of new imaging, printing and other peripherals on HP machines such as USB printers, cameras and Bluetooth products
    DevicePathXProyecto1.exeRoot.exeAdded by the GRUEL VIRUS!
    DevicesUolesvr.exeSalfeld Child Control 2003 - parental control software
    DevicewinX(Path to trojan)Added by the Troj/Banker-AEV TROJAN!
    devldr16.exeUdevldr16.exeAssociated with some Creative Labs sound cards.  Provides audio support for DOS applications.  Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
    Devlog?devlog.exeApparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it required
    dgtstartXdgtstart.exe DigitalNames.g adware
    dguardNdguard.exeeAcceleration Stop-Sign related; not recommended; see note
    DHCP ServerXregsvr.exeAdded by the W32/RBOT-PR WORM!
    dhcpagntYdhcpagnt.exeIntel DSL modem driver - leave enabled or you'll have to re-install the drivers
    diagentNdiagent.exeSystem Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
    DiagnosticXdiagnostic.exeAdded by the Troj/Alpha-C TROJAN!
    Dial22 or Dial33Xdlm.exeAdult content dialler
    DialerXrundll32.exe msa32chk.dllUnidentfied malware
    Dialer ControlUdc.exe Dialer-Control . Detects and protects from premium rate p0rn dialers
    Dialer DetectUdd.exe DialerDetect detects stealth installed premium rate dialers, and sounds the alarm when such a connection is being installed without you knowing it.
    Dialgo SDKUPhoneAnswer.exeDialgo Wave Modem ActiveX - "Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID, Wave Playback, Wave Recording, Digit Monitoring, POP3 e-mail Manipulation, Speech Recognition and Synthesis"
    DialNetXmxt32.exeAdult content dialler
    Dialog Box AssistantNOSDEx.exeDialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders
    Dialog HelperNPDDLGHLP.EXEDialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs
    DialUp Network ApplicationXRnaap.exeAdded by a variant of the W32/SDBOT WORM!
    Diamondview?Diamondview.exeManulife Financial Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup.
    DIECOXXcsrss.exeAdded by a BackDoor-ATM.gen trojan variant
    DieselXRecalculate.exe /reloadenterpiceAdded by the Lazar TROJAN!
    DietKUDietK.exe DietK - add-on for Kazaa Media Desktop; "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results."
    DigiDXDigitalSound.exeAdware downloader
    DigiGuideNCLIENT.EXEclient01.exeTV guide and reminder
    Digital DashboardNdevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
    Digital DashboardNCPQMLDET.exeFor Compaq PC's. Loads Digital Dashboard options
    Digital Line DetectNDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
    Digital River eBotNdownlo~1.exeDigital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here
    DigitalNamesXDigitalNamesStart.exe DigitalNames spyware variant
    DigitalWizardNISWizard.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
    DigitalWizard MonitorNdwMon.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
    DIGServicesUDIGServicesCreated by Disney but licensed to ESPN for watching videos.
    DIGStreamNdigstream.exeDIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
    DimensionUDimension.exeDimension, a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol.
    Dimension4Ud4.exeAtomic clock synchronisation freeware - starts-up, adjusts the system clock, then shuts down
    Dino3Xdino3.exeRelated to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
    DinstXdinst.exe IMIServer/IEPlugin adware component
    Dir1XcaKeAdded by the CAKE VIRUS!
    Direct settingsXsdchost.exeAdded by the TROJ/DAEMONI-I TROJAN!
    Direct UpdateUDUControl.exeDirectUpdate dynamic DNS updater
    Direct X Direct3DXdxd3d.exeAdded by a variant of the W32/SDBOT WORM!
    Direct X OpenglXdxopengl.exeAdded by a variant of the W32/RBOT-CJ WORM!
    direct3d.exeXdirect3d.exeAdded by the TROJ/CERTIF-F TROJAN!
    DirectCDNDirectCD.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    directs.exeXdirects.exeAdded by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!
    DIRECTVDSLUDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
    DirectXXddhelp32.exeAdded by the BIONET.318 VIRUS! Note - not the DirectX helper which is ddhelp.exe
    directxXDirectx.exeSqlexploit.exeNTCmd.exePipeCmd.exeAdded by the SDBOT.D WORM!
    DirectXXDirectX.exeAdded by the BLAXE or LOGPOLE VIRUSES!
    DirectXXdirectx32.exeAdded by the AGOBOT.CG WORM!
    DirectX 32Xdirectx32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    DirectX for Microsoft WindowsXdtxservice.exeAdded by the PROGENT TROJAN!
    DirectX for Microsoft WindowsXFservice.exeAdded by the PRORAT TROJAN!
    DirectX for Microsoft WindowsXSservice.exeAdded by the PRORAT TROJAN!
    DirectX For Microsoft® WindowsXfservice.exeAdded by the Troj/Prorat-P TROJAN!
    DirectX shell driverX(Path of the Trojan exe)Added by the Troj/MarktMan-B TROJAN!
    DirectX Video DriverXdxterm5.exeAdded by the W32/WILAB-A TROJAN!
    DirectX64XDirectXset.exeAdded by the BROWNEY.A VIRUS!
    DirectX9 DiagXdx9diag.exeAdded by the W32/RBOT-ALT WORM!
    DirkeyUDirkey.exeDirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl Alt 1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl 1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders 
    Disable EHCI?nousb20.exe??
    Disc DetectorNCtNotify.exeFor Creative sound cards. Detects when you insert a CD, DVD, etc
    disc detector?qnetquestnotifty.exe??
    discoveg?discoveg.exe??
    DiscoverDeskshopNDeskshop.exeDiscover Deskshop - single use "virtual" credit card
    Disk KeeperXSECURITY.EXE Daosearch adware
    Disk KeeperXkeep.exeMslware - recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.ve
    Disk ManagerXdiskver.exeAdded by the RBOT.AQT WORM!
    Disk MasterX(trojan name)Added by the DISTER VIRUS! - a spam relayer
    DiskCheckXmsdarkend.exeAdded by an unidentified WORM or TROJAN!
    DiskeeperSystrayNDkIcon.exe DisKeeper defragmentation software - can be started manually.
    diskinfXdiskinf.exeAdded by a CRYPTER.A trojan infection
    DISKMON.EXE?DISKMON.EXE??
    DisknagNdisknag.exeDell program that reminds you to make your  backup diskettes
    DiskstartXCode.exehit.exeSnt.exeAdult content dialler
    DiskstartXcat.exeMS-Connect dialler
    Disk_MonitorUDisk_Monitor.exeMulti-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
    displayUThe_Eye.exeAdded by the ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself.
    Display DriversXcssrs.exeAdded by the AGOBOT.FX WORM!
    Display SettingsNhptasks.exeAllows for the adjustment of the display for LCD screen, CRT Monitor and TV output on HP computers.
    DisplayTrayIconNTrayIcon.exeSystem Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel -> Display
    DisspyUdisspy.exe Disspy spyware detection and removal software
    Distiller Assistant 3.01NDISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
    Distributed File SystemXDfsvc.exeAdded by the MYFIP.A or MYFIP.K WORMS!
    Distributed File SystemXkernel32dll.exeAdded by the W32.MYFIP-C or W32.MYFIP.K or W32.Myfip.T WORMS!
    Distributed File SystemXblade.exeAdded by the W32.MYFIP.AC WORM!
    Distributed File SystemXwin.exeAdded by the W32.MYFIP.AB WORM!
    distributed.net clientUDNETC.EXEDsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses
    DitYdit.exe"Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
    DitXdit.exeAdded by the Troj/Lazar-A TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    DiTask.exeNDiTask.exeAssociated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
    Divamon.exe?Divamon.exeAssociated with an Eicon_Networks Diva ISDN or ADSL modem - what does it do and is it required?
    divxXdivxenc.exeAdded by the Trojan.Spbot.C TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    DivxXcodll.exeAdded by Troj/Gravebot-A TROJAN!
    DivX MediaPlayer 7.0XDr.DivX.exeAdded by the ALADINZ.G VIRUS!
    DivX PlayerXDivXPlayer.exeAdded by a variant of the WIN32.RBOT WORM!
    DivX UpdaterXDivX.ExeAdded by the NALDEM or MASTAK VIRUSES!
    Divx4 codecXdevldr32.exeAdded by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file
    DJREGFIXNregedit /s c:\hpdjregfix.regDJRegFix showed up first in WinME as a "clever" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This "utility" adds the functionality and compatibility HP forgot to add in its WinME drivers
    DJSNetCN?DJSNetCN.exe"Symantec Licensing Detect Internet Connection", part of Norton antivirus - what does it do and is it required?
    DkServiceYDkService.exeFrom Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. Used to schedule defragmenting on a regular basis and not required if you do so manually.
    DKTimeXdktime.exeAdded by a Downloader.Lunii trojan infection
    Dkware lptt01 or Dkware ml097eXdkware.exeVariant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    dkzzixm?dkzzixm.exe??
    dlaYtfswctrl.exeDrive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
    DlaTrayNDlatray.exeSystem Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
    dlbcserv?dlbcserv.exeRelated to a Dell Photo Printer - what does it do and is it required?
    dlderXdlder.exeAdvertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see here). Reported in the past as a virus
    DlDir1XcaKeAdded by the CAKE VIRUS!
    DLForcerExe?DLForcerEXE.exe??
    DLF_00000B00NVcdlf.exeKnown to cause problems with "Out of memory" errors (see here). Otherwise, it's purpose is unknown
    DLGNDLGCHBW.exeBackweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
    DLHelperEXENWATCH.exeDownload helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
    DLHelperEXE.exeXN/ADownloader for Microgaming/Casino software - stealth installed
    dlhostXdlhost.exeAdded by the Troj/ExpHook-A TROJAN!
    DliteXdllmanager.exeAdded by the WOOTBOT.DN WORM!
    Dll Boot Loader on Startup (do not remove this)X[various file names]Added by an unidentified TROJAN!
    DLL ManagerXdllmngr32.exeAdded by a variant of the WIN32.RBOT WORM!
    DLL Service ManagerX(path to worm)Added by the RPCBOT.F VIRUS!
    DLL32Xdllmem32.exeAdded by the KWBOT.E VIRUS!
    DLL32Xdllhost.dllAdded by the LOVELETER.A WORM!
    DLL32Xdllhost.dllAdded by the W32.Suclove.A WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder, be sure to check the link on this one, copies it's self under four different file names in three diffrerent folder locations.
    DllCacherv2Xdllcachev2.exeAdded by the BACKDOOR.LATEDA TROJAN!
    dlldmtXdlldmt.exeAdded by a CRYPTER.C trojan variant infection
    DllExecutableX[path to file]Added by the W32/VB-SP WORM!
    dllhelpXdllhelp.exeAdded by a W32/Startpage.DQ hijacker infection
    dllhelpXdllhlp.exeAdded by the Downloader-HI TROJAN!
    dllhostxp.exeXdllhostxp.exebrowser hijacker and adware downloader
    DllLoaderXlssas.exeAdded by the TROJ/BDOOR-JE WORM!
    DlloadXkiller.exeAdded by the Troj/KillAV-FK TROJAN!
    dllregXdllreg.exeAdded by a CRYPTER.A trojan infection
    DLLService32Xdllsvc32.exeAdded by the AGOBOT.VX WORM!
    dlsp2mxXdlsp2mx.exeAdded by the Dial/MPB-B Dialer. Note: The dialer provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as dlsp2mx.
    DLT?dlt.exe??
    dlucaXdluca.exeAdult content dialler - see here
    dlucaXdluca.exeAdded by the DLUCA.C VIRUS!
    dluxdeXdluxde.exeAll-In-One-Telcom (adult content dialler) variant
    DluxjpXcnfrm.exeAdded by the DLUCA.D VIRUS!
    DM mgrXdm_mgr.exeAdded by the JITTAR VIRUS!
    dm***.exe (* = random character)Xdm***.exe (* = random character)Malware, presumably related to a new WareOut variant - detected by Ewido_Security_Suite as "trojan small.fb". Examples of filenames spotted include for example dmmnh.exe, dmsqg.exe, dmnib.exe and so on.
    DMCXdmc.exeAdded by Trojan-Downloader.Win32.Dluca.bv TROJAN!
    DMILDRNdmildr.exePart of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs 
    DMISLNDMISL.EXEDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
    DMISLAPPNDMISLAPP.exeDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
    Dmsvc32XDmsvc32.exeAdded by the AGOBOT.ABU WORM!
    dmtdllXdmtdll.exeAdded by a Crypter.C trojan variant infection
    DMXLauncherUDMXLauncher.exePart of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files.
    DM_serverXdmserver.exeComet Cursor adware
    dm_serviceX[path to file]Added by the MITGLIEDER.P TROJAN!
    DnarXDnar.exeUnknown, except that it is not necessary. Tends to phone home a lot. DMI related - see here
    DNE Binding WatchdogYrundll dnes.dll, DnDneCheckBindingsDeterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
    DNE DUN WatchdogYrundll dnes.dll, DnDneCheckDUN13Deterministic NDIS Extender (DNE). DNE is an NDIS-compliant module which appears to be a network device driver to all protocol stacks and a protocol driver to all network device drivers. Part of Gilat Communications internet satellite systems. Required if you have this system. Also installed by Winproxy - a proxy program for sharing internet connections through one computer. Required if you want it to work
    DNSXmc-58-12-0000093.exeNail/Aurora related malware
    DNSXmc-58-12-0000080.exe "Shorty" adware component, also detected as the AGENT.FD TROJAN!
    DNSXmc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
    DNSXmc-58-12-0000120.exe "Shorty" adware component, also detected as the AGENT.FD TROJAN!
    DNSXmc-58-12-0000140.exe "Shorty" adware component, also detected as the AGENT.FD TROJAN!
    DNSXservices.exeAdded by the W32/Bckdr-CQG WORM! Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder). The legitimate Windows process should not be seen in Msconfig or as a Startup item. This worm file is found in the Common Files folder.
    Dns ResolverXdnsrslve.exeAdded by the W32/RBOT-WS WORM!
    DNS ServiceXdnsresolver.exeAdded by the W32/RBOT-PQ WORM!
    DNS2GoClient?dns2goclient.exeDNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required?
    DNSCacheBoostXdnsping.exeAdded by the TROJ/DNSBUST-A TROJAN!
    dnscleanerXdnscleaner.exe CoolWebSearch parasite related
    DNXVC?dnxvc.exe??
    DocTorXDoctor.exeAdded by the DOTOR VIRUS!
    DocuMagix InitNPWATCH.EXEPaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if needed
    Doggy Style XMsPMSPSd.exeAdded by the W32/Sdbot-AAP WORM!
    DOGStartXGSDOGST.EXEAdded by an unidentified VIRUS! A possibility is a trojan known as PENIS
    Doing?doing.exe??
    doit.exeXdoit.exeAdded by the W32/FORBOT-EK WORM!
    Don't PanicUdontpanicdemodp.exe30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
    Don't Panic Pop-Up StopperUdpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    dosXdos64.exeadware downloader trojan
    Dos Prompt LoaderXcygwin.exeAdded by the W32/SDBOT-VV WORM!
    Dosbat?????
    Dot.net NetworkingXSnss32.exeAdded by a variant of the IRC_TROJAN !
    DoUWantItNduwi.exeDoUWantIt - online shopping assistant. Start it manually
    downXhlp32.exeAdded by the TROJ_DLOADER.BG TROJAN!
    downX(Original Trojan filename)Added by the Troj/Small-QJ TROJAN!
    Download Accelerator Plus 5.0NDAP.exeDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is "adware" based
    Download PlusXDownloadPlus.exeDownloadPlus parasite - opens pop-up adverts
    Download WonderNDownloadWonder.exeDownload Wonder from Forty Software. Download manager for resuming downloads, amongst other features
    DownloadAcceleratorNDAP.EXE Download_Accelerator_Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is adware based
    DownloadLegalMusicXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    DownloadWareXdw.exeDownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
    DownloadWare EngineXDwe.exeDownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
    DownxzXDownxz.batAdded by the W32.Mydoom.W WORM!
    DPAgntNDPAgnt.exedigitalPersona fingerprint scanner
    DpcnavYdpcnav.exeDirecWay from DirectTV satellite based high-speed internet access
    DPConfigNDPConfig.exeCompuware DevPartner Studio Configuration Utility, a tool for software developers - system tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when needed.
    dpcproxyXdpcproxy.exeAdded by a Troj/GoldenP-A trojan infection
    DPCProxyLoadOnStartupYdpcstart.exeDirecWay from DirectTV satellite based high-speed internet access
    DpcstartYdpcstart.exeDirecWay from DirectTV satellite based high-speed internet access. Proxy software
    DpcstartUdpcstart.exeStartup program for Direcway 2-way satellite internet service. Loads DirecWay\'s Navigator, tray icon, etc
    dpiXdpi.exe Delfin_Media_Viewer or "Promulgate" adware
    dpnsvr32Xdpnsvr32.exe -quietAdded by Troj/AOLPass-B TROJAN!
    dpps2Udpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    dpsXdps.exe SmartestSearch parasite -poses as a foistware, bogus adware/spyware remover called "scumware-remover"
    Drag'n'Drop_AutolaunchNAutolaunch.exeIomega HotBurn - CD-RW burning software
    DragDrop?DragDrop.exe??
    DragnDrop_AutolaunchNAutolaunch.exe Iomega_HotBurn - CD-RW burning software
    DrCacheXMSTDC.EXEAdded by the Troj/Bdoor-JM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    DrefIWXSysDrefIWv2.exeAdded by the W32/DREF-C WORM!
    DrefIWXSysDref.exeAdded by the W32/Dref-D WORM!
    dregfix?ph_finder.exe??
    DrgToDscNDrgToDsc.exePart of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
    dried.exe?dried.exe??
    DriveLEDNOODLed.exeO&O DriveLED - displays your HDD LED on your monitor. Start manually
    DriverXgbot.exeAdded by the JUNTADOR.K VIRUS!
    Driver32XScam32.exeAdded by the SIRCAM VIRUS!
    DriverCheckXsvchost.exeAdded by the TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    DriverDBXsvcmdx32.exeAdded by the BACKDOOR.BERPI TROJAN!
    DriverLoadXsvchost.exeAdded by the TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    DriveSelectNdriveselect.exeDVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
    dRMON SmartAgentUSmartAgt.exePart of the network monitoring program group for 3Com NIC cards. See here for more info
    drmuXW95Mm.exeHomepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise. See this thread
    drocherXd.exePremium rate adult content dialer
    Drvddll_exeXdrvddll.exeAdded by the BEAGLE.X WORM!
    DrvListnr?DrvListnr.exeAnalog Devices SoundMAX soundcard related. What does it do and is it required?
    drvlsnrUdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
    drvnetwXdrvnetw.exe Troj/Brogger-B is an information stealing TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    drvr32hXdrvr32h.exeAdded by an unidentified VIRUS!
    drvrmanagerXdrvrquery32.exeAdded by the BOOHOO VIRUS!
    drvsys.exeXdrvsys.exeAdded by the BEAGLE.W WORM!
    drvupdXrundll32 ..drvupd.infHijacker - drvupd.inf file installs a "searchforge.com" hijack
    DrWatsonXdrwatson_.exeAdded by the TROJ/LOHAV-S TROJAN!
    DrWatsonXdrwatson_32.exeAdded by the TROJ/LOHAV-S TROJAN!
    DrWeb AntivirusXDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
    DrwebschedulerYDrwebscd.exeDr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
    DR_SXDR_S.exe AdShooter adware
    dsXds.exeAdded by the Backdoor.Spymon TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    DS ClockUdsclock.exeDigital desktop clock including synchronization with atomic servers - see here
    dsaXdsa.exeHomepage hijacker - redirecting to downseek.com
    DSAcassX(path to file)Added by the RANKY.M backdoor TROJAN!
    DSBXDSB.exe EnergyPlugin adware
    DSentryNDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
    DsiXdp-******.exeAdded by unidentified adware where ****** are random characters
    DsiXdp-him.exeAdded by the Troj/Multidr-AH TROJAN!
    DskcompatXDskcompat.exeAdded by the GEMA TROJAN!
    DSL MonitorNspdstrm.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
    DSLagentexeUDSLagent.exeEnables the Media Center software on a Media Center PC to be lauched via the button on the remote. Required if you prefer not to double-click the desktop icon first
    dslmonYdslmon.exeSagem DSL modem related. Apparently needed to detect the modem.
    DSLSTATEXEUdslstat.exeSystem tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
    DsmSerXdsm.exeAdded by the W32.Serflog.B WORM
    DsmSerXmsmpatch.exeAdded by the W32.Serflog.B WORM
    DsmSerXsvosm.exeAdded by the W32.Serflog.B WORM
    DsmSerXsysup.exeAdded by the W32.Serflog.B WORM
    DSSXdssagent.exeDSSAgent by Brřderbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info
    DSSX(Trojan filename)Added by the Troj/DSSDoor-C TROJAN!
    DSServiceXdmrss.exeAdded by the W32/AGOBOT-XX WORM!
    DSSSGENS?dssagens.exe??
    dstrayXdstray.exeAdded by the Troj/CmjSpy-AA TROJAN!
    DU MeterNDUMETER.EXEHagel Technologies internet bandwidth monitor
    duckXduck.exeAdded by the W32/Agobot-AVG Worm!
    Dumeter ServicesXdumeter.exeAdded by W32/Sdbot-AEQ WORM!
    dumprep 0 -kordumprep 0 -uNdumprep 0 -kdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    DUN_SERVICES3Xdun3.exeAdded by the Trojan.Sokiron TROJAN!
    DuweculeyXyujixit.exeAdded by the SDBOT.BRP WORM!
    dvd43NDVD43_Tray.exe DVD43 is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies."
    DVD43UDVD43.exe DVD43 is a small tool that overrides CSS copy-protection found on DVD movies.
    dvd98Xwindvd98.exeAdded by the CULT.P VIRUS!
    DVDBitSetUDVDBitSet.exeDVD RW Drive/Disc Compatibility Setting. Installed with HP DVD RW drives to enhance compatibility with existing readers. You can also set a DVD RW default drive write mode which is always used
    DvdcompatXDvdcompat.exeAdded by the GEMA TROJAN!
    DVDLauncherUDVDLauncher.exeA process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use
    DVDSentryNDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
    DVDTray?DVDTray.exeHP CD/DVD Tray icon - what exactly does it do, and is it required?
    DVDUpgrade?DVDUpgrd.exe??
    Dvp95YDvp95.exeScan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine
    dvpapi9xYDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
    DvpInitExeYDvpinit.exeCommand Antivirus related
    dvprptYDvprpt.exeCommand Antivirus real time protection
    dvraudioXdvraudio.exeAdded by a Crypter.C trojan variant infection
    dvsfssXfbsfsdrs.exeAdded by a W32/Sdbot-QA worm infection
    DVSyncUdvsync.exeDVSync is the program that allows you to synchronize your daVinci’s PDA's data with your Personal Information Manager on the PC
    DvxXwsxsvc.exe Delfin_Media_Viewer or "Promulgate" adware variant
    dwXdw.exeDownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
    DW4UWeather.exe Desktop_Weather
    DWHeartbeatMonitorUDWHeartbeatMonitor.exeDWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
    DwlClientNsupport.exeDownload manager for Dell support alerts
    dwStartYFireWall.exe The_Shield Firewall
    DxXsys#.exeAdded by the DEXTER.A VIRUS! where # is a random number
    Dx8compatXDx8compat.exeAdded by the GEMA TROJAN!
    dxdiags.exeXdxdiags.exeAdded by the Troj/Certif-G and Troj/Certif-K TROJANS! Note: These trojan files are found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    dxdll32Xntxdll.exeAdded by the W32.Gaobot.CPX WORM!
    DXDllRegExeNdxdllreg.exeCreated when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
    DxLoadXDX3DRndr.exeAdded by the GIBE.B VIRUS!
    DXM6Patch_981116Np_981116.exeWin32 cabinet self extractor. More info here
    dxmsrvXdxmsrv.exeAdded by an unidentified WORM or TROJAN!
    DxstyXDxsty.exeAdded by the GEMA TROJAN!
    Dxupdate.exeXDxupdate.exeAdded by the MAFEG VIRUS!
    dxvidXdxvid.exeAdded by Trojan-Downloader.Win32.Dluca.by TROJAN!
    DyFuCAXoptimize.exeAdult content dialler - see here
    DyFuCA Active AlertXactalert.exeAdult content dialler - see here
    Dynamic Dns BinaryXdynitora.exeAdded by the W32/RBOT-WT WORM!
    Dynamic Dns BinaryXwinxp34.exeAdded by a variant of the WIN32.RBOT WORM!
    Dynamic Dns BinaryXCMD16.EXEAdded by the W32/RBOT-XM WORM!
    Dynamic Dns BinaryXWinHelpcfn.exeAdded by a variant of the WIN32.RBOT WORM!
    Dynamic Link Library loaderXLoader32.exeAdded by the BACKDOOR.KOL TROJAN!
    DynDNS UpdaterUDynDNS.exeDynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org.
    DynDNS-Updater TraytoolNddutray.exe DynDNS updater tray icon; allows easy configuration of the Dynamic DNSSM service.; can be run manually
    DynHttp Dns BinaryXdynizari.exeAdded by a variant of the WIN32.RBOT WORM!
    DynSiteUDynSite.exe DynSite is a dynamic DNS client, also called an automatic IP updater.
    Dynu Basic ClientUdynubas.exe Dynu online dynamic IP update client. Useful when using a dial up modem.
    DZKillMe?DZSAVEME.EXE??
    E-CardXecard.exeAdded by the YODI VIRUS!
    E-colorUIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get \'what the game designer intended\' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
    E6TaskPanelNTaskPanl.exeEarthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space
    eabconfg.cplUEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
    Eac DownloadXdownload.exeAssociated with Webcelerator - spyware. Read eAcceleration's privacy statement here
    EACLEANUeaclean.exeFor Compaq PC's. Easy Access button support for the keyboard
    Eac_CnryXcanary.exeAdded by the CANARY VIRUS!
    Eac_rnvdl?ANTIVIRUS_INSTALL.EXE??
    EanthologyAppNEANTHO~1.EXEeAcceleration Stop-Sign related; not recommended; see note
    EanthologyAppNeanthology.exeeAcceleration Stop-Sign related; not recommended; see note
    eanthology_install.exeNeanthology_install.exeeAcceleration Stop-Sign related; not recommended - see note
    eanth_critical_update_alertNsys_alert.exeeAcceleration Stop-Sign related; not recommended; see note
    eanth_system_patcherNsys_alert.exeeAcceleration Stop-Sign related; not recommended; see note
    EapcisetupNsbsetup.exeRockwell RipTide soundcard application software. Sound works without it
    EAPCISETUPNwizard.exePart of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
    EarthLink ToolBar 5.0Netoolbar.exeEarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar, but you can delete these or add more buttons any time
    Easy Start ButtonNesb.exeProvides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
    Easy-PrintToolBoxUBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printer
    EasyAVXEasyAV.exeAdded by the W32.NETSKY.S or W32.NETSKY.T WORM!
    EasyDatesXEasyDates.exePremium rate adult content dialer
    EasyDates_nlXEasyDates_nl.exeAdult content dialler
    EasyKey or Easy KeyUeasykey.exeFor programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
    EasyKeyboardLoggerUepl.exe EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
    EasyMessageUem2.exeEasy Messenger, instant messenger for MSN, AOL, ICQ, and Yahoo. See here
    EasySearchBarXESBUpdate.exeEasySearchBar adware downloader
    easyServXServer.exeAdded by the EASYSERV VIRUS!
    EasySync ProUXCPCMenu.exeEasySync Pro is a Lotus program for synchronizing a PDA with Lotus Notes
    EasyTuneIIIUEasyTune.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
    EasyTuneIVUET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
    easywwwXeasywww.exe, easywww2.exe, iewwwint.exe EasyWWW adware
    EbatesMoeMoneyMakerXwjview ...Code Ebates adware
    EbatesMoeMoneyMaker0XEbatesMoeMoneyMaker0.exe Ebates adware
    eBay ToolbarXEBAYTBAR.EXEeBay Toolbar - reportes as spyware as it "phones home"
    eBayToolbarUeBayTBDaemon.exe eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites.
    eBoard or eMachines eBoardUEboard.exeeMachines multimedia keyboard manager. Required if you use the extra keys
    eBotNDownloadWizard.exeeBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
    eCopy Desktop Printer ServiceUmrmlnc32.exe eCopy Suite software connects your Canon imageRUNNER or document scanner to your company’s e-mail and other networked enterprise applications for easy, instantaneous distribution and management of scanned documents.
    ecpe?ECPE.EXE??
    edexterNedexter.exe eDexter supplements Internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser.
    editpadXeditpad.exe CoolWebSearch parasite related
    editpadXeditpad.exeAdded by a Consper-B trojan infection
    EDLoaderNDTLoader.exeEffective Desktop from MiniStars Software - desktop management software no longer being supported
    EDRestoreU??Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP"
    educational writerX(filename).exeAdded by a W32/Rbot-LZ worm infection
    EdwizardUEdwizard.exeSafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
    eFax DllCmdUJ2GDllCmd.exe eFax_Messenger fax software
    eFax Tray MenuUJ2GTray.exe eFax_Messenger fax software tray menu
    eFax.com Tray MenuNHotTray.exeeFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
    efaxs lptt01 or efaxs ml097eXefaxs.exeVariant of the RapidBlaster parasite (in an "efaxs" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    EFI Job MonitorU[path] efjm.dll,runRicoh Imagio Printer/Scanner driver status monitor
    Efpap.exeUEfpap.exeEasy File & Folder Protector. Deny access to certain files and folders, or to hide them securely from viewing and searching
    ehTrayUehtray.exeWindows XP Media_Center_Edition 2005. Enables the user to access Windows Messenger from within Media Center
    ei10.exeXei10.exeAdded by the AGOBOT-NK WORM!
    Eicon NetworksLAN_DAEMON or Eicon TechnologyLUwatch.exeAssociated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually
    eixfiXchina.batAdded by the WCUP VIRUS!
    ekor.exeXigamatuAdded by the BACKDOOR.SDBOT.AQ TROJAN!
    ElbycheckUElbyCheck.exeFrom Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it
    Electron MicroscopeUEMIII.exeElectron Microscope, or EM , is a program used to track Stanford’s distributed computing program client called Folding at Home, FAH It will monitor up to 50 clients and give you the details about each client’s progress as the FAH client runs. EM will also show you what each change in the protein looks like as the process continues.
    ElementXElement.txtAdded by the ELEM TROJAN!
    element furthX[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    elmNElmenv.exeViaTech eLicense for securing, distributing and selling music online
    ELNKProxyXsmproxy.exe Surfmonkey adware
    ELSA WINman SuiteUWinmsuit.exeAllows you to totally customize your ELSA graphics card settings, including overclocking the GPU
    ElsaCapiCtlYRcapi.exeAssumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem
    ELSAChipGuardUelsavect.exeChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed, and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
    ELSBLaunchUELSBLaunch.exeEarthLink SpamBlocker
    EMA.exeNEMA.EXETime management system which helps you to manage your time and appointments
    eMailEncryptionNvelozsys.exeeAcceleration Stop-Sign related; not recommended; see note
    eMakeSVXEMAKESV.EXE Switch premium rate adult content dialer variant
    eMakeSVXEMAKE2B.EXE Switch premium rate adult content dialer variant
    eMCryT Sh3ars PanagersX(Path to worm random filename)Added by the W32/Rbot-AWI WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    emoc0reXemo.exeAdded by the W32/AGOBOT-AGE WORM!
    empinXe121307.Stub.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    empinXe121307.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    emsw.exeXemsw.exeBelieved to be spyware - made by a company called Alset. Also known as "HelpExpress". Will install itself if you have previously had Attune by Aveo installed as they're by the same company. Uninstall via Add/Remove programs
    emuleXemule.exeAdded by the W32/Rbot-ALZ WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    eMusicClient SystrayNeMusicClient.exe eMusic MP3 download software
    EM_EXECUEM_EXEC.EXELogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    EN4060C TaskbarNen4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
    enBrowserX[name of file] WINBO adware component
    encapsulated command tool?wintr.com??
    Encarta Dictionary QuickshelfNQSHLFED.EXEProvides quick access to Encarta's Dictionary features?
    ENCMONITORNmonitor.exeThe Encompass Monitor. This program is the Connect Direct Program.  It is more trouble than it is worth and few use it
    Encoder AgentNWMENCAGT.EXEMS Windows Media Encoder, which already has a shortcut in the Start Menu if installed
    Encompass_ENCMONTRUENCMONTR.EXEOptional simple browser from Yahoo (Encompass)
    ENCSurf?surfboard.exe??
    Energizer FileSaverUEnergizer FileSaver.exeEnergizer FileSaver - UPS back-up utility for Energizer UPS products
    EnergyPlugInXEnergyPlugin.exe EnergyPlugin adware variant
    enginecs2Uenginecs2.exe Cyber_Sentinel Internet filtering software
    EngUtilYEngUtil.exePart of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
    Enh Win UpdtXenhupdt.exeAdware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.OneClickNetSearch.h
    enhance32Xenhance32.exeAdded by a CRYPTER.A trojan infection
    EnigmaPopupStopNEnigmaPopupStop.exePart of Enigma SpyHunter - not recommended, see note
    ENSApServer2_0?APSERVER.EXEIntel AnyPoint Wireless II Home Network related. What does it do and is it required?
    ENSMIX32.EXE?ENSMIX32.EXESound card driver. Is it required?
    EnsoniqMixerUstarter.exePuts the Ensoniq mixer in system tray. From Ensoniq Technologies "Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility
    Enumerate ServiceXwsys.exeAdded by the MANIFEST VIRUS!
    EnvyHFCPLYEnMixCPL.exeVIA Envy24 PCI Audio Controller driver
    eonemngUeOneMng.exeeOne Manager, provides access to the buttons on the keyboard and on the front of the console for the eMachines eOne PC
    EPoXUSDMNUSDM.EXE EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc
    ePrint 4.0 ServiceNEPRINT4.EXEA component of the LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more! - Can be started manually.
    ePrompterUePrompter.exeePrompter - E-mail notification software
    EPSNe_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    EPSNe_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    EPSON Background MonitorNSTMS.EXESupposed to keep an Epson printer ready for quick printing.  Users report little difference whether it is on or not
    EPSON CardMonitorUEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
    EPSON Status Monitor 3 Environment CheckNe_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    EPSON Status Monitor 3 Environment CheckNe_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
    EPSON Stylus C44 SeriesUE_S10IC2.EXEEpson Stylus C44 Series printer monitor - for checking ink levels, etc.
    EPSON Stylus C46 SeriesUE_S4I0T1.EXEEpson Stylus C46 Series printer monitor - for checking ink levels, etc.
    Epson Stylus C62 SeriesUE-S0BIC1.EXERequired for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
    Epson Stylus C82 SeriesUe_s0hic1.EXERequired for an interface to some versions of MS Word to ensure that some fonts are printed correctly. Start it manually if required
    EPSON Stylus Photo R300 SeriesUE_S4I2F1.EXEEpson Status Monitor - gets installed with many Epson printers and gives you a progress of your print jobs as they are printing.
    EpsonPhotoStarterUEPSON_PhotoStarter.exeOnly needed if you want to make full use of the capabilities of an Epson printer that included this 
    Equipmen?Equipmen.exe??
    EraserUeraser.exe -hide Eraser allows for complete removal of data from your hard drive
    eRecoveryServiceUcheck.exeAcer Notebook related - Acer eRecovery allows the user to restore the operating system or backup the current system profile, thus ensuring system integrity.
    ERegNreg32.exeEReg is a software registration tool incorporated on products such as those by Brřderbund, Connectix, Hewlett-Packard, The Learning Company, and Sierra. Needless to say you don't need it
    erfgddfkXwind2ll2.exeAdded by the W32.Beagle.CQ WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    erghgjhgdrXwindlhhl.exeAdded by the W32.Beagle.BG or W32.Beagle.BH or W32.Beagle.BI or W32.Beagle.BJ WORM!
    erm?erm.exe??
    Eror NukerNErrorNuker.exe ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required.
    eros.exeXeros.exeAdult content dailler
    ErrorGuardXErrorGuard.exeSpyware remover of dubious repute - see here
    erthegdrXwindll2.exeAdded by the W32.Beagle.CG WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    erthgdrXwindll.exeAdded by the BAGLE.BD WORM!
    erthgdrXsvc.exeAdded by the W32.Beagle.BK WORM!
    erthgdrXsvc.exeAdded by the W32.BEAGLE.BN or W32.Beagle.BP WORM!
    erthgdr2Xsvc23.exeAdded by the BAGLE.CG WORM!
    ERUNT AutoBackupUAUTOBACK.EXE ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored if desired.
    eSafe ProtectYESPWatch.exeeSafe from Aladdin - internet security for gateway and E-mail servers
    ESBUesb.exeEasy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
    eScan MonitorYAVKWCTL9X.EXEeScan antivirus
    eScan SchedulerUavkserv.exeeScan antivirus scheduler
    eScan UpdaterUTrayicos.exeeScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads
    EScorcherXescorcher.exePart of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
    ESFTPNesftp.exeESftp - FTP client for transfering files between a local PC and another remote computer
    EsohXEsoh123.exeAdded by the AGOBOT.FF WORM!
    EspecialXDeneca.batAdded by the W97M.DELUZ VIRUS!
    ESPN BottomLineNbline.exeESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."
    ESS Daemon?Essd.exeRelated to an ESS based soundacard. Is it required?
    essapm?essapm.exeESS Solo soundcard driver. Is it required?
    EssdcYessdc.exeRelated to an ESS Solo soundcard. Seems as though it's required
    ESSNDSYS?ESSNDSYS.EXERelated to an ESS based soundacard. Is it required?
    ESSOLOYESSOLO.exeSound card driver that re-instates itself every time it's removed
    esspkYesspk.exeESS Technology modem speaker driver file. Required to get on-line with this modem
    EssSpkPhoneUessspk.exeESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
    eSupInit?eSupCmd.exeRelated to SupportSoft "Real-Time Service Management software" - what exactly does it do and is it required?
    ETB TesterXetbtest.exeAdded by the W32/RBOT-ABR WORM!
    etbrunXelite***32.exe (* = random char) EliteBar adware variant
    EthernetNtcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
    ethernetXairftp.exeAdded by a variant of the W32/SDBOT WORM!
    ethernetXmsnger.exeAdded by a variant of the W32/SDBOT WORM!
    ethernetXmsftp.exeAdded by the SDBOT.BXJ WORM!
    Ethernet DriversXsmrrs.exeAdded by the W32/RBOT-AAK WORM!
    Ethernet DriversXethernet.exeAdded by the W32.GAOBOT.CEZ WORM!
    EtrafficXJavaRun.exeMarketing software from TopMoxie
    eTrust EZ FirewallYefpeadm.exeeTrust EZ Firewall
    eTrust PestPatrol Active ProtectionUPPActiveDetection.exe PestPatrol real-time protection feature. "Stops spyware before it infects your system"
    eTrustCIPEYezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
    eTunnelXwinfw.exeAdded by an unidentified TROJAN!
    EuroGlotUEuroGlot.exeEuroglot - "multilanguage translating system, available in the languages Dutch, English, French, German, Spanish and Italian"
    Event Log?eventlog.exe??
    Event Planner RemindersNPLNRnote.exeSierra Event Planner tray icon
    Event ReminderNpmremind.exeA calendar/alarm program that installs with Brřderbund Printmaster
    EVENTLISTENERUEvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
    eventmgrNeventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
    Evidence CleanerUecleaner.exe Evidence_Cleaner cleans up tracks left by your PC and Internet activities
    Evidence EliminatorNee.exeEvidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis
    EvilXEvil.exeAdded by the W32.Mytob.JM WORM! Note: This worm file may be found in the Windows or Winnt folder.
    evntsvcNevntsc.exeApplication Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. Not required - see here for more information, including how to disable it
    EVOLOSTAUEVOLOSTA.EXEEvolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it
    EvtHtmXevthtm.exePremium rate adult material dialer
    EW Message ServerUmsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
    eWare StartupNiWareStart.exeeWare iWare task bar. Not required
    ewupdaterXewupdater.exe EasyWebSearch adware updater
    Excite PlatformNExlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
    Excite Private Messenger Pipe?x8impipe.exe??
    ExciteAssistantEXENASSISTANT.EXEWith Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open
    exe lptt01 or exe ml097eXexe.exeVariant of the RapidBlaster parasite (in an "Exe" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    execfg4Xexecfg4.exeAdded by the ELECTRON VIRUS!
    Execute?delfolders.exe??
    ExeName32XWarm.scrAdded by the SCOLD VIRUS!
    exgiwsl?exgiwsl.exe??
    Exif LauncherUExiflaquickdcr.exe, QuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
    ExitKillerUEkiller.exeExit Killer - automatically closes pop-up windows in your browser
    exmon?hpimoniter.exeSome kind of hp digital camera maybe or a photo smart connection probe?
    exp.exeXexp.exeAdded by a variant of the SMALL.ABD downloader TROJAN!
    EXPL0RE.EXEXEXPL0RE.EXEAdded by the Troj/Popno-A TROJAN! Note: Notice that (EXPL0RE.EXE) is spelled using the number 0 instead of the letter O. This trojan is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Expl0rer softXexpl0rer.pifAdded by the W32/RBOT-AQR WORM!
    explerXUpdadv.exeAdded by the Troj/QQPass-N TROJAN!
    ExplkwXexpup.exeKeywords hijacker
    exploreXexplore.exeAdded by the W32.Hawawi WORM!
    ExploreXExplorer.exeAdded by the IRC.FLOOD.G VIRUS! Note - this is not the valid Windows "explorer.exe"
    ExploreXexplore.exeAdult content dialler
    explore managerXexplore.exeAdded by the DONBOMB.A TROJAN!
    explore.exeXExplore.exeAdded by the GRAYBIRD.G VIRUS!
    exploreff.exeXexploreff.exeAdded by the Finfanse or Troj/LegMir-BH TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    explorerUexplorer.exeStarts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a WORM! such as PE_BISTRO or DVLDR or MYDOOM.B or Troj/Torpig-A . Note that it is also not the explorer.exe task/service you'll see when via CTRL ALT DEL
    explorerXwscript.exe Sneaky way to start any VBS script. Many viruses use VBS files
    ExplorerXshellexpl.exeAdded by the GPIX and SHELDOR VIRUSES!
    explorerXexpl32.exeAdded by the RATSOU VIRUS!
    ExplorerX(path to worm)Added by the AUTEX VIRUS!
    ExplorerXshellexp.exeAdded by a variant of the Backdoor.Sheldor TROJAN!
    EXPLORERXEXPL0RER.EXEAdded by the Troj/BeastDo-Y TROJAN!
    explorerXexplorer.exeAdded by the PWS.ZAYA TROJAN! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is installed in a C:\Windows\System\Service folder. Moreover, the valid explorer.exe will only figure among the startups if you intentionally placed it there!
    EXPLORERXsys.exeAdded by the TROJ/SILLYFDC-A TROJAN!
    ExplorerXconfig_.comAdded by the W32/Floppy-D WORM!
    ExplorerXdrv.exeAdded by the Troj/Small-FD TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    explorerX[path to trojan]Added by Troj/Agent-EU TROJAN!
    Explorer LoaderXexplr32.exeAdded by the AGOBOT.N WORM!
    Explorer LoaderXexplorerl.exeAdded by the W32/Sdbot-ADI WORM! Note: This is not the legitimate Windows Process Explorer.exe (Notice the difference in the spelling.) This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Explorer lptt01 or Explorer ml097eXexplorer.exeVariant of the RapidBlaster parasite (in an "explorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Explorer which has the same executable name
    EXPLORER MICROSOFT SYSTEMXexplore.exeAdded by a variant of the WIN32.RBOT WORM!
    Explorer softXexplorer.pifAdded by the W32/Rbot-APK WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Explorer softXexplorer.comAdded by the W32/RBOT-ARM WORM!
    Explorer UpdaterXIEXPLORE.exeAdded by a W32/Sdbot-WO worm infection
    explorer.exeXexplorer.exeAdded by the Troj/Agent-EW TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Also, do not confuse this with the valid "explorer.exe" which is located in C:\Windows or C:\Winnt.
    Explorer32XExpl32.exeAdded by the HACKTACK VIRUS!
    Explorer32Xexplorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
    Explorer32Xefsdfgxg.exeAdded by the Troj/Clicker-AA TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Explorer64Xefsdfgxg.exeAdded by the Troj/Clicker-AA TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    exporetXwinset.exeAdded by the TROJ/QQPASS-I TROJAN!
    Exshow95UEXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
    External DependenciesXExternal.exeAdded by the W32.Mytob.EC WORM!
    ExtraDNSUExtraDNS.exeExtraDNS - DNS configuration tool
    Extranet AutoDial?AutoExt.exeNortel Networks Contivity Extranet Switching Software
    Extreme Messenger for AIMUExtremeMessenger.exe Extreme_Messenger - an extension for the AIM Instant Messenger client
    ExxtremeHelperDemon?exxdemon.exeCreative Exxtreme graphics card related ?
    Eye Tide LauncherNoneeyetideone.exeNascar wallpaper
    EZ FirewallYca.exeeTrust EZ_Armor Internet Security
    ezagentNezagent.exeEzVCR recording software for the ASUS TV FM card. Available via Start -> Programs
    EzButtonNEzButton.EXEEZbutton is a quick launcher for the Media player app that comes with certain laptops. Typically installed in a C:\Program Files\EzButton folder
    EZDeskNEZDESK.EXEUtility that remembers icon locations for each user and resolution. Available here
    EzEjMnApNEzEjMnAp.exeFor IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs
    eZmmodXmmod.exeeZula TopText adware
    EZNORUN?EZNORUN.EXEEasy Internet related?
    ezShieldProtector for PxorezPS_PxYezSP_Px.exe, ezSP_PxEngine.exeEngine that allows PrimoDVD from Veritas (was Prassi) and Drag\'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings
    EZSMART AppUezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
    ezulaXeZmmod.exeeZula TopText adware
    eZulaMainXeZulaMain.exeeZula TopText adware
    eZuluMainXeZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
    eZWOXwo.exeeZula TopText adware
    E_S10IC2UE_S10IC2.exeEpson Stylus printer monitor - for checking ink levels, etc.
    E_S23UE_SICN03.exeEpson printer status monitor - for checking ink levels, etc.
    E_S4I2G1?E_S4I2G1.EXERelated to the Epson Stylus CX5400 printer/scanner/copier. What does it do and is it required?
    E_SOEIC1UE_SOEIC1.exeEpson Stylus printer monitor - for checking ink levels, etc.
    F-Secure 2006Yfspex.exe F-Secure Anti-Virus automatic updater
    F-Secure Management AgentUFSMA32.EXEF-Secure Antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products
    F-Secure ManagerYFSM32.EXEF-Secure Antivirus - carry out scheduled virus scans automatically
    F-Secure Startup WizardYFSSW.EXE F-Secure antivirus
    F-Secure TNBYTNBUtil.exe F-Secure antivirus
    F-StopWYF-StopW.exeF-Prot anti-virus background scanner by F-Risk Software
    f1Tray.exeUF1TRAY.EXESystem Tray icon for FusionOne’s MightyPhone software. MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer.
    f607Xf607.exeAdded by the URAT.B VIRUS!
    f73cdc8ee94eXbtsendto.exeAssociated with mysearchnow.com/searchbar.html
    FamilyKeyLoggerUcisvc.exe"Family Keylogger - is your best choice, if you want to know what other users on your machine are typing". Note! - this is not the cisvc.exe service.
    Fantasia injectorXwincfg.exeAdded by the AGOBOT.US WORM!
    fapmon?fapmon.exeFair Access Policy monitor for DirecPC/DirecWay internet access
    farmmextXfarmmext.exe Transponder parasite updater/installer
    FashXFash.exe Ibis toolbar adware related
    FastNfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
    FAST DefragNFAST2.EXE FastDefrag defragmenting software
    Fast HomeXsvcnvt.exeReported by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Delf.ks This file may be found in the System folder on 9X machines, however as of this writing it has only been seen in the System32 folder.
    Fast SearchXsvcnv.exeHomepage, Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
    Fast startXNtut.exeAdded by unidentified adware - recognized by Kaspersky antivirus as Trojan.Win32.Favadd.i
    Fast startXsvcnt.exeAdded by unidentified adware - recognized by Kaspersky antivirus as a variant of the Win32.Favadd TROJAN!
    FastCacheUfc.exeFastCache from AnalogX - speeds up browsing by resolving DNS requests locally
    FastStartXntnut32.exeAdded by the StartPage.L TROJAN!
    FastStartXsvcnut.exeBrowser hijacker - a variant of the STARTPAGE.L TROJAN!
    FastStartXsvcnut32.exeBrowser hijacker - a variant of the STARTPAGE.L TROJAN!
    FastTrack AcceleratorNSPEED UP.EXEFastTrack Accelerator - "speedup" utility for programs that use the FastTrack network such as KaZaA Media Desktop, Grokster and Morpheus
    FastUserNfast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
    FatPipeUDHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
    Fatpipe DialerUfpdialer.exeDialler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
    fatrecovXfatrecov.exeAdded by the TrojanSpy.SCKeyLog.j keylogger - A keylogger or keyboard logger is a type of surveillance software that has the capability to record every keystroke you make to a log file, which can then be sent to a specified receiver.
    FaxCenterServerUfm3032.exe FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark, MCI, Lotus, My Software, Broderbund, Traffic Software and many others.
    FBDirectUFBDirect.exeSoftware that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
    FBI?FBISM.exeCompaq related but what does it do?
    fcXrunfc.exeAdded by the CAMPURF VIRUS!
    FCEngineXFCEngine.exe CASClient adware variant
    FDD SYSTEMXFdd.exeAdded by the W32/Mytob-FO WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Fdr Command ModuleXsp2.exeAdded by the SDBOT.WP WORM!
    FD_SAPUFD.exeReported to be the autopassword program from the Sony Microvault thumb drive.
    feelalrightXmirc.exeAdded by the W32/IRCFlood-M WORM!
    FEELitDeviceManagerUfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
    fegozeXSVCH0ST.EXEAdded by the GRAYBIRD.D VIRUS! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    Fellowes ProxyUR3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
    Fen StartupsXfensvc32.exeAdded by the W32.RANDEX.CCF WORM!
    FerrariWallPaperUFerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
    ffisXffisearch.exe iSearch "Desktop Search" hijacker
    FG1_00Ufrntgate.exeFrontGate MX - e-mail spam blocker
    fGQEGqHOMEXgwwgtp.exeAdded by the BACKDOOR.RANKY.J TROJAN!
    FhtisxkUfhtisxk.exeXtraKeys - keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove via Spybot S&D (for example)
    FieldForms SyncUSyncService.exeResco FieldForms . A solution for building of mobile forms that can be viewed or filled in on the run, on a wide range of mobile devices. Supports Microsoft Access databases, and provides for synchronization of other data as well.
    FiendlyTypeXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    FILEXabcdefg.exeAdded by the W32.Kelvir.DD Worm!
    file indexing service?msfindfile.exeNew version of MS FindFast and still a resource hog?
    file laoder configurationXrnd32.exeAdded by the RBOT.BQJ WORM!
    File SystemXtaskmqrs.exeAdded by a variant of the WIN32.TOXBOT/CODBOT WORM!
    File System ServiceXwmiprvsc.exeAdded by the AGOBOT-HZ TROJAN!
    File0_0XMD1.exeAdded by the Troj/Dloader-OR Trojan!
    File1XDia Claro.htmAdded by the Troj/Dloader-OR Trojan!
    FileFreedom_PluginNwtm.exeFileFreedom peer-to-peer sharing program
    FileManager32XWscript.exe ..ChkMgr32.vbsAdded by the NOTUP.A VIRUS!
    FileSoftXWscript.exe UpdataFiles.vbsAdded by the SST.B VIRUS!
    filitX(Path of the trojan exe)Added by the Troj/Perda-F or Troj/Perda-G TROJAN!
    FilterGateUfiltergate.exeFiltergate internet filtering software - filters sounds, popup ads, background sound and other unnecessary website items
    FilterguardUFiltrgrd.exeAn icon located in the lower left of the screen and looks like a lifesaver. This icon is a “short-cut” to access the basic features of SOS-Guardian, SOS-KidProof Lite, SOS Best Defense and SOS Pro such as Internet filtering utility. You can access this menu by “right-clicking” on the icon
    FindXfind.exeAdded by the W32.OPANKI WORM!
    Find FastXFindfast.exeComplete utter waste of space! Part of MS Office - searches disk drives for Office file types to make opening them easier
    Find Virus Launch ProgramYfvlaunch.exePart of Dr. Solomon's Antivirus
    FindHackX(Pathname of the Trojan exe)Added by the W32/Kelvir-BA TROJAN!
    FinePrint Dispatcher vxNFPDISPxA.EXEFinePrint - virtual printer for use with any printer. Search for "dispatcher" here for more information. If removed, it will re-install when program is run - hence the Y recommendation
    FineReader7NewsReaderProNAbbyyNewsReader.exeABBYY FineReader OCR software
    FireFoxXfirefox.exeAdded by W32/Rbot-ATP WORM!
    FireFox Service DriversXssmss.exeAdded by a variant of the W32/SDBOT WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item.
    FirewallX wmlaunch .exeAdded by the W32.ELIPTER.A or W32.ELIPTER.B or W32.ELIPTER.D WORM!
    FirewallXSP2 UPDATE.exeAdded by the W32.ELITPER.E WORM!
    FirewallXFirewall.batAdded by the VBS.Ypsan.G WORM!
    firewallXfw_304.exe /iAdded by Troj/Bdoor-JQ TROJAN!
    Firewall Client Connectivity MonitorYISATRAY.EXEMS Internet Security and Acceleration Server - see here
    Firewall Sp2 systemXsys32Conf.exeAdded by the W32/Rbot-ABT WORM!
    Firewall Update System1XWinedowsUpdater1.exeAdded by the W32/RBOT-ARU WORM!
    Firewall UpdaterXmsnupdateit.exeAdded by the W32/RBOT-AAQ WORM!
    FirewallStartupUFirewallstartup.exeInnovative Solutions The user can choose whether or not to monitor installs when loaded.
    FirewallSvrXFirewallSvr.exeAdded by the W32.NETSKY.X or W32.NETSKY.Y WORM!
    firewall_antiXfirewall_anti.exeAdded by the Trojan.Fantibag.A or Troj/Netdeny-B TROJAN!
    FireWire DriverXsamx.exeAdded by the BACKDOOR.SDBOT.AE WORM!
    FireWire ServiceXnvscv32.exeAdded by a variant of the W32/SDBOT WORM!
    FireWire ServicesXnvcsv32.exeAdded by a variant of the W32.SPYBOT WORM!
    First Home PageXhttp://find.naupoint.com Naupoint browser hijacker
    FIX =XWinFIX1.0.vbsAdded by the VBS/Gormlez-A Worm!
    Fix-itYmxtask.exePart of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard, intellicluster, anti-virus, or autoupdater. Otherwise not required
    Fix-it AVYmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
    FixniceXvcvw.exeAdded by the SDBOT TROJAN!
    FjMenuUFjMenu.exeFrom the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable.
    fkSysMonNfksysmon.exefkWrae SysMon - system monitor - "displays the current memory consumption, CPU and resource usage, date, time, Windows uptime, IP address and a lot more"
    FlaCPYXflacpy.exe FlashEnhancer adware variant
    FLASH32?-flash32.exe??
    FlashEncUFlashEnc.exeSupplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission. which is a pain. No need for it if you do not want these features
    Flashget Download ManagerXFlashget.exeAdded by the W32/RBOT-AGZ WORM!
    FlashPath Status or FlashPath MonitorNSDSTAT.EXE FLSHSTAT.EXESystem Tray icon that you can\'t get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
    FlenCPYXflencpy.exe FlashEnhancer Adware variant
    FlexicdUFlexicd.exeCD player - part of the Win95 Power Toys
    FLMK08KBUMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keys
    FLMOFFICE4DMOUSEUmoffice.exeMouse properties for Logytech Typhoon Office Mouse
    FLMTRUSTKB?KbdAp32A.exeKeyboard utility for a Trust brand keyboard. What does it do and is it required?
    FLMTRUSTMOUSE?mouse32a.exeMouse utility for a Trust brand mouse. What does it do and is it required?
    FlnCPYXflncpy.exe FlashEnhancer adware variant
    FLooDNeTXFLooDeR.exeAdded by the FLOODNET VIRUS!
    Floppy MasterX(Path of the Trojan exe)Added by the Troj/Zonit-F TROJAN!
    Flow Go TV?flogotv.exe??
    flpsXflps.vbsAdded by the BYRON VIRUS!
    flpycntlXflpycntl.exeAdded by a CRYPTER.C trojan infection
    FltProcessYmsinet.exePart of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done
    FlyswatDesktopXflydesk.exeAdvertising spyware
    FmctrlTrayUFmctrl.EXEGenius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
    fmnwebassistXfmnwebassist.exeAdware popup generator
    FMStartUFmstart.exeGFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks, allows all users to send and receive faxes right from their desktop
    fmszXfmsz.exeAdded by the FMSZ trojan
    fnmwebassistXfnmwebassist.exe WinPL adware
    Focus?Focus.exeISDN configuration wizard?
    Folder ServiceXwssdtu.exeAdded by the MANIFEST VIRUS!
    Folder ViewUfolderview.exe Folder_View enhances the Windows file Explorer by making all folders you need available in a single click.
    Folding@homeNWINFAH.EXEFolding@Home is a distributed computing project which studies protein folding, misfolding, aggregation, and related diseases - must be running in order to access the internet to upload to the servers. Available via Start -> Programs
    FoneSyncSystemTrayNFoneSyncSystemTray.exeSystem Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
    FontFixXfontfix.exeAdded by an unidentified VIRUS!
    FontsLoaderXldfnt32.htaUnidentified malware
    FONTVIEWXFONTVIEW.EXEAdded by the OPASERV.T VIRUS!
    foobin lptt01 or foobin ml097eXadaware.exeVariant of the RapidBlaster parasite (in a "foo1" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    FoolProofYfpwinldr.exeFoolProof Security PC security software from SmartStuff
    FoolProofSweepY??Part of FoolProof Security PC security software from SmartStuff
    ForbesNForbesAlerts.exeForbes Business News Alerts - displays business news headlines in a little window on the screen
    ForceShowXrundll32.exe QaBar.dll, ForceShowBarAdultLinks/QAbar parasite related
    Forget Me NotNAGRemind.exeCalendar reminder part of American Greetings® CreataCard®
    Fortis Secure Layer ConfigUcseinst.exeFortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information.
    FotoStation Easy AutoLaunchNFotoStation Easy AutoLaunch.exeInstalled with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
    Foul PXUFoulPX.exeFoul PX, Optusnet usage stat checker
    FourthDayUFourthDay.exeThe Fourth Day - "astronomical clock and almanac for your system tray"
    foxdhXfoxdhend.exeAdded by the PWSteal.Menghuan TROJAN!
    foxdhXfoxdh.exeAdded by the Troj/GWGhost-Q TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    foxrxjhXfoxrxjh.exeAdded by the TROJ/GWGHOST-T TROJAN!
    foxwudy9912Xservice.exeAdded by the TROJ/BANCOS-BT TROJAN!
    FP LoaderYloadfp.exeFoolProof Security - PC security software from SmartStuff
    FPWGMWZD?FPWGMWZD.exe??
    FpxNmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
    FranceXsvchost.exeAdded by a variant of W32.MIMAIL.C WORM! **Note this is not the valid svchost.exe as described for Win2K or WinXP
    FrapsNfraps.exeFraps Real-Time Video Capture software
    Free Download ManagerUfdm.exe"Free Download Manager" See here
    Free Downloads Monitor?fdcmon.exe??
    Free Ram OptimizerUfro.exe Free_Ram_Optimizer monitors your memory, and frees up ram if it falls below a certain minimum.
    FreedomYFreedom.exeZero Knowledge Freedom - Anti-Virus, Personal Firewall and Parental Control, it also blocks ads, safeguards your personal information, encrypts your passwords, and much more
    FreeMem ProUFMEMPRO.EXESome users swear by memory management utilities such as FreeMem Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
    FreeMemVn2UFreeMem.exeSome users swear by memory management utilities such as FreeMem but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
    FreeMP3downloadXrundll32.exe MSA64CHK.DLL, DllMostrar MatrixDialer related
    FreeRAM XPUFreeRAM XP Pro x.exeSome users swear by memory management utilities such as FreeRAM XP Pro but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind. "x" indicates the version number
    FreeRAM XPUFREERAM XP PRO 1.40.EXE FreeRAM_XP is a freeware application to free and defragment your computer’s RAM
    freestyleXlockx.exeAdded by the W32.Loxbot.A WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, rootkit type stealth involved.
    freesurferUfs20.exeEMS Free Surfer mk II - pop-up stopper
    Fresh DesktopUfreshdesktop.exe Fresh_Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals.
    FridaysInHellInstaller?FridaysInHellInstaller.exe??
    FriendlyTypeXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    FriendlyTypeNameXServices.exeAdded by NEVEG.A or NEVEG.B WORM! - Note - this is not the valid Windows Service Controller services.exe process
    FriendlyTypeNameXwinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!
    FriendlyWebQuick-LaunchNSELFCERT.EXEselfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
    FRISK FP-SchedulerUF-Sched.exeScheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis
    FRITZ!DSL Startcenter?StCenter.exeFRITZ! ISP software "StartCenter" User interface that allows you to manage, tweak and diagnose many aspects of your internet connection - is it required?
    FRITZ!webProtectUFwebProt.exeFirewall included in FRITZ! ISP DSL software
    Fromine WinPopupNwinpopup.exeInstant Messenger program
    FrskXfrsk.exeUnidentified adware downloader trojan
    FRW_EXEYFRW.EXEConSeal Signal9 firewall - now McAfee Personal firewall
    frxmxinsYfrxmxins.exeATI 3D Studio MAX/VIZ driver
    FS AgentXfagent.exeAdded by the TROJ/VOLVER-B TROJAN!
    fsaaYfsaa.exe F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers
    FSCBossNFSCBoss.exe Free_Store_Club shop online software
    FSDPSRV?FSDPSRV.exe??
    FSHXsvcnva.exeMalware, detected by Ewido_Security_Suite as TrojanDownloader.Delf.ks
    fspUfsp.exeFolder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents
    fsprYFolderShield.exeFolder Shield - hide personal files and folders
    FSScrCtlNFSScrCtl.exeScreen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
    fsservUfserv.exeFarsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time
    FSWXFSW.exeFreeScratchAndWin parasite
    FSWebServerUfsws.exe Easy_File_Sharing_Web_Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services.
    FtkCPYXftkcpy.exe FlashEnhancer adware variant
    FTMSFLT(USB)UFTMSFLTU.EXEFujitsu\'s Touch Panel Message Notifier
    FTP FOR WINDOWSXftpwin32.exeAdded by a variant of the WIN32.RBOT WORM!
    FTPGraberXFTPGraber.exeAdded by the DLOADER-DT TROJAN!
    FTPManagerNFTPDM.ex Robust_FTP is a Windows-based file transfer client application that transfers files between a user’s local PC and another, remote computer system connected via a modem and telephone lines or by a local-area network (With upload transfer resume and download transfer resume) - can be started manually.
    FtpqueueUFtpsched.exePart of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers
    Fujitsu MenuUFjMnuIco.exeFrom the "Fujitsu Menu" tray icon you have instant access to the Control Panel, Tablet pc keyboard, Tablet and pen settings, Fujitsu display controls, brightness control, sounds and audio devices, capture screen, capture window, Organize favorites, power options, printers and faxes, LCD brightness MIN, LCD brightness MAX, Enable/disable Button Panel and the Fujitsu menu settings, which are customizable.
    fukerserviceXfukerz.exe Win32.Rbot worm variant
    FUKLBARXbar.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    fvekXfvek.exeAdded by the Troj/Drivol-A TROJAN!
    FWDMON.EXEXfwdmon.exeAdded by the Troj/Proxy-S TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    fwenc.exeYfwenc.exeCheck Point SecuRemote VPN client - "dynamic and fixed IP addressing for all ISP services - dial-up, cable modem, or DSL - the ideal solution for telecommuters and mobile workers"
    Fwr Command ModuleXfwr.exeAdded by a W32/Sdbot-PP worm infection
    fwrastrcNfwrastrc.exeDial-up software for Friendly Technologies/1NationOnLine free ISP
    fwserviceNfwserviceeAcceleration Stop-Sign related; not recommended; see note
    FXXieloader.exeAdded by the WIN32.SMALL.RR downloader TROJAN!
    fxredirUfxredir.exeCanon MultiPASS fax redirector
    f~aXra32.exeAdded by the BackDoor-CAY TROJAN!
    g.exeXg.exeAdded by the Backdoor.Graybird.Q TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    G00123X(worm filename)Added by the BUGBROS VIRUS!
    G0mez =XG0mez.vbsAdded by the VBS/Gormlez-A Worm!
    G3XGSMedia3.exeMalware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
    Gadu-GaduNgg.exePolish language Instant Messaging client
    Gadwin PrintScreenNPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current window
    GAELICUM.EXEXGAELICUM.EXEAdded by the Troj/Penta-A TROJAN!
    gah95on6Xgah95on6.exe ShopAtHome/SAHagent adware
    gaimUgaim.exe Gaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks.
    GainwardUTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
    gameXshit.exeAdded by the Netclap Gold backdoor TROJAN!
    Game DeviceNJOYUPDRV.EXEGenius game controller profile activator
    Games AccelerationXsvshost.exe EasySearch adware
    Games AccelerationX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Games toolbarXrundll32.exe [path] tbGame.dll" DllShowTBTopconverting.com/180Search "Games Toolbar" adware
    GameSpotNkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    gameutil.exeUgameutil.exePart of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
    GammaHotKeysUsetgamma.exePart of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop
    gAnonymousPEUGetAnonymousP.exe GetAnonymous will prevent any attempt of private information becoming observed by anyone on the internet.
    gaSrvXgaSrv.exeAdware downloader, identified by Panda antivirus as Trojan.Downloader.ALQ
    gaSrveXgaSrve.exeAdware downloader, identified by Panda antivirus as Trj/Downloader.ALQ
    Gate Personal FirewallXSystpl.exeAdded by the RBOT.ADC WORM
    Gate Personal FirewallXSystpl.exeAdded by the RBOT.ADC WORM
    GatorXgator.exeSpyware - see here for removal instructions
    Gator eWalletXgator.exe Gator eWallet - also see here
    Gay_Sexy_**XGay_Sexy_**.exePremium rate adult content dialer (where * is a random char)
    GazelDisplayUgsyno.exeBT Digital Access USB - Gazel ISDN installation System Tray icon
    GBTray or GoBackUGBTray.exeSystem Tray icon access to Roxio\'s (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    gcasDtServXgcasDtServ.exeAdded by an unidentified WORM or TROJAN. - Note - there IS in fact also a Microsoft Antispyware process bearing the same name, but it will not figure among the startup items!
    gcasServUgcasServ.exeMicrosoft, formerly Giant AntiSpyware
    gcasServXrealsched.exeAdded by a variant of the WIN32.TACTSLAY.A TROJAN! - NOTE - do NOT confuse with the Real Player executable as described here
    GCC Reminder?gccrem.exeAssociated with AcraMax Greeting Card Creator. Is it a registration reminder?
    GCSNGrabClipSave.exeGrabClipSave screen capture tool
    GDAXX(path to file)Added by the BACKDOOR.RANKY.K TROJAN!
    gdien32Xgdien32.exeAdded by the Troj/Singu-P Trojan!
    GDMgr.exeUgdmgr.exe GuardMon is a commercial spyware program designed to monitor all forms of user activity on a computer
    GDriveNGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
    GearboxNconfsvr.exeNTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here
    GEARsecNgearsec.exeInstalled by Apple Quicktime package - iPod/iTunes CDRW support. Can be disabled if you only require Quicktime player
    GEDZACXGEDZAC.exeAdded by the GEMEL VIRUS!
    GemStRmWNGemStRmW.exeFor a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually
    gencrootXgencroot.exeAdded by the Troj/HacDef-X TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Gene USB MonitorUUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives.
    general lptt01 or general ml097eXgeneral.exeVariant of the RapidBlaster parasite (in a "General" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Generic host proccess for windowsXSVCHOSTS.EXEAdded by the W32/SPYBOT-GQ WORM!
    Generic Host ProcessXSCHOST.EXEAdded by the W32/RBOT-NC WORM!
    Generic Host ProcessXsvchost.exeAdded by the Troj/Dloader-NX Trojan!
    Generic Host Process for Win32 ServicesXntspcv.exeAdded by the SDBOT.S WORM!
    Generic Host Process for Win32 ServicesXintspvc.exeAdded by the DINFOR.D VIRUS!
    Generic Host Process for Win32 ServicesXwinsvc.exeAdded by a W32/Sdbot-O worm infection
    Generic Host Process for Win32 ServicesXbazzi.exeAdded by the W32.AHKER.E WORM!
    Generic Host Process for Win32 ServicesXwinsvc32.exeAdded by the W32/SDBOT-P WORM!
    Generic Host Process326a System BackupXscvhost326a.exeAdded by a variant of the W32/SDBOT WORM!
    Generic Host ServiceXlshost.exeAdded by a RBOT.LU worm infection
    Generic Service ProcessXregsvc32.exeAdded by the GAOBOT.UJ or GAOBOT.UL WORMS!
    Generic Service ProcessXregsvc32.exeAdded by the W32.GAOBOT.UJ WORM!
    Generic Service ProcessXserv1ces.exeAdded by the W32/Agobot-JK WORM!
    Generic Service ProcessXnvsvc.exeAdded by the AGOBOT.BY WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here
    Generic Services ProcessXregsvc32.exeAdded by the W32.Gaobot.SY worm
    Genie USB MonitorYUSBmonitor.exePort monitor for an external USB hard drive. Required to enable access to the drive
    Geography TX 1.0 NTXCompuSpeed.vbsAdded by the VBS/NEWLEY-A WORM!
    Gerenciamento de arquivos do WindowsXWinmod32.exeAdded by the Troj/Dloader-WG TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Gestionnaire de disques universelXsysoobe.exeAdded by the Troj/Toader-A TROJAN! Note: This trojan file is found in the System\oobe (95/98/Me) or System32\oobe (Nt/2000/XP) folder.
    Get SmileNgetsmile.exePuts smilie faces in your E-mail. Run manually when required
    GetRight Tray IconNGETRIGHT.EXEGetRight from Headlight Software - download manager for resuming downloads and choosing multiple download locations. The freeware version is/was spyware. The registered version isn't if you don't install the Aureate/Radiate software. Available via Start -> Programs
    GetTheMusicXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    GhostStartServiceNGhostStartService.exeRequired to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard
    GhostStartTrayAppNGhostStartTrayApp.exeSystem Tray access to Norton Ghost - added from the 2003 version
    GhostSurfDelSatellite?DeleteSatellite.exe SpyCatcher spyware remover related - what does it do and is it required?
    gigabit.exeXgigabit.exeAdded by the BEAGLE.U WORM!
    GigaByteXCheatle.exeAdded by the SHODI.B VIRUS!
    Gilat SOM EnumeratorYdllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    GilatFTCYftc.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    GinaDllXntgina.dllAdded by a ANIG.A worm infection
    GisdnLog?gisdnlog.exeBT Digital Access USB
    Glass2kUGlass2k.exe"Glass2k is a small little program that allows Win2K/XP users to make any window transparent"
    GLF Network Lan MonitorXNPFMNTOR.exeAdded by the W32/RBOT-AGY WORM!
    GlideYGlidew32.exeCirque touchpad driver
    GLSetIT32Xmsiexec16.exeAdded by the OPTIX PRO series of VIRUSES!
    GLSetIT32Xisass.exeAdded by a variant of the OPTIX PRO series of VIRUSES!
    GLSetT32Xsmsiexec.exeAdded by the TROJ/OPTIX-D TROJAN!
    gluon?gluon.exeIn a gluon/bin sub-directory
    glvXglv.exeAdded by the DLOADER-NG TROJAN!
    GMedia2XGSM2.exeMalware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
    GMedia2XGSMedia3.exeMalware downloader - detected by Kaspersky antivirus as Trojan.Win32.VB.ux
    GmouseYGmouse.exeAmouse mouse driver - required if you use non-standard Windows driver features
    GnetmousUgnetmous.exeGenius NetScroll mouse driver - required if you use non-standard Windows driver features
    GNP Generic Host ProcessXsvchost.exeAdded by the Troj/Zapchas-R NOTE - This file is placed in the C:\Winnt\System or C:\Windows\System folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    GNP Generic Host ProcessXsvchost.exeAdded by the Troj/Zapchas-AA TROJAN! Note: This one replaces svchost.exe in the System32 folder with a copy of Mirc on (NT/2000/XP) systems and just adds svchost.exe to the System folder on (95/98/ME) systems.
    Go!ZillaXgozilla.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
    Go!Zilla Monster DownloadsXGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spyware
    GoBackUGBMenu.exeRoxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    GoBack Polling ServiceUGBPoll.exeRoxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users
    GoBack Tray IconUGBTray.exeSystem Tray icon access to GoBack (above)
    GOGXGOG.exeAdded by the PHILIS.B VIRUS!
    goidrXgoidr.exe Goidr adware
    Goldensoft_MndlSvrUMndlSvr.exeGoldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
    GolumXservices.exeAdded by the GOLUM.A TROJAN! - Note - this services.exe file is placed in a Winnt\System32\Golum or Windows\System32\Golum subdirectory, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    golummXservices.exe CoolWebSearch parasite variant. Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    googleXgoogle.exeAdded by the W32/Rbot-AMW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Google Desktop SearchUGoogleDesktop.exe Google_Desktop_Search - "a desktop search application that provides full text search over your email, computer files, chats, and the web pages you've viewed. By making your computer searchable, Google Desktop Search puts your information easily within your reach and frees you from having to manually organize your files, emails, and bookmarks."
    Google Earth ViewerNGOOGLEMAPS.EXE Google_Earth "combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips."
    google Intrenet ExplorerXgoogle.pifAdded by the W32/RBOT-ARA WORM!
    google toolbarXggtb32.exeAdded by the W32/AGOBOT-RR WORM!
    GoogleDCClientNGoogleDCC.exeGoogle Compute Client - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing"
    googletalkUgoogletalk.exe Google_Talk "enables you to call or send instant messages to your friends for free–anytime, anywhere in the world". Can be launched manually.
    GoToMyPCUg2svc.exeExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser
    GotSmileyXGotSmiley.exe Gator GotSmiley - adware based, also see here
    gouday.exeXreadme.exeAdded by the BEAGLE.C WORM!
    GRANgra.exeLooks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup Utility
    gramdate?2Stop.exe??
    Graphic DriverXsmss32.exeAdded by a variant of the WIN32.RBOT WORM!
    Graphic LoaderXntvdm32.exeAdded by a variant of the WIN32.RBOT WORM!
    Gravis AppawareloaderUdbserver.exeLooks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
    Gravis Xperience Driver SupportUGrxp4exe.exeDriver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used
    GrayPigeonServer2.0XG_Server2.0.exeAdded by the Troj/Feutel-AD TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    GrdSys32?GrdSys32.exeX-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?
    Greetings WorkshopNGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
    gremierXwscript.exe gpremier.vbsAdded by the GPREMIER VIRUS!
    GremlinXintrenat.exeAdded by the DOOMJUICE VIRUS!
    GroksterNGrokster.exe Groster Peer-To-Peer File Sharing program
    GrpConvYgrpconv.exeMicrosoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article,
    GsAdsXgms2.exe PacerD_Media/Pacimedia.com adware component
    Gscbc?Gscbc.exe??
    gshpXzzgshp.vbsHomepage hi-jacker
    GsiconexeNGsicon.exeADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities
    GsiFinal?rundll32 gspndll.dll,postInstall finalUSB DSL modem related - [what does it do and is it required in startup?
    GSISETUP?[path] GsiInst.exe INSTALL [path] V205Res 13BT Voyager ADSL modem related - what does it do and is it required?
    GSOrganizerNGSOrganizer.exeGoldenSection Organizer - personal information manager
    gssomaticXgssomatic.exeSearchcentrix hijacker
    GStartupXGMT.exeGator spyware component - see here
    gsvXgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!
    GtwatchNgtwatch.exeAssociated with a Mustec scanner and not required
    GuardianNCMGrdian.exeMcAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
    guarnsetXguarnset.exe Adlogix adware
    GuruNetUGuruNet.exe GuruNet lets you click on any word on your screen to get the relevant information you want.
    GustavVEDX(random filename)Added by the OPASERV.H VIRUS!
    gvagfxjXrundll32 ...gvagfxj.dllUnidentified adware, spyware or virus
    gw port controllerYPORTCT95.EXEFrom a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by Samsung
    GWInkMonitorNGWInkMonitor.exeGateway ink monitor - makes an annoying popup that says your printer may be running out of ink, do you want to buy some!
    GWMDMMSGNGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
    GWMDMpiUGWMDMpi.exeUsed with internal modems on Gateway PCs such as the 450SX Notebook. Required for audio settings to be maintained and does not remain in memory once run. See here for more information
    gwumUgwum.exeGigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"
    gyy?gyy.exePossibly Gator (and therefore spyware) related?
    G_Server.exeXG_Server.exeAdded by the TROJ/FEUTEL-C and Troj/Feutel-J TROJANS!
    G_Server1.2.exeXG_Server1.2.exeAdded by the Troj/GrayBird-Z TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    H/PC Connection AgentUWCESCOMM.EXEActive sync for use with Windows CE based palm PC
    h4te Service DriversXh4te.exeAdded by a variant of the WIN32.RBOT WORM!
    hachimitsu-lemonXhachimitsu-lemon.exeAdded by the HACHILEM TROJAN!
    hagentXavp.exeAdded by the "Herman Agent" remote access TROJAN!
    HalifaxHowardClusterUskinkers.exe Howard_the_Weatherman desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages
    HaMFrontPanelUhampanel.exeDisplays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget, but otherwise pointless
    Handy Backup 3.9Uhbagent.exeHandy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers
    Hardware DoctorUHwdoctor.exeWinbond Hardware Doctor - as included on some motherboard using Winbond\'s hardware monitoring chips. Displays fan speeds, voltages, temperatures. Only required if you\'re concerned about your system temperature - typically for "overclocked" systems
    Hardware Monitor ServiceXmshms.exeAdded by the Troj/Wollf-A TROJAN!
    Hardware ProfileXhxdef.exeAdded by a variant of the LOVGATE WORM!
    Hardware Sensors MonitorUhmonitor.exeUtility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
    HareUhare.exeHare - improve and optimize performance of desktop/laptop PCs
    HATAPEX(Pathname of the Trojan exe)Added by the Troj/Banker-QF TROJAN!
    HawkEyeUHAWK_95.EXEControl Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
    HawkEye IV Control PanelUHAWK_32.EXEControl Panel application for the old Number Nine graphics cards to change resolution, colour depth, etc. Available via Start -> Programs
    Hawking HWU54G UtilityUHWU54G.exeRelated to Hawking Technologies HWU54G Mini Wireless-G USB Adapter
    HbinstXHbinst.exeHotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
    HC ReminderNhc.exeFor Compaq PC's. Help Compiler, crunches help database, will run without being in startup when needed
    HCDetectNHCDetect.exeMS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification, detection, and Internet Connection Sharing (ICS) taskbar icon. Not required - network can be set-up manually, also has a known memory leak problem
    hcenterUtgcmd.exeSee also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
    hclean32.exeXhclean32.exeTROJAN downloader/installer! - assumed to be associated with Wareout, malware masquerading as a spyware and dialer remover, see here
    HcontrolUhcontrol.exeHotkeys on an ASUS Notebook. Only required if you use the additional keys
    HDAudio Driver 1.0X(random).exeAdded by the Troj/Teadoor-D TROJAN!
    HDAudio Driver 2.0X(random).exeAdded by the Troj/Teadoor-E TROJAN!
    HDDHealthUhddhealth.exe HDD_Health is a "full-featured failure-prediction agent for machines using Windows 95, 98, NT, Me, 2000 and XP. Sitting in the system tray, it monitors hard disks and alerts you to impending failure."
    HDDlifeUHDDlife.exe HDDlife checks the health of your hard drives at regular intervals and informs you about the results of these checks.
    HDhelp?tbhdhelp.exeAssociated with Philips Edge series soundcards. Is it required?
    HDtrayNHDtray.exePhilips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
    he3bbcffXrundll32.exe (path) he3bbcff.dll,EnableRunDLL32 LZIO.com adware downloader
    he3e3fc4Xrundll32.exe (path) he3e3fc4.dll,EnableRunDLL32 LZIO.com adware downloader
    HELLBOT TESTX1hellbot.exeAdded by the W32.MYDOOM.BO WORM!
    hellodollyXshost.exeAdded by the YODO VIRUS!
    helloworldXnb32ext2.exeAdded by the W32/MYDOOM.BV WORM!
    helloworldXnb32ext3.exeAdded by the MYTOB.JT WORM!
    Help?helpext.exe??
    Help Temp FilesXnetreg.exeAdded by the W32/FORBOT-EM WORM!
    helpctl.exeXhelpctl.exeAdded by the GASLIDE VIRUS!
    HelperXeschlp.exeAdded by the BLASTER.T VIRUS!
    HELPERXNetherlands.exe AsdPlug premium rate adult content dialer variant
    HELPERXgreece_nm.exe AsdPlug premium rate adult content dialer variant
    HELPERXnew_zealand.exe AsdPlug premium rate adult content dialer variant
    HELPERXsweden.exe AsdPlug premium rate adult content dialer variant
    HELPERXfrance.exe AsdPlug premium rate adult content dialer variant
    HELPERXcanada.exe AsdPlug premium rate adult content dialer variant
    HELPERXtemp532.exe AsdPlug premium rate adult content dialer variant
    helper.dllX[path] rundll32.exe [path] helper.dllCnsMin (Chinese_Keywords) related
    HelpExp.exeXHelpExp.exeAttune HelpExpress. Disable - see here
    helpmanagerXspoler.exeAdded by the RANDEX.J VIRUS!
    helpwXhelpw.exeadware downloader
    henYAdded by the TARNO.G VIRUS!
    heomstoolXheomstool.exeAdded by the Heoms TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Creates multiple files.
    hErcUnesXsofthost.exeAdded by the W32.GARROCH WORM!
    Hermes MessengerUDGDRHE~1.EXEA LAN messenger alternative to WinPopUp - Digital Dreams Software
    Hewlett Packard ManagerXhpmanager.exeAdded by the W32.Mytob.KE WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Hewlett Packard RecorderNRemind32.exeHP multifunction registration
    HfUHf.exeHide Folders - hide your folders so only you can view them
    HF SecurityXhfsecure.exeAdded by the W32/AGOBOT-TI WORM!
    hffsrvUhffsrv.exe Hide_Files_&_Folders is a password-protected security utility working at the Windows kernel level allowing you to password-protect files and folders, or to hide them securely from viewing and searching.
    hfxpUhfxp.exe Hide Folders XP - hide your folders so only you can view them
    hgqhp.exeXhgqhp.exeAdded by the Troj/DNSBust-C TROJAN! or the Trojan.Flush.F TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Troj/DNSBust-C injects its code into EXPLORER.EXE and IEXPLORE.EXE.
    HGTXPEINFirstReboot.exeHerucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
    HiberMonitor?HCount.exe??
    HibernationUhib32.exeReduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly
    Hid.exeXhid.exeAdded by the RATSOU.B VIRUS!
    hidenXhiden.exeAdded by the AGENT-IW TROJAN!
    HideOEUHideOE.exe HideOE - allows you to 'hide' Outlook Express or minimize it to the sytem tray.
    HideRun.exeXHiderun.exe and svhost.exe and pro.gifAdded by the BOOHOO VIRUS!
    hidservUhidserv.exeThis is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards
    High Definition Audio Property Page ShortcutNHDAudPropShortcut.exeRealtek audio card related; probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required.
    HijackThis startup scanUHijackThis.exe HijackThis lists the contents of key areas of the Registry and hard drive--areas that are used by both legitimate programmers and hijackers. The program is continually updated to detect and remove new hijacks. It does not target specific programs and URLs, only the methods used by hijackers to force you onto their sites. As a result, false positives are imminent, and unless you're sure about what you're doing, you always should consult with knowledgable folks before deleting anything. Required if you'd like Hijack This to run a scan at startup, and show the results when new items are found (if so, check the appropriate box in the "Config" section")
    HijSrv32Xhijsrv.exeAdded by the Troj/Bankgerm-D TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    HistoryKillNhistkill.exeHistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs
    HitwarePKLiteUHITWAR~1.EXEHitware Popup Killer Lite
    HIVXHIV.exeAdded by the HIVA VIRUS!
    hkUhk.exe KeyLoggerExp keystroke logger/monitoring program - remove unless you installed it yourself!
    hkcmdUhkcmd.exeInstalled by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel
    HKEYokXrunlli32.exeAdded by the Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curre
    ntVersion\Run
    Xwindowsupdate.exeAdded by the W32/Forbot-BJ WORM!
    HKSERV.EXEUHKserv.exeKeyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
    hkssUhkss.exeCompaq HotKey Support - multimedia keyboard support
    HLcleanupXhlsetup2.exe LinkReplacer/FFinder adware component
    hlhtxo.exeXhlhtxo.exeAdded by the QLOWZONES-27 TROJAN!
    hlinstaller1Xhlinstaller1.exeIdentified by Kasperksy_Labs as Trojan.Win32.SecondThought.aa
    HLL Data ParameterXhllcxpa.exeAdded by the RBOT.AFG WORM!
    HMI PowerSystemXhmisvc32.exeAdded by the W32.RANDEX.CZZ WORM!
    HML PowerSourceXhmlsvc32.exeAdded by the W32/SDBOT-XL WORM!
    HmonitorUHmonitor.exeHardware sensor monitoring program. Only required if you overclock your system and want to check on the status
    HMV PowerSourceXhmusvc32.exeAdded by the W32/Sdbot-YW Worm!
    HOI ServicesXholsvc32.exeAdded by the W32/AGOBOT-SF WORM!
    Holiday LightsNHoliday Lights.exeHoliday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs
    HollabackXslvhosts.exeAdded by the SDBOT.BMO WORM!
    Home Theater SchSvrNSchSvr.exe WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    HomeAlarmUHomeAlarm.exeChameleon Clock - system tray clock replacement
    HomeCentre WakeUp?LGWAKEUP.EXEAssociated with the no longer supported Xerox HomeCentre printer/scanner
    Homeland NetworkXHomelandNetwork.exe Homeland_Network Notifier - Pops ads, see their privacy_policy
    Honor?honor.exe??
    Hook99startupUhk2re.exe"Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent"
    HookSysUHookSys.exeSurfinGuard Pro - protects against all malicious code delivered through executables, scripting files, ActiveX and Java
    HorngTech4DYbally4d.exeHorngTech 4D mouse driver
    HostXN/AAdded by the POPDIS VIRUS!
    Host ProcessXmame.exeAdded by the W32/Rbot-APO WORM!
    hostdll.exeXhostdll.exeAdded by the BANKER-BO TROJAN!
    HostManager?AOLHostManager.exeIn a Program Files\Common Files\AOL folder - what does it do, and is it required?
    Hostren.exeXHostren.exeAdded by PWS.BANKER.F, a variant of the BANKER-BO TROJAN!
    hostservXhostserv.exeAdded by the RBOT.BPZ WORM!
    hostservXwiz98.exeAdded by a variant of the W32/SDBOT WORM!
    HostSrvXsachostx.exeAdded by the LOOKSKY.A WORM!
    HostSVC syseXHostSVC.exeAdded by the W32/RBOT-ANZ WORM!
    Hot CornersUHotc.exeHot Corners - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"
    Hot Key Kbd 2690 DaemonUSK9910DM.exeMultimedia keyboard manager - required if you use any special keys
    Hot Key Keybd 9910 DaemonUSK9910DM.exeMultimedia keyboard manager - required if you use any special keys
    Hot Party 22?hotpart22.exe??
    HotAction_hrXhotaction_hr.exeAdded by the Dial/SiteIcon-B Dialer. Note: Dial/SiteIcon-B provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "HotAction_hr
    HotbarXHbinst.exeHotbar enhances the surfing experience offering a variety of innovative and fresh skins to the browser while providing users worldwide with access to various services of added value and fun. Also regarded as adware/spyware due to it's adds and browsing habits information gathering - see here
    HotbarXHbOEAddOn.exe Hotbar adware
    Hotfix UpdatXsvdhost32.exeAdded by the GAOBOT.ZW WORM!
    HotIDEUhotide.exeHotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
    HotkeyAppUHotkeyApp.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
    HotKeysCmdsUhkcmd.exeInstalled by the Intel 810 and 815 chipset graphic drivers. If you want the Ctrl Alt F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via Control Panel -> Display Properties
    HotPixXhotpix.exeAdult content dialler
    hotplugXhotplug.exe Trojan.Downloader.Agent.AM
    HotSurpriseXHotSurprise.exePremium rate adult content dialer
    HotSync ManagerNhotsync.exeInstalled when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing.  Available via Start -> Programs
    hotwetloveXhotwetlove.exeAdult content dialler. Will not uninstall - components have to be manually deleted
    Hot_KissXHot_Kiss.exeAdult content dialler
    Hot_TartsXHot_Tarts.exeadult material dialer
    Hot_Tarts_**XHot_Tarts_**Premium rate adult content dialer (where * is a random char)
    Hot_Tarts_mcXHot_Tarts_mc.exe Wink/HotTarts premium rate adult content dialer
    HoverDeskUHoverDesk.exeHoverDesk - desktop replacement software
    hp 1000 firmware?fwdl.exeHP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?
    HP AutoIndexerUhppautoindexer.exeInstalled by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
    HP CD-DVD or HP CD WriterNhpcdtray.exeSystem Tray access to a HP CD-Writer\'s functions. Available via Start -> Programs
    hp centerXBACKWEB-137903.exeBased upon HP's own description from here - "With the My HP Center, consumers have access directly from the desktop to Internet sites featuring special offers for HP customers ranging from personal finance and shopping to digital imaging and music" I have classified this as adware. The number may change - if yours is different let me know
    hp center UIXShadowBar.exeUser Interface for HP Center
    HP Component ManagerNhpcmpmgr.exeChecks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error "Windows can\'t shutdown the computer because hpcmpmgr.exe can\'t be ended"
    HP DeskjetXHP_DeskJet_500.exeAdded by the W32/FORBOT-DA WORM!
    HP Digital Imaging MonitorUhpqtra08.exeSystem Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos from a camera, for example
    HP Display SettingsUhpdisply.exeSets default display settings. Unchecking this item has been reported to cure a "Problem sending command to keyboard" error message
    HP IDScheduler?HPIDSCHD.exeHP Instant Delivery Scheduler
    HP Image Zone Fast StartNhpqthb08.exeImproves the startup time of HP Image Zone. If you disable it, HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time
    HP Info ExpressN??On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
    HP Instant SupportUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". HP Instant Support is required to run with the Help and Support program. If you uncheck HP Instant Support and and then run Help and Support it will add another HP Instant Support in the startup menu. If you remove the HP Instant Support in the add/remove program some help menus in help and support will not be available. You decide
    HP Internet CenterNSURFBRD.EXELoads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
    HP JetDiscoveryNHPJETDSC.EXEHP JetAdmin software which monitors printing jobs on a network environment
    HP JetSpeed AutostartNAUTOSTART.EXEAutostart executable for the old multiplayer game HP Jetspeed
    HP Laser Jet DirectorUhppdirector.exeSystem Tray icon that opens various functions such as copy, fax, email, scan, copy plus, etc. Right-click on it and you see a few options such as the preceding bar plus About, Help, ToolBox, Exit, etc
    HP Network Registry AgentNhpnra.exeHewlett-Packard Network Registry Agent background task installed by the drivers for many of HP’s printers since 2002. See here under "hpnra.exe"
    HP OfficeJet Series xxx Startup?HPOSTR03.EXEHPOstr05.exexxx represents the series number - such as 700. What does it do and it it required?
    HP Parallel Port TestNhppt.exeAssociated with a HP ScanJet scanner
    HP Photo ManagerXHPPhotoManager.exeAdded by the SDBOT.AXU WORM!
    HP Port Resolver?hpbpro.exe??
    HP Precision ScanNhpmdlbwx.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
    HP Presentation ReadyNPresRdy.exeHP Omnibook related:  "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
    hp psc 2000 SeriesUhpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
    HP RecordNowU??From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."
    HP ScanPatchUHPScanFix.exeProgram that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used, then it is safe to remove or prevent from starting
    HP ScanPictureNhpsplmwa.exeHP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
    HP SchedIndexerUhppschedindexer.exeInstalled by HP multi-function printer driver software, related to PC faxing. If you are not using the PC faxing feature you can go ahead and disable these services from the startup
    HP Service DriversXhdsys.exeAdded by the W32/Sdbot-ZE Worm!
    hp Silent Service?HpSrvUI.exeHP related
    HP Simple TraxNHpcron.exeSupplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
    HP software updateNHPWuSchd.exeHP software updates. If a shortcut doesn't exist, create your own and run it manually
    HP software updateNHPWuSchd2.exeHP software updates. If a shortcut doesn't exist, create your own and run it manually
    HP StatusNhpstatus.exeHP Printer Status and Alerts
    HP Status Server?hpboid.exe??
    HP TV NowUHpTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) - user's choice!
    HP UpdatesN??On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb
    HP Visualize Init?HpVisIni.exeHP Visualize software related. What does it do and is it required?
    HP-Aio FlightNRemind32.exeHP multifunction registration
    hpaiodeviceNhpodev07.exeDirect from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
    HPAiODevice(hp officejet g series)?hpoavn07.exeHP Printer related, reportedly lets file transfers from an HP device pass files through Windows firewall - is it required?
    HPAiODevice(hp psc 900 series) -1Nhpobrt07.exeInstalled with a Hewlett Packard 900 series colour printer, scanner, fax, photo card slot printer, copier. Assumed to perform an identical function to the hpaiodevice entry
    HPAIO_PrintFolderMgrNhpoopm07.exeDirectly from HP: "This process has one purpose - detects if the device moves to a different port, and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled, and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
    hpcmpmgrNhpcmpmgr.exeChecks the internet for updated drivers/utilities for your HP product - update manually. Also, disabling will obviously get rid of the more or less common error message: "Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"
    HPDJ Taskbar UtilityUhpztsbol.exe, hpztsd0*.exe, hpztsb0*.exe (* = digit)(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info
    or
    (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer 
    hpfschedNhpfsched.exeHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
    HPGamesActiveMenuUActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    hpgs2wndNhpgs2wnd.exe"HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites."Available via Start -> Programs
    Hpha1monUHpha1mon.exeMedia card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature.
    HPHAxMONUHPHAxMON.EXEMedia card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature and known to cause system crashes in some cases. "x" can be 1, 2 or 3 and depends upon driver version. Replaced by HPHmon** (where ** is the version number) from version 4 onwards
    HPHmon**UHPHMON**.EXEMonitors the status of the memory card reader slot on a HP printers and displays a tray icon if a memory card isn\'t inserted. Also creates a virtual drive and assigns it the first available drive letter - which can lead to problems with drive management. ** represents the version number. Disable if you don\'t use the reader
    HPHmon04Uhphmon04.exeMedia card reader for some HP series printers allowing them to read digital camera memory cards directly. Only needed if you use this feature
    hphmon05?hphmon05.exe?
    HPHmon06Uhphmon06.exeRelated to the Hewlett Packard software HP Photosmart printer, it provides easy access to flash card reading functions. This program is not essential to the running of the system. Your choice.
    HphomeXhphome.jsHomepage hijacker
    HPHUPD**Nhphupd**.exeHP software update checker and wizard launcher. ** represents the version number. Available via Start -> Programs
    hphupd04Nhphupd04.exeHP Photosmart software update checker and wizard launcher. Available via Start -> Programs
    HPHUPD05?hphupd05.exe?
    HPHUPD06Nhphupd06.exeBelongs to the HP Photosmart application and is responsible for keeping this software upto date. This program is not essential to the running of the system
    hpjsiroute?hpjsira.exeRelated to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2"
    HPl ServicesXhmlsvc32.exeAdded by the W32/AGOBOT-SI or W32/Agobot-SM or W32/Agobot-SN and W32/Agobot-ATK WORMS!
    HpLampYHPLAMP.EXEHP Scanner Utility that controls your scanner’s light bulb. Needed if it's switched on. Also refer here for troubleshooting
    hplampcUhplampc.exeHP Scanner Lamp Utility. Fixes an issue with the scanner lamp not going off.
    HPLaptopGamesActiveMenuUActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    HPLogiFinderUhp_finder.exeHP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
    HpMmKbdUHpMmKbd.exeHP’s multimedia keyboard driver which enables the end-user to use the automation features of the HP multimedia keyboard
    HPNTXhpdll.exeMalware - detected by Kaspersky antivirus as Trojan-Downloader.Win32.VB.ku
    hpodbliaNhpodblia.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
    hpodlb08Nhpodlb08.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
    hpotdd01.exeYhpotdd01.exehpotdd01.exe is installed alongside HP Multimedia products and is responsible for digital imaging. "This program is a non-essential process, but should not be terminated unless suspected to be causing problems."
    hppptaYHPPPTA.exeHP parallel port driver for certain hardware
    HpPrinterXhpserver.exeAdded by the Troj/CmjSpy-W Trojan!
    HPPROPTYNHPPROPTY.EXEHP LaserJet Toolbox
    HPPWRSAVUHPPWRSAV.EXEPower save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com, pick your OS option under the SUPPORT tab, follow the instructions and you will find an updated lamp control patch
    hpqcmon?hpqcmon.exeFrom HP and related to digital imaging
    HPSCANMonitorUhpsjvxd.exeHP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
    hpScannerFirstBoot?scannerfb.exeHP scanner related
    hpsjbmgrNhpsjbmgr.exeHP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup, unless the scanner is used every day, such as in a business environment
    HPStartNhpstart.wsfThis a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
    hpsysconf1X(random file name) VIVIA.A trojan variant
    hpsysdrvUhpsysdrv.exeThis item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP, if it can't tell that it is an HP it will not run. If unchecked, it can prevent the running of the Application Recovery CDs, the use of the multimedia keys, and the HP Instant Support. Also seen that without it running, the Riptide Sound card that was installed on some older HP computers stops working
    HPUNProvenTactics.exeProven Internet Marketing software
    hpWirelessAssistantUHP Wireless Assistant.exeThe HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices.
    HPZTS04Nhpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
    HP_dlaNdlatray.exeOn HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
    HQI ServicesXhqlsvc32.exeAdded by the W32/AGOBOT-RP WORM!
    HQI ServicesXhqisvc32.exeAdded by the W32/AGOBOT-RO WORM!
    HRUHr.exe HiddenRecorder periodically takes screenshots of the computer. If you didn't install this yourself remove it.
    HREF.OCXYregsvr32.exe ....HREF.OCXHREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller
    Hrn_qtvXhrnsvc32.exeAdded by the W32/Sdbot-AET WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    hsimXtoolbar.exeUnidentified Malware
    hsimXsexgame.exeUnidentified Malware
    hsimXisearch.exeUnidentified Malware
    HSLAB LoggerUlogger.exe HSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it.
    HtiUnpdor.exeAppears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
    HTML Help SystemXhhs.pifAdded by the W32/Rbot-ATB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    HTML32 Help SystemXhhs32.pifAdded by the W32/Rbot-ATE WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    HTpatchUhtpatch.exeHTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
    HtProtectXAVprotect.exeAdded by the W32.NETSKY.L WORM!
    http://www.lienvandekelder.beXLienVandeKelder.exeAdded by the W32/MYTOB-AZ WORM!
    http://www.lienvandekelder.beXLien Van de Kelder.exeAdded by the W32/Mytob-CP or W32/Mytob-CO or W32.Mytob.GK WORMS!
    http://www.lienvandekelder.beXLien vd Kelder.exeAdded by the W32/Mytob-M Worm!
    http://www.lienvandekelder.beXLien.exeAdded by the W32/Mytob-CZ Worm!
    http://www.lienvandekelder.beXLientjeuh.exeAdded by the W32/Mytob-P Worm!
    http://www.lienvandekelder.beXWe Love Lien Van de Kelder.exeAdded by the W32/Mytob-CV Worm!
    http://www.lienvandekelder.beXLienVdK.exeAdded by the W32/MYTOB-U WORM!
    http://www.lienvandekelder.beXVan de Kelder Lien.exeAdded by the W32/Mytob-BF Worm!
    http://www.lienvandekelder.beXLien Vande Kelder.exeAdded by the W32/Mytob-AQ Worm!
    http://www.lienvandekelder.comXLien Van de Kelder.exeAdded by the W32/Mytob-EQ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    http://www.lienvandekelder.com/XLienVandeKelder.exeAdded by the W32/Mytob-EO WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    httpdXc_pan.exeAdded by an infection by a Troj/Delf-A trojan variant!
    httpdXdeamon.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    httpdXmsgaol.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    httpdXs_menu.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    https-sslXhttps.exeAdded by the MOEGA.D VIRUS!
    huhdir?huhdir.exe??
    huigeziXHgzServer.exeAdded by the GRAYBIRD.C VIRUS!
    HvidXHvid.exeAdded by the GEMA TROJAN!
    HWINFO*XHWINFO*Added by the PUROL VIRUS! where * is a random character
    HWinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    HwpXsystem_wc.exeAdded by Eziin adware
    hxadsecX(pathname of the Trojan executable)Added by the Troj/AdClick-AP TROJAN!
    HXDL.EXE or HXIUL.EXEXHXDL.EXE HXIUL.EXEBelieved to be spyware - made by a company called Alset. Also known as "HelpExpress". Will install itself if you have previously had Attune by Aveo installed as they\'re by the same company. Uninstall via Add/Remove programs
    HydarVisionDesktopManagerUdesk95.exeATI's HydraVision desktop management software, allowing for multi-monitor support, as included in included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this_one . HydraVision can be uninstalled through Add/Remove Programs.
    HydarVisionViewportUviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    HydraVisionDesktopManagerUdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    HydraVisionViewportUviewport.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
    Hyper StartXinstantmsgrs.exeAdded by the W32/RBOT-NH WORM!
    I am not Ranky. I am eTunnel!Xwinsys.exeAdded by an unidentified WORM or TROJAN!
    I am not Ranky. I am eTunnel!Xmsyervice.exeAdded by an unidentified WORM or TROJAN!
    I am not Ranky. I am eTunnel!Xdisney.exeAdded by an unidentified WORM or TROJAN!
    I-Worm.GiGuXuGiG.eXeAdded by the GINK VIRUS!
    I/O ControllersXsvcnet.exeAdded by the TROJ/TIBIK-B TROJAN!
    I386XI386.exeAdded by the MYPOWER VIRUS!
    I81SHELL?I81SHELL.exeAppears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard
    i8kfanguiUi8kfangui.exeGraphical interface for fan speed control
    IAAnotifUiaanotif.exeIAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it\'s required to notify you if a RAID 1 disk has failed
    iamappYiamapp.exeAtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
    Iamnacho On Irc.MusIrc.com Is a Homosexual!XXBox64.exeAdded by the RANDEX.Y VIRUS!
    Iap?iap.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?
    iasUias.exe InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!
    IASHLPRXIASHLPR.EXEAdded by the OPASERV.T VIRUS!
    ibinX(Pathname of the Trojan executable)Added by the Troj/Perda-C Trojan!
    ibmXibm.exeAdded by the Troj/LegMir-AH Trojan!
    ibmmessagesNibmmessages.exeAllows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
    Ibmmon.exe?Ibmmon.exe??
    IbmpmsvcUibmpmsvc.exePower management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes
    IBMUltraBayHotSwapCPLLoaderUIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
    IBMUltraBayHotSwapSound?IBMBAYSN.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?
    IBWin Background processUIBackground.exe IBackup for Windows
    IBWin MonitorUIBMonitor.exe IBackup for Windows
    icasServXicasServ.exeBrowser hijacker, redirecting to Searchforfree.info, also detected as TROJ/ICASERV-A
    ICcontrolXiccontrol.exeAdded by the ICcontrol premium rate adult content dialer
    icdd7ee6Xrundll32.exe (path) icdd7ee6.dll,EnableRunDLL32 LZIO.com adware downloader
    icddefffXrundll32.exe (path) icddefff.dll,EnableRunDLL32 LZIO.com adware downloader
    ICH SynthNeusexe.exeSound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices
    icifatiXyujixit.exeAdded by the SDBOT.ZZH WORM!
    iCleanUiClean.exeIEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
    iCnNNAG.EXEiChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist
    ICONICO.EXEFound on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    Icon AnimationNHDE.EXEPart of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
    Icon Hearit 95Nhearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
    Icon Hearit 98Nhearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
    Icon lptt01 or Icon ml097eXicon.exeVariant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    ICONCLNTYiconclnt.exeAPC PowerChute Tray Icon. Associated with the UPS listing
    ICONDESKUICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop icons
    Iconfig.exeNIconfig.exeIcon for LS-120 "Superdisk"
    iConfigLoaderXDIIhost.exeAdded by the GAOBOT.AO WORM!
    IconoidNIconoid.exeIconoid is a desktop icon manager
    IconsaverNIconsaver.exeIconSaver is a desktop icon manager
    ICQ =XICQNET.vbsAdded by the VBS/Gormlez-A Worm!
    ICQ CenterXconsoles.exeAdded by the RANDIN VIRUS!
    ICQ Chat ServiceXicqjdhs.exeAdded by a variant of the WIN32.RBOT WORM!
    ICQ Hacking ProXICQpro.exeAdded by a version of the NETSPY VIRUS!
    ICQ LiteNICQLite.exeICQ Lite - compact version of the popular messaging program
    ICQ Lite MessengerXICQLITE.EXE, random file namesUnidentified worm or trojan. Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or Winnt\System32 directory.
    ICQ Messenger 2002XICQ2002.exeAdded by the W32/Sdbot-ABL WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    ICQ NetXwinlogon.exeAdded by the W32.NETSKY.C or W32.NETSKY.D or W32.NETSKY.E or W32.NETSKY.K WORM! **Note - this is NOT the legitimate Windows winlogon.exe process
    ICQ NetXwinlogon.exeAdded by the Win32.Netsky.D WORM! - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!
    ICQ PlusNvplus.exeICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs
    IcqBetaXwebcamupdate.exeAdded by an unidentified TROJAN!
    ICQNetXwinlogon.exeAdded by the W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    icrosof Avps32 ControlXav32.pifAdded by the W32/Rbot-AVC WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    icrosoft Windows DLL Services ConfigurationXpoker3.exeAdded by the W32/Sdbot-AER WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ICSDCLTUrundll32.exe Icsdclt.dll, ICSClientInternet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
    ICServerNIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
    ICSMGRYICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you’re sharing the internet on various computers
    IC_KEY_3Nspvic.exeInstant Chess related
    ID CommanderNIDCom.exeCaller ID utility for identifying incoming telephone numbers
    ID8525XID8525.exeid85255.exeID8525 VIRUS and homepage hijacker!
    IDA?IDA.EXEHP related - in a Program Files\Hewlett-Packard\PC COE folder
    IDEXide.exeAdded by the ASSASIN.F VIRUS!
    IDE LoaderXIDElibr32.exeAdded by the XILON VIRUS!. Related to the game "Diablo II"
    idecntlXidecntl.exeAdded by a Crypter.C trojan variant infection
    iDesktopUidesktop.exeImmersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
    IDManNIDMan.exeInternet Download Manager - download files faster, schedule and resume
    IDW Logging ToolNidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
    IE configureXexplorer.exeAdded by the Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the Windows or Winnt folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    IE DoctorUIEDoctor.exeIE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
    IE Java UpdateXiejava.exeAdded by the Troj/Agent-HD TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    IE Menu Extension toolbarXrundll32.exe [path] tbextn.dll DllShowTBTopconverting.com/180Search "IEMenuExtension" toolbar
    IE New Window MaximizerUiemaximizer.exeIE New Window Maximizer, see here - automatically maximize new Internet Explorer and Outlook Express windows.
    IE RuntimeXwini.exeAdded by the W32.Picrate.B WORM!
    IE RuntimeXwini.exeAdded by the W32/RBOT-ABK and W32/Rbot-ADM WORMS!
    IE RuntimesXwinis.exeAdded by W32/Rbot-ADZ Trojan!
    IE**.exe (* = random char)XIE**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    IE**32.exe (* = random char)XIE**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    IE6Xwkstmg.exeAdded by a variant of the W32/SDBOT WORM!
    IE6Xssmss.exeAdded by the W32.Gaobot.DXO WORM! Note: This trojan file ssmss.exe (Notice the extra s) is not the legitimate Windows Process. The legitimate Windows Process (smss.exe) should not be seen in Msconfig or as a Startup item.
    IE6Xporn.pifAdded by the W32/Rbot-ATF WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    IEACCESSXtemp532.exe AsdPlug premium rate adult content dialer variant
    IEACCESSXsurfya.exe IEAccess premium rate adult content dialer variant
    IECheckXMSDTCs.exeAdded by the W32/TIRBOT-D WORM!
    IECheckXxpssl.exeAdded by the W32/TIRBOT-E WORM!
    IECheckXmssvp.exeAdded by the W32/Tirbot-G Worm!
    iecheck.exeNiecheck.exeIntegrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
    IECleanAuxUIeboot6.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
    iedllXiedll.exeHomepage hijacker, redirecting to coolwwwsearch.com
    IEDriverXIEDriver.exeInstalled as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
    IEDriverXTD.exe IEDriver adware variant
    IEDriverXxplore.exe IEDriver adware variant
    IEengineXIEeng.exe TROJ_STARTPAG.AI hijacker
    ieexec.exeXieexec.exeAdded by the TROJ/MULTIDR-DY TROJAN!
    IEFeaturesXIEFeatures.exeInternetfeatures.exeAdded by the POPMON.A VIRUS! - also known as PopMonster adware
    IefxTrayXIefxTray.exeAdded by the RILER-H TROJAN!
    ieharv.exeXieharv.exeAdded by the Troj/Banker-HH TROJAN!
    IehelperXsyslaunch.exeOutwar adware downloader
    iel2cde8Xrundll32.exe (path) iel2cde8.dll,EnableRunDLL32 LZIO.com adware downloader
    ielcaabeX rundll32.exe (path) ielcaabe.dll,EnableRunDLL32 LZIO.com adware downloader
    IELoader32Xiexplore32.exeAdded by the W32.Spex or W32.Spex.B WORM!
    IesarXIesar.exeBrowser hijacker - redirecting to an adult web page
    Iesearch.exeXIesearch.exe LookNSearch adware
    iestartXiexp1orer.exeAdded by the NEMOG.C VIRUS!
    ietsrNietsr.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
    ieupdateXMCP****.exeAdded by the ASOXY VIRUS! where **** are random characters
    ieupdateXmcpdll32.exeAdware downloader trojan
    IEXPL0RERXIEXPL0RER.EXEAdded by the W32/AGOBOT-QL WORM!
    iexpl0resXiexpl0res.exeAdded by the RBOT.AEX WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot
    IexploitXIexploit.htmlAdded by the VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder.
    IexploreXiexplore.exeAdded by the BOXER VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder
    IEXPLOREXiexplore.exeAdded by the APHEXDOOR VIRUS! Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) wheras the valid "iexplore.exe" (IE) resides in C:\Program Files
    IExploreXIEXPLORE.EXEAdded by the Troj/Dloader-YZ TROJAN! Note: The infected file resides in the "C:\Program Files\Internet Explorer\Custom" folder.
    Iexplore ServicesXiexplore.exeAdded by an unidentified VIRUS!. This iexplore.exe file is located eleswhere rather than in the default Program Files\Internet Explorer folder
    IExplorerXIExplorer.EXEAdded by the BANCOS-CH and Troj/Bancos-CW TROJANS!
    IExplorerXIexplor32.exeAdded by the TROJ/BDOOR-BY TROJAN!
    IEXPLORERXmsiecfg.exeAdded by Troj/Bdoor-JU TROJAN!
    iexplorer lptt01 or iexplorer ml097eXiexplorer.exeVariant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
    Iexplorer.exeXIexplorer.exeAdded by the TROJ/BANCBAN-EN TROJAN!
    IExplorer32 Java ScriptingXIExplore32b.exeAdded by the RBOT.ABO WORM!
    IExplorer32c Java ScriptingXIExplore32cb.exeAdded by the RBOT.ABN WORM!
    IExplorer6 Java ScriptingXIExplore326.exeAdded by a variant of the W32/SDBOT WORM!
    IExplorer7 Java ScriptingXIExplore327.exeAdded by a variant of the W32/SDBOT WORM!
    IFSplash.exeUIFSplash.exeI-FORCE driver for force feedback steering wheel
    igamatuXatecaca.exeAdded by the IRCBOT.R WORM!
    igfxtrayNigfxtray.exeQuick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
    igsex2xXigsex2x.exe NewDial premium rate adult content dialler
    iHP-100?iHPDetect.exeDrive Letter Searcher , iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time?
    iilcXIILC.EXEHomepage hijacker
    IinlXiptl.exe PurityScan/Clickspring adware
    iisversXiisvers.exeAdded by an unidentified TROJAN or adware
    iIWiperNSystemwiper.exeSystem Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis
    IJ75P2PSERVERYIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
    IKE Service 95YIKEService.exeAssociated with PGP. The PGP Tray can bedisabled, but without IKESERVICE you won\'t be able to de- or encrypt anything
    iKeyWorksUIKEYMAIN.EXEA4Tech wireless keyboard driver and utility
    iLLeGaL or iLLeGaL.exeXMplayer.exeAdded by the HOLAR.C (or GALIL@MM) VIRUS! Note - this should not be comfused with Windows Media Player which has the same filename
    ILO_Office_Manager?IntEdReg.exe /OFFMANIntense Educational Ltd - Language Office Software. Is it required?
    iLyricUiLyric.exe iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
    iM Start CenterNiM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
    ImageXrundll32 (path) image.dll, Install, rundll32 (path)sdkqh32.dll,Install CoolWebSearch parasite related
    Image & RestoreYIMAGE32.exePart of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
    Image TransferNSonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually.
    ImagefoxUimagefox.exeImageFox 2.0 is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
    Imagemgt32XImagemgt32.exeAdded by the GEMA TROJAN!
    ImagePathXtaskbarmngr.exeAdded by the W32/SDBOT-XB WORM!
    IMAPIXload.exeAdded by the Troj/Downdel-A TROJAN! Note: This trojan file is found in the Windows or Winnt \Microsoft\Protect\S-1-5-18\User\svchost folder.
    IMClassXSvhosl.exeAdded by an unidentified WORM od TROJAN!
    imekrigNimekrig.exePart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
    IMEKRMIG6.1NIMEKRMIG.EXEPart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
    ImeshN??Imesh is a file sharing system
    Imesh Auto UpdateN??Update check for the Imesh, http://www.imesh.com file sharing system. Turn the update off under "options"
    IMEvtMgr.exeXIMEvtMgr.exeAdded by the Troj/Keylog-AR TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ImgIconUImgIcon.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    imgitX[path to file]Added by the BANKER-EM TROJAN!
    ImgStartNImgStart.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    imjpmig or Imjpmig8.1NIMJPMIG.EXEPart of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
    immcheck.exe?immcheck.exeRelated to I-FORCE driver for force feedback steering wheel?
    IMOLUIMOLApp.exeIncrediMail for Office Outlook_Add-On
    ImonitorNPlguni.exeMcAfee QuickClean 3.0 - removes internet clutter and unwanted programs
    IMONTRAYUimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
    IMStartUIMStart.exe InterMute security software related
    IMwireXimwireup.exe SafeSurfing parasite variant
    InCDYincd.exe Ahead_InCD packet writing software. Similar to DirectCD. - For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. - For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows.
    IncMailNIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    InControl Desktop ManagerNDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
    IncredimailNincredimail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    IncredimailNIncMail.exe "IncrediMail" is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
    Index ServiceXdllhost32.exeAdded by the AGOBOT.CH WORM!
    Index WasherUWashIdx.exe Windows_Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
    IndexindicatorXIndexindicator.exe /checkAdded by the Lazar TROJAN!
    IndexSearchNIndexSearch.exeAssociated with PaperPort scanner software from ScanSoft
    ineXsvchosts.exeAdded by the WIN32.RBOT.BNL WORM!
    Inet DataBaseXInetdbs.exeAdded by the W32.QEDS WORM!
    Inet DeliveryXinetdl.exe Inet_Delivery adware
    Inet DeliveryXinetdl_2.exe Inet_Delivery adware
    InetapiXNetapi.exeAdded by the NETDEVIL.14 (NetDevil 1.4) VIRUS!
    inetcntrlUinetcntrl.exeBsafe Online - internet filter
    InetConf?inetconf.exe??
    InetdUINETD32.EXEWindows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
    inetinfo.exeUinetinfo.exeExecutable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code ( more)
    inetinfomon managerXinetinfomon.exeAdded by the DONBOMB.A TROJAN!
    inetmgrXinetmgr.exeActual Names (AdvSearch) Internet Keywords parasite
    InetMSNXmsnet.exeAdded by a variant of the SDBOT WORM!
    InetServicesXwsock32.exeAdded by the Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN!
    inetsysX(Path to Executable)Added by the Troj/Delf-NV TROJAN!
    Info SelectUis.exeInfo Select from Micro Logic - personal information manager
    Info32xXInfo32x.exeAdded by the GEMA TROJAN!
    InfoPenMSNUInfoPenIM.exe InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand
    Infoplay.exe?Infoplay.exeWritten by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?
    Information UpdateXiu.exeReported by Kaspersky Anti-Virus as Downloader.Win32.Centim.ch TROJAN! Note: The Malware file associated with this is located in the Program Files\Information Update folder.
    Infra-red MonitorUIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
    infusXinfus.exeAdult content dialler
    InfuzerUInfuzer.exeInfuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
    infwinXinfwin.exeMsview parasite variant
    Init32XInit32.exeAdded by the W32.WINEX.A TROJAN!
    Initial PageXinstall.exe"EasySearch" browser hijack installer
    Initialize8x8Y8x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
    injobXinjobs.exeAdded by the Trojan.Binjo TROJAN!
    Ink MonitorNInkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
    InkWatchNInkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
    InoRPCYInoRpc.exeAssociated with eTrust Antivirus/InoculateIT
    InoRTYInoRT9x.exeAssociated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here
    InoTaskUInoTask.exeScheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here
    insCOA5?insCOA5.exe??
    InstaFinderKXInstaFinderK_inst.exe InstaFinder adware
    InstallXInstall.exeAdded by the Troj/Bancban-HG TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Install Pending Files?sifxinst.exeUninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?
    InstallAurealDemosNInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
    InstallBuddyUIbtna.exeInstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
    Installed shell32.dllXOffice.exe...Added by a variant of the LOVGATE WORM!
    InstallerXdial.exeMalware - detected by Kaspersky antivirus as trojan-dropper.win32.agent.mm
    InstallNAIProduct?SETUP.EXECould be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?
    Installs SP2X[path] repcale.exe [path] palsp.exeAdded by a variant of the RANDON.AN WORM!
    Instance 001X(Path of the worm executable)Added by the W32/Alasrou-A WORM!
    Instant AccessXrundll32.exe EGDACCESS_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant AccessXrundll32.exe p2esocks_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant AccessXrundll32.exe EGCOMSERVICE_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant AccessXrundll32.exe EGDHTML_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant AccessXrundll32.exe eg_auth_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant AccessXrundll32.exe EGCOMLIB_****.dll, InstantAccess Electronic_Group/InstantAccess premium rate adult content dialer variant
    Instant Buzz DaemonXIBDaemon.exe Instant_Buzz adware
    Instant Update CenterNreminder.exeFrom Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG.  PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner
    Instant Wireless Configuration UtilityUWUSB11cfg.exeUtility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
    Instant Wireless Configuration UtilityUWPC11Cfg.exeUtility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
    InstantAccessNINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
    InstantDriveUInstantDrive.exePinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
    InstantPleasureXinstantpleasure.exeAdult content dialler
    InstantPleasureXXXXinstantpleasurexxx.exeAdult content dialler
    InstantTrayNPCLETray.exe Pinnacle_InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually..
    institXinstit.batAdded by the OPASERV.H VIRUS!
    institXINSTIT.BATAdded by the OPASERV.K VIRUS!
    InstUtlR.exe?InstUtlR.exe??
    intdctrrXidctup20.exe SafeSurfing parasite variant
    Intec Service DriversXmsmsgrs.exeAdded by the W32/Sdbot-ADN WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Intel Active MonitorUimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
    Intel File TransferUxfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
    Intel PDSUpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
    Intel Product Number UtilityUIntelProcNumUtility.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
    Intel PROSet Tray IconNpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
    Intel system toolXwinnook.exeAdded by the Troj/Spyre-C Trojan! A.K.A WIN32.TOPANTISPYWARE.L
    Intel system toolXhookdump.exe Topantispyware adware - also detected as the SPYRE-H TROJAN!
    Intel system worksXiis.exeAdded by the RBOT.QGA WORM!
    intel32.exeXintel32.exeAdded by the SmitFraud alias FakeAle or SPYJACK-B TROJAN!
    IntelAPMClientUamclient.exeLANDesk Management_Suite software component.
    InteliSysXsmss.exeAdvertisingvision adware - file is located in C:\Windows or C:\Winnt, and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file which would normally NOT figure in Msconfig/Startup!
    intell32.exeXintell32.exeAdded by the SmitFraud alias Desktophijack.C TROJAN!
    IntelliPointUpoint32.exe Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    IntellitypeUtype32.exeFor MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them
    IntelMemUIntelMem.exeRelated to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line
    IntelProcNumUtilityUcpunumber.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
    IntelWirelessYifrmewrk.exeAssociated with the Intel PRO/Set Wireless software.
    Intel® Common User InterfaceNigfxtray.exeQuick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
    Intense Registry Service?IntEdReg.exe /CHECKIntense Educational Ltd - Language Office Software. Is it required?
    InterCheck MonitorYIcmon.exePart of Sophos ant-virus sofware
    InterdllXInterdll.exeAdded by the DELF family of VIRUSES!
    InternalX(trojan filename)Added by the SMOTHER & TRANSLAT VIRUSES!
    InternalXregedit.exe /s %windir%c:\Added by the FORTNIGHT.D VIRUS!
    InternalSystrayXKazza.exeAdded by the OPTIXPRO.12.C VIRUS! Note - unlike the valid KaZaA executable, this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP)
    InternatXsystray.exeAdded by the IRC.ALADINZ.P TROJAN! ** Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
    internatXinternat.exeAdded by the TROJ/LYDRA-F TROJAN!
    InternatXmsgsrv32.exeAdded by the TROJ/NYRUBOT-A WORM!
    internatXinternat.exeAdded by the Troj/Lydra-B Trojan!
    Internat ConfXbootconf.exeHomepage hijacker, redirecting to coolwwwsearch.com; see for example here
    internat.exeNinternat.exeLanguage selection icon in system tray
    Internat.exeXinternat.exeAdded by the NETSNAKE VIRUS! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon
    Internat32Xinternat32.exeAdded by a Octa-B trojan infection
    internctXWinSocks5.exeAdded by the GRAYBIRD.F VIRUS!
    internetXsmss.exeAdded by the Troj/Mifeng-K TROJAN!
    InternetXrecruit.exeAdded by the W32/Rbot-AJG WORM!
    InternetXInternet.exeAdded by the Troj/PWS-CS TROJAN!
    Internet Answering MachineUIAMNET~1.EXEFrom Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
    Internet Answering MachineUIAM.exeFrom Callwave It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
    Internet ConfigXsvchosts.exeAdded by the SDBOT WORM!
    Internet Connection WizardXstisvsq.exe EasySearch adware
    Internet Connection WizardX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Internet Content PublisherXICP.EXEAdded by the W32/RBOT-UD WORM!
    Internet Download AcceleratorUida.exe Internet_Download_Accelerator download manager
    Internet Exploere ServicesXurlmon32.dll.exeAdded by the EVIAN.C VIRUS!
    Internet Explore MicrosoftXlEXPLORE.EXEAdded by the W32/RBOT-AOF WORM! - NOTE: the legitimate Internet Explorer executable of the same name will always be located in the Program Files\Internet Explorer folder, while this imposter is located in the System or System32 directory.
    Internet ExplorerXiexplorer.exeAdded by the LORSIS VIRUS! Note - the valid Internet Explorer would not normally run at startup unless added manually by the user and would not run from the registry "RunServices" key as this does
    Internet ExplorerXIEXPLORE.EXEAdded by a Rbot-EY worm infection
    Internet ExplorerXIExplorer.exeAdded by the Troj/Nethief-O Trojan!
    Internet ExplorerXhttp.exeAdded as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed.
    Internet ExplorerXIEXPLORE.EXEAdded by Troj/Cosdoor-A TROJAN!
    Internet Explorer SecurityXiexplore.pifAdded by the W32/Rbot-ALQ WORM!
    Internet Explorer UpdaterXlexbac.exeAdded by the DOWNLOAD VIRUS!
    Internet Explorer UpdaterXiexplorer.exeAdded by the REUR.B VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
    Internet History EraserUHERASER.exeInternet History Eraser - deletes your browsing tracks
    Internet Loader1XMSInstall61.exeAdded by the KWBOT.B VIRUS!
    Internet Mail and NewsXmsqdevl.exe EasySearch adware
    Internet Mail and NewsX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Internet OptimizerXoptimize.exe Internet_Optimizer parasite
    Internet Protocol Configuration LoaderXipcl32.exeAdded by the SDBOT TROJAN!
    Internet SendXMore log.exeUnidentfied adware
    Internet ServiceXintersvc.exeAdded by the W32/SPYBOT-DE WORM!
    internet serviceXsyscfg32.exeAdded by the W32/RBOT-QS WORM!
    internet serviceXssvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Internet ServicesXsystemdev.exeAdded by the W32/Sdbot-PW WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Internet ServicesXinternet.exeAdded by the W32.Mytob.LM WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Internet ServicesXinterserv.exeAdded by the RBOT.BNT WORM!
    INTERNET SERVISESXwinz32.exeAdded by the KWBOT.Z VIRUS!
    Internet Sharing ServerYiss_srvr.exeIntel AnyPoint internet sharing software
    Internet SuspentionXstory.exeAdded by the WOOTBOT.HV WORM!
    Internet SweeperNSweeper.exeInternet Sweeper - removes unnecessart left over files after browsing the internet
    Internet TimerUITIMER.exeShareware dial-up connection call cost calculator from Ratsoft
    Internet.exeXInternet.exeAdded by the MAGICCALL VIRUS!
    internet.exeXyinyin3345.vbsAdded by the XM97/YINI-A macro VIRUS!
    Internet2 OptimizerXwkfix.exeAdded by a variant of the WIN32.RBOT WORM!
    InternetWasherPro or Internet Washer ProXiw.exeInternet Washer manages temporary browser files, cookies, etc - a \'trial\' Internet Washer Pro seems to have been widely stealth-installed around March 2003
    INTERNET_SERVISESXwinz32.exeAdded by the SDBOT.Q WORM!
    InternodeUsageUmum.exeAustralian ISP's free monthly download meter
    InterntXInternt.exeAdded by the PEEPER or CARUFAX.A VIRUSES!
    Intersoft MsngrXintersoftmsngr.exeAdded by the W32/AGOBOT-NW WORM!
    InterTrust Quick StartNit_cpq~1.exeInterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business
    InterUXWINDRV.EXEAdded by the IRCINTER.A VIRUS!
    Intervideo WinCinema ManagerNWinCinemaMgr.exeWinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    Intervideo WinSchedulerNWinScheduler.exeSchSvr.exeWinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    InterWARNUinterwarn.exeInterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs
    IntespentionXIEXPLORE.exeAdded by the W32/Forbot-FL WORM! Note: This is not the legitimate Windows Process IExplore.exe (Which is found in the Internet Explorer folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item unless you put it there. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    IntmgrXIntmgr.exeAdded by the GEMA TROJAN!
    intranetXSYS32CFG.EXEAdded by the W32/Spybot-DW WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    IntrenatXIntrenat.exeAdded by the LEMIR.E VIRUS!
    Introducing Media ManagerNSPLASHA.EXEMS Media Manager tour. Not required
    Introduction-RegistrationN??For Compaq PC's. Should only run first time, PC Introduction & Compaq registration
    IntruderAlertXia99.exeIntruder Alert '99 from Bonzi - spyware
    Inventory ScanULDISCN32.EXELANDesk Management_Suite software component.
    IoadqmXMedia Player.exeAdded by the HAWAWI VIRUS!
    iolo Task AgentUTask_Agent.exeiOlo System Mechanic Task Agent. Scheduled maintenance
    iolo Utility BarNSMUtilityBar.exeIolo "System Mechanic" Utility_Bar - can be launched manually.
    Iomega Automatic Backup or Iomega Automatic BUibackup.exeIomega Automatic Backup - automatic backups for use with Iomega portable HDD 
    Iomega Backup SchedulerNdtiom98.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    Iomega Disk Icons or Iomega Drive IconsUIMGICON.EXEDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    Iomega ImIconXPUimiconxp.exeIomega REV_System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks.
    Iomega QuickSync?Quicksync.exe??
    Iomega Startup OptionsNIMGSTART.EXEUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    Iomega WatchNIOWATCH.EXEUsed by Iomega drives. Available via Start -> Programs
    IomegaWareNCOMMANDER.EXEUsed by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
    Iomon98.exeUIomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
    IP StackXipstack.exeAdded by the AGOBOT.CW WORM!
    IP**.exe (* = random char)XIP**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    IP**32.exe (* = random char)XIP**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    iPalmNmon.exeInstalled with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded
    IPC ConnectionXipcconn.exeAdded by the W32/Rbot-AEG Worm!
    IPC Spool ManagerXwnmgre.exeAdded by the W32/SDBOT-ZC WORM!
    IPC Spool ManagerXwinspec.exeAdded by the W32/SDBOT-BLU WORM!
    ipcfg.exeXipcfg.exeAdware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan
    IPConfigXsvcxnv32.exeAdded by the HACARMY.E TROJAN!
    IPConfigXsvcxnw32.exeAdded by a variant of the HACARMY.E TROJAN!
    IpCtrlXipcon32.exeAdded by an unidentified WORM or TROJAN!
    IPFWXipwf.exeAdded by the Troj/Dloader-YF TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    IPInSightLAN 01Nipclient.exeInstalled with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resources.
    IPInSightMonitor 01Nipmon32.exeInstalled with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information
    IPinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    ipmon.exeXipmon.exeAdded by the RECERV or R3C.B VIRUSES!
    Ipnuker XIpnuker.vbsAdded by the VBS.Inker.B WORM! Note: This worm file is found in the Windows or Winnt folder.
    iPOD USB DriverXIPODUSB.EXEAdded by a variant of the WIN32.RBOT WORM!
    iPod USB ServiceXiPODService.exeAdded by a variant of the WIN32.RBOT WORM! - Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program Files\iPod\bin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup!
    iPodManagerUiPodManager.exeApple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods
    iPodWatcher?iPodWatcher.exeAssociated with Apple\'s iPod MP3 player. Detects when the iPod is connected?
    IPOT Service DriversXcompaq.exeAdded by a variant of the FUROOTKIT TROJAN!
    IPOT USB Service DRIVERXhpsebc087.exeAdded by the W32/SDBOT-WA WORM!
    IPOT USB Service DRV32Xhpsebc08.exeAdded by the W32/SDBOT-WH WORM!
    ipregXipreg.exeAdded by the Troj/Zagaban-H TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    iPrint TrayNiprntctl.exeNovell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net.
    iProtectYouUip.exeiProtectYou - internet filtering/parental control and network monitoring software
    iprunX\iPY.exe -hAdded by iProtectYou SPYWARE!
    ipsecdialerUipsecdialer.exeThe Cisco VPN_Client lets local users gain Administrator privileges on the operating system
    ipsecdialerUIPSECD~1.EXE -run_only_if_connected -auto_initiationThe Cisco VPN_Client lets local users gain Administrator privileges on the operating system
    IPSecMonYIPSecMon.exeMicrosoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
    IPTable ConfigurationXWinipcfgs.exeAdded by a variant of the WIN32.RBOT WORM!
    IPv6 Helper DriverXcsass.exeAdded by the AGOBOT.TC WORM!
    IPv6 STUN ServiceXnetstun.exeAdded by a variant of the W32/SDBOT WORM!
    IPW?IPW.exe??
    ipwfXipwf.exeAdded by the Trojan.Schoeberl TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    IQES.exe?iqes.exe??
    irc sessionXsessionmgr.exeAdded by the W32/SDBOT-ACE WORM!
    IREIKEYIreIKE.exeMicrosoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
    irfkXNITEAIM.EXEAdded by the W32/Sdbot-AEJ WORM!
    iRis Active MonitorNwinmon32.exeIris Antivirus - discontinued, replace with good alternative
    iRiS AntiVirus Active MonitorNWIMMUN32.exeIris Antivirus - discontinued, replace with good alternative
    iRiver AutoDBUMLService.exeAssociated with the iRiver Music Manager
    iRiver UpdaterNUpdater.exeUpdates for the iRiver Music Manager - used with their digital music players
    IrMonUIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
    IRPMonitor?itcnmon.exe??
    IrwftpX"(The full path of the running Trojan)"Added by a BANCOS.CR trojan infection
    irwftpXiexplorer.exeAdded by the TROJ/BANKER-AN TROJAN!
    irwftpXftpmon.exeAdded by the TROJ/BANCBAN-BO TROJAN!
    IrXferUIrXfer.exeMicrosoft Infrared Transfer application
    ir_ftpXir_ftp.exeAdded by the IRFTP VIRUS!
    ir_ftpXirwftp.exeAdded by the BANCOS.H VIRUS!
    IS CfgWizNcfgwiz.exeNorton Internet Security configuration wizard
    IsassXIsass.exeAdded by the BACKDOOR.FUTRO TROJAN!
    ISBMgr.exe?ISBMgr.exeBelongs to Sony's ISB Utility. what does it do and is it required?
    isdbdcNisdbdc.exeFor Compaq PC's. May install properties in dial-up networking when you register with an ISP
    isDeleteMeUisDel.batUsed by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product.
    ISDN MonitorNLinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    ISDNwatchUIWatch.exeFRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"
    ISHelpUhelp.exe ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it.
    iShieldUiShield.exeGuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser
    ISLP2STANISLP2STA.EXEPossibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though
    islp2staYislp2sta.exeA process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers.
    ISP.COM High SpeedUslipgui.exe Sliptstream Web Accelerator
    iSpyNOWUispynow.exeiSpyNOW - remote monitoring and surveillance software
    IsrafelXIsrafel.vbsAdded by the GAGGLE.D VIRUS!
    IsReminderNISPopup.exeRelated to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup.
    issEnc32SvrXissEnc32.exeAdded by a variant of the WIN32.RBOT WORM!
    ISStartUISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    ISSVCYISSVC.exePart of Norton Internet Security Suite
    IST ServiceXistsvc.exeISTBar foistware
    ist service uninstallXHIDES.EXE, mstasks2.exe, wow.exe, simple1.exe, random file names ISTBar parasite related
    istinstall_zazzer.exeXistinstall_zazzer.exeUnidentified adware downloader/installer
    ISUSPM StartupNISUSPM.exeInstallShield Update Service related; Automatically searches for and performs any updates to the software. Not required.
    ISUSSchedulerNissch.exeInstallShield Update Service Scheduler; automatically searches for and performs any updates to the software so you’re always working with the most current version. Not required.
    isystemXisystem.exeAdded by the Troj/Chorus-A TROJAN! Searchforfree Browser hijacker.
    ItkUItk.exeIn The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    iTouchUiTouch.exeiTouch loads the iTouch configuration program for Logitech keyboards. It’s needed if your keyboard has shortcut buttons and if you use them. It’s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock
    ItsDeductiblePopUpNItsDeductible.exeItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
    ITUNESXitune.exeAdded by the W32/RBOT-ZU WORM!
    ITUNESXitunes.exeAdded by the W32/OSCABOT-L WORM!
    ItunesXdials.exeDetected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus. Note: A Url is not available at this time.
    iTunesHelperYiTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
    ItweakUUClear.exeRelated to ItweakU
    IusageNnetdet.exeInternet Usage Monitor - utility to calculate the cost and time on the internet via dial-up
    IVPServiceMgrNivpsvmgr.exeToshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba’s equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates. Not required.
    IW ControlCenterUiwctrl.exe Pinnacle_Systems InstantWrite - enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM.
    iwctrlUiwctrl.exePinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
    ixploreXixplore.exeAdded by an unidentified WORM or TROJAN! - NOTE: although this file is placed in the Internet Explorer folder in Program Files, it is most certainly malware, and not to be confused with the legitimate IE executable, which is spelled iExplore.exe!
    ixproxyX(Path to Trojan)Added by the Troj/Xorpix-A TROJAN!
    iyelejivXyujixit.exeAdded by the SDBOT.BJK WORM!
    IZE?N/A??
    j2 Tray MenuNHotTray.exeeFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here
    JA Cfg Util v2Xjacfg2.exeAdded by the W32/RBOT-AL WORM!
    JammerUjammer.exeJammer by Agnitum - "Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"
    Jammer2ndXJAMMER2ND.EXEAdded by the W32.NETSKY.Z WORM!
    Jammer2ndXJammer2nd.exeAdded by the W32.Netsky.Z WORM!
    Java appletXjavaup.exeAdded by the W32/Sdbot-ACF WORM!
    Java Auto UpdateXujm.exeAdded by the W32/SDBOT-ADH WORM!
    Java RuntimesXiexplore.exeAdded by the KILLAV.B VIRUS! Note - this is not the valid IE (iexplore.exe) file as it's located in C:\Winnt\Java\Java rather than C:\Program Files\Internet Explorer
    Java Virtual MachineXjavaw.exeAdded by a variant of the WIN32.RBOT WORM!
    Java**.exe (* = random char)XJava**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Java**32.exe (* = random char)XJava**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    JavaScript Debugging ServiceXJsDbgMan.exeAdded by the W32.Derdero.E WORM!
    JavaUpdate0.07X*******.exe (* = random char)Added by the BACKDOOR.JUPDATE TROJAN!
    JavaUpdateSchedXjusched32.exeAdded by the Troj/Bckdr-CKB TROJAN!
    JavaVMXjava.exeAdded by the W32.MYDOOM.M or W32.MYDOOM.N or W32.MYDOOM.BB WORM! **Note - This is not the valid Windows "java.exe" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt
    jawa32Xjawa32.exe Backdoor.Agent.bg trojan
    Jawa322Xjawa32.exeAdded by a variant of the Backdoor.Agent.bg trojan
    JBNJiffybar.exe"Get Paid As You surf" application
    Jet DetectionNADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
    JetAdmin Discovery IndicatorYHPJETDSC.EXEHP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry, and remains active to control the Discovery Indicator
    jeteXyujixit.exeAdded by the SDBOT.BRT WORM!
    jijblXezlwy.batAdded by the REDDW VIRUS!
    Job-oversigtUtaskmon.exeTask Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)
    JobHisInitUJobHisInit.exeUsed by Ricoh network printers to enable network printing from the client
    JogServ2 or Jog ServeUJogServ2.exe"Jog Dial" on a Sony Vaio laptop.  The dial can select various functions such as control audio. Needed if you use its features
    jotl?millenzje.exe??
    JregXJreg2b.exe BroadcastPC adware variant
    JufualtXwinxp2.exeAdded by the W32/SDBOT-AAB WORM!
    JufualtXsvhost.exeAdded by the W32/Sdbot-ADJ WORM! Note: This (svhost.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    juschedNjusched.exeChecks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
    jushed32.exeXjushed32.exe CoolWebSearch parasite related
    jutsuXjutsu.exeAdded by the W32/RBOT-LS WORM!
    jv16 PT TempFileToolUTempTool.exejv16 PowerTools' temporary file remover
    jv16PT - Privacy ProtectorUTask.jvbjv16 PowerTools 2005 - Privacy_Protector allows you to protect your privacy by clearing the unwanted history items and cookies from you computer every time you startup your computer.
    Jv16pt Network ResidentUjv16pt_network.exejv16 PowerTools' network resident program. Only needed if you are using the program's network features
    jvdnlssnXfljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
    JVM0.12X[random file name]Added by the TEADOOR-A TROJAN!
    JVM0.14X[random file name]Added by the TROJ/TEADOOR-B TROJAN!
    jxef1104Xjxef1104.exeAdded by the W32/XIPI-A WORM!
    Jzi16?jzi16.exe??
    K2ps_full.taskXK2ps_full.exeAdded by the JUNTADOR.K VIRUS!
    K6CPU.EXENK6CPU.EXEAuthenticates CPU as K6 in system properties
    KadocX[random file name].exeAdded by the Staprew TROJAN!
    KadocX[random filename].exeAdded by the Staprew TROJAN!
    kakXkak.htaAdded by the KAKWORM VIRUS!
    KalibumpUKalibump.exeUsed with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy
    kalvsysXkalv***32.exe (* = random char) EliteBar/SearchMiracle adware
    Kana ReminderNReminder.exeKana Reminder is a program which can be used to set a reminder to be triggered at a specified time
    Karen's Once-A-Day IIUPTOAD.exe Karen's_Once-A-Day_II is a scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first time Windows starts each day, or the first time a particular user logs on each day.
    KASPUOESpamTest.exe Kaspersky_Anti-Spam
    Kasper AntivirusXKASPERANTIVIRUS.EXEAdded by the SPYBOTER.GEN TROJAN!
    Kasper AntivirusXKASPERANTIVIRUS.EXEAdded by a variant of the W32.SPYBOT WORM!
    Kaspersky Anti-HackerYKAVPF.exeKaspersky Anti-Hacker firewall
    Kaspersky AntivirusXKasperskyAV.exeAdded by a variant of the WIN32.RBOT WORM!
    KasperskyAvXkaspersky.exeAdded by the W32.MIMAIL.T WORM! **Note - This has nothing to do with Kaspersky AntiVirus
    KasperskyAVEngXKasperskyaveng.exeAdded by the W32.NETSKY.V WORM!
    KAVFOXXwin1ogoin.exeAdded by Troj/GWGhost-M TROJAN!
    KAVPersonalXsvchost.exeAdded by the Troj/Lineage-V TROJAN! Note:This is NOT the legitimate Windows svchost.exe process, which should NOT figure in Startup!
    KAVPersonal50YKav.exe Kaspersky Anti-Virus Personal 5.0
    KAVPersonal90Xwscntfy.exeAdded by the Troj/Banker-FZ or Troj/Banker-GD TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    KavPFWYKavPFW.exe KingSoft Personal Firewall
    KavRunsXWindll.exeAdded by the TRYNOMA VIRUS!
    KavStartYKAVStart.exe KingSoft Personal Firewall
    kavsvcYkavsvc.exe Kaspersky antivirus
    kavsvcX[random 6 char file name]Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe, rzazzi.exe, ivpaan.exe)
    KavSvcX******.exe reg_run (* = random char)Added by the QOOLOGIC TROJAN!
    KAVutilX(worm filename)Added by the WINTOO.B VIRUS!
    KAZAANkazaa.exeKAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it
    Kazaa Download Accelerator UpdaterXregsvr32 [path] kdpupd.dll SafeguardProtect/Veevo
    Kazaa Download Accelerator Updater (required)Xregsvr32 [path] kdp****.dll (*= random char) SafeguardProtect/Veevo
    Kazaa lptt01 or Kazaa ml097eXkazaa.exeVariant of the RapidBlaster parasite (in a "kazaa" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name
    KAZAACufX9Added by the KITRO.D (or ARGEN.A) VIRUS!
    kazaaliteNkazaalite.exeKazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original, this one does not contain any advertising or tracking mechanisms
    KaZooMNKaZooM.ExeKaZoom from Blue Haven Media - "add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"
    KB891711YKB891711.exeInstalled by the Windows KB891711 critical update, see this security bulletin - this file reportedly needs to continue running in order to patch the vulnerability, at least until a more practical solution is found. There have however been reports of fatal exception errors in systems running Windows 98, and in such a case Microsoft advises to either uninstall the patch (Add/Remove Programs) or prevent it from running at startup.
    KBDUKBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
    KBD MediaCenterUMEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
    kbddrv32Xkbddrv32.exeAdded by a CRYPTER.A trojan infection
    kbddrvinfXkbddrvinf.exeAdded by a CRYPTER.A trojan infection
    KCeasyNKCeasy.exe KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella.
    KClientUkstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet.
    kdxNKHost.exeKonTiki Secure Delivery Plug In related. "The Kontiki Delivery Management System (DMS) is a secure delivery network for distribution of video, software, audio, documents, and other digital media. The Kontiki DMS enables enterprises to efficiently publish, secure, deliver and track digital media to employees, partners, and customers"
    KE9801UDriBat32.exeKE-9801 multimedia keyboard - required if you use the multimedia keys
    KeenvalueXKeenvalue.exe eUniverse/KeenValue adware
    KEMailKbUKEMailKb.EXEControls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down
    Kemet?kemet.exe??
    Kerio VPN ClientUkvpnclient.exe Kerio VPN Client
    kern64dllX(filename)Added by a PWSteal.Tarno.J trojan infection.
    Kernal Fault CheckXntosrkl.exeAdded by a variant of the W32/SDBOT WORM!
    kernctl32Xrundll32 kctl32.dll,initializeAdded by a Trojan.Proxy.Agent.AT infection
    KernelXbboy.exeAdded by the MUMU.B VIRUS!
    KernelXservices.exeAdded by Troj/Fooz-A or Troj/VBbot-D TROJAN!
    KERNEL 32XSKERNEL32.comAdded by the W32/SEMAPI-A WORM
    Kernel FaultsXftphost.exeAdded by the RBOT.BHU WORM!
    Kernel LoaderXntkrnl.exeAdded by the CERVIVEC.A VIRUS!
    Kernel ManagerXkrnlmgr.exeAdded by the TROJ_JUNY.A TROJAN!
    Kernel ServicesXservice32.exeAdded by the TROJ/PRX-B TROJAN!
    kernel system daemonXACTIVAT0R.exeAdded by the RANDEX.AW VIRUS!
    kernel12.exeXkernel12.exeAdded by an unidentified WORM or TROJAN!
    kernel32Xkern32.exeAdded by the BADTRANS.A VIRUS!
    kernel32Xkernel32.exe Added by the W32/Chode-I WORM! Note: Do not confuse this with the Windows Kernel32.dll fle. This worm\trojan file is found in the System\(randomly named) folder (95/98/Me) or System32\(randomly named) folder (Nt/2000/XP).
    kernel32Xkernel.dliAdded by the NETDEVIL.B VIRUS!
    Kernel32XKernel.dllAdded by the REDLOF.M VIRUS!
    kernel32Xkernel32.dlIAdded by the NETDEVIL.15 VIRUS!
    Kernel32Xkrnl32.exeAdded by the EPON VIRUS!
    Kernel32XKernel32.winAdded by the GAGGLE.D VIRUS!
    Kernel32Xkernel32s.exeAdded by the W32/SDBOT-PU TROJAN!
    kernel32dllXguardpc.exeAdded by the W32/FORBOT-CU WORM!
    KernelCheckXsys****.exe ( * = digit)Added by an unidentified TROJAN!
    kernelfaultcheckNdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    KernelFaultCheckNdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    KernelFaultChkXsms.exeAdded by the DEADHAT VIRUS! Do not confuse with the valid "kernelfaultcheck" which runs "dumprep 0 -k" or "dumprep 0 -u"
    KernellXsystems.exeAdded by the TARNO.C VIRUS!
    Kernell32XKernell.dllAdded by the DESTINY VIRUS!
    KernellAppsXsvshosti.exeAdded by a Bancban-V trojan infection
    KernellAppsXcsrss.exeAdded by the BANCBAN-AC TROJAN!
    KernellAppsXlexplore.exeAdded by the Troj/Bancban-BS TROJAN!
    KernellApps32Xsmss.exeAdded by the Troj/Bancban-AN TROJAN! Note: This is not the legitimate Windows process smss.exe (Which is always found in the System32 folder) This trojan file is found in the System\Systens (95/98/ME) or System32\Systens (NT/2000/XP) folder.
    KernelwXKernelw32.exeAdded by the INDOR.E VIRUS!
    Kernel_checkXwmiprvse.exeAdded by the W32/SONEBOT-B WORM!
    keyXsysxp.exeAdded by the BEAGLE.AB WORM!
    keyXsys_xp.exeAdded by the BEAGLE.AC WORM!
    keyXwinxp.exeAdded by the BEAGLE.AG WORM!
    Key LoggerXcsrss.exeAdded by the W32.Buchon.A worm.
    Key1XRlid.exeAdded by the LIXY VIRUS!
    Key2?serve.exe??
    KeyAccessYkeyacc32.exeKeyServer KeyAccess client software - "when the KeyServer program is launched, the KeyServer process becomes active so license requests from client computers can be serviced. Without KeyAccess, a keyed program cannot run, so license control is very secure"
    KeybdcntlXkeybdcntl.exeAdded by a Crypter.C trojan variant infection
    Keyboard ManagerUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys. Can also be listed as MULTIMEDIA KEYBOARD
    Keyboard Preload CheckYPreload.exeMillenium Multi-Function Keyboard driver
    keyboard_enumXkeyboard_enum.exeAdded by the TROJ/BDOOR-GP TROJAN!
    KeyMaestroUkmaestro.exeMultimedia keyboard manager. Required if you use the multimedia keys
    keymapUkeymap.exeSystem Tray utility and background task used by games produced by Kesmai (published by Interactive Magic) and which enables you to program keys to do specific actions during the game
    keymgrldrXrundll32 setupapi, InstallHinfSection... keymgr3.inf CoolWebSearch parasite related
    KeyPatrolUKeyPatrol.exeKeyPatrol - detects Key Loggers ("keyboard loggers" or "keyloggers") using both behavioral and pattern-matching algorithms
    keystrokeUkeystroke QuickLaunch is a spyware program that logs keystrokes and captures screenshots. If you didn't install this yourself remove it.
    KeyTextNKeyText.exeKey Text 2000 from MJMSoft Design - utility to automate repetitive keyboard tasks. Available via Start -> Programs
    KeyWalletUKWallet.exe"KeyWallet is a useful and convenient desktop utility that spares you the trouble of filling in your logins, passwords and other personal data manually"
    kfienqXmasbl.batAdded by the KIFER VIRUS!
    kgjdi27Xkgjdie27.exeAdded by the Sdbot.AP WORM!
    khookerNkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
    KICKMON.EXEUKICKMON.EXEKeepItClean - utility that deletes safe to remove files, cookies, browsing history, etc. This is the scheduler - if you don't schedule clean-ups it isn't required
    Kill PopupUKillPopup.exe KillPopup Pop-up stopper
    kimochiz.exeXkimochiz.exeAdded by the TROJ/MDROP-BB TROJAN!
    KinberlinkNKinberlink.exeKinberlink network messaging. Available via Start -> Programs
    KK LoaderUloadkk.exeKeyKey XP Professional from KeyKey.com. "Monitor Instant Messages, Chats, Emails, Web Site URLs, Passwords, Computer Programs, Start Up and Shut Down time and much more completely undetected to the user."
    KKM ServiceXkkm.exeAdded by the W32/Nanpy-I WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    KLogUKeyspy.exeAdded by the Hacktool.KeyLoggPro.B keystroke logger/monitoring program - remove unless you installed it yourself!
    klopX[path to file]Added by the TROJ/AGENT-WQ TROJAN!
    klopX(Ranom).tmpFound with Trojan.Win32.StartPage.aw. Possibly a variant of the Troj/Agent-WQ TROJAN!
    klpUrun32dll.exePAL PC Spy - key recorder and screen capture utility which controls and monitors everything that happens on your pc and online
    klpUexplorer.exe ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is found in a C:\WINDOWS\System\PAL\CSS folder (Win 98/ME) or in the C:\Winnt\System\PAL\CSS or C:\Windows\System\PAL\CSS subfolder (Windows 2000 and Win XP)
    KM9801UUMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
    kmw_run.exeUkmw_run.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
    kmw_show.exeUkmw_show.exeKensington MouseWorks - mouse/trackball software. Not required unles you use any special features
    Kodak Batch TransferNpezdow1.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC
    Kodak EasyShare softwareUEasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually.
    Kodak Picture Easy *.* Batch TransferNPezDownload.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the version
    Kodak Picture Transfer SoftwareNpts.exeLooks for Kodak camera connection and media insertion. Available via Start -> Programs
    Kodak Software UpdaterNbackweb*****.exeSoftware updater for Kodak Easyshare digital cameras
    KodakCCSYKodakCCS.exeKodak DC File System Driver
    KomunikatorUtlen.exe Tlen - a Polish language Instant Messaging client
    Konni Symbol AutostartNKonniSymbol.exeGives configuration access to RagTime Solo professional business publishing software. RagTime Solo is the private user version of RagTime 5
    kontikiNkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    KPDrv4XPYKPDrv4XP.exeMediaKey USB Keypad Driver
    KREC32Ukrec32.exeStarrCommander Pro Keystroke logging software
    KrnlcheckXcsrss.exeAdded by the BACKDOOR.BOTNACHALA TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!
    KrnlmodUKrnlmod.exeKeylogger - see here. Given a "U" recommendation because it depends if you intentionally installed it. If you didn't, treat it as "X" and uninstall or remove via Spybot S&D (for example)
    Ksrv32XKsrv32.exeAdded by the W32/Agobot-PI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    KTAX Auto LoaderXktax.exeAdded by the W32/SdBot-MZ WORM!
    ktchnsnkUktchnsnk.exeHP program found with the Office Jet 500/600/700 series which initializes the Office Jet manager each time the computer is booted up or rebooted
    KV2005Xword.EXEAdded by the TROJ/VB-IW TROJAN!
    kv3000Xlover.vbeAdded by the ZSYANG.B VIRUS!
    kvern16.dllXregsvr32.exe [path] kvern16.dll DailyWinner adware
    KV_HOSTXcxjx.exeAdded by the Troj/LegMir-BB TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    kw3eef76Xrundll32.exe (path) kw3eef76.dll,EnableRunDLL32 LZIO.com adware downloader
    kX MixerNkxmixer.exeProvides Mixer and Control functionality to KxProject Audio driver for EMU10k based soundcards.
    KX509Ukx509_kfwk5.exe Kerberos Secure Authentication for Windows
    KYE_Showicon?shwicon.exeUSB Card Reader tray icon. Shows when the device is plugged in - is it required?
    KYK Control SettingsXKYSVCXD.EXEAdded by a variant of the WIN32.RBOT WORM!
    KYM Control SettingsXphqghum.exeAdded by the RBOT.BQD WORM!
    L4r1$$aXL4r1$$a.pifAdded by the W32/ASSIRAL-C WORM!
    laltinXL90112201.Stub.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    LAN DriverXlandriver32.exeAdded by the RBOT.BT WORM!
    lanbrupXlanbrup.exe SafeSurfing adware
    LanguageMonitorUOplmsb01.exeOKI Printer language support monitor
    LanGuardXlanguard.exeAdware downloader - also detected as the TROJ/SECONDT-C TROJAN!
    LanGuardX(Pathname of the Trojan executable)Added by the Troj/Dloader-VO TROJAN!
    LanSpeed2ULanSpeed2.exeMonitors any traffic that is using a LAN adapter (Ethernet or Token ring network card)
    laokey.exeULaoKey.exeLao Script for Windows (LSWin) is an extension to the Windows operating system to allow Lao language to be used with many different Windows-based applications.
    LapLink schedulerULlsched.exeUtility that automatically performs file transfers as unattended background operations
    LarXLlass.exeAdded by the INOR-A VIRUS!
    larX(trojan filename)Added by the ROXY.C VIRUS!
    LARISSA ANTI VIRUSXLARISSA_ANTI_VIRUS.exeAdded by the Klassir TROJAN!
    Lasb?ewat.exe??
    LasErmaXErmasys32.exeAdded by the W32/Lerma-A http://www.sophos.com/virusinfo/analyses/w32lermaa.html WORM! Note: This worm file is found in the Windows or Winnt folder. Makes multiple copies of it's self in the Windows and Windows System folders.
    LAsIAf32XRePEAtLD.exeAdded by the REPEATLD VIRUS!
    LASTinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    Later?later.exe??
    LaunAppULaunApp.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
    Launcg?launcg.exe??
    Launch Ai BoosterUOverClk.exeThe ASUS Ai_Booster is an application that allows you to overclock the CPU either manually or automatically without the hassle of entering the BIOS Setup.
    Launch Norton AntiVirus 2000Xjorgf.exeAdded by W32/Rbot-AUI WORM!
    Launch YahooPOPs! at Windows startupNYAHOOPOPS.EXEYahooPOPs - enables free POP3/SMTP access to Yahoo! Mail through a service on localhost that emulates the web interface. Available via Start -> Programs
    LaunchApULaunchAp.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
    LaunchAppUAlaunch.exeAcer Launch tool utility on laptops
    LaunchboardUlnchbrd.exe"LaunchBoard software from Darwin turns your keyboard into a remote control for the Internet and your computer! With LaunchBoard 2.0, you can customize up to 38 keys on your PC keyboard to instantly launch Web Sites, start applications, perform custom macros, handle Windows shortcuts, store passwords, and perform loads of other customizable functions"
    LauncherXlauncher.exeSpyware component related to DownloadWare and found in Program FilesKFH
    LauncherNrelaunch.exeAudio Applications Launcher for the Philips Rythmiic Edge soundcard (the Philips Rhythmic Edge is the same as the Thunderbird PCI soundcard - see TBtray). Available via Start -> Programs
    Lavasoft Ad-AwareXAd-Aware.exeAdded by the W32/RBOT-SO WORM! - NOTE: this is NOT the popular spyware remover, as described here
    Lavasoft AdwatchUAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    laxmsp32.exeYlaxmsp32.exeLexmark Scan and Copy Control Program for the X63 (and maybe others) printer/scanner. Required for the scanner to work 
    LazXKernn.exeAdded by the TROJ/BANCOS-LN WORM!
    LCDCULCDC.exeLCDC is an application that displays various information on your LCD or VFD screen. The number of things that LCDC can do is expandable by Plugins
    LCDPlayerYLCDPlyer.exeRelated to SuperAdBlocker
    lcfepNlcfep.exeTivoli ‘TME’ System Tray icon - "\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
    LClockUlclock.exe LClock is a program that makes the Windows' clock look like a Windows Longhorn Clock.
    lcvgaXlcvga.exeAdded by the Hostol-A TROJAN!
    ldXld.exe CoolWebSearch parasite variant
    LDMNbackweb-8876480.exe, ldmconf.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech. Also listed under Logitech Desktop Messenger
    ldriverXldriver.exeAdded by the Troj/Chorus-A TROJAN! Searchforfree Browser hijacker.
    LED TRAYULEDTRAY.EXEInstalls a USB compact flash card reader or drive on start-up. The device is distributed by Microtech and is made by a company called SnapShot. Required if you want the reader to work
    ledpointerUCNYHKey.exeChicony Electronics Multimedia Keyboard Hotkey Driver
    LeechGetNLeechGet.exeLeechGet download manager
    leemanXleeman.exeAdded by the Troj/Cosiam-D TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    LetsSearchXLetsSearch.exeBrowserAid/BrowserPal foistware variant
    Lexmark **** seriesUlxbtbmgr.exeLexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
    Lexmark **** SeriesUlxbkbmgr.exeLexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
    Lexmark **** SeriesUlxbmbmgr.exeLexmark System Tray application (where "****" is the model) that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
    Lexmark 2200 Series Button ManagerYlxbvbmgr.exeLexmark printer button manager. Required for correct operation
    Lexmark 3100 SeriesYlxbrbmgr.exeLexmark printer button manager. Required for correct operation.
    Lexmark X** Button ManagerYAcBtnMgr_X**.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    Lexmark X5100 SeriesUlxbabmgr.exeSystem Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
    Lexmark X6100 SeriesYlxbfbmgr.exeLexmark X6100 printer button manager - required for correct operation
    Lexmark X74-X75Ulxbabmgr.exeSystem Tray application that enables scan or fax functions to run directly from the printer via the buttons. Can be launched from a desktop shortcut
    Lexmark Xxx Button MonitorYACMonitor_Xxx.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    LexmarkPrinTrayNprintray.exeLexmark Printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. Can also be listed as PrinTray
    lexploreXlexplore.exeAdded by the W32.BROPIA WORM! - NOTE: this process is spelled "LEXPLORE.exe" (with an "L"), not Iexplore.exe like the familar Internet Explorer executable!
    lexppsNlexpps.exeFor Lexmark printers. From Lexmark: "This enables bi-directional printing over a peer to peer network. If the printer is connected directly to your PC, the file is not used, (or should not be used) at all". It is known that firewalls can however alert you to "lexpps.exe" requesting server privileges
    LexStartUlexstart.exeLexmark printer software may add Lexstart.exe in the startup folder to handle print commands that you send to the printer. Sometimes required for the printer to work correctly - not in the case of a Lexmark Z42 for instance
    LfhXLfh.exeAdded by the TROJ/ZAURGA-A TROJAN!
    LfsndmngUlfsndmng.exeLightningFAX Enterprise Fax Server - "puts faxing at the fingertips of networked enterprise users. It enables rapid, secure sending and Direct-To-Desktop Delivery of mission-critical documents"
    lhttsengNrundll32.exe ..lhttseng.inf, RemoveCabinetLeft over after installation of the British English version of the Lernout & Hauspie Text To Speech (TTS) Engine
    li-multi****Xli-multi****.exeAdult web-dialler - **** is random
    li-speed****Xdlres.exeAdult web-dialler - **** is random
    li-thund****Xli-thund****.exeAdult web-dialler - **** is random
    li-vita****Xli-vita****.exeAdult web-dialler - **** is random
    li01f948Xrundll32.exe (path) li01f948.dll,EnableRunDLL32 LZIO.com adware downloader
    LicCrtlNrunservice.exePart of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
    LicCtrlUrundll32.exe [path] MMFS.DLL,ServicePart of the eLicense Copy Protection scheme employed by some software and games. When this service is not running, the eLicense wrapper is unable to extract and execute the program
    LidPolicyUpwrschem.exeA utility for configuring certain HP notebook models to enter Standby mode when the lid is closed only when running on battery.
    Life FireWall Update1XFireWall-Update1.exeAdded by the W32/RBOT-ARS WORM!
    LifeScape Media DetectorNPicasaMediaDetector.exeMedia detector for Picasa's automatic photo organizer
    lifyXyujixit.exeAdded by a variant of the W32/SDBOT WORM!
    Lightning DownloadULightning.exe Lightning_Download download manager. Can be launched manually, but will need to start up if you want it to "catch clicks" off Internet Explorer
    LimewireXLimeWire.exeAdded by the W32/Rbot-AGH WORM!
    LimeWire x.xNLimeWire.exe LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware
    LimpetXexplorer16.exeAdded by the W32/Rbot-AJD WORM!
    Line Speed Meter V3.0NLineSpeedMeter.exeLineSpeedMeter - detect the download and upload speed of your internet connection
    LinkstsNlinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    LinkstsXlinksts.exeTray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon
    LinuxXLinux.vbsAdded by the LOVELETTER.AS VIRUS!
    LiquidViewUlviewj.exe"Liquid View lets you increase the legibility of the Microsoft Windows interface regardless of your display\'s native resolution. The software lets you increase the size of items that are hard to read on your monitor"
    LisaXLisa.exeAdded by the DIAL/SCOM-D premium rate adult content dialer.
    List checker 32 BITXlist32.exeAdded by the W32/Rbot-AHO WORM!
    LitebotX(Path to Trojan EXE)Added by the Troj/Litebot-A TROJAN!
    LIUNRubicon.exeLogitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
    LIUNLIU.exeLogitech Internet Update. Used to update drivers/software for Logitech's Wingman, QuickCam, etc devices. Reports claim it doesn't work very well and you can manually update the files anyway
    Live MenuNDllcmd32.exeeFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here
    LiveMonitorNLMonitor.exeMSI Live Update2 - auto-detects and suggests the latest BIOS/Driver/Utilities information
    LiveNoteNLivenote.exeAsus graphics card driver live update feature
    LiveSexCamsXLiveSexCams.exePremium rate adult content dialer
    LiveUpdateULiveUpdate.exeWeb-update utility as used by various types of software - see http://liveupdate.openwares.org/
    LivreXDibane.batAdded by the W97M.BANEDI VIRUS!
    LLMODCL2?rundll.exe setupx.dll, InstallHinfSection ..LLMODCL2.INF??
    llsassXllsass.exeAdded by the TROJ/PROXY-GG TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    LM StatusNLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
    LMA ManagerXlmamanager.exeAdded by the W32/Tilebot-AD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    LManagerUQtZgAcer.EXEAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    LManagerUQtZpAcer.exeAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    LManagerUHotkeyApp.exeAcer Launch Manager - on Acer laptops it allows users to configure shortcut keys and to set the operating state of the WLAN module and the (optional) Bluetooth radio
    lMAPlXlMAPl.exeAdded by the W32/AGOBOT-RE WORM!
    LMgrOSDUOSDCtrl.exeOSD (on-screen-display) utility - Part of Acer Launch Manager. Gives you control to customize the monitor to your liking...from sound, brightness, contrast, horizontal and vertical positions, phase, pixel clock, color and language - User's choice!
    LMonitorNLMonitor.exeLmonitor utility comes with MSI\'s LiveUpdate Version 3 - periodically checks for updated drivers and utilities
    lmpdpsrv?lmpdpsrv.exeRelated to a Lexmark printer/scanner. Printer sharing server? Is it required?
    lmrtXlmrt.exeUnidentified adware
    LMSTATUSNLMSTATUS.EXEXerox WorkCenter XE - language monitor status application
    lmuXLMU.exeDownloader trojan, recognized by Kaspersky antivirus as Backdoor.Win32.Agent.bg
    lnternet ExplorerXAMSNDMGR.EXEAdded by the KWBOT.R VIRUS! Note that the "l" is a lower case "L" and not an upper case "I"
    LoadXmdm.exeAdded by the Backdoor.Binghe TROJAN!
    loadXmsgsr32.exeAdded by the W32/SDBOT-QR WORM!
    loadX[file path to the worm]Added by the W32.Kelvir.AI WORM!
    LoadXMyGame.exeAdded by the W32/LameYear-A Worm!
    loadXsvhost32.exeAdded by the PWSteal.Wowcraft TROJAN!
    loadXInternat.exeAdded by the PWSteal.Wowcraft TROJAN!
    loadXrundll32.exeAdded by the PWSteal.Wowcraft TROJAN!
    loadX_Kerne1.exeAdded by the Troj/Lineage-AN TROJAN!
    loadXsvchsot.exeAdded by the Troj/GWGhost-O TROJAN! Note: (svchsot.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    loadXKerne14.exeAdded by the Troj/Lineage-BA TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    loadXdll.exeAdded by the Troj/Bdoor-LX TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    LOAD WBULOADWB.EXEPart of Stardock's WindowBlinds custom desktop program. "WindowBlinds is the first utility of its kind. It extends Win98/NT/2K/XP to have a fully skinnable user interface. You can change the style of title bars, buttons, toolbars and much more". If you use it - keep it if not then uninstall it
    Load-GuardXLGuarg.exe.vbsAdded by the VBS.YENO.C WORM!
    LOAD32XLorena.exeAdded by the W32.Mapson.C WORM!
    load32Xload32.exeAdded by the W32.DUMARU WORM!
    load32Xl32x.exeAdded by the W32.DUMARU.Z W32.DUMARU.Y or DUMARU.AD WORM!
    load32X1111a.exeAdded by the W32.Dumaru.AH WORM!
    load32Xload32.exeAdded by the NIBU or W32.Bambo TROJAN!
    load32Xswchost.exeAdded by the TURTA.A WORM!
    load32Xnetda.exeAdded by the NIBU.E TROJAN!
    load32Xswchost.exeAdded by the NIBU.I TROJAN! and the W32/Dumaru-AK WORM!
    load32Xwinldra.exeAdded by the BACKDOOR.NIBU.J or DUMARU-BI and Troj/Dumaru-N TROJANS! Note: Also known as Srv.SSA-KeyLogger by Sunbelt Software which has developed a free removal tool for this KeyLogger. For more information Click_Here
    load=Xdapdll.exeAdded by the W32.ATAK.E WORM!
    load=Nadw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
    load=Uasistat.exeStatus monitor for an NEC SuperScript printer
    load=?cfgsys32.exe??
    load=Uesspk.exeSpeakerphone capability through a soundcard for an ESS modem
    load=Yhotkey.exeSolo 5300 display driver for Win2K on some Gateway laptops
    load=NHPWHRC.EXELoads the Status Window software for the HP Laserjet printers
    load=?WPSLOAD.EXEWindows printing system that comes with the setup for Canon BJC series on the manufacturer's disk
    load=Nvi_grm.exeMonitor drivers for Trio2x/3x based video cards - displays control panel for quick access to display settings
    load=?WINOSCFG.EXECould it be something to do with configuring Windows on a new PC from an OEM supplier?
    load=Ywpshrc.exeRequired to prevent configuration errors on a Compaq LBP-660 parallel port laser printer (and maybe others)
    load=YBfrecv.exeBitware modem driver
    load=Xmsater.exeAdded by the RETSAM VIRUS!
    load=Xshambl3r.exeAdded by the REMABL VIRUS!
    load=XSpoolsv.exeAdded by the CIADOOR.B VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    Load=?wtfeat.exeAssociated with the Wintab Digitizer
    load=YAICLIENT.EXEAsset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system
    load=Xhint.exeAdded by the W32.ATAK WORM!
    load=Xa1g.exeAdded by the ATAK.B WORM!
    load=Xsvhost32.exeAdded by the TROJ/LINEAGE-AB TROJAN!
    load=Y[path] 01comm32.exeRelated to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions, plus a terminal program, a WWW-browser launch function, Internet telephony, and address management. Required if you use those.
    load=Xinetinfo.exeAdded by the TROJ/PROXY-GG TROJAN!
    Loadab1Xexplorer.exeAdded by the Troj/Lineage-AJ TROJAN!
    LoadBlackDYblackd.exeThis is the "intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility)
    LoadBtnHnd?BtnHnd.exeFujitsu LifeBook related
    LoadDBackUpXBcTool.exeAdded by the GIBE VIRUS!
    loaddllXloaddll.exeAdded by Winvest SPYWARE!
    LoadDvpApi9x?DVPAPI9X.exePart of Command AntiVirus for Windows 95/98/Me. Is it needed?
    loaderXloader.exeHomepage hijacker, redirecting to coolwwwsearch.com. Downloader for iedll.exe
    loaderXWMPLAYER.EXEUnknown baddie - WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn\'t load at startup
    loader32Xsys*****.exe [***** = random digit]Added by the Domcom TROJAN!
    loader32XLoader32.exeAdded by an unidentified TROJAN!
    LoadersXHeIp.exeAdded by the W32/Sdbot-ADB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    loadfaxXloadfax.exeAdded by the Troj/Winflux-C TROJAN!
    LoadFontsXLoadFonts.vbs, Tahoma.vbsHomepage hijacker that changes your homepage to an adult content site
    LoadGolfCoursesXLoadGolfCourses.exePlayMiniGolf.com foistware - stealth installed!
    LoadHTMLXrundll32.exe mshtmpre.dll, MShtmpre Mshtmpre adware
    LoadingAgentXZipLoader32.exeAdded by the OBLIVION TROJAN!
    LoadingAgentXmsload32.exeAdded by the OBLIVION TROJAN!
    LoadManagerXmsload.exeAdded by the OPASERV.T VIRUS!
    loadMecq0Xexplorer.exeAdded by the MUMUBOU.C TROJAN! ** Note - this is not the legitimate Windows Explorer (explorer.exe) which would only be in startups if you added it manually
    loadMecq3Xrundll32.exeAdded by the Troj/LegMir-AS TROJAN!
    loadMect1Xexplorer.exeAdded by the TROJ/LINEAGE-L TROJAN! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Program Files folder! Note: The LINEAGE-AD variant will drop the ct1dll.dll file in the system folder.
    loadMefsXrundll32.exeAdded by the TROJ/LEGMIR-JA TROJAN! - NOTE: this file is found in the C:\Windows\help folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
    loadMefsXsmss32.exeAdded by the TROJ/FLOOD-EL TROJAN!
    loadMefsXrundll32.exeAdded by the Troj/LegMir-JB TROJAN! Note: This is not the legitimate Windows Process rundll32.exe, Which is found in the Windows folder(98\ME) or the System32 folder(NT\2000\XP). This trojan file is found in the Windows\inf or Winnt\inf folder.
    LoadMSvcmmNmsvcmm32.exeAuto-update for Movielink - internet movie rental System Tray access
    LoadOrderVerificationX*.exeAdded by the TRON VIRUS! * is a random file name, possibly Pthymvfr.exe
    Loadout ManagerUnost_LM.exeManager for the Belkin Nostromo n50 SpeedPad game controller - see here
    LoadPFWXwmimgr.exeAdded by the W32/Qeds-B Worm!
    LoadPowerProfileXASDAPI.EXEAdded by the CABRO VIRUS! Not to be confused with the valid entry below
    LoadPowerProfileURundll32.exe powrprof.dllPower management specifics such as monitor shut-off, system standby, etc. Associated with power management and is listed twice - see here. Loads your selected power scheme. May not be required - depends upon whether you modify the default Control Panel -> Power Options settings
    LoadPowerProfileXRundll.exe powerprof.dllAdded by the LOXOSCAM TROJAN! **Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses "Rundll.exe" whereas the uninfected version uses "Rundll32.exe"
    LoadPowerProfileXrundl.exeAdded by the TOFAZZOL VIRUS! Note - do not confuse with the valid LoadPowerProfile entry above!
    LoadPowerProfileXRundll32.exeAdded by the MIROOT VIRUS! Note - do not confuse with the valid LoadPowerProfile entry which has "powrprof.dll" appended to the command/data line
    LoadPowerSchemeXrundll32.exe powerprof.dll CheckPowerProfile Ulubione adult content dialer
    LoadQMUloadqm.exeInstalled with MSN Explorer and loads the MSN Queue Manager. Required to enable the WU AutoUpdate feature. Note that disabling this can sometimes prevent internet sharing working on Win2K Pro SP2. Reports also suggest that removing it will re-enable internet access - hence the "users choice" recommendation. If you have problems leave it, otherwise I recommend you disable it
    loads.exeXloads.exe MediaMotor/Popuppers adware downloader
    loads.exeXmedload.exe MediaMotor/Popuppers adware downloader
    loads.exeXsuploads.exe MediaMotor/Popuppers adware downloader
    LoadServiceXRest In PeaceAdded by the W32/KANGAROO-A WORM!
    LoadServiceXVirusAdded by the CAGER.A WORM!
    LoadServiceXMaaf, tempatmu bukan di sinAdded by the Troj/Kagen-A TROJAN!
    LoadSIPSXrundll32.exe [path] SIPSPI32.dll,SIPSPI32123Mania adware
    LoadWatcher?Test.exeReportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct?
    loadwinXwinset.exeAdded by the TROJ/QQPASS-I TROJAN!
    loadwinXwinsys.exeAdded by the TROJ/QQPASS-J TROJAN!
    LoadWindowsFileX(filename)Added by the DELF.B VIRUS! where <filename> is the infected file
    Local Area NetworkXOpenGL.exeAdded by a variant of the WIN32.RBOT WORM!
    Local Internet ConnectionXLIC.exeAdded by the W32/SDBOT-YA WORM!
    LOCAL INTERNET WEB DRIVERS FOR WIN32Xphqghume.exeAdded by a variant of the WIN32.RBOT WORM!
    Local PageXhttp://find.naupoint.com Naupoint browser hijacker
    Local runole serviceXsrvc32.exeAdded by the TROJ/SMALL-DP TROJAN!
    Local Security Authority ServiceXlssas.exeAdded by the W32/POEBOT-J WORM!
    Local Security Authority ServiceXIsass.exeAdded by the W32.LINKBOT.M WORM!
    Local ServiceXIntenat.exeAdded by the Troj/Nuclear-J TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Local-Settings-of-[User Name]X[User Name].exeAdded by the W32.Gavgent.A WORM!
    Lock My PCUlockpc.exe Lock_My_PC . A tool for quick computer locking when you leave it unattended. It shows a lock screen, disables Windows hot keys and mouse.
    LoginUwinlog.exeSalfeld Child Control 2003 - parental control software
    Login Screen SaverXlogin.scrAdded by the W32/Rbot-AVN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Login ServiceX(path to file)Added by the MIGMAF VIRUS!
    LoginPassportXLgnpsp32.exeAdded by the REDIST.C VIRUS!
    LogitechXLogitech.exeAdded by the RBOT.BJH WORM!
    Logitech CameraXSoundcane.exeAdded by the SDBOT.MUC WORM!
    Logitech DesktopXIPCONN.EXEAdded by the W32/SDBOT-WE WORM!
    Logitech DesktopXApPache.exeAdded by the W32/RBOT-YP WORM!
    Logitech Desktop ControllerXwrcam.exeAdded by a variant of the WIN32.RBOT WORM!
    Logitech Desktop MessengerNbackweb-8876480.exe, ldmconf.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products, services and special offerings from Logitech
    Logitech Hardware Abstraction Layer?Khalmnpr.exeLogitech Bluetooth mouse Hardware Abstraction layer. A "hardware abstraction layer" is an interface that enables adding support for new devices and new ways of connecting devices to the computer, without modifying every application that uses the device. Not sure whether required.
    Logitech SetPointUKEM.exeKeyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
    Logitech SetPointUSetPoint.exeKeyboard and mouse drivers and utilities for Logitech's latest products - supersedes iTouch and MouseWare on their older products. Required if you use special features such as multimedia keys
    Logitech UtilityULogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    Logitech UtilityULogi_MwX.ExeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    Logitech WakeupNlgwakeup.exeLoads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
    Logitech WirelessXlogitechwls.exeAdded by the W32/Mytob-BS Worm!
    LogitechGalleryRepairUISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    LogitechImageStudioTrayNLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    LogitechsXLogitechs.exeAdded by the SDBOT.BWE WORM!
    LogitechSoftwareUpdate?ManifestEngine.exeUpdater, part of Logitech Image Studio - installed with Logitech QuickCam cameras. Probably not required.
    LogitechVideoRepairUISStart.exeLogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
    LogitechVideoTrayNLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    LogiTrayNLogiTray.exeLogitech Image Studio - installed with Logitech QuickCams
    Logi_MwxULogi_MwX.exeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    Logi_MwxULogi_MwX.ExeLogitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as "SmartMove". If you disable it and find you don't need it leave it disabled
    LogMeIn GUIUragui.exe RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone.
    LogMeIn GUIULogMeInSystray.exe RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN, an intranet or the Internet) - and on the client side all you need is a web browser, a terminal emulator or a WAP-enabled phone.
    LogoX(path of the Trojan EXE)Added by the Troj/Dloader-RH TROJAN!
    Logon LoaderULogonLoader.exe Logon_Loader - customize Boot & Login Screens
    Logon Loader RandomULogonLoader.exe Logon_Loader - customize Boot & Login Screens
    Logon.exeXlogon.exeAdded by the BKDR_ZINS.A TROJAN!
    logon.exeXlogon.exeAdded by the Zins.B TROJAN!
    LogonStudioUlogonstudio.exeWinCustomize LogonStudio - "Allows Windows XP users to edit, change, and apply new logon screens. LogonStudio comes built with a visual editor to make it easy to create your own logons which can then be uploaded to websites to be used by others users"
    LogServiceXwincalc.exeAdded by the BACKDOOR.PAPROXY TROJAN!
    LogServiceXlsass.exeAdded by the Troj/Bdoor-IU TROJAN! Note:This is NOT the legitimate Windows lsass.exe process, which should NOT figure in Startup!
    LogWatchUlogwat95.exeLicensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll - see here. Not required if you already have a newer version or the patch has been applied
    longosXWIWT.EXEAdded by the BANKER-CD TROJAN!
    Look 'n' StopYlooknstop.exeLook 'n' Stop personal firewall
    LookNMeetUAgent.exe LooknMeet dating service
    Lookup_SysXlookupsys.exeP04n trojan
    Lotus Organizer EasyClipNeasyclip.exe"The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address, appointment, task or Notepad page." Available via Start -> Programs
    Lotus QuickStartNsmartctr.exeLotus central application, called SmartCenter, which runs on the Windows desktop. SmartCenter toolbar stretches across the top or, optionally, the bottom of the screen. Uses a lot of resources. Available via Start -> Programs
    Lotus SuiteStartUsuitest.exePuts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
    LowVersionSupportX(random filename)Added by the LASTRAS VIRUS! where <filename> is the name of the file dropped by the virus
    LprXLpr123.exeAdded by the REMPSTEAL password stealer TROJAN!
    LPSULps.exeLocal Port Scanner - "With LPS you're able to check your computer for open or listening ports"
    LPtaskUlptask.exeProgram Lock It And Protect Pro - lock and protect your folders from being opened, moved or deleted
    LRBZ Utility 32Xlrbz32.exeAdded by the W32/AGOBOT-JQ WORM!
    LS120 SuperdiskN??Supposed to accelerate transfer rate on LS-120, contributes to system lockups
    LSAXwfdmgr.exeAdded by the W32.Mytob.C WORM!
    LSAXlsa.exeAdded by the W32/SDBOT-YV WORM!
    LSA ServiceXLSASS.exeAdded by the W32.Ahker.G WORM! **Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!
    lsa ServicesXlsa2srv.exeAdded by the W32/Tame-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    LSA Shell (Export Version)XLSASS.exeAdded by several variants of the AHKER WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    lsassXlsasrv.exeAdded by the W32.Mydoom.AU WORM!
    lsassXlsass.exeAdded by the RATSU.B VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
    lsassXstart.batAdded by the ZCREW VIRUS!
    lsassX(path to lsass.exe)Added by the ALADINZ.F VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
    lsassXlsasrv.exeAdded by the SAVAGE.A WORM!
    lsassXlsasrv.exeAdded by the W32.Mydoom.AS WORM!
    LsassXwoekd.exeAdded by an unidentified WORM or TROJAN!
    LsassXkavmm.exeAdded by an unidentified WORM or TROJAN! - NOTE - do NOT confuse with the legitimate Kaspersky antivirus module as described here . Contrary to this impostor, the legitimate file will always be located in the Kaspersky Lab folder in Program Files.
    lsassXelite***32.exe EliteBar adware variant
    LSASS 32XISASS32.pifAdded by the W32/ASSIRAL-C WORM!
    LSASS AuthorityXlshosts32.exeAdded by the SDBOT-UY TROJAN!
    LSASS AuthorityXlsvhosts.exeAdded by the SDBOT.BCE WORM!
    LSASS DaemonXLSASSd.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    lsass serviceXlsass2.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    lsass2k UpdateXlsass2k.exeAdded by a variant of the WIN32.RBOT WORM!
    LSASS32XIsass32.exeAdded by the W32.KELVIR.M WORM!
    lsass32Xlsass32.exeAdded by the Troj/Lydra-B Trojan!
    lsass64BiT.exeXlsass64BiT.exeAdded by the W32/FORBOT-CK WORM!
    lsassigXlsassig.exeAdded by the Troj/Bancos-EC TROJAN! Note: This trojan file is found in the System\drivers (95/98/Me) or System32\drivers (Nt/2000/XP) folder.
    lsasssXlsasss.exeAdded by the Troj/Geekmy-A TROJAN! Note: lsasss.exe (notice the extra s) is not the legitimate Windows Process. (lsass.exe) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    lsasss.exeXlsasss.exeSasser.E worm
    lsburnwatcherNlsburnwatcher.exeUsed for automatically updating HP programs
    lsessXlsess.exeAdded by the WURMARK.S or W32.SINNAKA.A WORM
    lsmss.exeXlsmss.exeAdded by the TROJ/PROXY-GG TROJAN!
    LSPFixNLSPmonitor.exeeAcceleration Stop-Sign related - not recommended, see note
    LSPmonitorNLSPmonitor.exeeAcceleration Stop-Sign related - not recommended, see note
    lssassXlssas.exeAdded by the AGOBOT.RL WORM!
    LSvrXLSvr.exePowerStrip foistware
    LT DAEMONYltdaemon.exeActs as a data spooler for the DSL modem (similar to a cache). Do not uncheck if the DSL modem is being used
    LTDMgrXLTDMgr.exePowerStrip foistware
    LTM2XMSGSRV32.EXEAdded by a LITMUS VIRUS variant! (Note: MSGSRV32.EXE in this case is in a Litmus sub-directory and is not to be confused with the valid version in C:\Windows\System)
    LTM2X bible.exeAdded by a LITMUS VIRUS Variant!
    LTM2Xwinupdate.exeAdded by a LITMUS VIRUS Variant!
    LTM2XMSGSRV320.EXEAdded by a LITMUS VIRUS Variant!
    LTM2XMPGSRV32.EXEAdded by a LITMUS VIRUS variant!
    LTM2Xwinscan.exeAdded by the TROJ/LITMUS-B TROJAN!
    LtMohULtmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
    LTMSGYltmsg.exeOne of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    LTSMMSGNLTSMMSG.exeLucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too
    LTSMSGXShell32.exeAdded by the PWSteal.Lemir.B TROJAN!
    LTWinModem1Yltmsg.exeOne of the "popular" WinModem series. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    ltwobXformatsys.exeAdded by the W32.Serflog.A WORM!
    ltwobXserbw.exeAdded by the W32.Serflog.A WORM!
    ltwobXmsmbw.exeAdded by the W32.Serflog.A WORM!
    LUGuardULUGuard.exePC-Duo Remote_Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN, WAN or internet.
    LusetupYLUSetup.exeSymantec, LiveUpdate_installer , required to install a new version of the application - will only run once, and the entry is automatically deleted after a reboot.
    LVComsUlvcoms.exeLvcomm server. Related to Logitech Quick Cam - works fine without it but it is needed for the Logitech ImageStudio software to connect to the camera
    LVCOMSXULVCOMSX.EXEIt provides extra functionality for Logitech multimedia webcam devices. It is non-essential to the running of the system, but should not be terminated unless suspected to be causing problems.
    LWBMOUSEUlwbwheel.exe, MOUSE32A.EXEMouse driver - required if you use non-standard Windows driver features
    Lwinst Run ProfilerNlwtest.exeLogitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
    lxamsp32?lxamsp32.exeAssociated with a Lexmark Printer - is it required?
    LXBLKsk?LXBLKsk.exeLexmark related, not sure whether required
    lxbrbmgrYlxbrbmgr.exeLexmark printer button manager. Required for correct operation.
    LXBRKsk?LXBRKsk.exeLexmark printer related - what does it do and is it required?
    LXBTCATS?rundll32 [path] LXBTtime.dll,_RunDLLEntry@16Lexmark printer related - what does it do and is it required?
    LXSUPMONNLXSUPMON.EXELexmark Printer. The printer should work fine without it
    lycosInside?Lyc_SysTray.exe Lycos_eMail related - what does it do and is it required?
    LzioMediaUpdaterXLzioMediaUpdater.exe LZIO.com adware downloader
    M Player Post Installer?postinstallm.exe??
    M-soft OfficeXM-soft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    M1cr0s0ft S3rcurityXsystemconfig.exeAdded by the RBOT.BKB WORM!
    M1cr0s0ft Upd4t4zSXupdate32.exeAdded by the W32/RBOT-MI WORM!
    m32infoXm32info.exeAdded by a CRYPTER.A trojan infection
    M3TrayNm3tray.exeMovielink - internet movie rental System Tray access
    m4n70s Personal FirewallXm4n70s.exeAdded by a variant of the W32.SPYBOT WORM!
    Macfee Security PatchXMpfsheild.exeAdded by the W32/RBOT-NP WORM!
    Machine Debug ManagerUmdm.exeUsed by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as MDM7. See here to disable
    Machine Debug ManagerXmsdn.exeAdded by a variant of the WIN32.RBOT WORM!
    Machine Update SoftXwusas.exeAdded by an unidfentified WORM!
    MacLicNMacLic.exePart of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
    MacNameNMacName.exePart of Conversions Plus from DataViz - allowing PC and MAC owners to share disks
    Macromedia Critical UpdaterXrarww.exeAdded by a variant of the WIN32.RBOT WORM!
    Macromedia Dreamweaver XMXmacdwXM.exeAdded by the W32/AGOBOT-RI WORM!
    Macromedia DriveXIexplor32.exeAdded by a variant of the WIN32.RBOT WORM!
    Macromedia Flash UpdateXscvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    MAD.EXEYMAD.EXEMAD.exe is the MS Exchange 5.5 System Attendant and can also consume a large amount of resources - resolved by the latest Exchange 5.5 Service Pack. Also part of Exchange 2000 Server but does it have the same problems?. Apparently you need to leave this running but is it needed at start-up?
    MadExeNLaunchRA.exeDell Resolution Assistant
    MAFWTaskbarAppUMAFWTray.exeDrivers for the M-Audio Firewire Audiophile - Interface
    MagicDskUMAGICDSK.EXEMagic DeskTop is a small and novel utility which will allow you the option of hiding or showing your desktop icons
    MagicLinker3UMagicLnk.exe ThaiSoftware Thai Dictionary
    MagitimeNMagitime.exeMagitime - connection tracking utility which monitors online time, expense, data transfer
    Mail.com?mcalert.exeMail.com - free web-mail service. Does mcalert.exe notify you when new mail has arrived?
    MailBellUmailbell.exeMailBell e-mail notification tool that will notify you about new messages arrived to your mailbox. Works with both POP3 mailboxes and web-mail based systems. You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
    Mailbox VerifierUmboxvrfy.exeMailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)
    MailCleanerNMAILCLEANER.EXEMailCleaner "protect your computer from viruses sent to your machine via the popular e-Mail reader Incredimail. In addition the program will check all incoming files downloaded by Internet Explorer, Netscape Navigator, ICQ and iMesh" - not recommended as it bundles Gator/Gain/Claria adware
    mailman.exeXmailman.exeAdded by the CERTIF-E TROJAN!
    MailScan DispatcherYLaunch.exeMailScan Dispatcher splits each e-mail message into various components such as the header, body and attachment. Compressed formats (ZIP, ARJ, etc.) are scanned for viruses and cleaned
    MailSkinnerXmailskinner.exe MailSkinner - an application by Electronic_Group , notorious for its premium rate "drive by" installed porn dialers
    Mail_CheckXMail_Check.exeAdded by the PANOIL.C VIRUS!
    MAINUmain.exeSpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
    Main Executable (HP)?HP05T0R5.exeHP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?
    main16Xmain16.exeAdded by a CRYPTER.A trojan infection
    main32Xmain32.exeAdded by a CRYPTER.A trojan infection
    MainStartXsvcmfte32.exeAdded by the Troj/Stinx-A Trojan!
    mainviewexXmainviewex.exeAdded by the W32.GEMA.D TROJAN!
    Major Microsoft Windows Driver Boot loaderXbpool.exeAdded by the W32.MYTOB.AJ WORM!
    ManageProtocolCtrlXcsmsv.exeAdded by the W32.Looksky.B or Troj/Stinx-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Mania Win RestoreNRESWIN.EXEPinball Mania for Windows from 21st Century Entertainment LTD (1995). Runs briefly at start-up then terminates. Available via Start -> Programs
    MantisX(filename)Added by the MANTIBE VIRUS! where <filename> is the filename
    MapiDrvXmpisvc.exeAdded by the MIPSIV VIRUS!
    mapisvc32Xmapisvc32.exeAdded by the KX VIRUS and also recognised by Symantec as FPAI adware
    mark the serviceXxxtra32.exeAdded by the SDBOT.APP WORM!
    MartiniXpinmart.exeAdded by a variant of the W32/SDBOT WORM!
    Mascro soft SDK updates2XSDKrepair2.exeAdded by the SDBOT.BXM WORM!
    Mascro soft SDK updates2XSDKrepair2.exeAdded by a variant of the W32/SDBOT.W WORM!
    masqform.exeNmasqform.exePureEdge Viewer 6.0, reportedly associated with viewing and text editing US Air Force electronic forms
    Mass storage check registryNrundll32.exe MSDServ.dll, check registryUsed with a USB based smartmedia card reader
    Master Volume SpyUMASTERVOLUMESPY.EXEVolume control for the Gateway Destination "DestiVu" media interface
    MatadorUmlfbuddy.exeMailFrontier - anti-spam application
    MatadorUmantispm.exe MailFrontier_Desktop (Matador) email spam blocker software
    MatrixScreenX[filename]Added by the MATRIXSCREEN TROJAN!
    MatrixScreenSaverXmss.exeMalware, see here
    Matrox Color ControlNhgcctl95.exeFor Matrox video cards. Quick access to changing colors
    Matrox Control CenterNmgactrl.exeFor Matrox video cards. Quick access to settings
    Matrox DiagnosticNmgadiag.exeFor Matrox video cards. Quick access to diagnostics
    Matrox PowerdeskNPDesk.exeFor Matrox video cards. Quick access to tweak your card to your liking
    Matrox QuickDeskNmgaqdesk.exeFor Matrox video cards. Quick access to tweak your card to your liking
    MaxAlertsXmax.exeBonzi MaxALERT - spyware
    MaxtorComboYComboButton.exeRequired to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
    MaxtorOneTouchUOneTouch.exeMaxtor OneTouch Hard Drives/OneTouch Family hard disk backup software
    MaxtorRegUAUTOREG.EXEPart of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
    MayaPanYMayaPan.ExeAudiotrak Maya soundcard driver
    MBM 4UMBM4.exeMotherboard Monitor 4 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    MBM 5UMBM5.exeMotherboard Monitor 5 - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    MBNetUmbnet.exeMBNet (Portugal) Credit Card Processing software
    MBProbeUmbrpobe.exeMBProbe - only needed if you overclock your system and want to keep a check on system temperatures/voltages/etc. Available via Start -> Programs
    MCXwintrims.exeAdded by the WINTRIM VIRUS!
    mc or SMC Service or SmcServicesYsmc.exe spfsmc.exeSygate Firewall
    McAfeeXMcAffeAv.exeAdded by the NETSKY.AL WORM!
    McAfeeXMcAffeAv.exeAdded by the W32.Netsky.AN WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    MCafeeXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    Mcafee Anti ScanXNortonScn.exe Win32.Rbot worm variant
    McAfee AntivirusXMcAfeeAV.exeAdded by a variant of the WIN32.RBOT WORM!
    McAfee Antivirus 32XMCAFEEAV32.EXEAdded by the W32/Spybot-EH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Mcafee Antivirus Monitoring System326XVSStatmn326.exeAdded by a variant of the W32/SDBOT WORM!
    Mcafee Antivirus Monitoring System32mnXVSStatmn32.exeAdded by a variant of the WIN32.RBOT WORM!
    McAfee Antivirus ProtectionXmcafeeAV.exeAdded by a variant of the WIN32.RBOT WORM!
    Mcafee Auto ProtectXmcafeshield.exeAdded by the W32/RBOT-UH WORM!
    McAfee FirewallYCPD.EXEFirewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
    McAfee GuardianNCMGRDIAN.EXEMcAfee's QuickClean, an offline version of the one in their online Clinic. Normally run offline and not needed. Incidentally, incorporates more cleanup programs than the likes of WinOptimizer and System Mechanic
    McAfee QuickClean ImonitorNPlguni.exe McAfee_QuickClean_3.0 - removes internet clutter and unwanted programs
    mcafee Software IntrenetXmcafee.exeAdded by W32/Rbot-ATR WORM!
    MCafee UpdateXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    McAfee Windows ProtectionXmcafee32.exeAdded by a variant of the W32.SPYBOT WORM!
    McAfee WinguageN??Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
    McAfee.InstantUpdate.MonitorURuLaunch.exeInstant Updater for McAfee\'s VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
    McAfeeScanPlusXMcAfeeScanPlus.exeAdded by the Backdoor.Mepcod TROJAN! Note: This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder.
    McAfeeUpdaterUIYUpdaterUI.exeAssociated with McAfee Enterprise 7.0.0. - background process
    McAfeeVirusScanServiceYAvsynmgr.exeFrom McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application
    McAfeeWebscanXYWebScanX.exeFrom McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
    Mcaffe AntivirusXMcafeescn.exe W32.SpyBot worm variant
    McAgentExeUmcagent.exeFrom McAfee VirusScan On-line. The Agent is a red M icon that appears in the Windows system tray or Notification Area (if you're running Windows XP). If you don't see the agent icon, VirusScan Online may not be installed
    Mcappins.exeYmcappins.exeUsed by McAfee Virusscan to perform product updates. When updates are available the program will download and install them automatically. Recommended to leave enabled.
    MChangerNMChanger.exeMedia Changer - utility that allows you to change wallpapers, sounds, themes, etc
    MCM3Xmcm3.exe ShopAtHome/SAHagent adware variant
    McRegWiz?mcregwiz.exeMcAfee antivirus related. What does it do and is it required?
    Mcrosoftr UpdateXMcrosoftr.exeAdded by a variant of the WIN32.RBOT WORM!
    McUpdateExeUmcupdate.exeFrom McAfee VirusScan On-line. Automatically updates your virus definitions. Leave enabled unless you regularly update these definitions
    MCUpdateExeXmcagent.exeAdded by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
    mcupdmgr.exeYMCUPDMGR.EXEMcAfee antivirus SecurityCenter Update Manager
    McVsRteYmcvsrte.exePart of McAfee's SecurityCenter. Must remain checked but one  user reports Windows glitches with no response from McAfee as to why
    mcvsshldYmcvsshld.exeMcAfee VirusScan On-line. See also McAgentExe entry.
    MCX UpdateXwisp.exeAdded by the W32/Rbot-AQH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MCX UpdteXscorti.exeAdded by the W32/RBOT-ARP WORM!
    MD IE PluginXmd.exe Marketdart spyware
    MD IE PluginXwiny.exeAdware
    mdac_runonceNrunonce.exeAssociated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe". 
    MDDiskProtect.exeNMDDiskProtect.exeMediaFour MacDrive for Windows - easily open, edit and save files from Mac-formatted disks, format Mac disks and burn Mac CDs and DVDs!
    mdetectX(path to trojan)Added by the SPABOT VIRUS!
    MdmXMdm.vbsAdded by the WHITEHO or TRAPPY VIRUSES!
    MDM7Umdm.exeUsed by developers for debugging. Those who have encountered it have unchecked it with no degradation in performance. May cause your computer to "hang" if you have MS Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendatioon. Can also be listed as Machine Debug Manager. See here to disable
    MdmdllXmdmdll.exeAdded by the WIN32.CRYPTER downloader TROJAN!
    Mdmdll32Xmdmdll32.exeAdded by a Crypter.C trojan variant infection
    MDNXMDNS.exeAdded by the W32.Spybot.JPB WORM!
    MDNXMDNZ.exeAdded by the RBOT.AQD WORM!
    MDNXMDN.exeAdded by the RBOT.AOA WORM!
    mds.exeXmds.exeAdded by the TROJ/MADS-A TROJAN!
    mdwmdmspXmdwmdmsp.exeAdware - recognized by Kaspersky antivirus and others as TrojanDownloader.Win32.Agent.am
    MECANMeca.exeMeca instant messenging client
    MedGSXMEDGS1.exe PacerD_Media/Pacimedia.com adware component
    Media AccessXMediaAccK.exeWindupdates MEDIAPAS.A adware
    Media AccessXMediaAccK.exeAdded by the Troj/Podrop-C TROJAN! Note: This file is found in the Program Files\Media Access folder. Read the link, rootkit type stealth involved.
    Media GatewayXMediaGateway.exe 180Solutions Windupdates adware variant - also see here
    Media LoadXmsn32.exeUnidentified backdoor trojan
    Media Manager IndexerUAIRSVCU.EXEPart of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database. For more information see here
    Media PassXMediaPassK.exe MediaPass adware
    Media PassXMediaPass.exeWindUpdates MediaPass adware
    Media PlayerXmedia.exeAdded by the FLDMEDIA-A VIRUS!
    Media PlayerXwmplayer.exeAdded by the W32/Agobot-BM WORM!
    Media PlayerXSysdll.exeAdded by the TROJ/BANKER-BR TROJAN!
    Media PlayerXSysnet.exeAdded by the BANKER.MW WORM!
    Media Player UpdateXxpsp1mfh.exeAdded by a variant of the WIN32.RBOT WORM!
    Media Plug x.1.2Xmsdm.exeAdded by the MULDROP.352 VIRUS!
    Media serviceXmsnmsgxr.exe WORM_SDBOT.TF
    Media ServiceXmsn64.exeAdded by a SPYBOT.EV worm infection
    Media serviceXSYSTEM64.EXEAdded by a RBOT.QV worm infection
    Media serviceXnotpad.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Media Software UPdaterXsscs.exeAdded by the W32/RBOT-ABE WORM!
    Media X ServicesXMSNGRx.exeAdded by the RBOT.AUL WORM!
    Media-XP-Service-Pack3Xmsnzx.exeAdded by the W32/Sdbot-ACW WORM!
    MEDIA32X(pathname of the Trojan executable)Added by the Troj/PurScan-Z Trojan!
    MediaFace IntegrationNSethook.exeFellowes Neato™ cd label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
    Mediafour Mac Volume NotificationsUMacvntfy.exeMediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
    Mediafour XPlay Tray Notification IconUXptryicn.exeMediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod
    MediaKeyUMediaKey.exeMultimedia keyboard manager. Required if you use the multimedia keys
    MediaLoads or MediaLoads InstallerXdw.exeMedialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
    MediaMonitorNMediam~1.exeInstalled by Smartdisk MVP CD burning software. Software will work fine without it
    mediamotor.exeXmmups.exe MediaMotor/Popuppers adware
    MediaPathXProyecto1.exe, Root.exeAdded by the GRUEL VIRUS!
    mediapluscash.exeXmediapluscash.exe MediaMotor/Popuppers adware component
    MediaRing TalkNmrtalk.exeMedia Ring Talk, voice recognition software, Resource hog. Available via Start -> Programs
    MediaXPServicePackXmxpsp.exeAdded by a variant of the WIN32.RBOT WORM!
    media_driverXmedia_driver.exeAdded by the TUPEG VIRUS! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    media_managerXmediaman.exeMini-Player,  IMESH related foistware, see here
    media_stubXstub.exeMini-Player,  IMESH related foistware, see here
    Meeting ConnectionXcomsutil.exeAdded by the PPDOOR-E TROJAN!
    Meeting ConnectionXwowdache.exeAdded by the TROJ/PPDOOR-D TROJAN!
    Members areaX******.exe (* = random digit)Premium rate adult content dialer
    MemConfigXSetupIE.comAdded by the TAPLAK VIRUS!
    MemMonsterUmemmnstr.exe MemMonster is a memory manager which enables your computer to work more efficiently.
    MemoKitUMK.EXEMemory optimizer. It loads from startup group and it goes off as soon as the program (memokit.exe) is loaded in the System Tray. Mk.exe does not run while the memokit.exe is running. Probably loads a flash screen at startup and shutdown that stays on screen less than 5 seconds and gives you a button to push to purchase the full version. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    memoryXoutlookrem.exeAdded by the W32.Nopir.C Worm!
    Memory CheckXmemore.exeAdded by the KILLAV.C VIRUS!
    Memory Stick MonitorNMSTAT.exeUsed with the Sony floppy disk adapter for memory sticks, showing if there is a stick in the computer
    Memory Stick MonitorUMSstat.exeSony/SmartDisk memorystick-floppydisk-adapter software - allows you to read memorysticks in a normal floppydrive
    Memory WatcherXMemoryWatcher.exe MemoryWatcher spyware
    Memory+Utfimemsr.exeMemory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    MemoryMeterXMemoryMeter.exeAutoinstalling spyware by Total Velocity
    memreader.exeXmemreader.exeAdded by W32/Agobot-TY WORM!
    MEMrealoadXMEMreaload.exe /checkmouse /updaterationAdded by the Lazar TROJAN!
    MemScannerNMemScanner.exeSpyHunter - spyware remover of somewhat dubious repute; see note
    MemTurboUmemturbo.exeMemTurbo memory optimizer. MS professionals recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind
    MenuSnapNMenuSnap.exeMenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe
    Message QueuingXmsmqs.exeAdded by the FREEFORS VIRUS!
    MessagerStarter FreeserveNStartMessager.exeFreeserve Messenger
    Message_BlockerUmessageblock.exeMessage Blocker - "prevents Outlook Express from loading images or other content from the internet without confirmation, as well as executing scripts when displaying a formatted email message"
    MessangerXtrillian.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    MessangerXdeamon.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    MessangerXmsgaol.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    MessangerXs_menu.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    MessengerXmessenger.exeAdded by the KUTEX VIRUS!
    MessengerXntsubsys.exeAdded by the SDBOT.BGE WORM!
    MessengerXWmsngr.exeAdded by a variant of the WIN32.RBOT WORM!
    Messenger BlockXmsngrblock.exeAdded by the PATOO VIRUS!
    Messenger ProtocolXnetsender.exeAdded by the W32/Sdbot-ACC WORM!
    Messenger ServiceXmsmsgs.exeAdded by the W32/SDBOT-ZB WORM!
    Messenger ServiceXnvhost.exeAdded by the MYTOB.IF WORM!
    Messenger Service UpdaterXsvshost.exeAdded by the MYTOB.GC WORM!
    Messenger start-upXMsgran.exeAdded by the GRAMOS VIRUS!
    Messenger6Xcommand.pifAdded by the W32.INZAE.B WORM!
    MessengerDiscoveryUMessengerDiscovery.exe MessengerDiscovery is a MSN Messenger add-on, adding over 70 new features.
    MessengerPlus, MessengerPlus2, MessengerPlus3NMsgPlus.exe MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware; the software does offer you a choice during setup: make sure to install MessengerPlus WITHOUT that "sponsor program"!
    messngerX(worm filename)Added by the DELODER VIRUS! where <filename> is the worm name
    messngerXDvldr32.exeAdded by the DELODER.A VIRUS!
    MeTaLRoCk (irc.musirc.com) has sex with printersXmetalrock-is-gay.exeAdded by the RANDEX.Q WORM!
    MeuProgramaXaccwizz.exeAdded by the W32.Ruland.A WORM!
    Mfc**.exe (* = random char)XMfc**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Mfc**32.exe (* = random char)XMfc**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    mfgboot?????
    mfin32Xmfin32.exeMyFreeInternetUpdate - adware downloader
    MGA Hook?Mgahook.exeMATROX Graphics card related. What does it do and is it required?
    MGA QuickdeskNMGAQDESK.EXEFor Matrox video cards. Quick access to tweak your card to your liking
    Mgabg?Mgabg.exeMatrox BIOS Guard. What does it do and is it required?
    mgavctrl or mgavrtclexeYmgavrtcl.exe mgavrte.exeMcAfee\'s Virus Scan Online
    MGA_CD_InstallNmgasetup.exeMatrox Millennium video driver. Not required once drivers installed
    mgmtapiXmgmtapi.exeUnidentified malware
    MHDOGStartXmhdogst.EXEAdded by an unidentified VIRUS! A possibility is a trojan known as PENIS
    MHINITNMHINIT.EXEPart of the Cybermedia Clean Sweep package
    Micr UpdateXsoundblaster.exe WORM_SDBOT.NP
    Micr0s0ft Ms D0sXmsdx.exeAdded by the W32/Rbot-AON WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Micr0s0ft Upd4t4zXsvchost32.exeAdded by a variant of the WIN32.RBOT WORM!
    Micrcoft ExploererXspoolsal.exeAdded by the W32/Rbot-AKK WORM!
    Micrcoft ExploererXsvchose.exeAdded by W32/Rbot-ASL WORM!
    Micrcoft UpdatXspoolsae.exeAdded by the W32/Rbot-AIB WORM!
    Micrcoft UpdatXspoolsaex.exeAdded by the W32/Rbot-AJM WORM!
    Micrcoft UpdatXInternet.exeAdded by the W32/Rbot-ANA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Micro ProcessXappconf.exeAdded by an unidentified WORM or TROJAN!
    Micro UpdateXdailin.exeAdded by the W32/RBOT-ER WORM!
    Microangelo DesktopUMuamgr.exeQuick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
    microAttuneDownloadNatmdlusr.exeUSR (US Robotics) modem auto updater. May be a sub-set of Attune
    MicroCQ0Xexplorer.exeAdded by the Troj/Lineage-AK Note: This trojan file (explorer.exe) is found in the Program Files folder and is not the legitimate Windows file (explorer.exe) that is found in the Windows folder.
    MicroDiallerUatdialler1.exePart of the Freeserve Connection Kit - changes the dial-up for Freeserve AnyTime if access problems are encountered
    MicroedSoft ToolbarXSmoked.exeAdded by the W32/RBOT-ALN WORM!
    Microfinder lptt01 or Microfinder ml097eXmcf.exeVariant of the RapidBlaster parasite (in a "mcf" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Microfot UpdateXwinldx32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microft ExploererXspoolsac.exeAdded by the W32/Rbot-AMD WORM! Note: This is not the legitimate Windows Process spoolsv.exe. (Notice the difference in the spelling) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Microft Update 32Xwinssx.exeAdded by the W32/Rbot-AQS or W32/Rbot-ATV WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MicroLoadX(random filename)Added by the DARBY VIRUS!
    Micromedia Flash UpdateXwdfmrg.exeAdded by a variant of the W32/SDBOT WORM!
    Microoft TimingXpupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    MICROSFT ANTIVIRUS UPDATE SUPPORTXMSGUPDATED.EXEAdded by the W32/Rbot-APZ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MICROSFT ANTIVIRUS UPDATE SUPPORTX(Random 10-letter filename).EXEAdded by the W32/Rbot-AQA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsft Confige 32Xmsaconfigurez.exeAdded by the RBOT.CLC WORM!
    MICROSFT MX UPDATE SUPPORTXtaskmngrs.exeAdded by the W32/Rbot-AUZ WORM!
    MICROSFT RAMA UPDATE SUPPORTX(Random filename)Added by the W32/Rbot-ASM or W32/Rbot-AUW WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MICROSFT RAMA UPDATE SUPPORTXmtakthmyn.EXEAdded by W32/Rbot-AUJ WORM!
    MICROSFT RAMA UPDATE SUPPORTXMSN32.EXEAdded by the W32/Rbot-AWJ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MICROSFT RAMA UPDATE SUPPORTXMSED32.EXEAdded by the W32/Rbot-AWR TROJAN!Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    microsft windows updatesXmwupdate32.exeAdded by a variant of the WIN32.TOXBOT/CODBOT WORM!
    Microsof ValueXnmatt.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsof Windows HostXsvhost32.exeAdded by the RBOT.ADY WORM!
    Microsof Winlog HostXwilogon32.exeAdded by the RBOT.XC WORM!
    Microsofot x386 System MonitorXsystem32.exe WORM_WOOTBOT.M
    microsoftXsvchost.exeAdded by the ASTEF or RESPAN VIRUSES! Note - this is not the valid svchost.exe as described here
    microsoftXmicrosoft.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    MicrosoftXwin32.exeAdded by the BACKDOOR.DARKMOON TROJAN!
    MicrosoftXiexplore.exeAdded by the Troj/QQRob-R TROJAN! Note: This is not the legitimate Windows process iexplore.exe. (Which is found in the Program Files\Internet Explorer folder.) This trojan file (iexplore.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft (C) HTML Application hostX[random file name]Added by the W32/Rbot-YB WORM!
    Microsoft .NET ConfinguratorXmsnconf.exeAdded by an unidentified VIRUS!
    Microsoft 16Bit UpdateXwuapdate16.exe WORM_RBOT.CZ
    Microsoft 64 Bit Runtime UpdaterXwupdt64.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ActiveX Debugger NTX(Path of the Trojan EXE)Added by the Troj/Bancos-DO TROJAN!
    Microsoft ADserviceXadservice.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ADserviceX[random file name]Added by a variant of the WIN32.RBOT WORM!
    Microsoft AgentXmdss32.exeAdded by the KEYLOG-AG TROJAN!
    Microsoft ALG32 ProtocolXalg32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Announcement ListenerNAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    Microsoft Ansti UpdateXmsie.exeAdded by a W32/Rbot-LE worm infection
    Microsoft AntiSpywareXBazzi.exeAdded by the AHKER.J WORM!
    Microsoft AOL Instant MessengerXMSAOL32.exeAdded by the W32/RBOT-AAI WORM!
    Microsoft AOL32 ProtocolXaol32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Application CenterXmappc.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Application ManagerXmsapl32.exeAdded by the TROJ/BROPIA-AE TROJAN!
    Microsoft Associates, Inc.Xiexplorer.exeAdded by a variant of the LOVGATE WORM!
    Microsoft AUT UpdateXMSlti32.exe W32/Rbot-X worm
    Microsoft AUT UpdateXMSlti16.exeAdded by the RBOT.EB WORM!
    Microsoft Authority ServiceXlsass.exeAdded by the W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
    Microsoft auto updateXwinupdate.exeAdded by the BMBOT VIRUS!
    Microsoft Automatic Update SerivceXmsautou.exeAdded by the W32/Rbot-AOB WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Automatic UpdaterXExplorer.exeAdded by the W32/RBOT-SG WORM!
    Microsoft AutoUpdaterXsvhost.exeAdded by a RBOT.QG worm infection
    Microsoft Bool ValueXMV2.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft boot system cfg32Xactboost.exeAdded by the W32.Bropia.R WORM!
    Microsoft Broadband NetworkingUMSBNTray.exeMicrosoft Broadband Networking Tray Application
    Microsoft Cab ManagerXexec.exe Affilred.B adware
    Microsoft checkerXMsPMSPTv.exeAdded by a variant of the W32/SDBOT WORM! - do not confuse with the Microsoft's Digital Rights Management file described here
    Microsoft ClientXmshost.exeAdded by the W32/Rbot-AND WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Client PcXspoolsrv.exeAdded by the W32/RBOT-AQM WORM!
    Microsoft Client/Server Runtime Server SubsystemXcsrs.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft Client/Server Runtime Server SubsystemXcsrssa.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft Command LineXwincmd.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Compiler PackXDSDEV.EXEAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Conf LdrXsysconf.exeAdded by a variant of the SDBOT WORM!
    Microsoft ConfgKeysXwurmgrd32.exeAdded by the W32/RBOT-ARX WORM!
    Microsoft ConfigXmsconf.exeAdded by the RBOT.PV WORM!
    Microsoft ConfigXMSCONF.EXEAdded by the RBOT-LG WORM!
    Microsoft Config 32bitXmscnfg32.exeAdded by the W32/RBOT-Z WORM!
    Microsoft Config FileXconfig.exeAdded by the Win32.KillFiles.gr TROJAN! - This is malware that will attempt to delete all system dlls!
    Microsoft Configuration UtilityXmsconf.exeAdded by the W32/RBOT-AFX WORM!
    Microsoft Connection Manager MonitorXcmmon.pifAdded by the W32/Rbot-AKV WORM!
    Microsoft Control CenterXcrtl.exeAdded by the W32/RBOT-VX WORM!
    Microsoft Core SupportXMSxUP32.exeAdded by the W32/Rbot-ANR WORM!
    Microsoft Corp UpdatesX"wupdates.exe"Added by W32/Rbot-AUU WORM!
    Microsoft CorporationX(random filename)Added by various VIRUSES such as VISAGES, BABYBEAR and TOFACED
    Microsoft CorporationXjview.exeAdded by the W32/Rbot-AOD WORM! Note: This is not the legitimate Visual J viewer. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft CronD ServiceXMSCRON.EXEUnidentified AIM-based worm/trojan
    Microsoft Crs Fix ServXwincrs.exeAdded by the SDBOT.BWF WORM!
    Microsoft CSRSS32 ProtocolXcsrss32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft CSRSS386 ProtocolXcsrss386.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft CvrtXmscvrt32.exeAdded by a unidentified VIRUS!. Named almost, but not exactly like the legitimate msvcrt or msvcrt20.dll
    Microsoft Data HelperXcihost.exeMalware, possibly a Linst trojan variant
    Microsoft Data MachineXcsdata32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Database HandlerXmssql32.exeAdded by the RANDEX.AX VIRUS!
    Microsoft Datalog ApplicationXmsdata.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft DDE ControlXwupades.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft DDEs ControlXErun.pifAdded by the W32/Rbot-AMU WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Debug ServiceXdbgbgr.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Decryption TechnologyXMsfenoe.exeAdded by the W32/SPYBOT-DG WORM!
    Microsoft Desktop ManagerXmsdesk32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft DevXiexplorer32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft Development DebuggerXmsdev.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Device ManagerXmsdevmgr32.exeAdded by the LATEDA.B TROJAN!
    Microsoft DiagnosticX.exeAdded by the ACEBOT VIRUS! The <filename>.exe will be random and must be deleted after the virus has been removed. Not to be confused with the DOS based MSD.EXE
    Microsoft DiagnosticXmsdiag32.exeAdded by the W32/RBOT-UC WORM!
    Microsoft Digital ClockXmsclock.exeAdded by a W32/Nackbot-D worm infection
    Microsoft DirectXXSpoolserv.exeAdded by the DINFOR VIRUS!
    Microsoft DirectXXrasmngr.exe Win32.Rbot worm variant
    Microsoft DirectXXPDSched.exeAdded by the SDBOT.CN WORM!
    Microsoft DirectXXwuamgrd.exeAdded by the SDBOT.MY WORM!
    Microsoft DirectXXtime123.exeAdded by the SDBOT.MD WORM!
    Microsoft DLLXfumeta.exeAdded by W32/Rbot-AUG WORM!
    Microsoft DLL ExtensionsXSystemDll.exeAdded by the W32/Rbot-ADV or W32/Rbot-AJR WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Dll ManagementXwindll.exeAdded by the W32/RBOT-MT WORM!
    Microsoft Dll Printer ManagerXdllpt.exeAdded by the SDBOT.BIH WORM!
    Microsoft DLL VerifierXfile.exeAdded by the W32/Rbot-AED Worm!
    Microsoft DLL VerifierXchkfile.exeAdded by the W32/Rbot-APP WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft DLL VerifierXcsrssv.exeAdded by W32/Rbot-ATK WORM!
    Microsoft DLLSet32Xdllset32.exeAdded by the RBOT.OZ WORM!
    Microsoft DNS QueryXmsdns.exeAdded by a variant of the W32/WOOTBOT WORM!
    Microsoft DocumentXkrisp.exeAdded by the W32/SDBOT-RQ WORM!
    Microsoft DriverXfaet.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Driver ManagerXmswindrv.exeAdded by the W32/FORBOT-EZ WORM!
    Microsoft driver updateXMshome.exeAdded by the SDBOT.BL WORM!
    Microsoft DriversXWSconf.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft ErgoPackXwserb32.exeAdded by the W32/RBOT-RI WORM!
    Microsoft EV32 ServiceXMSev32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ExcelXmsexcel.exeAdded by the W32/RBOT-TQ WORM!
    Microsoft ExcellXwuamngr32.exeAdded by the W32/RBOT-QH WORM!
    Microsoft ExecutingXmicrosoft.exeAdded by the AGOBOT.UV WORM!
    Microsoft ExplorerXsvapache.exeAdded by the W32/RBOT-VR WORM!
    Microsoft ExplorerXexplorer.scrAdded by the W32/Rbot-ADH Worm!
    Microsoft ExplorerXexplorer.pifAdded by the W32/Sdbot-ACX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Explorer2Xbitchbot.exeAdded by the SDBOT.EV WORM!
    Microsoft Explorer2Xnome.exeAdded by the RANDEX.AA WORM!
    Microsoft Explorer2Xsystem.exeAdded by the BKDR_IRCBOT.BS TROJAN!
    Microsoft EXPLOREXP ProtocolXexplorexp.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft FeaturesXms32cfg.exe WORM_RBOT.HO
    Microsoft FeaturesXmsie.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft File Demand ManagerXwmgrdf.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Find FastXFindfast.exeComplete utter waste of space! Part of MS Office - searches disk drives for Office file types and creates an index to make opening them easier
    Microsoft FirewallXfirewallsp2.exeAdded by a W32/Rbot-MC worm infection
    MICROSOFT FIREWALL CLIENTYISATRAY.EXEMS Internet Security and Acceleration Server - see here
    Microsoft GamesXgamemanager.exeAdded by the SPYBOT.AHQ WORM!
    Microsoft Generic Update ManagerXwupdate.exeAdded by the W32/Rbot-AWC TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Gina V EncryptionXMSGINAV.EXEUnidentified worm or trojan
    Microsoft Greetings ReminderNMHPRMINF.EXEYou really want to be reminded about somebody's birthday at the expense of resources?
    Microsoft Greetings RemindersUMHPRMIND.EXEMicrosoft Home Publishing greetings reminder
    Microsoft Greetings Workshop ReminderNGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?
    Microsoft HelpXsvh0st.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Help SVCXmsnmngr.exeAdded by a W32/Sdbot-PQ worm infection
    Microsoft Help SystemXmshelp32.exeAdded by a CoolWebSearch parasite variant
    Microsoft Host ProtocolXsvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Host ServiceXmswinexect.exeAdded by the RBOT.ZU WORM!
    Microsoft Hosting ServiceXWINHOSTING.EXEAdded by the RBOT.AEV WORM!
    Microsoft Hosts ServiceXIsass.exeAdded by a variant of the WIN32.RBOT WORM!
    microsoft hotmail monitorUmshotmon.exeAdded by the MYTOB.LY WORM!
    Microsoft IDCNXmshe1p.exeAdded by an unidentified TROJAN!
    Microsoft IEXIexplore.exeAdded by a W32/Forbot-AG worm infection
    Microsoft IE Execute shellXIEExec.exeAdded by the ALADINZ.N VIRUS!
    MicroSoft IE SasserXISASS.EXEAdded by the SDBOT.MX WORM!
    Microsoft IISXsyshost.exeAdded by the FRANCETTE VIRUS!
    Microsoft IISX(filename)Added by the W32/Francette-S Worm!
    Microsoft Inc.Xiexplorer.exeAdded by a variant of the LOVGATE WORM!
    Microsoft IncroporateXmfs.exeAdded by the W32/RBOT-ANF WORM!
    Microsoft Inet Xp..Xteekids.exeAdded by the BLASTER.C VIRUS!
    Microsoft Instant MessengerXmsngmsngr32.exeAdded by the Win32.Spyboter.gen TROJAN!
    Microsoft Int ServiceXMsIntSrv.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Intellitype ProUspeedkey.exeAdditional keyboard shortcuts on MS programmable keyboard
    Microsoft Internal AntiVirus SystemsXdIlhost.exeAdded by the W32/Rbot-AEV Worm!
    Microsoft InternetXexpl0rer.exe W32.SpyBot worm variant
    Microsoft InternetXwindows32.exeAdded by a W32/SdBot-F worm infection
    Microsoft InternetXmsnm.exe W32/Sdbot worm variant
    Microsoft InternetXwincfg16.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Internet Acceleration UtilityX iau.exe EasySearch adware
    Microsoft Internet Acceleration UtilityX[path to file]Added by the TROJ/AGENT-CX TROJAN!
    Microsoft Internet Acceleration UtilityX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Microsoft Internet ExpXiiexplorer.exeAdded by a W32/Rbot-KX worm infection
    Microsoft Internet ExplorerXsvchosts.exeAdded by a Bancban-U trojan infection
    Microsoft Internet ExplorerXmsngrt.exeAdded by a W32/SdBot-GU worm infection
    Microsoft Internet ExplorerXiexplorer.exeAdded by the W32/SDBOT-XN WORM!
    Microsoft Internet ExplorerXiexplore.exeAdded by the W32/POEBOT-J or W32/Mytob-CW or W32/Poebot-P WORM! - NOTE - This file is installed in the Windows\System32 or Winnt\System32 folders and is NOT to be confused with the Internet Explorer executable, which will always be located in the Internet Explorer folder in Program Files!
    Microsoft Internet ExplorerXsmiissm.exeAdded by the TROJ/DLOADER-JQ TROJAN!
    Microsoft Internet ExplorerXmovies.exeAdded by the Troj/Bancos-DZ TROJAN!
    Microsoft Internet ExplorerXsvzhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Internet ExplorerXcrsys32.exeAdded by the RBOT.UZ WORM!
    Microsoft Internet ExplorerXmccagent.exeAdded by the TROJ/DLOADER-UD TROJAN!
    Microsoft Internet ExplorerXsysini.exeAdded by the Troj/Delf-LN TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft Internet Firewall ManagerXGMT16.exeAdded by the RANDEX.AT VIRUS!
    Microsoft Internet ServicesXSmss32.exe WORM_RBOT.MS
    Microsoft Internet, varying file namesXdmsvc32.exeAdded by a W32/Sdbot-AZ worm infection
    Microsoft Intrenet ExplorerXSoundsyst.exeAdded by the W32/RBOT-AQU WORM!
    Microsoft Intrenet ExplorerXgoaw.pifAdded by the W32/Rbot-API WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Intrenet ExplorerXcnsg.pifAdded by the W32/RBOT-ARO WORM!
    Microsoft Intrenet ExplorerXwcumrg.exeAdded by the W32/Sdbot-AFD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft IPCXsystem.exeAdded by the NULLBOT VIRUS!
    Microsoft IPCXsvshost.exeAdded by an unidentified VIRUS!
    Microsoft IT UpdateXwinn43.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft IT UpdateXIEserv.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft IT UpdateXmsupdate.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft IT UpdateXrandom files namesAdded by a variant of the Win32.Rbot WORM!
    Microsoft IT UpdateXsvchsst.exeAdded by the W32/RBOT-DH WORM!
    Microsoft IT UpdateXwin43.exeAdded by the SPYBOT.BI WORM!
    Microsoft IT UpdateXwinsyst32.exeAdded by the W32/RBOT-FC WORM!
    Microsoft Java Virtual MachineXwinscr32.exeAdded by a variant of the W32/WOOTBOT WORM!
    Microsoft Java Virtual MachineXMsConfiG.exeAdded by the W32/FORBOT-DV WORM!
    Microsoft Java Virtual MachineXmsvmjava.exeAdded by the RBOT.ER WORM!
    Microsoft Java Virtual MachineXjavavm.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Java Virtual MachineXmsjvm.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Java Windows UpdateX(random filenames)Added by the W32/RBOT-DZ WORM!
    Microsoft JavaVMXmsjarun.exe W32/Rbot-JW worm
    Microsoft KernelXWindows_kernel32.exeAdded by the W32.NETSKY.AE WORM!
    Microsoft LAN32 ProtocolXlanXp.exeAdded by the W32/RBOT-SS WORM!
    Microsoft Legacy DeviceXtrass.exeAdded by the W32/Rbot-AIX WORM!
    Microsoft Lmhosting ServiceXlmhosts.exeAdded by the W32/RBOT-RC WORM!
    Microsoft Locals 332Xsywrscds.exe, random file namesAdded by a W32/Rbot-KU worm infection
    Microsoft LoginXwinlogin.exeAdded by the W32/Rbot-AJP WORM!
    Microsoft LSA layerXMSLSA32.exeAdded by the W32/Rbot-AKZ WORM!
    Microsoft LSASS386 ProtocolXscvhost32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft LVX[path to file]Added by the TROJ/BDOOR-BDL TROJAN!
    Microsoft MachineXwinjava.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft Macro Protection SubSsyXmsacroprots386.exeAdded by a W32/Rbot-KE worm infection
    Microsoft Macro Protection SubsystemsXmsmacroprotxz.exe W32.SpyBot worm variant
    Microsoft Macro Protection SubsystemsXMsmacroprot32.exeAdded by the RBOT.KN WORM!
    Microsoft ManagementXlmas.exeAdded by the W32/FORBOT-CZ WORM!
    Microsoft Management ConsoleXlssas.exe EasySearch adware
    Microsoft Management ConsoleX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Microsoft ManagerXmsmanager.exeAdded by the MYTOB.LF WORM!
    Microsoft Map PCXmappc.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Mapped PCXmappedpc.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft mediaXwinmplayers.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Media player 9Xmsmedia32.exeAdded by the W32/RBOT-ADO WORM!
    Microsoft media servicesXIassd.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Microsoft media servicesXwinmplayer.exeAdded by a RBOT.ZO worm infection
    Microsoft MediaScopeXwinmes.exeAdded by the W32/RBOT-XU WORM!
    Microsoft Message MachineXmsmesg32.exeAdded by the SPYBOT.BI WORM!
    Microsoft Messenger Management ControlsXmsmgmctl.exeAdded by the W32/Rbot-APA WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Messenger ServiceXmsmsg32.exeAdded by the RBOT.BOK WORM!
    Microsoft Messenger XPXMSMSN32.exeAdded by the W32/RBOT-ZP WORM!
    Microsoft MicroP ProtocolXwdgmr32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Ming ServiceXming.exeAdded by the W32/Rbot-AWS WORM!
    Microsoft Movie MakerXMmaker.exeAdded by the IRCBOT.C VIRUS! Note that this is not a valid Microsoft program
    Microsoft MSGPLUS32 ProtocolXmsgplus32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft MSNGR32 ProtocolXmsngr32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft msnseruXmsnseru.exeAdded by the W32/Rbot-APB WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft MsnSTXmsnst32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft MSUPDATEXSpoolSvc.exeAdded by the SXTB-A VIRUS!
    Microsoft Neser ExperienceXnese.exeAdded by the W32/RBOT-YH WORM!
    Microsoft NetMeeting Associates, Inc.XNetMeeting.exeAdded by a variant of the LOVGATE WORM!
    Microsoft NetviewXgesfm32.exeAdded by the RANDEX.C VIRUS!
    Microsoft NetviewXmssvc32.exeAdded by an unidentified VIRUS!
    Microsoft Netview Component v5.1Xmsnv32.exeAdded by the RANDEX.F VIRUS!
    Microsoft NetworkXmsnet.exeAdded by the MOCKBOT.A VIRUS!
    Microsoft NetworkXNetworksystem.exeAdded by the W32/SDBOT-AAI WORM!
    Microsoft Network Daemon for Win32XNetd32.exeAdded by the SDBOT.R WORM!
    Microsoft Network HostXsvc0host.exeAdded by W32/Sdbot-AEN WORM!
    Microsoft Network Services ControllerXmmsvc32.exeAdded by the W32/NANPY-A WORM!
    Microsoft Networking Agent For SP2Xmsnac32.exeAdded by the W32.SPYBOT.PEN WORM!
    Microsoft NotePadXnotepad.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft NT UpdateXwinexec32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft OfficeXMSMSGR.exeAdded by the GAOBOT.BB WORM!
    Microsoft OfficeNMsoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly.
    Microsoft OfficeXlserv.exeAdded by the W32/Rbot-ATM WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft OfficeXMicrosoft Office.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    Microsoft OfficeXmsoicons.exeAdded by the W32/RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups!
    Microsoft OfficeXsvxhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft OfficeXnxcxtpr.exeAdded by the W32/RBOT-YG WORM!
    Microsoft OfficeXNxcao.exeAdded by the W32/RBOT-ZE WORM!
    Microsoft OfficeXmsoffice32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Office Fast CacheNFastboot.exePart of MS Office 95 (v7.0). According to this;en-us;Q132755 it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled
    Microsoft Office OneNote 2003 Quick LaunchUONENOTEM.EXEONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work.
    Microsoft Office or Microsoft Office StartupNOsa.exe, Osa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show.
    Microsoft Office Shortcut BarNMsoffice.exeAlternative shortcuts to the Start -> Programs way of running applications installed as part of MS Office. Some people prefer it, but a better way is to create Desktop Shortcuts if you want access these programs quickly.
    Microsoft Office StartXwinupdates.exeAdded by the GAOBOT.BC WORM!
    Microsoft Office StudioXscvhvst.exeAdded by the W32.Randex.CST WORM!
    Microsoft OfficeXPXofficeXP.exeAdded by the KILLAV.MA WORM!
    Microsoft OpeionsXIEXwe.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Outlook Express ProtocolXsvchst.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft PC Health Remote Assistance File Open & Save
    controls
    Xsfrcdlg32.exeAdded by the W32/Rbot-AVY WORM!
    Microsoft PCHealth32X[path to file]Added by the TROJ/NICE-A TROJAN!
    Microsoft PCHealth32XNDDENB.exeAdded by the Troj/PWSYahoo-A TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    Microsoft PCI ManagerXmspci.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Personal FirewallsXbakw.exeAdded by a W32/Rbot-KS worm infection
    Microsoft Proc Driver32Xmsprc.exeAdded by a variant of the W32/WOOTBOT WORM!
    Microsoft Procedure CallXMSPCALL.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft PSTCP32 DataXpstcp32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft QMGRXmsnqmgr.exeAdded by the TROJ/IRCBOT-S TROJAN!
    Microsoft RDLLXsysconf32.exeAdded by a variant of the SDBOT WORM!
    Microsoft RedirectX[path to file]Added by the BANKER-FW TROJAN!
    Microsoft RedirectXsysten.exeAdded by the Troj/Bancos-FO TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Microsoft RegistroXsvchostt.exeAdded by the TROJ/BANCOS-DH TROJAN!
    Microsoft RegistryXcsrse.exeAdded by the W32/RBOT-PC WORM!
    MicroSoft Remote Secure ServiceXMSRSS.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft RestoreXscrgrd.exeAdded by the SPYBOT.BR WORM!
    Microsoft RundllXwindos.exeAdded by the W32/SDBOT-WF WORM!
    Microsoft RuntimeXCfgDll32.exeAdded by the RANDEX.BD VIRUS!
    Microsoft ScanregXmicrosoftscanreg.exeAdded by the FRANRIV.A VIRUS!
    Microsoft SCVHOST32 ProtocolXscvhost32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft sddcE ContolXtaskmnegr.exeAdded by W32/Rbot-AUM WORM!
    Microsoft sdDDE ControlXtaskmnegr.exeAdded by the W32/Rbot-AVU WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft sdk tempXsdktemp.exeAdded by the W32/Rbot-ANP WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft SDKP3Xmswinsdq.exeAdded by the W32/RBOT-ARY WORM!
    Microsoft Secure Messenger.NET ServiceXsecuritychk.exe WORM_SDBOT.VT
    Microsoft SecurityXwinService.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Security CenterXsavservices.exeAdded by the W32/RBOT-ANU WORM!
    Microsoft Security ControlersXfxsecues.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Security GManagersX[random file name]Added by a variant of the W32/SDBOT WORM!
    Microsoft Security Hot Fix UpdateXmshotfix.exe Affilred adware
    Microsoft Security ManagementXwinserv.exeAdded by the W32/Rbot-MJ WORM!
    Microsoft Security ManagementXmsisrv32.exeAdded by a W32/Rbot-ML worm infection
    Microsoft Security ManagementXwinnt.exeAdded by the W32/RBOT-MQ WORM!
    Microsoft Security ManagementXwinamp.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Security ManagementXwuauct1.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Security ManagerXwinamp.exeAdded by the RBOT.TU WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
    Microsoft Security PanagerX[name of file]Added by the W32/RBOT-ANL WORM!
    Microsoft Security PanagersX[random file name]Added by the W32/RBOT-AIG WORM!
    Microsoft Security PanagersXzzoboony.exeAdded by the W32/Rbot-AOI WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Server ApplacationsXmsnmsg.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Server ApplacationsXwuauct1.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Server ApplacationsXlsasss.exeAdded by the W32/RBOT-AQQ WORM!
    Microsoft Server ApplicationXSound.exeAdded by the W32/RBOT-NE WORM!
    microsoft server baseXlass.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ServiceXmicrohost.exeAdded by a W32/Rbot-LC worm infection
    Microsoft ServiceXwinsvc.exeAdded by a W32/Spybot-DB worm infection
    Microsoft ServiceXrundll.exeAdded by the W32/Popo-A WORM! Note: This worm file is found in the Windows or Winnt folder.
    Microsoft Service ControllerXservices.exeAdded by the W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
    Microsoft Service DriversXVSADNIM.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Service DriversXSystem.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Service Host ProcessXsvchost.exeAdded by the KRYNOS.B WORM! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    Microsoft Service PackXWindowsSP.exeAdded by the W32/RBOT-RF WORM!
    Microsoft Service Pack2.1Xsvchost2.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ServicesXlsrv.exe W32/Rbot-BK worm
    Microsoft ServicesXlssrv.exe WORM_RBOT.CW
    Microsoft ServicesXservices.exeAdded by the ALETS VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process
    Microsoft ServicesXsvshost.exeAdded by the BACKDOOR.ALETS.B TROJAN!
    Microsoft ServicesXbsc32.exeAdded by the BDOOR-AW TROJAN!
    Microsoft ServicesXsvssshost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft ServicesXSmss32.exeAdded by the W32/RBOT-AD WORM!
    Microsoft Services UnitdXMSU32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Servicez ManagerXservicemgrz.exeAdded by the W32/Rbot-ASN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Session Manager SubsystemXsmss.exeAdded by the W32/Kalel-D WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
    Microsoft Sidewinder Game Controller SoftwareNSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs
    Microsoft SinsupXodjiwjf.exeAdded by the W32/RBOT-DN WORM!
    Microsoft SoftwareXsysinfo33.exeAdded by a RBOT.LS worm infection
    Microsoft softwareXcdaccess.exeAdded by the RBOT.ABK WORM!
    microsoft softwareX****.exeAdded by an unidentified WORM or TROJAN! (where * stands for a random character)
    Microsoft Software UpdateXnmon.exeAdded by a RBOT.HZ worm infection
    Microsoft Sound DriverXsound32.exe W32.SpyBot worm variant
    Microsoft Sound TechnologyXwinsound.exeAdded by the W32/Rbot-AGG WORM!
    Microsoft Sound Volume ToolNmssvol.exeThis is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
    Microsoft SourceSafeXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    Microsoft SpA ServiceXmsapps.exeAdded by the W32/RBOT-VI WORM!
    Microsoft SpA ServiceXwin32.exeAdded by the RBOT.ATS WORM!
    Microsoft SpA ServiceXWinupd32.exeAdded by the RBOT.LT WORM!
    Microsoft Special offerXinfoebay.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Spool Server for Win32Xspoolsrv.exeAdded by the RANDEX.H VIRUS!
    Microsoft SSISVRI32 ProtocolXssisvri.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Standard Executions LibraryXwin32lib.exeAdded by W32/Rbot-AUK WORM!
    Microsoft standard protectorXwinsocks5.exeAdded by a variant of the TROJ/STOX-B TROJAN!
    Microsoft standard protectorX(Path to trojan)Added by the Troj/Stox-C TROJAN!
    Microsoft Sum32Xsum32.exeAdded by the W32/RBOT-YW TROJAN!
    Microsoft Sum32Xsum32.exeAdded by the W32/RBOT-YW WORM!
    Microsoft SupportXsys32ms.exeAdded by the W32/RBOT-AHI WORM!
    Microsoft Synchronization ManagerXbot.exeAdded by a SDBOT.IH worm infection
    Microsoft Synchronization ManagerXasgard.exeAdded by a SDBOT.PH worm infection
    Microsoft Synchronization ManagerXxXx.exeAdded by a W32/Sdbot-KZ worm infection
    Microsoft Synchronization ManagerXWinLoginnn.exeAdded by a SPYBOT.FO worm infection
    Microsoft Synchronization ManagerXnetscape.exeAdded by a RANDEX.AE worm infection
    Microsoft Synchronization ManagerXwinupdate.exeAdded by a SDBOT.ER worm infection
    Microsoft Synchronization ManagerXsvhost.exeAdded by a W32/Sdbot-PY And W32/Sdbot-YR WORMS!
    Microsoft Synchronization ManagerXslhost.exeAdded by a SDBOT.YH worm infection
    Microsoft Synchronization ManagerXal.exeAdded by the OPTXPRO.132 TROJAN!
    Microsoft Synchronization ManagerX___synmgr.exeAdded by the W32.MASLAN.C WORM!
    Microsoft Synchronization ManagerXwin.exeAdded by the SDBOT.AK WORM!
    Microsoft Synchronization ManagerXsvchosts.exeAdded by the W32/SDBOT-LM WORM!
    Microsoft Synchronization ManagerXjava.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Synchronization ManagerXwinlogon32.exeAdded by the SDBOT.AEU WORM!
    Microsoft Synchronization ManagerXwincfg32.exeAdded by the SDBOT.DO WORM!
    Microsoft Synchronization ManagerXsvxhost.exeAdded by the W32/Sdbot-ZU WORM!
    Microsoft Synchronization ManagerXscreen.exeAdded by the W32/SDBOT-ACO WORM!
    Microsoft Synchronization ManagerXdevldr32.exeAdded by a variant of the WIN32.RBOT WORM! - Note - do NOT confuse with the legitimate Creative Labs devldr32.exe file
    Microsoft Synchronization ManagerXexplorer.exeAdded by the W32/Sdbot-AEA WORM! Note: This is not the legitimate Windows process explorer.exe (Which is always found in the Windows or Winnt folder.) This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Synchronization ManagerXfirewire.exeAdded by the W32/Sdbot-AFC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft SystemXmsupdtm.exeAdded by the W32.Spybot.PKC Worm!
    Microsoft System BackupX(RANDOM NAME).exeAdded by the W32/Rbot-AGM WORM!
    Microsoft System CheckupXCool.exeAdded by the W32.HLLW.Donk.B WORM!
    Microsoft System CheckupXWnetlib.exeAdded by the W32.HLLW.Donk.C WORM!
    Microsoft System CheckupXdbnetlib.exeAdded by the W32.HLLW.Donk.L WORM!
    Microsoft System CheckupXKeymgr.exeAdded by the W32.HLLW.Donk.M WORM!
    Microsoft System CheckupXinetman.exeAdded by the W32.HLLW.Donk.O WORM!
    Microsoft System CheckupXntsysmgr.exeAdded by the W32.Donk.S WORM!
    Microsoft System CheckupXntsysman.exeAdded by the W32/SDBOT-QW WORM!
    Microsoft System CheckupXlibsysmgr.exeAdded by the W32/SDBOT-CAF WORM!
    Microsoft System CheckupXsysmgr.exeAdded by the SDBOT-OO TROJAN!
    Microsoft System CheckupXnetapi32.exeAdded by the W32/DONK-E WORM!
    Microsoft System CheckupXwnetmgr.exeAdded by the W32.DONK.Q WORM!
    Microsoft System CheckupXlibsys32.exeAdded by the W32/SDBOT-ACK WORM!
    Microsoft System DebugXservices32.exeAdded by the RBOT.AKH WORM!
    Microsoft System DLL Services ConfigurationXwindir32.exeAdded by the following WORMS! W32/Sdbot-ACY - W32/Sdbot-AEK - W32/Sdbot-AEL - W32/Sdbot-AEW - W32/Opanki-L Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder
    Microsoft System NTXsvhost.exeAdded by the IRC/SDBOT.COU WORM!
    Microsoft System Restore ConfigurationXCBRSS.EXEAdded by a variant of the SPYBOT VIRUS!
    Microsoft System ServicesXmsnmgsr.exeAdded by the W32.KELVIR.K WORM!
    Microsoft System ServicesXmsmsgr.exeAdded by the W32/RBOT-ZH WORM!
    Microsoft System UpdateXsysupdate.exeAdded by the SDBOT.DG WORM!
    Microsoft Taskmanager UpdaterXkeyboard.exeAdded by the W32/RBOT-ALU WORM!
    Microsoft Telecom CenterXtellecom.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Telecoma CenterXtellcoma.exeAdded by the W32/Rbot-AWX WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Time ManagerXdveldr.exe W32/Rbot-HQ worm
    MicroSoft ToolbarXkey.exeAdded by the W32/Rbot-AEW Worm!
    Microsoft Transfer File ServerXmtfs.exeAdded by the RBOT.AFE WORM!
    Microsoft TrayX(random filename)Added by the DELF.BZ VIRUS!
    Microsoft UXwuamkopxp.exeAdded by the W32/RBOT-AHC WORM!
    Microsoft UMA UpdateXMSuma32.exeAdded by the RBOT.FS WORM!
    MICROSOFT UNPACCKER SYSTEMXunpak32.exeAdded by a variant of the WIN32.RBOT WORM!
    MICROSOFT UNPACK SYSTEMXwinrarx.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Updat3Xmswkst32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXmsiwin84.exeAdded by the GAOBOT.AFJ WORM!
    Microsoft UpdateXmssmgrd.exeAdded by the SDBOT.JT WORM!
    Microsoft UpdateXwserv32.exeAdded by the RBOT.AF WORM!
    Microsoft UpdateXmuamgrd.exeAdded by a variant of the AGOBOT.GEN WORM!
    Microsoft UpdateXwinsys32.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft UpdateXnavmgrd.exeAdded by the BKDR_SDBOT.DP TROJAN!
    Microsoft UpdateXMicrosoftx.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft UpdateXSmss32.exeAdded by the W32/Rbot-CB WORM!
    Microsoft UpdateXwudmate.exeAdded by the RBOT.AP WORM!
    Microsoft UpdateXIsac.exeAdded by the W32/Rbot-AU WORM!
    Microsoft UpdateXVPC32.EXEAdded by the AGOBOT.XM WORM!
    Microsoft UpdateXautomgr32.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft UpdateXmvsc.exeAdded by a variant of the W32.Spybot.DAZ WORM!
    Microsoft UpdateXascdl.exeAdded by the W32.Gaobot.SY WORM!
    Microsoft UpdateXsys32cfg.exeAdded by the RBOT.DR WORM!
    Microsoft UpdateXwuammgr32.exeAdded by a variant of the W32/Rbot-AW WORM!
    Microsoft UpdateXMslti32.exeAdded by the W32/Rbot-LX WORM!
    Microsoft UpdateXmediap.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft UpdateXmsconfg.exeAdded by the Win32.Rbot.H WORM!
    Microsoft UpdateXwebm.exeAdded by the SDBOT.WK WORM!
    Microsoft UpdateXwuamgrd32.exeAdded by the RBOT.ZB WORM!
    Microsoft UpdateXMicrosoft.exeAdded by the GAOBOT.AFJ WORM!
    Microsoft UpdateXmsawindows.exeAdded by the GAOBOT.AFJ WORM!
    Microsoft UpdateXxpupdate.exeAdded by the W32/RBOT-QE WORM!
    Microsoft UpdateXsystemi32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft UpdateXNAV.exeAdded by the W32/RBOT-IV WORM!
    Microsoft UpdateXwuagrd.exeAdded by the W32/RBOT-FK WORM!
    Microsoft UpdateXwauguard.exeAdded by the RBOT.AEE WORM!
    Microsoft UpdateXprowind32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft UpdateXlsac.exeAdded by the GAOBOT.XW WORM!
    Microsoft UpdateXsnlogsvc.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwinscv.exeAdded by the W32/RBOT-BH WORM!
    Microsoft UpdateXsvhost.exeAdded by the W32/RBOT-PI WORM!
    Microsoft UpdateXwuampd.exeAdded by the W32/RBOT-UT WORM!
    Microsoft UpdateUphqghumea.exeIdentified as unknown malware W32/Backdoor by Norman
    Microsoft UpdateXwkfix.exeAdded by the W32/RBOT-ABZ WORM!
    Microsoft UpdateXwuagmrd.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwssvr.exeAdded by the W32/RBOT-OD WORM!
    Microsoft UpdateXwindows24.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXBotnet.exeAdded by the RBOT.AFL WORM!
    Microsoft UpdateXupdate_w.exeAdded by the W32/RBOT-EW WORM!
    Microsoft UpdateXwuamagr32.exeAdded by the SPYBOT.CG WORM!
    Microsoft UpdateXwingrd32.exeAdded by the W32/RBOT-DW WORM!
    Microsoft UpdateXwingrd32.exeAdded by the W32/RBOT-DW WORM!
    Microsoft UpdateXaaupdt.exeAdded by the W32/RBOT-RQ WORM!
    Microsoft UpdateXsghost.exeAdded by the SDBOT.AKV WORM!
    Microsoft UpdateXmsupdate32.exeAdded by the SPYBOT.LZ WORM!
    Microsoft UpdateXWinUpdate32.exeAdded by the W32/RBOT-TI WORM!
    Microsoft UpdateXwinsys.exeAdded by the W32/RBOT-GV WORM!
    Microsoft UpdateXwumgrd.exeAdded by the W32/SDBOT-KY WORM!
    Microsoft UpdateXwuamgrd.exeAdded by the W32/RBOT-YI WORM!
    Microsoft UpdateXwtm32.exeAdded by the W32/RBOT-AQ WORM!
    Microsoft UpdateXmcupdate.exeAdded by a variant of the WIN32.RBOT WORM! - NOTE - this file is located in the Windows\System32 or Winnt\System32 folder, and must NOT be confused with the McAfee antivirus executable as described here
    Microsoft UpdateXscvhost.exeAdded by the W32/Rbot-AEM Worm!
    Microsoft UpdateXwin-mang.exeAdded by the W32/Rbot-AFK Worm!
    Microsoft UpdateXwuamkop.exeAdded by the W32/Rbot-AFI Worm!
    Microsoft UpdateXup2dat5.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft UpdateXwuamkop32.exeAdded by the RBOT.BGU WORM!
    Microsoft UpdateXwuamk0032.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwuampkd.exeAdded by the SDBOT.BBX WORM!
    Microsoft UpdateXwuamk032.exeAdded by the W32/RBOT-AHD WORM!
    Microsoft UpdateXKkk.exeAdded by the W32/RBOT-AHL WORM!
    Microsoft UpdateXsys.exeAdded by the W32/RBOT-AJ WORM!
    Microsoft UpdateXsvghost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwuamk0p32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwinamp.exeAdded by a variant of the WIN32.RBOT WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
    Microsoft UpdateXwinupdater.exeAdded by the RBOT.BIN WORM!
    Microsoft UpdateXMsnmsngr.exeAdded by the RBOT.BQS WORM!
    Microsoft UpdateXMicr0s0ft.exeAdded by the AGOBOT.AAR WORM!
    Microsoft UpdateXmsupdate.exeAdded by the TROJ/BOROBOT-I TROJAN!
    Microsoft UpdateXmixer.exeAdded by the W32/Rbot-AIR WORM!
    Microsoft UpdateXdevmks32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft updateXwinupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwin32.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft UpdateXsvzhost.exeAdded by the RBOT.OX WORM!
    Microsoft UpdateXwininit.exeAdded by the W32/Rbot-AKR WORM!
    Microsoft UpdateXWudates.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdateXwuamgrd3.exeAdded by the W32/Rbot-AMC WORM!
    Microsoft UpdateXms.exeAdded by the BKDR_SDBOT.CC WORM!
    Microsoft UpdateXwuagmsd.exeAdded by the W32/RBOT-AX WORM!
    Microsoft UpdateXcmss.exeAdded by W32/Rbot-ATQ WORM!
    Microsoft UpdateXbling.exeAdded by the W32/Rbot-AVK WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Update 23XNtKernelSystem.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 23Xspoolvs.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 32Xexplore32.exeAdded by the W32.Spybot.CYM WORM!
    Microsoft Update 32XMSupdate32.exeAdded by a variant of the Win32.SpyBot WORM!
    Microsoft Update 32Xwininit32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 32Xwininit.exeAdded by the W32/RBOT-ANY WORM!
    Microsoft Update 32X(original filename)Added by the W32/Rbot-AJJ WORM!
    Microsoft Update 32XwinitXP32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 32Xmscnfg.exeAdded by the W32/Rbot-ALM WORM!
    Microsoft Update 32Xservic.exeAdded by the W32/Rbot-AXN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Update 32Xwiit.exeAdded by the W32/Rbot-AMS WORM!
    Microsoft Update 32Xmssetup32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update 32Xwinnit.exeAdded by the W32/Rbot-AOM WORM!
    Microsoft Update 32Xom4r.exeAdded by the W32/RBOT-AQP WORM!
    Microsoft Update 32Xexplorer.exeAdded by the W32/Rbot-ARF WORM! Note: This is not the legitimate Windows process explorer.exe (Which is always found in the Windows or Winnt folder.)The legitimate Windows process should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. folder.
    Microsoft Update 32Xwinin.exeAdded by the W32/RBOT-ARR WORM!
    Microsoft Update 32Xnetwork.exeAdded by the W32/RBOT-ARZ WORM!
    Microsoft Update 32Xwuinit.exeAdded by the W32/Agobot-UE WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Update 33Xinit.exeAdded by W32/Rbot-ATT WORM!
    Microsoft Update 64 BITXwininit32.exeAdded by the W32/RBOT-AHE or W32/RBOT-ATO or W32/Rbot-AST WORM!
    Microsoft Update 64 BITXwinman32.exeAdded by the W32/Rbot-AKI WORM!
    Microsoft Update 64 BITXschvost.exeAdded by the RBOT.CAU WORM!
    Microsoft Update 64 BITXwinl32xe.exeAdded by the W32/RBOT-AQO WORM!
    MICROSOFT UPDATE CONFIGURATIONXWIN32SNC.exeAdded by the W32/Rbot-AI WORM!
    Microsoft Update ControlXMs64.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update DebuggerXwincfg32.exeAdded by the SPYBOT.ZC WORM!
    Microsoft Update DLLXrxxhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update EmulatorXkern-mxe.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update LoaderX(random file name)Added by a variant of the Win32.Rbot WORM!
    Microsoft Update Loaders 2005Xwinusers.exeAdded by the W32/RBOT-AIQ WORM!
    Microsoft Update Loaders 2006Xwinusersystem32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Microsoft Update MachineXexpl0rer.exeAdded by a variant of the SDBOT.OK WORM!
    Microsoft Update MachineXwuamgrd.exeWindUpdates SyncroAd adware
    Microsoft Update MachineXrxhost.exeAdded by the RBOT.FC WORM!
    Microsoft Update MachineXservicz.exeAdded by the W32/Rbot-HU WORM!
    Microsoft Update MachineXwinxpini.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXwininigo.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXSP2.exeAdded by the SPYBOT.FP WORM!
    Microsoft Update MachineXxvshost.exeAdded by the RBOT.QP WORM!
    Microsoft Update MachineXwinini.exeAdded by the W32/Rbot-KV WORM!
    Microsoft Update MachineXwinmgr.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXntce.exeAdded by the W32/RBOT-FA WORM!
    Microsoft Update MachineXwuawx.exeAdded by the W32/RBOT-CE WORM!
    Microsoft Update MachineXzonealarm.exeAdded by the W32/RBOT-BZ WORM! - NOTE: this is not the valid Zone Labs firewall program!
    Microsoft Update MachineXsystem03.exeAdded by the W32/RBOT-NM WORM!
    Microsoft Update MachineXmemstat.exeAdded by the W32/RBOT-OM WORM!
    Microsoft Update MachineXwinupdt.exeAdded by the W32/RBOT-FP WORM!
    Microsoft Update MachineXsystemll.exeAdded by the W32/RBOT-JT WORM!
    Microsoft Update MachineXsvshost.exeAdded by the RBOT.AK WORM!
    Microsoft Update MachineXwupdt32x.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Update MachineXwuamgd.exeAdded by the SDBOT.HQ WORM!
    Microsoft Update MachineXrandom file namesAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXlinux.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXwindowsu.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineX lmrss.exeAdded by a variant of the Win32.Rbot WORM!
    Microsoft Update MachineXWinregs32.exeAdded by the RBOT.DN WORM!
    Microsoft Update MachineXWinmsixp32.exeAdded by the RBOT.DN WORM!
    Microsoft Update MachineXwuagrd.exeAdded by the W32/RBOT-GF WORM!
    Microsoft Update MachineXwinss.exeAdded by the RBOT.JU WORM!
    Microsoft Update MachineXMSOICONS.EXEAdded by a variant of the WIN32.RBOT WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here . The latter wil not be listed among your startups!
    Microsoft Update MachineXwupdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXservicez.exeAdded by the SPYBOT.BI WORM!
    Microsoft Update MachineXqwerty.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXlsasse.exeAdded by the W32/RBOT-DI WORM!
    Microsoft Update MachineXSystemnt.exeAdded by the RBOT.DA WORM!
    Microsoft Update MachineXsystemse.exeAdded by the W32/RBOT-BD WORM!
    Microsoft Update MachineXtaskmngrs.exeAdded by the W32/RBOT-CR WORM!
    Microsoft Update MachineXspoolserv.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXwindowsup.exeAdded by the W32/RBOT-FV WORM!
    Microsoft Update MachineXwuamgard.exeAdded by the SPYBOT.CS WORM!
    Microsoft Update MachineXcrss32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXrxxhost.exeAdded by the RBOT.EP WORM!
    Microsoft Update MachineXwinnie.exeAdded by the W32/RBOT-ACD WORM!
    Microsoft Update MachineXscvhost.exeAdded by the W32/RBOT-GS WORM!
    Microsoft Update MachineXsystem.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXwins32.exeAdded by the RBOT.EZ WORM!
    Microsoft Update MachineXwinortho.exeAdded by the W32/RBOT-NW WORM!
    Microsoft Update MachineXTMEMSER.EXEAdded by the W32/RBOT-NQ WORM!
    Microsoft Update MachineXWin32.exeAdded by the SDBOT.UV WORM!
    Microsoft Update MachineXTASKMAN4.EXEAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update MachineXwftestb.exeAdded by the W32/Rbot-AFZ Worm!
    Microsoft Update MachineXwindns.exeAdded by the RBOT.EF WORM!
    Microsoft Update MachineXserviz.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update ManagerXsvshost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update ManagerXWINRLS.EXEAdded by the RBOT-AF WORM!
    Microsoft Update ManagerXscvhost.exeAdded by the AGOBOT.AXJ WORM!
    Microsoft Update MecheneXUpdatez.exeAdded by the W32/RBOT-GI WORM!
    Microsoft Update ProcessXwmipcvse.exeAdded by the TROJ/AGOBOT-JF TROJAN!
    Microsoft Update Security PatchXmssecurityupdatepatch.exeAdded by the Win32.Agent.ef backdoor TROJAN!
    Microsoft Update ServerXmssrv.exeWorm or trojan, as yet unidentified
    Microsoft Update ServiceXcsrss32.exeAdded by the W32/Agobot-HC WORM!
    Microsoft Update ServiceXmswin32.exeAdded by a variant of the Win32.Spybot WORM!
    Microsoft update serviceXsystemm.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Update SERVICEXphqghum.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update ServiceXmsupdate.pifAdded by the W32/Rbot-AQB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Update ServicesXwsnfty.exeAdded by the W32/RBOT-AFU WORM!
    Microsoft Update ServicesXwcsnfty.exeAdded by the W32/RBOT-AGK WORM!
    Microsoft Update TimeXwuam.exeAdded by the W32/Rbot-M WORM!
    Microsoft Update USB2Xwuammgrd32.exeAdded by the W32/Rbot-ADT Worm!
    Microsoft Update v2.6Xlxxex.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Update Win32aXwinupdate32a.exeAdded by the W32/Rbot-LO WORM!
    Microsoft Update Win32xXwinupdate32x.exeAdded by the W32/Rbot-AJN WORM!
    Microsoft UpdaterXwuamgrds.exeAdded by the BKDR_RBOT.A!
    Microsoft UpdaterXWinsys32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Updater ResourcesXWinFixd32.exeAdded by the SPYBOT.CA WORM!
    Microsoft UPDATER32Xlsass.exeAdded by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup
    Microsoft UpdatersXtskmgr.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdatersXsysconfigs.exeAdded by the W32/RBOT-DF TROJAN!
    Microsoft Updaters ProsXWINDLL32XP.EXEAdded by the SPYBOTTER.GEN VIRUS!
    Microsoft UpdatesXwuamgrd.exeAdded by the W32/RBOT-CO WORM!
    Microsoft UpdatesXwkssvrs.exeAdded by the W32/RBOT-EB WORM!
    Microsoft UpdatesXwkssvr.exeAdded by the RBOT.R WORM!
    Microsoft UpdatesXsystemc32.exeAdded by the W32/RBOT-GR WORM!
    Microsoft UpdatesXwtemp32.exeAdded by the W32/Rbot-AHQ WORM!
    Microsoft Updates 2 USBXwgafixer.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Updates 5 USBXsp3fixer.exeAdded by the W32/Rbot-ADS Worm!
    Microsoft Updates ResourcesXWinFixIDs.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdatingXwuamguards.exeAdded by the W32/RBOT-BY WORM!
    Microsoft UpdatingXsyswr.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdatingXnavguard.exeAdded by the RBOT.HW WORM!
    Microsoft Updating ClientXwebsvc.exeAdded by the RBOT.AQ WORM!
    Microsoft Updating MachineXsysc0de.exeAdded by the RBOT.RB WORM!
    Microsoft UpdattingXmiroupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft UpdoteX(Random File name)Added by the W32/Rbot-ARC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft UpMachineXdoezs.exeAdded by the RBOT.BCT WORM!
    Microsoft upnp UpdateXmsie.exeAdded by a W32/Rbot-LQ worm infection
    Microsoft uptime ServiceXsysuptime.exeAdded by the W32/RBOT-ACG WORM!
    Microsoft uptime ServiceXsycuptime.exeAdded by the W32/RBOT-AHY WORM!
    Microsoft UpToDate Driver (32-bits)X[random file name].exeAdded by the W32.SPYBOT.LXJ WORM!
    Microsoft USB2 DriverXcrmss.exeAdded by the W32/RBOT-VK WORM!
    Microsoft Utility StartupXOSA9.exeResource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway. Different filenames used for different variants
    Microsoft VertupdateXMSvert32.exeAdded by the W32/MYTOB-CY WORM!
    Microsoft Video Capture ControlsXMSsrvs32.exeAdded by the W32/SDBOT-AAK WORM!
    Microsoft Video ControlsXtskmsgr.exe W32.SpyBot worm variant
    Microsoft Viral Scanning ProtectionXmsviral.exeAdded by the W32/Sdbot-CLH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Virual MachineXsms.exeAdded by the W32/RBOT-SP WORM!
    Microsoft Visual SourceSafeXservices.exeAdded by the W32.Neveg.B worm. Note - this is NOT the legitimate services.exe system file, which should NOT figure in Msconfig/Startup
    Microsoft Visual SourceSafeXwinlogon.exeAdded by the W32.Neveg.B worm
    Microsoft Visual StudioXplscdksxg.exeAdded by the W32/Rbot-AWV WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Visual Studio VSAXvarpc32.exe W32.SpyBot worm variant
    Microsoft Web DeviceXwdevice.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft WebserverUsvctrl.exePersonal web server program which enables you to create and host a web server from your computer. Not required for most people
    MicroSoft Wind0ws UpdaterXwinsupdater.exeAdded by a variant of the WIN32.RBOT WORM!
    MicroSoft Window UpdaterXwinsupdater.exeAdded by the W32/RBOT-ZZ WORM!
    Microsoft WindowsXmstask0.exeAdded by the SDBOT.FQ WORM!
    Microsoft WindowsXatupAdded by a variant of the WIN32.RBOT WORM!
    Microsoft WindowsXMicrosoft Windows.htaHTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
    Microsoft WindowsXexplorar.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft WindowsX(Path of Executable)Added by the Troj/Bdoor-LI TROJAN!
    Microsoft WindowsXwindets.comAdded by the Troj/Flood-EQ TROJAN!
    Microsoft Windows 128bit SubsystemXsystem12.exeAdded by the Troj/Ranck-CZ TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows 16BitXmswinn16.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Windows 2000XWinupdsdgm.exeAdded by the GAOBOT.AO WORM!
    Microsoft Windows 32BitXmswinn32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows 64 BitXmswin32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows ControlXmswctl32.exeAdded by the RBOT.JP WORM!
    Microsoft Windows CSRSSXcsrss.exeAdded by the W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Microsoft Windows DHCPX___r.exeAdded by the W32.Maslan.A or W32.Maslan.C WORMS!
    Microsoft Windows DLL 32-BITXmsncheck32.exeAdded by the W32/SDBOT-XX WORM!
    Microsoft Windows DLL ServicesXmwindll.exeAdded by the W32/SDBOT-VX WORM!
    Microsoft Windows DLL Services ConfigurationXregscv.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Windows DLL Services ConfigurationXwinDSL.exeAdded by the W32/Sdbot-ZG Worm!
    Microsoft Windows DLL Services ConfigurationXproxy.exeAdded by the W32/Sdbot-ZL Worm!
    Microsoft Windows DLL Services ConfigurationXnewdll.exeAdded by the W32/Sdbot-ZR WORM!
    Microsoft Windows DLL Services ConfigurationXnewdll2.exeAdded by the W32/SDBOT-ABD WORM!
    Microsoft Windows DLL Services ConfigurationXwindll32.exeAdded by the SDBOT.BHD WORM!
    Microsoft Windows DLL Services ConfigurationXpoker.exeAdded by the W32/SDBOT-ZY WORM!
    Microsoft Windows DLL Services ConfigurationXwindir32a.exeAdded by a variant of the SDBOT.BHF WORM!
    Microsoft Windows DLL Services ConfigurationXpoker3.exeAdded by the W32/SDBOT-AAH WORM!
    Microsoft Windows DLL Services ConfigurationXdllmanager32.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Windows DLL Services ConfigurationXwindir32.exeAdded by the RBOT.BRQ WORM!
    Microsoft Windows DLLHandlerXbitpaint.exeAdded by the SDBOT.AHG WORM!
    Microsoft Windows ExplorerXiexplorer.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows Files LoaderXcgy32win.exeAdded by the W32/Rbot-AXR WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows Game UpdaterXmsgame32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows GUIXWindowz.exeAdded by the RANDEX.AEV VIRUS!
    Microsoft Windows GUIXmsmonk32.exeAdded by the W32/SDBOT-PE WORM!
    Microsoft Windows Kernel ServicesXwinkrnl386.exeAdded by the ZEBROXY VIRUS!
    Microsoft Windows LoaderXwloader.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Microsoft Windows Media PlayerXwimp.exeAdded by the W32/RBOT-FN WORM!
    Microsoft Windows Media PlayerXmediaplayer.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows Registry ServiceXwregistry.exeAdded by the AGOBOT.AKG WORM!
    Microsoft Windows Registry UpdaterXwreg.exeAdded by the W32/FORBOT-DN WORM!
    Microsoft Windows Secure ServerXrpcxWindows.exeAdded by a W32/Rbot-LL worm infection
    Microsoft Windows Secure UpdateXrpcxwinupdt.exeAdded by an unidentified WORM or TROJAN!
    Microsoft Windows SecuretyXwurguar.exeAdded by the W32/RBOT-KY WORM!
    Microsoft Windows SecurityXspvsper.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Windows SecurityXwscndrives.exeAdded by the W32/Rbot-AJK WORM!
    Microsoft Windows ServiceXwinsys.exeAdded by the W32/Rbot-ADP Worm!
    Microsoft Windows Service PackXwinspkn.exeAdded by the W32/Rbot-AYD WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Windows Services ControllerXwservices.exeAdded by the WIN32.RBOT.FD WORM!
    Microsoft Windows Storage Machine ServiceXwinms.exeAdded by the W32/RBOT-AHK WORM!
    Microsoft Windows SystemXsyshost.exeAdded by the W32/Rbot-ASW WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows SystemXsrwhost.exeAdded by a variant of the W32/Rbot-ASW worm! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows System Service ManagerXwinsvc.exeAdded by the SPYBOT.LR WORM!
    Microsoft Windows Task MangerXMstosk.exeAdded by a W32/Sdbot-WW worm infection
    Microsoft Windows UpdataXscvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows UpdateXrundlls.exeAdded by the HABRACK VIRUS!
    Microsoft Windows UpdateXspools.exe WORM_SDBOT.TD
    Microsoft Windows UpdateXmsoffice2.exeAdded by a W32/Rbot-GB worm infection
    Microsoft Windows UpdateXsvchos.exeAdded by a Backdoor.Sdbot.AC worm infection.
    Microsoft Windows UpdateXsvcshost.exeAdded by the W32/FORBOT-CF WORM!
    Microsoft Windows UpdateXsvshost.exeAdded by the WOOTBOT.CJ WORM!
    Microsoft Windows UpdateXsvmhost.exeAdded by the W32/FORBOT-CH WORM!
    Microsoft Windows UpdateXscvvhost.exeAdded by the W32/Forbot-FH WORM!
    Microsoft Windows UpdateXswwhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows UpdateXMSNMSGR.EXEAdded by the W32/SDBOT-WM WORM!
    Microsoft Windows UpdateXsvzhost.exeAdded by the W32/FORBOT-EV WORM!
    Microsoft Windows UpdateXscrhost.exeAdded by the W32/Rbot-AOW WORM! Note: This (scrhost.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Windows UpdateXsccvhost.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Windows UpdateXmnswinsx.exeAdded by the W32/Rbot-AWH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows Update ApplicationXwuap.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows Update LogonXwin-logon.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows Update ServiceXwupdmgr32.exeAdded by the DOS.AUTOCAT VIRUS!
    Microsoft Windows Update XP64X********.exe (* = random char)Added by a variant of the WIN32.RBOT WORM!
    Microsoft Windows UpdaterXwinupdgm.exeAdd by the GAOBOT.BI WORM!
    Microsoft Windows UpdaterXsvchostz.exeAdded by the DAEMONI-E VIRUS!
    Microsoft Windows UpdaterXWINIUPDATES.EXEAdded by a W32/Rbot-KK worm infection
    Microsoft Windows UpdaterXWINUPDATE.EXEAdded by the W32/SDBOT-PU WORM!
    Microsoft Windows UpdaterXwin32upd.exeAdded by the W32/RBOT-EC WORM!
    Microsoft Windows UpdaterXTMNTSrv.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft Windows UpdaterXwindates.exeAdded by the SDBOT.TE WORM!
    Microsoft Windows UpdaterXmsnupdateit.exeAdded by the W32/AGOBOT-RL WORM!
    Microsoft Windows UpdaterXspoolvs.exeAdded by the RBOT.ACQ WORM!
    Microsoft Windows UpdaterXsuvhost.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft Windows updaterDXlog32zx.exeAdded by the W32.Mydoom.W WORM!
    Microsoft Windows UpdatesXexplorer32.exeAdded by the SDBOT.VQ WORM!
    Microsoft Windows W32 ServicesXmssw32.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Windows WinSaSS ManagementXwinsass.exeAdded by the W32/Rbot-APW or W32/Rbot-AUO WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows WKS ServiceX gt.exeAdded by the SDBOT.FV WORM!
    Microsoft Windows WorkstationXdevcode.exeAdded by the W32/Rbot-AWL WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft Windows XP Configuration LoaderXm32svco.exeAdded by the W32/SDBOT.WORM.48548
    Microsoft WINGS32 ProtocolXWinSGR32.exeAdded by the W32/Rbot-APU WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Microsoft WinRaRXwinrar.exeAdded by the W32/Rbot-AEC Worm!
    Microsoft WinsockXmswinsck.exeAdded by the W32/RBOT-ANK WORM!
    Microsoft Winsock ServiceXmsusvc.exeAdded by the W32/Rbot-ANS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoft Winsock WrapperXws2_32s.exeAdded by a variant of the W32.SPYBOT WORM!
    Microsoft Winsocks 32 ControllerXMSWSCK32.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft WinSoundX[random file name]Added by a variant of the WIN32.RBOT WORM!
    Microsoft WinUpdateXsyslx32.exeUnidentified worm or trojan
    Microsoft WinUpdateXsyswin32.exeAdded by the W32/Rbot-HO WORM!
    Microsoft WinUpdateXsvh0st.exeAdded by a SPYBOT.DL worm infection
    Microsoft WinUpdateXWinamp61.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft WinUpdateXspfix.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft WinUpdateXmntcgf032.exeAdded by the W32/RBOT-PF WORM!
    Microsoft WinUpdateXWinupd32.exeAdded by the RBOT.MQ WORM!
    Microsoft WinUpdateXWinNTinit32.exeAdded by the RBOT.VS WORM!
    Microsoft WinUpdatesXserm32.exeAdded by the RBOT.GE worm
    Microsoft WMXmswm32.exeAdded by the TROJ/BCKDR-AM TROJAN!
    Microsoft WordXBootSector.exeAdded by a variant of the AGOBOT alias GAOBOT WORM!
    Microsoft Word ProfissionalXcsrss.exeAdded by the Troj/Bancban-DB or Troj/Bancos-DP TROJAN! (Note:) May also be found in the \protect\ or \JavaVM\ folder.
    Microsoft Word ProfissionalXJava Plug In close.exeAdded by the Troj/Banker-EL TROJAN!
    Microsoft Works Calendar RemindersNwkcalrem.exeProduces a pop-up reminder of events scheduled using the MS Works Calendar
    Microsoft Works PortfolioNWksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program.Can be prevented from starting from a setting within Portfolio
    Microsoft Works Update DetectionNwkdetect.exe, WkUFind.exeChecks for updates to MS Works
    Microsoft World ServiceXwinworld.exeAdded by an unidentified IRC worm with backdoor capability!
    Microsoft WxdateXSyswu32.exeAdded by the SPYBOT.HZ WORM!
    Microsoft X UpdateXwuamkoppnp.exeAdded by the W32/RBOT-ANI WORM!
    microsoft xdaemon 2.0Xxdaemon.exeAdded by the DELF.D VIRUS!
    Microsoft XML ServiceXmsxmlx.exe WORM_RBOT.KS
    Microsoft Xp Systems loaderXwinsystem32xp.exeAdded by the W32.KELVIR.W WORM!
    Microsoft Xp Systems loadersXwin32xpsys.exeAdded by the W32.SPYBOT.NYT WORM!
    Microsoft XPSP ProtocolXxp386.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsoft xpsp2Xxpsp2.exeAdded by the W32/Sdbot-YQ Worm!
    Microsoft xpsp2XNetworksystem.exeAdded by a variant of the W32/SDBOT WORM!
    Microsoft's System ModuleXSysmodule.exeAdded by the TROJ/BDOOR-FJ TROJAN!
    Microsoft--UpdatesXsxvhost.exeAdded by a W32/Rbot-FH worm infection
    Microsoft-softwareX****.exe (where * = random char)Added by a variant of the WIN32.RBOT WORM!
    Microsoft-UpdateXwngard.exeAdded by a W32/Rbot-JV worm infection
    Microsoft-UpdatesXsvxhost.exeAdded by the W32/Rbot-CT WORM!
    Microsoft32.exeXMicrosoft32.exeUnidentified worm or trojan
    microsoft420Xmicrosoft420.exeAdded by the MENACE.B (or W32.SOFUNNY) VIRUS!
    Microsoftf DDEs ContDLLXrune.pifAdded by the W32/Rbot-AGF WORM!
    Microsoftf DDEs ContrDLXrunm.pifAdded by the W32/Rbot-AFQ Worm!
    Microsoftf DDEs ControlXlxes.exeAdded by the RBOT.BOF WORM!
    Microsoftf DDEs ControlXwees.exeAdded by a variant of the the RBOT.BOF WORM!
    Microsoftf DDEs ControlXFEnR.exeAdded by the W32/RBOT-AIM WORM!
    Microsoftf DDEs ControlXsoff.pifAdded by the W32/Rbot-AKH WORM!
    Microsoftf DDEs ControlXErun.pifAdded by a variant of the WIN32.RBOT WORM!
    Microsoftf DDEs ControlXwhy-.exeAdded by the W32/Rbot-AMV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Microsoftf DDEs ControlXmsnn.exeAdded by the W32/Rbot-AXT WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MicrosoftkeysdXsystemproc.exeAdded by the W32/FORBOT-BI WORM!
    MicrosoftkeysdXsystemwin32s.exeAdded by the WOOTBOT.CO WORM!
    MicrosoftkeysdXsystemwin32.exeAdded by a variant of the WIN32.RBOT WORM!
    MicrosoftkeysdsXlass32.exeAdded by a variant of the WIN32.RBOT WORM!
    MicrosoftKsXDrivers.batAdded by the Troj/Shutdown-F TROJAN!
    microsoftm eegs cuntrolXloor.pifAdded by a variant of the WIN32.RBOT WORM!
    Microsoftmsn32.exeXmicrosoftmsn32.exeAdded by the TROJ/CERTIF-C TROJAN!
    MicrosoftMultimediaTaskXMmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
    MicrosoftNetwork Daemon for Win32XNETD32.EXEAdded by the RANDEX.F VIRUS!
    MicrosoftOEMXsmvss.exeAdded by the TROJ/DEDLER-G TROJAN!
    Microsofts mediaXwinmplayd.exeAdded by an undidentified WORM or TROJAN!
    Microsofts mediaXwingtp.exeAdded by the W32/RBOT-VO WORM!
    Microsofts MediaScopeXwinmep.exeAdded by the W32/Rbot-WB WORM!
    Microsofts MediaScopeXwinmedplay.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsofts Security ManagerX****.exe [**** = random char]Added by the RBOT-WH TROJAN!
    Microsofts ServiceXlcsrv16.exeAdded by a variant of the WIN32.RBOT WORM!
    Microsofts UpdatesXlsasss.exeAdded by the W32/Rbot-AEX Worm!
    Microsofts UpdatezXcmsssr.exeUnidentified worm or trojan
    Microsofts UpdatezXexploirez.exeAdded by a variant of the WIN32.RBOT WORM!
    MicrosoftServiceManagerXmstask32.exeAdded by the YAHA.P VIRUS!
    MicrosoftServiceManagerXWintsk32.exeAdded by the YAHA.U VIRUS!
    MicrosoftServiceManagerXEXPLORERE.EXEAdded by the YAHA.AB VIRUS!
    MicrosoftServiceManagerXmsupdat.exeAdded by the YAHA.AA VIRUS!
    MicrosoftSourceSafeXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    MicrosoftSysXSPOOLSYS.exeAdded by the PWSteal.Tarno.N TROJAN!
    MicrosoftUpdateXsyshelper.exeAdded by the WOOTBOT.AC WORM!
    MicrosoftUpdateXWinUp32.exeunidentified worm
    MicrosoftUpdatesXsyshelped.exeAdded by a W32/Forbot-AZ worm infection
    MicrosoftUpdatesX(Original Trojan filename)Added by the Troj/Delf-LO TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MicrosoftValueXsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    MicrosoftvirusXsysoverload.exeAdded by the W32/FORBOT-AL WORM!
    MicrosoftWindowsXMagicSearch - a CoolWebSearch parasite variant,
    Microsoftz turn ControlXread.pifAdded by the W32/Rbot-AFS Worm!
    Microsoftz turn ControlXaexl.exeAdded by the SDBOT.BCO WORM!
    Microsoft© PID LexXPIDLex.exeAdded by the NIOVADOOR VIRUS!
    Microsoft« ActiveX Debugger NTXsetdebugnt.exeAdded by the Troj/Bancos-CZ Trojan!
    Microsoft® System MapperXSysMap.exeAdded by the MAPSY VIRUS!
    MicrosongXsvchosts11.exeAdded by the W32/SDBOT-EV WORM!
    Microszoft Update Mach1nezsXsvchst.exeAdded by the W32/RBOT-ED WORM!
    Microzoft_OfizXKdzEregli.exeAdded by the AMUS.A VIRUS!
    Micrsoft CFG 32Xlrbzus32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Micrsoft DriverXwindrive.exeAdded by the BACKDOOR.SDBOT.AF WORM!
    Micrsoft DriverXmsdriver.exeAdded by the W32/SDBOT-XD WORM!
    Micrsoft Internet ExplorerXIEXPL0RE.EXEAdded by the W32/RBOT-AQV WORM!
    Micsorosft Security CenterXwcnsfty.exeAdded by the W32/RBOT-AHU WORM!
    MightyFAX ControllerNMFNTCTL.EXEMighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software"
    MigrationVend or SetupCaller?rundll32.exe migrate.dll, CallVendorSetupDlls??
    MimBootNmimboot.exeStarts Musicmatch_Jukebox at bootup - can be started manually.
    MincerXMincer.exeAdded by the WM97/Minceme-A Worm!
    MINIBUGXMINIBUG.EXEDisplays ads inside Weatherbug - see here
    MINIFERT.EXENMINIFERT.EXEPart of Backweb
    minilogUMINILOG.EXEIf you don't have ZoneAlarm or ZoneAlarm Pro running you don't need this. This must be enabled if programs such as VisualZone Report utility or ZoneLog Analyzer are in use
    MiniMavisNMiniMavis.exeMavis Beacon typing tutor
    minimoX[path to file]Added by the TROJ/MOSUCK-X TROJAN!
    MiniNoteNMININOTE.EXEMini NoteTab was the first in the family of "NoteTab" text and HTML editors from Fookes Software
    Miniphone?glophone.exe VoiceGlo Glophone Voice over Internet Protocol (VOIP) communications software - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" - is it required in startup?
    miniportXusb2chk.exeAdded by the Troj/Lazar-A TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MiniPortRtXminiport_mp.exeMalware - see here
    MiniServer.exeXMiniServer.exeAdded by the Troj/LittleW-E TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    MinMaxExtenderUMmext.exeMinMaxExtender - window handling tool
    Miosf UpdateXwimsqaad.exeAdded by the BACKDOOR.SDBOT.AG WORM!
    Mirabilis ICQNNDetect.exe, icq.exe, ICQNet.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
    Miramar Systems, Inc.Uatmsg.exeMiramar PC/Mac networking software
    Miranda IMNmiranda32.exe Miranda Instant Messaging client
    Mirate Sp 2 InformationXmiratesp2.exeAdded by the RBOT.QH WORM!
    Mircosoft DNS ServiceXsvchost.exeAdded by Troj/IRCBot-AK TROJAN!
    Mircosoft Sockets SP2Xmssck.exeAdded by the MYTOB.ET WORM!
    Mircosoft UpdateXwuampkd.exeAdded by a variant of the W32/SDBOT WORM!
    Mircrosoft Svchost32Xsvchost32.exeAdded by the W32/RBOT-AZW WORM!
    Mircrosoft Windows Config DLLXrundllc32b.exeAdded by the W32/RBOT-ZY WORM!
    miroVIDEO Tray ToolNmisitray.exeTool for quickly changing options for miro/Pinnacle capture cards during capture/playback/output. When this program is closed, another program (mv-ctrl) is also closed, but mv-ctrl does not have its own EXE file. Only needed when using the capture card, e.g. for the above actions
    MirrorFolderShellUmrfshl.exe MirrorFolder backup software
    Mirsoft sdcEXtaskmegr.exeAdded by the W32/Rbot-AWY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    misiCTRL?misiCTRL.exeMiro video driver related. Is it required?
    misiTRAY?misiTRAY.exeMiro video driver related. Is it required?
    MismoXwin32x.exeAdded by the W32/RBOT-JP WORM!
    MixerNMixer.exeC-Media Mixer - C-Media produce audio chipsets that are often found on popular motherboards with on-board audio. Provides System Tray access to change audio settings. Available via Start -> Settings -> Control Panel or Start -> Programs
    MixghostNmixghost.exeManagement software for Altec Lansing speakers.  If a change is needed, the user can launch it from the Start menu
    ml00!.exeXml00!.exeMalware, detected by Panda antivirus as Trj/Downloader.BWD
    ML1HelperStartUpUML1HEL~1.EXE Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    ML1HelperStartUpUML1Helper.exe Midnight_Lake Screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    mloadXlxmstart.exeAdded by an unidentified VIRUS!
    MM Install?setup.exePossibly Money Manager from Moneysoft?
    MMB2Xexplorer.exeAdded by an unidentified WORM or TROJAN - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)
    MMCXinisys.exeAdded by the W32/Oscabot-I Worm!
    mmcndmgrXmmcndmgr.exeunidentified worm or trojan
    MMCWINMGMTNwinmgmt.exeUsed for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
    MMERefresh?MMERefresh.exeRelated to Digidesgin Protools. What does it do and is it required?
    MmessengerXmessenger.exeAdded by the AGOBOT.GM WORM!
    MmgsvcXmmgsvc.exe Spyware.Mmgsvc
    MMhidUmmhid.dllThis is the Human Interface Device Server for Win98, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to Hidserv in Win98SE/2000/Me/XP
    MMHK?mmhk.exeA driver found on a Compaq Presario 800T notebook. Possibly something to do with multimedia hot keys?
    MMHotKeyNMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
    MMKeybdUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
    mmodXmmod.exeeZula TopText adware
    mmptiNm1mmpti.exeMpact Mediaware Properties Taskbar Icon - multimedia software icon for Chromatic Research Mpact video cards
    MMRun?mmrun.exe??
    mmsys?recover.exe?
    MMSystemX"%\Windows%\rundll32.exe "%System%\mmsystem.dll"", RunDll32"Added by a FUNNER.A worm infection
    MMSystemXRunDll32Added by the W32/FUNNER-A WORM!
    MMTASKYmmtask.tskA check on the file\'s properties reveals "Multimedia background task support module". MMTASK is a very simple 16-bit program used by certain multimedia drivers (which are still 16-bit on Win9x) to perform background processing. Some soundcards need this to support MIDI, etc
    mmtaskNmmtask.exePart of MusicMatch Jukebox - digital music player / CD burner and ripper / music organizer / playlist creator
    MMtask ServiceXmmtask.exeAdded by the BACKGAT.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename
    MMTrayNmm_tray.exeMusicMatch Jukebox icon in the task tray - digital music player / CD burner and ripper / music organizer / playlist creator
    MMTrayNMMTray.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    MMTray2KNMMTray2K.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    MMTrayLSINMMTrayLSI.exePart of Morgan Multimedia Codecs. Only required when the codecs are used
    mmusrstp?procrun.exe??
    mmxp2passion.exeXmmxp2passion.exe MediaMotor/Popuppers adware component
    mmxrunXmsosa.exeAdult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and RegCompres (REGCPM32.EXE), otherwise they return
    mmxrunXmswinindex.exeAdded by TwoSeven SPYWARE!
    mnklinsXmnklins.exe Transponder parasite related
    mnpolXmnpol.exeAdded by the DOWNLOADER.DLUCA.B TROJAN!
    MNSUMNS.exe Mobile_Net_Switch enables you to use your computer on more then one network with the click of a button. It allows you to automatically select the correct drive mappings, printer settings, IP settings and much more.
    mnsvcXmnsvc.exeAdded by the AUTOUPDER VIRUS!
    mnsvcspXmnsvcsp.exeVIRUS!
    mobsyncNmobsync.exeMS Syncrhonization Manager - updates the network copy of materials that were edited offline, such as documents, calendars, and e-mail messages
    MOBSYNC32.EXEXmobsync32.exeAdded by the FINERO VIRUS!
    MODNmuamgr.exeMicroAngelo On Display from Impact Software lets you customize Windows icons. With a few exceptions, you can customize icons by right-clicking on them
    ModemXlocatesvc.exeAdded by a variant of the W32.SPYBOT WORM!
    Modem Driverz UpdatesXmdmdrv.exeAdded by a variant of the W32/SDBOT WORM!
    MODEMBTRUMODEMBTR.EXEModem Booster from inKline Global to improve ISP connections
    ModeminfXModeminf.exeAdded by a CRYPTER.C trojan variant infection
    ModemOnHoldUMOH.EXENetWaiting Modem-on-Hold Application
    ModemUtilityNmdmsetpe.exeSystem Tray configuration icon for Aztech modems
    ModularConfigXsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    Module Call initializeXRUNDLL32.EXE reg.dll, ondll_regAdded by a variant of the LOVGATE WORM!
    Modulo 00FE0F01 Host InternetXsyschost.exeAdded by the TROJ/DELF-KW TROJAN!
    MOJNPluginSrIvcsXneomonap23.exeAdded by a variant of the W32/SDBOT WORM!
    Money ExpressNmoneyexpress.exePart of MS Money. Available via Start -> Programs
    MoneyAgentNmoney express.exePart of MS Money. Available via Start -> Programs
    MoneyAgentNmnyexpr.exeMicrosoft Money
    MoneyStartUpNMoney Startup.exeMicrosoft Money
    MoneyStartUp10.0NActivation.exePart of MS Money 2002. Available via Start -> Programs
    monitorXmonitor.exeBrowser hijacker, redirecting to NCM Search
    Monitor Apache ServersUApacheMonitor.exePart of the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start -> Programs
    Monitoring ServiceXsvchost.exeAdded by the CONE.C VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32
    MonitormgtXMonitormgt.exeAdded by the GEMA TROJAN!
    MonitorSDXSDMonitor.exeMax Secure Spyware Detector, bogus "Spyware remover" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "spywaredetector.net"
    Monitor_HelperUmonitor.exe MyLittleSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    MONPluginSrIvcsXn3monap23.exeAdded by a variant of the WIN32.RBOT WORM!
    MonstersoundtrayNFreectrl.exeDiamond Multimedia sound card control panel
    MonTestXvccxzq.exeAdded by the W32/SDBOT-EA WORM!
    MoodBookUmb.exe MoodBook is a free Windows utility that brings art to your desktop
    MoodLogic UpdaterNUpdater.exeRelated to MoodLogic MP3 mix maker
    MoodLogicTVNmtv.exeRelated to MoodLogic MP3 mix maker
    moon phaseNmoon.exeMoon Phase - tray icon that indicates the phases of the moon
    MorpheusNmorpheus.exeMusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free, and a visitor quotes "I have seen no instance of any since using it"
    morphstbXmorphstb.exeAdware downloader - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Stubby.c
    mosearchXmosearch.exeFast Search in Office XP - similar to the new revision of the Find Fast feature in Office 2000. Fast Search uses the Indexing Services in Office XP to create a catalog of Office files on your computer's hard disk. As with Find Fast - a waste of resources. If it can't be disabled via MSCONFIG try here
    Motherboard ConfigXAti2xxx.exeAdded by the W32/RBOT-AIK WORM!
    MotherBoard SoundsXSounds.exeAdded by the W32/RBOT-AAP WORM!
    Motive SmartBridgeNmpbtn.exeSystem tray icon for the Virtual Assistant from AT&T Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    Motive SmartBridgeNMotiveSB.exeSystem tray icon for the Virtual Assistant from AT&T_Broadband , used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    Motive SmartBridgeNBTHelpNotifier.exeSystem tray icon for the Virtual Assistant from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start -> Programs - not required
    MotiveMonitorUmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required
    MotiveSBNMotiveSB.exeThe same as Motive SmartBridge below
    MotMonUmotmon.exeFound on HP/Dell and Compaq systems (and maybe others). MotiveMonitor is used the suppliers on-line support and allows the agent at the far end to do harddrive/ram/video/etc tests on the computer. Can cause some users problems with IE and Netscape by disabling this - in this case leave it to run. You may also wish to leave it alone if the PC is still within the support period from the manufcaturer. For most users it\'s not required
    motoinXmm15201518.Stub.exe Delfin_Promulgate adware variant
    Mount Safe & SoundUFbmount.exeFrom McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
    mouseXmouse.exeAdded by the W32/Rbot-AHJ WORM!
    Mouse 32ANMouse32A.exeMouse driver to control mouse functions from Azona. Available via Start -> Programs
    Mouse Suite 98 DaemonNpelmiced.exeMouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    Mouse Suite 98 DaemonNICO.EXEFound on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
    mousebutXmousebut.exeAdded by a CRYPTER.A trojan infection
    MousecntlXmousecntl.exeAdded by a Crypter.C trojan variant infection
    MouseCountNMC.exeMouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required
    mousedrvXmousedrv.exeAdded by a CRYPTER.A trojan infection
    MouseDrvXupdate.exeAdded by the ZOTOB.N WORM!
    MouseDrvX(Path to the worm file)Added by the W32/Zoload-B WORM!
    mouseElfUMC.exeSystem Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
    mouseElfUgnetmous.exe Genius_NetScroll mouse driver - required if you use non-standard Windows driver features
    mouseElfUmouseElf.exeSystem Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
    MouseImpUMImpHost.exeMouseImp Pro - "A reliable assistant that turns your mouse into a simple, native but powerful controlling device"
    MousinfoUmousinfo.exeMS mouse information tool - for troubleshooting mouse problems
    MoveSearchXSearch.exe PigSearch adware
    Movielink Manager UninstallNmsvcmm32.exeAuto-update for Movielink - internet movie rental System Tray access
    MovieNetworksXMovieNetworks.exeMovieNetworks will connect you by DOMESTIC PREMIUM RATE TELEPHONE NUMBER 900-xxx-xxxx. So you get xxx rated pictures and junk. And it will allow you to stay on the internet on their line and $$$ and remove the C:\Program Files\MovieNetworks directory
    MovieplaceXMovieplace.exeMoviePlace malware
    Mozila FirefoxXfirebox.exeAdded by the W32/RBOT-AIP WORM!
    Mozilla FirefoxXF1REF0X.EXEAdded by a variant of the W32/SDBOT WORM!
    Mozilla Quick LaunchNNetscp6.exeMozilla.exeNetscape 6 and Mozilla browsers
    MP TcloaxsXmptcloaxs.exeAdded by the RANDEX.CT VIRUS!
    Mp3 LoaderXSysdata.EXE /SAdded by the W32/Avette-A VIRUS!
    MP3downloadXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    MPEOUCsinsm32.exeAutomatic logging of installs from Norton CleanSweep - available via Start -> Programs
    MPFExeYmpf.exeMcAfee Personal Firewall
    MPFExeYMpfTray.exeMcAfee Personal Firewall
    MPFExeXmcagent.exeAdded by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
    MPL32 driverXMPL32.exeAdded by a Loony-M trojan infection
    MplSetupUMplSetup.exeUsed by Ricoh network printers to enable network printing from the client
    MPM ManagerXMPM.exeAdded by the DONBOMB.A TROJAN!
    MPowerUMPower.exeMPower from MindBeat. "Defragments and frees your RAM giving more stability to your system and avoiding needless use of swap file. Willl also benchmark (speed test) your hard disk drives and your CPU load". Some users swear by programs such as this but I suggest you read this article and make up your own mind
    MPR MSGXmprmsg32.exeAdded by the W32.MYTOB.CF WORM!
    MPREXEXMPREXE.EXEAdded by the OPASERV.T VIRUS! Note - this is not the legitimate Mprexe.exe system file
    MPREXE.exeYmprexe.exeWIN32 Network Service Interface Process. MPREXE.exe enables the computer to have multiple clients/protocols for networks. There are some problems with it sometimes though - see here and here. Note - why some people have it listed in start-up programs I don\'t know but I was asked to include it here. It automatically runs in the background. NOTE : sometimes it will appear in start-ups if you have a virus
    MprHTMLXMprHTML.exeAdded by a variant of the VAGRNOCKER VIRUS!
    mprocessorXmprocessor.exeInstallDollars.com foistware
    MPSExeUmscifapp.exeMcAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
    MpsOnnYMpsOnn.exeCanon printer driver
    MPT?MPT.exe??
    MPtask ServicesXmptask.exeAdded by the LALA or DOWNLOADER-BN.B or AOT VIRUSES!
    MPTBoxNMPTBOX.EXECannon Multi-Pass toolbox - a button bar
    mptsgsvc.exeXmptsgsvc.exe Hacker_Tool - detected by TDS-3 antitrojan as "HackTool.Win32.Hidd.j"
    MPXTrayNmpxptray.exeWindows Media Player PowerToy which is run from the taskbar. It can be used to hide Windows Media Player (when in use) and choose various standard buttons (play/pause, next,previous) etc
    MP_STATUS_MONITORUmonitr32.exeCannon Multi-Pass status monitor - your choice.
    mqbkupXmqbkup.exeAdded by the OPASERV.K VIRUS!
    mrtMngrNmrtMngr.exeMaintenance Release Task Manager for Intuit’s QuickBooks or Quicken
    MRU-Blaster SchedulerUscheduler.exeMRU-Blaster scheduler - detects and cleans MRU (most recently used) lists on your computer
    MRU-Blaster Silent CleanNmrublaster.exeMRU-Blaster - performs silent cleaning of MRU lists at boot
    MRUBlasterUindexcleaner.exe MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder
    MS Auto-IPSec ProtectionXMSASP32.exeAdded by the W32/Rbot-AER Worm!
    MS Autoloader 32XMSAuto32.exeAdded by the SPYBOT.BD WORM!
    Ms BuildersXWupated.exeAdded by the W32/AGOBOT-SS WORM!
    MS Config LoaderXsvchos1.exeAdded by the AGOBOT.R WORM!
    MS Config LoaderXMSWin32bck.exeAdded by the GAOBOT.AA WORM!
    MS Config LoaderXsvcrhost.exeAdded by a variant of the WIN32.RBOT WORM!
    MS Config ServiceXMsloader32.exeAdded by the W32/Rbot-KJ WORM!
    MS Config v13Xlrbz32.exeAdded by the W32.GAOBOT.AOL WORM!
    MS ConfigurationXMSFramer.exeAdded by the RANDEX.OL VIRUS!
    Ms ConfigurationXmicrosoftsa32.exeAdded by the W32.KELVIR.X WORM!
    MS DATABASEXMSDATA32.EXEAdded by a variant of the W32/SDBOT WORM!
    MS Decryption SoftwareXactive.exe MediaTickets adware variant
    MS DVD DirectX Dll DriversXmdxdl.exeAdded by the W32/SDBOT-XI WORM!
    MS DVD DirectX Sound DriversXmsdrvdx.exeAdded by the W32/SDBOT-XJ WORM!
    MS ExplorerXmexplore.exeAdded by the YAHA.AE VIRUS!
    MS FIREWALLXmsfrewall.exeAdded by the W32/SDBOT-PU WORM!
    MS FIREWALLXmsfirewall.exeAdded by the W32/SDBOT-QH WORM!
    MS HTMLXmsHtml.exeAdded by the PESTDOOR.31 VIRUS!
    MS HTMLXmslat.exeAdded by the LATINUS.SVR VIRUS!
    MS HTML Location ClassXMSHTML32.exeAdded by the W32/RBOT-YD WORM!
    MS Internet Executor 32XMSIXEC32.exeAdded by the W32/Rbot-AEQ Worm!
    MS lsass StartupXlsass135.exeAdded by the RBOT.WM WORM!
    MS lsass6 StartupXlsass1356.exeAdded by a variant of the W32/SDBOT WORM!
    MS management console?mms.exeSuspicious as the Microsoft Management Console is "mmc.exe" and doesn\'t normally run at startup
    MS Microsoft Socket DeamonXMSSCKD32.exeAdded by a variant of the WIN32.RBOT WORM!
    MS MSN Menssenger 7.0XMSMSN7.exeAdded by the W32/RBOT-ACA WORM!
    MS MSN Menssenger 7.0XMSEXPORT.exeAdded by a variant of the W32/SDBOT WORM!
    MS Network ControlXmswin.exeAdded by the DUMBA VIRUS!
    ms ownageXwinPE.exeAdded by the W32/Rbot-AJL WORM!
    MS PLUS INCXwpad.exeAdded by the W32/MYTOB-AN WORM!
    Ms Processe ManagerXmsproc.exeAdded by the RBOT.ATO WORM!
    MS Real PlayerXRealPlyr.exeAdded by the RBOT.MR WORM!
    MS Registry ServiceXMSRMS32.exeAdded by the W32/Rbot-AKP WORM!
    MS Remote Procedure CallXmsrpc32.exeAdded by the W32/RBOT-QL WORM!
    MS Screen SaverXscrsave.scrAdded by the W32/Rbot-AGT WORM!
    MS SecurityXsystm.pifAdded by the W32/Rbot-AQN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS Security Authority ServiceXlsass.exeAdded by the W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    MS Security HotfixXservice5.exeAdded by the GAOBOT.AG WORM!
    MS serviceXmsservice.exeAdded by the W32/RBOT-ZG WORM!
    MS Sound Config 16bitXsndcfg16.exe SdBot.MB backdoor trojan
    Ms Sound DriversXmsdrv.exeAdded by the W32/SDBOT-WR WORM!
    Ms Spool32XMS SPOOL32.EXEAdded by the ASASSIN VIRUS!
    MS SyS RestoreXsysrestore.exeAdded by the RBOT.XM WORM!
    MS Sys SecurityXmswin.pifAdded by the W32/Rbot-APJ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS System SecurityXmswin32.pifAdded by the W32/Rbot-AOX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Ms task managerXtskmgr.exeAdded by the SDBOT.CCD WORM!
    MS taskbarXnts.exeAdded by the W32/RBOT-AGB WORM!
    MS taskbarXcrssr.exeAdded by the W32/Rbot-AGO WORM!
    MS taskbarXtaskbars.exeAdded by the RBOT.BRW WORM!
    MS TaskbarsXtaskbars.exeAdded by the W32/Sdbot-ACV WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MS taskmanagerXtskmgr.exeAdded by the W32/Rbot-AKA WORM!
    MS UniXXnavupdate64.exeAdded by a variant of the WIN32.RBOT WORM!
    MS Unix BinaryXwin32ttb.exeAdded by the SPYBOT.OQ WORM!
    MS Unix BinaryXmsnupdate.exeAdded by the W32/RBOT-AAM WORM!
    MS Unix BinaryXoutlookexpressupdate.exeAdded by the W32/RBOT-YU WORM!
    MS Unix BinaryXmsmq2inst.exeAdded by the W32/RBOT-YF WORM!
    MS Unix BinaryXWin32Update.exeAdded by the W32/RBOT-BAS WORM!
    MS Unix BinaryXNorton2005Update.exeAdded by a variant of the WIN32.RBOT WORM!
    MS Unix BinaryXtrmupdate.exeAdded by the W32/RBOT-ACC WORM!
    MS Unix BinaryXWinGuard.exeAdded by the W32/RBOT-ACL WORM!
    MS Unix BinaryXmsnq3insller.exeAdded by a variant of the WIN32.RBOT WORM!
    MS UpdateXsyshost.exeAdded by a W32/Evaman-F worm infection
    MS UpdatesXmscache.exeSpyware web downloader
    MS UpdatesXsyshosts.exeAdded by the W32.Mydoom.Y WORM!
    MS UpdatesXaupd.exeSpyware web downloader
    MS Updating UtilityXmsupdater.exeAdded by the W32/RBOT-XR WORM!
    MS USB 2.0 Windows SupportXmsusb32.exeAdded by a variant of the WIN32.RBOT WORM!
    Ms Valud LoaderXSvhots.exeAdded by the W32/AGOBOT-SP WORM!
    ms window updateX******.exe (* = random character)Added by a variant of the WIN32.RBOT WORM!
    MS Windows AOL DriverXMSAOLdrv.exeAdded by the W32/Rbot-ASP WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS windows Data list processXMSDATLST.exeAdded by an unidentified WORM or TROJAN!
    MS Windows procces 32Xmsprocces.exeAdded by the W32/Rbot-AEZ Worm!
    MS Windows Process ClassXMSPRCSS32.exeAdded by the W32/RBOT-YQ WORM!
    MS Windows Process InitXMSWPI32.exeAdded by the W32/Rbot-ASQ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS Windows Security UpdaterXupdater.pifAdded by the W32/RBOT-AKY WORM!
    MS Windows UpdateXscguard.exeAdded by the W32/RBOT-YZ WORM!
    MS WINS BinaryXign32.pifAdded by the W32/Rbot-ASB WORM! This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ms************* ( * = random digit)Xms*************.exe ( * = random digit) WINBO adware component
    Ms**.exe (* = random char)XMs**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Ms**32.exe (* = random char)XMs**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    MS-ConnectXarr.execdm.exegame.exemsite18.exeweb.exeAdult content dialler - see here
    MS-DOS Boot ServiceXBoot32.pifAdded by the W32/Rbot-AMF WORM!
    MS-DOS Boot ServiceX boot32.pifAdded by a variant of the WIN32.RBOT WORM!
    MS-DOS Security ServiceXms-dos.pifAdded by the W32/Rbot-AMR WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MS-DOS ServiceXMS-DOS.pifAdded by the W32/Rbot-AII WORM!
    MS-DOS Windows ServiceXMS-DOS.PIFAdded by the W32/Rbot-AJW WORM!
    MS-HTMLX(random filename)Added by the LATINUS.15 VIRUS!
    MS-patchXmsconfig32.exeAdded by the W32/Rbot-AUF WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS-patchXmspatch32.exeAdded by the W32/Rbot-AWF TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MS-RunKeyXarr.exeMS-Connect dialler/hijacker
    ms64.exeXms64.exeAdded by a variant of the WIN32.RBOT WORM!
    MS7531Xms7531.exeHomepage hijacker
    MSACMXmsacm.exeAdded by a W32/Opaserv-O worm infection
    msadcheckXmsadcheck32.exeBrowser hijacker, redirecting to search-system.com
    MSAdminXjdbgmrg.exeAdded by the DASMIN.A VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here
    msadp32Xmsadp32.exeAdded by a Octa-B trojan infection
    MSAgentXmshtm.exeBrowser hijacker, redirecting to buldog-search.com
    MSAgentXhhnt.exeAdded by the TSPY_AGENT.JI spyware
    MSAgentXPXMSAgentXP.exeReported by Ewido_Security_Suite as TrojanDownloader.Reqlook.c
    msaimUmsaolim.exe MessageSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    msappts32Xmsappts32.exeAdded by the Troj/Elburro-A TROJAN! Note: This trojan file is found in the Windows\msapps\msinfo or Winnt\msapps\msinfo folder.
    MSBBXmsbb.exe nCase adware
    Msbb.exeXmsbb.exe nCase adware
    msbcsXmsbcs.exeAdded by the Troj/Dadobra-G TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MsBootMgr.exeXMsBootMgr.exeAdded by the BACKDOOR.VERIFY TROJAN!
    msbscX(Path to Trojan)Added by the Troj/Banker-DF Trojan!
    MSChoExEXsuge.exeAdded by a variant of the Win32.Rbot WORM!
    msci?mcinfo.exeMcAfee Internet Security related. What does it do and is it required?
    mscleanXmsvchost.exeAdded by the W32/Opanki-Q TROJAN!
    mscmanXmscman.exeSpyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK, "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
    mscnUmscn.exePart of the SafeChildNet internet filtering program - required if you use it
    MscntXmscnt.exeAdded by the Troj/Dluca-C TROJAN!
    MscolourXmscolour.exeAdded by the WIN32.GEMA TROJAN!
    MSCommXXmscommx.exe Win32.Rbot worm variant
    MSCONFG32.EXEXMSCONFG32.EXEAdded by the OPTIX.04.C VIRUS!
    MSCONFG32.EXEXMSCONFG32.EXEAdded by the OPTIX.04.C VIRUS!
    MSConfigNMSCONFIG32.EXEUnidentified adware, spyware or virus
    msconfigXmsconfig.exe CoolWebSearch parasite related. **Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting
    msconfigXwins.exeAdded by the RBOT.PF WORM!
    MSConfigXMSCONFIG35.EXEAdded by a variant of the W32.SPYBOT WORM!
    Msconfig lptt01 or Msconfig ml097eXmsconfig.exeVariant of the RapidBlaster parasite (in a "msconfig" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Windows Msconfig which has the same executable name
    MSConfig ManagerXmsupdate.exe CoolWebSearch parasite related,
    MSConfig or MSConfigReminderNmsconfig.exeThis is an entry that appears when you uncheck an item in the Startup group, and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode
    msconfig serviceXMSupdate32.exe W32.SpyBot worm variant
    msconfig.exeXuline.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    msconfig.exeXproxy.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    MSConfig45XMSConfig45.exeAdded by the SDBOT.OJ WORM!
    MSConfigrXjdbgmrg.exeAdded by the DASMIN.C VIRUS! Note - this is not the valid JDBGMGR.EXE file - see here
    MsConfigsXMsConfigs.exeAdded by the ALCAN.A WORM!
    MSControl28Xcrsss.exeAdded by the SPYBOT.AJX WORM!
    MSControl31Xwinnsyst.exeAdded by the RBOT.CFY WORM!
    MSControl3d1Xisasse.exeAdded by the RBOT.CGU WORM!
    MSCOREXsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    MscsgsXMSCSGS.EXEAdded by the ZEZER VIRUS!
    Mscsgs32XMSCSGS32.EXEAdded by the ZEZER VIRUS!
    mscsvc.exeXmscsvc.exeAdded by the PWSTEAL.BANCOS.T and Troj/Banker-CK TROJANS!
    Msctrl32XMsctrl32.scrAdded by the REDIST VIRUS!
    MSCVTXMSCVT.exeAdded by the SLIDESHOW VIRUS!
    MSDcomXMSDcom.exeAdded by a variant of the W32/SDBOT WORM!
    msdevXmsdev.exeAdded by the FORBOT-CR WORM!
    msdevXmsconfig.exeAdded by the AGOBOT.AAU WORM! - Note, this is NOT the legitimate Windows System Configuration Utility as described here
    msdirect.exeXmsdirect.exeAdded by the Troj/Certif-L TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSDLLXsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    MsdmxmXmsdmxm.exeAdded by the Troj/Dload-DC TROJAN!
    MSDNXnese.exeAdded by the SDBOT.AHY WORM!
    MSDN HELPXmsdn.exeAdded by the AGOBOT.AIB WORM!
    MSDOS Security ServiceXmsdos.pifAdded by the W32/Rbot-AMP WORM!
    MSDOS ServiceXMSDOS.PIFAdded by the W32/RBOT-AIY WORM!
    MSDOS Windows ServiceXMSDOS.PIFAdded by the W32/Rbot-AKF WORM!
    Msdos32XMsdos32.pifAdded by the RECORY VIRUS!
    msdos423Xmsdos423.exeAdded by the MENACE.A (or W95.SOFUNNY.WORM@M) VIRUS!
    MSDTCNmsdtc.exeMS Distributed Transaction Coordinator - handles transactions across multiple servers and is installed by MS Personal Web Server and MS SQL Server
    Msemu32XMsemu32.exeUnidentified spyware/adware/hijacker
    mservices.exeXmservices.exeAdded by the SDBOT.WJ WORM!
    MsfindXMsfind.exe CoolWebSearch parasite related.
    MSFind32Xmsfind32.exeAdded by the CAYAM VIRUS!
    msfindosa.exeXmsfindosa.exeAdded by the DOWNLOADER-BS VIRUS!
    MSFTP Service ConfigXr3grun.exeAdded by a variant of the W32/SDBOT WORM!
    MSFWAVTSMXFTPDev.exeAdded by the W32/RBOT-ACF WORM!
    Msg FixageXmsgfixed.exeAdded by the SDBOT.ZD WORM!
    MsgApiX(path to file)Added by a Dedler-D trojan infection
    msgb1Xmsgb1.exeAdded by a Win32.Dluca.gen trojan infection
    MsgCenterExeNRealOneMessageCenter.exeRealNetworks RealPlayer related - disabling this application will not affect Real Player in any way.
    msgex32Xmsgex32.exeAdded by the W32/APPFLET-A WORM!
    MsgmgrX(path to worm)Added by the BABYBEAR VIRUS!
    msgserv_XSyss.exeAdded by the FANTA TROJAN!
    msgsm32Xmsgsm32.exeAdded by the W32/Rbot-ASG WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Msgsrv16XMsgsrv16.exeAdded by the DELF family of VIRUSES!
    MSGSRV32.exeYmsgsrv32.exeWindows 32-bit VxD Message Server. For more information on its function and why it's needed, see here. Note - why some people have it listed in start-up programs I don't know but I was asked to include it here. It automatically runs in the background
    MsgSvcMgr32Xcmdzxdll.exeAdded by the W32/Rbot-AEK Worm!
    msgsvr32Xmsgsvr32.exeAdded as the result of the DEADHAT.B VIRUS! Note - not to be confused with the valid "msgsrv32.exe" file which resides in the same directory (C:\Windows\System) on a Win9x/Me machine
    MSGTAGUMSGTAG.exe MSGTAG is an application that tells you when your emails have been received and opened.
    MsgtrayXsys16.exeAdded by an unknown VIRUS!
    Mshelp32Xmshelp32.exeAdded by a CoolWebSearch parasite variant
    MSHT@XMSHT@.EXEAdded by the MAGISTR.A VIRUS!
    msidentXmsident.exeUnidentified adware or trojan
    msidleXmsidle.exeAdded by a W32/Opaserv-O worm infection
    MsIdle32.exeXMsIdle32.exeAdded by the BACKDOOR.VERIFY TROJAN!
    MSIdllXwinmp.exeAdded by a variant of the WIN32.RBOT WORM!
    MSIE ParsersXMSIE32ab.exeAdded by the SDBOT.MV WORM!
    msiewXmseiw.exeAdded by the LITTLOG TROJAN!
    MSIEXECXMSIEXEC32.exeAdded by the AINESEY.A VIRUS!
    MSIEXECXMSIEXEC.EXEAdded by the VBS/YOSENIO-A VIRUS!
    MSIMN32XMSIMN32.EXEHijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx
    MSIN?MSin.exe??
    MsinetXMsinet.exeAdded by the W32/Rbot-AOA WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MSInfoXmsinfo.exeAdded by the ALADINZ.M VIRUS!
    MSInfoXAVBgle.exeAdded by the W32.NETSKY.O WORM!
    MSInstallXsmvss.exeAdded by the TROJ/DEDLER-G TROJAN!
    msjava serviceXxpcd.exeAdded by a SDBOT.VM worm infection
    MSKAGENTEXEUMskAgent.exePart of McAfee Spamkiller
    MSKCES32X(random filename)Added by the CLONER VIRUS!
    MSKDetectorExeUMSKDetct.exePart of McAfee Spamkiller
    MSKernel32XMSKernel32.vbsAdded by the LOVELETTER (I LOVE YOU) VIRUS!
    MSkernel32XSystem.exe 4820Added by the TUXDER VIRUS!
    MSKExeUspamkiller.exeMcAfee SpamKiller
    mskjXmskj.exeAdded by the Kaemon TROJAN!
    MSKServerExeUMSKSrvr.exePart of McAfee Spamkiller
    mslagentXmslagent.exeAdded by the Troj/Wintrim-F TROJAN!
    MSLARISSAXMSLARISSA.pifAdded by the ASSIRAL.B WORM!
    MSLIB32?mswatch32.exe??
    MSLogXMicrosoftLog.exeAdded by a variant of the W32/SDBOT WORM!
    Mslogon lptt01 or Mslogon ml097eXmslogon.exeVariant of the RapidBlaster parasite (in a "Mslogon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    MsManagerXmsmgr32.exeAdded by the YAHA.AF VIRUS!
    msmanager32Xmsmngr32.exeAdded by the RANDON-R (or WOMANIZ.A) VIRUS!
    msmautoprotectXmsmssgs.exeAdded by the TROJ/BIFROSE-AJ TROJAN!
    msmcXmscpbo.exeClientMan parasite variant
    msmcX ms****.exe (* = random char) ClientMan parasite variant
    msmcXmsmc.exe ClientMan parasite variant
    MSMcAfeeeXAvsynmgr32e.exeAdded by the FRAMAR VIRUS!
    MSMcAfeehXAvsynmgr32h.exeAdded by the FRANGO VIRUS!
    MSMcAfeeSXAvsynmgr32S.exeAdded by the VOLAC or VOLAC.DR VIRUSES!
    MSMessngerXmsnupd.exeAdded by the W32/Rbot-ADY Worm!
    msmgr?msmgr.exe??
    msMGRXrtkmsg.exeAdded by the W32/SDBOT-BPY WORM!
    MsmgtXmsmgt.exeTotal Velocity adware/hijacker
    MSMNTJBEXMSMNTJBE.EXEAdded by the Troj/Bancos-EF TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MSMNTJNGXMSMNTJNG.EXEAdded by the Troj/Graber-G TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MSMNTMTSXMSMNTMTS.EXEAdded by the TROJ/BANKER-GZ TROJAN!
    msmonXmsmon.exeAdded by a variant of the Win32.GEMA.D TROJAN!
    MsMoviesXMsMovies.exeMalware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h
    MsmqIntCert?regsvr32 /s mqrt.dllMicrosoft Message Queue Server - Internal Certificate - see here for more info and here for a potential problem. Is it required?
    MSMSGSUmsmsgs.exeWindows Messenger utility. If you don\'t use Windows Messenger, this can be annoying. Available via Start -> Programs. Go to Windows Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
    MsMsgSrvXmsmsgsrv.exeAdded by the BACKDOOR-CQO TROJAN!
    MSMsgSvcXMSMSGSVC.exeBrowser hijacker, identified by some antiviruses as a variant of the StartPage.QC TROJAN!
    msmsngrXmsmsngr.exeAdded by the W32/DOPBOT-B WORM!
    msnXsystem32.exeAdded by the KITRO.A VIRUS!
    msnXmsnmsg.exe W32/Rbot-GO worm
    MSNXmsnmsgs.exeAdded by a W32/Rbot-KL worm infection
    MSNXmsnmesengers.exeAdded by a W32/Rbot-ME worm infection
    MSNXctfmoons.exeAdded by the SPYBOT.HI WORM!
    MSNXmsnmesengers.exeAdded by the RBOT-ME WORM!
    MSNXmsnmsgr.exeAdded by the W32.Mytob or W32.Mytob.B WORM! **Note - this is not the valid MSN_Messenger utility
    msnXmsnsvc.exeAdded by a variant of the W32/SDBOT WORM!
    MSNXmsn16.exeAdded by the W32/SDBOT-VN WORM!
    MSNXmsnsgr.exeAdded by an unidentified WORM or TROJAN!
    MSN 9.0 PlusX(Random letters).exeAdded by the W32/Rbot-ALY WORM!
    MSN Administration For Windowsmsnadp32.exeAdded by the BROPIA.W WORM!
    MSN angXcssrss.exeAdded by the W32/FORBOT-CE WORM!
    MSN BETAXservice.exeAdded by the RBOT.AUU WORM!
    Msn ConfigXmsngf.exeAdded by the W32/RBOT-QG WORM!
    Msn Configuration LoaderXmsngms.exeAdded by the W32.KELVIR.T WORM!
    MSN Funny ImagesXimsngsr.exeAdded by the W32/Agobot-TT WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN Internet AccessNtrayclnt.exeQuick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards
    MSN ManagerXcvss.exe W32.SpyBot worm variant
    MSN ManagerXmscmgr.exeUnidentified malware - causes multiple browser windows to open
    MSN Message Background loaderXmsnmesg.exeAdded by a variant of the WIN32.RBOT WORM! Note: File name may be different with some of the other variants.
    MSN MessagesXmsnmesg.exeAdded by the W32/RBOT-ACN WORM!
    MSN MessangerXmsnmsng.exeAdded by a SDBOT.XN worm infection
    Msn MessengXwindns.exeAdded by a variant of the WIN32.RBOT WORM!
    Msn MessengeXIExplorer.exeAdded by the Troj/Delf-LL TROJAN! Note: This is not the legitimate Windows process Iexplore.exe or explorer.exe (Notice the difference in the spelling). This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN messengerXmessenger.exeUnidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread
    Msn MessengerXmsnmsgs.exeAdded by the TROJ/LOONY-P TROJAN or the W32.MYTOB.AD WORM! - NOTE: not to be confused with msmsgs.exe, the well known MSN Instant Messaging application!
    MSN MessengerXReosmsngr.exeAdded by a variant of the W32.SPYBOT WORM!
    MSN MessengerXmsnmsgr.exeAdded by the AGOBOT.AOQ WORM! - Note - this is not the valid MSN Messenger utility as described here
    MSN MESSENGERXmsmmsgr.exeAdded by the W32.KELVIR.Q WORM!
    MSN MessengerXmsmsgs.exeAdded by the TROJ/DLOADER-LN or ZLOB-C and Troj/ZlobDrop-C TROJANS! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!
    MSN MessengerXmsmsgs.exeAdded by the Zhopa TROJAN!
    MSN MessengerXmsnmsngr.exeAdded by a variant of the WIN32.RBOT WORM!
    MSN MessengerXIExplorer.exeAdded by the Troj/Banker-EU TROJAN!
    MSN MessengerXPIC1324(1)(1)(3).exeAdded by the W32/CHOKE.C WORM!
    Msn MessengerXmsnmsnr.exe Troj/Banker-GG is a keylogging TROJAN! NOTE - This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN Messenger 32Xmsniu.exeAdded by the W32/Rbot-AWB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN Messenger 323Xmsniu3.exeAdded by the W32/Rbot-AXB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN Messenger 6.2Xtyd.exeAdded by a variant of the WIN32.RBOT WORM!
    MSN messenger serviceXmssgs.exeUnidentified trojan VIRUS!. Note - this is not the real MSN Messenger, see this thread
    MSN Messenger Service StarterXmsnmgsr.exeAdded by the W32/Rbot-AOS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Msn Messenger UpdateXmsnupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    MSN Messenger User ControlsXmsmsgr.exeAdded by the W32.Kelvir.HI WORM!
    Msn MessengersXMSNMSGR.EXEAdded by a RBOT.KX worm infection
    MSN MMISSENGERXmssmmspgr.exeAdded by the W32.KELVIR.AJ WORM!
    Msn PatchXmsndp.exeAdded by the RBOT.AAI WORM!
    Msn PatchesXmsndr.exeAdded by a variant of the W32/SDBOT WORM!
    Msn Plus UpdaterXmsnplus.exeAdded by the W32/RBOT-MU WORM!
    Msn Processe ManagerXmsni32.exeAdded by the W32/Rbot-ADX Worm!
    MSN Quick ViewNMsndc.exeQuick way to connect to MSN internet service
    MSN Registry loaderXmsmnwin.exeAdded by the W32.Kelvir.FK WORM!
    MSN serviceXmsnmgr16.exeAdded by a variant of the WIN32.RBOT WORM!
    MSN serviceXNTDKRN.EXEAdded by the RBOT.UJ WORM!
    Msn ServiceXmatrixcam.exeAdded by the MYTOB.JH WORM!
    Msn ServiceXraloded.exeAdded by the W32/Mytob-DY WORM!
    MSN ServiceXamsnmsgrs.exeAdded by a variant of the W32/SDBOT WORM!
    MSN serviceXmsnmsgr16.exeAdded by the W32/Rbot-RZ WORM! Note: This worm has nothing to do with MSN and this worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSN StartXmsnmsgr7.exeAdded by the W32/RBOT-PH WORM!
    MSN UpdateXmsn32.exeAdded by the RBOT.AHN WORM!
    Msn Update Manager (Sp2)XMSMSGS.EXEAdded by the W32/AGOBOT-NL WORM!
    Msn Update ServiceXuserx.exeAdded by the W32.Mytob.JF WORM!
    MSN UpdaterXmsnms.exeAdded by the FORBOT-CG WORM!
    Msn UpdaterXmsnplugins.exeAdded by the W32/RBOT-HS WORM!
    Msn UpdaterXwindatemanager.exeAdded by the SDBOT.TS WORM!
    MSN UPDATERSXvirtualmemory.exeAdded by a Rbot-JK worm infection
    MSN UpdatesXspoolsv32.exeAdded by a variant of the WIN32.RBOT WORM!
    msn.exeXson.exeAdded by the Troj/StartPa-GS TROJAN!
    MSN32 X ServiceXMSN32x.EXEAdded by an unidentified WORM!
    MSN8m StartupXmsn8m.exeAdded by a variant of the WIN32.RBOT WORM!
    msnager32Xsvchostt.exeAdded by the WOMANIZ.E TROJAN!
    msnappauNmsnappau.exeUpdater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to "update" the toolbar
    MsnarratorXmsnarrator.exeAdded by the NARAT.A VIRUS! - also identified as MPGCOM Toolbar adware
    MSNavWHXMSWkwrH.exeAdded by the W32/ANAV-A WORM!
    MSNETXmsnet.exeAdded by the BOA VIRUS!
    MsnExplorerXwinagent.exeAdded by the TROJ/BDOOR-EQ TROJAN!
    MsnExplorerXMSEXPLOREN.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    MsnExplorerXSHCH.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    MsnExplorerXSVCHST.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    MsnFixer?msnfixjs.jsLocated in the HP\bin\msnfix directory of a HP PC
    MSNGrabberXMSNgrabber.exeAdded by the W32.ENVID.A WORM!
    msngta32Xmsngta32.exeAdded by a variant of the WIN32.RBOT WORM!
    MSNIANMSNIASVC.EXEAdded with MSN version 9. Resets certain internet settings upon bootup and can\'t be disabled via MSCONFIG
    msnload32.exeXmsnload32.exeAdded by the BANCOS.M TROJAN!
    MSNMESENGERXMain.exeAdded by the PRORAT VIRUS!
    msnmsgXasgag.exeAdware trojan - probably CoolWebSearch parasite related.
    msnmsgXTBC.exeAdded by an unidentified TROJAN!
    msnmsg.exeXmscmd32.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    msnmsgq32Xmsnmsgq.exeAdded by the WIN32.TACTSLAY.H TROJAN!
    msnmsgrNmsnmsgr.exeMSN Messenger utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger > Tools > Options > Preferences and uncheck "Run this program when Windows starts"
    MsnMsgrXMsnMsgrs.exeAdded by the W32/NETSKY-AN WORM!
    msnmsgr32-.exeXmsnmsgr-.exe W32.SpyBot worm variant
    MSNMSGR5XMSNMSGR5.exeAdded by a RBOT.PQ worm infection
    MSNMSGREXswef.batIRC worm or backdoor trojan!
    MSNMSGREXswef.batIRC worm or backdoor trojan!
    MSNMSGRRXswin.batIRC backdoor trojan or worm!
    MSNMSGRSXswe.batIRC worm or backdoor trojan!
    MSNMSGRSXswiss.batIRC worm or backdoor trojan!
    MSNMSGRS1Xswed.batIRC worm or backdoor trojan!
    msnmsgs.exeXmsnmsgs.exeAdded by the Troj/Banker-HK TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    msnmsgsgsXmsnmsgsgs.exeAdded by the "Catal" alias Spy.Delitall.B backdoor TROJAN!
    msnmsgyX[path to file]Added by the TROJ/BANKER-EQ TROJAN!
    MSNPluginSrIvcsXn3vasap23.exeAdded by a variant of the WIN32.RBOT WORM!
    MSNPluginSrvcsXp6.exeAdded by the SDBOT.AKJ or W32/Rbot-VJ WORM!
    MSNPluginSrvcsXsagate.exeAdded by the SDBOT.AKJ WORM!
    MSNProxyNMSNProxy.exe MSNProxy - SOCKS4 proxy for MSN Messenger. Desktop shortcut available
    msnsched2Xmsnsched2.exeAdded by the W32.SPYBOT.NNT WORM!
    MSNServiceXMSNService.exeAdded by the CARPET.C VIRUS!
    msnsgsXmsnsgs.exeAdded by the Troj/Cheuko-B TROJAN!
    msnshedXmsnshed.exeAdded by the W32/RBOT-YN WORM!
    MSNSysRestoreXpc32.exeAdded by a variant of the MASTAK VIRUS!
    msnToolbaarXmsnmsgesc.exeAdded by the RBOT.BMF WORM!
    MSObject32XMSObject32.jsAdded by the PUN VIRUS!
    MsofficeXmsoffice.htaHijacker - redirecting to Searchdot.net
    MSOfficeXservices.exeBrowser hijacker. The file is placed in a newly created MSOffice folder in System32 - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    MSOfficeCfgXqservice.exePremium rate adult material dialer
    MSOfficeCfgXnavchk.exePremium rate adult material dialer
    MSOfficeCfgXmsocfg.exePremium rate adult material dialer
    MSOfficeCfgXshman.exePremium rate adult material dialer
    MSOfficeCfgXssvr.exePremium rate adult material dialer
    msoffwzXmsoffwz.EXEAdded by the Troj/Bancban-HQ TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    msoft-updater23Xslssystem.exeAdded by the W32/Rbot-ASR WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    msoft-updater23Xmssysstems.exeAdded by W32/Rbot-ATU WORM!
    MSOleath32Xwinss.exeAdded by the KATHER TROJAN!
    MSOOBDXMSOOBD.EXEAdded by the MAGISTR.A VIRUS!
    mspaint.exeXcheck32.exeAdded by the WIN32.AGENT.AH TROJAN!
    Mspatch69X(path to trojan)Added by the MPROX VIRUS!
    Mspatch89Xcnqmax.exeAdded by the RANDEX.P VIRUS!
    mspingXmsping.exeAdded by the Trojan.Floodblack Trojan!
    MSPluginSrvcXp3.exeAdded by the W32/RBOT-WV WORM!
    MSPLUSXmsplus32.exeAdded by the W32/MYTOB-AM or W32/MYTOB-CL WORMS!
    MSPQFileXMSA****.TMPHomepage hijacker. See here for more information. **** can be anything
    MSPRO32Xpnp.exeAdded by the ZOTOB.O WORM!
    MSPRO32X(PATH TO WORM FILE)Added by the W32.Iberio WORM!
    MSprotect.exeXMSprotect.exeAdded by the W32/Dabyrev-A WORM!
    mspwrUpupstman.exe"Transparent icon background" feature of Ashampoo's PowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me) 
    mspwrUpupxpman.exeRelated to Ashampoo's PowerUp_XP
    mspwrUpwrupst.exeAshampoo PowerUp_XP is a tool for fine-tuning your Windows® NT4, 2000, 2003 Server and XP configuration.
    MSPY2002NImScInst.exePart of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
    MSRXmsr.exeAdded by the AGOBOT.RT WORM!
    MsrcXMsrc.exeAdded by the KRYPTONIC GHOST VIRUS!
    msreg.exeXmsrege.exeAdded by the ZINX VIRUS!
    msReg32 LoaderXmsreg32.exeAdded by the AGOBOT.IU WORM!
    MSREGITXMsgp.exeAdded by the KRYPGHOS (Kryptonic Ghost) VIRUS!
    MSRegScanUSGP.exe SpyGator is a spyware program that monitors Internet activity, logs keystrokes, and takes screenshots.
    MSRegScanUETNKL.exeAdded by the ComKeylogger surveillance software. Uninstall this software unless you put it there yourself.
    MSRegSvcXregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
    msrepairXmsrepair.exeAdded by the SDBOT.AFL WORM!
    msresearX(Path to trojan EXE)Added by the Troj/Weasyw-B TROJAN!
    msresearchXmsresearch.exeTROJAN! - 180SearchAssistant adware related
    msresearchXtool3.exeSpy Sheriff/SpywareNO malware component, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
    msrundllXmsrund1l32.exeAdded by the Backdoor.Binghe TROJAN!
    msrunocx32Xmsrunocx32.exeAdded by the SKUS VIRUS!
    Msrv32XMsrv32.exeAdded by the AGOBOT-NB WORM!
    MSSCDLUMSSCDLL.exe SpyCapture keystroke logger/monitoring program - remove unless you installed it yourself!
    msservXlvsrev.exeAdded by the TROJ/BROWMON-B TROJAN!
    msservXmsserv.exeAdded by the TROJ/BLACKLOG-A TROJAN!
    msserv32Xmsserv32.exeAdded by the W32/RBOT-ACK WORM!
    msserviceXmsserv.exeAdded by the HYD VIRUS!
    MSSeverX(Path to Executable)Added by the Troj/PWS-CW TROJAN! Note: This trojan will attempt to steal passwords and other personal information.
    mssfosXsfool.exeAdded by the W32.Randex.EUS WORM!
    MSSGisgX(path to file)Added by the RANKY.N TROJAN!
    MSShowXMSShow.exeAdded by the Troj/QQRob-M TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    MSSHVCXMSSHVC.exeAdded by the NUFFY.A VIRUS!
    mssoulXmsmscc2.exeAdded by the Win32.Dapizl.A banker WORM!: ( a "banker worm" is designed to pillage banking information and send it back to the perpetrators!)
    mssp3Xmssp22.exeAdded by the TROJ/IBANK-D TROJAN!
    MSSQLXMssql.exeAdded by the SDBOT WORM!
    MsstartXmsstart.exeAdded by the LIVUP.C VIRUS!
    MSStartOptimizerXIexpres.exeAdded by the POLDO.B VIRUS!
    MSStartOptimizerXWINUPD.EXEAdult content dialler - see here. This has to be cleared at the same time as RegCompres (REGCPM32.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
    msstaskXmsstask.exeAdded by the MYPARTY VIRUS!
    mssurfer lptt01 or mssurfer ml097eXmssurfer.exeVariant of the RapidBlaster parasite (in a "surfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware
    mssvcX(path to trojan)Added by the PSK VIRUS!
    MSSVCXsvcsys.exeAdded by the FATOOS-C TROJAN!
    MSSVC.EXEYMSSVC.EXEStealthdisk - hides folders, files and applications. Will also encrypt them for better protection
    mssvc32Xmssvc32.exeAdded by the W32/Agobot-ME WORM!
    mssysXmssys.exeAdded by the MYSS.B VIRUS!
    mssysintXIexplore .exeAdded by the PWSTEAL.ABCHLP and PSPIDER.310.B VIRUSES! Note - this is not the valid Internet Explorer (iexplore.exe)
    mssysintXcomime.exeAdded by the TROJ/NETSNAKE-I TROJAN!
    mssyslanhelperXmsmsgri32.exeAdded by the RANDEX.D VIRUS!
    MsSystemXmsdos.exeAdult content downloader - see here
    MsSystemXmssys.exeAdded by the VANTA.A VIRUS!
    MSSYSTEMXsvcsys.exeAdded by the FATOOS-C TROJAN!
    MstapiXMstapi.exeKeylogger trojan
    MstaskXmstask.exeAdded by the OPASERV.N VIRUS! Note - this is not the "Scheduling Agent" and the executable resides in C:\Windows or C:\WINNT
    mstaskXmstask.exeBrowser hijacker, redirecting to find-more.net
    MSTaskXrun_dll.exe Yuupsearch adware
    MStaskXsvchost.exeAdded by the TROJ/LDPINCH-BV TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    MsTaskXwstask32.exeAdded by W32/Mytob-FE and W32/Mytob-FG WORM!
    MSTaskbar 32Xtbsvc32.exeAdded by the RBOT.BQZ WORM!
    mstasksXmstasks.exeAdded by the PWSTEAL.OMERSTROKE TROJAN!
    Mstcgww?MSTCGWW.EXE??
    Mstng32XMSTng32.exeAdded by the TANG VIRUS!
    MSUpdateXwupd.exeAdded by the ALADINZ.M VIRUS!
    MSUpdateXsvchosthlp.exeAdded by the BLASTER.T VIRUS!
    msupdateXmsupdate.exeAdded by the W32/RBOT-MZ WORM or Troj/Surila-E backdoor TROJAN! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MSUpdateXcriticalUpdate.exe Affilred adware
    msupdateXupdate.exeAdded by a variant of the W32/SDBOT WORM!
    MsupdateXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    MsupdateXoutIook.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    MsupdateXexpIorer.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    MsupdateXsvcshost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    MsupdateXsvchosts.exeAdded by a variant of the WIN32.TACTSLAY TROJAN!
    MsUpdateXMsUpdate.exeAdded by the W32.Alcra.D WORM! Note: This worm file is found in the Program Files\MsUpdate folder.
    MSupdate.exeXN/A CoolWebSearch parasite related.
    MSUpdateDevKitXaxfd.exeAdded by the W32/SDBOT-ZD WORM!
    MsUpdater SystemXudpsys32.exeAdded by the RBOT.AAA WORM!
    MSupdater.exeXN/A CoolWebSearch parasite related.
    msupdater25Xlsasser.exeAdded by W32/Rbot-ATS WORM!
    msupdatesXmsupdt.exeAdded by a W32/Rbot-JO worm infection
    MSUpdSrvXmsupdsrv.exeBrowser hijacker, redirecting to a porn site
    msurlXmsurl32.exeAdded by a CRYPTER.A trojan infection
    msuser32.exeXmsuser32.exeAdded by the ANDROV VIRUS!
    MsVBdllXMsVBdll.pifAdded by the W32.Aimdes.A WORM!
    MsVBdllXsys32dll.exeAdded by the W32.Aimdes.B or W32.Aimdes.C WORM!
    MSVBVM60Xmsvbvm60.pifAdded by the W32/SCOLD-B WORM!
    MSVBVM60XMSVBVBM60.pifAdded by the SCOLD.C WORM!
    msvc32Xmsvc32.exeClientMan parasite variant
    msvc32Xmsvc32.exeAdded by the W32/AGOBOT-NT WORM!
    msvccXmsvchost.exeAdded by the XOMBE VIRUS!
    MSVersionXINTERNETFEATURES.exe, clrschp038.exeAdded by the POPMON.A VIRUS! - also known as PopMonster adware
    msvhostXaig.exeAdded by the Troj/Aimbot-BC TROJAN! Note: This worm file is found in the Windows(95/98/Me/XP) or WINNT (Nt/2000) folder.
    msvload32Xmsvload32.exeAdded by the W32/RBOT-ACI WORM!
    msvsc32Xmsdev.exeAdded by the W32/RBOT-GJ WORM!
    MSVsmtXrpcxctx.exeAdded by an unidentified WORM or TROJAN!
    MSVSyncXvideosync.exe W32.SpyBot worm variant
    MSVXDXMSVXD.EXEAdded by the DATOM.A VIRUS!
    mswXmsw.exeAbcsearch.com/DealHelper adware variant
    mswaveXmswave.exeAdded by a CRYPTER.A trojan infection
    MswavedllXmswavedll.exeAdded by the CRYPTER-C TROJAN!
    MSwheelUmswheel.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    MSWinXmswin.exeAdded by the BANKER-CU TROJAN!
    MswincfgXMswincfg32.exeAdded by the BACKDOOR.CYBSPY TROJAN!
    MsWindows SysDateXsysmsvc.exeAdded by the W32.Spybot.FCD WORM!
    MSWindows SyspgXmspg32.exeAdded by the W32/Rbot-TB WORM!
    MSWindowsUpdateXSystern.exeAdded by the W32/Rbot-AFD Worm!
    Mswinpid32Xmswinpid32.exeAdded by the Win32.Lapos.A TROJAN! This is a a keylogger which emails back to China PayPal passwords and account information - thus allowing the perpetrators to steal PayPal funds in the name of the victim!
    MSWinSrvXMSWinSrv.exeAdded by the MTRON TROJAN!
    MSWinSrv32XMSWinSrv32.exeAdded by the MTRON-B TROJAN!
    MSWinupdXwinupd.exeAdded by the Troj/Dloader-YE or Troj/Dloadr-AAA TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MsWinVgrXmsvgr.exeAdded by the W32.Mytob.LE WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    mswkork ServiceXmsework.exeAdded by a variant of the WIN32.RBOT WORM!
    mswordXmsword.exeAdded by the W32/Rbot-ADR Worm!
    mswork ServiceXmswork.exeAdded by a variant of the W32.SPYBOT WORM!
    mswsplXwmplayer.exe, other file namesAdded by a TROJ_SMALL.IQ trojan downloader infection
    mswsplXsearchbarcash.exeSearchBarCash adware variant
    mswsplXvnmispoisn_downloader.exeSearchBarCash adware variant
    mswsplXplugin1.exeAdded by the TROJ_SMALL.IQ downloader TROJAN!
    msxctXmsxct.exe eXact_Advertising (NaviSearch, BargainBuddy, CashBack) adware component
    Msy1 StartupsXmsyj32.exeAdded by the W32/AGOBOT-QQ WORM!
    msys lptt01Xmsys.exeNew variant of the RapidBlaster parasite (in a "Msyss" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Msys32Xmorfitwebentrance.exeMorfit ADjectPager - "uses home page rental technology for generating revenues". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage 
    MSysDrvXmsdrv.exeAdded by the Win32.VB.wf backdoor TROJAN!
    ms_anti_spywareXmwfirewall.exeAdded by the Trojan.Gamqowi TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    ms_anti_spywarebxpXmwfirebpx.exeAdded by the Troj/Surila-D TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    MS_LARISSAXMS_LARISSA.exeAdded by the W32.Assiral WORM!
    MS_NETD_WIN32Xnetd32.EXEAdded by the RANDEX.F VIRUS!
    MS_SETUP.EXEXMS_SETUP.EXEAdded by the CHARGE VIRUS!
    MS_Update CheckXwdfmgr.exeAdded by the W32/AGOBOT-TB WORM!
    MtdAcqNMtdAcq.exe Creative_MediaSource "Sound Sniffer", monitors the drive for new media files then automatically adds them to the media library.
    Mtr2Xmtr2.exeAdded by the KRYPTONIC GHOST VIRUS!
    MUALUmual.exeMillesky video mail updater and launcher
    muamgrUmuamgr.exeQuick access to MicroAngelo 5.0. It can make the background of the icon text transparent and also change the color of the shortcut\'s text to a color you want. Very useful, if you have a wallpaper. Available via Start -> Programs
    Mufix?mufix.exePart of INFOConnect, web-based, enterprise client configuration, management, and deployment software, as used by ABSS (a financial management system used by the US military which will allow purchase request packages to be electronically submitted to contracting, and which also facilitates electronic receipt of items and EFT) - what does it do and is it required
    Multi-function keyboardUGWHotkey.exeSoftware that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)
    MultiCAM InitializerUMCamBoot.exeThe MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled
    Multimedia CodecsXmcc.exeAdded by the TROJ/DLOADER-MB TROJAN!
    Multimedia extensionsXmservice.exe EasySearch adware
    Multimedia extensionsX(Path to EXE)Added by the Troj/SmutSrch-A Trojan!
    Multimedia KBD or MULTIMEDIA KEYBOARDUMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys. Can also be listed as Keyboard Manager
    multiranXmultiran.exeAdded by the Troj/Cosiam-E TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MultiResUMultiRes.exeMultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP
    MUPSUMUPS.exeLauches the Belkin Bulldog Plus Service - required if you want to access the UPS advanced functions
    murphy shieldYlmgui.exeFirewall part of BitDefender virus scanner/firewall
    Music01 ServerNMusic01 Server.exeJ River Media Jukebox
    MusIRCXmusirc4.71.exeAdded by the RANDEX.Q WORM!
    MusIRC (irc.music.com) clientXmusirc4.71.exeAdded by the RANDEX.Q WORM!
    Mustek MDC 3000?Mounter.exeRelated to software for the Mustek MDC_3000 digital camera - what does it do and is it required?
    MutexServiceExNSys32Smm.exeWebroot Sofware's discontinued "Privacy Master"
    MW1HelperStartUpUMw1helper.exeScreenScenes MagicWaterfall screen saver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $ 30...
    mwavscanUmwavscan.comMicroWorld Anti Virus Toolkit is a free anti-virus scanner that runs on-demand. You can choose to scan your entire system, including memory, services, starup items and registry, or only scan files in a specified folder or drive.
    MWProEngNMWProEng.exeLogitech Mouseware Pro software - only required when using special functions
    MWSnapNMWSnap.exeMWSnap - screen capture utility. Start manually when required
    mwsoemonXmwsoemon.exe"My Web Search" malware
    MwsvmXmwsvm.exeSeekSeek search hijacker related - as seen here
    MxHLp32XMxHLp32.exeAdded by a variant of the VAGRNOCKER VIRUS!
    MXO Auto LoaderUMXOaldr.exeMaxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
    MXOBGUMXOALDR.EXEMaxtor includes a driver to bypass the Windows certified drivers check just when it detects an external drive. MXOaldr.exe is installed with the new driver and if disabled the button on a Maxtor OneTouch External Store no longer functions
    MxRunnerUMxRunner.exeEasyUninstall from Aladdin Systems (formerly by Ontrack)
    My AgentXmsagent.exeAdded by the NEGASMS.A VIRUS!
    My AppXSMSSvc.exeAdded by the NEGASMS.A VIRUS!
    My Search Bar EqXS4BAREQ.EXEMySearch bar parasite
    My-disgoUMyKey disgo.exeRelated to disgo_pro Program will synchronize data.
    MyAccessMediaXtmp**.exe (where * = random char/digit)My AccessMedia toolbar related, stealth installed!
    MyAgtTryUMyAgtTry.exeSystem tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
    MyappX(filename)Added by the FATEE.B VIRUS!
    MyappXservice.exeHomepage hijacker
    MyAVXavpguard.exeAdded by the W32.NETSKY.J WORM!
    MyCIO Agent ServiceYmyagtsvc.exeMcAfee VirusScan ASaP Agent service
    myCIO.com ASaPUMyAgtTry.exeSystem tray notification for McAfee VirusScan ASaP on-line scanner. Not required to be protected but you lose notifications
    myCIO.com SplashNSplash.exeSplash screen for McAfee VirusScan ASaP on-line scanner
    MyCometCursorXMYCOME~1.EXEComet Cursor adware
    MyDailyHoroscopeXMyDailyHoroscope.exeeConfidence MyDailyHoroscope foistware
    MyDailyHoroscopeXMYDAIL~1.EXEeConfidence MyDailyHoroscope foistware
    MyFastAccessXmyfastupdate.exeMy-Fast-Access toolbar updater
    myhuyXhuy.exeAdded by the W32/Blaster-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    myhuyXhuy2.exeAdded by the W32/Blaster-L WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    MyIE.exeUMyIE.exe MyIE2/Maxthon browser related
    MyLifeXCmdServ.exeAdded by the HOLAR.A VIRUS!
    myNetWatchmanUnwclient.exeSends your firewall alerts to a website, which then filters them and forwards details of suspicious activities to the host ISP they originated from. Only needs to be running when your firewall is running
    MyPointsPointAlertXwjview ...MyPointsPointAlertrun.exe"With MyPoints you can earn rewards from name-brand merchants. You can even earn vacations and frequent flyer miles". Dubious privacy policy
    myprint mileageUmpm.exeReports battery status on a portable printer
    MyPrivacyIndexPathYMyPrivacyIndex.exeOmniquad Total_Security
    MySLScanXmsvc32.exeAdded by the W32/FORBOT-EH WORM!
    mysoftXwinexplor.exeBrowser hijacker, also detected as the TROJ/STARTPA-JR TROJAN!
    MySoftware NewsFlash?Newsflsh.exe??
    MytekSystrayExePathUMyTekSystray.exeMyTek system tray - web site providing computer tech support in Australia
    MyTotalSearch Email PluginXmtsoemon.exe MyTotalSearchBar adware
    MyVBAppXSysNT.exe ReferAd adware
    MyVirt.exeXMyVirt.exeAdded by the REMADM-C TROJAN!
    MyVitalAgentUVtlAgent.exeMyVitalAgent from Lucent Technologies. Replacement for Net.Medic, monitoring all popular internet transactions and alerting the user of the loaction of connection problems. Available via Start -> Programs
    MyWebSearch Email PluginXmwsoemon.exe MyWebSearch parasite
    M_S DVD DirectX Dll DriversXmsxdl.exeAdded by the W32/SDBOT-BJN WORM!
    N2PTrayUNet2fone.exeAn Internet telephony application. Needed only if you have an account at Net2Phone, Inc
    NADaemonNNADAEMON.EXEProgram by NetActive which appears to be piggybacked onto some Nvidia graphics cards software. They seem to look after "digital rights management". One user reports disabling it has no detrimental affect - not required
    NaggerrunkeyNnagger.exePackard Bell Free Internet Signup screen
    Naimagent_serviceYEPOAgentnaimas32.exeNetworked version of McAfee VirusScan. Installs, configures and updates the software and DAT (virus definition) files on local computers from a network server. A resource hog but required for DAT updates and if disabled can also cause random freezes and error messages
    Naimagent_UIYEPOAgentnaimag32.exenaimag32.exeWorkstation background program for Network Associates’ McAfee ePolicy Orchestrator - a network management tool for enforcing antivirus protection of the workstations using system policies. Works with both McAfee and Norton AntiVirus. NAIMAG32 and NAIMAS32 communicate with the ePolicy Orchestrator processes on the network fileserver to check for virus updates or for the need to perform a virus scan
    NameXIexplorer0.exeAdded by the THREADSYS VIRUS!
    NAMEDPIPE SYSTEMXnamedpipe.exeAdded by the W32.Mytob.LO WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    NAMEDPIPE SYSTEMXnamedpipe.exeAdded by the W32/Mytob-FH TROJAN!
    NAP32XNAP32.exePremium rate adult content dialer
    NarratorX******.exe (* = random char)Added by the QOOLOGIC TROJAN!
    NatalXNatal.scrAdded by the OPASERV.AE VIRUS!
    NAVXRuxDLL32.exeAdded by the MAPSON.D VIRUS!
    nAv AGENTXN/AAdded by the RIOSYS VIRUS! Note the lower-case "n" and "v" in the name as this is not the valid Norton AntiVirus entry of the same name - indeed it closes Norton AV processes
    NAV AgentXsystems.exeAdded by the TARNO.C VIRUS! Note - this is not the valid Norton Antivirus entry of the same name
    NAV AgentYnavapw32.exeNorton Anti-Virus's background scanning process
    NAV AgentXwinsnav.vbsAdded by the W32.ANPES WORM!
    NAV AgentXwmilib32.exeAdded by the Troj/VB-XU TROJAN!
    NAV Auto ProtXnavprot1.exeAdded by the RBOT.ZAC WORM!
    NAV Auto ProtectXnavprotect.exeAdded by a variant of the WIN32.RBOT WORM!
    NAV Auto ProtectXmsfwe1.exeAdded by a variant of the WIN32.RBOT WORM!
    NAV Auto ProtectXdnsserv.exeAdded by a variant of the W32/SDBOT WORM!
    NAV Auto ProtectXmcafee32.exeAdded by a variant of the W32.SPYBOT WORM!
    NAV Auto UpdateXNavautoupdate.exeAdded by the SPYBOT VIRUS!
    NAV Auto UpdatesXslserver.exeAdded by a variant of the W32/SDBOT WORM!
    NAV Auto UpdatesXnavwindows.exeAdded by a variant of the W32/SDBOT WORM!
    NAV Auto UpdatesXcsrssp.exeAdded by a variant of the W32/SDBOT WORM!
    NAV Auto UpdatesXslserves.exeAdded by a variant of the W32/SDBOT WORM!
    NAV Auto UpdatesXnavupdaters.exeAdded by the W32/RBOT-UN WORM!
    NAV Auto UpdatesXnavupdaterx.exeAdded by a variant of the WIN32.RBOT WORM!
    NAV CfgWiz or NAV Configuration WizardNcfgwiz.exeIntroduced with Norton Anti-Virus 2002, this is a real resource hog. Many NAV users will find they can live without loading it
    NAV DefAlertUDefAlert.exeNorton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
    NAV Live UpdateX(path to worm)Added by the DEBORMS.C VIRUS! <filename> represents the path to the worm. Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec
    NAV Scan ServiceXNAVSCAN32.EXEAdded by a SDBOT.VG worm infection
    NavAgent32Xlasvr32.exeAdded by the FEMOT.D VIRUS!
    NavAgent32XSCardSvr32.ExeAdded by the MOFEI.B VIRUS!
    navappXnavapp.exe NavExcel adware variant
    navapw32Ynavapw32.exeNorton Anti-Virus's background scanning process
    NAVCheckXnavchk.exePremium rate adult material dialer
    NAVCheckXshman.exeAdult material premium rate dialer
    NaviscopeUnaviscope.exeNaviscope is a multipurpose browser enhancement that can speed up Web searches, lock out cookies, examine HTML send/receive headers, provide single-click network diagnostics, and much more
    NaviSearchXnls.exeeXact Advertising BargainBuddy/NaviSearch adware
    navman_20Xsysnav32.exe CoolWebSearch parasite related.
    NAVNetX***.tmp (* = random digit)Unidentified adware
    navp.exeXnavp.exeAdded by the W32/AGOBOT-OE WORM!
    NavPassXNavPass.exeFree system for gaining access to and downloading from adult content web-sites
    NavRegReminderNNavLoad.iniCorel, HP or ScanSoft registration reminder; not required
    NavScanX(random filename)Added by the OBSORB VIRUS!
    NAVSCAN32.EXEXNAVSCAN32.exeAdded by the W32/SDBOT-DO WORM!
    NAVSCANNER32XNAVSCANNER32.EXEAdded by the RBOT.QC WORM!
    NAVUpdXrundll32.exe navupd.dll, StartupAdded by the NAVU VIRUS!
    NAV_UpdateXNAV_Update.exeUnidentified WORM or TROJAN!
    nawadll32Xnawadll32.exeAdded by the W32/Sdbot-ZI Worm!
    nawdll32Xnawdll32.exeAdded by the W32/Sdbot-ZM Worm!
    NB Common Dialog EnhancementsNCOMDLGEX.EXEPart of McAfee Nuts & Bolts. With Common Dialog Enhancements, you can add MRU list box to open dialogs
    NB Start MenuNSTARTM.EXEPart of McAfee Nuts & Bolts. Provides the same control as MSCONFIG and can be used instead if you have N&B
    NB Windows PatternsNWINDBKGND.EXEPart of McAfee Nuts & Bolts. With Background Patterns, you can change background patterns of wizard and dialog windows
    NBJUNBJ.exeAhead Nero BackItUp backup program. Only required for if you have scheduled back-ups
    NbkCtrlUNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
    NBT System aliasX[path] repcale.exe [path] beird.exeAdded by a variant of the RANDON.AN WORM!
    nbustrce1D?nbustrce1D.exeDevice driver, possibly CD-ROM/DVD-ROM related - what exactly is it and is it required in startup?
    NcaoXosoa.exe PurityScan/Clickspring adware
    NcaoXurpo.exe PurityScan/Clickspring adware
    NCClient?N/A??
    NCDNncd.exeNorton Change Directory - from the DOS days that allows the user to change directories on their machine without typing the complete path
    NCLAUNCH?NCLAUNCH.ExePart of SWF Studio from Northcode Inc - an extension to Flash. Bundled when you create a self-installing screen-saver on Win2K/XP. Is it required?
    NCS_SSNCsinsm32.exeSame as CleanSweep Smart Sweep-Internet Sweep
    NDAvXcsnss.exeAdded by the W32.Serflog.C WORM!
    NDAvXsvhost.exeAdded by the W32.Serflog.C WORM!
    NDDEAGNT?NDDEAGNT.EXEWinNT default process. Network Dynamic Data Exchange (DDE) Agent, handles requests for network DDE services
    NDIS AdapterXndis.exeAdded by a SDBOT.VF worm infection
    NDIS AdapterXwindows.exeAdded by the W32/FORBOT-BR WORM!
    NDIS AdapterXlsass2.exeAdded by the WOOTBOT.CW WORM!
    NDIS AdapterXservenxpp.exeAdded by the W32/FORBOT-GP WORM!
    NDIS AdapterXservenxpp.exeAdded by the W32/Forbot-GP WORM!
    NDplDeamonXnstask32.exeAdded by the RANDEX.E WORM!
    NDplDeamonXwinlogin.exeAdded by the RANDEX.E WORM!
    NDPSUDPMW32.EXENovell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature
    NDrvXNDrv.exe PurityScan/Clickspring adware
    NDSTrayUNDSTray.exeConfigFree Tray on a Toshiba laptop. Tray utility for their network switching application which permits switching network devices and settings with a click on the tray icon. While it is not required, for people who span multiple networks and want an easy way to go from wired to wireless and change addresses and other network settings, it's a must have.
    NecbarNNecbar.exeNec Assistant; Ark's Navigator, a graphical interface for NEC computers
    NECMFKYnecmfk.exeNEC wireless keyboard driver
    NecutrayUNecutray.exeDriver for external USB storage devices (hard drives, flsh disks, etc)
    neqprvfy.exe?neqprvfy.exeAppears to be related to the downloading of some application - possibly verifying updates?
    NeroXshch.exeAdded by a variant of the TROJ/BDOOR-EB TROJAN!
    neroXnrchk.exePremium rate adult content dialer
    Nero CheckerXnerocheck.exeAdded by the Troj/Proxy-X TROJAN! Note: This is NOT related to "Nero Burning Rom" CD writing software. This trojan file is found in the Windows or Winnt folder.
    Nero Updater.6.12Xwmp9.exeAdded by the W32/Agobot-AAG Worm!
    Nero.maX.exeAdded by the JONBARR.D VIRUS! where <digits> is 2 or 3 random digits
    NeroAutoStartClientXNeroASM.exeAdded by the AGOBOT.VG WORM!
    NeroCheckUnerocheck.exeAssociated with "Nero Burning Rom" CD writing software. Checks for driver issues
    NeroCheckXregedit.exeAdded by the DOOMJUICE.B VIRUS! Note - this is not the valid Ahead Nero CD burning program. Also it is not the valid Windows registry editor which resides in C:\Windows or C:\Winnt wheras this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP)
    NeroFilterCheckUNeroCheck.exeAssociated with "Nero Burning Rom" CD writing software. Checks for driver issues
    NeroLoaderXNeroLoader.exeAdded by the Troj/Bancban-EJ TROJAN!
    NeroNETTrayIconNNNServiceCtrl.exeSystem tray access to NeroNET - Ahead Software's network-capable extension of their CD/DVD burning program. NeroNET allows a burner to be shared across a network
    NeroUpdater6.8Xwinjava.exeAdded by the AGOBOT.AMK WORM!
    NetXWINREG.EXEAdded by the ASSASIN.D VIRUS!
    Net AcceleratorUNetAccelerator.exeRizal NetAccelerator - "Optimizing Dial-Up, Lan, Cable, DSL, and Satellite connections do you want to speed up your Internet access up to 200% - 300% ???". Only required if you find it helps improve your performance
    Net Activity DiagramUnad.exeNet Activity Diagram from MetaProducts. Monitors your computer internet activity. Available via Start -> Programs
    NET Bios StatsXntbstats.exeAdded by the W32/Sdbot-ZX WORM!
    Net**.exe (* = random char)XNet**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Net**32.exe (* = random char)XNet**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Net-It LauncherNNILaunch.exeNet-It - web publishing software
    NetAcceleratorUNetAccel.exeNetAccelerator is a "software utility that optimizes your internet access up to 1200% faster!. NetAccelerator speeds all modems allowing you to download faster, browse faster, surf faster!. Only required if you find it helps improve your performance
    NetAdm7XNETADM7.EXEAdded by the BANCOS.F VIRUS!
    NetapiXNetapi.exeAdded by the NETDEVIL.14 (NetDevil 1.4) VIRUS!
    netapi32Xnetapi32.exeAdded by an unidentified TROJAN!
    NetAppXwinserv.exeAdded by the SHADOWTHIEF VIRUS!
    Netbios HelperXnbthlp.exeAdded by the PWS-BANKER.Y password stealing TROJAN!
    netconfigXnetconfig.exeAdded by the NETCONF VIRUS!
    NetCruiser DialerUNCDialer.exeNetCruiser Dialer from NetCruiser Software. "An Internet dialer and connection monitor with features to launch applications when a connection is detected, dial and hangup at predefined times and automatic redialing of dropped connections"
    netdaemonXnetdaemon /vAdded by the Vb.RH TROJAN! - malware designed to "kill" a number of antispyware applications: (SpyBot, Giant, SpyDoctor, SpySweeper, SpyHunter, Anvir, WinPatrol, and more)
    netdll32Xnetdll32.exeAdded by a CRYPTER.A trojan infection
    netdllexXnetdllex.ExeAdded by a CRYPTER.A trojan infection
    NetDyXVisualGuard.exeAdded by the W32.NETSKY.N or W32.NETSKY.W WORM!
    NETFP32.EXEXNETFP32.EXETrojanDownloader.Win32.Agent.cd
    netfxupdate or NetFxUpdate_v1.0.3705?netfxupdate.exeWould appear to be a valid Microsoft .NET file (see here) but this suggest\'s it\'s a trojan?
    NetGuardUNetGuard.exeFBM Software ZeroSpyware 2004 spyware detector and remover; real time monitor.
    NetlimiterUNetlimiter.exeNetlimiter - "An internet traffic control tool to monitor applications which access the internet and actively control their internet traffic. Use it o set (download/upload) speed limits for applications or even single connection. NetLimiter also allows you to share your internet connection bandwidth among all applications running on your PC."
    Netline UserNnetchk.exeNetline supplies internet related products and services and this program identifies user ID and IP information. Found installed along with the Falcon 4 game, for example
    NetLinkXnetlink32.exeAdded by the GAOBOT.WO WORM!
    NetLogonXuserint.exeAdded by the W32/SDBOT-BC WORM!
    NetManageImportUnmcpdata.exe NetManage business software related
    NetManagerServiceXntss.exeAdded by the BESTPICS.A VIRUS!
    NetMeterXNetMeter.exeNetRatings Premeter spyware
    NetMeterXNielsenOnline.exeAppears to have possible Malware functions, for more information Click_Here
    NetMonXnetmon.exeAdded by the W32.MIMAIL.M WORM!
    NetmonwXNetmonw.exeAdded by the TROJ/BDOOR-FX TROJAN!
    netmsgUnetmsg.exe Net_Message is a small tool to send messages across the network, using the Windows Messenger Service, so there is no client install required to receive the messages. It has a number of other features as well.
    NetPatrolUwinclient.exeNetPatrol network monitoring software
    netpc32.exeXnetpc32.exeMalware, probably CoolWebSearch parasite related
    NetPerSecNNetPerSec.exeNetPerSec - measures the real-time speed of your Internet connection
    NetPumperXNetPumperIEProxy.exe NetPumper download manager - bundles Cydoor and SaveNow adware, see here
    NetReachXnrcheck.exeAdded by an unidentified VIRUS!
    Netropa Internet ReceiverXNetropa.exeNetropa Internet Receiver. Shows a scrolling bar with the news. Major resource hog and flagged as spyware
    NetRunUNetRun.exeNetRun - will 'RUN' a 'List' of programs only when a internet connection is detected, and close/kill the same 'List' when the connection is lost
    Netscape MessengerNNETSCAPE.EXEIn Netscape 6 (I know for sure with 6.2.1, maybe with 6.0) Netscape.exe is the main executable file for Netscape Navigator, Netscape Mail and News, and Netscape Messenger (the new name for the embedded AIM, no doubt to make it sound like Windows Messenger, the XP version of MSN Messenger). Basically, netscape.exe can be more than just Netscape Messenger, and Messenger can be more then just AIM in disguise, depending on the version of Netscape installed
    Netscp6NNetscp6.exeNetscape 6
    NetScreen-RemoteUSafeCfg.exe NetScreen_Remote VPN Client Software
    NetServiceXntsvc.exeAdded by the Troj/QQPass-DU TROJAN!
    NetServiceXntsvc.exeAdded by the Troj/QQPass-DU TROJAN!
    netservicesXrecall.exeAdded by a variant of the W32/SDBOT WORM!
    netservicesXsvchostn.exeAdded by the SDBOT.GI WORM!
    NETServicesXcsxrs.exeAdded by a variant of the W32/SDBOT WORM!
    NetShow Powerpoint HelperUNSPPTHLP.EXEIf disabled, user created fonts can no longer be seen by other programs
    NetStat LiveNNsl.exeAnalogX NetStat Live - TCP/IP protocol monitor which can be used to see your exact throughput on both incoming and outgoing data
    netsv32Xnetsv32.exeAdded by a W32/Sdbot-PX worm infection
    NetTimeUNETTIME.EXEFrom a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols, e.g. NTP."
    NetTurboUnetturbo.exeNetTurbo from SharewareOnline.com. "Accelerate Your Internet Connections by up to 600%". If you find it helps your connectivity leave it enabled
    Netunit32Xwunit32.exeAdded by an unidentified WORM or TROJAN!
    NetWatch32Xnetwatch.exeAdded by the W32.MIMAIL.C WORM!
    Netword AgentNnwant33.exeAn interesting browser utility that allows you to navigate by typing a single word or phrase (a "NetWord") related to what you're looking for into your browser's location field. It also puts an icon in the system tray icon that is a circle with the letter N in the center to access the menu faster. Available via Start -> Programs
    NetWorkXcsrs.exeAdded by the AGOBOT.JJ WORM!
    Network AccessXwinssh.exeAdded by a variant of the W32/SDBOT WORM!
    Network AdministrationXNAS.exeAdded by the ANTILAM.20.Q VIRUS!
    Network Administration ServiceXrsvc32.exeAdded by the RBOT.ABH WORM!
    Network Associates Error Reporting ServiceUTBMon.exeNetwork Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software
    Network ConnectionsXinternat.exeAdded by the TROJ/VB-ZD TROJAN!
    network device driverXmsfirewall.exeAdded by the Troj/Delf-LB TROJAN!
    NetWork Device SwitchUNetDevSW.exeToshiba laptops with built-in Wi-Fi. Allows switching between Wi-Fi and internal ethernet. Only necessary if you have regular need to switch back and forward between these network interfaces. Located in Startup folder so make own shortcut to it and disable if not really necessary
    Network Host ControllerX(path to trojan)Added by the WHISPER VIRUS!
    Network Host ServiceXmsmnart32.exeAdded by the W32/RBOT-CJV WORM!
    Network Protocol ServiceXwuamgrd.exe WORM_RBOT.EA
    Network protocol serviceXwintcp.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Network SecurityXsecsvc.exeAdded by the W32/Rbot-ALX WORM!
    Network Security GuardX**********.exe (* = random char) CoolWebSearch parasite related.
    Network Security GuardX(Pathname of the Trojan executable)Added by the Troj/Colem-A TROJAN!
    Network ServiceXsvchost.exeHijacker, also detected as Win32.Omal.C Trojan.
    Network ServiceXsvhost.exeAdded by the Troj/HacDef-K TROJAN!
    Network Service ManagerXnetsvc.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    NetworkAssociates IncXinternet.exeAdded by a variant of the LOVGATE WORM!
    NetworkClientXNetworkClient.exeAdded by the LEMUR VIRUS!
    NetworkKeyXnetkey.exeAdded by the Troj/IRCBot-AJ TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Networks ConfiguratorXNetConfs.exeAdded by the W32/RBOT-OX WORM!
    Networks ControlerXNetsis.exeAdded by the W32/RBOT-NG WORM!
    NetworkSetupNdlink.exeD-Link System Tray icon
    NetZero_uoltrayNexec.exe regrunNetzero free ISP software - not required
    Netzip Smart DownloaderXnpnzdad.exeAdvertising spyware
    NetZIPFoldersNnzfprop.exeNetzip Classic zip file manager
    NeuroMedia(IESpeaker)XNeuroMedia.exePart of an older freeware version of IESpeaker - a program that allows you to listen to web pages. NeuroMedia.exe only downloads advertisments. Not included in the paid-for version currently available
    NeuroSpeech OESpeakerNOEMonitor.exePart of OESpeaker - a program that allows you to listen to long E-mails instead of reading them in Outlook Express. OEMonitor.exe checks whether OE is open or not
    New Csnm ManagerXcsmn.exeAdded by the SDBOT.BZS WORM!
    New.net or NEWDOT~1Xrundll32.exe NewDotNetStartup Newdot~2.exe NewDotNet foistware
    New.net StartupXrundll32 (path to file),NewDotNetStartup -s NewDotNet foistware
    NewmanXplayavi.exeAdded by the Troj/Lineage-AT TROJAN! Note: This trojan file is found in the Windows\java or Winnt\java folder.
    News Service?ispnews.exe F-Secure antivirus related. However, is this particular item required??
    NewsalrtNNEWSALRT.EXEMSNBC News system tray utility to alert you to new news
    Newsgroup lptt01 or Newsgroup ml097eXnewsgroup.exeVariant of the RapidBlaster parasite (in a "newsgroup" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    NewsUpdNnewsupd.exeFor Creative Soundblaster Live! series soundcards. System tray application for News updates. Available via Start -> Programs. Also spyware - see here.
    NewtonKnowsUpdXNewtKnow.exe ...NewtnUpd.dll, runkeyNewtonKnow hijacker
    NFM ServiceUNPDOR9x.exeAppears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required
    nForce Tray OptionsNsstray.exenVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
    NGClientUngctw32.exeSymantec Ghost Server software - needed for a "a Ghost multicast" (transfer images to multiple machines). Can be launched manually
    ngpw36Xngpw36.exe AdBlaster adware variant
    NGServerNngserver.exeSymantec/Norton Ghost Console service
    NI.UWFX5XUWFX5NetInstaller.exeWinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    NI.UWFX5LP_0001_0802XUWFX5LP_0001_0802NetInstaller.exeWinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    NI.UWFX5LP_0001_0803XUWFX5LP_0001_0803NetInstaller.exeWinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    NI.UWFX5TXUWFX5TNetInstaller.exeAdded by the Troj/DownLdr-BO TROJAN! Note: This trojan file is found in the Windows\Downloaded Program Files or Winnt\Downloaded Program Files folder.
    NI.UWFX5V_0001_0802XUWFX5V_0001_0802NetInstaller.exeWinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    NiceDownloadsXrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    Nielsen NetRatingsNinsight.exeNielsen NetRatings -  "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site’s audience and your customers". Is it required?
    nikLausXnikLaus.exeAdded by the NIKLAS VIRUS!
    NInitNNInit.exeNorton Uninstall Deluxe. Monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging - not required
    nisservYNISSERV.EXENorton Personal Firewall
    NisumYNISUM.EXENorton Personal Firewall
    niSvcLocUniSvcLoc.exeRelated to National Instruments Corp. LabView
    NJG40XNJG40.EXEAdded by the BANCOS.D VIRUS!
    NkvMon.exeNNkvMon.exeNikon View 5 - for transferring pictures from Nikon digital cameras
    NkVwMon.exeNNkVwMon.exeNikon View - for transferring pictures from Nikon digital cameras
    NLS KeyboardXkeyboard.exeAdded by a variant of the W32.SPYBOT WORM!
    NLS MonitorXnlsmon.exeAdded by the W32/Rbot-AXJ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    NMSSvc?NMSSVC.EXENIC Management Service - diagnostics program for Intel Pro family network cards
    NMSVCYnmSvc.exeCovenant Eyes - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Disabling it means loss of internet connection until renabled - therefore required if you use it
    nMTaskBarService?nMtsk.exeTaskbar control for ISDN NetMod modem. Sorry, I dont know whether or not it is required. Unknown if this is a required item for startup
    nnmgrXnnmgr.exeAdded by the Adware.FFToolBar adware toolbar.
    NNSvcUnnsvc.exeNetNanny internet filter
    No Credit CardXplugin-.exeAdult content pop-up dialler
    No-IP DUCUDUC20.exePart of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available
    NoAdsUNoAds.exeBlocks advertisement banners in Internet Explorer
    NoAdwareUNoAdwareNoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . The latest version has since apparently mended its ways: see note
    NoAdware3UNoAdware3NoAdware Adware/Spyware remover - initially considerered a "rogue" program - see here . Has since apparently mended its ways: see note
    Nod32 Free antivirusXnod32krn.exeAdded by the W32/RBOT-AAO WORM!
    Nod32CCUnod32cc.exeControl Center part of Eset's NOD32 virus-scanner. Leave this enabled if you want to update your virus data files via the click of a button
    NOD32kernelYNod32krn.exeNod32 Antivirus Version 2
    nod32kuiYnod32kui.exeNod32 Antivirus Version 2
    NOD32POP3YPop3scan.exePOP3 E-mail part of Eset's NOD32 virus-scanner
    Nod3d2 Free antivirusXN0D32KRN.EXEAdded by the W32/RBOT-ABQ WORM!
    NodeMnger?Nodemngr.exePart of the Dell OpenManage Client installation - to allow Dell representatives to remote logon?
    nodriverXAUEKXRZ.EXEAdded by a variant of the SPYBOT VIRUS!
    NohaXaasd.exe PurityScan/Clickspring adware
    Nokia Connection MonitorNNclConf.exeMonitors the infrared port, the serial ports and the Bluetooth for a Nokia phone connection. It is installed by the Nokia PC Suite (and Nokia PC Connectivity SDK), and the tray icon shows if a phone has been connected. If you have a conflict with another program, such as TV tuner card remote control monitor, you can disable it, and run only when needed. Available via a desktop shortcut or Start -> Programs - not required
    Nokia Tray ApplicationUNclTray.exeNokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
    NOMAD DetectorUctmnrun.exeDetects the Creative NOMAD jukebox/MP3 player at the time it is attached to USB and starts the needed application (Creative PlayCentre 2) that you use to copy MP3 files to and from it. This is required if you want PlayCentre 2 to take control of the NOMAD once connected
    NomdCheckNnomdchek.exePart of Intel's Native Audio
    Norman ZANDAUZLH.EXESystem Tray icon for Norman Antivirus
    NortE AntivirusXnorten.exeAdded by the W32/Rbot-AFF Worm!
    NortE AntivirusXnorte.exeAdded by the RBOT.BQQ WORM!
    norten Software IntrenetXnorten.pifAdded by W32/Rbot-AWA WORM!
    Norton Antivirus 2004XSYMANTECAV2.EXEAdded by the W32/Spybot-DY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Norton Antivirus 7.0aX[path to file]Added by the PERDA-B or RANCK-CT TROJAN
    Norton AntiVirus AutoProtectYnavapw32.exeNorton Anti-Virus's background scanning process.
    Norton Antivirus AVXFVProtect.exeAdded by the W32.NETSKY.P WORM! **Note - this is not the popular AV software!
    Norton AntiVirus SysXNAVsys32.exeAdded by a variant of the W32/WOOTBOT WORM!
    Norton Auto ProtectXnava.exeAdded by an unidentified WORM or TROJAN!
    Norton Auto ProtectXcrss32.exeAdded by the SDBOT.ATF WORM!
    Norton Auto-ProtectYnavapw32.exeNorton Anti-Virus's background scanning process. Can be inconvenient because it scans files when Run/Opened or Downloaded/Created and you can scan files manually via right-click after downloading/copying. However, in light of some of the viruses around these days it's probably best to put up with the inconvenience
    Norton Auto-ProtectXccApp.exeAdded by the W32.Ahker.D WORM! **Note - for the valid Norton AV entry the filename is "navapexe". This is also not the valid Norton_AV_2003 file with the same filename
    Norton Auto-ProtectXSERVICES.exeAdded by the W32.Ahker.B WORM!
    Norton AV Preload?Premend.exeNorton Antivirus related. What does it do and is it required
    Norton AV Protection StartupXAti2xxx.exeAdded by a variant of the WIN32.RBOT WORM!
    Norton Crashguard MonitorNcgmenu.exeTroublesome program that doesn't actually work with WinME so Norton removed it from SystemWorks 2001
    Norton Disk DoctorNNdd32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up, checking for disk errors. Better than ScanDisk but can be started manually via Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
    Norton Drive ProtectionXmsdt32.exeAdded by the W32/FORBOT-GB WORM!
    Norton eMail ProtectYPOPROXY.EXEProxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it
    Norton FirewallX(path of the Trojan EXE)Added by the Troj/Banker-ET TROJAN!
    Norton Ghost 9.0NGhostTray.exe Norton_Ghost tray icon - the application can be launched manually
    Norton Guard 32Xntguard32.exeAdded by a variant of the WIN32.RBOT WORM!
    Norton Live Update ServerXcpsdv.exeAdded by the AGOBOT.EW WORM!
    Norton Live UpdaterXCavapsvc.exeAdded by the GAOBOT.AO WORM!
    Norton Live UpdaterXSochost.exeAdded by the GAOBOT.AO WORM!
    Norton Navigator LoaderNnnloader.exeAn older Norton utility for file management under Windows 95. More information here
    Norton Personal FirewallXnpfw.exeAdded by the W32/RBOT-UI WORM!
    Norton Personal FirewallXjah.exeAdded by a variant of the W32/SDBOT WORM!
    Norton Personal FirewallXnpfw32.exeAdded by the W32/RBOT-UQ WORM!
    Norton Personal FirewallXlah.exeAdded by a variant of the WIN32.RBOT WORM!
    Norton Personal FirewallYIntroWiz.exePart of Norton Personal Firewall or Norton Internet Security
    Norton Program SchedulerUnsched32.exe, NPSsvc.exeInstalled on a Windows system where the Windows Task Scheduler isn't used as part of the OS (Win95, WinNT(?), Win2K(?)) to schedule automatic tasks such as Norton Anti-Virus scans
    Norton Program Scheduler Event Checker?npscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as NPS Event Checker
    Norton ProtectXnpprotect.exeAdded by the W32/RBOT-WW WORM!
    Norton protectXnvsvc.exeAdded by a variant of the WIN32.RBOT WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here
    Norton Protect ActiviesXcsrss.exeAdded by the Troj/Banker-CZ TROJAN!
    Norton Service DriverXwsul.exeAdded by the W32/RBOT-ABI WORM!
    Norton Service ProcessXnavapvc.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Norton SpySweeper AutoUpdateXnavsw.exeAdded by a W32/Forbot-AS worm infection
    Norton Swap CleanerXnortonswap.exeAdded by a W32/Rbot-MH worm infection
    Norton System DoctorNSysdoc32.exeNorton Disk Doctor from Norton Utilities. Automatically runs at start-up, major resource hog and best started manually form Start -> Programs. Delete the shortcut in the Start -> Programs -> Startup folder as well
    Norton SystemWorksNcfgwiz.exeNorton SDystem Works configuration wizard. Reportedly a resource hog. Many users find they can live without loading it
    Norton UpdateXccUpdate.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Norton UpdateXwinsvc.exeAdded by the AGOBOT.ALP WORM!
    Norton updatedXNVSV32.EXEAdded by the SDBOT.ABH WORM!
    Norton UpdaterXwinset.exeAdded by a variant of the W32.SPYBOT WORM!
    Norton UpdaterXNortonUpdate.exeAdded by an unidentified WORM or TROJAN!
    Norton UpdaterXlsa.exeAdded by a variant of the WIN32.RBOT WORM!
    Norton UpdaterXccUpdate.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Norton UpdaterXnavupdtr.exeAdded by the SDBOT.AXV WORM!
    Norton WizzardXnwiz.exeAdded by the GAOBOT.ZX or GAOBOT.ADV WORMS! Note - this is not the valid nVidia application that shares the same name
    norton32Xnorton32.exeUnidentified worm or trojan
    NortonAntivirusXLSASS.exeAdded by the W32.Pexmor WORM! Note: This (LSASS.exe) is not the legitimate Windows Process and has nothing to do with NortonAntivirus. The legitimate Windows Process (Lsass.exe) is found in the System32 folder and should not be seen in Msconfig or as a Startup item. This worm file is found in the Windows\Temp or Winnt\Temp folder.
    NortonAVXnorton_antivirus.exeAdded by the BACKDOOR.NETJOE TROJAN! **Note: this is not the legitimate Symantec AV program
    nortonavXCCUPD32.EXEAdded by an unidentified WORM or TROJAN!
    Nortons AV SYSTEMXscvchost.exeAdded by a variant of the WIN32.RBOT WORM!
    nortonsantivirusXccEvtMngr.exeAdded by the TROJ/HZDOOR-A TROJAN!
    NortonVPlusXsvchost.exeAdded by the Troj/Roamer-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Notebook MaximizerUmaximizer_startup.exeToshiba Notebook Maximizer software; adjust settings to save battery power and increase efficiency
    NotebookManager?nbm.exeAssociated with Acer notebook PCs. What does it do and is it required?
    NOTEPADXNOTEPAD.exeAdded as the result of the RUSTY VIRUS! Note - not to be confused with the valid Windows "NOTEPAD" text editor! - This malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    Notepad lptt01 or Notepad ml097eXnotepad.exeVariant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not Windows Notepad which has the same executable name
    notepad.exeXupx.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    notepad.exeXmsmsgs.exeAdded by the TROJ/ZLOB-I and Troj/Zlob-H TROJANS!
    notepad.exeXmsmsgs.exeAdded by a variant of the Troj/FAKESPY-B TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32 or Winnt\System32 folder, and should not be mistaken for the MSN Messenger file of the same name!
    notepad2.exeXpopuper.exeAdded by the Troj/Puper-C or TROJ/PUPER-E or Troj/Puper-AX TROJAN!
    notesXnotepaad.exeAdded by the RBOT.BME WORM!
    NotnXEber.exe PurityScan/Clickspring adware
    NotnXwtta.exe PurityScan/Clickspring adware
    NovaBackup * Tray ControlUNbkCtrl.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see http://www.no-panic.com/backup/tech_supt/nbackup7_commandline.html * represents the version number
    NovaPortal Single User Service?NPSU.exe??
    Novast or SchedulerdUSCHENGD.EXENovaStor NovaBACKUP Scheduler - back-up utility. If you don't have regularly scheduled back-ups you don't need it
    NOYPI_KANG_ASTIGXExit to DosPrompt.pifAdded by the W32.Filukin.A WORM!
    NPF ValueXNPFMONTR.exeAdded by a variant of the W32.SPYBOT WORM!
    NPFMonitor?NPFMntor.exeNorton AntiVirus Firewall Install Monitor - what exactly does it do and is it required?
    NPROTECTUnprotect.exeNorton Protected Recycle Bin from Norton Utilities. Adds an extra layer of safety before you remove deleted files from the Recycled Bin. Can be listed twice which is valid - see here
    NPS Event Checker?npscheck.exePart of Norton Anti-Virus. What does it do? Apparently it can safely be disabled without causing problems. Can also be listed as Norton Program Scheduler Event Checker
    NSXns.exeAdded by the W32/AGOBOT-HS WORM!
    NSCheckXNSCHECK.EXE NetSetter/Marketscore foistware
    nscntrlXnscntrl.exeAdded by the Troj/Dload-DC TROJAN!
    nsdcmd servicesXnsdcmdav.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    nsdcmd vid processXnsdcmdwin.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    nsdluaXnsdlua.exeAll-In-One Telcom - adult content dialler
    nsdriverXnssys32.exe NetShagg adware
    nseXnse.exeAdded by the AGOBOT-ML WORM!
    NsengineUNsengine.exeScheduling engine of NovaSTOR Backup Service. Only required if scheduling is enabled and wanted - see here
    NSHelperUaexnsinstallhelper.exeAltiris Express Notification Server Install helper - monitors integrity of the installation
    nssysconfX(random file name) VIVIA.A trojan variant
    nstatXnetstat.exeadult material dialer
    NsUpdateXNsUpdate.exeAdded by the Dial/Laet-B Dialer! Note: This is a premium rate dialer application and can run up very large phone bills.
    NsvXnsvsvc.exe Delfin_Promulgate adware
    nsvcinXn20050308.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    NsvdrXnsvdr.exeAdult content dialler
    nsysUnsys.exe NetSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    nsys32Xnsys32.exeAdded by the W32/Agobot-SU Worm!
    NSystemMonitorNSymmon.exeNorton Uninstall Deluxe - monitors programs being installed and logs them for removing later. Available via Start -> Programs for manual logging
    NT Kernel PatchNntkrnlpt.exeFaxServe network fax software
    NT Logging ServiceXSyslog32.exeAdded by the W32/SDBOT-ACK WORM!
    NT MICROSOFT SVCDXntvsvcd.exeAdded by a variant of the WIN32.RBOT WORM!
    NT securityXrundll32.comAdded by the W32/Rbot-AJC WORM!
    NT ServiceXNTOKSRNL.EXEAdded by the W32/RBOT-AAG WORM!
    NT ServicesXntsvc.exeAdded by the AGOBOT.VJ WORM!
    NT Video API32XNTAPI32.exeAdded by the W32/RBOT-FW WORM!
    NT Virtual MachineX[path to file]Added by the W32/SCAERBOT-A WORM!
    Nt**.exe (* = random char)XNt**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Nt**32.exe (* = random char)XNt**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    NT-Virtual Device ManagerXntvdmn.exeAdded by the W32/SDBOT-AAA WORM!
    NtcheckXmapserver.exeAdded by the TROJ/TOMPAI-B WORM!
    NTCommLib3XNTCommLib3.exe Admess adware variant
    ntddetectXntddetect.exeAdded by the TROJ/AGENT-CU or BDOOR-ZAU TROJANS!
    NTdhcpXNTdhcp.exeAdded by the Troj/QQRob-O or Troj/QQRob-K TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder
    NTdhcpXCiKewl.exeAdded by the Troj/QQRob-N TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ntdllXntdll.exeAdded by the BIONET.404 VIRUS!
    NTDLMXcsrss.exeAdded by the HALE VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling as this resides in c:\winnt\system32\qossrv
    Ntech.patchsX(trojan filename)Added by the LEMIR.G VIRUS!
    ntechinXn20050308.exeAdware downloader, Delphin_Media_Viewer related, also detected as the DELMED.A TROJAN!
    NTFS16Xntfs16.exeAdded by a W32/Rbot-LY worm infection
    NTFSCLUPYNTFSCLUP.EXEPart of ConfigSafe- "checks if an ntfssos restore has been performed since it was last run. It exits immediately after running. 99 % of the time it will only execute about a dozen instructions before exiting"
    ntfsmonitorproXntfs64.exeAdded by the W32/FORBOT-EB WORM!
    NTFSS Microsoft SystemXfilees.exeAdded by the RBOT.GAB WORM!
    NTFSS MICROSOFT SYSTEMXfiless.exeAdded by the RBOT.AXZ WORM!
    ntldrXntldr.exeBrowser hijacker to search-control.com (TrojanDropper.Win32.Small.ig). In addition to Registry changes found by HijackThis, also creates the following system files: * Creates file C:\WINDOWS\SYSTEM\ntldr.exe. * Creates file C:\m.exe. * Creates file C:\WINDOWS\Search-For-You.url. * Creates file C:\n.bat. * Deletes file c:\q.exe. * Creates file C:\q.exe. * Creates file C:\r.bat
    ntlfreedomNRyDial.dll, QuickStartNTL Freedom ISP software - reportedly not required
    ntmsevtXntmsevt.exeAdded by the TROJ/STOPED-B TROJAN.
    NTP ServerX(path to trojan)Added by the RANKY.F VIRUS!
    nTrayFwYntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
    NTrtcNntrtc.exeDell year 2000 tool to deal with non-standard applications. Only required on older Dell PCs that may need this support - see here
    NTSet32Xservices.exeAdded by the Troj/WinSpy-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\dll32 or Winnt\dll32 folder.
    NTSF Microsoft SystemXntsf.exeAdded by the RBOT.ARQ WORM!
    NTSF Microsoft SystemXfylez.exeAdded by a variant of the WIN32.RBOT WORM!
    NTSF MICROSOFT SYSTEMXwntsf.exeAdded by the RBOT.ATC WORM!
    NTSF MICROSOFT SYSTEMXfufffy.exeAdded by the W32/Rbot-AEL Worm!
    NTSF MICROSOFT SYSTEMXscvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    NTSF MICROSOFT SYSTEMXntssf.exeAdded by a variant of the WIN32.RBOT WORM!
    NTSF MICROSOFT SYSTEMXwinsis32.exeAdded by a variant of the WIN32.RBOT WORM!
    NTSF MICROSOFT SYSTEMXmarya.exeAdded by the W32/Rbot-AXY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ntsmodXntsmod.exeadware downloader/installer, probably VX2/Look2Me related - also detected as the WIN32.VB.RL TROJAN!
    NTsocketXNoeWinnt.exeAdded by the Ataka-E TROJAN!
    NTsrv.exeXNTsrv.exeAdded by a variant of the SERVU-O TROJAN!
    nTuneUnTune.exenVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
    ntupd32Xntupd32.exe See_Here
    ntupdateXdnsvc.exeAdded by the W32/SDBOT-TC WORM!
    NTupdaterX(Points to the renamed mIRC client.)Added by the Troj/Digarix-D TROJAN!
    NTVDMUNTVDM.EXEWindows NT Virtual DOS Machine (NTVDM) for running 16-bit tasks on the 32-bit OS\'s (Windows NT, 2K and XP). Required if hardware on a machine with these OS\'s needs 16-bit DOS drivers. You can find a bit more about NTVDM here
    ntvdmdXntvdmd.exeAdware downloader - also detected as the TROJ/DLOADER-YP TROJAN!
    ntvdscmXntvdscm.exeAdded by the Troj/ScKeyLog-I TROJAN!
    NuTCSetupEnvironYncoeenv.exeUsed by the MKS Toolkit for Enterprise Developers product. NuTCracker is a Unix runtime environment for Windows, so disabling this would be unwise if you are using NuTCracker or any 3rd party package that is using it. Since you might not know what is actually using it it's probably best left alone
    NVagentXInforme.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    NvagNTXnvagNT.exeAdded by the W32/AGOBOT-RV WORM!
    nvc Win32Xnvcvc.exeAdded by the W32/Rbot-ADD Worm!
    NvClipRsvXswchost.exeAdded by the W32/Dumaru-AK WORM!
    NvClipRsvXrsv32.exeAdded by a Troj/Tofger-X trojan infection
    NvClipRsvXsvchost.exeAdded by the W32/Dumaru-AK WORM!
    NVCLOCK?rundll32 nvclock.dll, fnNvclockOverclocking utility for nVidia based graphics cards?
    NvColorInit?rundll32.exe NvQtwk.dll, NvColorInitAssociated with Nvidia based graphics cards
    NVCOMXNVCOM.exeAdded by the W32/AGOBOT-SB WORM!
    NvCplUNvStartupIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NvCplXNvCpl.EXEAdded by the W32.YANZ.B WORM!
    NvCplUrundll32.exe NvCpl.dllIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NvCplXwindowsp.exeAdded by a variant of the W32/SDBOT WORM!
    NvCplX(random executable)Added by the W32/AGOBOT-APJ WORM!
    NvCplXrundl32.exeAdded by the W32/Agobot-TO WORM! Note: This (rundl32.exe) is not the legitimate Windows process rundll32.exe (Notice the difference in the spelling.) This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    NvCplDXm2gr32.exe "Switch" premium rate adult content dialer
    NvCplDXntcpl.exe "Switch" adult content dialer
    NvCplDaemonNrundll32.exe NvQtwk.dll, NvCplDaemonSystem Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
    NvCplDaemonUrundll32.exe NvCpl.dllIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NvCplDaemonUNvStartupIntializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card
    NvCplDaemonXmsmsgrs.exeAdded by the Troj/Dloader-YI TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    NvCplDaemon32Xanvshell32.exeAdded by the Troj/VB-XU TROJAN!
    NvCplDeamonXnvdisp.exeAdded by the Troj/PeepVie-I TROJAN!
    NvCplDmnXNAVSVC.EXEAdded by an unidentified VIRUS!
    NvCplScanXmsc32.exeAdded by the W32/FORBOT-DD WORM!
    NvCplScanXwinasp.exeAdded by the FORBOT.BZ WORM!
    NvCplScanXnvsc32.exeAdded by the W32.Kelvir.D WORM!
    NvCplScanXkav32.exeAdded by the W32/FORBOT-EW WORM!
    nvd32 lptt01 or nvd32 ml097eXnvd32.exeVariant of the RapidBlaster parasite (in a "nvd32" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    NvidX<8 random charachters>Unidentified adware
    Nvid32XNvid32.exeAdded by the GEMA TROJAN!
    Nvidex32XNvidex32.exeAdded by the GEMA TROJAN!
    NVIDIA ActiveArmorYntrayfw.exeSoftware interface for NVIDIA ActiveArmor - hardware firewall built into nVidia nForce motherboard chipsets
    Nvidia Control DaemonXnksvc32.exeAdded by the W32/AGOBOT-OV WORM!
    Nvidia Control PanelXncsvc32.exeWorm, as yet unidentified
    NVIDIA DriverXMSPMSPSU.EXEAdded by a WORM_WOOTBOT.Y infection
    NVIDIA nForce APU1 UtilitiesNNVATray.exenVidia's nForce Audio Processing Unit (APU) ; provides 3D positional audio and DirectX 8.0 compatibility, and encodes and decodes Dolby Digital 5.1 audio in real time.
    NVIDIA nTuneUnTune.exenVidia nTune - motherboard monitoring and overclocking utility for nVidia nForce chipset based motherboards
    NVIDIA Remote Control Panel?Nvarem.exeNVIDIA graphics card related - what does it do and is it required?
    NVidia System UtilityUNVSystemUtility.exeThe NVidia_System_Utility lets you adjust bus speeds, hardware voltages, memory controller timings, and fan speed as well as additional settings to increase performance aggressiveness and hardware voltages. Will also display a dynamic graph of CPU and system temperatures, hardware voltages, and memory bus speeds.
    NVIDIA Video driversXvideo_32D.exeAdded by the AGOBOT.KV WORM!
    NVIDIA Video driversXvideo_32sD.exeAdded by the W32/RBOT-BB WORM!
    Nvidia32Xnvidia32.exe CoolWebSearch parasite related.
    NvidiaQuickTweak or NVQuickTweakNrundll32.exe NvQtwk.dll, NvTaskbarInitSystem Tray icon used to change display settings for nVidia based graphics cards. Unnecessary since you can easily configure these settings the way you want them in the Display Properties
    nvidll32Xnvidll32.exeAdded by the W32/RBOT-XK WORM!
    NVIEWUrundll32.exe nview.dll, nViewLoadHookThis is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers
    nviload32Xnviload32.exeAdded by the W32/SDBOT-VT WORM!
    nviload32Xnviload32.exeAdded by the W32/SDBOT-VT WORM!
    NvInitializeNrundll32.exe NvQtwk.dll, NvXTInitThought to enable the clock frequency option on nVidia control panels. You can overclock without leaving this enabled
    nvirundllXnvirundll.exeAdded by the W32.SPYBOT.NPS WORM!
    nvjxueXnvjxue.exeAdded by the W32/EYEVEG-J WORM!
    NVmaxYNVmax.exeNVmax is a old tweaking utility for NVidia graphics cards. In the startup list if the user chooses to overclock their card
    NVMCTRAYNRUNDLL32.EXE ...NVMCTRAY.DLL, NvTaskbarInitSystem Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
    NvMediaCenterNRunDLL32.exe NvMCTray.dll, NvTaskbarInitSystem Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
    NVMixerTrayNNVMixerTray.exeSystem Tray access to audio controls from nVidia's motherboard ForceWare software
    nvmsgdwnXNVMSGDWN.EXEAdded by the Troj/Graber-D TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    NvMsnWXIsass.exeAdded by the WIN32.BROPIA.K WORM!
    NVRaidServiceYnvraidservice.exenVidia NVRaid - hard disk striping/mirroring utility for increased performance and reliability. Required if you have a RAID setup
    NVRTNnvrt.exeNVRefreshTool is a utility that will automatically detect the maximum refresh rate at each resolution that your monitor supports
    NVRTClk?NVRTClk.exeRelated to a Gigabyte video card; unsure whether required
    nvsv32.exeXnvsv32.exeAdded by the W32/FORBOT-DI WORM!
    nvsv32.exeXcstr.exeAdded by a variant of the W32/SDBOT WORM!
    nvsv32.exeXasr_fnt.exeAdded by the WOOTBOT.GE WORM!
    nvsv32.exeXnvsv33.exeAdded by the WOOTBOT.FP WORM!
    NvSvcNnvsvc.exeNVIDIA Driver Helper Service - installed when you change from the WDM drivers to nVidia's latest versions but not requied. Extreme shutdown delays can be encountered with this service active, but no adverse side effects with it disabled. NOTE: If using drivers other than nVidia's, such as Asus, this service may have been renamed to reflect that
    NVSVCXnvsvc.exeAdded by the AGOBOT.ALX WORM! - NOTE - do NOT confuse with the legitimate NVIDIA Driver Helper Service file as described here
    nvsvca32Xnvsvca32.exeAdded by the WIN32.TACTSLAY.E TROJAN!
    NVSystem32Xnvscv32.exeAdded by the W32/Agobot-NO WORM!
    NvUpdaterXnwiz32.exeAdded by a variant of the WIN32.RBOT WORM!
    NvXplDeamonXxstyles.exeAdded by the SMALL.AJ VIRUS!
    NWEReboot?dummy.exe??
    nwizNnwiz.exeAssociated with the newer versions of nVidia graphics cards drivers.  Allows you to immensely improve desktop layouts by setting preferences and optimizations.  However, this isn't necessary for the operation of your system
    nwiz32Xnwiz32.exeAdded by the Troj/Sinbank-A TROJAN!
    NwpopupYNwpopup.exeBroadcast message handler part of Novell_Netware that displays server, printer and other messages.
    nwrecmsgUnwrecmsg.exeBroadcast message handler part of Novell_Netware that displays server, printer and other messages - can cause crashes
    nwssUSp0.exeAdded by the SpyOutside surveillance software. Uninstall this software unless you put it there yourself.
    NWTRAYYnwtray.exeNovell Netware. Displays the red "N" tray icon which can be disabled (by right-click on the icon) but is also needed by the client
    oadaemon?oadaemon.exeBackground process that establishes connection with a C3-1000 scanner and watch general status of the device and for scanner button presses. Can it be started manually?
    oahstifrYoahstifr.exeComes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
    OAKSTARTUOAKSTART.EXESets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
    OAKTASKNOAKTASK.EXETaskbar utility for a "control panel" for a CD-RW
    OASClnt?oasclnt.exeMcAfee VirusScan On-Access Scan Client service - what does it do and is it required?
    Object Store ServerYosserver.exeComes with HyperTextStudio. From the supplier - "The Osserver maintains the database for HyperText Studio projects - absolutely vital, it verifies all the links etc in a site. It runs as a service in NT, 2K and XP but needs to start up in Win 9.x so you'll see a DOS box for a short while during boot up."
    objtjprx?objtjprx.exe??
    obsver?obsver.exePart of LingoWare translating software - what does it do and is it required?
    OCAudioIniNOCAudioIni.exeOne-click Audio Converter - allows you to convert files of multiple audio formats right from Windows Explorer
    ocrawareNocraware.exeOptical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications, such as Word, WordPerfect, etc. Available via Start -> Programs
    ocx32Xocx32.exeAdded by the ASTEF or RESPAN VIRUSES!
    OCXUPDT32Xocxupdt32.exeAdded by the W32/AGOBOT-IF WORM!
    ODXSYSCNTR.EXEHotVideo dialler
    od-matrxxXod-matrxx.exeAdult dialler - xx can be any number
    od-stndxxXod-stndxx.exeAdult dialler - xx can be any number
    od-teenxxXod-teenxx.exeAdult dialler - xx can be any number
    ODBC BackUpUfdxxl.exeG Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!
    oddworldz.exeXoddworldz.exeAdded by the Troj/Multidr-EG TROJAN!
    OdometerNOdometer.EXEMouse odometer - tracks how far your pointer/arrow has traveled on the screen. Shortcut available
    ODSPConfigUODSPConfig.exe DsktopSurveil surveillance software - get rid of it unless you installed it yourself!
    OeloaderXOeloader.exeXupiter OrbitExplorer toolbar related, drive-by foistware
    OEM Tools 32Xtres32.exeAdded by a RBOT.QB worm infection
    OEM32 ToolsXsres32.exe W32.SpyBot worm variant
    OEMCLEANUP or OEMRESETNoemreset.exeResets OEM installation settings at bootup. Not required unless you\'re new to PC\'s
    OEMRUNONCEUoemrun.exeWindows Millennium file - used by setup when installing the OEM 'express' version of the operating system. Uncheck after setup has finished.
    oepluginUbxOEPlugin.exe noHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple text.
    OEPowerPlugs?winoeinit.exe??
    OESpamTestUOESpamTest.ExE Kaspersky_Anti-Spam
    OEXCheckNEA2Check.exeExpress Assist from AJSystems.com. Utility for use with Outlook Express to backup, restore, synchronize amongst others
    Offer Companion or OffersXoffers.exeAdvertising spyware
    Office StartupNOsa.exe, Osa9.exeApplication which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required - Note: if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show.
    Office StartupXExploer.exeAdd by the GAOBOT.BV WORM! **Note - This is not a valid MS Office entry
    Office StartupXexploer.exeAdded by the AGOBOT.BV WORM!
    OfficeAgentXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    OfficeAgentXoutIook.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    OfficeAgentXexpIorer.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    OfficeAgentXsvcshost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    OfficeDeamonXmsorunner.exeAdded by a variant of the WIN32.TACTSLAY TROJAN!
    OfficeGuard RegCheckerYogrc.exeKaspersky Labs anti-virus
    OfficeGuardUIXsvcss.exeAdded by the DEDLER-C TROJAN!
    officejet 6100?hposol08.exeAssociated with a HP PSC2110 (and maybe others) all-in-one machine
    OfficeQuickAccessXOfficeHost.vbsAdded by the W32.Pexmor WORM! Note: This worm file is found in the Windows\Temp or Winnt\Temp folder.
    OfficesXmsnmgd32.exeAdded by the W32/FORBOT-DV WORM!
    OfficeScan95Ypccwin97.exeTrend Micro antivirus OfficeScan
    OfficeScanNT MonitorYpccntmon.exeTrend Micro OfficeScan Antivirus real-time scan monitor
    OFFICEXPXOFFICEXP.exeAdded by the WOOTBOT.HE WORM!
    office_updateX(Pathname of the Trojan exe)Added by the Troj/Dloader-ZB TROJAN!
    OfotoNow USB DetectionNRundll32.exe OFUSBS.DLL, WatchForConnection OfotoNowAutodetects when a digital camera is attached to a USB port and launches OfotoNow image software. Available via Start -> Programs
    ogrcYogrc.exeKaspersky Labs anti-virus
    Oil ChangeNOCTray32.exeFrom CyberMedia/Network Associates. Checks for updates to software installed on your PC. Available via Start -> Programs
    OIM?oim.exeRelated to the O2 (was "genie") mobile phone service. What does it do and is it required?
    OLEX(filename)Added by the STAWIN or TARNO.D VIRUSES!
    oleaccrcXoleaccrc.exeAdware downloader - recognized by Kaspersky antivirus as TrojanDownloader.Win32.Agent.am
    OLEDb ServiceXrunoledb32.exeAdded by a variant of the SPYRE.B TROJAN!
    OlehelpXOlehelp.exe CoolWebSearch parasite related.
    olehelpXolehelp.exeAdded by the BOOKMARKER.D or BOOKMARKER.G hijacker/viruses
    OleLoaderXole32.exeAdded by the BACKDOOR.WIN32.DELF.BR TROJAN!
    olesvrUolesvr.exeSalfeld Child_Control_2003 - parental control software
    Olive SystemXSzchost.exeAdded by the MERCURYCAS.A VIRUS!
    OlympicXIE4321.exeAdult content premium rate dialer - also detected as Trojan.Win32.Small.CZ
    Omf4XOMF4.EXEAdded by the FREEMEGA VIRUS!
    OmgStartupNomgstartup.exeSony program called OpenMG Jukebox - player and music organizer
    OmniHTTPdUohttpd.exeOmniHTTPd web server from Omnicron
    OmniPageNOpware32.exePart of OmniPage Pro from Scansoft (was Caere) - "the fastest, easiest way to turn paper documents into digital files you can edit." Opware32.exe links Word, via OLE, with OmniPage. If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs
    OmniPassUscureapp.exeOmniPass from Softex Inc. - secure password management software
    On Screen DisplayUOSD.EXEBy Netropa for HP and other brands. Same group as KBD MediaCenter & Touch Manager. Pressing a "hot key" on such a keyboard brings a corresponding panel on the screen for volume, etc. Nice but not required if you don\'t adjust things regularly - can also freeze
    OneTouch MonitorNOneTouchMon.exe"Finds" the Visioneer scanner to see if it's on then loads it in the tray for quick access which delays the initial boot to desktop process. According to the Windows_Startup_Online_Repository , with the icon in the tray, if you restart or leave desktop, on your return, it again looks for the scanner and again bogs down your system. A desktop icon or star t > programs will provide access without the constant delays. Advise not to load this one in the tray.
    OneTouchMonitor or One Touch Monitor or ONETONOneTouchMonitor.exe 1tou~2.exe ONETOU~2.EXEFor Visioneer OneTouch scanners. System tray access to the control panel for the scanner
    OnflowXonflow.exeOnflow is a internet company that offers an online advertising program. Not required - uninstall
    Online ServiceXsvchost.exeAdded by the HOSTIDEL.B or TARNO.B VIRUSES! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32
    Online ServiceXsvchost.exeAdded by the HOSTIDEL.C VIRUS!. This is not the valid svchost.exe as described here
    OnlinePCfix SmoothSurferUSS.exeSmooth-Surfer - blocks banners, ads, popups, and cleans MRU and Recent file lists
    OnlineTimeNonlinetime.exeOnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs
    online_partyXonline_party.exeAdult content dialler
    Onluna SarviceXsachost.exeAdded by the TROJ/TOFGER-AA TROJAN!
    Onlune SarviceXsachost.exeAdded by the TROJ/DAEMONI-J TROJAN!
    OnSrvrXOnSrvr.exeOnWebMedia adware
    oo4XRunDLL32.EXE oo4.dll, DllRunBookedSpace parasite variant
    OOLHELPT?OOLHELPT.exe??
    OP12 ReminderNEreg.exeRegistration reminder for OmniPage Pro 12 from ScanSoft
    Open Service DriversXopiater.exeAdded by a variant of the WIN32.RBOT WORM!
    Open SiteXopnste.exe OpenSite adware
    Open SiteXopensite.exe OpenSite adware
    Open2EnterXrunme.exeAdult Content Dialler
    Open2EnterXrunme2.exeAdult Content Dialler
    Open32XOpen32.exeHorseserver.net browser hijacker
    OpenGL DriversX0penGLD.exeAdded by the W32/YIMP-A WORM!
    OpenMstartXmcmgr32.exe "Switch" adult content dialer
    OpenMstartXmmgr32.exe "Switch" adult content dialer
    OpenMstartXSnt.exe "Switch" adult content dialer
    OpenOffice.org *.*.*Uquickstart.exe OpenOffice.org office suite quick start (where "*.*.*" is the version number)
    OpenOffice.org xNQUICKS~1.EXEDisplays OpenOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the OpenOffice suite. Available via Start -> Programs. Will automatically be started when any OpenOffice component is started from Start -> Programs. A resource hog (takes > 16 MB of memory). "x" represents the version number
    Openwares LiveUpdateULiveUpdate.exeWeb-update utility as used by various types of software - see here
    Operations Typhoon Rising RegistrationNNOVG.EXE Joint_Operations registration reminder
    OperatorN??Media Pilot operator, in Win.ini. Locks port open
    OperatorUxtmop.exeFax/Phone answering facility for Extreem Machine - as supplied with the old Diamond SupraExpress modems. No longer supported
    OpiStatNOPISTAT.EXEOpiStat is a European Research Institute whose goal is to understand consumer needs and opinions better
    OPQFileXregedit.exe /s ...rad03FA6.tmpUnsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
    oprXopr.exe MediaMotor/Popuppers adware component
    opsql update checkXopsql.exeAdded by the W32/RBOT-ACJ WORM!
    OPTIMIZERXiexplore.exeAdded by the EVIVINC VIRUS! Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) whereas the valid "iexplore.exe" (IE) resides in C:\Program Files
    Optimum OnlineXNetsurf.exeOptimumOnline ISP software related spyware - displays advertising popups and collects information about user activity.
    Optional Web Drivers For WIN32Xphqghume.exeAdded by a variant of the WIN32.RBOT WORM!
    Optus Cable Data MonitorUdatamonitor.exeAllows Optus customers to monitor their actual data usage against Optus' "data allowance limits".
    OptusNetUsageUOptusNet Usage Meter.exeThis product is designed specifically for OptusNet users who wish to have their connection monitored on a frequent basis. It can also estimate when you are going to hit your usage limit, and how far over your suggested limit you should be.
    Opware12NOpware12.exeOmniPage Pro 12 from ScanSoft
    Opware14NOpware14.exeScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs
    OpwareSE2NOpwareSE2.exeScanSoft's OmniPage_Pro_14 - If running, a user can call up OmniPage from inside of Word and ask it to scan something, via "File, Acquire Page." Also some of OmniPage's Options dialog boxes are accessible from within Word. Only required by novices and is Available via Start -> Programs
    OrbitUpdateXupdate.exeXupiter OrbitExplorer toolbar, drive-by foistware
    OrbitViewXview.exeXupiter OrbitExplorer toolbar, drive-by foistware
    OrderReminderNOrderReminder.exeThe HP Order Reminder utility is installed with the HP LaserJet printer software and allows you to set specific times for reminders to check the current level of toner in the print cartridge - it also contains an Order Now link to a Web page that helps you order supplies online from a reseller of your choice.
    org5.exe?org5.exeLotus Organizer 5 application file, Lotus Organizer software. What does it do and is it required?
    OrgyCamXOrgyCam.exeAdult content dialler
    OrigRage128TweakerURAGE128TWEAK.EXEThird party tweaker for ATI Rage 128 Video cards from http://www.rageunderground.com
    ORiNOCOUCmluc.exeClient Manager software for an ORiNOCO wireless LAN card
    OS SecurityXmswind32.pifAdded by the W32/Rbot-ASU WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    OSAXwinword.exeAdded by the Trojan.Kangenie TROJAN!
    Osa32XNTOSA32.exeAdded by the ANIG VIRUS!
    OSSXossproxy.exe NetSetter/Marketscore foistware
    OSSXrk.exeRelevantKnowledge, NetSetter/Marketscore foistware variant
    OSSXrlvknlg.exe MarketScore/Relevant_Knowledge adware related.
    OSSProxyXOSSPROXY.EXE NetSetter/MarketScore foistware
    OStivityInvAgtUostivity.exeOStivity - "a desktop and server hardware and software asset/inventory solution for small to enterprise sized organizations that need to quickly gain knowledge of 'what's installed' without having to manually touch every computer in the company. The next time the computer logs into the network, a complete inventory (software and hardware) is taken of the system"
    OsusXacao.exe PurityScan/Clickspring adware
    OsusXrrup.exe PurityScan/Clickspring -Adware - The executable is located in the user's "Application Data" folder or the Program Files\htwu folder.
    otcxXotcxxh.exeAdded by the CAROOL VIRUS!
    outlookXoutlook.exeAdded by the W32/SDBOT-RU WORM!
    Outlook Express ConfigX*****.exe (where * = random char)Added by a variant of the WIN32.RBOT WORM!
    Outlook Express ProtocolXlook.exeAdded by the W32/RBOT-ACS WORM!
    Outlook Mail ServicesXexpress.exeAdded by the RBOT.CJN or W32/RBOT-ATJ or W32/SDBOT-AEM WORM!
    OutLooksXInSane.exeAdded by the SWOOP TROJAN!
    Outpost FirewallYoutpost.exeOutpost personal firewall
    outpostupdateXoutpostupdate.exeAdded by the Troj/Cosiam-C TROJAN!
    OutwarXsyslaunch.exeOutwar adware downloader
    OVCJ?ovcj.exe??
    OvernetNOvernet.exeOvernet peer-to-peer (P2P) file sharing program
    ovyriwiXtelace.exeAdded by the SDBOT.BVS WORM!
    OWCCardbusTrayUocbtray.exeIcon in the system tray for safely removing PCMCIA cards. Only required if you have a laptop or desktop which includes a PCMCIA card interface
    OWCWebCamDVUwcdvtray.exeWebCamDV from Orange Micro, Inc - enables the user to use a DV camera connected via Firewire as a Webcam
    OWMngrXOWMngr.exe OnWebMedia/SearchSeekFind advertising foistware
    OxigenClientAdminUOxigen.exeOpen University Oxigen screensaver admin client. Downloads the latest information from the net to display in the screen saver.
    oz2Xoz2.exeAdded by the W32.Mydoom.W WORM!
    P0w3rF1YXsvchost.exeAdded by the Troj/Bdoor-MM TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    P17Helper?Rundll32 P17.dll,P17Helper ASIO driver for the Sound Blaster Audigy & Audigy 2 series sound card - is it required in startup?
    P2P NETWORKINGNP2P Networking.exe p2pautostart.exeP2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required; see here
    P2P NetworkingNP2PPeer to Peer (P2P) sharing of files on the internet
    P2P Networking2X P2P Networking2.exeP2P Networking2.exe is an advertising program by Joltid. This process monitors your browsing habits and distributes the data back to the author's servers for analysis. This also prompts advertising popups. This program is a registered security risk and should be removed immediately.
    P2P Networking3NP2P Networking3.exeP2P Networking, a component bundled with Kazaa that enables other applications to use Peer-to-Peer functionality. Not required; see here
    p2pnetworkXp2pnetwork.exeAdded by the ALCAN.A WORM!
    p2pnetworkingXp2pnetworking.exeAdded by the W32/Rbot-AFL Worm!
    P3p4chkXP3p4chk.exeAdded by the GEMA TROJAN!
    p4mx4Xp4mx4.exeAdded by a CRYPTER.A trojan infection
    PaciSoftXpacis.exe PacerD_Media/Pacimedia.com adware installer
    Packard Bell EverSafe Tray Control?TrayControl.exePackard Bell EverSafe software. What does it do, and is it required?
    PadTouchNPadExe.exeToshiba Touch and Launch, offers easy movement and freedom of programs navigation with TouchPad.
    Pagekeeper Jobs or Pagekeeper LiteUpkjobs.exePageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etc
    PAgentXPAgent.exeScans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local filesystem for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is found. See here for more info
    Pagis SchedulerNMonitor.exeScheduler for the Pagis scanning suite from Scansoft. 
    pagmstart?client.exePossibly related to this?
    PagooNPAGOO.EXEPagoo - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem
    paint.exeXshnlog.exeAdded by the TROJ/PUPER-A And Troj/Puper-D TROJANS!
    PaintingRoom evidence monitorXpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
    PaintingRoom smile monitorXpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...
    Palm MultiUser Config?Configtool.exeMultiUser configuration for a Palm PDA device?. Is it required?
    Palm.exeNPalm.exePalm Desktop Software for use with Palm handheld devices. Available via Start -> Programs
    PalNetawareXpnetaware.exe PalTalk
    PaltalkNetaware.exeNPALNETAW~1.EXEVoice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start -> Programs. Delete the shortcut in Start -> Programs -> StartUp as well otherwise it will be reinstated
    pamela.exeUpamela.exe Pamela is a plug-in or add-on that adds features to Skype peer to peer voice service. Note: Located in the Program files\Pamela folder.
    Panda Antispam Server ServiceUPasSrv.exeAntiSpam software, part of Panda Platinum_Internet_Security
    Panda CleanerYpavdr.exePanda Antivirus related - possibly Panda ActiveScan
    Panda Preventium+ ServiceYPREVSRV.EXE Panda_Titanium Antivirus
    Panda Software IntrenetX"panda.pif"Added by W32/RBOT-ATZ WORM!
    PandaAVEngineXPandaAVEngine.exeAdded by the W32.NETSKY.R WORM!
    PandaSchedulerUpavsched.exePanda Antivirus scan scheduler. Required if this is your virus scanner program and you have scans scheduled on a regular basis. I recommend that you scan manually so you don't need this but if you tend to forget then leave it
    PanteraXpantera.exeAdded by the SDBOT.AYN WORM!
    PaperportNrunppdrv.exeLoads the drivers associated with monitoring scanner status associated with PaperPort software. Can be a resource hog - see here
    PaperPort PTDNpptd40nt.exe"PaperPort" software associated with scanners
    PaperQuote System Tray IconNPQTRAY.EXEPaperQuote is a "wallpaper" changer with daily quotes that are either for inspiration or motivation
    Parallel TaskingXptask.exeAdded by the TROJ/SMALL-CJ TROJAN!
    PartSealUPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
    Password Door LoaderUPDMonitor.exePassword Door - password protection software
    PasteListerNplister.exePasteLister - clipboard extender. Start manually when required
    PatchXpatch.exeAdded by the W32/NetBus TROJAN!
    Patches ValueXWinGamed.exeAdded by a SDBOT.BR worm infection
    Path?lide.exe??
    pathnameXpathname.exeAdded by the BACKDOOR.IRCCONTACT TROJAN!
    PathNvidiaTV?patchnvidiaTVout.exeAppears to be related to Nvidia Gigabyte Video card. Typical file location is the Program Files\Gigabyte\Nvidia folder.
    PAV.EXEX%Number%Added by the KITRO.D (or ARGEN.A) VIRUS!. %Number% can be any number
    PAV.EXEYPAV.EXEPER Antivirus
    PAVFIRESYPavFires.exePanda Antivirus
    PAVFNSVRYPavFnSvr.exe Panda Titanium Antivirus
    Pavkre9xYpavkre9x.exe Panda_Titanium Antivirus
    PavProcYPavPrS9x.exe Panda Titanium Antivirus
    PavProtYPavProt.exe Panda Titanium Antivirus
    Pavprot9YPavprot9.exe Panda_Titanium Antivirus
    PayTimeXpaytime.exeAdded by Troj/StartPa-YR or Troj/Paymite-C TROJAN!
    pbagentUpbagent.exe Probot keystroke logger/monitoring program - remove unless you installed it yourself!
    PC Alert IIIUalert.exeMSI PC Alert III - allows you to view your system and cpu temperature, fan rpm and more. Only required if you overclock
    PC BoosterUpcbooster.exePC Booster from inKline Global - "easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"
    PC Dynamics SdwMon32Usdwmon32.exe SafeHouse "Personal Privacy" protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted.
    PC-Config32Xcorona.exeAdded by the CORONEX.A VIRUS!
    PC-Duo System SnapshotUCLBOOT32.EXE PC-Duo_Remote_Control from Vector. "System Snapshot provides a detailed inventory of a Client's hardware configuration. It includes information on CPUs, memory, operating systems, printers, display drivers, disk size and free space, network details and much more!". For tech support users to provide remote assistance
    pcAnywhere AgentUpcamgt.exePart of pcAnywhere 9.0 or later. This process listens for incoming PC Anywhere connections if your PC is configured as a PC Anywhere host.
    PCBODYGUARD or PCBGYPCBODYGUARD.EXEPC Bodyguard from Calluna - protects system files and settings from being deleted, modified, etc
    PCCClient.exeYPCCClient.exePC-Cillin 2002 antivirus software
    pccguide.exeYpccguide.exePC-Cillin 2002 antivirus software
    PCCIOMON.EXEYPCCIOMON.EXEPC-Cillin 2000 antivirus software. This is the actual virus-scanner
    PCClient.exeYPCClient.exeTrend Micro PC-cillin Internet Security
    PccPfwYPccPfw.exeTrend Micro PC-Cillin personal firewall
    PcCtlComYPcctlcom.exeTrend Micro PC-cillin Internet Security
    PCDRealtimeNrealtime.exeApparently the monitoring device for PC Doctor Online. It provides a "free" examination on system files (i.e. registry), reports the number of errors it finds, and invites you to "order" the fee-based fixes from its web site.
    PcEXPLODEXspecialfile.exeAdded by a RBOT.RH worm infection
    PCHbuttonNPCHbutton.exeUsed by HP Instant Support
    PCHealthNpchschd.exeThis is a "scheduler" and does not turn off PC Health. For more information refer here
    PCHEasySearchXSTUpdate.exePCH EasySearch bar
    PCIMODEM?pcimodem.exeAssociated with Lucent based Aztech MDP7800-U PCI modems. Is it required?
    PCLEPCIUppe.exePinnacle Systems PCI Performance Enhancer. "This tool helps to increase the PCI Busmaster performance of all Pinnacle PCI boards."
    PClKXPClK.exeAdded by the Troj/LegMir-BL TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    PCMCIA Resource Monitor?nvp2pmon.exeNVIDIA nForce P2P Driver - what does it do and is it required?
    PCMService?PCMService.exeIn a Dell\Media Experience sub-directory
    PCprotXcrcss.exeAdded by an unidentified WORM!
    pcqmqgn.exe?pcqmqgn.exe??
    PCRecSAUPCRecSA.exePart of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a "clean" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need to
    pcServerXserver.exe "Ssppyy" spyware
    PCShieldXregsvr32 /s [path] sfg_****.dll SafeguardProtect/Veevo malware, where * is a random char or digit
    PCStartNPcm25.exeRuns as part of PCMonitor which is a program for monitoring your activity on your system. It makes screen dumps and key logging. It can hang-up your system because the screen dump page gets VERY big
    PCSuiteTrayApplicationNTrayApplication.exeSystem Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu.
    PCSuiteTrayApplicationNLaunchApplication.exeSystem Tray icon for Nokia PC Suite. PC Suite lets you synchronize, edit, and back up many of your phone's files on a compatible PC through a wireless or cable connection. PC Suite can also be launched through Start Menu.
    PcsvXpcsvc.exe Delfin_Media_Viewer or "Promulgate" adware
    PcSyncNPcSync.exeIf a Nokia phone has been connected, synchronises the phone with MS Outlook or other organiser software. It is installed by the Nokia PC Suite, and the tray icon shows if a phone has been connected. Available via a desktop shortcut or Start -> Programs
    PcSyncXPCsync.exeAdded by the W32/RBOT-XJ WORM! - NOTE: do NOT confuse with the Nokia application described here
    pctspkUpctspk.exeUsed for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
    PCTVOICEUpctvoice.exeThe program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It’s better to leave it
    PCTVOICEUpctspk.exeUsed for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functions
    PCWatchUpcwatch.exeAdded by the Spyware.PCWatch surveillance software. Uninstall this software if you did not install it yourself.
    PDA CommanderXstisvc32.exeAdded by W32/Agobot-TX WORM!
    PDASCANXpdascan.exeAdded by the W32/AGOBOT-QY WORM!
    PDEngineUPDEngine.exePerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-boot
    pdexploNPDEXPLO.EXEPowerDesk Pro by Ontrack. Enhanced desktop and file manager. Available via Start -> Programs
    PDF Converter Registry Controller?RegistryController.exeScanSoft PDF_Converter related - what does it do and is it required?
    pdfFactory Pro Dispatcher v1Nfppdis1.exe"With pdfFactory you can create PDF documents from any program printing to the virtual PDF printer". Available via a desktop shortcut or Start -> Programs
    pdfMachine dispatcherUmapisnd.exe pdfMachine Windows print driver
    pdfSaver3NpdfSaver3.exe PDF-XChange - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher etc.
    PDirectNPDirect.exeIBM Presentation Director software
    pdp ServerUctpdpsrvr.exeIncluded and setup with the drivers for my Compaq A3000 all-in-one printer/scanner - maybe for networking. Works fine without it - but may be needed when used over a network
    PDUiP6000DMonUPDUiP6000DMon.exeRelated to Canon iP6000D printer
    PDUiP6000DTskbrUPDUiP6000DTskbr.exeRelated to Canon iP6000D printer
    PDVDServUPDVDServ.exeRemote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one
    Pe2ckfnt SENchkfont.exeUsed to check whether the fonts are installed properly on your computer or not for a scanner. If you don't want to execute it, you can uncheck it in the startup menu
    Peeramid?PService.exeIn a "Koptimizer" folder in Program Files - what is it and is it required?
    PeerGuardianNPeerGuardian_1.99b_pr14.exe PeerGuardian "is a tiny firewall program especially designed for P2P software users, but also for anyone who is concerned about the investigations that corporations and authorities perform on the internet. PeerGurdian blocks connections for the configured IP ranges and logs the blocked connections."
    PeerGuardianUpg2.exe PeerGuardian is an IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists, a list editor, automatic blocklist updates, and blocking all of IPv4 (TCP, UDP, ICMP, etc).
    Pent@VALUE 3.2UPent@VALUE.exePent@VALUE Digital Satellite Internet PC Receiver
    PeqBL100XPEQBL100.exeAdded by the W32.PEQ WORM!
    PER Email ProtectionYpavmail.exePER Antivirus
    PerfectPrintNpfppop70.exePrint engine used by Corel WordPerfect 7 and Presentations 7
    Perfomance MonitorXdavcsync.exeAdded by the W32/Lamud-A Worm!
    Perfomance SettingsXsvchost.exeAdded by the TROJ/TOFGER-AP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    PerformClXperfcl.exeadware downloader and installer
    PersFwYPersFw.exeKerio or Tiny Personal Firewall
    PersistenceNigfxpers.exeAssociated with the Common User Interface module for Intel graphics cards
    Personal ComputerXscvhost.exeAdded by the W32/Rbot-AJE WORM! Note: This trojan file scvhost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item.
    Personal FirwallXptmedsrv.exeAdded by the SDBOT.XY WORM!
    Pervasive.SQL Workgroup EngineUW3dbsmgr.exeDatabase Service Manager for Pervasive SQL 2000 Workgroup edition. Required if you use Pervasive SQL but it's recommended you start it manually before using it as it has a tendancy to crash/freeze if loaded with other applications at startup
    PestPatrol Control CenterUPPControl.exePestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
    PestPatrolCLUPestPatrolCL.exe PestPatrol's command line scanner, combines with the Windows Task scheduler and is required in cases where schedules for regular scanning are set
    Petit Larousse 2001UHIPL2000Popup.exePopup dictionary tool
    Pex Sound DriverXToday's Results.vbsAdded by the W32/Trode-A WORM!
    pex Sound driver 2XToday's Results.vbsAdded by the W32/Trode-A WORM!
    PFW_CfgEngine?PFWCFG~1.EXEPersonal Firewall related?
    PFW_PullSrv?PULL.EXEPersonal Firewall related?
    PgMonitrXPgMonitr.exe Delfin_Promulgate adware variant
    PGPSDKSVCYpgpsdkserv.exePGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionality
    PGPSERVICEUpgpservice.exePGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a "fall-back" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big difference
    PGPtrayNpgptray.exePGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start -> Programs
    PGStub.exeXUnidentified adware
    pgtaffXpgtaff.exe AdRotator adware variant
    Phime2002a or PHIME2002ASyncNTINTSETP.EXEPart of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
    PHIME2OO2ASystX(Pathname of the Trojan exe)Added by the Troj/DBdoor-B TROJAN!
    PhoneFree version 6.2UPHONEF??.EXEAn Internet telephony application. Complicated registration and ad banners tailored to your profile - see here
    Photo Express Calendar Checker SENCALCHECK.EXEIf you create multiple Weekly/Monthly/Yearly calendars to use as your wallpaper, Photo Express will replace the wallpaper automatically. Photo Express 2.0 has a calendar checker which checks the date on your system and updates your wallpaper accordingly
    Photo Loader supervisoryNPlauto.exeCasio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your pictures
    PhotoshopXsvchost.exeAdded by the Troj/Cdopen-E TROJAN! Note: This file is usually located in the Program Files directory.
    PhotoShow Deluxe Media ManagerNmssysmgr.exeSimple Star PhotoShow_Deluxe photo editing and organizing software; makes it easy to send and share digital photos.. Bundled with software from Nero, ComCast, SnapFish, MacroMedia and others.
    PhotoWise QuickLinkNquicklnk.exeAgfa PhotoWise - "PhotoWise QuickLinkTM lets you drag and drop photos right from the camera into your document (applications must be OLE-compliant). Use PhotoWise to print contact sheets and photographic prints. Create slide shows, screen savers, wallpaper and more."
    PIC SYSTEMXpicx.exeAdded by the MYTOB.LL WORM!
    Picasa Media DetectorNPicasaMediaDetector.exeMedia detector for Picasa's automatic photo organizer
    PicasaNetNHello.exe Hello is an application that allows Blogger users to post digital photos and captions directly to their personal weblogs, or blogs.
    PickatagNpickatag.exePick-a-tag - "Freeware utility for random selection of your taglines. This utility randomly picks a tagline out of a list of taglines. It will create a signature file which your mailer can use to place under your messages"
    PICPRTRNPICPRTR.EXEProgram for viewing and measuring a variety of 3D CAD data formats
    picsvrXpicsvr.exe Delfin_Promulgate adware
    pictureBUZZTrayNswtray.exeSystem Tray access to PictureBUZZ on-line printing software from Streetwise Software. If you use the software set the page you use as a favourite in your browser and run it manually
    PiDunHKUPIDUNHK.EXEPart of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happens
    piiserviceOEUN/ASpam Inspector (nee Postal Inspector) from The Giant Company or iHateSpam from Sunbelt Software - spam filter add-ons for OE
    pilifXpilif.exeAdded by a W32.Fili worm infection
    PingerNpinger.exePinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification
    PingTimeout InstitutionXpingchek.exeAdded by the W32/SDBOT-VY WORM!
    PinnacleDriverCheckYPSDrvCheck.exePart of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
    PioletNpiolet.exePiolet - peer-to-peer file sharing client
    PIPE SYSTEMXpipe.exeAdded by W32/Mytob-FF WORM!
    PiracyNSysUtil.exe"Software Piracy Alert" feature bundled with PGWare software. Cries foul when it detects an 'illegal' version. The alerts are reported to disappear as soon as the software is correctly registered. There are privacy issues though: "The Software includes a feature that assigns a unique order number to GameGain based on purchase information. The Software reports this number to us via the internet either when you run the Software or enter the registration number, or both. The Software may also identify and report to us your IP address, date and time of installation, registration and/or use. We use this information strictly to count the number of installations, detect unauthorized access or piracy of the Software, and develop rough statistical data regarding the geographic location of our users."
    PivotSoftwareNwpctrl.exePivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
    Pixel32XPixel32.exeAdded by the GEMA TROJAN!
    Pixelpwr32XPixelpwr32.exeAdded by the GEMA TROJAN!
    PixelsvrXPixelsvr.exeAdded by the GEMA TROJAN!
    pjWebCamUpjWebCam.exeWebcam automation software that saves regular photos from webcam and can also act as HTTP server
    PK GuardXpkguard32.exeAdded by the W32.Guapim WORM!
    PK ServicesXpksvc.exeAdded by the W32/FORBOT-BW WORM!
    PktAnythingUPocketCompanion.exe PocketAnything lets you save anything on your computer to your mobile, with one click.
    PlanlćgningsagentUmstask.exeWindows Task Scheduler (on Danish language versions of Windows) - displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on.
    PlaxoUpdateUInstallStub.exeInstallstub.exe is is Plaxo's core executable program, which is used to check for new or updated information from the Plaxo Network. This program also interacts with Outlook.
    PlayboyXplayavi.exeAdded by the PWSteal.Gamanlock TROJAN! Note: This trojan file is found in the Windows\java or Winnt\java folder.
    PLEAPCPUCPLUpleapu.exeCPU Control Panel for the Powerleap CPU upgrade
    PLFFAP?HotfixQ0306270.exeProlific Technology Inc. USB Flash Disk driver is it required in startup?
    PlguniNPlguni.exeMcAfee QuickClean 3.0 - removes internet clutter and unwanted programs
    plmg.exeUplmg.exeParagon Last Minute Bidder - auction assistant software
    PLoader?umsd.exeUSB Mass Storage Disk related tray icon. Is it required?
    PlobXkernel.comAdded by the OPTIXPRO.12 VIRUS!
    PlookXplook.exeAffiliateTarget.com alias PLook adware
    Pluck TrayUPluckTray.exeRSS (XML TAGS) reader program
    PluckSvrNPluckUpdater.exe Pluck Toolbar updater
    Plug And PlayXmsnmsg.exeAdded by the W32/RBOT-ID WORM!
    PLXSTARTUPLXSTART.EXESets the spindown timeout and access speeds at startup and displays the "Plextor Manager 2000" splash screen for Plextor CD-RW.
    PLXTASKNPLXTASK.EXETaskbar utility for a "control panel" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)
    pm32ctrlXpwr32crtl.exeAdded by a CRYPTER.A trojan infection
    pm32infoXpm32info.exeAdded by a CRYPTER.A trojan infection
    pmcX764.exeAdult content dialler
    pmcqtXpmcqt.exeAdded by the Troj/Dluca-V TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    PMediaXwinsrvc.exeInternet marketing sofware from PMedia as used in E-Card FriendGreetings foistware - see here . Treated by Trend as the FRIENDGRT.B WORM!
    PmProxy?PmProxy.exeAssociated with Analog Devices "SoundMAX" audio chipset - often built-in to motherboards. What does it do and is it required?
    pmrXpmr.exePowerstrip foistware variant
    PMTUpersonalmoneytree.exeAccording to the web site Personal_Money_Tree is an automatic cash rebate program. Note: Not recommended.
    PMTSHOOTNpmtshoot.exeMS tool for troubleshooting power management problems
    PMXInitUpmxinit.exeRestores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gamma 
    PNAgentNPNAgent.exePhatNoise Music Manager - manages WMA, MP3, WAV, etc music files
    PNPXwuaaclt.exeAdded by the W32/Lilbre-A WORM!
    PnP DriverXplayboy.exeAdded by the W32/Forbot-FR WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. Added Note: This malware can collect system information, add or delete shares and users, kill processes, download and execute files, send email, remotely control a connected web cam, sniff network traffic or launch a denial-of-service attack!
    PNP FIXX(Worm filename)Added by the W32/Rbot-AKQ WORM!
    PnpchkUPnpchk.exeAztech Labs Sound 3 PnP driver
    pnpsvc_lockXstartsvs.exebrowser hijacker
    pnpsvc_lockX******.exe (* = random digit)browser hijacker
    PNSetupUPNSetup.exePopNot - pop-up killer
    PNtask ServicesXpntask.exeAdded by the LALA.C VIRUS!
    Pocket Sheet SyncUPSXLTRAY.EXECasio Pocket Sheet synchronization software
    PoetPoet.exeAdded by the DOEP.A VIRUS!
    PofatchXnstrue.exeAdded by the RANDEX.Z VIRUS!
    point32Upoint32.exeMicrosoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    POINTERUpoint32.exe Microsoft_Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
    Points ManagerNpoints manager.exeAltnet TopSearch adware
    PollonXpollone.exeAdded by the SPYBOT.FW WORM!
    polo.exeXpolo.exeAdded by the Troj/Agent-PE TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    POPXPopSrv***.exePeopleonPage foistware, bundled with Grokster where *** are random digits
    Pop-Up SmasherUPopupSmasher.exePop-Up Smasher - pop-up killer
    Pop-Up StopperUdpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    Pop-Up_BlockerUPopup.exeA Tweak-XP component, blocks advertisement pop-up windows in Internet Explorer. Can be enabled/disabled via Tweak-XP -> Internet Tweaks
    Pop-Up_ScannerUPopupscn.exe Panicware popup blocker
    pop3trap.exeYpop3trap.exePC-Cillin 2000 antivirus software -> E-mail scanner
    PopeSvrXPopeSvr.exeAdded by the Troj/LegMir-AJ TROJAN!
    PopMarkXWinTask.exe"Pop Marketing" adware
    PopNotUPopNot.exePopNot - pop-up killer
    PopOopsUPopOops.exePopOops - pop-up killer
    PopopenUpopopen.exePopOpen makes your windows spring open with animation effects
    PoproxyYPOPROXY.EXEProxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning it
    popsrv146Xpopsrv146.exePeopleOnPage online dating browser enhancement - also adware and privacy issues, see here. For removal instructions see here
    PopSubtractUPopSub.exePopSubtract - pop-up killer
    Popup Ad FilterUPopFilter.exePopup Ad Filter - pop-up killer
    Popup Blocker SystemXPopUpBlocker.exeAdded by a variant of the WIN32.RBOT WORM!
    Popup Blocker System326a MonitoringXPopUpBlocker6a.exeAdded by the RBOT.AUH WORM!
    Popup Blocker System8 MonitoringXPopUpBlocker8.exeAdded by a variant of the WIN32.RBOT WORM!
    Popup Blocker UpdaterXregsvr32 veev****.dll SafeguardProtect/Veevo
    Popup Defence UpdaterXregsvr32 [path] pdfupd.dll SafeguardProtect/Veevo hijacker
    Popup Defence Updater (required)Xregsvr32 /s [path] pdf****.dll (* = random char/digit) SafeguardProtect/Veevo hijacker
    Popup DefenderUPD.exePopup Defender - pop-up killer
    Popup TerminatorUGLADManager.exePopup Terminator - pop-up killer
    PopupEliminatorUPopup Eliminator.exePopup Eliminator - pop-up killer
    PopUpKillerUPopUpKiller.exePopUpKiller - pop-up killer
    popuppersXnewpop63.exe Popuppers adware variant
    popuppers64Xa64sddd.exePopuppers adware, also detected as the TROJ/LOWZONE-AA TROJAN!
    popuppers65Xa65d.exe Popuppers adware variant
    popuppers65Xa64sddd.exe Popuppers adware variant
    PopUpStopperCompanionUPSComp.exe PopupStopper_Companion popup blocker
    PopUpStopperFreeEditionUPSFREE.EXEPnaicware's Pop-Up Stopper - free limited features version
    PopUpStopperProfessionalUPopUpStopperProfessional.exe Panicware's Pop-Up Stopper - paid for version
    PopupVanishUPopupVanish.exePop-up blocker
    PopUpWasherUPopUpWasher.exe PopUpWasher pop-up killer
    PopUpWatchUPopUpWatch.exePart of BPS Trace Remover - made by the folks who "developed" BPS Spyware Remover which reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!
    POS-Partnerbatchprocessor?BATCH.EXEVISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start -> Programs or a manually created shortcut?
    Post-It(r) SoftwareNPsnotes.exePop-up "yellow" notes on screen. Available via Start -> Programs
    POW!Upow.exePop-up killer
    Power ScanXpowerscan.exe"Foistware" by Integrated Search Technologies - the people behind the ISTbar parasite
    PowerBarNPowerbar.exePart of CyberLink's PowerDVD software; not sure what exactly it does, but not required in startup
    PowerChuteYPwrchute.exe"During a power outage, if you're not available to save your files & close down Windows....PowerChute will do that for you. PowerChute will save your application files, close your applications and shut down your computer just like you would...otherwise, the APC UPS (Uninterruptible Power Supply) unit would go to battery until it wore down, then your computer would shutoff"
    PowerChuteXPwrchute.exeAdded by the Troj/Lazar-A TROJAN! Note: This trojan file is found in the Windows\Program Files>\APC_Power or Winnt\Program Files>\APC_Power folder.
    PowerDOCSAPIHostUpapihost.exeHummingbird PowerDOCS - "delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"
    PowerDVDNPowerDVD.exeLaunches Cyberlink's PowerDVD software and creates a system tray icon. If enabled, PowerDVD will open automatically when a DVD movie is inserted. Launch manually
    PowerKeyUPowerKey.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610
    PowerManagementXRundlll.exeAdded by the SURDUX VIRUS!
    PowerManagerXSvchost.exeAdded by the JEEFO VIRUS! Note - this is not the valid svchost.exe as described here
    PowerPanelYPOWPANEL.EXEPower management utility on notebooks/laptops - automatically switches modes when running on battery
    PowerPrifileXrundl132 kenel.dll, PowerProfileEnableAdded by the INMOTA VIRUS!
    PowerProUpowerpro.exePart of the power professional program that loads the floating menu bar. Can be accessed from Start -> Programs, but I'd leave it alone if you use this program
    PowerProfXPowerProf.exeAdded by the WIN32.LOREX.B TROJAN!
    PowerProfileXmfcp30.exeAdded by the RINDAS-A TROJAN!
    PowerQuest Startup UtilityNPQINIT.EXEFrom a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems"
    PowerReg SchedulerNPowerReg Scheduler.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
    PowerReg SchedulerV2NPowerReg SchedulerV2.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
    PowerReg SchedulerV3NPowerReg SchedulerV3.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst others
    POWERR~1?POWERR~1.exePower monitoring?
    PowerS?PowerS.exeProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?
    PowerSet?Regedit.exe /s ...PowerSet_8100_CU.REGAppears to be Toshiba power management related
    PowerStripNpowerstrip.exePowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
    PowerStripNpstrip.exe PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings
    PowerTools Tray IconUpttray.exePowerTools - add-on for AOL
    PowertweakUPT2.EXE"Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if \'Use predefined settings\' is enabled in the programs options
    PowertweakUPTCTRL.EXE"Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured." This item is added to startup if \'Configure system at logon\' is enabled in the programs options
    Power_GearUBatteryLife.exePower management for all Asus notebook. Useful but not critical.
    PP****usbNFBDirect.exeSoftware that monitors the status of a Visioneer OneTouch scanner button and allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop!. The **** represents the model, 5300, 7600, etc. Available via Start -> Programs
    PP2000 InstaupdateUPPInupdt.exeProtector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
    PP2000 Real Time ScanYPPVstop.exeProtector Plus anti-virus software - real time scanner
    PP2000 Taskbar ControlYPPTbc.exeProtector Plus anti-virus software - system tray access
    PP3100bNflatbed.exeTwain driver for the Visioneer PaperPort 3100b scanner that allows you to scan, fax, copy, print, and easily communicate by simply dragging and dropping scans on your PaperPort Desktop
    ppassUAntispy.exeAntiSpy firewall - "program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide"
    PPControlUPPControl.exePestPatrol Control Terminal - launches PestPatrol features such as PPMemCheck and CookiePatrol
    PPCRunonce?PPCRunOnce.exeRelated to PeoplePC ISP software - what does it do and is it required?
    PPHIDPADUpphidpad.exe PenPower Chinese handwriting recognition software
    PPK Setup(Server)USEServe.exeProgrammable Power Key on Sony Vaio laptops. "Using the Programmable Power Key (PPK) button, collect your e-mail automatically with one key stroke. You can also program your PPK to turn on your SuperSlim Notebook at a predetermined time and perform simple tasks - completely unattended"
    PPMemCheckUppmemcheck.exePPMemCheck - "extends PestPatrol's power so that the most dangerous Pests -- those that are about to execute -- are found, terminated, and cleaned from a user's system"
    PPPOEOXpingppac.exeAdded by the W32.Spybot WORM!
    PPPOEOEXWINLITE.EXEAdded by the W32/RBOT-AAN WORM!
    PProTrayNpprotray.exePart of the power professional program. Loads the System Tray control
    PPSVCU[path to file] PC_Police is spyware that logs keystrokes, files looked at, applications used, and chats on either MSN, Yahoo, ICQ or AOL. This information can then be transmitted to a remote user. If you didn't install this yourself remove it.
    pptd40ntNpptd40nt.exe"PaperPort" software associated with scanners
    PPUpdateUppupdater.exePPUpdater - "is the update program that ships with PestPatrol. It is able to update licensed and evaluation versions, and presents a visual display of what it is doing". Run manually unless you think you'll forget to check for updates on a regular basis
    PPWWebCapNPPWebCap.exe"PaperPort" software associated with scanners
    pqhelperXpqhelper.exeSearchcentrix hijacker
    PractiSearchUPSearch.exePractiSearch web search software
    Praize MessengerUitLoad.exePraize IM Christian chat instant messenger
    PrayerUPTW.EXEIslamic Adhan program (call fpr daily prayers)
    prdtectXprdtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prmtect.exe and so forth!
    PreAnnotate?PreAnntt.exeGenius Wizard Pen Tablet driver related. Is it required?
    Precision Time Clock CheckerNPrecisionTime.exePrecision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
    PrecisionTimeXPrecisionTime.exe PrecisionTime - clock synchronizing software containing adware by Claria/GAIN
    precpop2Xstarter.exePrecisionPop adware
    PreinXAPP****.tmp (* = random char or digit)Unidentified adware
    PreloadYPreload.exeMillenium Multi-Function Keyboard driver
    PreloadApp?hphprld.exeHP PhotoSmart printers related - what does it do and is it required?
    PremeterXprmt.exeNetRatings software by Opistat. "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
    PremeterXnrpr.exeNetRatings software by Opistat . "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
    Preview AdServiceXPrevAdServ.exe Windupdates Adware Variant
    PrevxHomeYSAGUI.exe PrevX_Home intrusion prevention software
    PrevxOneYPXConsole.exe Prevx intrusion prevention software
    PrevxProYSAGUI.exe Prevx_Home intrusion prevention software
    prgtectXprgtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    Price PatrolNneo.exePrice Patrol by Half.com - internet shopping companion for finding the best on-line prices
    PrimaLauncher?Launcher.exeAssociated with PrimaScan scanners. Is it required?
    Primax 3D MouseU3dmoused.exeEnables the scroll button on the Primax 3-D Scroll mouse
    Primsta?Primsta.exeLinksys Wireless CompactFlash Card driver related. Is it required?
    Print Driver Helper ServiceXcrsrr.exeAdded by the AGENT-BC TROJAN!
    Print Master Event ReminderNPMremind.exePrint Master Gold - calander feature that pops up reminders, such as birthdays
    Print Screen DeluxeNpsdeluxe.exeUtility allows "Print Scrn" or "Print Screen" key to capture, print or save the current window
    Print ServicesXspolserv32.exeAdded by the RBOT.ZP WORM!
    print sharingXstart.batAdded by the ZCREW VIRUS!
    print sharingXhidden32.exe (path) explorer.exeAdded by the ZCREW.B VIRUS! Note - this is not the valid Windows Explorer (explorer.exe)
    Print SpoolerXSpoolsv.exeAdded by the CIADOOR.B VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    Print SpoolerXspoolsvc32.exeAdded by the SDBOT.BB WORM!
    Print SpoolerXspools.exeAdded by a W32/Rbot-LD worm infection
    Print SpoolerXspool.exeAdded by the TROJ/BDOOR-IS TROJAN!
    Print SpoolerXspoolsv32.exeAdded by the RBOT.SW WORM!
    PrinterXSpyassault.exeBogus "Spyware remover" - see this list of non-Recommended anti parasite software
    PrinterXprivate.exe Win32.Rbot worm variant
    PrinterXdipset.exeAdded by a variant of the Proxy-FBSR TROJAN!
    printerXsysprinter.exeAdded by the TROJ_SMALL.ZY TROJAN!
    printerUSpyAssaultScanner.exeBogus "Spyware remover" - see this list of non-Recommended anti parasite software
    Printer MonitorXwebprinter.exeAdded by the TROJ/IRCBOT-Z TROJAN!
    Printer SpoolXupdater.exeAdded by a variant of the WIN32.RBOT WORM!
    Printer spool ServiceXspool.exeAdded by the W32/RBOT-ACP WORM!
    printer spoolerXcommonaccess.exeAdded by the Troj/Delf-LB TROJAN!
    Printer Spooler SubsystemXspoolss.exeAdded by a variant of the WIN32.RBOT WORM! - Note - this is NOT the legitimate Windows spoolss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    Printer Update?CFGREG.EXEMaybe a registration reminder or automatically updates drivers or application software for a printer?
    PrinterSpoolX[path] RESTORE.EXE [path] SPOOL.EXEAdded by the ALADINZ.K VIRUS!
    Printing DriverXmsprint.exeAdded by the RBOT.JH WORM!
    Printkey2000Nprintkey2000.exeScreen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
    PrintMngrXsystem.exeAdded by an unidentified TROJAN!
    printnowNprintnow.exePrintNow - a utility that primarily allows "Print Srceen" or "Alt Print Screen" screenshots to be sent directly to a printer
    PrinTrayNPrintray.exeLexmark/Compaq printer icon in the System Tray for quick access. Not required - uncheck via Printer configuration rather than MSCONFIG. See also LexmarkPrintray and CompaqPrinTray
    PrintScreenNUNWISE.EXEGadwin PrintScreen - utility to capture, print or save the current window
    Printscreen 95NPRT95MIN.EXEPrintscreen 95 - utility to capture, print or save the current window
    PrintSpoolSvXSystem.exeAdded by a Troj/Bdoor-S worm infection
    PRISMSTA.EXEUPRISMSTA.EXECreates a system tray icon for accessing information about Intersil Prism Wireless Settings. Intersil silicon is used by Trendware/Trendnet for example
    PRISMSVR.EXE?PRISMSVR.EXESiemens Gigaset USB Adapter software related. Is it required?
    Privacy Eraser ProNPrivacyEraser.exePrivacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activities
    PrivacyKeyboardUPrivacyKeyboard.exe PrivacyKeyboard is a product "that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices, both known and unknown, currently in use or presently being developed worldwide."
    PrivacyScannerXpscan.exe"Privacy Champion", a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to porn websites, and then offers to "clean" them.. Produces loads of False Positives as goad to purchase.
    PrivateNetX(Various filenames)Premium rate adult content dialer
    PrivoxyUprivoxy.exePrivoxy - web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk
    PrizeSurferXprizesurfer.exe"PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
    prjtectXprjtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prktectprktect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prltectXprltect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prmtXprmt.exeNetRatings software by Opistat. "OpiStat measures Internet usage anonymously and surveys participants according to their profiles and online habits". This software has been reported to get downloaded and installed automatically after a Grokster install. It anonymously collects your use of the Internet protocols (sites visited, Web pages, advertisements seen, electronic commerce, streaming). To be avoided!
    prmtectXprmtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prxtect.exe, prdtect.exe and so forth!
    PrnSys ExecutableUPrnSys.exePrint screen utility bundled with some HP printer software; not required, but your choice if you like that feature.
    proX[path to file]Added by Troj/Spywad-F TROJAN!
    proXSpySheriff.exeAdded by the Troj/Spywad-I TROJAN! Note: This trojan file is found in the Program Files\SpySheriff folder.
    Pro PCL Status MonitorUPENGSS.EXEXerox printer/fax/copier status monitor (PCL = printer control language)
    ProArt?ProArt.exe??
    Proc992X[path to file]Added by W32/Ixbot-C WORM!
    Proc993Xwqxfne.exeAdded by the W32/Ixbot-D WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    process.exeXprocess.exeAdded by the PWSTEAL.BANCOS.P TROJAN!
    ProcessGovernorUprocessgovernor.exeProcess Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions.
    ProcessSupervisorGUIUProcessSupervisor.exeProcess Supervisor is a technology designed to automatically configure and manage processes on one or more computers for the goal of maintaining system stability and responsiveness, restricting executables from running, and logging of program executions.
    procmonXprocmon.exeAdded by the BIONET.40A VIRUS!
    Prodigy DSL?EnterNetDUN.ExeProdigy EnterNet DUN PPPoE Client - is it required?
    ProdikeysAutorunNProdload.exeCreative Prodikeys software. "an interactive music entertainment device which not only functions as a full-featured, ergonomic “QWERTY” keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop."
    ProDslNProDsl.exeIntel Pro/DSL 2100 modem connection manager. Available via Start -> Programs
    ProfileXProfile.vbsAdded by the WHITEHO or TRAPPY VIRUSES!
    ProfileAMPUProfile8WinAmp media player add-on; "will replace %s with the current Winamp song and %m with current memory stats every song change. Change the color of your links, have a count down to a certain date. Works for all versions of Winamp."
    ProfilerNProfiler.exeEnables the "Profiler" to be launched from a System Tray icon for Saitek's game controllers. Available via Start -> Programs
    profilerXprof.exeAdded by the TROJ/ZAPCHAS-G WORM!
    profilerXliteout.exeAdded by the TROJ/ZAPCHAS-G WORM!
    ProgXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    ProgXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    Program FileXProgmon.exeAdded by the PEEPER VIRUS!
    Program in WindowsXiexplore.exeAdded by a variant of the LOVGATE WORM!
    Program Neighborhood AgentUpnagent.exe Citrix_Program_Neighborhood_Agent
    projselectorNprojselector.exeRoxio Project Selector; can be started manually
    Promon.exeNpromon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
    PromptCastUPromptCast.exeAuto-download for viewing short films and movie trailers for Surveys - Membership to site is required and it 'background'-downloads the needed clips for the survey.
    PromulGateXPgMonitr.exe Delfin_Promulgate adware variant
    PRONoMgr.exeNPRONoMgr.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
    PRONoMgrWiredUPRONoMgr.exeIntel’s Pro 100 Ethernet card manager
    Propel AcceleratorUPropelAC.exePropel Internet Accelerator
    ProPort StartupUProPort.exeProport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolving
    ProSiteFinderXprositefinder.exeAdware by 180Solutions
    Proteçăo de telaXssmaze.scrAdded by the BANCBAN-FB TROJAN!
    ProtectUSHVRTF.EXE PC_Angel takes a 5-second snapshot of the current system registry each time the PC boots up. In the event of a crash, PC ANGEL will retrieve everything up to the minute before the crash or the last known stable registry.
    protectXprotect.scrAdded by the Troj/Dloader-TQ TROJAN!
    Protected StorageXRUNDLL32.EXE MSSIGN30.DLL ondll_regAdded by a variant of the LOVGATE WORM!
    ProtectionXProtection.exeAdded by the W32/FEBELNECK-A WORM!
    ProtectionX[path] runtask.exe [path] protection.exeAdded by a variant of the Downloader.Agent.3.AU TROJAN!
    ProtectionXFirewall.exeAdded by the W32.Elitper.A WORM!
    ProtectionXIExplore[space].exeAdded by the W32.Elitper.D WORM!
    ProtectionXNorton Internet Security.exeAdded by the W32.ELITPER.E WORM!
    ProtocolDiskChkXssrms.exeAdded by the Troj/Bdoor-ML TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Provan SecurityXpsecure.exeAdded by the RBOT.BRV WORM!
    PROXOMITRONNPROXOM~1.EXEHTML proxy
    ProxomitronNProxomitron.exeHTML Proxy
    ProxyWayUproxyway.exe ProxyWay anonymous proxy surfing software
    PRPCMonitorUPRPCUI.exeIntel® SpeedStep™ interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40%
    prqtectXprqtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prrtectXprrtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prstectXprstect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prtcctXprtcct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prttectXprttect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prutcctXprutcct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D.
    prutdctXprutdct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutgctXprutgct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    pruthctXpruthct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutictXprutict.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutlctXprutlct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutpctXprutpct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutqctXprutqct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prutsctXprutsct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    pruttctXpruttct.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: routinely uses alternative file names like prdtect.exe, prtcct.exe and so forth!
    prvtectXprvtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    prxtectXprxtect.exe"Prutect" malware from e2Give - attempts to tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. - NOTE: has been seen using alternative file names like prdtect.exe, prmtect.exe and so forth!
    ps1Xps1.exe PacerD_Media/Pacimedia.com adware component
    PS2Ups2.exeMultimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lost.
    psaload32Xpsaload32.exeAdded by the W32/Rbot-ADL or W32/Rbot-ANW WORM!
    PSD Tools ChannelXChannelUp.exeBuddyLinks adware
    PSDrvCheckYPSDrvCheck.exePart of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
    PServiceXsvcnow32.exeAdded by the TROJ/SPYBOT-DJ TROJAN!
    PSFreeUPSFree.exePop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
    PSGuardXPSGuard.exeBogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN!
    PSGuard spyware removerXPSGuard.exeBogus spyware remover - also known as the SmitFraud alias FAKEALE-C TROJAN!
    pshowerXpshwr.exe SafeSurfing adware variant
    PSIMSVCYPSIMSVC.exe Panda Titanium Antivirus
    PSIWin2.3 Connection ServerNPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start -> Programs
    psklUkeyspy.exe KeyboardLogger logs keystrokes and records the windows in which they were entered. If you didn't install it yourself remove it.
    PsMFCardUPsMFCard.exeComponent of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in use
    PSNotifyYpsnotify.exePharos SignUp Vx - "PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries"
    PSof1XPSof1.exe PacerD_Media/Pacimedia.com adware installer
    PSoft1Xpsoft1.exe PacerD_Media/Pacimedia.com adware installer
    PsPCCard?PsPCCard.EXEFound on a Toshiba laptop?. Any ideas?
    PspContrUpspcontr.exeDriver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driver
    PsSoundUPsSound.exeOn a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delay
    pstUmemaker2.exeAdded by the SpymodePCSpy surveillance software. Uninstall this software unless you put it there yourself.
    PSTORES?PSTORES.EXEPart of Windows Services Protected Storage?
    ptechXptech.exeRelated to "Prutect" malware from e2Give
    ptfbNptfb.exePush the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"
    Ptipbmf?rundll32.exe ptipbmf.dll, SetWriteCacheModeInstalled with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller
    PtiuPbmd?Rundll32.exe ptipbm.dll, SetWriteBackInstalled with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. If used is it required?
    ptrun32Uptrun32.exeParent Tools for AIM
    PTRUN32Uptr32w.exeAdded by Spyware.ParentTools surveillance software. Remove unless you installed it yourself!
    PtsnoopNPtsnoop.exeThese descriptions I've come across - all valid as far as I can see :-
    (1) Program installed with some modems that monitors the COM ports for the modem driver. Not required from what I've read - may need a registry edit to get rid of it
    (2) Backdoor trojan virus that copies itself as PTSNOOP.EXE -see here for more info
    (3) Apparently the people who put it out claim it's a driver for a Voice modems (don't know who they are though - Ed)
    Note: If using AOL and you disable this you may lose your connection or lock up
    (4) Can also be an older Logitech scanner program. Remove from the Win.ini tab under Load='path'\PTSNOOP and the System.ini tab under drivers='path'\ptrtkr.drb. Can cause parallel port conflicts big time dragging system resources way down when a conflict exists
    (5) Allows audio monitoring of modem phone dialling tones and can be useful if you have connection problems
    (6) Karen Kenworthy's Snooper - "logs the start and stop time of all programs run under Windows"
    pttrunUpttrun.exeTransmeta Crusoe processor related. Reduces application launch times and makes the computer "more responsive"
    PtUDFAppNPtUDFApp.exeSony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start -> Programs. Note that you must add a /T switch to the command line to get it to load to the taskbar
    Public Microsoft ODBCXODBC32*.exe (* = random char)Added by the MASLAN.D WORM!
    pumcfgpUproxycfg.exeGuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser
    Pure Networks Port MagicNPortAOL.exePure Networks Port Magic, as available in the latest version of the AOL® 9.0 Optimized SE software; automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and video. See here
    PurgativeUPURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
    PurgatoryXPurga.exeAdded by the W32/Purgory-B WORM!
    Push ClientNpull.exeClient software from Interwise that MS use for their webcasts
    Push The Freakin' ButtonNptfb.exePush the Freakin' Button - "When a dialog causes irritation, you simply tell PTFB which button should be pressed, and it will handle the dialog in future"
    PUSH6599NPUSH6599.EXEScan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software
    PutA!!XPutA!!.exeAdded by the OPASERV.L VIRUS!
    PutAS!XPutA!!.comAdded by the OPASERV.Z VIRUS!
    putilX(filename)Added by the LDPINCH VIRUS!
    putilX(file name)Added by a Troj/LdPinch-AA trojan infection
    PV92TRAYUPV92Tray.exe PCtel HSP V.92 modem Configuration Utility
    PVRNPVR.exePocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound card
    PVUnInst1UPVUnInst1.exe Privacy_View is privacy software that ensures that all your private computer files, photos, documents, and websites remain secure from prying eyes.
    pwindicatorNpwic.exeParaWin XP - International Language Software for Windows XP/NT/2000
    Pwr32ctrXPwr32ctr.exeAdded by the GEMA TROJAN!
    Pwr32ctrlXPwr32ctrl.exeAdded by the GEMA TROJAN!
    Pwr32mgtXPwr32mgt.exeAdded by the GEMA TROJAN!
    PwrmonitYRundll32 PwrMonit.dllIBM's proprietary 'battery maximiser' and power monitoring software for laptops
    PwroffXPwroff.exeAdded by the GEMA TROJAN!
    PwrsaveUPwrsave.exeToshiba Power Saver utilities. Required on a laptop if you run of a battery and want to conserve power
    Pwruplogin?pulogin.exe??
    PwrupTweakMeUPUPXPTWK.EXE"Ashampoo PowerUp XP is a convenient tool for fine-tuning your Windows® NT4, 2000 and XP configuration to suit your precise needs and wishes. It gives you direct access to many frequently-required settings and parameters, enabling you to make your operating system behave the way you want." Boot-up options won't work if disabled 
    PWS TrayUPwsTray.exeMicrosoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start -> Programs
    p_981116Np_981116.exeWin32 cabinet self extractor. More info here
    Q152404Nwsript.exe Q152404.VBSAppears to run Scandisk at bootup on NEC PCs
    q36i36OXlms2cenu.exeAdded by the SECONDTHOUGHT VIRUS!
    QAGENTNqagent.exeQuicken program is controlled by a separate utility program called the Quicken Download Manager (also known as Qagent). When Quicken Download Manager option is enabled, background downloading takes advantage of unused bandwidth to download current financial information anytime your computer is connected to the Internet
    qappsrvc32.exeXqappsrvc32.exeAdded by a Proxy_Trojan variant - identified by Kaspersky antivirus as Trojan-Proxy.Win32.Webber.m
    QBCD autorunNautorun.exeQuick Books CD
    qbkupdbsXmqbkup.exeAdded by the OPASERV.K VIRUS!
    qbotdX(random filename)Added by the BOTTEN VIRUS!
    qBrowse?qbrowse.exe??
    QBRSRXQuickBrowser.exe QuickBrowser/Top-banners.com adware
    Qchex Tray IconUQchex.exeRelated to G7_Productivity_Systems Check Software.
    QCTRAYUQctray.exeSystem Tray icon providing access to the "IBM Access Connections" wizard on ThinkPad laptops and also allows to change the network environment. Not the same as QCWLIcon, which is pertinent only to the Wireless LAN
    QCWLICONUQcwlicon.exeUsed by IBM Thinkpad laptops with built-in wireless card (802.11). System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off
    QD FastAndSafeNQDCSFS.exeAutomatically runs Fast & Safe clean-up from Norton/Quarterdeck Cleansweep. Deletes safe to remove files such as Temporary Internet Files (cache). Recommended you run it manually
    QDM or QDMStartUQdmStart.exeQDM (QDI Desktop Manager) - part of QDI ManageEasy for QDI\'s series of motherboards for monitoring PSU, temperatures, BIOS information, etc. Only required if you overclock system components and need to monitor temperatures, etc
    Qdsafe?????
    Qexplo?Qexplo.exe??
    qgqqftX[path to Trojan]Added by the Ranky.T TROJAN!
    QH Live Update SchedulerYUPSCHD.EXE Quick_Heal Anti-Virus
    QH Office 2K CheckYO2KCHECK.EXE Quick_Heal Anti-Virus MS Office documents virus checker
    QMusic?QMAgent.exe??
    QNPlusNQNPlus.exeQuick Notes Plus by Conceptworld - sticky notes tool
    QoeloaderUQoeloader.exeQurb 2.0 anti-spam tool for Outlook/Outlook Express. Required when supporting OE but not for Outlook. Shortcut available via Start -> Programs
    QQXsendmess.exeAdded by the SEMES VIRUS!
    QQServerXQQ.exeAdded by the Troj/DownLdr-AN TROJAN!
    qservicesXqservice.exeAdded by the Troj/Progent-A TROJAN!
    qservicesXqservice.exeAdded by the Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    QSort2000NQSORT.EXEUtility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"
    QT4HPOTUOneTouch.exeHewlett Packard One Touch keyboard driver. Required if you use the additional keys
    QTaskStartupUqtask.exeFeature of Quicken.com Brokerage to customize and display Desktop Alerts and icon. It is not required for the Quicken Program to run correctly, it is only required for the Desktop Alerts feature
    QTimeXnrchk.exePremium rate adult content dialer
    QTSTUB.EXENQtstub.exePart of an old version of the Quick Tax application. It enables Quick Tax Calendar Popup to show tax calendar reminders
    QTSvcXssvr.exeAdult material premium rate dialer
    QTSvcXshman.exeAdult material premium rate dialer
    QTSvcXnavcke.exeAdult material premium rate dialer
    QTSvcXmsocfg.exeAdult material premium rate dialer
    qttaskNQttask.exeSystem Tray access to Apple's "Quick Time" viewer from version 5 onwards
    Quantifier SecurityXqsecue.exeAdded by the W32.Spybot.UOL WORM!
    QUBCity?qtp.exe??
    Queensla?Queensla.exe??
    Quick ControlsUAstrotoolbar.exeGateway Astro Screen and Sound Controls tray icon
    Quick Heal MessengerUQHM32.EXE Quick_Heal Anti-Virus Messenger - Keeps you informed about the latest threats, hoaxes etc.
    Quick Heal On-Line ProtectionYCateye.exeQuick Heal - virus scanner
    Quick Heal Startup ScanYQHSTRT32.EXEQuick Heal - virus scanner
    Quick Shelf xxNqushelfxx.exePlaces an icon in the system tray for launching MS Bookshelf. Available via Start -> Programs"xx" represents the version number - ie, 98, 99
    Quick StartupYFquick32.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
    Quick Time file managerXquicktimeprom.exeAdded by the SDBOT TROJAN!
    Quick View PlusNQVP32.EXEQuick View Plus from Inso Corporation. Multiple file type viewer. Available via Start -> Programs
    QuickBooks Delivery AgentNQBDAGENT.EXEAs far QAGENT but for QuickBooks. Can also have the version number in the name
    Quickbooks Update AgentNqbupdate.exeAssociated with Intuit's Quickbooks but not required. Possibly to do with the payroll update service but you're prompted to check for updates when appropriate whether this is running or not
    QuickCamProUQuickCamPro.exeSystem Tray for Picture Capture utility that can run unattended. Pictures every 30 seconds for example, auto FTP Upload, etc
    quickenXquicken.exe Waol.exe Winrar.exe CoolWebSearch parasite related.
    Quicken Scheduled UpdatesNbagent.exeQuicken background downloading module
    Quicken StartupNQWDLLS.EXEQuicken option to load DLLs at startup
    QuickenSEMessageNQsemsg.exeQuicken option
    QuickFinder SchedulerNQFSCHD100.exe, QFSched.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
    QuickLaunchErYQuickLaunchEr.ExeQuickLaunchEr - allows you to quickly launch programs from an icon in the system tray
    Quicklink IIINQL.EXEHP fax program and only needs to be in the start-up group if you allow your phone to automatically answer your phone in fax mode, that is, to receive faxes after a certain number of rings. Available via Start -> Programs
    QuicknoteNquicknote.exeJC&MB Quicknote Virtual Scrapbook
    QuickPasswordUagquickp.exeSmart card-based authentication and digital signature client software
    QuickResNQUICKRES.EXEUtility to quickly change desktop resolution - left over from Win95 Power Toys. In Win98 and above incorporated via Control Panel -> Display. Not required unless you have to change resolutions on a regular basis
    quicksetNquickset.exeDell taskbar icon allowing you to quickly change settings
    QuicktimeXqttasks.exeAdded by the TROJ/ADCLICK-AK TROJAN!
    QuicktimeXshch.exeAdded by a variant of the TROJ/BDOOR-EB TROJAN!
    Quicktime MediaplayerXwinmplyer32.exeAdded by the W32/RBOT-PM WORM!
    Quicktime MediaplayrXwnmplyr.exeAdded by a variant of the WIN32.RBOT WORM!
    Quicktime Pro 3.0Xwinuodps.exeAdd by the GAOBOT.BH WORM!
    Quicktime RuntimeXQtimer.exe W32.SpyBot worm variant
    QuickTime TaskNQttask.exeSystem Tray access to Apple's "Quick Time" viewer from version 5 onwards
    QuickTime TaskXqttasks.exe CoolWebSearch parasite related.
    Quicktime TaskXrandom file name NetVision dialer
    QuickTime Update Completion xNquicktimeupdatehelper.exeDifferent numbers caused by number of launches. So if 3 updates are made separately, 3 would appear (in theory)
    QuicktimeMngrXQUICKTIMEMNGR.EXEAdded by a WOOTBOT.AW worm infection
    QuickTimeUpdateXQuickUpdate.exeAdded by the Troj/Bifrose-CW TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    QuicktlmeXru.exeAdult content dialler
    QuickTVUQuickTV.exeInfra-red remote control driver for the AVerTV Studio TV tuner/personal video recoder from AVerMedia. Required if you use the remote control
    QuickzipXLs.exeMsConnect browser hijacker and dialler
    QuickZipXlu.exeMsConnect browser hijacker and dialler
    QuikShieldNqkshield.exeQuikShield popup blocker - reportedly stealth installed, see here
    QuikSyncNQUIKSYNC.EXEUsed by Iomega drives. Available via Start -> Programs
    qweXqwe.exeAdded by the TROJ/LINEAGE-F TROJAN!
    QWS3270 SessionsUsessions.exeQWS3270 Secure terminal emulation software
    RA ServerXSlave.exeAdded by the RA VIRUS!
    RabbitWannaHomeXrabbit.exeAdded by the W32.MIMAIL.S WORM!
    Rabo Session MonitorYRaboSessionMon.exeRelated to RaboBank electronic banking software
    RadarSyncNRadarSync.exeRadarsync utility comes from DFI with their latest motherboards, e.g., DFI LanParty Ultra - checks for BIOS and driver updates periodically
    RadBootURadBoot.exeRadLinker - tweaker/linker for ATI Radeon based graphics cards. It allows you easy access to per game settings
    RadioSvrURadioSvr.EXEUsed to configure wire less networks. Windows automatically detects the Wireless network and it configures the network
    RainlendarURainlendar.exe Rainlendar is a customizable calendar that displays the current month.
    RAM Idle ProfessionalURAM_XP.exe RAM_Idle - a memory management program which manages the free RAM that is available to Windows, thus preventing your computer from running progressively slower over time.
    RAMASSTURAMASST.exeOptionally installed with some DVD drives (LG, Panasonic, etc). Disables Windows XP\'s CD-burning abilities because they cause some incompatibilities. It does not affect your ability to burn CDs. If you do not have this program running, you may have some compatibility issues with burnt DVDs
    RamBooster2Xrb.exeAdded by the AKAK VIRUS!
    RAMDefUramdef.exeRam Def Xtreme - monitors and defragments your system RAM to improve reliability and speed. Some users swear by programs such as this but I suggest you read this article and make up your own mind
    RAMDriveURDTask.exeVirtual Hard Drive (Ram Drive) takes a portion of your system memory (RAM) and uses it to simulate a hard disk drive. For more information see FarStone
    RamIdleUramidle.exeRAM Idle - "A smart memory management program that will keep your computer running better, faster, and longer. RAM Idle works by  freeing up physical RAM wasted by Windows and other applications. In addition, RAM Idle also includes Cache and startup manager program that will give you more power to optimize your Windows." Some users swear by programs such as this but I suggest you read this article and make up your own mind
    RAMpageURAMpage.exeSmall Windows utility that displays the amount of available memory in an icon in the System Tray. It can also free memory by double clicking the tray icon, or by setting a threshold that activates the program automatically, or by having it run automatically when an application exits. RAMpage is free, and open source
    Randex virus built for IRBMeXirbme.exeAdded by a W32.Randex.RH worm infection
    random 10-character filenameXWinupdates.exeAdded by a W32/Rbot-MM worm infection
    RandomWin32Xmgnwin32.exeAdded by the W32/SDBOT-DV WORM!
    rantXrant.exeAdded by the W32/RBOT-ZB WORM!
    RapAppYRAPAPP.EXEApplication protection component of BlackICE PC Protection (was Defender) firewall, informing you of any modifications to programs, files or folders and detecting unknown programs trying to launch
    RapdataXravsecs.exeAdded by the Troj/QQPass-V TROJAN!
    RapdataeXrabseuser.exeAdded by the TROJ/QQPASS-S TROJAN!
    Rapid RestoreUrrpcsb.exe XPoint "Rapid Restore PC"; a "Managed Recovery™ solution that enables IT Administrators to protect the corporate image, while offloading personal data backup and recovery chores to the end user."
    RapidBlasterXrb32.exeHomepage hijacker (adult content) - see this newsgroup thread
    RaptelnetXravspeger.exeAdded by the Troj/QQPass-AA TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RapteltXravspegtl.exeAdded by the Troj/QQPass-AB TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder and the Temp folder as temp~3
    Raptor MobileYvpnservices.exeSymantec VPN Client used to connect to corporate networks. If unchecked, must be uninstalled using Add/Remove Programs as it tightly integrates into networking
    RasCon Remote Access Service ManagerXrasmngr.exe WORM_SPYBOT.EM
    rasctrsXrasctrs.exeHijacker, also detected as the ADWAHECK TROJAN!
    RaseXboln.exe PurityScan/Clickspring adware
    RasMan.exeXRasMan.exeAdded by the Troj/Feutel-H Trojan!
    rate.exeXi11r54n4.exeAdded by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS!
    rate.exeX********.exe (* = random char)Unidentified adware
    RAV8TrayYravtray8.exeRAV anti-virus related
    RAVEN_VLZS.EXEXRAVEN_VLZS.EXEAnother eAcceleration program - spyware. Read their privacy statement here
    RavMonYRavMon.exe RAV AntiVirus
    RavTimeXMstray.exeAdded by the WUKILL.A VIRUS!
    RavTimerYRavTimer.exe RAV AntiVirus
    RavTimerXexplores.exeAdded by the Troj/Homey-A TROJAN! Note: This is not the legitimate Windows process explorer.exe (Notice the difference in the spelling.) This trojan file (explores.exe) is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RavTimeXPX(worm filename)Added by the WULLIK.B VIRUS!
    RavTimeXPXVirusAdded by the CAGER.A WORM!
    RavTimXPX(worm filename)Added by the WULLIK.B VIRUS!
    RavUptpeXravsesur.exeAdded by the TROJ/QQPASS-T TROJAN!
    rav_temp.exe?rav_temp.exe??
    RAX SYSTEMXscrigz.exeAdded by the MYTOB.KR WORM!
    Ray Process KillerNPrkill.exeRay Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL ALT DEL instead
    razertraYrazertra.exe razer diamondback mouse driver
    rb32 lptt01 or rb32 ml097eXrb32.exeVariant of the RapidBlaster parasite (in a "RapidBlaster" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    rbenh ml***eXrbenh.exeVariant of the RapidBlaster parasite (in a "RBEnhance" folder in Program Files) where *** represents random digits. It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Rcf DriverXrcf.exeAdded by the RANDEX.BLD VIRUS!
    rCronXrcron.exe "Switch" adult content dialer
    rCronXdservice.exe"Switch" premium rate adult content dialer
    RCScheduleCheckURCSCHED.EXEScheduler for VCOM's Recovery Commander - which "can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"
    RCSyncXRCSync.exePrizeSurfer related. "PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!" Stealth installed malware
    RDClientURDCLIENT.EXERemote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection
    RDLLXRunDll16.exeAdded by the SDBOT.F WORM!
    rdvsX(worm filename)Added by the ULTIMAX VIRUS! <filename.exe> is the worm filename created
    Reactor3X[random name]32.exeAdded by the W32.BOFRA.A WORM!
    Reactor5X[random name]32.exeAdded by the W32.BOFRA.D WORM!
    Reactor6X[random name]32.exeAdded by the W32.BOFRA.C WORM!
    Reactor6X[random name]32.exeAdded by the W32.Mydoom.AK WORM!
    Reactor7X[random name]32.exeAdded by the W32.BOFRA.B WORM!
    Reactor8X[random name]32.exeAdded by the W32.BOFRA.E WORM!
    Reactor9X[random name]32.exeAdded by the W32.BOFRA.E WORM!
    readdb40Xrundll32.exe (path) readdb40.dll,EnableRunDLL32 LZIO.com adware downloader
    Real Internet PlayerXReaiplay.exeAdded by a variant of the W32.SPYBOT WORM!
    Real player updaterXrealupd.exeAdded by the PARLAY VIRUS!
    real schedulerXreal scheduler.htaAdded by the CEEGAR TROJAN!
    Real Spy MonitorUWinrsm.exe Realspy keystroke logger/monitoring program - remove unless you installed it yourself!
    Real Statics AgentXccreal.exeAdded by a variant of the WIN32.RBOT WORM!
    Real-TensXReal-Tens.exeDownloadWare based advetising spyware
    RealAudioXRealAudio.exeAdded by the CEEGAR TROJAN!
    RealDownloadNRealPlay.exeDownload manager. Available via Start -> Programs
    RealDownload ExpressXnpnzdad.exeAdvertising spyware
    Reality Fusion GameCam SENRFTRay.exeSystem Tray access for Logitech's Reality Fusion GameCam. For more details see here. Available via Start -> Programs
    RealJukeboxSystrayNtsystray.exeSystem Tray icon for RealJukebox
    realone_nt2003Xmoniker.exeAdded by the SNONE.A VIRUS!
    RealP1ayerX[path to file]Added by the RPLAY.A TROJAN! **Note that the name has a number "1" in place of the second lower case "L"
    realplayNrealplay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
    realplay lptt01 or realplay ml097eXrealplay.exeVariant of the RapidBlaster parasite (in a "RealPlay" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not RealPlayer which can have the same executable name
    Realplayer Codec SupportXrealsched.exeAdded by the W32/AGOBOT-AAD WORM - NOTE - do NOT confuse with the Real Player executable as described here
    Realplayer OneXrealplay.exeAdded by the W32/RBOT-NK WORM!
    RealPlayer2NMsgCenterExeRealNetworks RealPlayer related - disabling this application will not affect Real Player in any way.
    RealPlayerUpdaterXrealupd32.exeAdded by the TROJ/LOHAV-T TROJAN!
    Realpopup?Realpopup.exeRealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor"
    RealschedNrealsched.exeApplication Scheduler installed along with RealOne Player. Runs independently of RealOne Player, to remind AutoUpdate and Message Center to perform their tasks at pre-scheduled intervals. If it can't be disabled try deleting or renaming realsched.exe and then delete the entry in the registry
    Realtime Audio EngineUmmrtkrnl.exeAssociated with ALCATech BPM_Studio
    Realtime MonitorYrealmon.exeRealtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates
    RealTimeUpdate?RealTimeUpdate.exeProduct description in properties is "InternetExplorerCommunicationAgent Module" ?
    RealTrayNRealPlay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
    RealUpdaterXrealupd.exeAdded by the PARLAY or MITGLIEDER.I VIRUSES!
    RebateNation0XRebateNation0.exe WebRebates adware variant
    RebootNReboot.exeMS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
    RecguardYrecguard.exeOn HP computers, Recguard prevents the deletion or corruption of the WinXP Recovery Partition. Without it enabled, it is possible to knock that completely out and force the customer to send the PC back to HP for a re-image, possibly at the customer's expense
    ReclipNreclip.exeReclip Popup Clipboard manager
    Recommended Hotfix - {0421701D-CF13-4E70-ADF0XRH.DLLSmartPops adware
    RecoverNN/AAdded during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
    RecoverFromReboo?RecoverFromReboot.exeUnknown
    RecoverFromReboo?RECOVE~1.EXEUnknown
    RecoverFromReboot?RECOVE~1.EXEUnknown
    RecoverFromReboot?RecoverFromReboot.exeUnknown
    RecSheNRecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
    Recycle Bin HandlerXrecycler.exeAdded by the TROJ/SHUCKBOT-A TROJAN!
    Recycle Bin Handler 2005Xsystem.exeAdded by the TROJ/BDOOR-HO TROJAN!
    RecycleSTRXmsreg32.exeAdded by the W32/RBOT-TC WORM!
    Red FlagNredflag.exePMS prediction program with modes for guys and girls - no longer available
    Red Swoosh EDN ClientXRSEDNClient.exeRed Swoosh - mechanism used by web sites to allow you to download files from those sites quicker and more efficiently. Note from the license agreement they automatically update the software and share non-personally identifiable information with others in the network
    redirectXredirect*.exeDotcomtoolbar/Linksummary hijacker installer - where * is a random digit
    Redline TaskbarNtaskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
    REEGRUNX(path to file)Added by the SECDROP.AI TROJAN
    Reek 32 ServerXreek32.exeAdded by the RANDEX.AL WORM!
    RefereeUreferee.exeMediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run
    RefreshNRefresh.exe(Iomega) Refresh - loads the Iomega desktop icons at startup
    RegXReg.htaHomepage hi-jacker. Removal instructions here
    Reg Check?lpt.exeRelated to Supanet ISP software -what does it do and is it required?
    Reg ServiceXwinsy.exeAdded by a variant of the W32.SpyBot WORM!
    Reg ServiceXwinslogon.exeAdded by the W32/AGOBOT-SC or W32/Agobot-SY WORM!
    Reg ServiceXREGSRV32.EXEAdded by the RBOT.ZW WORM!
    Reg ServiceXipcfg.exeAdded by the W32/Agobot-SO Worm!
    Reg ServiceWinnConfig.exeAdded by the W32/Agobot-PF Worm!
    Reg ServicesXWinboot32.exe WORM_RBOT.PB
    reg1.regXvuamgard.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    reg2.0USVCH0ST.EXEAdded by the eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    Reg32XReg32.exeHijacker - redirecting to only-virgins.com
    reg32Xreg32.exeAdded by the NOUPDATE.B VIRUS!
    Reg32Xreg33.exe CoolWebSearch parasite related.
    RegcheckX~CAB001.EXEAdded by the CYBERSPY VIRUS!
    regcheckX[path to file]Added by the SERVPAM TROJAN!
    RegCleanerXSYSio32.exeAdded by an unidentified virus VIRUS!. Note - do not confuse this with the popular RegCleaner registry cleaner freeware
    RegCompresXRegcpm32.exeAdded by the POLDO.B VIRUS!
    RegCompresXREGCPM32.EXEAdult content dialler - see here. This has to be cleared at the same time as MSStartOptimizer (WINUPD.EXE), atisrc2 (windfind.exe) and mmxrun (msosa.exe), otherwise they return
    RegcxdinafXREGCXDINAF.EXEAdded by the TROJ/BANCOS-BW TROJAN!
    RegcxnXRegcxn.exeAdded by the COIBOA-D TROJAN!
    regdefendUregdefend.exe RegDefend is a configurable, kernel based registry protection system, designed to intercept selected changes before they occur, thus also preventing malicious software like viruses, trojans and worms from using the registry to their advantage.
    RegDoneXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup!
    RegDoneXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    RegDone ExXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    RegDoneExXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    regeditXregedit.exeAdded by the BRID.A VIRUS! Note - resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). The valid "regedit.exe" resides in C:\Windows (Win9x/Me/XP) or C:\Winnt (WinNT/2K)
    REGEDITXRegsrv32.comAdded by the SOUTHGHOST VIRUS!
    regeditXsvchost.exe ccRegVfyAdded by the Trojan.Rona Trojan!
    regeditXautoexe.exeAdded by a variant of the WIN32.RBOT WORM!
    RegexitXUpdadv.exeAdded by the Troj/QQPass-N TROJAN!
    RegexitXrunlli32.exeAdded by the Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    RegFreezeUregfreeze.exe RegFreeze anti-spyware software
    reggsdgXspoolserv.exeAdded by the W32/SDBOT-MS WORM!
    RegHelpUsvchosts.exe SpyGraphica spy software - "Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."
    reginfo32?reginfo32.exe??
    Register ManagerXRegistryManage.exeAdded by the SDBOT.AYH WORM!
    Register MediaRing TalkNregister.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
    Register SeqChk?regsvr32.exe ..csseqchk.dll?
    RegisterDropHandlerUREGIST~1.EXEPart of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation 
    Registration ServiceXtoker.exeAdded by the W32/SDBOT-BB WORM!
    Registration-Studio 8NRegTool.exeRegistration for Pinnacle Studio Version 8 home video software from Pinnacle Systems
    RegistryXwscript.exeAdded by the VBSWG VIRUS!
    RegistryUclass0117[random].exe Blackbox captures emails and chat logs, and monitors Internet activity - remove if you didn't intentionally install it.
    Registry CheckerXRegrun.exeAdded by the SDBOT TROJAN!
    Registry CheckupXwinreg.exeAdded by an unidentified WORM or TROJAN!
    Registry Checkup System326a MonitorXWinregs326a.exeAdded by a variant of the W32/SDBOT WORM!
    Registry Integrity CheckerXregintmon.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Registry IntegritycheckXWCPDT.EXEAdded by the W32/AGOBOT-RF WORM!
    Registry LoaderXregloadr.exeAdded by the GAOBOT.AO WORM!
    Registry LoaderXwinhlpp32.exeAdded by the GAOBOT.AO WORM!
    Registry oidetXwin32.exeAdded by the RBOT.BMT WORM!
    Registry ScannerXregscanr.exeAdded by the OPTIX LITE FIREWALL BYPASS VIRUS!
    Registry ServerXregsrv32.exeAdded by the W32/Rbot-GM WORM!
    Registry ServiceXREGSRV32.EXEAdded by a variant of the WIN32.RBOT WORM!
    Registry ServicesXRegistry.exeAdded by the DOWNLOADER.CILE VIRUS!
    Registry Startup CheckXcheckreg.exeAdded by the Troj/RemLoad-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Registry System16 Checkup MonitorXSystemReg16.exeAdded by a variant of the WIN32.RBOT WORM!
    Registry System166 Checkup MonitorXSystemReg166.exeAdded by a variant of the WIN32.RBOT WORM!
    Registry Value NameXservice.exeAdded by the W32/RBOT-AHT WORM!
    Registry Value NameXwinapi32.exeAdded by a variant of the WIN32.RBOT WORM!
    Registry Value Name StartXMsPMSPSa.exeAdded by a variant of the W32/SDBOT WORM!
    RegistryCheckXrundll32.exe chkreg.dll,CheckRegistry Ulubione adult content dialer
    RegistryChkXwinbackup.exeAdded by the MERTIAN VIRUS!
    RegistryMechanicURegMech.exeRegistry Mechanic for Windows - "you can safely clean and repair Windows registry problems with a few simple mouse clicks! Problems with the Windows registry are a common cause of Windows crashes and error messages"
    RegistryMonitorXregistry.pif Affilred adware
    REGIST~1UREGIST~1.EXEPart of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for "Send To" can be found here Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation
    Regkey for autostartXwinservice.exeAdded by the W32/RBOT-NU WORM!
    REGMSYSX(Path of Executable)Added by the Troj/LowZone-AX TROJAN!
    RegMutexXlexplore_.exeAdded by the Troj/MSNOpt-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    RegProtYRegprot.exeRegistryProt from Diamond Computer Systems - protects the system registry against changes
    RegptmensXREGPTMENS.EXEAdded by the Troj/Bancos-ED TROJAN!
    RegroXrundll132.exeAdded by the PWSteal.Ragnarok TROJAN! Note: This trojan file rundll132.exe (Notice the 1 in the file name) is not the legitimate Windows Process (rundll32.exe). Do not confuse the two. This trojan file is found in the Windows or Winnt folder.
    RegRunXmActiveX.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    REGRUNXwinfix22490.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    REGRUNX(pathname of the Trojan executable)Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    REGRUNXsory.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    REGRUNXregeditt.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    REGRUNXdialer.exeAdware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
    RegRun WinBaitUwinbait.exePart of RegRun - used to detect unknown viruses. RegRun compares winbait.exe with the original copy called winbait.org and warns if the files are different..
    Regrun2YWatchDog.exeGreatis Software's RegRun 3 Security Suite which amongst other things replaces MSCONFIG. The WatchDog check for registry changes caused by trojan's, viruses, etc 
    REGRUNMXautoprotect.exeAdded by an unidentified WORM or TROJAN!
    RegrxXrundll32.exeAdded by the TROJ/WAYIC-A TROJAN! - NOTE: this file is found in the C:\Windows folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
    RegscanXregscanr.exeAdded by the TROJ/OPTIX-SE TROJAN!
    RegScanXDLLSRV32.EXEAdded by the AGOBOT.AEW WORM!
    RegScanXRegscan.exeAdded by the BACKDOOR.TALEX TROJAN!
    RegServer?regserve.exeRelated to XGI Technology's Volari graphics cards - what does it do and is it required?
    regservices.exeXregservices.exeAdded by a W32/Rbot-MN worm infection
    RegShaveNregshave.exePart of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers, erasing all entries from the registry. Only required BEFORE attempting to uninstall the Fuji software or the uninstall may not work correctly
    regsrvXregsrv.exeAdded by the OPTIXPRO.11 VIRUS!
    regsrvXscvhost.exeAdded by the AGOBOT.E WORM!
    regsrvcXregsrvc.exeAdded by the TROJ/STOPED-A TROJAN!
    RegsvXregsv.exeSearch hijacker - redirecting to scheo.com
    regsvcUsystuneAdded by AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
    RegsvcXregsv.exeAdded by an unidentified TROJAN!
    regsvc32Xregsvc32.exeHomepage hijacker that changes your homepage to an adult content site
    regsvrXregsvr.exeAdded by the WEBMONEY-G TROJAN!
    REGSVR32Uregsvr32.exe ctasio.dllASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality
    RegSvr32Xmsmsgs.exeAdded by the Trojan.Zlob.B or Troj/Zlob-M TROJAN!
    regsyncXregsync.exe SafeSurfing adware
    regtmlp?N/A??
    RegTweakURegTwk.exeRage3d Tweak - ATI Radeon tweaker which allows access to registry tweak options, custom display modes, refresh rates and overclocking all through an easy to use interface
    RegVerXREGVER.EXEAdded by the LATINUS.16 VIRUS!
    RegWriteXcsrss.exeAdded by the SOKACAPS VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling
    Regx10EXEUatix10.exeATI Remote Wonder - PC wireless remote control
    reg_keyXFUKULAMER.exeAdded by the BEAGLE.AH WORM!
    reg_keyXloader_name.exeAdded by the BEAGLE.Y or BEAGLE.Z or BEAGLE.AA WORMS!
    reg_runXSysten.exeAdded by the TROJ/BANCOS-BS TROJAN!
    Reg_WFTXRegsysw.comAdded by the WILSEF VIRUS!
    Reg_WFTXscanreg32.comAdded by the Troj/SennaSpy-F Trojan!
    ReleaseRAMURRAM.exe"Release RAM allows your computer to run faster and uses your computer's RAM more efficiently". Some users swear by programs such as this but I suggest you read this article and make up your own mind
    reloadXreload.vbsAdded by the LOVELETTER.AS VIRUS!
    ReloadXreload.exe /reloadenterpiceAdded by the Lazar TROJAN!
    RemHelpNRemhelp.exeBT Voyager ADSL Modem Help related
    ReminderNreminder.exeFrom MS Money. Reminds you of your bills
    ReminderNRemind_XP.exeSubscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package
    Reminder-cpqXXXXXNremind32.exeCompaq printer Registration
    Reminder-hpcXXXXXNremind32.exeHP CD-Writer Registration
    Reminder-ranXXXXXNremind32.exeRegistration reminder widget for Rand Mcnally maps
    reminder-ScanSoft Product RegistrationNremind32.exeRegistration reminder for ScanSoft products such as PaperPort
    RemindMeURemindMe.exeRemind-Me - calendar software
    Remind_XPNRemind_XP.exeSubscription reminder to unlock unkimited use for SoftThinks CD Creator CD/DVD rewriting software, usually supplied with HP PC's as a pre-installed package
    RemndrXCsRemnd.exeCasinoOnline foistware
    Remote AccessUrnaapp.exeDial-up networking application - not normally found in the startup locations. It runs when you connect to the net via this method (ie, analogue 56K modem) and terminates after the connection is closed
    Remote Access SlaveXSynchost.exeAdded by the RIPJAC VIRUS!
    Remote ControlNRc.exeHinet Hi-Five ISP software
    Remote ControllerNTVRMVCR.EXEProLink PlayTVpro TV tuner software
    Remote Desktop ComputingUmarspc.exeMarspc Remote Desktop Computing
    Remote Management AgentUzenrc32.exePart of Novell's ZENworks - "Complete End-to-End Directory-enabled Network Management". Installed on a managed workstation fo an administrator to remotely manage the workstation. Required if the PC is a managed workstation
    remote masterUremote master.exeRequired if you want your ASUS Remote control to work at all. Available via Start -> Programs
    Remote Procedure CallXwinsysrpc.exeAdded by a W32/Sdbot-PS worm infection
    Remote Procedure CallXwinrpc.exeAdded by a W32/Rbot-KM worm infection
    Remote Procedure Call For Windows 32bitXrpc.exeAdded by a W32/Rbot-MD worm infection
    Remote Procedure Call LocatorXRUNDLL32.EXE reg678.dll ondll_regAdded by a variant of the LOVGATE WORM!
    Remote Procedure CallsXmswinrpc.exeAdded by a RBOT.KJ worm infection
    Remote Procedure CallsXmswinc.exeAdded by the W32/RBOT-IT WORM!
    Remote Procedure CallsXwin.exeAdded by the W32/SDBOT-QI WORM!
    Remote Update MonitorYimonitor.exe Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer.
    RemoteAgentYRAUAgent.exeTrend Micro's Office Scan Client, see here ; "Its Web-based management console gives administrators transparent access to desktop and mobile clients to coordinate automatic deployment of security policies and software updates".
    RemoteCenterURcMan.exeRemote control for Creative MediaSource - plays back music in DVD-Audio, MP3, WMA, WAV and other media formats
    RemoteControlUrmctrl.exeRemote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
    RemoteControlUPDVDServ.exeRemote Control background application for CyberLink\'s PowerDVD version 5 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don\'t have a remote control, or don\'t wish to use one
    Remote_AgentNRemoteAgent.exeCyberlink Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings, you will need this, otherwise can be disabled. Available via Start -> Programs
    REMOVE MEXwindos.exeAdded by the SDBOT.EE WORM!
    RemovecplNRemovecpl.exeRelated to a Belkin 54Mbps Wireless Utility Control Panel applet
    Removed.exeXRemoved.exeGatorCheat - adware downloader
    RemStart?remstart.exePart of McAfee\'s Remote Desktop 32 Agent application. What does it do and is it required?
    RenolB?ib.exe??
    RepliGo AssistantURepliGoMon.exeCerience RepliGo software - "any document you have on your PC can be transferred to your mobile device"
    ReproPRDUPrdUsb.exeThrustmaster Corporation Presets application - a game controller driver, presumably necessary for certain functions to work
    requesterXrequester.*.exeAdded by a variant of the Win32.Muquest.A trojan - NOTE: the asterisk stands for a digit, examples: requester.5.exe, requester.10.exe
    RequesterXrequester.11.exeAdded by the Muquest TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Required Service DriversXmicront.exeAdded by the W32/RBOT-ABD WORM!
    resagntXrestun.exeAdware downloader - detected by Panda antivirus as Trj/Downloader.ALQ
    reseurceX(Path to Trojan)Added by the Troj/Lineage-AI TROJAN!
    Resolution AssistantNmatcli.exeDell Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide
    Resource MeterNrsrcmtr.exeWindows Resource Meter. Available via Start -> Programs. You may want this enabled if your PC is suffering from crashes and want to know potential causes
    Restart Watch?Watch.exeAssociated with an Eicon Networks Diva ISDN or ADSL modem. What does it do and is it required?
    Restart WSC SettingUwscrestp.exeWinStart Commander - part of Ultra_WinCleaner_Utility_Suite . Starts Windows faster and controls hidden programs to boost performance and prevent system slow downs and crashes.
    Restart_VS?Viewsonic.exeCould be a left-over from the installation of a Viewsonic flat panel display
    RestoreIT!YVBPTASK.EXERestoreIT! from FarStone "allows you to recover instantly your files, system configuration, and even your operating system, to any point in time prior to the data loss or system failure."
    restoryXrestory.exeAdded by the RETSAM VIRUS!
    Resume CopyUcopyfstq.exePart of Total Copy - an improved version of the Windows copy function. Allows for resumption file copies or moves in progress when computer was shut down. Not required if your not using the program or don't care about that function
    ResumeFixClocksUresumefix.exePart of the RadeonTweaker utility for overclocking ATI Radeon graphics cards
    retimeXretime.exeAdded by the GIPMA VIRUS!
    RetrieverSchedulerUretrieverscheduler.exe80-20 Retriever from 80-20 - "80-20 Retriever is a powerful personal search tool that encompasses email folders, archived email, and local or network file systems, giving users one point of fast, accurate search for all personal information". Real-time scheduler - shortcut available
    RevoTaskbarAppURevoTask.exeControl Application for M-Audio Revolution 7.1 sound card. The sound card will function without it; but changes to speaker setup and sound modification (Bass/Treble etc) will not be available.
    RexSyMonNrexsymon.exeIntellisync for REX sychronization software for Xircom REX MicroPDAs for sharing information between the PDA and PC
    RFXEC.exeAdded by the Troj/Lineage-U TROJAN!
    rfagentUrfagent.exe Registry_First_Aid - scans the Windows registry for orphan file/folder references, finds these files or folders on your drives that may have been moved from their initial locations, and then corrects your registry entries to match the located files or folders
    RFTrayXRFTRay.exeReality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
    rfwYRfw.exe RAV AntiVirus
    RFX_auto_upgradeNrundll32.exe npvpg005.dllA browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade
    RHUrh32.exeEuroFonts - adds Euro symbols to pre-Euro computers
    RhinoX[random name]32.exeAdded by the W32.BOFRA.A WORM!
    RhinoBlockerURhinoBlocker.exeRhinoBlocker - pop-up stopper
    RHSI SHSNSHS.exeRogers Hi-Speed Internet software. "Should you ever lose access to your Rogers Hi-Speed Internet connection or e-mail, the Self-Healing Software (SHS.exe) will automatically repair your settings to get you up and running in a flash"
    richupXrichup.exe SafeSurfing parasite variant
    Ring Central FaxUrcenterrll.exeOnly needed if you want a PC to answer faxes automatically
    rIOphosIsXrIOPHosIs.vBSAdded by the RIOSYS VIRUS!
    RivaTuner or RivaTunerStartupDaemonURivaTuner.exeRivaTuner for tweaking nVidia graphics cards. Required if you make any changes
    RjLyraInstaller?setup.exe??
    rmctrlUrmctrl.exeRemote Control background application for CyberLink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one
    rmmonNmprmmon.exeResource Monitor for the now defunct Chromatic Research MPact2 3DVD graphics card
    RMremote?RmRemote.exeRemote control driver for REALmagic Xcard. Is it required?
    rn4dXdirote.exeAdded by the BKDR_MAROON.A TROJAN!
    RnaomfltUnaomf.exe Naomi internet filtering software
    RNBc TestXwf32vbs.exeAdded by the W32/Rbot-AGR WORM!
    RNBc TestXbvldv32.exeAdded by the W32/Rbot-AJF WORM!
    RNBOStartUsentstrt.exeProgram used to initialise the VxD virtual driver for Sentinel drivers associated with Rainbow H/W keys that plug-in to the parallel port. These are usually supplied with workplace design tools and restrict the use of the software only to the machine to which the H/W key is connected. Required if you have such tools
    RNBz TestXwf32vbc.exeAdded by the W32/Rbot-AEY Worm!
    RNDc TestXwf32b.exeAdded by a variant of the W32/SDBOT WORM!
    rndll2?rndll2.exeMay be related to the DivX program as a *.dat file in the same directory had "DivXPro505Bundle.exe" mentioned within?
    rngmfX(path to trojan)Added by the RANKY.C VIRUS!
    Rnudll32Xtadxtr.exeAdded by the TROJ/QQPASS-O TROJAN!
    Roam04XActiveX.exeAdded by the Troj/Roamer-A TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder.
    RoboFormNRoboTaskBarIcon.exeRoboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin
    RoboFormWatcherNRoboFormWatcher.exeAI Roboform from Siber Systems. Automatically completes web forms. Available via Start -> Programs
    Rocket.TimeURocketTime.exeTime synchronization software from Rocket Software
    roketpipe?rpclient.exe??
    rollbkXsysup.exeAdded by the W32.Serflog.B WORM
    rollbkXsvosm.exeAdded by the W32.Serflog.B WORM
    rollbkXmsmpatch.exeAdded by the W32.Serflog.B WORM
    rollbkXdsm.exeAdded by the W32.Serflog.B WORM
    romahereXmatrixhere.exe SuperSpider hijacker - a CoolWebSearch parasite variant
    romahere2X************.exe (* = random char) SuperSpider hijacker - a CoolWebSearch parasite variant
    romahere3X************.exe (* = random char) SuperSpider hijacker - a CoolWebSearch parasite variant
    Root_MachineX(Pathname of the Trojan exe)Added by the Troj/Bancban-DI TROJAN!
    ROOT_MachineXwinlogon.exeAdded by the Troj/Banker-FI TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows\inf or Winnt\inf folder.
    ROUTD?ROUTD.exe??
    RoxAssistNRoxAssist.exeRoxio Assistant is designed to correct Engine Initialization errors. If Easy CD & DVD Creator's Engine does not initialize, the applications in Easy CD & DVD Creator will not recognize your recorder. After running this program you should receive the message "Engine initialized successfully with full recorder support". If you do not receive the message, update your Virus software and then check and clean your system for viruses. After the removal of any viruses, uninstall and then reinstall Easy CD & DVD Creator (use "Add Remove Programs" in "Control Panel".) .Can be run manually
    Roxio Engine?MSMNGR32.EXENot believed to be a valid Roxio program - more likely a variant on the WOMANIZ.A VIRUS!
    RoxioAudioCentralNRxMon.exePart of Roxio EasyCD Creator 6.0 - places the Roxio AudioCentral icon in you system tray. "Includes a player, media manager, ripper, tag and sound editor - integrated in a single application". Not required for Roxio to work properly.
    RoxioDragToDiscNDrgToDsc.exePart of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
    RoxioEngineUtilityYEngUtil.exePart of Roxio EasyCD Creator 6.0 - corrects any modification made to the Roxio Engine, it exits after checking
    RP32Urp32.exeControlIT (was Remotely Possible) from Enterprise International for remote control and access to Win9x/NT systems.
    RPCXMSschost.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    RPC PatcherX(path to worm)Added by the BOLGI VIRUS!
    rpc Win32Xshost32.exeAdded by the W32/RBOT-ABL WORM!
    rpc Win32Xspoolscv.exeAdded by a variant of the WIN32.RBOT WORM!
    rpcda Win32Xrpcda.exeAdded by the W32/Rbot-AE Worm!
    RPCserr32gXwinlogon.exeAdded by the W32/Ritdoor-B WORM! Note: This trojan file is found in the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    RPCserv32Xservices.exeAdded by the W32.MYDOOM.AL WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    RPCserv32gXservices.exeAdded by the MYDOOM.BH WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCserv32gXservices.exeAdded by the W32.BOBAX.AA WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCserv32gXservices.exeAdded by the W32/MYDOOM.BV WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCserv32gXMSDEFR.EXEAdded by the BOBAX.AD WORM!
    RPCserv32gXNB32EXT2.EXEAdded by the BOBAX.AD WORM!
    RPCserv32gXCSRSS.EXEAdded by the BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCserv32gXSMSS.EXEAdded by the BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCserv32gXWINLOGON.EXEAdded by the BOBAX.AD WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    RPCSS.exeYrpcss.exeRemote Procedure Call. Required by windows for programs to communicate with each other on networks/different machines. Originally for NT only but now installed with Win98/98se. Under Win98/98se, a program may need it to communicate with other components of itself. You could delete the program but if any abnormalities occur soon after then reinstall. Under NT, deleting this critical system component will disable the OS. For a more detailed explanation see here
    RpcxWindows ExtensionsXrpcxwinex.exeAdded by the RBOT.ACP WORM!
    rregXrreg.exeUnidentified adware
    RRMedicXrrmedic.exeTroubleshooting utility for the RoadRunner cable internet service. Not required and you are advised to completely uninstall it. Provides a lot of false alarms and gets a lot of people panicking about there internet connection
    rscmptUrscmpt.exeRequired on the GeFroce 64 meg MX card to show the full 64 meg memory and appears to be a software memory emulator running under the Win2K - see here. High CPU useage results - hence the U status
    RSD_HDDThermoNHDD Thermometer.exeRelated to RSD_Software hard disk temperature monitoring tool.
    rsMenuUrsMenu.exeSynchronizes a Casio PDA with MS Outlook
    RSPC DriverX(random filename)Added by the W32/RBOT-SN WORM!
    RSPC Driver DX(random filename)Added by a variant of the WIN32.RBOT WORM!
    RSRCMTZ?RSRCMTZ.exe??
    RSSXrundll32 RSSToolbar.dll, DllRunMain"Related Sites" toolbar - SearchAndClick hijacker variant
    RssReaderURssReader.exe RssReader - a free RSS reader able to display any RSS and Atom news feed (XML)
    RSyncXnetsync.exe SafeSurfing adware
    rtcdllXrtcdll.exeUnidentified adware
    RTHDCPLYRTHDCPL.EXERealtek HD Audio Sound Effect Manager
    RtlMon.exeNRtlMon.exeMonitor for RealTek network card
    RTMonitorYRTMonitor.exeCheyenne, ( now eTrust ) antivirus
    rtosXrtos.exeIRC trojan
    RTStartMute?N/A??
    rtvscn95YRTVSCN95.EXEReal-time virus scanner component of Norton Anti-Virus Corporate Edition
    Ruby13XRuby13.exeAdded by the MEXER.E worm
    Ruby14XRuby14.exeAdded by the W32/FIGHTRUB-A WORM!
    ruinXsystem32.exeAdded by the TROJ/DELF-JM TROJAN!
    RuLaunchURuLaunch.exeInstant Updater for McAfee's VirusScan, Internet Security, Quick Clean, Uninstaller and Firewall products. In the case of VirusScan leave it enabled unless you update manually on a regular basis
    runXdec25.exeAdded by the W32.ATAK.F WORM!
    runXinetinfo.exeAdded by the Backdoor.Binghe TROJAN!
    runXAutoexec.comAdded by the HOLCAS.A WORM!
    Run Msn MessengerXmsnmgr.exeAdded by the AGOBOT.HA WORM!
    Run MSupdt32Xwscript MSupdt32.vbsAdded by the CASER VIRUS!
    Run POPFile in backgroundUperl.exewperl.exePOPFile - E-mail spam blocker
    Run Services as ApplicationXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Run Services as ApplicationXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Run StartupMonitorUStartupMonitor.exeMike Lin's StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
    Run TaskMrgXcsrss.exeAdded by the TROJ/LDPINCH-W TROJAN!
    run windowsXservic.batAdded by the REBOOT-AP TROJAN!
    Run XP Service PackXxpservicepack.exeAdded by a Sdbot.AQA worm infection
    Run05Xrundll_32.exeAdded by the Troj/Bancos-DT TROJAN!
    run32dllXWINClock.exeUnidentified mIRC VIRUS!
    run32dllXtask32.exeUnidentified mIRC VIRUS!
    Run32dllXocxdll.exeUnidentified mIRC VIRUS!
    run=Xinfo32.exe CoolWebSearch parasite variant.
    run=Ncmmpu.exeMIDI emulator driver for the integrated sound chip by C-Media based on the CMI-8330 chip set normally found in cheap motherboards. Also installed as part of the software for a Guillemot Maxi Muse sound card (PCI)
    run=NhpfschedHPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
    run=Nlxdboxcp.exeLexmark DOS-Printing Control Program for the Lexmark 2050. Only required if you need to print from DOS
    run=Npcfix2k.exepcfix2k splash screen
    run=Xptlseq.cplPhoenixNet BIOS adware. See here
    run=Uramsys.exeAdvanced Startup Manager from Rays Lab
    run=?wallflip.exeDesktop wallpaper changer?
    run=Xsvcinit.exe CoolWebSearch parasite related.
    run=Xfntldr.exe CoolWebSearch parasite related.
    run=Ysmsrun16.exeMicrosoft Systems Management Server (SMS) related - program that reads SMSRUN16.INI on clients running Win 3.1, Windows for Workgroups, Win95, or OS/2 to create program groups on the client and then launch SMS client programs
    run=XRAVMOND.exeAdded by a variant of the LOVGATE WORM!
    run=Xreal.exeAdded by a variant of the LOVGATE WORM!
    run=?LXBTppls.exeReportedly part of Lexmark printer software - what does it do and is it required?
    run=Xcyxid98.exeUnidentified malware
    run=XiexpIore.exeAdded by the OBLIVION-B TROJAN!
    run=Xservices.exe Krepper-G trojan, a CoolWebSearch parasite variant. Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
    run=Xmouse_configurator.winAdded by the VBS.GAGGLE.E WORM!
    run=XRegistryReminder.exeAdded by the APSTROJAN.OB TROJAN!
    run=Xmsxmidi.exe CoolWebSearch parasite variant -recognized by Kaspersky antivirus as TrojanDropper.Win32.Small.cw
    run=Xwmplayer.exe CoolWebSearch parasite variant - Note: this is not the Windows Media Player executable!
    run=Xwinlogon.exe CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process!
    run=XMsvxd.exeAdded by the W32.DATOM WORM!
    run=Nfmedia.exeFMedia FaxWorks related - can be run manually
    run=Ywswpd.exeUsed with some models of Panasonic, Epson and NEC printers - required for printer to work.
    run=Yasistat.exeUsed with some models of Panasonic, Epson and NEC printers - required for printer to work.
    run=Xmsreg32.exeAdded by the BACKDOOR-FORCEDENTRY TROJAN!
    run=Xclean_service.cmdAdded by the W32.Refaz WORM!
    run=XAutoexec.comAdded by the HOLCAS.A WORM!
    run=Xhtmlsync.exeSearchforfree.info browser hijacker
    run=Xmsoffice.exeAdded by the ADWARELOADER TROJAN! - NOTE: Do NOT confuse with the (legitimate) Microsoft Office file, which would typically be located in the Program Files\Microsoft Office\Office folder!
    run=XDRDOOM.EXEAdded by the W32/SEMAPI-A WORM
    run=Xsvhost.exeAdded by the ADMINCASH.B TROJAN!
    run=XCeline.scrAdded by the TROJ/CELINE-A TROJAN!
    run=Xservices.exeAdded by the TROJ/KREPPER-N TROJAN! - NOTE - this file is placed in a inet10066 folder in Winnt or Windows , and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    run=Xdllreg.exeAdded by the TROJ/DUMARU-L TROJAN!
    run=Xmdm.exeAdded by the TROJ/PROXY-GG TROJAN!
    RunAlertUAService.exeMSI MOtherboard PC Alert III - MSI motherboard monitoring software. Only required if you "overclock" your system
    runAPNrunAP.exeNot required but what is it?
    Runapp32XRunapp32.exeAdded by the NEODURK VIRUS!
    RunBackXLaunchBD.exe MyBackDrop - is or bundles a GoGotools adware variant. See privacy_policy
    RunBDXbackdrop.exe MyBackDrop - is or bundles a GoGotools adware variant. See privacy_policy
    RunCAYInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
    Rund11XRund11.EXEAdded by the W32/Mario-C WORM!
    rund1132Xrund1132.exeAdded by the W32/DOPBOT-A WORM!
    Rund1132.exeXRund1132.exeAdded by the Troj/StartPa-HS TROJAN!
    Rund1l32XWinfi1e32.exeAdded by the MERTIAN VIRUS!
    Rundil32XUpdadv.exeAdded by the Troj/QQPass-N TROJAN!
    Rundil32Xrunlli32.exeAdded by the Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    rundl332Xmath.exe ...pluged.exeAdded by the DOOMJUICE VIRUS!
    rundli32Xrundli32.exeAdded by the LADE VIRUS!
    Rundli32Xrunlli32.exeAdded by the Troj/QQPass-U TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    RunDLLXrundll32.exe bridge.dll, LoadFlingstone.com browser hijacker
    RundllXRundll~.exeAdded by the W32/DELF-KT TROJAN!
    RundllXrundll32.exe [random file name].dll "taskmon"Added by the MYTOB.IG WORM!
    RunDllXRunDll.exeAdded by Troj/QQPass-AH TROJAN!
    rundll###Xdie.exe and either ttg.exe or secure.exe or mdll.exe or secure.batAdded by the SUMTAX VIRUS! where ### is 134, 569, 777 or 946
    Rundll16XRundll16.exeAdded by any number of VIRUSES!
    Rundll32XRundll32.exeAdded by the DVLDR VIRUS! Note - this is not the valid "Rundll32.exe" as it\'s in the Windows\Fonts directory
    RUNDLL32NRUNDLL32.EXE NvQtwk, NvCplDaemonSystem Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards. This is unnecessary since you can easily configure these settings the way you want them in the Display Properties and not have to mess with them again. Also disable the "NVIDIA Driver Helper Service" if enabled as it can cause this entry to be re-enabled on re-boot (note that this service can also cause extreme shutdown delays if enabled - see here)
    RunDLL32NRunDLL32.exe NvMCTray.dll, NvTaskbarInitSystem Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
    rundll32URundll32.exe Wf2kcpl.dll DllLoadDefaultSettingsLoads default settings for Leadtek Winfast graphics cards
    RunDLL32Xwinupdate.exeUnidentified VIRUS! - possibly a BMBOT variant
    Rundll32XWindows.exeAdded by the QQPASS.E VIRUS!
    rundll32X(path to worm)Added by the AUTEX VIRUS!
    rundll32Xrundll32.exeAdded by the SANKER VIRUS! Note that the valid "rundll32.exe" resides in C:\Windows\System32 wheras this version resides in C:\Windows
    rundll32Xcsrss.exeAdded by the GUTTA TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup!
    rundll32URunDLL32.exe irprops.cpl, BluetoothAuthenticationAgentAssociated with a Bluetooth adapter. If disabled the error dialogue box disappears
    RUNDLL32Xrundl32.exeAdded by the W32/Demotry-A Worm!
    rundll32Xrundll32.exeAdded by the Troj/Agent-EZ keylogging TROJAN! Note: This trojan file is found in the System\SHELLEXT (95/98/ME) or System32\SHELLEXT (NT/2000/XP) folder. Do not confuse this with the real rundll32.exe which resides in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Rundll32 cmicnfgNRundll32 cmicnfg.cpl, CMICtrlWndSystem tray control panel for C-Media based soundcards - often included on popular motherboards with in-built audio. Available via Start -> Settings -> Control Panel
    Rundll32.exeXProyecto1.exeRoot.exeAdded by the GRUEL VIRUS!
    Rundll32.exeX(file name)Added by a W32/Xelif-A worm infection
    Rundll32_7Xrundll32.exe MSIEFR40.DLL, DllRunServerBrowserAid "Featured Results" hijacker variant
    Rundll32_8Xrundll32.exe inetp60.dll, DllRunServerBrowserAid parasite variant
    Rundll32_8Xrundll32.exe C:\1.dll,DllRunServerAdded by BrowserAid adware
    rundll64X(path to worm)Added by the AUTEX VIRUS!
    RundllSvrXRundll.exeAdded by the W32.HUAYU WORM!
    Rundllsystem32XRundllsystem32.exeAdded by the NETDEVIL.B VIRUS!
    RundnmXRundnm.exeAdded by the TROJ/DELF-HA TROJAN!
    RUNGogoToolsXLaunchAdware.exe GoGoTools adware
    RUNGogoToolsXGoGoLaunch.exe www.gogotools.com adware
    RUNHYPERXhyperx.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    runingXwin.exeAdded by the Troj/Delf-LC TROJAN!
    RUNLOADXl0ad.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    RUNLOUDXloud.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    RunnerXlsass.exe /i (Original trojan file name)Added by the Troj/Drowsy-B TROJAN! Note: This is not the legitimate Windows Process lsass.exe. (Which is found in the System32 folder.) This worm/trojan file of the same name is found in the Windows or Winnt folder.
    RunOnceURUNONCE.EXEPart of MS Data Access Components - only required if you use these
    RunProgXServer.exeAdded by the OPTIX.04.A VIRUS!
    RunProgXwini.exeAdded by the OPTIX.04.D VIRUS!
    runreperXviewer.exeAdded by the W32.REPER.A WORM!
    runsXrun.exeAdded by the W32/Rbot-BWF WORM!
    RunServicesXrunsvc32.exeAdded by the AGOBOT.QJ WORM!
    runSubvaluesX[path to file]Added by the TROJ/DLOADER-QY TROJAN!
    RunSysd32URunSysd32.exeDesktopShield2000 by Stéphane Groleau. Locks the desktop at bootup so that users cannot bypass the Windows screensaver password. Only essential if using the program and is an optional setting. It can be disabled from within
    Runtt1XInternet.exeAdded by the Troj/Lineage-Q Trojan!
    Runtt1XInternat.exeAdded by the Troj/Lineage-R Trojan!
    RunWinX[path to file]Added by the TROJ/BANKER-ES TROJAN!
    runwin32Xrunwin32.exe Troj/ESearch-A trojan
    RUNWIN32Xrunwin32.exeAdded by the Troj/VB-AET TROJAN! Note: This trojan file is found in the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    RunWindowsUpdateXuptodate.exeBrowserAid/BrowserPal foistware
    Run[0]Xsyscnfg.exeAdded as the result of an unidentified VIRUS!. "syscnfg.exe" is found in the C:\windows\fonts (or C:\winnt\fonts) directory where no *.exe files should reside
    Run_cdXRun_cd.exeAdded by the GHOST.23 VIRUS!
    Rupsw32URupsw32.exe MegaTec Rups, UPS monitoring software - monitor and control DB9 UPS running on either Windows & Novell NetWare (with RUPS 2000) or Unix (with RUPS for Unix / Plus) operating systems.
    RUSBHOLoader?rundll32.exe RUSBHOLoader.dll, AutoRegister??
    RVC6PlayerXtskdbg.exeAdded by the TROJ/ZAPCHAS-M TROJAN!
    rvdeXN/ARelated to li-speed****
    RVPXbpc.exe BroadcastPC adware
    RxMonNrxmon9x.exeDell Resolution Assistant
    r_serverYr_server.exeRadmin - remote admistrator server
    r_serverXservice.exeAdded by the TROJ/MULTIDR-CP TROJAN!
    S0undManXsvch0st.exeAdded by a variant of the LOVGATE WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    S24EvMon?S24EvMon.exeEvent Monitor - supports driver extensions to NIC Driver for wireless adapters. Is it required?
    S3 Internal ChipXs3serv.exeAdded by the W32/AGOBOT-DD WORM!
    S3apphkNS3apphk.exeA tool installed alongside the drivers for your S3 video output device. It is not necessary but should be allowed to run unless it is causing problems.
    S3Hotkey?s3hotkey.exeS3 Video driver related. What does it do and is it required?
    S3Mon?S3Mon.exeS3DuoVue multi-monitor taskbar helper by S3 Graphics. What does it do and is it required?
    S3TRAYNS3Tray.exeS3 display configuration taskbar utility for S3 chipset based graphics cards. Can be run from Start-> Settings -> Control Panel -> Display
    s3tray2?s3tray2.exeSame as the s3tray entry in this table?
    S3TRAYHP?S3trayhp.exeS3 Video driver related. What does it do and is it required?
    S4FUS4F.exeS4F internet filtering software
    s4helperXs4helper.exeSearchcentrix hijacker
    SA?Sa3.exeLogitech QuickCam driver. Is it required?
    SA Service?SAservice.exeAssociated with Cyber Trio and Warner troubleshooting software fromG-Tek Technologies and pre-installed on some Packard Bell and NEC PCs. What function does this perform and is it required?
    Sa3dsrvNSa3dsrv.exe3D sound extension for Windows
    saapXsaap.exe 180Solutions/N-Case adware variant
    SabreserverNSABSERV.EXEAirline reservation software from Sabre. Available via Start -> Programs
    sacXsac.exe 180Solutions/N-Case adware variant
    SACCXsacc.exe SurfAccuracy adware
    SAClientNRegCon.exeAT&T or ComCast BBClient - monitors system and network-delivered services for availability. Your current network status is displayed on a color-coded web page in near-real time. When problems are detected, you\'re immediately notified by e-mail, pager, or text messaging
    SafeXSafeWin.exeAdded by a PWSteal.Focosenha trojan infection.
    SafeX(Path to trojan exe)Added by the Troj/Banker-DT TROJAN!
    SafeGuard Popup Blocker UpdaterXregsvr32 [path] sfgupd.dll SafeguardProtect/Veevo
    SafeGuard Popup Blocker Updater (required)Xregsvr32 [path] sfg****.dll (* = ramdom char/digit) SafeGuardProtect/Veevo
    SafeGuard Popup Updater (required)Xregsvr32 [path] PDF****.dll (* = random char/digit) SafeguardProtect/Veevo hijacker
    SafeHouseSystemTrayUSDWTRAY.EXE SafeHouse "Personal Privacy" system tray icon - PP protects and hides your private and personal photos, videos, files and folders by making them "invisible" and encrypted.
    SafeInstall.exeNSAFEIN~1.EXEMonitors a download and ensures an newer version of a file isn't replaced by an older one
    SafeOFFNSafeOff.exeProvides protection that if user accidentally presses the power switch a dialog will pop up for confirmation
    SafeSearchXsafesearch.exeAutoSearch parasite variant
    SafeSurfingUpdateXSSUpdate.exeDyFuCa/MoneyTree parasite variant
    SafeworldUFreedom.exeSafeWorld Internet Security
    Sagate Security FirewallXsagate.exeAdded by the W32.GAOBOT.BOW WORM!
    SAgent2ExePathNSAgent2.exeSeiko Epson printer status agent. Disable if printer is not used often
    SAGENTSERVICEUSagent.exe -startAdded by TinySpyAgent **Note this application must be manually installed.
    sagntXsagnt.exeAdware web downloader
    SAHagentXSahagent.exe ShopAtHomeSelect adware
    SAHBundleXbundle.exe ShopAtHomeSelect adware
    SAHBundleXshop1003.exe ShopAtHomeSelect adware
    saieXsaie.exe 180Solutions/N-Case adware variant
    SAIMONUSaiMon.exeSaitek joystick driver
    sainXsain.exe 180Solutions/N-Case adware variant
    saisXsais.exe 180Solutions/N-Case adware variant
    SaiSmart?SaiSmart.exe"Smart Button Special Sauce" - included with the latest software for Saitek game controllers. Related to the "S", "Shift" or "Smart" button. What does it do and is it required?
    SaitekAutoConfigureUsaicnfig.exeConfiguration for Saitek game controllers
    SakemsneqlXsimenu.exeAdded by the SDBOT.BTO WORM!
    salmXsalm.exe 180Solutions/N-Case adware variant
    Sam-sungXSam-sung.exeAdded by a variant of the W32/SDBOT WORM!
    SAMcalUSAMcal.exeSamCal - calendar/reminder program
    Sametime ConnectUConnect.exeIBM Lotus Instant Messaging and Conferencing software
    SamsongXSamsong.exeAdded by the SDBOT.BNE WORM!
    SamsungXSamsungs.exeAdded by an IRC_TROJAN variant!
    SandIconNSandIcon.exeSanDisk ImageMate CompactFlash card reader SDDR-31 (USB). Very little use except to place the Sandisk icon beside its drive designation in Windows Explorer. The reader itself will work fine without it. The simplest thing is to just unplug the reader when you're not using it. It may slow the startup by a few nanoseconds, but once the software sees there's no reader, you get back the resources
    sappXsapp.exe 180Solutions/N-Case adware variant
    saSyncMgrXrundll32.exe sasync.dll, SyncWaitBrowser hijacker - redirecting to Searchant.com
    SATARaidUSATARaid.exeRAID driver for serial ATA disks on some motherboards such as the DFI Lanparty range. Only loaded if one is using RAID support on SATA drives
    satmatXsatmat.exe Transponder parasite updater/installer
    sauXsau.exe 180Solutions/180Search adware
    SAUpdateUSAUpdate.exeBig Brother from Quest Software. System and network monitor
    SAutoLaunchExeUSAutoLaunchExe.exeSharp Zaurus PDA related, needed to synchronize information with a Desktop or Notebook.
    SAVAgentYSAVAgent.exePart of Sophos anti-virus software. Required for centrally administered Sophos updates to work correctly, e.g. automatically updating PCs used by dial-in home or out-of-office users
    SaveXSave.exe SaveNow adware
    SaveDateXSaveStartDate.ExeUnidentified adware
    SavenowXSaveNow.exe SaveNow adware
    SavenowXsavenow.exe SaveNow adware
    SAWXsaw.exe SmartAdware adware
    Say The Time 5.0USAYTIME.EXEThis program has audio cues for the system clock in male and female voices, customizes the appearance of the system clock, and can synchronize it to a time server regularly
    SBUsb.exeAcer Soft Button on Acer Tablet PCs
    SB Audigy 2 Startup MenuN/l:engRelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function
    SB WatchdogXSBWatchdog.exeSpyware utility installed by the manufacturers of some laptops (Sony) used to monitor browsing habits and send them back to whoever installed it - released by SoftBank. See here for more information
    SBAutoUpdateUsbautoupdate.exeSpywareBlaster auto-updater
    SBC Self Support ToolUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The SBC Self Support Tool is required to run with the Help and Support program. If you uncheck SBC and and then run Help and Support it will add another SBC entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide
    SBC Yahoo! Connection ManagerNConnectionManager.exeThe cmanager.exe process is used to create and connect your SBC Yahoo DSL connection. This program has been reported to cause problems for some users. If you find that it causes you pc to become slow or unstable you should uninstall it (using Add/Remove programs) and manually connect your DSL connection.
    SBDrvDetUSBDrv.exeDetects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" on the Sound Blaster Audigy 2 Platinium eX. Can be disabled if you don't have one
    sbdrvdetNsbdrvdet.exeChecks to see if Creative sound card driver should be updated
    SBHCXsbhc.exeSuperBar parasite - uninstall available here
    SBMPOPXSBMPop.exeSearchByMedia adware
    SBMXNsbmx.exeSoundMAX MPU401 MIDI device emulator for x86 VM DOS games/apps (for Win9x only)
    sbss LauncherXsbss.exe SideBySide adware
    SbUsb AudCtrlURunDll32 sbusbdll.dll,RCMonitorControl for Soundblaster MP3 external (USB) sound card
    scNscrubxp.exeScrubXP - utility that deletes safe to remove files, cookies, browsing history, etc
    scUsc.exeWatchdog 2.0 Software - monitoring program
    scUrun.exe All-In-One_SPY stealth monitoring software - allows monitoring and recording of all actions performed on a computer. It records all keystrokes, remembers addresses of Internet pages visited, and maintains a log file listing all applicationsrun on the computer. It can create screenshots and record sounds from the computer's microphone to a sound file.
    sc23exec?sc23exec.exePossibly related to a digital camera
    SC3300CCYSC3300CC.exeSiPix digital camera Twain device driver
    scainXs030109.Stub.exeAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    ScamDiskXSVOHOST.exeAdded by the LEWOR.D WORM!
    scanXmscman.exeSpyware/malware, included into the latest version of Grokster, among others. According to research by SpyBot's PMK,  "able to trick ZoneAlarm, auto-clicking it to allow passing through the firewall!"
    Scan Detector?Pmxdetect.exeAssociated with PrimaScan scanners. Is it required?
    Scan RegisterXssms.exeAdded by the W32/RBOT-AT WORM!
    Scan Wizard?button.exeAssociated with ScanWizard as supplied with Microtek scanners - see also Scanner Detector or SDetect. What does it do and is it required?
    ScanDiscXsatan.exeAdded by the GregStar backdoor TROJAN!
    ScanDiskXScanDisk.exeAdded by the GANDA.A VIRUS! Note - this is not the valid "ScanDisk" Win9x/Me standard disk error checker
    scands32.exeXscands32.exeAdded by a variant of the Adclicker TROJAN!
    ScanFile?????
    ScanInicio?Inicio.exePart of Panda Anti-Virus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active
    Scanner DetectorNSDetect.exeScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
    ScanPanel?ScnPanel.exeTrust Easy_Webscan scanner related - what does it do and is it required?
    ScanregX(filename)Added by the QQPASS.E VIRUS!
    ScanRegistryXnsrvnt.exeAdded by the NERTE VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe
    ScanRegistryXscanregv.exeAdded by the MASTERLOCK VIRUS!. Not to be confused with the real ScanRegistry below - which is a vital Windows file. This version has the executable as scanregv.exe not scanregw.exe
    ScanRegistryYScanregw.exeScans the Windows 98 and Millennium system Registry and makes back-ups at start-up. This is vital should the registry become corrupt. The "Scanregw.exe" executable is located in %windir% (the Windows directory - typically C:\Windows)
    ScanRegistryXScanregw.exeAdded by the W32.STATOR WORM! Not to be confused with the legitimate ScanRegistry entry - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt). Runs from the registry RunServices key as opposed to the Run key
    ScanRegistryXScanregw.exeAdded by the GWGHOST VIRUS!. Not to be confused with the real ScanRegistry above - which is a vital Windows file. The executable "Scanregw.exe" is located in %windir%\System (where %windir% is the Windows directory - C:\Windows or C:\Winnt)
    ScanSpyware v *XScanner.exe"Spyware remover" (where * = the version number) of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    scAppXscApp.exeAdded by the W32/Stando-E WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SCardSvrNscardsvr.exeRelated to SmartCard readers and sometimes uses lots of system resources
    SCardSvrXSCardSvr32.ExeAdded by the MOFEI.B VIRUS!
    scheckXscheck**.exeAdded by the KETCH VIRUS! where ** represents a number
    scheck45Xscheck45.exeRelated to unknown Malware - hidden installer associated with it
    ScheduIeXnrchk.exePremium rate adult content dialer
    Scheduled MaintenanceNScheduled_Maintenance.exeScheduler for Iolo System Mechanic tweaking utility. It can cleans your registry and deletes temporary files at defined intervals. Available via Start -> Programs
    SchedulerXsvcrhost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    SchedulerXoutIook.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    SchedulerXexpIorer.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    SchedulerXsvcshost.exeAdded by the WIN32.TACTSLAY.A TROJAN!
    SchedulerXwinagent.exeAdded by the WIN32.TACTSLAY.B TROJAN!
    SchedulerXMSMSGS.EXEAdded by the TROJ/HOSTBANK-A TROJAN! - NOTE: this particular msmsgs.exe file is located in the Windows\System32\Config or Winnt\System32\Config folder, and should not be mistaken for the MSN Messenger file of the same name!
    SchedulerUScheduler daemon.exe Tenebril GhostSurf or SpyCatcher related scheduler - you can schedule daily, weekly, monthly or one-time only cleanings.
    Scheduler ServiceXwsass.exeAdded by the WIN32.LIOTEN.KX WORM!
    SchedulerMgrXnavchk.exePremium rate adult material dialer
    Scheduling AgentXScheduler.exeAdded by the SUBWOOFER VIRUS! Note - this is not the real MS Scheduling agent as the executable is incorrect
    SchedulingAgantXMMTASK.EXEAdded by the YAB.A VIRUS! Not the valid MusicMatch Jukebox which has the same filename
    SchedulingAgentUmstask.exeWindows Task Scheduler, displayed as a box with a stopwatch in the System Tray - required if you have regularly scheduled tasks like defragmenting, ScanDisk, weekly virus scans and so on.
    SchedulingAgentUmstinit.exeMS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans
    SchmailiUSchmaili.exeSchmaili - insert animated smilies into your e-mail
    Schoolpop0USchoolpop0.exe Schoolpop Shopping Buddy
    schostX(Path to trojan)Added by the Backdoor.Tjserv.D TROJAN!
    SCHWIZEXYSCHWIZEX.EXEPart of ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions - provides a restore function. This part takes a snapshot of your system following a healthy re-boot
    ScManagerXscman.exeAdded by the W32/FORBOT-CW WORM!
    scopedllXscopedll.exeAdded by a CRYPTER.C trojan variant infection
    Scotia OnLine Recovery or Scotia OnLine SecurNetdirrcv.exeScotia OnLine Security Software provided by Entrust for Scotiabank. Provides trusted secure access to Scotia OnLine Secure Web sites. *.* represents the version number. Now obsolete after Scotiabank modernised their login process
    ScrXscr.scrAdded by the OPASERV.T VIRUS!
    ScrapPadNScrappad.exeScrapPad allows you to quickly and easily record notes, thoughts, messages, and just about anything you want. Use it like you use scrap paper
    scrbmkX(Pathname of the Trojan executable)Added by the Troj/Dloader-VP TROJAN!
    Screen CalendarUscrcal.exe Screen_Calendar allows you to create custom desktop wallpapers with built in active calendar and scheduler.
    Screen GuardUlaunch.exePart of Access Denied security and privacy software
    Screen Guard Message ScanUsgms.exePart of Access Denied security and privacy software
    Screen SaverXscrnsaver.scrAdded by the W32/Rbot-AGP WORM!
    Screen Saver ControlNFSScrCtl.exeInstalls as part of the Hubble Space Telescope screen saver (and possibly others). Lets you control your installed screensavers from a System Tray icon
    ScreenPrint32NScreenPrint32.exe ScreenPrint32 screen capture software - can be launched manually.
    screxe?scruser2k.exe??
    script?script.batMaybe associated with DOS on a Win9x machine
    ScriptBlockingYSBServ.exeUpdate to Norton AntiVirus 2001. Detects certain types of script-based viruses without the need for specific virus definitions - such as JavaScript and VBScript. This will help protect you from these viruses even before virus definitions are available. Note - some users complain of problems once the update is installed - refer here for more information
    ScriptSentryYScriptsentry.exeScript Sentry from Jason's Toolbox. Blocks malicious scripts and allows safe scripts to run. Only required if you want it to check the file associations it guards at startup. It will function regardlessly
    Scroll-In-Mouse V2.0USCROLL.EXEToolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features
    scrsvcXscrsvc.exeHijacker, a CoolWebSearch parasite variant - also detected as the Troj/Agent-DS Trojan!
    ScrSvrXScrSvr.exeAdded by the OPASOFT.A VIRUS!
    ScrSvrXScrSvr.exeAdded by the OPASERV VIRUS!
    ScrSvrOldX(worm filename)Added by the OPASERV VIRUS!
    ScsiYScsi.exeSCSI Miniport driver
    scvhostXsvzhost.exeAdded by a variant of the W32.SPYBOT WORM!
    scvhostXscvhost.exeHijacker, redirecting to bestsearch.cc - recognized by Kaspersky antivirus as Trojan.Win32.StartPage.rw
    scvhostUscvhost.exe Wiretap is a spyware program that monitors and records keystrokes, programs executed, Web sites visited, and Instant Messenger conversations. If you didn't install this yourself, remove it.
    scvhost loaderXixplore.exeAdded by the SDBOT-CY TROJAN!
    scvhost.exeXscvhost.exeAdded by a Troj/Lohav-N trojan infection
    scvhost.exeXscvhost.exeAdded by the W32/AGOBOT-RA WORM!
    sd32infoXsd32info.exeAdded by a CRYPTER.A trojan infection
    SDaemonUsdaemon.exePC Security from Tropical Software. 'PC Security™ 5.1 is the ultimate in computer security, offering multiple locking systems for the Windows environment and internet. Lock files, monitor programs' activities, even detect intruders! PC Security offers flexible and complete password protection, "Drag and Drop" support, plus many other handy features'
    SDAutoLiveupdateXLiveUpdateSD.exeMax Secure Spyware Detector, bogus "Spyware remover" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "spywaredetector.net"
    SDAvXcsnss.exeAdded by the W32.Serflog.C WORM!
    SDAvXsvhost.exeAdded by the W32.Serflog.C WORM!
    sdchosts32Xvbdd.exeAdded by the WIN32.RANKY.AG backdoor TROJAN!
    SDetectNSDetect.exeScanSuite Scanner Detector - part of ScanWizard, supplied with Microtek scanners. Waits until you press the "GO" button and seems to serve no other purpose. Automatically installed without prompting. Not required if you can start your scanning application before pressing the "GO" button
    sdfsdfsdfXsp2update.exe W32.SpyBot worm variant
    SDIN AdapterXsdin.exeAdded by a W32/Forbot-AP worm infection
    SDJobCheck?triggusr.exePart of CA_Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required in startup?
    SDK Codre Function22Xsdkimddprovment2.exeAdded by the W32/SDBOT-YJ WORM!
    SDK Core ComponentXSDKC0RE.exeAdded by the W32/SDBOT-WC WORM!
    SDK Core ComponentXsdkcore.exeAdded by the W32/SDBOT-WC WORM!
    SDK Core FunctionXsdkimprovment.exeAdded by the RBOT.BHL WORM!
    SDK Core Function2Xsdkimprovment2.exeAdded by the W32.SPYBOT.OGX WORM!
    Sdk**.exe (* = random char)XSdk**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Sdk**32.exe (* = random char)XSdk**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    SDKcore Update Components2XSDKC0R3.exeAdded by the W32/RBOT-ABA WORM!
    sdkupdate22XSDK0mCORE.exeAdded by the W32/FORBOT-DT WORM!
    SDPhotoBar.exeNSDPhotoBar.exe SmartDraw_Photo . Organize, enhance, print, and share your photos. It's also a powerful graphic editor for creating images and web graphics.
    sdrssXsdrss.exeAdded by the W32/SDBOT-SQ WORM!
    sds20Usvchost.exe InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it.
    SDTrayUsdtray.exeRSA Keon Web_PassPort - software that allows organizations to use digital certificates in a Web-based environment to help ensure that their transactions are authentic, confidential and digitally signed.
    sdxsys32Xsdxsys32.exeAdded by the Troj/Brogger-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    sealmonUsealmon.exe SealedMedia enables you to combine document protection and control with your existing applications, such as Microsoft Word, Microsoft Excel, Microsoft PowerPoint and Email.
    Search BarXtaskbar.exeAdded by the W32/OPANKI-F WORM!
    Search Hook?srchhook.exe??
    Search PageXhttp://find.naupoint.com Naupoint browser hijacker
    Search-ExeXSE.exeHijacker - redirecting to Search-exe.com
    Search-ExeXse.exeSearch-Exe hijacker
    Search.vbsXHijacker
    searchbarXvnmispoisn_downloader.exeSearchBarCash adware variant
    SearchEnhancementXscbar.exeIE search hijacker
    searchnavXsearchnav.exeSearchNav adware - IEFeatures/Popnav variant
    SearchNavVersionXsearchnavversion.exeSearchNav adware - IEFeatures/Popnav variant
    SearchSetterXsearchsetter[1].exebrowser hijacker, redirecting to FindWhateverNow.com
    SearchSquire33XSearchUpdate33.exeSearchSquire parasite
    SearchUpgraderXSearchUpgrader.exe eUniverse/KeenValue adware related hijacker
    SecbootXw32tm.exeAdded by the HAXDOOR.D TROJAN!
    secbootXmszx23.exeAdded by a variant of the HAXDOOR.D TROJAN!
    secbootXvtd_16.exeAdded by the TROJ/HAXDOOR-AE TROJAN!
    SecondChanceUsctray.exePower Quest Second Chance. Sets checkpoints for saving a backup copy of the registry to a disk so you can restore it if you have a crash
    SecretXSecret.exeAdded by the Troj/Delf-LW TROJAN!
    Secret-CrushXstart.exeHijacker that may reset your browser's home page and/or search settings to point to undesired sites
    SECRETMAKERUsecretmaker.exe SECRETMAKER is a combonation of eight privacy-defending programs, including Spam Fighter Pro, Worm Hunter, Pop-Up Killer, Banner Blocker, Cookie Eraser, Privacy Protector, History Cleaner, and Garbage Cleaner.
    SecretSmileysUss.exe Secret_Smileys is an add-on for AIM® that provides users access to 1000's of new Smileys that can be viewed by anyone using a current version of AIM. Secret Smileys also adds other features such as logging of IM conversations, and it gets rid of that annoying advertisement on your buddy list window.
    secserv.exeXsecserv.exeReported by Panda as an EasySearch Adware variant. Note: EasySearch modifies the Internet Explorer settings and may download programs onto the infected computer.
    secsvc32Xsecsvcnt.exeAdded by the Global_Patrol TROJAN!
    SecsysUSecsys.exeKey Interceptor - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    secureXsecure.exe DealHelper adware
    secureX[random filename] DealHelper adware
    secureXsvshost.exeAdded by the W32/Rbot-AFO Worm!
    SecureClean4RegManagerNscregmanager4.exeWhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
    SecureClean4TrayNsctray4.exeWhiteCanyon SecureClean_4 disk cleaner - clean hard drive data, MRUs, temp files and more. Can be started manually
    SecureCleanIECleanNSCIEClean.exeSecureClean - scans your system for hidden temporary files, deleted email messages, Internet histories and caches
    SecureItProUSecureitpro470p.exeSecureIt Pro - lock your computer when you're not there, to stop malicious users from accessing your desktop
    SecureLoginXMslg32.exeAdded by the REDZED VIRUS!
    Security Accounts Manager SMXsamsm.exeAdded by the SPYBOT.JE WORM!
    Security AgentXsecurag.exeAdded by the Troj/Bancban-F TROJAN!
    Security Agent ManagerXmssams.exeAdded by the W32/RBOT-SV WORM!
    Security iGuardNSecurity iGuard.exe"Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    Security ManagerUSecurityManager.exeA ComCast Internet software suite that provides a variety of features (firewall, popup blocker, parental controls etcetera) to help ensure your computer is secure, and your information is kept private.
    Security PatchXscmss.exeAdded by the W32/RBOT-ZW WORM!
    Security PatchXWinUpdate32.exeAdded by the W32/SDBOT-BM WORM!
    Security PatchesXmsnkn.exeAdded by the RBOT.WW WORM!
    Security PatchesXWinLab32.exeAdded by the W32/SDBOT-KB WORM!
    security serviceXsyss.exeAdded by an unidentified WORM or TROJAN!
    securwXNctrup.exeAdded by the W32.NOPIR.A WORM!
    SECWIZ98YSECWIZ98.EXESecurity Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here
    seeveXseeve.exe MediaMotor/Popuppers adware variant
    Select serverXslcsvr.exeAdded by the TROJ/DLOADER-WD TROJAN!
    SelfHostUtil?slefhost.exe??
    seliX[path to executable]Added to Troj/LowZone-AS TROJAN!
    SeMSUSeMS.exe

    PCsms - tool that enables you to send sms text messages from your PC to any UK mobile phone

    SenXtlii.exeReported by Kaspersky Anti-Virus as Win32.PurityScan.ah This Malware file is usually found in the Program Files\bama folder.
    SensivaUSensiva.exe Symbol_Commander makes the use of your PC, laptop, Tablet PC, and Pocket PC much easier and much faster. It recognizes your handwriting with unparalled performance and executes commands in a snap. Just by using your mouse, pen, or touchpad, simply draw symbols to execute actions instantly.
    SENTRYXSENTRY.exeFrom IP Insight. Allows website owners "to instantly determine the precise geographic location, connection speed and detailed demographics of every visitor to your website". Will be detected by most firewalls and the majority of home users should disable it 
    Sepate Security FirewallXsepate.exeAdded by a variant of the WIN32.RBOT WORM!
    SerialsXserials.exeAny one of a variety of worms and trojans
    serpeXformatsys.exeAdded by the W32.Serflog.A WORM!
    serpeXserbw.exeAdded by the W32.Serflog.A WORM!
    serpeXmsmbw.exeAdded by the W32.Serflog.A WORM!
    serrdctl.exeYserrdctl.exe"Shared Modem Service Client Event Viewer" - used when a number of PCs have access to a number of modems. Required to be running on each PC for access to the modems
    SERV PacK2Xnerx.exeAdded by the W32/SDBOT-ACP WORM!
    Serv-UNserv-u32.exeFTP server
    Serv-UXwssdsu.exeAdded by the MANIFEST VIRUS!
    serverXserver.exeAdded by the Troj/Singu-Q TROJAN!
    serverXsystem.exeAdded by the Troj/Meths-A TROJAN!
    Server BackboneXserver05.exeAdded by the W32/RBOT-ZM WORM!
    SERVER.EXEXSERVER.EXEAdded by the BUSHTRO122 or SMOKODOOR VIRUSES!
    serverexXServer.txt.vbsAdded by the DELTAD.A VIRUS!
    ServiceXservice.exeAdded by the ALADINZ.H VIRUS!
    ServiceXservices.exeAdded by the W32.NETSKY or W32.NETSKY.B WORM! **Note - not to be confused with the valid Windows "services.exe" which resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K) or C:\Windows\System32 (WinXP) as this resides in C:\Windows or C:\Winnt
    ServiceX(trojan filename)Added by the KAITEX.E VIRUS!
    ServiceXSYSNT.exeAdded by the BACKDOOR-CHA TROJAN!
    serviceXservices.exeAdded by the W32.NETSKY.AI WORM! - Note - this is NOT the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    ServiceXService.pifAdded by the W32/ASSIRAL-C WORM!
    serviceXwN2S.exeAdded by a variant of the WIN32.RBOT WORM!
    Service CleanerXfilen.exeAdded by the RBOT.BRH WORM!
    Service ConnectionNsccenter.exe, bwtray.exeFor Compaq PC's. Part of Backweb
    Service ControllerXCsrrs.exeAdded by the GAOBOT.AO WORM!
    Service ControllerXservice.exeAdded by the PREVERT TROJAN!
    Service DriversXCompt.exeAdded by the W32/RBOT-ZJ WORM!
    Service DriversXmsnpg.exeAdded by the RBOT.BMD WORM!
    Service DriversXPC.EXEAdded by the W32/SDBOT-WK WORM!
    Service DriversXabl.exeAdded by the W32/Sdbot-YX Worm!
    Service HostX(filename).exeAdded by the TORVEL.B VIRUS!
    Service HostXspoolos.exeAdded by the TORVEL VIRUS!
    Service HostXSVCHOST.EXEAdded by the DAOSER-A TROJAN! - NOTE - this file is placed in a subfolder of WINDOWS\System32\Services, and is not to be confused with the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    Service Host DriverXsvchost.exeAdded by the HITON VIRUS! This is not the valid svchost.exe as described here. Located in a Windows directory, and not in Windows\System32
    Service ManagerXDXSOUND.EXEAdded by the Proxy-Gric TROJAN!
    Service ManagerNsqlmangr.exeSQL Server Service Manager - provides tray access to SQL server, the server agent and MSDTC. Available via Start -> Programs
    Service ManagerXSERVICEMGR.EXEAdded by the W32/PASSMAIL-D VIRUS!
    service managerXservice.exeAdded by the DONBOMB.A TROJAN!
    Service ManagerXserv3manager.exeAdded by the W32/Sdbot-AGO WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Service MonitorXfilen.exeAdded by a variant of the WIN32.RBOT WORM!
    Service MonitorXmsnfilen.exeAdded by W32/Rbot-ALE or W32/Rbot-AUY WORM!
    Service MonitorXWinOcx.exeAdded by the W32/Rbot-AQJ WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Service MonitorXjavams32.exeAdded by the Troj/Delf-NK TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Service MonitorXmsnserve.exeAdded by the W32.SPYBOT.YQW WORM!
    Service PackX(See description box.)Added by the W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
    Service Pack DLL RuntimeXspdll32.exeAdded by a variant of the WIN32.RBOT WORM!
    Service ProcessXSVCHOST.EXEAdded by the DARKER VIRUS! Note - not the valid svchost.exe as described here. Located in %Windir% not %Sysdir%
    Service ProcessXwinset.exeAdded by a variant of the W32.SPYBOT WORM!
    Service ProcessXservice.exeAdded by the Troj/Dcmbot-C TROJAN!
    Service Registry NT SaveXjdbgmgrnt.exeAdded by the Troj/Bancos-EU TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Service Registry NT SaveXtaskmgrnt.exeAdded by the TROJ/BANCOS-BY TROJAN!
    Service Registry NT SaveXregeditnt.exeAdded by the TROJ/BANCOS-BM TROJAN!
    Service SchedulerXscheduler.exeAdded by the W32/AGOBOT-PH WORM!
    Service SystemXkernels32.exeAdded by the TROJ/BANCOS-DA TROJAN!
    Service SystemXwindowsXP.exeAdded by the Troj/Bancos-EL TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Service SystemXwernell87.exeAdded by the Troj/Bancos-FJ TROJAN! Note: This trojan file is found in the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    Service SystemXkgbfsm344.exeAdded by the Troj/Bancos-FS TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    service updaerXqualityz.exeUnidentified worm, probably a W32.SpyBot variant
    Service.exeXService.exe"servedby.advertising" popup generator
    service32Xservice32.exeAdded by the W32/AGOBOT-ST WORM!
    ServiceConfigUispbeg.exeComcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
    serviceconnectXserviceconnect.exeAdded by the AGOBOT.AIR WORM!
    ServiceLayerYServiceLayer.exeNokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly.
    servicemngXservice.exeAdded by the W32/Tame-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    servicesXSvchosts.exeAdded by the SDBOT.N WORM!
    servicesXstart.batAdded by the ZCREW VIRUS!
    ServicesXAdded by the RANCK or RANCK.B or METEORSHELL VIRUSES!
    ServicesXback32.exe ...service.exeAdded by an unidentified VIRUS! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
    ServicesXwinread.exeUnidentified trojan
    ServicesXkirby.exe Proxy-Agent trojan variant
    ServicesXservices.exeAdded by the Backdoor.Zincite.A TROJAN! NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    ServicesXwindns.exeAdded by a variant of the WIN32.RBOT WORM!
    ServicesXmshost.exeAdded by the TROJ/LANFILT-J TROJAN!
    ServicesXsockys32.exeAdded by the WIN32.RANKY.L Proxy_Trojan
    ServicesXscks32.exeAdded by a Proxy_Trojan variant
    ServicesXsys.exeAdded by a Proxy_Trojan variant
    servicesX(Pathname of the Trojan executable)Added by the Troj/Gpcode-B TROJAN!
    ServicesXcsrss.exeAdded by a variant of the BACKDOOR.RANKY.U TROJAN!
    servicesXwindows32.exeAdded by the W32/FlyVB-C WORM!
    servicesXsocks.exeAdded by the WIN32.SMALL.N Proxy TROJAN! - A PT is a backdoor trojan which allows a remote hacker to connect to other systems via the compromised system.
    ServicesXservices.exeAdded by the W32/Antiman-E WORM!
    ServicesX[pathname of Trojan Executable]Added by Troj/Ranck-DB TROJAN!
    servicesXservices.exeAdded by the Troj/QQRob-S TROJAN! Note: This is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
    ServicesXiexplore.exeAdded by the W32.Mogi WORM! Note: This is not the legitimate Windows process iexplore.exe (Which is normally found in the Program Files\Internert Explorer folder) This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, rootkit type stealth involved.
    Services AdministratorXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Services AdministratorXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Services ControllerXlsassa.exeAdded by the CIADOOR.122 VIRUS!
    Services ControllerXservices.exeAdded by the TROJ/CIADOOR-F TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Services HostXScchost.exeAdded by the DONK VIRUS! Note - this is not the valid svchost.exe as described here
    Services HostXsvchost32.exeAdded by the W32/Agobot-TG WORM! Note: (svchost32.exe) is not the legitimate Windows Process. (Notice the 32 that's been added.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Services LogonXservices.exeAdded by the W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    Services ProcessXservices.exeAdded by unidentified spyware - recognized by Kaspersky antivirus as TrojanSpy.Win32.Small.x
    Services ProcessXsmss.exeAdded by the Troj/Small-EK Trojan!
    Services StartupXsvhost33.exeAdded by a variant of the WIN32.RBOT WORM!
    Services StartupXservices.exeAdded by the W32.CROWT.A WORM! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    Services.dllXsmss.exeAdded by the W32/SOBER-L WORM! - NOTE - this file is placed in a %WinDir%\msagent\system folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Services.EXEXservices.exeAdded by the KAZPING VIRUS! Note - this is not the valid Windows Service Controller (services.exe) process
    services.exeXServices.exeAdded by the CIADOOR-F TROJAN! - Note - this is NOT the legitimate Windows services.exe process, which should NOT figure in Msconfig/Startup!
    Services004X(worm filename)Added by the BUGBROS VIRUS!
    services32Xmc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
    services32Xmc-58-12-0000120.exe "Shorty" adware component, also detected as the AGENT.FD TROJAN!
    services32Xmc-58-12-0000140.exe "Shorty" adware component, also detected as the AGENT.FD TROJAN!
    Services32 StartupXwin32dll.exeAdded by the W32/SDBOT-XO WORM!
    ServicesLogXccapp32.exeAdded by the W32/Rbot-AMX WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    ServicingXhostd.exeAdded by the SDBOT.BUI WORM!
    Servicio LocalXsvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    servicsXservics.exeAdded by the Troj/Singu-J Trojan!
    SERVlCEXSERVlCE.EXEAdded by the W32/Agobot-UB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ServUTrayIcon?ServUTray.exeSystem Tray icon for Serv-U FTP server.Is it required?
    Session ClientUsescli.exe SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    Session Manager Subsystem Xsmssa.exeAdded by the W32/Rbot-AGS WORM!
    SESyncXsed.exe Downloadware/SED adware downloader
    SetDefaultMIDI?MIDIDef.exeRelated to a Soundblaster Audigy soundcards. What does it do and is it required?
    setdefprtNsetdefprt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
    SetDefPrtNBrStDvPt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
    SetecCertUtilUCertutil.exeSetec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet, mobile handsets and digital TV
    setFTPBackXcreatesw.exeAdded by the FTP_BMAIL VIRUS!
    SetHookNSetHook.exeFellowes Neato CD label design software. "Launch NEATO's MediaFACE II label making software directly from the productname toolbar"
    seticlient or SETI@homeNSETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
    SetIconNSetIcon.exeInstalled by a 6-in-1 (4 Media Card slots, a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog
    SetiQueueNSetiqu~1.exeProvides work unit buffering for Seti@Home clients - see here for more details
    SetiSpyNSetiSpy.exeFrom the site - 'SETI Spy is a little program I wrote to "spy" on the progress and performance of the SETI@home client. I call it a "spy" because I tried to make it as unobtrusive as possible'
    SetPointXSetPoint.exeAdded by the W32/RBOT-BWI WORM!
    SETPOINT Logitech IncXKHALMNP.exeAdded by the W32/RBOT-AAX WORM!
    SetRefresh?SetRefresh.exeFound on a Compaq PC. Video refresh rate utility? Is it required?
    SettingXsysweb.exeAdded by the SDBOT.GEN WORM!
    setupNhphprld.exe ....setup.exeHP DeskJet Setup - printers function normally without it
    Setup experationXsvchost.exeAdded by the TOFGER-AW TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which is located in the System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    setupaXrunt32.exeAdded by the TROJ/QQPASS-K TROJAN!
    setupdataXrnll32.exeAdded by the Troj/QQPass-AG TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SetupICWDesktopNicwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
    setupuserXregedit.exe setupuser.log CoolWebSearch parasite related.
    setuzp?setuzp.exe??
    SetVrcXsetvrc.exeAdded by the HUNTOCX VIRUS!
    Sex TerisXst01b.exeAdded by the REPAD VIRUS!
    SexnowXSexnow.exeAdded by the Dial/Senow-B premium rate porn dialer
    Sexy_sgXSexy_sg.exePremium rate adult content dialer
    sfXsf.exe SurfEnhance adware component
    sfitaXsfita.exeAdded by the Troj/Favadd-H TROJAN! also known as SurfEnhance adware component.
    SFPNvzSFPWin.EXEVerizon Online Support Center, promps for online updates
    sfpcUsfpc.exe Spy4PC is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it.
    SFtrb ServiceXcftrb32.exeAdded by the SOBIG.D VIRUS!
    SfWinStartInfoUsfWinStartupInfo.exe

    SFIRM32 Online Banking software

    SgecryptUSgecrypt.exeSafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
    SgeecviewUEcview.exeSafeGuard Easy - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"
    sginstNsginst.exeeAcceleration Stop-Sign related; not recommended; see note
    SGTBox?SGTBox.exeCanon scanner driver. Is it required?
    sgtrayUsgtray.exeStorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
    shambl3rXcnf.batAdded by the REMABL VIRUS!
    shambl3r*Xshambl3r.exeAdded by the REMABL VIRUS! where * is 2 to 11
    ShaniaXShania.vbsAdded by the SHANIA VIRUS! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    Share-to-Web Namespace DaemonNhpgs2wnd.exe"HP's exclusive Share-to-Web software makes it easy to share content with others through our affiliate Internet websites." In other words an application that allows users to upload scanned images to their personal webpages if desired. Available via Start -> Programs
    ShareazaNShareaza.exe Shareaza P2P client
    ShareazaUbindata.exe Shareaza P2P client related
    sharedpremXsharedprem.exeAdded by the MAKECALL VIRUS!
    Sharing and Mapping SoftwareYDShmap.exeIntel AnyPoint internet sharing software
    SharkEjectNAEJCT32.exeAllows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required
    ShcenterNchcenter.exeIMSI HiJaak - "the easiest way to convert, capture, and manage all your graphic files"
    SheduIerXsvchst.exePremium rate adult content dialer
    SheduIerXshch.exeAdded by the TROJ/BDOOR-EB TROJAN!
    SheduIerXsvchst.exeAdded by the TROJ/BDOOR-EB TROJAN!
    SheduIerXwinagent.exeAdded by the TROJ/BDOOR-EB TROJAN!
    ShedulerXnerocheck.exeAdded by the WIN32.TACTSLAY.B TROJAN!
    ShellXShell32.exeAdded by the BADSECTOR TROJAN!
    ShellXray.exeTray.exeHomepage hijacker re-directing browsers to adult content websites
    ShellXwmedia16.exeAdded by the GOLDUN TROJAN!
    ShellXOpen32.exeAdded by the Troj/Small-DL TROJAN!
    ShellXExplorer.exe, msmsgs.exeAdded by the Zhopa TROJAN!
    ShellXsvchost.exeAdded by the Doyorg TROJAN!
    ShellXExplorer.exe sound_drive16.exeAdded by the TROJ/BDOOR-GP TROJAN!
    ShellXiexplore.exeAdded by the W32/Kipis-U WORM!
    shellXexplorer.exeAdded by the Trojan.Kakkeys Trojan!
    ShellXibm0000*.exe (* = digit)Added by the Troj/Torpig-C and Troj/Torpig-J TROJANS! - Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on.
    ShellXtaskmrg.exeAdded by the Troj/Bancban-FT TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ShellXibm[RANDOM 5 DIGIT NUMBER].exeAdded by the Anserin TROJAN! Note: This trojan file is found in the Program Files\Common Files\Microsoft Shared\Web Folders folder.
    Shell API32Xsvcnet.exeAdded by the WIN32.TIBICK.C WORM!
    Shell ExtensionXspollsv.exeAdded by a variant of the LOVGATE WORM!
    Shell MonitorXservices32.exeAdded by a variant of the WIN32.RBOT WORM!
    Shell Tray WindowXShellTraywnd.exeAdded by the TROJ/STULTDOR-A TROJAN!
    shell updateXshellexec.exeAdded by the W32/Agobot-TH WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Shell32XShell32.vbsAdded by the VBS.Scafene WORM!
    shell32Xntldrt.exeAdded by the W32/Jlok-A WORM!
    ShellApiXSHELLMSN.EXEAdded by the NETDEV.B VIRUS!
    Shellapi32XShellapi32.exeAdded by the NETDEVIL (or NERTE) VIRUS!
    Shellapi32Xsvcnet.exeAdded by the W32/TIBICK-C WORM!
    Shellapi32Xmcvsrte.exeAdded by an unidentified WORM! - Note, do do confuse with the McAfee SecurityCenter file of the same name described here
    ShellCommandX(path to file)Added by the Troj/Remcon-A TROJAN!
    ShellExXShellEx.exeAdded by the ANAKHA VIRUS!
    ShellOSXA+++.exeAdded by the WIN32.VB.AV keylogger TROJAN!
    ShellRunXlexplore_.exeAdded by the Troj/MSNOpt-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ShellsplXlsas.exeAdded by the TROJ/YALER-A TROJAN!
    ShellsplXspools.exeAdded by the PROXAGE-A TROJAN!
    shellsystemXshellsystem.exeAdded by the UPCHAN TROJAN!
    shhostXshhost.exeAdded by the BACKDOOR.WIN32.AGENT.CE TROJAN!
    shicoxpNshicoxp.exeInstalled with the drivers for multi card readers of various brands. To differentiate between the various card slots on multi slot readers the shicoxp.exe file assigns and loads unique drive icons for the various card slots that are displayed in Windows Explorer.
    ShineXShine.exeAdded by the HAPPYLOW or W32/Nishe-A VIRUS!
    SHINITV?SHINITV.exe?
    Shmgrate.exeXibot4.exeAdded by the GASTER VIRUS!
    shockmachinereminderNSmReminder.exeShockmachine is an entertainment playback device that lets you save your favorite Shockwave.com titles and play them back in full-screen mode, off-line, anytime. Could be a registration reminder for the trial version
    ShockwaveXcsrss.exeAdded by the SNDOG VIRUS! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    Shockwave InitNSWINIT.EXEPart of Macromedia Shockwave. Controls the Shockwave Remote Control Panel. The Remote Control can be activated manually from the Start Menu by locating and selecting Shockwave and then Shockwave Remote under Programs
    ShortKeys 99NSHORTKEY.EXEShortKeys from Insight Software Solutions - allows you to program keys with text strings
    ShowbehindXSHOWBEHIND.EXEAdvertisement display which can be stopped here
    ShowFFXShowFF.exeAdded by the Adware.FFToolBar adware toolbar.
    ShowIcon_SmartDisk Corporation_USB Card Reade?shwicon.exeCard reader for memory cards from digital cameras. Is it required?
    ShowmeXRuden.vbsAdded by the WM97/Handle-A VIRUS!
    ShowWndXShowWnd.exeAdded by an unidentified backdoor TROJAN!
    SHPC32USHPC32.exePort monitor for Lexmark printers on a USB connection. Ties in with the Printer Control Program. Features like cancelling a print are unavailable if disabled
    ShStatEXEYSHSTAT.EXEFrom McAfee VirusScan NT 4.x. Handles program communication among VShield components, displays VShield icon. Can be started automatically or available via Start -> Programs
    ShutdownawareUshutdownaware.exeLoaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system
    ShutDownProUShutDownPro.exeShutDownPro - shutdown, reboot, logoff your System with one mouse click
    Si Meter?SIMETER.EXE??
    si91e44bXrundll32.exe (path) si91e44b.dll,EnableRunDLL32 LZIO.com adware downloader
    SIAPRO6Usia.exeSteganos Internet_Anonym privacy software
    SicomXSicom.exeAdded by the NETLIP VIRUS!
    SideACTUSideACT.exeSideACT organizer software
    SidebarXSidebar.exeSearchcentrix hijacker
    SideWinderTrayV4 or SWTrayV4NSWTrayV4.exeMS SideWinder game controller system tray icon. This is specific to version 4 of the software. Available via Start -> Programs
    SigmatelSysTrayApp?stsystra.exeRelated to Sigmatel Appears to come preloaded.
    SigX?sigx.exe??
    SigXCXSigX.exe SigX is a "dynamic signature image generated based on whatever data your computer sends it though our SigX program. It can display your current Mp3, current OS, Free Ram, your current time and more."
    SimcastNSimcastAlerts.exe Simcast is a free service that allows you to subscribe to information on a large variety of topics. Alerts will appear on your desktop when a channel that you have subscribed to has something to say.
    SimpLite-MSNUSimpLite-MSN.exeRequired if you use the SimpLite add-on to MSN Messenger (SimpLite adds encryption to the instant messaging service)
    SingaporeXsingapore.exeAdds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself
    SiS DnsXdnssvc.exeAdded by the Troj/Dloader-UE TROJAN! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    SiS KHookerNkhooker.exeSiS Keyboard Daemon. System Tray utility which gets installed by the drivers of the latter day SiS VGA cards. Can cause errors at startup and isn't required
    SiS Mpc ServiceXmpcsvc.exeAdded by an unidentified TROJAN!
    SiS Tray or sistrayUsistray.exeSystem Tray icon for SiS based graphics. Note - this resides in C:\Windows\System
    SiS Windows KeyHookUkeyhook.exeSIS graphics cards related: "Super VGA Keyboard Daemon" - hooks into the keyboard processing chain in order to enable hotkey settings.
    SiS7012UtilityYSiSAudUt.exeSiS Corporation sound card driver
    SISAM10M?SISAM10M.exe??
    SiSAudioNMP_S3.exeWinME patch for an older SiS 961 chipset FERR bug. Enable if you have audio problems
    siscolorUcolor.exeProbably on-board graphics related based upon the SiS chipsets. Has been seen on ASUS motherboards with SiS chipsets and known to cause conflicts if you choose another graphics card and disable the on-board
    siService.exeUsiService.exeSpam Inspector - anti email spam software
    SiSPower?Rundll32.exe SiSPower.dll,ModeAgentResponsible for power management for SIS chipsets - is it required?
    SiSSetCDfmt?SiSSetCDfmt.exeRelated to a Silicon Integrated Systems Corp (SiS) product?
    SISSoundman?Soundman.exeRelated to a Silicon Integrated Systems Corp (SiS) product?
    SiSSWLEDUsisswled.exeSystem Tray utility for SiS 900 network cards
    sistrai.exeXsistrai.exeAdded by the PROVA VIRUS!
    sistrayXsistray.exeAdded by the PROVA VIRUS! Note - this resides in C:\Windows\Command
    Sistray32Xremotehost.pifAdded by the W32.Holcas.A WORM!
    Sistray32Xwin.batAdded by the W32/Jupir-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Sistray32Xvirus.exeAdded by the Troj/Tometa-C TROJAN!
    sistryXsistry.exeAdded by the CEBE VIRUS!
    SiSUSBRGNSiSUSBrg.exeSiS USB Registry Patch File - fixes the undetectable problem with SiS USB controller on Windows XP
    sixtysixXsixtypopsix.exe MediaMotor/Popuppers adware downloader
    SK51USK51.EXE SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!
    SK60USK60.EXEAdded by the SaveKeys surveillance software. Uninstall this software unless you put it there yourself.
    SK9910DMUSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
    SKDAEMONUSKDAEMON.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys 
    skinkersUskinkers.exeSelection of desktop messaging/marketing tools with celebrity tie-ins including MTV's "Desktop Ozzy" and Arsenal's "Desktop Wenger" - see here
    sks-32XSKS32P~1.EXE SpyKeySpy logs keystrokes and sends the stolen information to a configurable email address.
    SkyBlaster SchedulerYSSFSch.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    skynetave.exeXskynetave.exeAdded by the SASSER.D VIRUS!
    SkynetRevengeXwinlogon.scrAdded by the W32.NETSKY.AA WORM!
    SkypeNSkype.exe"Skype is free and simple software that will enable you to make free calls anywhere in the world in minutes"
    SkySurfer Management ServiceYSmaServ.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
    sl4 rulesXrbot32.exeAdded by the W32/SDBOT-QC WORM!
    Slayhacker734Xslay7383.exeAdded by the Troj/SikBot-A TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    SleepManagerNSleepMgr.exeThis program locates free contiguous disk spaces and allocates them for storing BASE MEMORY, EXTENDED MEMORY, VIDEO MEMORY, and SM RAM. It helps the computer come out of hibernate mode
    SlickRunUsr.exe"SlickRun is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords), so C:\Program Files\Outlook Express\msimn.exe becomes MAIL"
    slideXIexplore.exeAdded by the GASLIDE VIRUS! Note - this is not the valid Internet Explorer file "iexplore.exe"
    slimp3NSliMP3 Server.exeSlimp3 Server - "presents an entirely new way of accessing and enjoying your music collection. Instead of storing your music on CDs or memory cards, the SliMP3 uses your home network to access the music stored on your PC"
    SlingshotNSLINGS~1.EXEAtomica Slingshot - "reference tool with access to dictionary and encyclopedia terms, bios, technical terms, history, geography, and much more"
    SlipStreamUslipcore.exe Sliptstream Web Accelerator
    slmssXslmss.exeSeekSeek search hijacker related - as seen here
    sloadXsload.exeWin SynchroAd adware, also detected as TROJ/DLOADER-QG TROJAN!
    slvchost32Xslvchost32.exeUnidentified worm or trojan
    smXsr_exe.exeAdded by the LUKUSPAM TROJAN!
    smXsm_exe.exeAdded by the OLFEB.A TROJAN!
    smXsa_exe.exeAdded by the OLFEB.A TROJAN!
    smXsf_exe.exeAdded by the OLFEB.A TROJAN!
    SM1BG?SM1BG.EXEUSB driver for downloading from within Napster to portable MP3 players. Is it required to run at startup or can it be run manually?
    Sm56aclNsm56hlpr.exeHelper utility for Motorola based SM56 software modems - resides in the System Tray
    smanXapp***.tmp (* = digit)Unidentified adware
    SmappNsmtray.exeSystem Tray access for the Compaq/ADI SoundMAX integrated digital audio controller
    Smart Card ServiceNScardSvr.exeFor Smart Card readers. Known to cause problems, especially for Windows 2000 users - see here. Probably not required unless you use such a device regularly
    Smart Connect MonitorUSCMon.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
    Smart Connect SetupUSCSetup.exeAppears on a Sony Vaio. Smart Connect Version 2.1 enables data transfer between Vaios via i.LINK cable. Smart Connect supports File and Printer Sharing for MS networks. You can copy files from your Vaio to another Vaio or print using a printer connected to a remote Vaio
    Smart Label O ServerNssloserv.exePart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
    Smart Label O ServerNssloserv.exePart of the printer software for the smart-label printer made by Seiko. Can reportedly be disabled safely.
    Smart Label RFViewerNSSLFVIEW.EXEPart of the printer software for the smart-label printer made by Seiko. Can be disabled safely
    Smart Type AssistantNsta.exeSmart Type Assistant - a complex typing automation tool, intended to make your work faster and safer
    SmartalecUpcaccel.exeSmartalec PC Accelerator - system optimization utility
    SmartBarXPNSmartBarXP.exe SmartBarXP is a bar that runs down the side of your screen, and can be configured to display interactive panels known as 'panes'. These panes include media players, slideshow and image viewing panes, a virtual desktop manager, and live news, weather and stock feeds to mention but a few
    sMaRTcaPsNSMARTC~1.EXEsMaRTcaPs from Phoebus LLC - enables you to configure the time needed to depress Caps Lock, Num Lock & Insert keys
    SmarthruengineUQS.exeSamsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers
    SmartPCXLUpcaccel.exeSmartalec PC Accelerator - system optimization utility
    SMax4NSMax4.exeSystem Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
    SMax4PNPUSMax4PNP.exeSoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
    smbdpmi?smbdpmi.exeIBM Netfinity Director and Universal Management Services related. What does it do and is it required?
    smcservXwinsrv.exeAdded by the W32/AGOBOT-OU WORM!
    SmcServiceYsmc.exe Sygate Personal Firewall
    Smcsta.exe?Smcsta.exeSMC Networks wireless PCI card driver. Is it required?
    SmcSVRXSmcSVR.exeAdded by the LEGMIR.JU TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Smith Micro tryNsmiptray.exeSmith Micro shared files. Comes with D-Link web cam
    SmoothViewNSmoothView.exeTOSHIBA Zooming Utility - allows "automatic" zoom feature in some appications, like IE, MS-Office, WMPlayer, Adobe-Reader and also desktop icons.
    smresXsmres.exeAdded by W32/Agobot-UA WORM!
    SMS Application LauncherULAUNCH32.EXEMicrosoft Systems Management Server - used to manage computers on a network remotely
    SMS Client ServiceUclisvc95.exeWhen the SMS Client service starts on a domain controller, the Client service modifies the SMSCliToknAcct & user account group membership, user rights, and account comment. The Client service then waits for the synchronization of the comment to verify that the account and user rights are properly set for this account. This account is used to obtain a token to start the SMS Client processes, such as the Software Inventory and Software Distribution agents (MS Systems Management Server)
    Sms System32XSmsSystem32.exeUnidentified malware
    SMS Win9x Message AgentUSMSMsg.exeThis program assigns a user to a Systems Management Server site
    SmserialYsm56hlpr.exeMotorola based modem driver
    SMSI LoaderNSMLoader.exeSmith Micro HotFax - fax software
    smsmXsmsm.exeAdded by the Troj/Banker-CO Trojan!
    smsrvXsmsrv.exeAdded by the W32/Agobot-SX Worm!
    smssX(path to smss.exe)Added by the ALADINZ.F VIRUS! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
    SMSSXSMSS.EXEAdded by the Troj/Borobot-K or Troj/Subot-D TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    SmssXssms.exeAdded by the RBOT.OP WORM!
    smssLevel4Xsmss.exeUNidentified malware - NOTE - this file is placed in a C:\Program Files\Windows Media Player\Skins\WindowsMediaSkin\Data\Level4 folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SMSSSXsmsss.exeAdded by the SDBOT.ZD WORM!
    SMSSS LoaderXsmsss.exeAdded by the AGOBOT.MQ WORM!
    SMSSUXSMSSU.EXEHijacker, detected by Norton antivirus as Trojan.StartPage.O
    smsysXExplorer.exeAdded by the CLICKER-C VIRUS! Note - the valid "explorer.exe" is located in C:\Windows or C:\Winnt whereas this one is located in a C:\Windows\Template or C:\Winnt\Template subdirectory
    smsysXvi.exeAdult content dialler
    SmtUSMT.exe Win-Spy keyboard logger/monitoring software - remove unless you installed it yourself!
    SMToolbarNSMToolbar.exeStartMake.com toolbar
    SMTP32 Mailing ProtocolXsmtp32.exeAdded by a variant of the WIN32.RBOT WORM!
    SmWizard?SmWizard.exeSmartWizard MFC Application - associated with C-Media who produce audio chipsets commonly used for on-board sound on motherboards. What does it do and is it required?
    SN MessengerX msnmsgr.exeAdded by the W32/Rbot-AVP WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    snappleXsnapple.exeAdded by the W32/FORBOT-EG WORM!
    snbr?snbr.exe??
    snbuptXsnbupt.exe UpSpiralBar adware component
    sncntrXsncntr.exeAdded by the Troj/Dluca-I TROJAN!
    SNCT511?vsnct511.exeUnidentified "Snapshot Viewer"- what does it do and is it required?
    snd332Xsnd332.exeAdded by the "B1ld0" AIM WORM!
    SndcompatXSndcompat.exeAdded by the GEMA TROJAN!
    SNDMonUSNDMon.exePart of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the "U" recommendation
    SndPnpMixXwauctlxp4.exeAdded by the WIN32.MUDROP.N TROJAN!
    SndsaverXSndsaver.exeAdded by the GEMA TROJAN!
    sndsrvc?SNDSRVC.EXEPart of Norton Personal Firewall and Norton Internet Security - what does it do and is it required?
    SNInstallX[various file names]Spy Sheriff/SpywareNO malware, also detected as the SPYHOAX-A TROJAN, pretends to be a spyware remover! - file names spotted sofar include VXH8JKDQ2.EXE, NS6281400.so, CVXH8JKDQ2.EXE, down3.exe, sefe.exe, winstall.exe, and tool2.exe
    SnippetUSnippingTool.exeThe Snipping Tool (part of the Experience_Pack for Tablet PC) allows you to easily "cut out" anything on screen and share it with other people. The whole screen becomes an "inkable" surface that you can add comments to and mark up however you like. You can then save that annotated image to use later, or send it to someone else in an e-mail message.
    SNP Generic Host ProcessXsvchost.exeAdded by the Troj/Zapchas-O TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    snpstd?vsnpstd.exe Sonix PC Camera Monitor MFC Application - what does it do and is it required?
    SNPSTD2?vsnpstd2.exeCameraMonitor MFC Application. Appears to be related to a USB connection to a digital camera -is it required?
    SnsiconNSnsicon.exeLaunches a screensaver program from Second Nature
    SNSS.EXEXSNSS.EXEAdded by the Dialer.Nunci premium dialer.
    SO5 Integrator Pass One?sointgr.exeStarOffice 5. See here for more details
    SO5 Integrator Pass Two?sointgr.exeStarOffice 5. See here for more details
    SoarXRwon.exe PurityScan/Clickspring adware
    Social Security AgencyXrpcxsocsa.exeAdded by a variant of the WIN32.RBOT WORM!
    Sock32Xsock32.exeAdded by the SDBOT WORM!
    SoDA StartupYSodaStartup.exeUsed by the Rational SoDA project management tool. Unsure of it's actual purpose but it's recommended you leave it enabled if you use the software
    sofficeNSOFFICE.EXEDisplays StarOffice quick start applet in System tray. Right clicking on the icon allows rapid starting up of components of the StarOffice 6.0 suite. Available via Start -> Programs. Automatically started when any StarOffice 6.0 component is started from the Start -> Programs. A resource hog (it eats > 16 MB of memory).
    Soft Profile IncXhxdef.exe...Added by a variant of the LOVGATE WORM!
    softIce Update 32Xwininits.exeAdded by the W32/Rbot-ANB WORM! Note: This worm/trojan file is found in the Windows or Winnt folder.
    SoftickPPPUPPPGate.exe Softick_PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computer.
    SOFTinstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    SoftStuff Wallpaper ChangerUsoftstrt.exe AzureBay wallpaper changer
    SoftwareXsoftware.exeAdded by the TROJ/CRABTON-B downloader TROJAN!
    Solo SentryYSolosent.exeSolo Antivirus
    SoloScheduleUSolocfg.exeScheduler for Solo Antivirus. Leave enabled unless you scan manually on a regular basis
    SoloSysCheckUSyscheck.exe Solo_antivirus System Integrity Check - Monitors system registry, system.ini, win.ini and startup to protect you from new Internet Worms and Backdoors.
    somaticXsomatic.exeSearchcentrix hijacker
    Sonic A3D ControlNvrtxctrl.exeSound related options
    Sonic RecordNow!Xsmsc.exeAdded by a variant of the W32/SDBOT WORM!
    SoniqueQuickStartNsqstart.exeQuickstart for Sonique audio player. Available via Start -> Programs
    SonnReg?SonnReg.exePart of E-Color 3Deep for color calibration. Possibly a registration reminder?
    SonudManXSonudMan.exeAdded by the Trojan.Startpage.Q or Troj/StartPa-HN TROJAN! Note: This trojan file is found in the Windows or Winnt folder. Should not be confused with (soundman.exe) which is a SIS and Realtek file.
    SonudMonXSonudMon.exeAdded by the Troj/Lewor-J TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    SonyPowerCfg?SPMgr.exeRelated to Sony Power Management for VAIO Computers - is it required?
    Soot?rcea.exe??
    sophagnt?sophagnt.exePossibly related to Sophocles Screenwriting Software?
    SOSXSOS.exeAdded by the PHILLIS VIRUS!
    SOS SQL DatabaseNscm.exeSQL Server Service Control Manager. Available via Start -> Programs
    SoSyncMonitor?SoSyncMonitor.exeSuperOffice related. What does it do and is it required?
    Sound LoaderXsndloader.exeAdded by the AGOBOT-BV WORM!
    Sound servicesXSOUND32.EXEAdded by the AGOBOT.GG WORM!
    Sound SystemXWinSound1.exeAdded by an unidentified worm or trojan infection
    soundcontrlXsoundcontrl.exeAdded by the GAOBOT.AFJ WORM!
    sounddrvXsndbdrv3104.exe CoolWebSearch parasite related.
    SoundFusion?rundll32 cwcprops.cplControl panel item for the Terratec DMX Xfire 1024 soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
    SoundFusion?rundll32 hercplgs.cpl, BootEntryPointControl panel item for Hercules Fortissimo soundcards (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
    SoundFusion?RunDll32 cwaprops.cpl,CrystalControlWnd[Control panel item for a Terratec soundcard (Start -> Settings -> Control Panel) based upon a Cirrus Logic "SoundFusion" DSP. Does it need to run at start-up every time?
    soundmanNsoundman.exeSystem Tray icon for the Realtek AC97 Audio Sound Manager for AC97 onboard audio. Available via Start -> Settings-> Control Panel
    SOUNDMAN Microsoft HelpXsoun.pifAdded by the W32/RBOT-AIU WORM!
    SoundMAXUSMax4.exeSystem Tray icon for SoundMax integrated sound. Sound properties can be accessed through the Start Menu or Control Panel
    SoundMAXXSoundMAX.exeAdded by the W32/RIZON-A WORM! - NOTE - this file is placed in the Startup folder itself, and has NO relation to SoundMax sound cards!
    SoundMAXPnPUSMax4PNP.exeSoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
    SoundMixerXsmvss.exeAdded by the TROJ/DEDLER-G TROJAN!
    SoundmxXSoundmx.exe CoolWebSearch parasite related.
    soundtaskXsoundtask.exeAdded by the AGOBOT.VQ WORM!
    soundtaskXsoundtask.exeAdded by the AGOBOT-MD WORM
    soundtasksXsoundtasks.exeAdded by a Crypter.C trojan variant infection
    soundtctrlsXsoundtctrls.exeAdded by the W32/Agobot-ZV WORM!
    SoundViewXmsdview32.exetrojan downloader
    sounoftsXsounofts.exeAdded by the W32/Agobot-ND WORM!
    sountskmanagerXsountaskmgrAdded by an unidentified WORM or TROJAN!
    SourcePathNgwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programs
    spXsp.regIE search hijacker - changes the default search to http://www.gocybersearch.com/
    spXregedit-s .... sp.dllMalicious javascript annoyance that changes the default search engine in IE to one of many including "topsearcher". See here for more and a fix
    spXrundll32 [path] se.dll,DllInstallAdded by the StartPage.M TROJAN, a CoolWebSearch parasite variant
    spXrundll32 (Path to Trojan DLL),DllInstallAdded by the Troj/Ablank-W and Troj/Ablank-Z TROJANS!
    SP TimeSyncUSP TimeSync.exeSP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server).
    SP00LSVXSp00lsv.exeAdded by the GRAYBIRD.E VIRUS!
    SP2 Connection Patcher?SP2ConnPatcher.exeUnidentified - possibly part of the "Warez" P2P client software what does it do and is it required?
    SP2 Connection PatcherUSP2ConnPatcher.exeChanges limit of concurrent TCP connections of Windows Service Pack 2.
    SP2 dataX[path] repcale.exe [path] apc.exeAdded by a variant of the RANDON.AN WORM!
    SP2 Firewall/Internet UpdaterXcrssrs.exeAdded by the RBOT.BJO WORM!
    sp2chk.exeXsp2chk.exeAdded by the Aluroot.A TROJAN!
    SP2ConnPatcher?sp2connpatcher.exeUnidentified - possibly part of the "Warez" P2P client software what does it do and is it required?
    sp2ctrXsp2ctr.exeAdded by a Troj/Dluca-M trojan infection
    sp2updateXsp2update.exe ADWARE! Adware.SP2Update Tracks URLs visited and search terms entered into Internet Explorer.
    Spam Blocker for Outlook ExpressXSBInst.exe HotBar related
    Spam SleuthUSpamSleuth.exeSpam Sleuth E-mail spam detection program
    SPAMfighter AgentUSFAgent.exe SPAMfighter anti email spam filter
    spamihilatorUspamihilator.exe Spamihilator spam filter
    SpamPalUspampal.exeSpamPal - anti-spam tool
    SpamSubtractUSpamSubtract.exeIntermute SpamSubtract - junk email detection and removal program
    spc_wNhcm.exe NetZero Search Enhancement related
    spc_wNblspc.exe NetZero Search Enhancement related
    spc_wNnzspc.exe NetZero Search Enhancement related
    SpdstartNSpdstart.exeNorton Utilities Speed Start. "This feature optimizes the start up speed of launching applications, such as Word and Excel."
    Speaking Clock DeluxeUSpClDlx.exeSpeaking Clock Deluxe - turns your computer into a speaking clock with several languages. It can also keep track of up to 50 alarms that can be set to a time and a date, and be repeated daily, weekly, monthly and yearly
    Special Firewall ServiceXavguard.exeAdded by the W32.NETSKY.G WORM!
    SpecialOffersXSpecialOffers.exe SpecialOffers adware
    SpecialOffersXSpecialOffers*.exe (* = digit) SpecialOffers adware
    specificXspecixic.exeAdded by a variant of the W32/SDBOT WORM!
    Speed racerNCTSRReg.exeSoftware for a Creative sound card
    Speed TecUspeedtec.exeAccel SpeedTec from Montana Software speeds up your modem. SpeedTec modifies the Internet Protocol settings in the Windows registry to speed downloads on all modems. If you find this improves your connectivity and download speeds leave this enabled
    SpeedBossX(worm filename)Added by the OPASERV.AD VIRUS!
    SpeedkeyUSPEEDKEY.EXEAdditional keyboard shortcuts on MS programmable keyboard
    SpeedMeterUSpeedMeter.exeApplication measuring upload and download speed
    SpeedOptimizerUspo.exe SpeedOptimizer is designed to optimize and speed-up your Internet data transmission including browsing, streaming, downloading, uploading and e-mail communication.
    SpeedswitchXPUSpeedswitchXP.exe SpeedswitchXP is a CPU frequency control for notebooks running Windows XP
    Speedtouch USB DiagnosticsUDragdiag.exeFor an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an \'at-a-glance\' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
    SpeedUpMyPCUSpeedUpMyPC.exe SpeedUpMyPC "automatically fine-tunes all your resources including hardware, system settings and internet usage to operate at peak performance at all times."
    Spees1Xspeedy.scrAdded by the OPASERV.Y VIRUS!
    Spees2XSpeedy.batAdded by the OPASERV.AD VIRUS!
    Spees3XSPEEDY.PIFAdded by the OPASERV.AD VIRUS!
    Spellex AnywhereNsa.exeSpellex-Anywhere - adds spell checking functionality to almost any Window program. Create a shortcut and run manually before it's to be used
    SpIDerMailYspiderml.exeDrWeb antivirus Spider Mail e-mail scanner
    Spinner PlusNspinner.exe"Spinner Plus lets you listen to over 100 channels of music broadcast from Spinner.com. Spinner Plus uses RealNetwork's G2 technology to provide high-quality online audio. The technology adjusts the audio streaming to match your Internet connection speed, which helps eliminate sound distortion or choppiness". Available via Start -> Programs
    SPINXXOXNEY.B.VBSAdded by the VBS.YENO.C WORM!
    SPntXSPnt.exePremium rate adult material dialer
    SpokeSysTrayUSpokeSysTray.exe Spoke_Software client application. Spoke "uses data in your e-mail and other enterprise information systems to discover the existing relationships of people in your enterprise. It then builds a private, secure relationship network for each user without any additional manual data entry."
    spolsvr2Xspolsvr2.exeAdded by the Win32/Evilsock.10 TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    spoo1svXspoo1sv.exeAdded by the SOULJET VIRUS!
    SpoolX[path to file]Added by the RANKY.R TROJAN!
    SpoolXmsvc.exeAdded by the RANKY.R TROJAN!
    SpoolXwys.exe WhileUSurf adware component
    SPOOL ConfigurationXspoolsvc.exe W32/Sdbot-KD worm
    Spool LoaderXspool.exeAdded by a variant of the WIN32.RBOT WORM!
    Spool LoadKItXspoolv.exeAdded by a variant of the WIN32.RBOT WORM!
    Spool lptt01 or Spool ml097eXspool.exeVariant of the RapidBlaster parasite (in a "spool" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Spool ManagerXspoolsrv.exeAdded by the Troj/Banker-FR TROJAN! Note: This is not the legitimate Windows process spoolsv.exe (Notice the difference in the spelling). This trojan file (spoolsrv.exe) is located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Spool Server DaemonXSPOOLSVD32.EXE Win32.Rbot worm variant
    Spool32Xpool32.exeAdded by the ASSASIN-F TROJAN!
    spoolaxX(Path of the trojan exe)Added by the Troj/Perda-D TROJAN!
    Spooler ServiceXSpoolsrv.exeAdded by the JOINER.C1 VIRUS!
    Spooler Sub System ProcessXSPOOL32.EXEAdded by the YAB.A VIRUS!
    Spooler SubsystemXspoolsub.exeAdded by the W32/SDBOT-ABG TROJAN!
    Spooler SubSystem AppXspoolsvc.exeAdded by the W32/POEBOT-J WORM! Note: Spoolsvc.exe is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (spoolsv.exe) should not be seen in Msconfig or as a Startup item...Also search for fccj.bat if found this is the W32/Poebot-M variant.
    Spooler SubSystem AppXspooIsv.exeAdded by the W32.LINKBOT.M WORM!
    Spooler SubSystem ApplicationXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler SubSystem ApplicationXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Spooler Subsytem AppXspoolsvc.exeAdded by the TROJ/SDBOT-MM WORM!
    SpoolerSubSystemProcessXSpooI32.exeAdded by the SPY.EHKS.21 VIRUS! Note - the "I" between "o" and "3" is a captial "i" not a lower case "L"
    Spools Service ControllerXspools.exeAdded by the W32/KASSBOT-C and W32/Kassbot-E WORMS !
    spoolservXspoolserv.exeAdded by a W32/Sdbot-PN worm infection
    SpoolServiceXspolsv.exeAdded by the W32/AGOBOT-CS WORM!
    SpoolsvXSpoolsv.exeAdded by the CIADOOR.121 VIRUS! Note - "Spoolsv.exe" is located in the Windows or Winnt directory, and not in System32, like the legitimate Spoolsv.exe system file
    spoolsvXscvhosts.exeAdded by the TROJ/SMALL-AW TROJAN!
    spoolsv managerX"%Windir%\SpoolMgr.exe"Added by the W32.Assiral WORM!
    spoolsv serviceXspoolsv32.exeAdded by the W32/RBOT-AHP WORM!
    SPOOLSV32XSPOOLSV32.EXEAdded by the TROJ/CWS-I or Troj/Hazif-B TROJAN!
    spoolsvcXspoolsvc.exeAdded by the TROJ/DROPPER-AT TROJAN!
    spoolsvr32Xcsmss.exeAdded by the AGENT-AU TROJAN!
    spoolsvr32Xcsmss32.exeAdded by a variant of the AGENT-AU TROJAN!
    spoolsvs.exeXspoolsvs.exeAdded by the Troj/Dloader-RK TROJAN!
    SPOOLSVUXSPOOLSVU.EXEAdded by the StartPage.K TROJAN!
    spoolsvvXspoolsvv.exeSearchcentrix hijacker
    SpoolvsXspoolvs.exeAdded by the SDBOT.AUS WORM!
    SporeXMsNews.vbsAdded by the VBS.SORPE.A WORM!
    Spore.bXScmhlpr.vbsAdded by the VBS.SORPE.B WORM!
    SPP?run.exe??
    sppXregedit -s spp.regIE search hijacker - changes the default search to http://www.hotsearchbox.com/ie/
    sppbridge?sppbridge.exeAssociated with an Anycom bluetooth wireless card on laptops - used for printing to portable printers for example. Is it required or can it be started manually? 
    SprintPort?SprintPortA.exeNovatel wireless modem related. What does it do and is it required?
    SPSTEALTUSmartProtectorPro.exeSmart Protector Pro - internet privacy tool that erases tracks, MRU lists, etc
    spstore?storesp.exe Softprobe is a program designed to provide managers with an analysis of an individuals computer use who are under their supervision. This program is NOT related to Winpup.
    Spy BlockerUspyblocker.exeSpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
    Spy Sweeper FixYSpySweeperFix.batRelated to Webroot_SpySweeper
    Spy-ControlXSpy-Control.exe"Spyware remover" of dubious repute - see this list of non-recommended anti parasite software
    Spy-KeyloggerUskl.exe SpyKeylogger is a security risk that records keystrokes. If you didn't install it yourself remove it.
    SpyBanXSpyBan.exe"Spyware remover" of dubious repute - see this list of non-Recommended anti parasite software
    SpyBlastXSpyBlast.exeSpyware killer that is in effect autoinstalled foistware, targeted by SpyBot, among others
    SpyBlockerUspyblocker.exe SpyBlocker blocks the communications of spyware installed on a PC so spyware runs but can't exchange data with the server to which it should report. Ensuring spyware can't communicate is important, as you may find after using Ad-Aware that some applications containing spyware subsystems may not run correctly or at all
    SpyBlocsXSpyBlocs.exe Rogue anti-spyware program.
    SpyBlocsXGLFF.exe Rogue anti-spyware program.
    SpyBlocs3.0XSpyBlocs3.0.exe Rogue anti-spyware program.
    SpybotSD TeaTimerUTeaTimer.exeSpybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla. TeaTimer.exe monitors certain changes to the registry and notifies when browser plugins and activeX controls get installed, allowing you to block/reverse this.
    SpyBotSnDUSpybotsd.exeSpybot - Search & Destroy - free multi-spyware removal tool from Patrick Kolla
    Spybott lptt01 or Spybott ml097eXspybott.exeVariant of the RapidBlaster parasite (in a "Spybott" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    SpyCop ScanCheckUMAIN.EXESpyCop surveillance software detection - checks to see when your machine was last scanned and if it was more than a week asks if you want to scan
    SpyExXWinllogo.exeAdded by the W32/PrsKey-A WORM!
    SpyHunterNSpyhunter.exeSpyHunter - spyware remover of somewhat dubious repute; see note
    SpykillerUSpykiller.exeShareware "Spyware remover" of questionable quality and repute. There are better alternatives that are freeware to boot. See this page on Rogue/Suspect Anti-Spyware Products & Web Sites
    SpyNukerXSpynuker.exeA "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages
    SpySheriffXSpySheriff.exe SpySheriff malware
    SpySpotterNSpySpotter.exe"Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    SpyStopperUspystopper.exeSpyStopper - blocks intrusive spyware, Web bugs, worms, scripts, advertisements, and cookies. Protects you from being profiled and tracked
    SpySubtractUSpySub.exe SpySubtract - multi spyware removal tool
    SpySweeperUSpySweeper.exeSpy Sweeper - detects and removes spyware
    SpyTrooperXSpyTrooper.exeSpyTrooper, malware, posing as a spyware remover - alse see here
    SpywareXSpyware.exe

    BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!

    Spyware BegoneNSpywareBegone.exeSpyware BeGone - free spyware removal utility; not recommended; see note
    Spyware BegoneNfreescan.exeSpyware BeGone - free spyware removal utility; not recommended; see note
    Spyware CleanerXSpywareCleaner.Exe"Spyware remover" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
    Spyware DoctorUspydoctor.exe Spyware_Doctor spyware remover
    Spyware DoctorUswdoctor.exe Spyware_Doctor spyware remover
    Spyware Guard Control PanelUspywar~1.exe

    "SpywareGuard provides a real-time protection solution against spyware"

    Spyware NukerXswn2.exeA "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages
    Spyware Nuker InstallerXSpywareNukerInstaller.exe

    A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages

    Spyware removerXRemove_spyware.exeUnidentified, but not known to belong to any known spyware remover, and strongly suspected to be adware related!
    Spyware ScannerNAseScanner.exeAluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here
    SpyWare ShieldUShield.exeAcronis Privacy Expert Spyware_Shield prevents spyware and other suspicious programs from being installed on desktop PCs and laptops.
    Spyware SlayerXSpywareSlayer.Exe"Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    Spyware StormerNSpywareStormer.ExeSpywareStormer spyware remover; not recommended: see here
    Spyware VanisherXFreeScanner.exe"Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    Spyware X-terminatorUSpywareX.exe Spyware_X-terminator spyware remover
    Spyware-CopXSpyware-Cop.exeSpyware-Cop alias SpywareKilla - "Spyware remover" of dubious repute, see this list of Rogue/Suspect Anti-Spyware Products & Web Sites
    SpywareGuardUsgmain.exe

    "SpywareGuard provides a real-time protection solution against spyware"

    SpywareGuardXdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application as described here
    Spywareguard lptt01 or Spywareguard ml097eXSpywareguard.exeVariant of the RapidBlaster parasite (in a "Spyguard" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    SpywareGuardPlusXwinmm64.exe"Trojan.Win32.StartPage.ht" homepage hijacker
    SpywareKillaNSpywareKilla.exeSpyware remover of ill repute. For more info about it do a search for 'SpyareKilla' at this web page on "Rogue/Suspect Anti-Spyware Products & Web Sites"
    SpywareNoXSpywareNo.exeBogus "Spyware remover" - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
    SPYWATCHUSpyWatch.exe

    BPS Spyware Remover - reportedly uses an old, "borrowed" SpyBot database. Read this and this. Do not support these guys!

    SQConfigCheckerXcc.exeXupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
    SQInstallerXSQInstaller.exeXupiter hijacker
    SQL ServerNscm.exeSQL Server Service Control Manager. Available via Start -> Programs
    SQL Server ServiceXsql.exeAdded by the W32/Rbot-ADF
    sqservicesXwins32.exeAdded by the Troj/Progent-B TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    SQUpdatesCheckerXuc.exeXupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
    sqvynikpXsqvynikp.exeFree_Scratch_Cards foistware
    sr1exe?updtSup3.exeFound on a Dell computer, in a Documents and Settings\All Users\Application Data\Dell\Alert2 subfolder
    sr64X********. exeAdware, as yet unidentified
    SrchfstUpdateXsrchupdt.exeSearchFast adware downloader
    sreXrundll32.exe sre.dll,Register CoolWebSearch parasite variant, also detected by Kaspersky antivirus as Trojan.Downloader.Agent.Fc
    SRFirstRun?rundll32 srclient.dll,CreateFirstRunRpCreated by execution of the Windows XP sr.inf file, which installs the Windows XP System Restore feature, needed for example when installing System Restore into Windows Server 2003. - does this indeed need to run at every bootup?
    SrmcleanUsrmclean.exeSrmclean helps in the installation and execution of the SoundMax SoftPaq for Compaq/ADI SoundMax Integrated Digital Audio. According to Compaq - "If you disable the entry from loading into startup, then you will not be able to use the features of the sound card"
    SRNGXsrng.exeSearch hijacker - see here
    SRP StartupUsrrpro.exeSystem Restore Remover Pro allows you to safely and easily remove System Restore and various other Windows Millennium "features." This is enabled if you tick the "Remove unnecessary System Restore information on startup" box. Available via Start -> Settings -> Control Panel
    SRS AppletYSrsTray.ExeS3 Sonic Vibes sound card drivers - if disabled you loose sound
    srshost.exeXsrshost.exeAdded by a variant of the RBOT-ASW worm! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Srv RPCromXNClienti386.exeAdded by the W32.Watsoon.A TROJAN!
    Srv32XSrv32.exeAdded by the OPASERV.J VIRUS!
    Srv32XSrv32.exeAdded by the OPASERV.S VIRUS!
    srv32Xsrv32.exeAdded by the W32/AGOBOT-AMI WORM!
    Srv32 spool serviceXrunsrv32.exeTopantispyware.com malware, recognized by Kaspersky antivirus as Trojan-Clicker.Win32.Spyre.b
    Srv32 spool serviceXspoolsrv32.exeAdded by the SPYRE.B and Troj/Dloader-ON TROJANS!
    Srv32 spool serviceX(Trojan file path)Added by the Troj/Dloader-LB TROJAN!
    Srv325XSrv325.exeAdded by the W32/AGOBOT-PR WORM!
    Srv32OldX.PIFAdded by the OPASERV.J VIRUS! where <filename> is the original worm name
    Srv32WinUSpyAgent4.exeSpyAgent - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    Srv32WinUSvchost.exeRealtime-Spy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn\'t treat it as "X" and uninstall or remove
    Srv32WinUsysdiag.exe NetVizor surveillance software - uninstall this software unless you put it there yourself!
    srv32winUwin16dll.exe Screenspy captures screenshots silently. If you didn't install this yourself, remove it.
    Srvce Pack UpdteXsvcpack.exeAdded by a variant of the WIN32.RBOT WORM!
    srvexc.exeXsrvexc.exeAdded by the BACKDOOR.SERVSAX TROJAN!
    srvprcUsrvprc.exeAdded by the Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself.
    SsAAD.exe?SsAAD.exeSony SonicStage software related - "Atrac Hard Disk Monitor" - what does it do and is it required?
    ssate.exeXirun4.exeAdded by the BEAGLE.J WORM!
    ssate.exeXwinsys.exeAdded by the BEAGLE.K WORM!
    SSBkgdUpdateNSSBkgdupdate.exeScanSoft OmniPage auto updater. Can be disabled using the main program's options.
    SSC Service UtilityUssc_serv.exeSSC Service Utility is a printer utility for refilled Epson cartridges
    SSCFBTN.EXEUSSCFBTN.EXESamsung smarthru software,used with Lexmark Z82 or Samsung multifunction printers
    SSCFBTN.EXE?SSCFBTN.EXESamsung Scanner or Printer related - what does it do and is it required?
    SSC_UserPrompt?UsrPrmpt.exePart of Symantec (Norton) Security Centre - but what does it do and is it required?
    SsdYStd.exeStealthdisk - file and folder hiding/locking utility
    ssdiag?ssdiag.exeEquinox"Configuration and DOS Diagnostic for DOS and Windows platforms"
    SSDPSRVNssdpsrv.exeSimple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play
    ssgrate.exeXsystem.exeAdded by the MITGLIEDER.C VIRUS!
    ssgrate.exeXirun.exeAdded by the MITGLIEDER.D VIRUS!
    ssgrate.exeXirun4.exeAdded by the MITGLIEDER.F VIRUS!
    ssgrate.exeXsysdoor.exe Trojan.Mitglieder.N
    ssgrate.exeXwinerdir.exeAdded by the MITGLIEDER.O VIRUS!
    ssgrate.exeXwinsystems.exeAdded by the TROJ/BAGLEDL-J TROJAN!
    ssgrate.exeXwintems.exeAdded by the Trojan.Mitglieder.Q Trojan!
    SSh32USSh32.exe 2Spy keystroke logger/monitoring program - remove unless you installed it yourself!
    SSK ServiceXwinssk32.exeAdded by the SOBIG.E VIRUS!
    SSLXsvchost.exeAdded by an unidentified VIRUS!
    ssmmgrUssmmgr.exeSamsung printer monitor - for checking ink levels, etc.
    ssms.exeXSSMS.EXEAdded by the W32.GISMOR WORM!
    SSPYUSSYTEM.EXE SurfingSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    sssasasb32Xsssasasb32.exeAdded by the WIN32.TACTSLAY.F TROJAN!
    sstataXdwdas.exeAdded by the Dasda trojan
    sstataX(Path to Trojan exe)Added by the Troj/Ranck-DF TROJAN!
    SStb.exeXSStb.exeAdpowerzone.com "ServerSide" keyword hijacker
    sstrayNsstray.exenVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
    SSUpdateXSSUpdate.exeDyFuCa/MoneyTree parasite variant
    ssvchostXssvchost.exeAdded by the HELIOS.B VIRUS!
    SSWPlauncherXcomet.exe /app:SSWPlauncher CometCursor by Comet Systems
    StacmonNStacmon.exeInstalled with the drivers for a SigmaTel C-Major Audio card (on a Dell Inspiron 600m PC for example). Appears as though it can be disabled with no ill effects
    standalone.exeX"standalone.exe"Added by W32/AGOBOT-ADS WORM!
    Stardust Screen Saver Control 2003NSCMain.exeRelated to Stardust_Software Screen Saver Control 2003
    Stardust Wallpaper Control 2003NWCMain.exeRelated to Stardust_Software Screen Saver Control 2003
    StarSkinUstarskin.exe StarSkin allows you to change the view and appearance of your Windows XP box with the use of publically available themes.
    StartYQuick95.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
    StartXwindows.vbsHomepage hijacker
    start?start.exe??
    Start aThx RollXf0mered.exeAdded by the RBOT.AAV WORM!
    start extractingXspoolvse.exeAdded by the W32/RBOT-XF WORM!
    start extractingXspoolvs.exeAdded by the RBOT.AKC WORM!
    Start GetrightNgetright.exeSee Getright Tray Icon
    Start It UppingXsvchosets.exeAdded by a variant of the WIN32.RBOT WORM!
    Start PageXhttp://find.naupoint.com Naupoint browser hijacker
    Start PageXsvcnt32.exeHomepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks
    Start RF Wireless KeyboardYktrexe.exeYuanxun Electronics RF wireless keyboard driver
    Start RF Wireless MouseYcm20.exeYuanxun Electronics RF wireless mouse driver
    Start ServiceUupssrv.exeCyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner."
    Start Up CopUstartcop.exeStartUp Cop - startup manager
    start uploadingXsmsss.exeAdded by a variant of the W32/SDBOT WORM!
    Start UppingXtaskmrg.exeAdded by a W32/Rbot-MA worm infection
    Start UppingXSVCHOSTES.EXEAdded by the W32/RBOT-NB WORM!
    Start UppingXtaksmgr.exeAdded by the W32/RBOT-QK WORM!
    Start UppingXmcrt32.exeAdded by a variant of the W32.SPYBOT WORM!
    Start UppingXwindupds.exeAdded by the SDBOT.AFH WORM!
    Start UppingXwindupdts.exeAdded by a variant of the WIN32.RBOT WORM!
    Start UppingXxdcc.exeAdded by the SPYBOT.OY WORM!
    Start UppingsXsvcchosts.exeAdded by the SDBOT.VY WORM!
    Start UppingsXmssupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Start Wingman ProfilerNlwtest.exe, lwemon.exeLogitech Wingman software required to operate Logitech joysticks and gamepads.  Unless you're a hard-core gamer, it's best to leave it unchecked
    StartaccUstartacc.exeLaunches Webroot\'s Accelerate 2000 software that "speeds up your Internet connection by up to 300%". Leave enabled if you find it improves internet connection
    StartEAKYStartEAK.exeEasy Access Button Support for Compaq PCs. Required if you use these
    StartEAKUcpqeadm.exe Easy_Access Button Support for Compaq PCs. Required if you use these
    StarterXscvhosting.exe WORM_SDBOT.RU
    starterXscvhostingg.exeAdded by the W32/FORBOT-FB WORM!
    Starting upXwvsvc.exeAdded by a RBOT.QQ worm infection
    startkeyXXMCHAI.EXEAdded by the Troj/Bifrose-AO TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    startl.exeNstartl.exeLingocom LingoWare - translates any application into your language
    StartMenuXs_menu.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    StartMenuXdeamon.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    StartMenuXmsgaol.exeAdded by the WIN32.TACTSLAY.C TROJAN!
    StartMenuXbrowse.exeAdded by the Troj/Drowsy-C TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    startpageXstartpage.exeBrowser hijacker - redirecting to pages2start.com
    STARTPAGEUstart1.exe NoSpy.org - prevents spyware from changing your startpage and other browser properties. The start1.exe file is located in a NOSPY.ORG folder.
    StartStopUSTARTSTOP.EXEStartStop from TFI Technology - startup manager
    StartSurfingUSTARTS.exeStart Surfing allows you to protect your privacy while surfing and searching the Internet by acting as a "filter" between you and the website you are visiting. Startsurfing acts as your shield from Pop Up Windows, Mouse Traps, Window Resizing, and scripts that attempt to record your personal information. Available via Start -> Programs
    StartupN??Related to an Iomega drive
    StartupXWinlogonStartupUnidentified malware
    StartupXmirc.exeAdded by the Troj/Flood-EU TROJAN! Troj/Flood-EU provides an uninstall option for mirc.exe which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as mIRC. This one puts 10 files in the Windows or Winnt folder.
    Startup ConfigurationX[six character filename]Added by the W32/RBOT-ARV WORM!
    Startup ConfigurationXwztoid.exeAdded by the W32/Rbot-ASD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Startup Launcher GUI?GUI.exeStartup manager?
    Startup Manager ScannerUStartupMonitor.exe Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans, adult-dialers, and other scumware.
    Startup UpdateXCvshost.exeAdded by the GAOBOT.AO WORM!
    StartupBinXiwnujdss.exeAdded by the W32/SDBOT-XZ WORM!
    StartupMonitorUStartupMonitor.exeMike Lin\'s StartupMonitor, throws up an alert and asks your permission every time any change is made to your start-up configuration, either in the registry or start menu
    startwinXstartwin.exeAdded by the W32.ANTIMAN.A WORM!
    startwindowskeyuserXrundle2.exeAdded by the JAVAKILLER VIRUS!
    Stat 'n' PerfNStatnPerf.exeStat 'n' Perf monitors your internet connection and displays information about sent and received bytes
    StatBarXSTATBAR.exeStatBar (system status bar) allows you to quickly get an overview of your system's condition (memory, CPU, uptime, and much more). Due to the sheer number of resources (over 60%) consumed by this program, it is unsuitable for Windows 95/98/SE/Me
    State ServiceXcsrss.exeAdded by the TROJ/DADOBRA-CP TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    StatisticsXstatslist.exeAdded by the W32/Opanki-S WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Status MonitorNBrMfcWnd.exeBrother scanner status monitor - can be started manually
    Status Monitor XENENGSS.EXEThe Xerox Document WorkCentre XE Series Status Monitor displays information about your printer and currently active or waiting print jobs. You can use it to control your printing environment and manage your printing operations. Available via Start -> Programs
    StatusClient?StatusClient.exePart of Hewlett Packard network printer drivers
    Stay Connected!NStayCon.exeMore than just a pinger, actually simulates online activity. Supports AOL, NetZero, MSN, ATT WorldNet, CompuServe and many other ISPs as well. Available via Start -> Programs
    StayAliveUsa.exeStayAlive from TFI Technology. "This top-notch tool intercepts crashes when they happen, keeping your programs running so you can save your work."
    STBVision?STBVisn.exeRelated to the STB Velocity graphics card. What does it do and is it required?
    STBWEBTVNSTBWEBTV.EXEUsed to display TV on your PC
    stcinstallerXid53.exeAdd as a result of TROJ_SCTHOUGHT.L TROJAN!
    stcloaderXstcloader.exePopup adware by 2ndThought software
    STCPOYSTCPO.exeSophos Sweep antivirus software
    stdlibX[name of file]Added by the TROJ/PERDA-E TROJAN!
    STDSBYSTDSB.exeScrollbar driver for notebooks. If taken out of the Startup, it will not provide scrolling.
    Stealth Anonymizer 2.5Ustealth25.exeNow named Stealther - proxy server agent that lets you travel the Internet with maximum possible privacy
    steamXsteam.exeAdded by the W32/Rbot-AJT WORM! Note: The file steam.exe will be found in the Windows System folder.
    SteamNsteam.exeValve Software's STEAM broadband game client. Steam is Valve's new way of getting games into your hands ASAP. Games like Half-Life, Counter-Strike, and Counter-Strike: Condition Zero are all being made available through Steam. Steam games are automatically kept up-to-date with the latest content and revisions. Steam also includes an instant-message client which even works while you're in-game. Can be started mnaually.
    SteFanieXSteFanie.vbsAdded by the VBS.Stefan WORM! Note: Make sure you check the hyper link for VBS.Stefan, this one copies it's self to numerous dirves and folders.
    StickiesNSTICKIES.EXEStickies - utility that allows you to put yellow "Post-It" type messages on your desktop and can be used to set reminders. Available via Start -> Programs
    Sticky NotesNstikynot.exeMicrosoft Sticky Notes - virtual sticky notes tool
    StickyNoteNStickyNote.exeUtility that allows you to put yellow "Post-It" type messages on your desktop. Available via Start -> Programs
    StillImageMonitorUStimon.exeStimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners
    stisrvXstisrv.exeAdded by the RBOT.BQF WORM!
    stlbdistXrundll32exe stlbdist.DLL, DllRunMainHijacker pointing to www.searchandclick.com
    stlbupdtXrundll32.exe stlbupdt.DLL, DllRunMainBrowserAid/Startium parasite
    STManager?drst.exeDr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here
    stmhaXwkfxi.jsAdded by the JS.SPETH WORM!
    StopSignSsTsMonNsstsmon.dll,VerifyStatuseAcceleration Stop-Sign related; not recommended; see note
    StopSignStatusNstopsinfo.dll",VerifyStatuseAcceleration Stop-Sign related; not recommended; see note
    STOPzillaUStopzilla.exe STOPzilla popup blocker
    STOPzilla ServiceUSZNTSVC.EXE STOPzilla popup blocker
    StorageGuardUsgtray.exeStorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups 
    STPMGR?STPMGR.EXEPart of SafeTP which is transparent FTP security software. Does it need to be running permanently or can it be started manually via Start -> Programs
    stratasXxmconfig.exeAdded by the W32/Rbot-AHR WORM!
    StratasXggfig.exeAdded by the OPANKI.W WORM!
    stratasXlockx.exeAdded by the W32/Opanki-K or W32/Rbot-ASH or W32/Sdbot-AEG WORM!
    StreamZap RemoteUzremote.exe StreamZap_PC_Remote - Control Windows Media Player, iTunes, RealPlayer, Winamp, PowerPoint, MusicMatch Jukebox, and many other multimedia applications
    StrgSync.exeUStrgSync.exeSimpleTech Inc's StorageSync backup software - backs up an entire PC, or selected files and folders.
    strmsnmsgrXmsnmsgrs.exeAdded by the W32/RBOT-ACQ WORM!
    strmsnmsgrsXmsnmsgrsc.exeAdded by a variant of the WIN32.RBOT WORM!
    strmsnnmsXmsnmegrs.exeAdded by the Troj/Sdbot-YU TROJAN!
    strmsnnrsXmsnmcgrs.exeAdded by the TROJ/RBOT-ACT TROJAN!
    strmsoumsXmsnmegrse.exeAdded by the Troj/Sdbot-ZK Trojan!
    Strng32Xstrngbox.exeAdded by the STRANO VIRUS!
    StrokeItUstrokeit.exe StrokeIt is an "advanced mouse gesture recognition engine and command processor".
    strtasXlockx.exeAdded by the BKDR_IRCBOT.AV TROJAN!
    strtasXlock1.exeAdded by the W32/Sdbot-ADQ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    strtasXlockx.exeAdded by the W32/Sdbot-AEB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    strtoXstrto.exeAdded by the TROJ/KILLPROC-F or KillProc-G TROJAN! Note: File name may be different.
    strtoX(Path to trojan executable)Added by the Troj/KillAv-AP TROJAN!
    StsXiwnujdss2.exeAdded by the W32/SDBOT-YI WORM!
    StubbishXStubbish.exeAdded by the W32/STUBBOT-A WORM!
    StubPathXSservice.exeAdded by the PRORAT VIRUS!
    stxrmsgmsXmstats.exeAdded by the TROJ/IRCBOT-AE TROJAN!
    StyleXPUStyleXP.exeStyleXP allows you customize the way WinXP looks. If disabled via msconfig it re-instates itself at reboot, therefore uninstall it if you don't want it
    SubAHXSubAH.exeAdded by the SubAH backdoor TROJAN!
    Subtract the AdsNAdSub.exeRemoves adverts from web pages. Although useful - not required
    suckXl0ad.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    Suitcase StartupUSuitcase.exe Suitcase . System font manager start up utility. Used for dynamic managment of fonts on your system.
    SuiteXSuiteOffices.exe /cleandbAdded by the Lazar TROJAN!
    SULFNBJ.EXEXSULFNBJ.EXELeft as the result of being infected by the PE_MAGISTR.DAM virus. This virus infects system files and renames them (changing one letter) before adding them to the Run keys in the registry. Once the virus is removed via anti-virus software, delete the infected file and remove the key from the registry
    SunX(Path to Executable)Added by the Troj/Flat-E TROJAN!
    sunasDTServUsunasDTServ.exeSunBelt CounterSpy spyware detection and removal software
    sunasServUsunasServ.exeSunBelt CounterSpy spyware detection and removal software
    SunJavaSchedXccEvtMngr.exeAdded by the W32/Sdbot-YP Worm!
    SunJavaSched UpdaterXavamx.exeAdded by the W32/RBOT-ABJ WORM!
    SunJavaUpdateXsmvss.exeAdded by the TROJ/DEDLER-G TROJAN!
    SunJavaUpdateSchedNjusched.exeChecks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
    SunJavaUpdateSchedXscvhost.exeAdded by the W32/SDBOT-AVX WORM!
    SunJavaUpdateSchedXjavamx.exeAdded by the W32/SDBOT-WI WORM!
    SunkistUshwicon98.exeCard reader for memory cards from digital cameras, etc
    Sunkist2kUshwicon2k.exeCard reader for memory cards from digital cameras, etc
    SunKistEMUshwiconem.exeUsed by your computer to communicate with your Alcor_Micro Multimedia Card Reader - necessary if you're using this software
    SuNotificationUsuatshut.exe ShadowSurfer - "provides a safe computing environment by creating a virtual twin of your PC. Restore the pre-ShadowMode™ system state no matter what changes have occurred to your PC."
    SunProtectionServerUSunProtectionServer.exe CounterSpy antispyware software
    SunServerUSunServer.exe CounterSpy antispyware software
    SupaDial?SupaDial.exeSupaNet.com modem driver related - is it required?
    SupastatusNstatus.exeSupanet ISP software
    superXfuckbx.exeAdded by the LINEAGE-H TROJAN!
    superXsuper.exeAdded by the W32/AGOBOT-QT WORM!
    Super Popup BlockerUpopkill.exeSaga Super Popup Blocker - pop-up stopper
    SuperAdBlockerUSAdBlock.exe SuperAdBlocker
    SuperBar.ComponentXservices.exeAdded by FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetsrv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SupercleanerUSupercleaner.exeSupercleaner - all in one disk cleaner for your computer
    SuperCool Compress BackupUMain.exe"SuperCool Zip Backup software is a data backup,restore and file synchronization program"
    SuperHeissSexXSuperHeissSex.exeAdded by the HeissSex premium rate adult content dialer!
    supernews12Xnewsd32.exeAdware, also detected as the TROJ/DLOADER-JN TROJAN!
    SupernovaX.exeAdded by the SURNOVA (or SUPOVA) VIRUS! <filename>.exe is the chosen name
    superslutXmsslut32.exeAdded by the SLUTER-A VIRUS!
    SuperSpamKiller ProUSsk.exe SuperSpamKiller_Pro email spam blocker
    Supervisor.exe?Supervisor.exeHas been reported to be associated with various antitrojan software like ATS and PC_Doorguard . If so it's required in Startup - any further information is welcome.
    support-reverse-smileysX(TROJAN FILE NAME)Added by the Backdoor.IRC.Litebot TROJAN!
    supporter5Xsupporter5.exePart of eScorcher anti-virus software- responsible for updates of new virus bases each time you logon to the web. Used to collect information about the user and therefore treated as spyware - now the web-site is dead
    SureCleanProfessionalUSRClean.exe SureClean PC and Internet tracks cleaner
    SureshotpopupkillerUStopthepop.exeStop-the-Pop-Up popup blocker
    SureshotpopupkillerUpusak.exe Stop-the-Pop-Up popup blocker
    SurfAccuracyXsacc.exe SurfAccuracy adware
    SurfBuddyXrundll32 [path] sbuddy.dllSurfBuddy adware - not to be confused with the legitimate SurfBuddy application by SurfApps!
    SurfChoiceUSCMan.exeSCMan is a utility that can control services on WinNT from the command line. This utility can create, start, pause, stop, delete services. Furthermore it can retrieve a service's current state, get the displayname for a service and vice versa
    Surfer lptt01 or Surfer ml097eXsurfer.exeVariant of the RapidBlaster parasite (in a "mssurfer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    SurfinGuard ProUwinsfcm.exeSurfinGuard Pro - internet protection software
    SurfSecretUss2-full.exe"House-cleaning utility that enables you to keep your computer usage to yourself. Runs quietly from the system tray, eliminating tell-tale files at a regular interval of your choosing. You can set it to clear your Internet cache files, cookies, history, temp folder, etc. It can also clear the history of your Run and Find menus, in addition to the AOL cache"
    SurfSideKick 2XSsk.exe SurfSideKick adware
    SurfSideKick 3XSsk.exe SurfSideKick adware
    SurfStreamUSurfStream.exeConceiva "SurfStream lets you surf the Web faster. It contains a fully featured proxy server that lets you surf the Web significantly faster. It also blocks all pop-up windows and banner ads from Web pages. An intelligent tune-up tool automatically analyzes and optimizes your computer's Internet connection and TCP/IP settings."
    SursXawab.exe PurityScan/Clickspring adware
    Surveysa?surveysa.exeFound in the SonyVaiosurvey directory on a Sony Vaio PC - what does it do and is it required?
    SuspXSusp.exe Transponder parasite updater/installer
    SustemXexplorer.exeUndentified VIRUS!
    SustemUpdateXexplorer.exeUndentified VIRUS!
    SV00LSVXSV00LSV.EXEAdded by the GRAYBIRD-C TROJAN!
    SVA PlayerXSVAplayer.exeQuickFlicks Streaming Player - regarded as spyware. See here for details of how to disable or uninstall it
    SvcXsvc.exeHijacker, Clientman parasite variant, redirecting to madfinder.com. Detected by Symantec as the MADFIND VIRUS!
    SVCUsvchost.exe ElfSpy keystroke logger/monitoring program - remove unless you installed it yourself! - this file should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SVC ServiceXsvcinit.exeAdded by the SINIT VIRUS!
    SVC ServiceXsvcpack.exe CoolWebSearch parasite related.
    SVC ServiceXsvcinit.exe CoolWebSearch parasite related.
    SVC ServiceXsvc32.pifAdded by the W32/Rbot-ASC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SVC SocksXmstaskm.exe CoolWebSearch parasite related.
    svcdata.exeXsvcdata.exeAdded by the W32.Spybot.ZIF WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SvcedXSvced.exeAdded by the DELF.F VIRUS!
    SVCH ServiceXsvch32.pifAdded by the W32/Rbot-ASZ or W32/Rbot-ASY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SvcH0stXmsexploren.exeAdded by a BackDoor-CGZ trojan infection!
    SvcH0stXSHCH.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    SvcH0stXSVCHST.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    SvcH0stXWINAGENT.EXEAdded by the TROJ/BDOOR-EB TROJAN!
    SVCH0STXspoo1sv.exeAdded by the Troj/VB-HF TROJAN!
    SVCH0STXSVCH0ST.EXEAdded by the Troj/VB-IK TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    SVCH0TSXsp00lvs.exeAdded by the Troj/Lineage-AZ TROJAN! Note: This is not the legitimate Windows process spoolsv.exe (Notice the difference in the spelling). This trojan file (sp00lvs.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    svchastXsvchast.exeAdded by the Troj/Lineage-AV TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    SVCHOSTXsvchost.exeSystem1060 homepage hi-jacker. Found in a WindowsSystem1060 directory. Note - this is not the valid svchost.exe as described here
    svchostXsvchost.exeAdded by the MORB or TARNO VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32
    SVCHOSTXmrowyekdc.exeAdded by the GOTORM VIRUS!. This is not the valid svchost.exe as described here
    svchostX(path to trojan)Added by the HAZZER VIRUS!. This is not the valid svchost.exe as described here
    svchostXADMAGIC.EXEAdded by the SMIBAG VIRUS!. This is not the valid svchost.exe as described here
    SvchostXwinhost.exeAdded by the LOLAWEB.A VIRUS!. This is not the valid svchost.exe as described here
    SvchostXsvchost.exeAdded by a W32/Moze-A worm infection
    SVCHOSTXvar.txt.exeAdded by a PWSteal.Ldpinch.C trojan infection.
    SvchostXsvchosl.pifAdded by the W32.INZAE.A WORM!
    svchostX[path] SETUP.EXEAdded by the SETCLO WORM!
    SVCHOSTXscvhost.exeAdded by the W32.Mytob.E or W32.Mytob.G WORM!
    SVCHOSTXtaskgmr.exeAdded by the W32.Mytob.F WORM!
    SVCHOSTXtaskmgr.exeAdded by the W32.Mytob.H WORM!
    SVCHOSTXSVCH0ST.EXEAdded by the Troj/MMThief-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    svchostXsvchost.exe /nosplashAdded by the Troj/Bancban-DH TROJAN!
    svchostXolehelp.exe Olehelp adware component
    SVCHOSTXupdater32.exeAdded by the W32.RANTS.A WORM!
    SVCHOSTXSPOOLSV.EXEAdded by the W32/Baitap-A WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the Windows or Winnt folder.
    SvcHostXsvchost32.exeAdded by the W32/Agobot-TM WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    svchostXsvchost.exeAdded by the Troj/Bancban-HL TROJAN! Note: This trojan file is found in the Windows\config or Winnt\config folder.
    SVCHOST Generic applicationXsvchost.exeAdded by the Troj/Daemoni-O TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    svchost.exeXsvchost32.exe CoolWebSearch parasite related.
    SVCHOST.EXEXSVCHOST.EXEAdded by the TROJ/WRMSCAN-A TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    svchost.exeXsvchost.exeAdded by the Troj/PWSjx-A TROJAN!
    svchost.exeXsvchost.exeAdded by the Backdoor.Bifrose.D TROJAN! Note: This is not the legitimate Windows process. (Which is always found in the System32 folder.) This trojan file is found in the Root folder. (C:\), (D:\), (E:\) etc, etc.
    svchost1Xsvchost1.exeAdded by the AGOBOT.ZZ WORM!
    SvcHost32Xsvchost32.exeAdded by the W32.MIMAIL.I or W32.MIMAIL.J WORM!
    svchost64Xsvchost64.exeAdded by the SDBOTER.G WORM!
    svchostaXsvchosta.exeAdded by the TROJ/SNIFFER-I TROJAN!
    svchostbXsvchostb.exeAdded by the TROJ/SNIFFER-J TROJAN!
    svchostdll.scrXsvchostdll.scrAdded by the Troj/Bancban-FM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SvcHostoXv1rg1n.exeAdded by the W32/Agobot-TK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    svchostrXsvchostr.exeAdded by an unidentified WORM or TROJAN!
    svchostsXsvchosts.exeAdded by the Troj/Bancban-ADR or Troj/Bancban-DC or Troj/Banker-ED TROJANS!
    svchosts.exeXsvchosts.exeAdded by the W32/AGOBOT-JN WORM! or Troj/Bancban-GR TROJAN!
    svchosts.exeXsvchosts.exeAdded by Troj/Bancban-GX or Troj/Bancban-GV TROJAN!
    svchosts.scrXsvchosts.scrAdded by the Troj/Bancban-DQ or Troj/Bancban-GO or Troj/Bancban-GY TROJAN!
    SVCHOTXSVCHOT.exeAdded by the Troj/QQRob-U TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    svcinfoXsvcinfo.exeAdded by a CRYPTER.A trojan infection
    SvclhostXsvcchost.exeAdded by an unidentified WORM or TROJAN!
    svcmonUsvcmon.exeAdded by Spyware.PersonInspect surveillance software. Remove unless you installed it yourself!
    svcrootXsvcroot.exeAdded by the TROJ/KEYLOG-AC TROJAN!
    SvcSysX[path to file]Added by the PWSTEAL.BANCOS.Z TROJAN!
    Svcsys Registry ManagerXsvcsysreg.exeAdded by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.cv
    svctaskXsvctask.exeAdded by the Troj/Chuckyb-A TROJAN!
    svcwinprocess32X(path to worm)Added by the UPERING VIRUS!
    SVHOSTXsvhost.exeAdded by the W32.Mydoom.I WORM!
    SVHOSTXSVCHOST.EXEAdded by the W32.Zori.A VIRUS!
    Svhost LoaderXsvshost.exeAdded by the AGOBOT.G WORM!
    svhost updatesXSvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    svhost windows servicesXsvhost8.exeAdded by the W32/RBOT-WQ WORM!
    SVIDC32M?SVIDC32M.exe??
    sVideo2Xvxdrun6.exe "Switch" premium rate adult content dialer
    sviload32Xsviload32.exeAdded by the W32/RBOT-AAS WORM!
    SVM Pop?svmpop.exe??
    svnlitup32Xsvnlitup32.exeAdded by the RBOT.CBJ WORM!
    svnloaderXsvnload32.exeAdded by the W32/RBOT-ACU WORM!
    svphost.exeXsvphost.exeAdded by the Troj/Proxyser-N TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    svrrunXsvrrun.exeadware hailing from Deskwizz.com
    svsekinXsvsekt.exeAdded by the TROJAN.PWS.QQPASS.G TROJAN!
    svshostXsvshost.exeAdded by the KELVIR.CP WORM!
    svshostXmessenger.exeAdded by the TROJ/LOONY-G TROJAN!
    Svshost Update ServiceXsvcbind.exeAdded by the MYTOB.LH WORM!
    svshost32Xmsgrsv32.exeAdded by the WIN32.RANKY.AJ TROJAN!
    svshost32Xsvshost32.exeAdded by a variant of the W32/SDBOT WORM!
    svshostdriverXsvshost.exeAdded by the TROJ/SDBOT-HN TROJAN!
    svwin32Xunninst32.exeAdded by the W32/AGOBOT-NF WORM!
    SVX Control ServiceXsvxhost.exeAdded by the W32/Rbot-K WORM!
    Swap NutNjavaw.exeSwapNut is a peer-to-peer file sharing and searching utility developed and marketed by File Metrics, Inc. Users can search for and find almost any type of digital file (audio, video, photos etc.) through a secure peer-to-peer network
    SWCallerXSWcaller.exeSwcaller2.exeHomepage hijacker - see here
    SWClientUswsys.exe ActivMonAgent Keyboard logger/monitoring program - remove unless you installed it yourself!
    swcrootXswcroot.exeUnidentified adware
    swcrootXswcroot.exeAdded by the Troj/Soleno-A TROJAN!
    SWdNwinwd.exePC Security from Tropical Software - lock files, password protect, etc
    Sweep95YICLOAD95.EXEPart of Sophos ant-virus sofware
    Swf32XAVupdate.exeAdded by the MERKUR VIRUS!
    Swf32X_backup.exeAdded by the SYMTEN VIRUS!
    SwimSuitNetworkXSwimSuitNetwork.exeAdvertising spyware
    swingsysXSWINGSYS.EXEAdded by the Troj/Bancos-CX Trojan!
    Switch OffUswoff.exeSwitch Off - tray-based system utility that can automatically perform various frequently used operations like shutdown or restart your computer, disconnect your current dialup connection, lock workstation, etc
    Switchboard.com ToolbarNAtHoc.exeToolbar for the on-line version of Yellow Pages in the US - Switchboard.com
    Switcher.exe?Switcher.exeSony VAIO Wireless Switch Setting Utility - what does it do and is it required?
    switpXswitpa.exe OfferAgent adware component
    SWLUrundll32.exe [path] SWL.dll rdlAdded by the Stealth.Weblog surveillance software. Uninstall this software unless you put it there yourself.
    sws.exeX.exeHaldex type adult content dialler
    sws.exeXsvchost.exe GlobalDialer premium rate adult content dialer. The file is located in a GlobalDialer or HaldexLtd folder in Program Files - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    sws.exeXgd-dial.exeComponent of the "GlobalDialer" adult content premium rate dialer
    SwTrayNSWTRAY.EXEMS SideWinder game controller system tray icon. Available via Start -> Programs. May have the version number after it
    SXGDSENU?sxgdsenu.exeYamaha SXG soundcard driver
    SxgTkBar?sxgtkbar.exeYamaha SXG soundcard driver
    Sxplog?sxpstub.exePart of CA_Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required in startup?
    sxrrvXsxrrv.pifAdded by the Troj/Vax-A TROJAN!
    SyBot v2.1 By Sky-DancerXHPSV.exeAdded by the ZOTOB.I WORM!
    SYDNEYX(file path)Added by the SYNEY VIRUS!
    syelimS-esreveR-troppuSX[name of file]Added by the BKDR_LITBOT.C TROJAN!
    Syga432te Pe432rsonal FirewallXMrNo4236.exeAdded by the W32/RBOT-AQY WORM!
    Sygate Peral FirewallXSyga.exeAdded by the W32/Rbot-AQK WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Sygate Personal 3Xsvrv.exeAdded by the W32/RBOT-XD WORM!
    Sygate Personal BlockXStudio.exeAdded by the W32/RBOT-TW WORM!
    Sygate Personal FirewallXsystem32.exeAdded by the RBOT.VI WORM!
    Sygate Personal FirewallXWin32x.exeAdded by a W32/Rbot-KZ worm infection
    Sygate Personal FirewallXspoolsrv.exe W32.SpyBot worm variant
    Sygate Personal FirewallXsysgut.exeAdded by the SDBOT.WM WORM!
    Sygate Personal FirewallXSygate.exeAdded by the W32/Rbot-ASO WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Sygate Personal FirewallXMcafeeupdate.exeAdded by the RBOT.YN WORM!
    Sygate Personal FirewallXSygate32.exeAdded by the SDBOT.WW WORM!
    Sygate Personal FirewallXexplorer1.exeAdded by a variant of the W32/SDBOT WORM!
    Sygate Personal FirewallXsys.exeAdded by the W32/RBOT-ZC WORM!
    Sygate Personal FirewallXservice.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personal FirewallXMSNSRV32.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personal FirewallXt1ktik.exeAdded by the W32/RBOT-VP WORM!
    Sygate Personal FirewallXhost32.exeAdded by the W32/RBOT.ALD WORM!
    Sygate Personal FirewallXsyserror.exeAdded by the RBOT.UC WORM!
    Sygate Personal FirewallXsexy.exeAdded by the W32/RBOT-XY WORM!
    Sygate Personal FirewallXwinxpstat.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personal FirewallXwins.exeAdded by the RBOT.AOB WORM!
    Sygate Personal FirewallXSygat.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personal FirewallXhostserv.exeAdded by the RBOT.BKO WORM!
    Sygate Personal FirewallXmsnmsgrs.exeAdded by the RBOT.XN WORM!
    Sygate Personal FirewallXSyga.exeAdded by the W32/Rbot-AQD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Sygate Personal Firewall StartXservices32.exeAdded by a W32/Rbot-MB worm infection
    Sygate Personal Firewall StartXservic.exeAdded by the W32/RBOT-RY WORM!
    Sygate Personal PortXcrss.exeAdded by the W32/RBOT-PX WORM!
    Sygate Personal Port BlockerXwinupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personal Port BlockerXvolume.exeAdded by a variant of the WIN32.RBOT WORM!
    Sygate Personals FirewallsXccsrn.exeAdded by a variant of the WIN32.RBOT WORM!
    SyGateServiceUsgserv95.exeSyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs
    SymantecXccapp.exeAdded by the W32.Reatle WORM! Note: This is not a Symantec file.
    SymantecXInforme.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    Symantec Anti VirusXsymantec32.exeAdded by a variant of the W32/WOOTBOT WORM!
    Symantec AutoscanX(Random filename)Added by the W32/Rbot-AJO WORM!
    Symantec Configuration LoaderXccApp32.exeAdded by a variant of the GAOBOT.GEN WORM!
    Symantec Core LCYsymlcsvc.exePart of Norton AntiVirus 2004. What does it do?
    Symantec Fax Starter Edition PortNOLFSNT40.EXEOffers a virtual printer as a fax machine. Can be run via a desktop shortcut
    Symantec NetDriver MonitorUSNDMon.exePart of Symantec's LiveUpate (eg, Norton). Not required if you run manual upadates but probably requireD if you leave them to run automatically - hence the "U" recommendation
    Symantec NetDriver WarningUSNDWarn.exePart of Symantec Live Update - displays the warning when you need to update the firewall database.
    Symantec SecurityXsymantec32.exeAdded by the RANDEX.PR or RANDEX.YR VIRUSES!
    Symantec Security AddonXnvsvc.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Symantec Security Routine Addon for Microsoft WindowsXnavpxaw32.exeAdded by the AGOBOT-GJ TROJAN!
    Symantec UpdateXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    SymAVXSymAV.exeAdded by the W32.NETSKY.U WORM!
    SymKeepAliveUCKA.exePart of Norton SystemWorks 2003 - keeps a dial-up modem connection alive
    SymlcsX(path to executable)Added by the Troj/YaSpy-A TROJAN!
    SymRunXccApps.exeAdded by the Troj/Kagen-A TROJAN! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    SymRunXccApps.exeAdded by the TROJ/KAGEN-B TROJAN!
    SymTray - Norton SystemWorksNSYMTRAY.EXEKeeps all System Tray icons for Norton SystemWorks together to reduce clutter. SystemWorks includes Norton Anti-Virus, Norton Utilities and Norton CleanSweep - mentioned elsewhere here. Personally I only have Norton eMail Protect running which doesn't need SymTray
    Sync DataUHndsync.exePocket Real Estate - mobile synchronization manager
    Sync-ItUSyncit.exeSync-It - synchronizes the system clock with time servers on the internet
    SyncAgentUsyncagent.exeGhost Keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
    Synchronization ManageXrservers.exeAdded by the W32/Forbot-FM WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Synchronization ManagerNmobsync.exeFind more information about its use here
    syncmanXwinsync.exeAdded by the Troj/MancSyn-A TROJAN!
    SyncManagerXmsorunner.exeAdded by a variant of the WIN32.TACTSLAY TROJAN!
    SyncMonXadslcomdos.exeAdded by the CLUNKY-A TROJAN!
    SynSetup?SynTP.tmp RunOnce.exeProbably associated Synaptics touchpads on laptops as for the SynTPEnh and SynTPLpr entries but what does it do and is it required?
    SyntaxXwindows32.exeAdded by the SDBOT.CQ WORM!
    Syntax ScriptXsystacq.exeAdded by the SDBOT.AI WORM!
    SynTPEnhUsyntpenh.exeSynaptics touchpad tray icon. Displays status and provides quick launch to touchpad features such as scrolling and tap zones. Required on IBM Thinkpads with UnltraNav (pointstick and touchpad combo) if you don't want to loose the advanced pointstick features such as scroll
    SynTPLprYsyntplpr.exeSynaptics touchpad driver helper. Required for touchpad features to work
    sysXregedit /s sys.regHijacker
    sysXsysdllwm.reg CoolWebSearch parasite related.
    Sys RenXSysRen.exePart of FlashEnhancer adware
    sys************* ( * = random digit)Xsys*************.exe ( * = random digit) WINBO adware component
    Sys**.exe (* = random char)XSys**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Sys**32.exe (* = random char)XSys**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    sys008Xsys008.exeHijacker, also detected as the TROJ/STARTPA-GK TROJAN!
    sys009Xsys009.exeAdded by the Troj/StartPa-ZB TROJAN!
    sys201Xsys209.exeAdded by the Troj/StartPa-ZY TROJAN!
    Sys29Xwin***32.exe (* = random char) EliteBar adware
    sys32Xsys32.exeAdded by the FLUX.E Backdoor TROJAN!
    sys32Xsysx32.exeAdded by the W32/Kvex-A VIRUS!
    sys32dllXsys32dll.exeAdded by the W32.Aimdes.B WORM!
    sys32sqlUsys32win.exeAdded by the Active_Keylogger surveillance software. Uninstall this software unless you put it there yourself.
    SysAXwin***32.exe (* = random char) EliteBar adware
    SysAgentUSysAgent.exeSYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
    SysAIXSysAI.exeAproposMedia adware - also creates SysAI folder in Program Files where the SysAI.exe is also located
    SysBkupU[path to file]Added by the Keyspy surveillance software. Uninstall this software unless you put it there yourself.
    SysbotUsysbot.exeSpector - spying (or monitoring) software to record internet activity
    syscfgXsyscfg32.exeAdded by the KWBOT.S VIRUS!
    syscfg34.exeXsyscfg34.exeAdded by the ELECTRON VIRUS!
    SyscheckXwin.htaBrowser hijacker
    syscheckXiexplorer.exeAdded by a Win32.Agent.dm downloader trojan infection. NOTE - This is NOT the Internet Explorer file, which is called Iexplore.exe, and will always be located in the Internet Explorer folder in Program Files!
    sysclxXntldrt.exeAdded by the W32/Jlok-A WORM!
    syscmXSyscm.exeVanish adware
    SysComp?mssdnl.comUnknown but suspect as *.com are not usually run at start up and the name isn't recognized
    sysconXsyscon.exeAdded by the W32.APRILCONE.A WORM!
    syscon lptt01 or syscon ml097eXsyscon.exeVariant of the RapidBlaster parasite (in a "Syscon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    sysconfigXiexplorer.exeAdded by the CULT.C VIRUS!. Note - iexplorer.exe is not to be confused with Interrnet Explorer (iexplore.exe)
    SysConfigXsyscfg35.exeAdded by the KAZMOR.C VIRUS!
    sysconfigXiexplorer.exeAdded by the CULT.H VIRUS! Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
    SysConfigXwincfg32.exeAdded by the SDBOT.ZD WORM!
    SysconfigUStealth KeySpy.exe StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!
    SyscpyXSyscpy.exeFirewall-bypassing, proxied spam relayer. Detected by Symantec as the HOGLE VIRUS!
    SysCtlXsysctl.exeAdded by the AOK VIRUS!
    SysctrlsXprocdll.exeAdded by the WEEDBOTZ.14 VIRUS!
    sysdat.dllXsysdat.dll.exeAdded by the Nishica 1.1 backdoor TROJAN!
    SysDataX[path to file]Added by Troj/Ranck-BA TROJAN!
    SysDesktopXfswan.exeAdded by the Troj/QQPass-AF TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SysDesktopXfswanQQ.exeAdded by the Troj/QQSend-A TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    sysdirXwinrun.exeAdded by the WINBUR.B VIRUS!
    sysdllX(Trojan file name)Added by the Trojan.Hugesot TROJAN!
    SysdptXsysdpt.exe TrojanDownloader.Win32.Crypt
    sysdxvidXsysdxvid.exePremium rate adult content dialer
    sysdxvidXsysdxvid.exe /nocommAdded by the Troj/Dluca-S TROJAN!
    SysEQXsvclgx32.exeAdded by the TROJ/IRCBOT-AC TROJAN!
    sysfilerXsysfiler.exeAdded by the RETSAM VIRUS!
    SYSfitXSYSfit.exe AdShooter adware variant
    sysflg32Xsysflg32.exeAdded by a Crypter.C trojan variant infection
    sysformatXsysformat.exeAdded by the W32/BAGLE-BK WORM!
    sysfrcxXsysfrcx.exeAdded by the KEYLOG-SCLOG TROJAN!
    syshelpXsyshelp.exeAdded by a variant of the LOVGATE WORM!
    sysinX[path to file]Added by the TROJ/DSRC-A TROJAN!
    sysinfoXsysinfo.exeAdded by the BEDRILL VIRUS!
    sysinfo.exeXsysinfo.exeAdded by the BEAGLE.V WORM!
    SysInitXwininit32.exeAdded by the XABOT VIRUS!
    sysinitXservices.exeTroj/NewIfrm-A trojan
    SysinoXlsess.exeAdded by the W32/FORBOT-BF WORM!
    sysint16Xsysint16.exeAdded by a Crypter.A trojan variant infection
    SyskeyXsysinit.exeAdded by the W32.BEAGLE.AX WORM!
    SyslibXSyslib.exeAdult content related downloader trojan
    Syslog lptt01 or Syslog ml097eXSyslog.exeVariant of the RapidBlaster parasite (in a "Syslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    syslogin.exeXsyslogin.exeAdded by a W32/Bagz-B worm infection
    SysmanUSysman KeyTrap is a spyware program that records all keyboard activities. If you didn't install it yourself remove it.
    sysmemXmmsete.exeAdded by the W32.Nopir.C Worm!
    sysmemXoutlookrem.exeAdded by the W32/Nopir-C Worm!
    SysMemory managerXmdms.exeAdded by the Troj/Cimuz-D TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SysMetrixUSysMetrix.exeSysMetrix - skinnable clock and metering application. It monitors and reports on a great number of statistics
    sysmngr32Xsys64mnger.exeAdded by a variant of the WIN32.RBOT WORM!
    sysmodXsysmod.exeAdded by the W32/Spybot-DU WORM!
    sysmonXsysmon.exeAdded by the BIZEX VIRUS!
    SysmonXrpcmon.exeAdded by the RANDEX.ATX VIRUS!
    sysmonXsysmon44.exeAdded by a variant of the BackDoor-CBA TROJAN!
    SysMonXwowexece.exeAdded by the Troj/Mulan-A TROJAN!
    sysmon12X[various file names]TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    sysmonntXsysmonnt Transponder parasite related
    sysmonntXsysmonnt.exe SearchPounder sends keywords typed into HTML forms and popular Internet search engines to a remote server
    SysMonXPXSysMonXP.exeAdded by the W32.NETSKY.Q WORM!
    sysnateXsysnate.exeAdded by the MEDIAS VIRUS!
    SysnetXsnuninst.exeUnidentified adware
    sysnetXsysnet.exeCasClient adware - also detected as the CMAPP TROJAN!
    sysobj.exeXsysobj.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    SysOpsXSysOpsAdded by the MSNCORRUPT VIRUS!
    syspareXsyspare.exeAdded by the Troj/Bifrose-AN TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    syspathXdrv.exeAdded by the SOBER VIRUS!
    sysPersonalFirewallXmsnmssgr.exeAdded by a variant of the WIN32.RBOT WORM!
    sysPersonalFirewallXsystem.exeAdded by the WOOTBOT.FH WORM!
    sysPersonalFirewallXtskm0nitor.exeAdded by a variant of the WIN32.RBOT WORM!
    SysPilotUfdxxl.exeG Data "PC Spion". PC monitoring and surveilling software, captures all users activity on the PC, see here . Disable/remove if you didn't install it yourself!
    sysPnPXbootconf.exeHomepage hijacker, redirecting to coolwwwsearch.com; see for example here
    SysPnPXrundll32 setupapi, InstallHinfSection.... oemsyspnp.infSearch hijacker - see here
    syspolXsyspol.exeAdded by the TROJ/DREMN-B TROJAN! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    SysPoolYMssvc.exeStealthDisk - hides folders, files and applications. Will also encrypt them for better protection
    SysPoolXMSSVC32.EXEAdded by the Troj/Bancban-IO TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    sysprocessor UpdateXsysprocessor.exe Win32.Rbot worm variant
    SysProtectXSystem.exeAdded by the NETSPY VIRUS!
    syspw32.exeXsyspw32.exeAdded by the W32.Appflet WORM!
    SysrXsysmd.exe Ulubione adult content dialer
    SysRegXSysReg.exeAdded by the CCINVADER2 VIRUS!
    SysRegXSysReg.exeSearchSeekFind textual marketing foistware
    SysresXSysres.exeAdded by the LOGMOD VIRUS!
    SysResXTASKMANAGER.exeAdded by the W32.Elitper.A WORM!
    SysResXWWE DIVAS.exeAdded by the W32.Elitper.D WORM!
    SysResXIExpIore .exeAdded by the W32.ELITPER.E WORM!
    SysScanXbvt.exeAdded by the AUTOUPDER VIRUS!
    SysSearchXRegedit.exe -s [path] pcsearch.regAdded by the StartPage-FN browser hijacker
    SysSearchXREGEDIT.EXE -s [path] sysreg.regAdded by the STARTPA-ME TROJAN!
    SysSearchX[path] REGEDIT.EXE -s [path] sysreg.regHijacker, also detected as the TROJ/STARTPA-ME TROJAN!
    sysserX(path to file)Added by the W32.RAHACK WORM! or the Troj/RaHack-B TROJAN!
    SysServiceXSysService.exeAdded by the TROJ/BDFORM-A TROJAN!
    SysServiceUSERVICES.EXE NSKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\NSkeylogger folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SysService32XSysService32.exe, ln32k.dllAdded by the KINDAL VIRUS!
    SysService32lXsystask32l.exeAdded by the THEUG VIRUS!
    SYSsfitbXSYSsfitb.exeSearchforit browser hijacker
    SysStartX***sysi6.exe (* = random char)Added by ZenoSearch adware - filenames spotted include jdisysi6.exe, hjisysi6.exe, ffgsysi6.exe and more.
    SysStartX1.exeAdded by ZenoSearch adware
    systXsyst.exeAdded by the JOKE_DUMB.A "Joke" virus
    SystemXrun322.exeAdded by the LANFILT VIRUS!
    SystemXsystem.exeAdded by a number of VIRUSES, including CHILI, NULLBOT, FULAMER.25, NETCONTROLL, NETCONTROLL, GATECRASH.A, GATECRASH.B, NTCONTROL.A, BUSHTRO122& VIVAEL
    systemXregedit -s system.dllHomepage hijacker
    systemXsystemsearch.htaJetseeker.com hijacker
    SystemXdcomx.exeAdded by the CIREBOT VIRUS!
    systemXExplorer.exeAdded by the GRAYBIRD VIRUS! Note - this is located in this is located in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) rather than the valid Windows Explorer which is located in C:\Windows or C:\Winnt
    SystemXYPager.exeAdded by the JUNTADOR.K VIRUS! Note! - this is not Yahoo! Messenger
    systemXoutlook.exeAdded by the W32.MIMAIL.Q WORM! **Note - Microsoft's outlook.exe resides in the Program Files sub-directory whereas this resides in C:\Windows or C:\Winnt
    SystemXAtira.exeAdded by the KOTIRA VIRUS!
    SYSTEMXlsas.exeAdded by the SPYBOT.CJ worm
    SystemXkernels32.exeAdded by the VICSFRAM TROJAN!
    SystemXsysctrl.exe /aAdded by WinGuardian **Note: This Commercial_keylogger is no longer made or sold by Webroot but older copies may still be in existance, those copies will be identified as spyware.
    SystemXcsrss.exeAdded by the Troj/LdPinch-PT TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
    SystemXsvchost.exeAdded by the LDPINCH-AU or Troj/LdPinch-BD and Troj/LdPinch-BH TROJANS! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    systemXlsasse.exeAdded by the W32/RBOT-YL WORM!
    SystemXsystray.exeAdded by the TROJ/PISABOY-A TROJAN! - NOTE - this is NOT the valid System Tray application as described here
    SystemXcber.exeAdded by an unidentified TROJAN!
    SystemXwindowsps.exeAdded by a variant of the WIN32.RBOT WORM!
    SystemXsvchîst.exeAdded by the Troj/LdPinch-BF TROJAN!
    SystemXWINL0G0N.EXE /nosplashAdded by the Troj/Bancos-DB TROJAN!
    SystemXabcdefg.exeAdded by the W32/Harwig-B WORM!
    SystemXwumgrd32.exeAdded by a variant of the WIN32.RBOT WORM!
    SystemXserwin.exeAdded by the TROJ/LDPINCH-BN TROJAN!
    SystemXsystem.exe (74295303)Added by the W32/VB-IU WORM!
    systemXmessenger.exeAdded by an unidentified WORM or TROJAN!
    SystemXsystem23.exeAdded by the W32/Lebreat-D WORM!
    SystemXSPOOLSU.EXEAdded by the Troj/Banker-FC TROJAN! Note: SPOOLSU.EXE (Notice it's spelled with a U) is not the legitimate Windows Process. The legitimate Windows Process (Spoolsv.exe) is found in the System32. This trojan file is found in the Windows or Winnt folder.
    SystemXabcdefg.exeAdded by the W32/HARWIG-C WORM!
    SYSTEMXd.exeAdded by the MYTOB.LP WORM!
    SYSTEMX(Random filename)Added by the W32/Mytob-FB WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SystemXinetinfo.exeAdded by Troj/ParDrop-A TROJAN!
    SYSTEMXwiinlogon.exeAdded by the W32/Rbot-AVG WORM! Note: This is not the legitimate Windows process winlogon.exe (Notice the difference in the spelling.) This worm\trojan file (wiinlogon.exe) is located in the System (95/98/ME) or System32 (NT/2000/XP) folder. Do not confuse the two files!
    System 64 Driver for GamesXsys64dvr.exeAdded by the SDBOT WORM!
    System Applications ProfileXsap.exeAdded by the W32/RBOT-QF WORM!
    System BackupXmsystem.exeAdult content dialler
    System backupX[random or different file name]Added by the ADMINCASH.B TROJAN! - NOTE multiple different file names have been spotted; examples: web.exe, soft.exe, msxmidi.exe, wmplayer.exe, as well as completely random ones such as 9a2de006.exe, 36c75e3c.exe and so on.
    System Backup ServicesXbackups32.exeAdded by a variant of the WIN32.RBOT WORM!
    System Buffer ApplicationXbuffer32.exeAdded by the W32/SDBOT-UD WORM!
    System CacheXSysCache.exeUnidentified worm or trojan
    System CheckURundll32.exe SysDll32.dll, SystemCheckXPCSpy Pro keylogger, surveillance and monitoring software
    system checkXupdater.exeUnidentified adware downloader
    System CheckXRundll32.exe SysDll32.dll,SystemCheckAdded by XpcSpy SPYWARE!
    System CheckingXwasul.exeAdded by the RBOT.BHM WORM!
    System ConfigXBF3.EXEAdded by the W32/Spybot-DT WORM!
    System Config ManagerXcrss.exeAdded by the AGOBOT.GH WORM!
    System Config ManagerXsmssl.exeAdded by the W32/Agobot-ZJ WORM!
    System ConfigurationXiexplore.exeAdded by the RANDEX.AD VIRUS! Note that the real "iexplore.exe" is located in Program Files\Internet Explorer
    System ConfigurationXsyscfg32.exeAdded by the W32.Mytob.EA WORM!
    system configureXsvchost.exeAdded by the Troj/Lineage-C TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    System CPL managerX[random file name]Added by the W32/RBOT-SR WORM!
    System CSRSS PatchXscrtkfg.exeAdded by a variant of the WIN32.RBOT WORM!
    System CSRSS PatchXSCRTKFG.EXEAdded by the W32/RBOT-ADA WORM!
    System Database administrationXsystemDA.exeAdded by the W32.Derdero.B WORM!
    System Database Administration Support ProcessXsysdasp.exeAdded by the W32.Derdero.C WORM!
    System DiagnosticsXsysdiag32.exeAdded by the SDBOT.GEN WORM!
    System DLFNcpqdiaga.exeCompaq Diagnostic record system utility which allow you to view information about your computer's hardware and software configuration. Available via Start -> Programs
    System DLL ResourcesUsysdll.exeAdded by the SnapKey SPYWARE! **Note if you did not intentionally install this remove it.
    System Document ApplicationXnmod.exeAdded by the W32/SDBOT-ABB WORM!
    System Document ApplicationXmsdocument.exeAdded by the W32.Randex.COX WORM!
    System Document ApplicationXwins.exeAdded by the SDBOT.AUB WORM!
    System driverXMessenger.exeAdded by the WOOTBOT.GI WORM!
    System DriversXwingmt.exeAdded by the W32/SDBOT-MG WORM!
    System Efficiency MonitorXmscedit32.exeAdded by the SDBOT.P WORM!
    System Efficiency MonitorXmscommand.exeAdded by the KWBOT.P VIRUS!
    System Event ManagerXsecsvc.exeAdded by the RBOT.BMY WORM!
    System Executable DLL LibraryXEXECDLL32.exeAdded by the RANDEX.AZ VIRUS!
    System Failure StatisticXcnstat.exeAdded by a W32/Rbot-LF worm infection
    System Failure StatisticXcnstat.exeAdded by the W32/RBOT-LF WORM!
    System File DriversXnvsysvc32.exeAdded by the AGOBOT.WJ WORM!
    system firewallXmakeini32.exeAdded by the W32/AGOBOT-PS WORM!
    System GuardXmhguard.exeAdded by the W32/Rbot-AGU WORM!
    System HandlerXLSASS.EXEAdded by the NIMOS VIRUS! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
    System Host ManagerXsyshost.exeAdded by the W32/BANWORM-C WORM!
    System Host ServiceXsvchost.exeAdded by the CONE.F VIRUS! Note - this is not the valid svchost.exe as described here
    System Information ManagerXNavcpe.exeAdded by a W32/Sdbot-QB worm infection
    System Information ManagerXMsbb.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    System InitializationXmsmsgri32.exe, payload.datAdded by the RANDEX.D or ROXY or ROXY.B VIRUSES!
    System Kernal SupportXsystem.exeAdded by the SDBOT.BWV and W32/Rbot-AEA WORMS!
    System KernelXlsass.exeAdded by the Troj/VBbot-G TROJAN!
    System LifeGuard SchedulerUSlsched.exeSystem LifeGuard scheduler
    System Log EventXcsrss32.exeAdded by the W32/Agobot-JI WORM!
    System Management ServiceXsmsc.exeAdded by the W32/RBOT-ANN WORM!
    System ManagerXsvchost.exeAdded by the TROJ/BANKER-AE TROJAN! Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    system managerXSystem.exeAdded by the W32/FORBOT-BO WORM!
    System ManagerXwinsrv32.exeAdded by an unidentified WORM or TROJAN!
    System ManagerXsysmng.exeAdded by the W32/Tame-C WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System Manager UpdatesXwinsvc.exeAdded by the AGOBOT.AEM WORM!
    System Mechanic Popup StopperUPopupstopper.exe Iolo "System Mechanic" popup stopper
    SYSTEM MESSAGERXwmisg.exeAdded by the W32.Mytob.ES WORM!
    System Messaging QueueXSMCSS.EXEAdded by a variant of the WIN32.RBOT WORM!
    System MessengerXSYSMSG32.EXEAdded by the W32/SPYBOT-DK WORM!
    System MonitorUSYSMON.EXEComes with some Aopen motherboards. Monitors CPU temp, voltage and fan speed. Warns if any become abnormal
    System MonitorXSysmon16.exeAdded by the SDBOT WORM!
    System MScvbXmscvb32.exeAdded by the SOBIG.C VIRUS!
    System NetXsys32.exeAdded by the W32/Forbot-FX WORM!
    System Net DatabaseXsysnd.exeAdded by the W32/RBOT-AAW WORM!
    System NetworkingXsysnet.exeAdded by the RBOT.API WORM!
    System Power ManagmentXsvcnost.exeAdded by W32/Dref-I WORM!
    System ProcessXlsass.exeAdded by the TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows lsass.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    System ProcessXsvchost.exeAdded by the TROJ/ADCLICK-AG TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    System ProcessXcsrss.exeAdded by the TROJ/ADCLICK-AG TROJAN! - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, located in the Winnt/System32 or Windows\System32 folder, and which should NOT figure in Msconfig/Startup!
    System ProcessXCSRSR.exeAdded by the W32/AGOBOT-SQ WORM!
    System ProfileXRegsrv.exeAdded by the BDS/OPTIXPRO.12 VIRUS!
    System RebootXrebootsys.exeAdded by the W32/RBOT-WU WORM!
    System RedirectXsysbho.exeDownloader trojan, "Melkosoft" adware related
    System RestoreXsvcnet.exeAdded by the W32.TIBICK WORM
    System Restore DataX[path] repcale.exe [path] beird.exeAdded by the RANDON.AN WORM!
    System Restore DLLsXixplorer.exeAdded by a variant of the W32/SDBOT WORM!
    System ServiceXMSREXE.EXEAdded by the AML VIRUS!
    system serviceXspoolcrv.cplAdded by the INSPIR.11 VIRUS!
    System ServiceXsystems.exeAdded by the AGOBOT.VZ WORM!
    System serviceXsystem.exeAdded by the PWSteal.Bancos.AA TROJAN!
    System ServiceXservicent.exeAdded by the W32/Rbot-AJI WORM!
    System ServiceXexp0lrer.exeAdded by a variant of the WIN32.RBOT WORM!
    System ServiceXcoderxt.exeAdded by the W32/Rbot-ALD WORM!
    System ServiceXservicez.exeAdded by the W32/Rbot-AOY WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System ServiceXmsnwindows.exeAdded by the W32.Spybot.YCL WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System ServiceXteskmangr.exeAdded by W32/Rbot-AUV WORM!
    System ServiceXmsnxpexe.exeAdded by the W32/Rbot-AYC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SYSTEM service helperXsyshelp.exeAdded by a variant of the W32/MONKBD-A WORM!
    SYSTEM service helperXsvchelper.exeAdded by the W32/MONKBD-A WORM!
    System service61Xpokapoka61.exe EliteBar adware component
    System service62Xpokapoka62.exe EliteBar adware component
    System service62Xpokapoka63.exe EliteBar adware component
    System service63Xpokapoka63.exe EliteBar adware component
    System service63Xpokapoka64.exe EliteBar adware component
    System service63Xpokapoka66.exe EliteBar adware component
    System service65Xpokapoka65.exe EliteBar adware component
    System service66Xpokapoka66.exe EliteBar adware component
    System service67Xpokapoka67.exe EliteBar adware component
    System service68Xpokapoka68.exe EliteBar adware component
    System service69Xpokapoka69.exe EliteBar adware component
    System service69Xpokapoka69.exeAdded by the Troj/Elitebar-O TROJAN! Note: This trojan file is found in the Windows\etb or Winnt\etb folder.
    System service70Xpokapoka70.exe EliteBar adware component
    System service71Xpokapoka71.exe EliteBar adware component
    System service72Xpokapoka72.exe EliteBar adware component
    System service73Xpokapoka73.exe EliteBar adware component
    System service74Xpokapoka74.exe EliteBar adware component
    System service75Xpokapoka75.exe EliteBar adware component
    System service76Xpokapoka76.exe EliteBar adware component
    System service77Xpokapoka77.exe EliteBar adware component
    System service78Xpokapoka78.exe EliteBar adware component
    System service78X[path to executable]Added by Troj/Elitebar-T and Troj/Elitebar-U TROJAN!
    System service79Xpokapoka79.exe EliteBar adware component
    System service79X(Pathname of the executable)Added by the Troj/Elitebar-V TROJAN!
    System ServicesXconnection.exeAdded by an unidentified WORM or TROJAN!
    System ServicesX[random file name]Added by a variant of the WIN32.RBOT WORM!
    System ServicesXsvcsenes.exeAdded by a variant of the WIN32.RBOT WORM!
    System ServicesXsvcsenes32a.exeAdded by the W32/Rbot-AFG Worm!
    System ServicesXssms.exeAdded by a variant of the WIN32.RBOT WORM!
    System Session ManagerXsmss.exeAdded by the W32/Kalel-E WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    System settingsXburndl32.exeAdded by the W32/SDBOT-ZO WORM!
    System SetupXrpcxcmod.exeAdded by an unidentified WORM or TROJAN!
    System Soap ProXsoap.exeSystem Soap Pro internet cleaning software. Bundles foistware like HTTPER and Zipclix - best avoided
    System startupUcharmapx.exeOnly required if using an oriental language
    System StartupXVoltio.exeAdded by a RBOT.NJ worm infection
    System StartupXkimochi.exeAdded by a variant of the WIN32.RBOT WORM!
    System Startup ManagerXsmcss.exeAdded by the RBOT.AMD WORM!
    System StatsXSystemStats.exeAdded by a variant of the W32/WOOTBOT WORM!
    System SupportXsystem32.exeAdded by the W32/RBOT-AHA WORM!
    System SupportXsyscfg.exeAdded by the W32/Rbot-AGQ WORM!
    System SupportXsyssql.exeAdded by W32/Rbot-AUH WORM!
    System TerminalXSYSTEM2.EXEAdded by a Troj/Spybot-BZ trojan infection
    System time updatorXCSysTime.exeAdded by the RANDEX.S VIRUS!
    System ToolkitXSystools.exeAdded by the RONOPER-G VIRUS!
    System TrayXmsccn32.exeAdded by the W32/SOBIG.B Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com. Note - this is not the valid SystemTray ( SysTray.exe)
    System TrayXsystray.exeAdded by the W32/Fan-A WORM!
    System Tray ServicesXspooles32.exeAdded by the AGOBOT.ZH WORM!
    System Tray32XSysTray32.exeAdded by the REPAD VIRUS!
    System UnixXsyscfg32.exeAdded by the W32/RBOT-ZD WORM!
    system updataXupdata.exeAdded by the Troj/Lineage-C TROJAN!
    System UpdateX(random file name)Added by the Troj/Soromo-A TROJAN!
    System UpdateXwupdmgr.exeAdded by a Troj/Soromo-A trojan infection
    System UpdateXwauluclt.exeAdded by the SDBOT.EF WORM!
    System Update ServiceXwinupd32.exeAdded by the ADTODA-A TROJAN!
    System Update ServiceXsystem.pifAdded by the W32/Rbot-ALL WORM!
    System Update ServiceXupdate.pifAdded by the W32.Spybot.WOE WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    System Update2Xwininet.exeAdded by the Autotroj-C TROJAN!
    System Update2Xupdate.exeAdded by the Autotroj-C TROJAN!
    System Update2Xtaskmon.exeAdded by the Autotroj-C TROJAN!
    System Update2Xsvchost.exeAdded by the Autotroj-C TROJAN!
    System Update2Xservices.exeAdded by the Autotroj-C TROJAN!
    System Update2Xwupdmgr.exeAdded by the Autotroj-C TROJAN!
    System Update2Xwinspool.exeAdded by the Autotroj-C TROJAN!
    System Update2Xwebcheck.exeAdded by the Autotroj-C TROJAN!
    System Update2Xexplorer.exeAdded by the Autotroj-C TROJAN!
    System Update2Xwinlogon.exeAdded by the Autotroj-C TROJAN!
    System Update2Xsystem.exeAdded by the Autotroj-C TROJAN!
    System Update2Xtaskman.exeAdded by the Autotroj-C TROJAN!
    System UpdatedXsvchoes.exeAdded by the W32/Rbot-ASF WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System Updater ServiceXwmiprvsw.exeAdded by the GAOBOT.AFC WORM!
    System UpdatesXwinsci.exeAdded by a variant of the WIN32.RBOT WORM!
    System UpdatesXunve.exeAdded by the W32/Rbot-AWG TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System UpdatesXszwi.exeAdded by the W32/Rbot-AXE WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    System Updates 4Xmssysfix.exeAdded by the W32/Rbot-ADU Worm!
    System Updates ManagerXwinserv32.exeAdded by the W32/Agobot-AGA Worm!
    System Updates ServiceXupdates.pifAdded by the W32/Rbot-AMA WORM!
    System Uptime ServerXSYSENTRY.EXE, SYSENTRY32.EXEAdded by a RBOT.LK worm infection
    system xpXacdsee demo.exeAdded by W32.SALGA.A WORM!
    System-ConfigXmsptmf32.comAdded by a Win32.Lioten.FA worm infection
    System-ServiceXEXPLORER.SCRAdded by the BENJAMIN VIRUS! KaZaA file-sharing users beware!
    system.Xsystem..exeAdded by the OPTIXPRO.13.C VIRUS!
    system...Xsystem...exeAdded by the OPTIXPRO.13.C VIRUS!
    system.exeXsystem.exeAdded by the PWSTEAL.JGINKO TROJAN!
    system.exeXsystem.exeAdded by the Troj/Jginko-B TROJAN! Note: This trojan file is found in the Root folder. (C:\), (D:\), (E:\) etc, etc.
    System132XCsrtss.exeAdded by the LANFILT-I TROJAN!
    system23XnotPad.exeAdded by the ESTEEMS.D TROJAN!
    System32Xsystem.exeAdded by the BUSHTRO122 VIRUS!
    System32XSystem32.exeAdded by the MARI, SYSXXX and other VIRUSES!
    System32Xsystem32,1.exeworm or trojan, as yet unidentified
    System32Usysdiag.exe SpyAgent.B surveillance software - uninstall this software unless you put it there yourself!
    System32Xsystem.exeAdded by a BushTro122 trojan infection
    system32XNeT-BoT.exeAdded by the W32/AGOBOT-LJ WORM!
    System32Xlsasss.exeAdded by the W32/RBOT-XW WORM!
    System32Xcrsvvc.exeAdded by the RBOT.BLY WORM!
    system32XQQGame.exeAdded by the TROJ/QQPASS-AC TROJAN!
    System32 PCI ManagerXsyspci32.exeAdded by the W32/Rbot-AFR Worm!
    System32 TCP ManagerXsysterm.exeAdded by the RBOT.AFD WORM!
    System32 TCP ManagerXsystcpm.exeAdded by a variant of the WIN32.RBOT WORM!
    System32 Temp ServiceXsystmp.exeAdded by the W32/Rbot-AET Worm!
    system32.dllXsysteminit.exe CoolWebSearch parasite related.
    system32.dllXsysdll32.exe CoolWebSearch parasite related.
    system32.exeXservices32.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    system32.exeXsystem32.exeAdded by the Backdoor.Graybird.P TROJAN! Note: This worm/trojan file is found in the Windows or Winnt folder.
    System32CheckX.exeAdded by the Troj/Chast-A keylogging TROJAN! Note: This worm file is found in the Windows(95/98/Me/XP) or WINNT (Nt/2000) folder.
    System32DllXDLL32SYS.EXEAdded by a W32/Spybot-CZ worm infection
    System32ExXSystem32Ex.exeAdded by a Backdoor.IrcContact trojan infection
    System32kfvwĆUsysdiag.exe SpyAgent.B surveillance software - uninstall this software unless you put it there yourself!
    System33XFB_PNU.EXEAdded by the NICHELLO-A VIRUS!
    System4224411XVirusAdded by the CAGER.A WORM!
    System4224411XSystemdll.exeAdded by the W32/Yusufali-B WORM! Note: This worm\ file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    SystemAdministrationXWincmp32.exeAdded by the ASYLUM VIRUS!
    SystemAgentUSage.exe"Microsoft Plus! System Agent automatically tunes your system, performing tasks such as disk optimization and error correction. It can also run any application at prescheduled times"
    SystemBXMessengerStopper.exe MessStopper adware
    SystemBackupXmtx.exeAdded by the MTX VIRUS!
    SystemBackupXMicroLog.exeAdded by the MICROLOG.A VIRUS!
    SystemBoot?ladies.htmUnknown but sounds very suspicious??
    SystemBootXMshta.exe ...filename.htaAdult content dialler
    SystembootXmsnsngr.exeAdded by a variant of the WIN32.RBOT WORM!
    SystemBootXservices.exeAdded by the W32.SOBER.P WORM! - NOTE - this file is placed in a "%Windir%\Help\Help" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SystemCheckXSystemcheck.exeAdded by the LAVITS VIRUS!
    SystemCheckXSysCheckBop32.exe WINBO adware component
    SystemCheckXservices.exeAdded by the W32/SOBER-M WORM! - Note - this file is placed in a %WINDOWS%\Config\system subfolder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SystemCheckXsvchost.exeAdded by the TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SystemCheckerXSyschk.exeAdded by the GAIL.F VIRUS!
    SystemCONF98iXSystemCONF98i.exeAdded by the FROZEN BOT VIRUS!
    SystemDebugXSysdeb32.exeAdded by the SYSBUG VIRUS!
    SystemDllXSystemDll.exeAdded by the LOXOSCAM TROJAN!
    systemdll32.exeXsystemdll32.exeAdded by the FEUTEL-F TROJAN!
    SystemDriverXcsrss.exeAdded by the ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!
    SystemDriverCheckXsvchost.exeAdded by the TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    SystemDriverLoadXsvchost.exeAdded by the TROJ/DELF-KR TROJAN! - NOTE - this file is placed in a C:\DriverLoad folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    systemdrvXms32sys.exeWORM related - most likely GAOBOT
    SystemEmergencyX CoolWebSearch parasite related.
    SystemExplorerXexplore.exeHomepage hijacker - file located in the "Services" folder in Common Files
    SystemFileXSystemFile.exeAdded by the Troj/Dulldoor-A Trojan!
    SystemFTPXVSENMB.exeMalware (ie, malicious software).  Also changes the system.ini Shell line to read Shell=Explorer.exe VSENMB.exe, and it hacks the Winstart.bat as well
    SystemidleXstemIdle.exeAdded by the WOOTBOT.AO VIRUS!
    SystemInitXiservc.exeAdded by the FIZZER VIRUS!
    Systemiom UpdaterXSystemiom.exe WORM_SPYBOT.TY
    SystemLoad32Xsysload32.exeAdded by the W32.MIMAIL.E WORM!
    SystemManagerXSysman32.exeAdded by the DOWNLOADER-BW.B VIRUS!
    SystemMap32XNetisp32.vbsAdded by the REDIST.C VIRUS!
    SystemMDXmd.exeHomepage hijacker
    SystemMonitorXSysmon32.exeAdded by a AIDID.A worm infection
    SystemMonitorXSYSMON32.exeAdded by the W32.Aidid VIRUS!
    SystemNetworkXNETSERV.EXEAdded by the NETCONTROL VIRUS!
    SystemNetworkXsysnet.exeAdded by a variant of the WIN32.RBOT WORM!
    SystemNTXSystemNT.exeAdded by the TROJ/PWSVB-EG TROJAN!
    SystemNTXSystemNT.exeAdded by the TROJ/PWSVB-EG WORM!
    systemrXd11host.exeAdded by the Troj/VB-GX Trojan!
    systemrXgedit.exeAdded by the Troj/StartPa-HC TROJAN!
    systemrXgedit.exeAdded by the Troj/AdClick-AQ TROJAN!
    SystemReg?PROCES.EXE??
    SystemRegXsvchost.exeAdded by the DEWIN.E VIRUS! Note - this is not the valid svchost.exe as described here
    SystemRegXWINREG.EXEAdded by the DEWIN.A VIRUS!
    SystemsXscchost.exeAdded by the Troj/Tofger-AK TROJAN! Note: This trojan file scchost.exe (Notice the difference in the spelling) is not the legitimate Windows Process. The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item.
    SystemsXsvch0st.exeAdded by the W32.MYDOOM.BI WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    SystemsXSystems.exeAdded by the TROJ/BANKBOA-A TROJAN!
    SystemsXitDDD.exeAdded by the Troj/Dloader-PP TROJAN!
    SystemsXitDDD.exeAdded by the Troj/VIXUP-G WORM!
    Systems BackupsXwindrives.exeAdded by the W32/AGOBOT-RB WORM!
    Systems RestartXspchost.exeAdded by a variant of the BANCOS.RF TROJAN!
    Systems RestartXslchost.exeAdded by the BANCOS.RF TROJAN!
    Systems RestartXRundll32.exe beem.dll, DllRegisterServerAdded by the Best_Search browser hijacker!
    Systems RestartXRundll32.exe snim.dll,DllRegisterServerAdded by the Startpage.I browser hijacker
    Systems RestartXRundll32.exe boln.dll,DllRegisterServerAdded by the StartPage.J TROJAN!
    Systems RestartXRundll32.exe zolk.dll, DllRegisterServerAdded by a variant of the StartPage.J TROJAN!
    Systems.exeUSystems.exeKeyboard Spectator - monitoring software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    systems.exeUSystems.exe KGBSpy is a commercial spyware program. It logs keystrokes, Web sites visited, and clipboard activity. It also has a screen capture logger and can be run automatically in a silent, undetectable mode.
    SystemSafeUSyssafe.exeSystem Safety Monitor - system monitoring tool with additional application firewalling
    SYSTEMSars32Xcsrss.exeAdded by the AHLEM.A VIRUS! Note - this is not the valid Client Server Runtime Subsystem (csrss.exe) process, which provides text window support, shutdown, and hard-error handling
    SystemSASXSystem32.exeAdded by the KWBOT.C VIRUS!
    SystemSearchXregedit.exe -s c:\ie.regInstalls a Seachxl.com browser page hijack
    SystemSearchXregedit.exe -s c:\sys.regInstalls a i--search.com browser page hijack
    SystemServiceXmsocfg.exePremium rate adult material dialer
    SystemServiceXqservice.exePremium rate adult material dialer
    SystemServiceXnavchk.exePremium rate adult material dialer
    SystemServiceXshman.exePremium rate adult material dialer
    SystemServiceUnsserver.exe NiceSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    SystemServiceXpokapoka62.exe EliteBar adware component
    SystemSettingfXTRUG.vbsAdded by the TRUG.B VIRUS!
    SystemSuite Task ManagerUMXTASK.EXEvcom (nee Ontrack) SystemSuite - PC maintenance and security. Use the program's configuration options to enable only the parts you want running all the time - such as Virusscanner Pro
    SystemTasksXfilez.exe, sexypicz.exe, loaded.exeAdult content dialler
    SystemToolsXkernels32.exeAdded by the VICSFRAM TROJAN!
    SystemtraXSystra.exeAdded by a variant of the LOVGATE WORM!
    SystemTraXCDPlay.EXEAdded by a variant of the LOVGATE WORM!
    SystemTrayXSystemTray.exe Added by the BIGFOOT TROJAN! Note - this is not the valid SystemTray ( SysTray.exe )
    SystemTrayXSysTray.exeAdded by the IRC.ALADINZ.P TROJAN! ** Note - Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file
    SystemTray or SysTrayUSysTray.ExeSYSTRAY.EXE - System Tray Services. Provides the Volume Control, PC Card Status, Power Management and other icons that reside in the System Tray (see here). SYSTRAY.EXE may be disabled if none of these services are required. It will launch as and when required if you later enable the icons. If you need these items they\'re available via Start -> Settings -> Control Panel
    SystemTraySDXSDSystemTray.exeMax Secure Spyware Detector, bogus "Spyware remover" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "spywaredetector.net"
    SystemTraySRXSRSystemTray.exeMax Secure Spyware Detector, bogus "Spyware remover" - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "spywaredetector.net"
    SystemUpdNSystemUpd.exeUpdater for Swapoo.com, a kind of Napster for games
    SystemWideHook for Windows NTX%WinHook32.exeAdded by the W32.Mydoom.AC WORM!
    SystemWizard SnifferUSniffer.exeSystemWizard for Win98/ME from SystemSoft - diagnoses and solves hardware and software problems on a PC
    systemyom UpdaterXsystemyom.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    SYSTEMZ PatchXSYSZ.exeAdded by the ALADINZ.P VIRUS!
    System_MessagesUpprsen.exeTerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like"
    SystesXjrdtifkkxbbsa.exeAdded by the W32/Rbot-ADC Worm!
    Systesms.exeXsystesms.exeAdded by a W32/Rbot-HI worm infection
    SystestNSystest.exeClean Space temp files cleaner
    systhreadXwinkernal.exeAdded by the LIAMED VIRUS!
    SysTimeXsystime.exe Troj/StartPa-CR , a CoolWebSearch parasite variant
    SystmesyXSystmesy.exeAdded by a W32/Rbot-KQ worm infection
    Systoan32Xsystoan.exeAdded as the result of an unidentified VIRUS!
    systr32?systr32.exe??
    systransX(Path of Trojan EXE)Added by the Troj/StartPa-GZ TROJAN!
    systrax?systrax.exe??
    SystrayXSystray_.ExeAdded by the KERGEZ.A VIRUS!
    SystrayXa.exe, b.exeWinfavorites adware
    SYSTRAYXUNMT.EXEAdded by a W32/Sdbot worm infection
    SYSTRAYXUNMT.EXE Proxy-Agent trojan variant
    SysTrayXSnnpapi.exeAdded by an unidentified TROJAN!
    SYSTRAYXUNMT.EXEAdded by the TROJ/DLOADER-LQ TROJAN!
    SystrayXw32explorer.exeAdded by the W32/Rbot-AJY WORM!
    SystrayXSteFanie.vbsAdded by the VBS.Stefan WORM! Note: Make sure you check the hyper link for VBS.Stefan, this one copies it's self to numerous dirves and folders.
    Systray driverXsystray.exeAdded by the IRC.MUTEBOT TROJAN! ** Note - this is not the legitimate systray.exe process.
    SystrayServicesXMsxpw.exeAdded by the CITOR VIRUS!
    SystryX(path to worm)Added by the AUTEX VIRUS!
    SYStryXspoolsvr.exeAdded by the SDBOT.GN WORM!
    SystrytX(path to worm)Added by the AUTEX VIRUS!
    systuneUsystune.exeAdded by AceSpy SPYWARE! ** Treat as an X if it wasn't intentionally installed.
    Systweak Memory OptimizerUmemtuneup.exePart of SysTweak Advanced System Optimizer
    sysuXsysu.exeDynamic Desktop Media adware - see here
    sysug32.exeXsysug32.exAdded by an unidentified TROJAN or WORM!
    SysupdXSysupd.exe VirtuMonde adware
    SysvupexXSysvupex.exeAdded by the MEDIAS VIRUS!
    SysW8Ucsta.exeClean Space - privacy and perfomance enhancer
    SYSWB6USYSWB6.exeWe-Blocker - gives parents the opportunity to monitor their children's Internet access and provide them with age-appropriate content, while filtering out sites that contain adult content
    SysWinXSysWin.exeAdded by a Backdoor.IrcContact trojan infection
    Syswin32Xsyswin32.exeAdded by a Backdoor.IrcContact trojan infection
    syswin32Xsyswin32.exe W32.SpyBot worm variant
    syswin32Xsyswin32.exeAdded by the SDBOT TROJAN!
    SyswindowXSyswindow.exeAdded by the COW VIRUS!
    SysWyXrundll32.exeAdded by the TROJ/LINEAGE-JH TROJAN! - NOTE: this file is found in the C:\Windows\System folder, and is not to be confused with the legitimate rundll32.exe file, always located in the Windows folder on Win 98 and ME systems, and in the Winnt\System32 or Windows\System32 folder in Windows XP and NT!
    sysX3Xsys22.exeAdded by the W32.RANTS.C WORM!
    SYS_CLEANXService.exeAdded by the FLOPCOPY VIRUS!
    Sys_RunXghost.exeAdded by the Troj/Lineage-N Trojan!
    sys_Runtt1Xexplorer.exeAdded by the LINEAGE-M TROJAN! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is found in the Program Files folder!
    SZMsgSvc.exeUSZMsgSvc.exeStopZilla! - pop-up killer
    tXxclean.exe Flashtrack.B adware
    T-DSL SpeedMgrNspeedmgr.exeT-Online ISP SpeedManager; shows upload and download speed; also checks for updates automatically.
    TaakcontroleUtaskmon.exeTask Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)
    TabaXstte.exeClickspring spyware
    TabletNTablet.exeLoads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL ALT DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds)
    tablet sYtablet sStarts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful)
    Tablet TaskXtabletsk32.exeAdded by the W32/Rbot-AJB WORM!
    TabletTipUtabtip.exeThe Microsoft Tablet PC Input Panel converts handwriting to text dynamically, and you can make corrections quickly and easily before inserting text.
    TabUserWYTabUserW.exeWacom pen tablet driver
    TAcelMgr?TAcelMgr.exeTOSHIBA Acceleration Utilities related - what does it do and is it required?
    TadNtad.exeFrom Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute
    TAG?tag.exe??
    Tahni DeskmateNTahni.exeTahni Deskmate - "Interactive cartoon character that lives on your Windows desktop"
    TakeMP3Xrundll32.exe MSA64CHK.dll, DllMostrar MatrixDialer related
    TAKSMGNXtaskmr.exeAdded by the W32/Rbot-AHS WORM!
    TalkingReminderNTALKINGREMINDER.EXETalking Reminder from Software River Solutions - talking calendar reminder
    talknow?talknow.exeCould it be related to this or something similar?
    Tango?Setup.exeTango Broadband access software. Is it required?
    TangoManager?TangoManager.exeTango Broadband access software. Is it required?
    TANG_INA_MOXAutoRun.batAdded by the W32.Filukin.A WORM!
    TapicfgXTapicfg.exe CoolWebSearch parasite related.
    TapisysXtss.exeTrojan.Win32.Small variant
    TapiTNAUTapiTNA.exeTelephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys
    TardisUTardis.exeTardis - time synchronization software
    TaskXtasker.exeAdded by the W32.Mydoom.R WORM!
    Task BarXTASKBAR.EXEAdded by the FRETHEM.J VIRUS!
    Task BarClient?TaskBarClient.exeResponsible for creating the System Tray icon and associated display system for theStarband satellite always on internet service
    Task BarSvr?TaskBarSvr.exePart of the Starband satellite always on internet service. Not included on the current system. What does it do and is it needed?
    Task CommanderXregsvc32.exeAdded by the W32/AGOBOT-RX WORM!
    Task DebuggerXsysdll.exeAdded by the W32/RBOT-CQ WORM!
    Task HelpXwualcts.exeAdded by a variant of the WIN32.RBOT WORM!
    Task ManagerXtaskmngr.exeAdded by a RBOT.Y worm infection
    Task ManagerXtaskman.exeAdded by the W32/FORBOT-T WORM!
    Task ManagerXprcview.exeAdded by the W32/AGOBOT-RT WORM!
    Task managerXTikTo.exeAdded by the RBOT.LV WORM!
    Task managerXtaskemngr.exeAdded by the W32/Rbot-AGA Worm!
    Task Monitoring ServiceXsvchost.exeAdded by the CONE.D VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32
    Task Scheduler EngineXschedsvc32.exeAdded by the W32/Rbot-ASJ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    task serviceXtaskservices.exeAdded by a variant of the WIN32.RBOT WORM!
    Task serviceXtaskmgs.exeAdded by a variant of the WIN32.RBOT WORM!
    TASK SETUPXtasksetup.exeAdded by the W32/RBOT-YR WORM!
    TaskbarNTaskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
    TaskBarNCTLTask.exeThe Creative Sound Blaster Audigy Taskbar is used to choose between different types of EAX Effects - not required in startup. NOTE: if you get a ctltask.exe error message while installing the Audigy drivers, see this Microsoft Knowledge Base article.
    Taskbar Display ControlsNRunDLL deskcp16.dll, QUICKRES_RUNDLLENTRYOnly appears in MSCONFIG if you have a Display Settings icon in the System Tray allowing resolution changes on the fly. Can also be disabled under Control Panel -> Display -> Settings -> Advanced -> General. Also appears if you have Win95 with the QuickRes "Powertoy" installed
    Taskbar ServiceXtaskbar.svcUnidentified adware
    Taskbar SystemXtasksys.exeAdded by a variant of the W32/SDBOT WORM!
    Taskbell.exeXRund1.exeAdded as a resukt of the YIPID trojan
    TaskListXtasklist32.exeAdded by the TROJ/BANCOS-DX TROJAN!
    TaskManXrundll32.exeAdded by the DVLDR VIRUS! Note - this is not the valid "rundll32.exe" as it\'s in the Windows\Fonts directory
    taskmanagerXtaskmgr.comAdded by the BEREB VIRUS!
    taskmanagerXtaskmanager.exeAdded by the W32/AGOBOT-TF WORM!
    taskmangerXtaskmanger.exeAdded by a variant of the WIN32.RBOT WORM!
    TaskmgoX(path to file)Added by the TROJ/BANCBAN-T TROJAN!
    TaskmgrXTaskmgr.exeSystem1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory
    TaskmgrXtskmgr32.exeHomepage hi-jacker
    taskmgrXtaskmgr.exeAdded by the Startpage.G hijacker - NOTE: this is NOT the Windows Task Manager file!
    TaskmgrXsystem.exeAdded by the TROJ_PAKES.G TROJAN!
    taskmgr.exeNtaskmgr.exeWindows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut
    taskmgr.exeXpaint.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    taskmgr.exeXpaintms.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    taskmgr.exeXmirc.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    TASKMGRUXTASKMGRU.EXEHijacker - recognized by Kaspersky antivirus as Trojan.Win32.Agent.cx
    taskmngrX[path] msnve.exe [path] task.exeAdded by the FLOOD-EK TROJAN!
    taskmngr lptt01 or taskmngr ml097eXtaskmngr.exeVariant of the RapidBlaster parasite (in a "Taskmngr" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    TaskMonXtaskmon.exeAdded by the MYDOOM.A or MYDOOM.J WORMS! Note - this is not the valid Win98/Me file of the same name which resides in C:\Windows as this version resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP). It is not normally on a WinXP system
    Taskmon driverXwinampa.exeAdded by the LOONY-I TROJAN
    taskmonetaskmone.exeAdded by the TROJ/SINGU-S TROJAN!
    TaskMonitorUtaskmon.exeThe Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)
    TaskMrgXschwoch.exeAdded by a Troj/LDPinch-Y trojan infection
    taskmrg.exeXtaskimg.exeAdded by the TROJ/DLOADER-QZ TROJAN!
    taskopen.exeXtaskopen.exeAdded by the HackTool.Win32.Hidd.c TROJAN!
    TaskPlusNTASKPLUS0.EXE, TASKPL~1.EXETask and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
    TaskRegX(random filename)Added by the CBLAD VIRUS! <filename.exe> is the full path and name of the infected file
    TaskS managerXtaskmgrs.exeAdded by the AGOBOT.QU WORM!
    TaskschdXTRAYWND.EXEAdded by the LITMUS.002 VIRUS!
    TaskSchedulerUTaskSch.exe ProSeries accounting software related
    taskswitchNtaskswitch.exeALT TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen
    tasksysXtasksys.vbsAdded by the BYRON VIRUS!
    TasktrayNCTLTray.exeInstalled with the Sound Blaster Audigy range of soundcards. Allows you to set EAX effects or equalizer settings for the Sound Blaster Audigy from a systray icon.  Also allows you to launch the Taskbar via right-click -> Show Taskbar. The tasktray can be accessed via Start -> Programs -> Creative -> Sound Blaster Audigy -> Taskbar
    TasmgrXTaskmgr.batAdded by the VBS.Ypsan.G WORM!
    tatXtatss.exe Delfin_Promulgate adware variant
    Tau monitorYTaumon.exe"Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system."
    TAudEffect?TAudEff.exeTOSHIBA Notebook related - what does it do and is it required?
    TB2PROEXEUtb2start.exeTimbuktu Pro - remote desktop access software
    TBC ProUtbcpro.exeTitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus
    TBC.exeUTbc.exe TitleBarClock software
    tbctrayNtbctray.exeProvides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
    TBLFUNCYtblmouse.exeAiptek HyperPen driver
    tbonXtbon.exe BestOffers adware
    TBPanelUTBPanel.exeConfiguration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
    TBPSXTBPS.exeWebSearch toolbar, HuntBar parasite variant
    TBTrayNtbtray.exeVLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start -> Settings -> Control Panel
    TB_setup?TB_ANI~1.EXE??
    TB_setupXtb_setup.exeHuntBar parasite toolbar installer
    tcactiveYtca.exePart of The Cleaner from MooSoft - stops virus trojans before they can do any damage
    TCASUTIEXENTCASUTI.exeAssociated with the 3COM diagnostic module (3COM NIC Doctor). No further information is available
    TCAUDIAG -off or TCASUTIEXENtcaudiag.exeAssociated with the 3COM diagnostic module (3COM NIC Doctor).  No further information is available
    TCDPbtn?TCDPbtn.exeFound on a Toshiba laptop
    TCDPlay?TCDPlay.drvFound on a Toshiba laptop - sounds like the driver for the CD-ROM but why doesn't it use the standard Windows drivers - any comments?
    TClockUTCLOCK.EXEKazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start -> Programs
    TClockExUTCLOCKEX.EXEPuts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks
    tcmonitorUtcm.exePart of The Cleaner from MooSoft - warns of changes to the registry
    TCOYFReminderUtcoyftray.exe My_ParenTime Fertility Planner Reminder. (The Calendar provides a quick overview of the status of your fertility.)
    Tcp Application ManagerXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Tcp Application ManagerXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    tcp checkerXtcpcheck.exeAdded by the TROJ/VBBOT-A TROJAN!
    TCP MonitoringXLanNSvc.exeAdded by the RANDEX.AAS VIRUS!
    tcpippuitcpippui.exeAdded by the W32/Rbot-APS WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    tcpippui32Xtcpippui32.exeAdded by the W32/RBOT-ART WORM!
    TCPXP UpdateXtcpxp.exeAdded by the W32/RBOT-UL WORM!
    tcupdaterXtcupdater.exeTopconverting.com/180Search adware updater
    TDispVol?TDispVol.exe??
    TDKSTARTUTDKSTART.EXESets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW.
    TDKTASKNTDKTASK.EXETaskbar utility for a "control panel" for a CD-RW
    TDockNUndock?N/AFound on a Toshiba laptop - for use with a docking station?
    TDS3UTDS-3.exeDiamondCS TDS3 antitrojan . Can be used to scan on demand, but required in startup if you prefer real time protection
    TDspOff?Tdspoff.exeFound on a Toshiba laptop
    Teach In BoxNteachbox.exeTutoring program that comes with a SystemAX Computer
    Tech-In-A-BoxYtechbox.exeTech-in-a-Box "provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running"
    Telechips,MassUpatch.exeRemovable Disk Driver for the Muro MP3 player
    Telemeter 3.0Ntelemeter3.exeInternet connection bandwidth meter from a user ISP
    TelepathYtelepath.exeDrivers for the WinModem versions of the US Robotics "Telepath" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    Telnet24X(Random file name)Added by the W32/Rbot-ARD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    TELUS Security serviceYfreedom.exe Freedom Internet Security, provided by TELUS Communications Inc
    TempComX(random name).comAdded by the TRAXG VIRUS!
    TempComX(random file name)Added by the W32/Traxg-E WORM! Note: May be found in any of the following folders: \fonts, \help, \system, \temp, \web
    TempRemoveUterminator.exeCB Predictor by Decisioneering
    tempxXtempx.exeAdded by the TEMPEX.A TROJAN!
    Tencent QQXRund1132.exe qq.dll, Rundll32Added as the result of the QQPASS.F VIRUS!
    Terminal UpdateXbiosefui.exeAdded by the Troj/PPdoor-O TROJAN!
    Terminate PopupXFPUK.exeZPU.exeFree Popup Killer - foistware proven to install the Regsvc32 homepage hijacker.  Also see here
    TEscKeyUTEscKey.exeToshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
    Tesco.netNrundll32 [path] RyDial.dll, QuickStart Tesco.net dial-up ISP software - not required
    Tesla?TESLA.EXE??
    testXi love you.exeAdded by the Troj/Singu-T TROJAN!
    Testing 123Xmsdata.datAdded by the W32.Nits.A WORM!
    testit.exeXtestit.exe ISTbar/XXXToolbar adware component
    TExBUtil Registry?TExBUtil.exe??
    TextAloudNTextAloudMP3.exeTextAloud MP3 - convert text into spoken words and MP3s
    Textbridge Instant Access OCRNtelepath.exeTextBridge from Scansoft. OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs
    TEXTCONVXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    TEXTCONVXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon process winlogon.exe process. It should not appear in Msconfig/Startup!
    TEXTCONVXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    TFncKyUTFncky.exeDeals with the <Fn> - <Function> key combinations on a Toshiba laptop
    TFNF5UTFNF5.exeToshiba Hotkey Utility for Display Devices. By pressing <FN> <F5>, a window appears showing the displays that can be chosen – LCD, LCD CRT, CRT, TV
    tfswctrlYtfswctrl.exeDrive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
    TFTP###Xtftp###Added by the SPYBOT VIRUS! where # can be any number
    TFunckeyUTFuncKey.exeDeals with the <Fn> - <Function> key combinations on a Toshiba laptop
    TgAddServerNtgfix.exeSoftware from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove, Charter offer some uninstallation instructions involving a registry patch that you may be able to modify for your proivder or try here
    tgbcdeXmodule32.exeAdded by the WIN32.REIGN.R TROJAN!
    TgcmdUtgcmd.exeThis part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
    tgcmdprovidersbcUtgcmd.exeThis part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. "tgcmdprovidersbc" is for SBC Yahoo DSL. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
    TGCMGN??Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work
    TGDC IE PluginXtgdc.exeShopForGood spyware - see here
    tgkillXtgkill.exeComcast (the cable folks who are replacing @home in some parts of the USA) have struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This is "beta" at present and was made available to download by mistake at present. Remove via Start -> Settings -> Add/Remove Programs
    TgsetsiteUtgfix.exeSee TgAddserver and Tgcmd above. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation
    ThdetrfNthdetr32.exeAppears to be related to Lycos advertising
    ThEXwind0s.exeAdded by an unidentified WORM or TROJAN!
    The Easy Bee's HiveUATCEgSvr.exeThe Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence
    The EthernetXethernet.exeAdded by a variant of the W32/SDBOT WORM!
    The IntranetXintranet.exeAdded by a variant of the W32/SDBOT WORM!
    TheMainStart?N/A??
    THGuardUTH_Guard.exeResident memory scanning for TrojanHunter
    THGuardUTHGuard.exeResident memory scanning for TrojanHunter
    This is a virus, please delete itXbigbadvirus.exeAdded by the RANDEX.F VIRUS!
    THOTKEYUTHotkey.exeAssociated with the Fn keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen
    ThpSrv?thpsrvTOSHIBA HDD Protection related - what does it do and is it required?
    ThreadedXintcp32.exeAdded by the RANDEX.UG VIRUS!
    ThrustTSRUTMTMTSR.exeThrustmaster Thrustmapper. "The Thrustmapper - t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly"
    Thumbs Plus X.XXthmbplusXX.exeAdded by the W32/Agobot-AAF WORM! (XX is a combination of random digit and character.)
    TI WLANUTIWLANCu.exe Texas_Instruments TI wireless LAN products
    tibs3Xtibs3.exePremium rate adult content dialer - see here
    tibs5Xtibs5.exePremium rate adult content dialer - see here
    TigerXShine.exeAdded by the HAPPYLOW or W32/Nishe-A VIRUS!
    TiKLUtikl.exe TinyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!
    Time ManagerXTimeManager.exeAdded by the W32/Mytob-BV WORM!
    Time Zone SynchronizationXwscript zshell.jsAdded by the NETDEX-A VIRUS!
    TimeCalendarNtc.exeTimeCalender - calendar reminder
    TimeCalendarUTC.exe TimeCalendar digital planner
    Timed Backups Manager StartupNBACKTIME.EXEBackup Plus - backup software
    TimeLeftUTimeLeft.exe TimeLeft is a countdown, reminder, clock, alarm clock, stopwatch, timer, sticker and time synchronization utility which uses Winamp skins to show digits and text.
    Timemanager.exeUTimemanager.exe Time_Manager will let you track billable and non-billable time by customer, by category and by associate and then integrate directly to our custom billing package.
    TimeOnlineNTIMEONLINE.EXELightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
    TIMERXTIMER.EXEAdded by the TIMESE.AG VIRUS!
    TimerXcomm.exeAdded by the TROJ/BDOOR-IP TROJAN!
    TimerXtimed.exeAdded by the Troj/Bdoor-LV TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    TimeServiceXtrun.exeAdded by the TlfLic-A premium rate adult content dialer.
    TimeSink Add ClientXTSADBOT.EXE TimeSink Ad Client - advertising spyware
    timessquareXtimessquare.exeReported as Trojan.Win32.StartPage.aw by Kaspersky Anti-Virus.
    TimeSyncAppXTimeSynchronize.exe DealHelper adware
    TimeUpNTimeup.exeTimeUp - internet online timer
    TimezoneUTimeZone.exeMicrosoft Daylight Saving Time Update Utility - see here
    TINTSETPNTINTSETP.EXEPart of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
    Tiny AVXfooding.exeAdded by the W32.Netsky.I WORM!
    Tiny Personal FirewallYpersfw.exeTiny Personal Firewall
    tinySpellUtinyspell.exeTinyspell - "allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard"
    TiomanExeUTioman.ExeAgate Tioman - warm and hot swap removable bay device manager for IBM laptops
    TipsNmousetips.exeSuggests tips on using your mouse
    TiTleBarClockUTiTleBarClock.exeTitleBarClock displays the day/month/time and free physical RAM on the right hand side of an open window, replacing the system tray clock at startup
    TivoliNLCFEP.EXETivoli ‘TME’ System Tray icon - "\'lcfep\' is the program that displays statistics about the Endpoint. Apparently stopping/removing this process has no impact on the Endpoint itself which will continue to function normally"
    TIxDSLUtidslmon.exeActiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start -> Programs
    TizzleTalkXTizzleTalk.exe TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messengers. Bundles adware, hence not recommended. From their EULA : "As a result of installing the Company's Software, you will see occasional banner ads, pop-up or pop-under ads, or other types of ads selected based on your online activities .../... Occasionally, we may automatically or through other remote means, update, upgrade, patch or uninstall the Company's Software, including the Company's advertising-supported software, without further notice to you. These upgrades also may include installation of additional applications from the Company as well as third party applications."
    tjstartupXsvchost.exeAdded by the CURDEAL TROJAN! **Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!
    tjstartupX(path to file)Added by the BACKDOOR.TJSERV.C TROJAN!
    TkBell.ExeNtkbell.exeApplication Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBell.ExeNevntsvc.exeApplication Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBell.ExeNrealsched.exeApplication Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBellExeNevntsvc.exeApplication Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBellExeNrealsched.exeApplication Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBellExeNtkbell.exeApplication Scheduler installed along with RealOne_Player Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
    TkBellExeeXrealschd.exeAdded by an unidentified downloader TROJAN!
    TkNetDriver MonitorXlexbce.exeAdded by the W32/SDBOT-ADF WORM!
    tkonnectNTKONNECT.EXEDialer for the Tiscali internet service provider. Available as a desktop shortcut
    tlcXupdate13.js, update911.jsHijacker installer
    TlcR?avp.exe??
    TLogonPathUtb2logon.exeTimbuktu Pro - remote desktop access software
    TM Outbreak AgentUTMOAgent.exeTrend Micro Internet Security anti-virus software virus outbreak warnings. Notifies users of virus outbreaks and offers to update the scanner
    TMA distributionUcfinst.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
    tmaxXpupdate.exeAdware pop-up generator
    tmchookXtmchook.exeDetected by Kaspersky as the TrojanDownloader.Win32.VB.aa VIRUS!
    TMEEJME?TMEEJME.EXEFound in a Toshiba\TME3 directory. Toshiba Mobile Extension related?
    TMERzCtl?TMERzCtl.EXEFound in a Toshiba\TME3 directory. Toshiba Mobile Extension related?
    TMESBSUTMESBS21.exeToshiba Mobile Extension Selectable Bay Service for WinXP - support for docking stations. Not required if you don't use a docking station
    TMESBS32?TMESBS32.EXEFound in a Toshiba\TME3 directory. Toshiba Mobile Extension related?
    TMESRV31NTMESRV31.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
    TMExLogonUTMESRV.EXEToshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station
    Tmmkb?Tmmkysvr.exeToshiba multi-media keyboard software - possibly including creating keyboard shortcuts?
    TmNetDriver MonitorXexbce.exeAdded by the W32/Sdbot-ABR WORM!
    Tmntsrv32XTmntsrv32.exeHijacker, detected by Norton antivirus as Trojan.StartPage.O
    TMOUSEUtmouse.exeComponent of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint
    tmproxyYtmproxy.exeTrend Micro PC-cillin 2003 antivirus software
    TMTMTSRNTMTMTST.exeInstalled with Thrustmaster game controllers. It launches the Thrustmapper utility. Not required if you install the "driver only" from Thrustmaster website
    TNTClkUTNTCLK.exeOverclocking program for TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked to let it run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job
    ToADiMon.exeUToADiMon.exeT-Online ISP software connection assistant
    Tok-CirrhatusXIDTemplate.exeAdded by the RONTOKBRO.A WORM!
    Tok-CirrhatusXsmss.exeAdded by the RONTOKBRO.B WORM! - NOTE - this file is placed in the UserProfile%\Application Data folder, and should NOT be confused with the legitimate Windows smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Tok-CirrhatusX[path to file]Added by W32/Brontok-F WORM!
    TomcatStartup?hpbpsttp.exeApache Tomcat web server, part of HP LaserJet "Printer Tools" software - what does it do and is it required?
    Tommorrow?tomorrow.exe??
    ToPassSrv?Pktopass.exeRelated to Caere Pagekeeper scanning software (now taken over by Scansoft), Disabling is known to cause problems
    TopDeskUTopDesk.exeTopDesk; puts an icon in your system tray that when clicked upon, opens a pop-up menu that gives instant access to all of your desktop programs without having to minimize, resize, move or close other programs or files.
    ToPicks StarterXIdhost.exeToPicks parasite related
    topmoxieXJavaRun.exeMarketing software from TopMoxie
    TopSearchXTopSearch.exe TopSearch adware variant
    tor anonymous proxyXtor32.exeAdded by the W32/Sdbot-ADR WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Torjan ProgramXservices.exeAdded by the W32.Autex.C WORM! Note: This is not the legitimate Windows process (Which is always found in the System32 folder). The legitimate Windows process should not be seen in Msconfig or as a Startup item. This worm file is found in the Windows or Winnt folder, be sure to check the link for this one, it makes 11 other copies of it's self all with different file names and in four different folders!
    Torjan ProgramXsmss.exeAdded by the PWSteal.Wowcraft.B TROJAN! Note: This is not the legitimate Windows process smss.exe (Which is always found in the System32 folder.) This trojan file (smss.exe) is found in the Windows or Winnt folder.
    TOSCDSPD?toscdspd.exeToshiba laptop related
    Toshiba FanYfan.exeToshiba untilty to keep the fan on a laptop running if they fail to detect there is too much heat
    Toshiba Key StateUKEYSTATE.EXEDisplays an icon in the System Tray indicating the state of the CAPS LOCK key. Can be handy on (e.g., Toshiba) laptops which do not have a Caps Lock indicator light. Available via Start -> Programs
    ToshibaPingerNpinger.exePinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notification. Disabling instructions here
    TOSHIBSUUToshibsu.exeReduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly
    TosHKCWUTosHKCW.exeToshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed)
    TosMemYtosmem.exeToshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem
    TosRotationUTRot.exeTOSHIBA Rotation Utility - allows users to rotate a notebook's screen image 180 degrees in order to share information on the screen with others seated across a table or desk
    Total SecurityYTScutyNT.exeOmniquad Total_Security
    TotalSecurityUpdateYTSAtUdt.exeOmniquad Total_Security updater
    TotRecSchedUTotRecSched.exeScheduler for Total_Recorder from High Criteria Inc - audio capture utility
    ToUcamVPropertyYVProperty.exePhilips Web Camera model name pcvc740k, ToUcam driver configuration tray icon.
    Touch ManagerUWinLED.exeDell keyboard utility. Disabling can result in loss of screen saver and power saver functionality
    TouchEDUTouchED.exeTouchPad On/Off Utility on a Toshiba laptop
    tourNregedit ..tour.regEdits registry values to keep the WinMe tour in Task Scheduler
    TourNwincool.exeComponent of WinME that's annoying as hell. Pop\'s up a prompt to play the C:\WINDOWS\Application Data\Microsoft\INTROCONTENT.HTA that plays a full screen version of the WinME product preview Windows Media video file that cannot be stopped to my knowledge until it finishes. That prompt will keep popping up after an install/reinstall of WinME until you give in and watch the thing. It also puts a task scheduler entry to run that annoying thing every 30 minutes, and don't bother deleting that entry, Windows puts it right back. Not only should you disable it from running, you should delete the thing altogether, as it, somehow can re-enable itself. Apparently you can try setting the file to read only
    tourpathNregedit /s [path] tour.regEdits registry values to keep the Win 2000 "tour" in Task Scheduler
    TP4EXUtp4ex.exeAdds accessibility options for an IBM TrackPoint
    tp4mon?tp4mon.exeMay be IBM Thinkpad mouse/trackpoint related, if so is it required?
    tp4servUtp4serv.exeSupports the "pointer stick" on Thinkpads in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
    TP98TRAY or TPTRAY?TP98TRAY.EXEIBM Thinkpad related utility. What does it do and is it required?
    TP98UTILNTP98.EXEIBM Thinkpad feature setup & configuration utility
    tpcupdaterXupdatetc.exeAdware, probably 180Solutions related
    TpHotKeyUTPHKMGR.EXEActivates "ThinkPad Help" when the "Thinkpad key" is pressed on an IBM ThinkPad laptop. Also activates the audio buttons (volume up/down, mute) on models such as the Thinkpad T30
    TPKMAPHELPER?TpKmapAp.exeIBM ThinkPad related - what does it do and is it required?
    TpKmapMnUTpKmapMn.exeCreate Keyboard combinations for special Thinkpad buttons when using an external keyboard, e.g. "Ctrl-arrow up" for "volume up". Only required when using an external keyboard. Available via Start -> Programs
    TPNFNTPTray.exeTouchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel
    tpopserviceUtpopservice.exeDirecWay two-way satellite internet service enhanced POP proxy server for email
    TPP Auto LoaderUTppaldr.exeInstalled with DataStor's (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives. System tray icon allowing the user to disconnect the external drive without an error message being displayed
    TprtrayUTprtray.exeDisplays the Power icon in the System Tray on a Toshiba laptop
    TpShocksYTpShocks.exeResponsible for controlling the IBM Hard Drive Active Protection system found on newer models of IBM Thinkpads, including T41, T42, X40, R50, and R51. The Hard Drive Active Protection system is based on a technology similar to that used in automobiles to deploy airbags on contact: An accelorometer on the motherboard detects physical acceleration--such as when the notebook falls--and in response the system temporarily parks the hard drive's read/write head until stability returns
    TPSmain?TPSMain.exeToshiba related; not sure whether required
    TPTrayNTPTray.exeTouchpad configuration tray icon for Toshiba laptops. Available via Start -> Settings -> Control Panel
    TPwrMgr?TPwrMgr.exeFound on a Toshiba laptop. Related to power management?
    TPWRTRAYYTpwrtray.exeToshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use
    tqrecvUtqrecv.exeTellique satellite broadcast reception software
    TracelessNlaunch.exeTraceless 2003 - clear your cookies, temp directories and browser history with a click of a button. It also clears the recent documents and the IE drop down auto complete box
    Track4WinMonitorUSTMonitor.exe Track4Win is a spyware program that takes screenshots and logs user activity such as URLs and currently running processes. It uploads the logs and screenshots to a preconfigured server. If you didn't install this yourself remove it
    Tracker?Tracker.exePossibly associated with My Deluxe Invoices program
    TrackpointSrvUdaemon.exe, tp4serv.exeSupports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
    TrackPointSrvUtp4mon.exeSupports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
    Tracks Eraser or Tracks Eraser ProUte.exeTracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity" 
    TraniconUtranicon.exeA Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent
    TransparentUTransparentW.exe, TransparentD.exe, TransparentB.exeUtility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here
    TransparentIconsUtranicon.exeA Tweak-XP component (only in the registered version), makes Desktop icons transparent. Can be enabled/disabled via Tweak-XP -> System File Tweaks -> Windows Tweaks -> Desktop Tweaks -> Make Desktop Icons Transparent
    TransTaskUtranstask.exe Tweak-XP_Pro related; feature to make the Windows XP taskbar transparent
    TrashgrdUTRASHGRD.EXEPart of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin
    Tray Pilot LiteUTrayPlt.exe Tray_Pilot allows you to hide the System Tray window.
    Tray TemperatureNWeatherbug.exeWeatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
    TraybarXlsass.exeAdded by the W32.Mydoom.L WORM!
    traydate.exeUTRAYDATE.EXEDisplays the date as well as the time in the System Tray. Available from TUCOWS
    TrayManagerUTrayman.exeTrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded)
    TraymonUtraymon.exeNetropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news
    TraySantaCruzNtbctray.exeProvides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start -> Settings -> Control Panel
    TrayServerNTrayServer.exeFor monitoring tray icons
    TrayXXwinppr32.exeAdded by the SOBIG.F VIRUS!
    tray_helperNtray_helper.exeTray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder
    Trend Micro Anti-SpywareUTmas.exe Trend_Micro_Anti-Spyware - required when using real time monitoring
    TrendMicro AntivirusYAveagent.exeVirus scanner
    TrendMicro OfficeScan NTYTMLISTEN.EXEVirus scanner
    TricklerXfsg.exe Gator adware
    TricklerXfsg_****.exe (* = random digit) Gator adware
    TricklerXfsg-ag_****.exe (* = random digit) Gator adware
    TricklerXgain_trickler_****.exe (* = random digit) Gator adware
    TridentTVIconYtvicon.exeTrident Microsystems, Inc Display driver
    TridTray?TridTray.exeSystem Tray access to Trident 4DWave soundcards?
    TridTray?TridTray.exeSystem Tray access to Trident 4DWave soundcards?
    TrillianUtrillian.exePart of Trillian ICR client
    trirotYtrirot.exeTrident Microsystems 3D video driver
    Trojancheck 6 GuardUtcguard.exe TrojanCheck anti-trojan software
    TrojanScannerUTrjscan.exeTrojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed
    TrojanShieldUInit.exe TrojanShield anti-hacker/anti-trojan software
    TrojanShield ProtectorUPort.exe TrojanShield anti-hacker/anti-trojan software
    True Internet Color IconUinternetcolor.exePart of Colorific & 3Deep from LightSurf Technologies (nee E-Color). "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"
    TrueFontsXfonts.htaBrowser hijacker - redirecting to Hugesearch.net
    TrueSync LauncherNtstool.exeStarfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services
    TrueVectorYVSMON.EXEEven if you don't have ZoneAlarm or ZoneAlarm Pro run at start-up you do need this
    trustras.exe?trustras.exeTrust ADSL modem related - is it required?
    TrustyHound-TSXTrustyHound-TS.exe TrustyHound spyware
    tsaXtsm.exe TargetSaver adware
    Tsa2Xtsm2.exe TargetSaver adware
    Tsa2Xtsm2.exe TargetSaver adware
    TsAdbotXTSADBOT.EXE TimeSink Ad Client - advertising spyware
    TSBxLogon?TMESBS2.EXEFound on a Toshiba laptop. May be related to TMESBS?
    TSE_PLUtilUPLBkMon.exe Prolific USB Flash Disk Log On Application
    Tsk Mng HlpXwins32.exeAdded by the W32/AGOBOT-JB WORM!
    tskdbgXtskdbg.exeAdded by the FLOOD.E VIRUS!
    TSkrMain?TSkrMain.exeTOSHIBA Acceleration Utilities related - what does it do and is it required?
    TslXtsl.exe Uploader-R adware
    Tsl2Xtsl2.exe TargetSaver adware
    TSMsgerNTSMsger.exeEpson scannner software - required for "one-touch" operation. Can be launched manually
    TSPower?spower.drvFound on a Toshiba laptop. Related to power management?
    TSService?NSSERVICE.EXE??
    tsvcinXn20050308.EXEAdware downloader/installer, Delphin_Media_Viewer related - also detected as the DELMED.A TROJAN!
    tsyssmon?tsyssmon.exeFound in a Toshiba\sysstability directory
    TSystemX(original Trojan filename)Added by the Troj/Nsys-A Trojan!
    ttaaXtata.exeAdded by the TROJ/LINEAGE-T TROJAN!
    ttasq?ttasq.exe??
    TTS SyncXtesttts.exeAdded by the SDBOT.BVA WORM!
    ttuptXttupt.exeeZula TopText adware component
    Tukati?TukatiRedistributor.exeTukati Digital Content Distribution. Is it required?
    tunebite.exeNtunebite.exe Tunebite is an application that allows you to make unprotected copies of copy-protected music files by recording them while they are being played. Can be launched from it's Start Menu shortcut.
    TuneUp MemOptimizerUmemoptimizer.exePart of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboard
    TurboExplorerUTE.exeWeb accelerator - "TurboExplorer® 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer® 4/5 to achieve a faster and more effective approach to the internet". Only needed if you find it improves web browsing
    TurboLaunchUTlaunch.exe TurboLaunch is a tool-bar style application that can be set up to run many programs and perform certain pre-programmed actions.
    TurboMemoryChargerUturbomemorycharger.exeSome users swear by memory management utilities such as Turbo Memory Charger but others say you don't need them - especially if you have Win98 or WinME. See this article and make up your own mind
    TurboNoteNtbnote.exePost-It's on your desktop. Available via Start -> Programs
    TurboTopUTurboTop.exeTurboTop - make any window "Always on top"
    TV MediaXTvm.exeCleverIEHooker hijacker variant
    TV SchedulerUTVSCHL.EXEProLink PlayTVpro TV tuner software scheduler
    TVMDXtvmd.exeTotal Velocity - "Secure commerce company that enables the ‘checkout’ process for our customers in order to safely and securely purchase our award winning software". Autointsalling spyware
    TvNowUTvNow.exeApplication supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts).
    Tvs?TvsTray.exeTOSHIBA Notebook related - what does it do and is it required?
    tvs_bXtvs_b.exe BroadcastPC adware variant
    tvs_bXtvs_ln.exe BroadcastPC adware variant
    tvs_reXtvs_re_inst.exe BroadcastPC adware variant
    TVTMDXTVTMD.EXETotal Velocity variant - autoinstalling spyware
    TVWakeupNtvwakeup.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    Tvwatch?tvwatch.exeAssociated with the TV-oOut option on Asus AGP or Intel graphics cards. Is it required?
    Twain imageXmmp32.exe DailyWinner adware related
    TWarmBay?N/AFound on a Toshiba laptop. Related to hotswap bay management?
    TWarnMsgUtwarnmsg.exeToshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops
    TWBbtn?N/AFound on a Toshiba laptop
    TWBrowse?TWBrowse.drvFound on a Toshiba laptop. Possibly related to TWAIN drivers (ie, scanners, etc) - see this?
    Tweak Manager?WinManager.ExeWinGuides Tweak Manager. Is this required for the live updates feature and/or if settings are changed?
    Tweak UIUrundll32.exe tweakui.cpl, tweakmeupRestores settings that can\'t be retained if you have Microsoft\'s Tweak UI "powertoy" installed
    Tweak UIUrundll32.exe tweakui.cpl, tweaklogonAutomatically logs you on if you have Microsoft\'s Tweak UI "powertoy" installed
    Tweak UIXRunDLL32 tweakUI.DLL, TWEAKUI /tweakmeupAdded by the SUBWOOFER VIRUS! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup"
    Tweak UI 1.33 deutschURUNDLL32.EXE TWEAKUI.CPL, TweakMeUpRestores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed - German version
    Tweak-MeUTWEAK-ME.exe3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here
    Tweak-xpUTweak-xp.exeMain program for Tweak-XP - a WinXP tweaking utility
    TweakDUNUtweakdun.exeUtility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets
    Tweaki4PUUtwksup.exe "Tweaki puts several Windows utilities into one easy to use program while adding hundreds of additional tweaks not found in other system tweakers"
    tweakico?tweakico.exeMay be a HP program to control their icons?
    TweakMASTERUTMTray.exe TweakMASTER Internet Optimizer
    twisterUtwister.exeTwister "AntiTrojanVirus"
    TwkSCardSrvNSCardS32.ExeUsed with Towitoko SmartCard Readers for card recognition
    twunk serviceXtwunk16.exeAdded by the RBOT.BAT WORM!
    twunk_32Xtwunk_32.exeAdded by the BLACKMAL.C WORM! - This malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    Twunk_64Xtwunk_64.exeSystem1060 homepage hi-jacker. Note - this is not a Windows file and is found in a Windows\System\1060 directory
    tyack driveXtyack.pifAdded by the W32/Rbot-AMT WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    type32Ntype32.exeFor MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them
    TypingSatelliteNKBOOST.exeTyping Master 2002 background utility that collects typing errors and builds up customised typing lessons for your needs. Available via Start -> Programs
    UateXoocs.exe PurityScan/Clickspring adware
    UBSShellUUBSShell.exeUBS (United Bank of Switzerland) banking software
    UCmore XP - The Search AcceleratorUrundll32.exe UCMTSAIE.dll, DllShowTBUCmore toolbar - search accelerator
    UC_SMBNucstart.exePart of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
    uc_startNucstartup.exeAuto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc
    UD AgentUUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
    Ueproc32UUEPROC32.exePart of Norton Utilities - most likely associated with the Unerase Wizard in older versions
    UFD Monitor9382?ufdlmon.exePart of USB Flashdisk software - what does it do and is it required?
    UFD Utility9382?UFDTool.exePart of USB Flashdisk software - what does it do and is it required?
    ugon?aockstrs.exe??
    UidlerNUidler.exeUniloc Titlewave Browser used with some shareware
    UIWatcherNUIWatcher.exeAshampoo Uninstaller Suite - installation watcher. Available via Start -> Programs
    ujmXnm32.exeAdded by the Keylogger.Stranget KEYLOGGER! Note: This keylogger file is found in the Windows\fyt or Winnt\fyt folder.
    UKVideo2Xukvideo2.exeAdult content dialler
    Ulead Photo Express x.0 CalendarNcalcheck.exeUlead Calendar Checker - part of Ulead Photo Express, where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually. See here for disabling instructions
    UltimateZip Quick StartNuzqkst.exeUltimateZip - file compression utility
    Ultra Hal Assistant 4.5 StartupNHalAsst.exeZabaware Ultra Hal Assistant - artificial intelligence conversation simulator. It is capable of being your digital secretary and companion
    UltraDVDMon?DVDMon.exe UltraDVD DVD player software - is it required?
    UlubioneXsys****.exe Ulubione adware component
    UMAX VistaAccessNvsaccess.exeVistaAccess gives you quick and easy access to scanning functions right from your desktop
    UMonitUumonit.exeAlerts when USB device is plugged in
    umxagentYumxagent.exeTiny Personal Firewall V4 - main engine
    umxldraYumxldra.exeUser mode executive module DLL loader - part of Tiny Personal Firewall V4
    UMXLDRWYUMXLDRW.exeTiny Personal Firewall (pre V4)
    un32infoXun32info.ExeAdded by a CRYPTER.A trojan infection
    UNERIXyujixit.exeAdded by the SDBOT.BOO WORM!
    UnHackMe MonitorUhackmon.exe UnHackMe allows you to detect and remove a new generation of 'invisible' Trojan programs called "rootkits".
    uninstalXregsvr32 /u /s image.dll CoolWebSearch parasite related.
    Uninstall####Xupd.exeAdult content based screen saver where #### can be any number
    UninstallAbilityNuability.exeUninstallAbility uninstaller
    UninstallHLXPreUninstallHL.exe LinkReplacer/FFinder adware component
    UninstallQLXPreUninstallQL.exe LinkReplacer/FFinder adware component
    Uninstall_TBPSXTBuninst.exe /removeWebSearch toolbar related, HuntBar parasite variant
    Uninstall_WinToolsUWTuninst.exe WinTools adware uninstaller. Should only need to run once in order to complete uninstall; when done, disable.
    UniPrintUSetDfltSettings.exeDrivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix.
    UniScUUnisc.exeMcAfee UnInstaller
    uniucu?uniucu.exe??
    Universal USB ServiceXsvchost32.exeAdded by the W32.KELVIR.R WORM!
    Unix File SupportXinit3.exeAdded by the W32/RBOT-ZN WORM!
    unldr16Xunldr16.exeAdded by a CRYPTER.C trojan variant infection
    unldr32Xunldr32.exeAdded by a Crypter.C trojan variant infection
    UnSpyPCXUnSpyPC.exe"Spyware remover" of dubious repute - see the authoritative SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
    untrayYuntray.exePart of Command AntiVirus
    uoltrayNexec.exeNetzero free ISP software - not required
    Up ServiceXup32.pifAdded by the W32/Rbot-ARI WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    UpConfgVerNUpgConf.exePanda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function.
    UpDataXwupdata.exeAdded by the TROJ/IRCBOT-AA TROJAN!
    UpdateX(original file path)Added by the LYNDEGG VIRUS!
    UpdateXCDUpdater.exe"Carpe Diem" adult premium rate dialler related
    UpdateXSysupd.exeAdded by the SLACKBOT VIRUS!
    UpdateXmshtm.exeBrowser hijacker, redirecting to buldog-search.com
    updateXwinis.exeAdded by the W32/RBOT-VD WORM!
    updateXr00t.exeAdded by the W32/RBOT-ACO WORM!
    UpDateXRAuth.exeAdded by the TROJ/DLOADER-UL TROJAN!
    UpdateXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    UPDATE =XWinUpdater5.0.vbsAdded by the VBS/Gormlez-A Worm!
    Update for WindowsX(See description box.)Added by the W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
    Update for Works?MSWkstz.exeMaybe related to later versions of MS Works?
    Update GroksterNWiseUpdt.exeAutomatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor
    Update InstallXSchost.exeAdded by the GAOBOT.AO WORM!
    Update local?SetCPQLC.exeRunning on a Compaq desktop. Any ideas?
    Update ManagerNUpdateManager.exeSearches for updates for the Rogers Yahoo!_Browser - can be run manually
    Update MCafeeXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    update run dosXlogon.exeAdded by a variant of the W32/SDBOT WORM!
    Update Run MSwordXLOGON.EXEAdded by the RBOT.TY WORM!
    Update ServiceYUpdate.exeLoaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall
    update serviceXsvxhost.exeAdded by the RBOT-MG WORM!
    update serviceXwinx.exeAdded by a variant of the WIN32.RBOT WORM!
    Update ServiceXwinu32.exeAdded by the W32/RBOT-MG WORM!
    Update SymantecXWinNT.exeAdded by the W32.Vig.C VIRUS! Note: Copies it's self to multiple Drives and folders.
    Update TUT?WiseUpdt.exe??
    Update ver 1.0XSwap.exeAdded by the W32/SWAP-C WORM!
    Update" -s setupXZupdate.exe B3d Projector foistware - periodically tries to access the internet. (1) Uninstall via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
    Update.exeXravseuper.exeAdded by the Troj/QQPass-P TROJAN!
    Update32Xconfigs.exeHijacker, also detected as the QURL-2 TROJAN!
    UpdateCheckXwinstall.exeAdded by the W32/SPYBOT-CY WORM!
    UpdateComponentXCNF UPD.EXEAdded by the SPYBOT.GEN VIRUS!
    UpdateFW?fwdload.exeAppears to be firmware update software for a Network Associates ATMbook OC-3 SMF Interface Module?
    UPDATEHOOK?Rundll32.exe??
    updatelavasoftXupdatelavasoft.exe CoolWebSearch related hijacker, redirecting to lalasearch.com
    UpdateManagerUsgtray.exeStorageGuard from Veritas (this version by Sonic). Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop), Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups
    UpdateMediaXUpdateMedia.exeMediaUpdate foistware
    UpdateMgrXupdmgr.exeAdded by the SouthBeachTel premium rate adult content dialer.
    updatemgr.exe or UPDATE~1Nupdatemgr.exe UPDATE~1.EXEOnce a month, your EarthLink 5.0 Update Manager contacts EarthLink\'s servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually
    UPDATEMSNXsvhost.exeAdded by an unidentified WORM or TROJAN!
    updaterXwupdater.exe eUniverse/KeenValue adware
    updater?updater.exe??
    UpdaterXadservernow.exe AdServerNow adware
    updaterXwisvc.exeAdded by the TROJ/ORSE-A TROJAN!
    Updater Service ProcessXsvhost32.exeAdded by the AGOBOT.TY WORM!
    updater32Xwinload32.exeAdded by the CULT.M WORM! **Note - not to be confused with the valid Windows "NOTEPAD" text editor
    UpdatesXmsupdate.exe CoolWebSearch parasite related.
    Updates from HPNbackweb*****.exeAutomatically detects an internet connection and downloads any available updates - * is random digit
    UpdatestatsNUpdatestats.exeStatblaster - "Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues"
    updatev01Nupdatev01.exeUltra-networks.com software updater/downloader
    Updatewiz?updatewiz.exe??
    upddateitXwinit.exeAdded by the W32/RBOT-MS WORM!
    UpdmgrXupdmgr.exe eUniverse/KeenValue adware related
    updmgrXrvupdmgr.exe eUniverse/KeenValue adware
    UpdRegNUpdreg.exeReminder to register Creative Labs SoundBlaster Live! cards
    UpdSysNAdded by the BJ VIRUS!
    Upgrade SarviceXsxchost.exeAdded by a variant of the TROJ/TOFGER-I TROJAN!
    Upgrade ServiceXsxchost.exeAdded by the TROJ/TOFGER-I TROJAN!
    Upgrade ServiceXwinupd.exeAdded by the TROJ/TOFGER-U TROJAN!
    upmeX(path to file)Added by the W32.MUGLY.F WORM!
    UpmeXDLLMAN.EXEAdded by the MUGLY.I WORM!
    UPnP ManagerXupnpman.exeAdded by a variant of the Win32.Agobot.gen WORM!
    UPNPServiceXWinSVCservice.exeAdded by the AGOBOT.UN WORM!
    Upromise0UUpromise0.exe Upromise college savings progrram
    UPSYups.exePowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
    UPSXUPS32.exe -vAdded by the W32.Femot.O Worm!
    UPSentry 2000 or UPSlimYupsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss 
    UPSMONUUPSMON.exe UPSMON Power Management software
    UPSUtlXweb.exe CoolWebSearch parasite related.
    Uptimer4UUptimer4.exeUptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things
    UpTimes service XWinUp.exeAdded by the W32/Rbot-AKB WORM!
    UpToDateXuptodate.exeBrowserAid/BrowserPal foistware
    upyxoXyujixit.exeAdded by the SDBOT.BIX WORM!
    URLLSTCK.exeYUrlLstCk.exePart of Norton Internet Security. From Symantec - "UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled"
    URLMAPNUrlmap.exeInstalled by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it
    UrtSvcExeYUrt95Svc.exe"Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"
    Usb?Usb.exeHP related - not sure whether it\'s required
    USB 2.0 DriverXWinsys32.exeAdded by the W32/AGOBOT-QM WORM!
    USB 2.0 DriverXupdateXPSPC.exeAdded by the W32/AGOBOT-RJ WORM!
    USB 2.0 DriverXupdateXP.exeAdded by the W32/AGOBOT-QP WORM!
    USB 2.0 DriverXwinsystem.exeAdded by the W32/AGOBOT-QS WORM!
    USB 2.1 DriverXwinupdate1.exeAdded by a variant of the WIN32.RBOT WORM!
    USB controllerXSvcmm32.exe SvcMM backdoor parasite downloader
    USB DeviceXservicelog.exeAdded by the WOOTBOT.CB WORM!
    USB DeviceXwin32usb.exeAdded by the W32/FORBOT-BQ WORM!
    USB Driver4XUpdateXP2.exeAdded by a variant of the W32/SDBOT WORM!
    USB Driver4XUpdateXP6.exeAdded by a variant of the W32/SDBOT WORM!
    USB Drivers1Xmsupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    USB Driverz2Xmsnplus1.exeAdded by the W32/SDBOT-XQ WORM!
    USB Fix 1.1Xwuservices.exeAdded by a variant of the W32/SDBOT WORM!
    USB FixesXwuafix.exeAdded by the W32/RBOT-ABV TROJAN!
    USB Hardware MonitoringXUSBhardware.exeAdded by the W32/RBOT-NN WORM!
    USB Hardware326 MonitoringXUSBhardware326.exeAdded by a variant of the W32.SPYBOT WORM!
    USB Hardware32c MonitoringXUSBHARDWARE32C.EXEAdded by the W32/RBOT-UU WORM!
    USB Host ServiceXusbsvc.exeAdded by a W32/Rbot-GG worm infection
    USB Hub Keyboard Patch?SKBPATCH.EXEUSB HUB Update
    USB SECURITY DEVICE CoInstallerYJupitCo.exe ButterflyMedia USB Flash drive related - required for the password security feature to work.
    USB UpdatesXmservices.exeAdded by a variant of the SDBOT WORM! - see here
    USB UpdatesXmsfirewalls.exeAdded by a variant of the WIN32.RBOT WORM!
    USB Updates 2Xwugfixx.exeAdded by a variant of the WIN32.RBOT WORM!
    USBConfigration2Xwmmndir.exeAdded by the W32/Agobot-SV Worm!
    UsbDXiexplore32.exeUnidentified worm or trojan
    UsbDXsvhost32.exeAdded by the TROJ_AGENT.IB TROJAN!
    UsbDXsmss32.exeAdware downloader - recognized by Kaspersky antivirus as Trojan-Proxy.Win32.Agent.cj
    UsbdXusb_d.exeAdded by the TROJ/CIDRA-A TROJAN!
    UsbDX(Path of the trojan executable)Added by the Troj/Cidra-F TROJAN!
    USBDetectorUUSBDetector.exeUSBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
    USBDetector?UDetect.exeUSB detector, apparently for an MP3 player - any further information appreciated!
    USBDrivesXmsfirewalI.exeAdded by the W32/RBOT-ABP WORM!
    usbdrvXservicetask.exeAdded by a variant of the W32/SDBOT WORM!
    USBHWDRVXgam.exeAdded by a variant of the TROJ/LOWZONE-I TROJAN!
    USBHWDRVXmsdc.exeAdded by a variant of the TROJ/LOWZONE-I TROJAN!
    USBHWDRVXsst4.exeAdded by a variant of the TROJ/LOWZONE-I TROJAN!
    USBHWINFOXsst6.exeAdded by the TROJ/LOWZONE-I TROJAN!
    USBHWINFOXmmc.exeAdded by the TROJ/LOWZONE-I TROJAN!
    USBHWINFOXmac.exeAdded by the TROJ/LOWZONE-I TROJAN!
    USBMMKBDUusbmmkbd.exeUSB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information
    USBMonit.exeUUSBMonit.exeMonitors USB ports for insertion of Sandisk USB flashdrives
    usbnXusbn.exeAdult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa
    usbnX(path to Trojan)Added by the Troj/Hogil-E TROJAN!
    USBPNPYUSBPNP.exeSiPix digital camera Twain USB driver
    USBTANusbtapnp.exeSystem Tray access for the BeWAN Gazel 128 USB ISDN adapter
    useful-softXsvchst.exeBrowser hijacker, redirecting to elite-glsex.net
    userXuser32.exeAdded by the Backdoor.Binghe TROJAN!
    User LoggerUUsrLog.exe UserLogger is a commercial spyware program. It logs keystrokes, programs used and computer ID information. It also captures screenshots, can hide its presence on the computer and can be disguised in the Windows Task list.
    User ManagerXfcllls.exeAdded by the ZAGABAN-B TROJAN!
    User ServicesXusersvc.exeAdded by the REVCUSS.A VIRUS!
    User23.exeXDIAL.exeThis is a trojan trying to disguise itself as User32.dll
    User32X(random filename)Added by the NETTRASH VIRUS!
    UserFaultCheckNdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
    userinitXwinlogon.exeAdded by the Troj/Dloader-TP TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
    UserinitXlsass.exeAdded by a variant of the Troj/Dloader-TP TROJAN! - NOTE - this file is placed in the Program Files\Common Files folder, and should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    UserinitXlsass.exeAdded by a variant of the Troj/Viran-A TROJAN! - Note: This file is placed in the "Program Files\Common Files\System" folder. This file should NOT be confused with the legitimate Windows lsass.exe process located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    UserInit StartUpXrpcxuisu.exeAdded by a variant of the W32/SDBOT WORM!
    userint32Xuserint32.exeAdded by an unidentified TROJAN via an Instant Message that says, "This was cool, check it out here." Also contains Aurora popups
    USERINTERFACE REPORT3RXM0USE.exeAdded by the MYTOB.HS WORM!
    Userinterface ReporterXsrv32.exe ISTbar/XXXToolbar adware downloader
    Userinterface ReporterXfuuuucktttttt.exeAdded by the W32/MYTOB-DK WORM!
    UserSystemX CoolWebSearch parasite related.
    ushliXsscbltqu.exeObtained from an MP3 search list site. Also generates random processes on reboot
    usrgtway.exeXsyswrun4x.exeAdded by the MITGLIEDER.E VIRUS!
    USRobotics 802.11g Wireless Network UtilityNUSRWLANG.exeUSRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck "Use Windows to configure my wireless settings" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties
    Usrobotics Online RegistrationN??Pop-up reminding customers to register their products online at US Robotics
    USRpdAY[path] USRmlnkA.exe RunServices \\Device\\3cpipe-USRpdA US_Robotics modem driver
    UsrrXrncr.exe PurityScan/Clickspring adware
    UsrrXrpen.exe PurityScan/Clickspring adware
    USRSTA?USRSTA.exeWireless Card controller. What does it do and is it required?
    USSShRegNUSSSHREG.EXERegistration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
    Utility Ping?UTILIT~1.EXE??
    UtilityProNUtilityPro.exeIE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions
    UTILsInstYN/AFor Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
    Utopia AngelNAngel.exeCalculator for the online Utopia game
    uwyrlXuwyrl.exeAdded by the PHEL.A TROJAN!
    uwyw.exeXyujixit.exeAdded by the SDBOT.BGB WORM!
    V.92 Modem On HoldULtmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
    V128IIDYRundll32.exe v128iitw.dll, STB_InitTweakLoads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages
    V128IITV???Loads drivers for some STB graphics cards. May be related to such a card with a TV out option?
    V66SHELL?V66SHELL.EXEIt looks to be part of the display driver set for ASUS V3800, V6600 and V6800 display adapters. Probably a system tray quick access control?
    va10keyUva10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
    Vaganza-XPloit-[User Name]"X[user name].exeAdded by the W32.GAVGENT.A WORM!
    VAGCtrlYVAGCTRL.EXEVexira Antivirus - virus scanner from Central Command
    VAGuardYVAGNT.exeVexira Antivirus - virus scanner from Central Command
    VAIO Action Setup (Server)UVAServ.exeSony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB
    VAIO RecoveryUPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere
    ValidDataX(path to file)RANKY.H backdoor WORM!
    vb6Xvb6.exeAdded by the W32.MUGLY.D WORM!
    VBouncerXVirtualBouncer.exe Virtual_Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code.
    VbouncerDLXVBouncerInnerxxxx.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here. "xxxx" represents 4 random numbers
    VbouncerDLXVBouncerInner.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself.
    VBS.Ipnuker@mmX(original worm file name).vbsAdded by the VBS.Nukip Worm!
    VBS_AUTO_UPDATEX0548656X.vbsAdded by the VBS/Gormlez-A Worm!
    VBundleOuterDLXBundleOuter.EXE VIrtualBouncer malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs
    VB_runXcomctl_32.exeDubious downloader from densmail.com
    VC5MediaPlayerXcsmss.exeAdded by the W32/DEDLER-B WORM!
    VC5PlayNVC5Play.exeVirtual CD drive emulator - version 5. Available via Start -> Programs
    VCatchXVcatch.exeCommonSearch Vcatch - "antivirus" software which actually bundles spy/adware itself!
    VCatch PremiumXVCatchpre.exeVCatch antivirus. Considered spyware itself - see here
    VCDPlayerNVCDPlayer.exeVirtual CD drive emulator. Available via Start -> Programs
    vcdplayxNvcdplayx.exeCD emulation part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically 
    VCDTowerUVCDTower.exeGoldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive, users can simultaneously access as many as 23 virtual CD-ROM drives at a speed of 200X for true multitasking
    VCDWATCH?VCDWATCH.EXEConfirmed as Voyetra CD Watcher as it was found in a Compaq/Voyetra/AS2 directory but what does it do?
    VCSPlayerNvcsplay.exeVirtual CD drive emulator. Available via Start -> Programs
    VCXD SettingsXphqg.EXEAdded by the RBOT.BRF WORM!
    VC_LogUkeylog.exe PaqKeylog is a spyware program that logs keystrokes and can run in stealth mode. If you didn't install this yourself remove it.
    Vdat UpdateXlalaa.exeAdded by a variant of the WIN32.RBOT WORM!
    VDI Manager (HP)?HPO0VDX05.exeHP (Hewlett-Packard) related. Now - what does it do?
    vdtaskNvdtask.exeProgram part of GameDrive& VirtualDrive from Farstone. Not required as starting these programs load this automatically 
    Vegas Palms - LauncherNLauncher.exeVegas Palms on-line cassino
    veja_fotos.exeXveja_fotos.exeAdded by the TROJ/MDROP-F TROJAN!
    VERBATIM STORE 'N' GUverbatim store 'n' go.exeLoads the driver for the Verbatim Store'n'Go™ PRO USB Flash Drive - reportedly required only on systems running Windows 98 and Millennium
    VerifXvxst.exeAdded by the NOPIR.B WORM!
    Veritas PatchXveritas.exeAdded by the W32/RBOT-XT WORM!
    Verizon Control PadNcpad.exeControl Pad - installed with Verizon DSL accounts. Tool designed to streamline the online experience
    Verizon Online Support CenterUmatcli.exe"matcli.exe is a motive Assistant Command line interface that gathers information about your system\'s identity like your name email address, city, state, etc and gets written to a log file". Verizon Online Support Center is required to run with the Help and Support program. If you uncheck Verizon Online Support Center and and then run help and Support it will add another Verizon Online Support Center in the startup menu. If you remove the Verizon Online Support Center in the add/remove program some help menus in help and support will not be available. You decide
    vern16.dllXregsvr32.exe [path] vernn16.dll DailyWinner adware
    vernn16.dllX[path] vernn16.dll DailyWinner adware
    versatoUversato.exe"Hot" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards
    VersionXVersion.exe, manage.exeJRAUN adware variant
    versionXadl_dh.exe DealHelper adware related
    versionX[random filename] DealHelper adware related
    Vet AlertYvetmsg9x.exeComputer Associates "InnoculateIT" and Vet Anti-Virus virus software
    Vet AlertYVETMSG.EXEComputer Associates Vet Anti-Virus software
    Vet Start UpYvet98.exevet32.exeComputer Associates "InnoculateIT"  and Vet Anti-Virus virus software. This option will slow down your system, if set too aggressively. There is no need to scan every file when opened, closed, etc. Check in InoculateIT PE options
    VetTrayUvettray.exeComputer Associates "InnoculateIT"  and Vet Anti-Virus virus software. System Tray quicklaunch access, not really necessary but only occupies 36k resources
    VFW Encoder/Decoder SettingsXRUNDLL32.exe MSSIGN30.DLL ondll_regAdded by a variant of the LOVGATE WORM!
    VGA StartupXvgacard.exeAdded by a variant of the WIN32.RBOT WORM!
    VgaDriverXRsrVga32.exeAdded by the TROJ/KEYLOG-AH TROJAN!
    VGATuneXVGATune.exeAdded by the W32/Rbot-AWM WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    VGAUtilUG-VGA.exeGigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical)
    vid32cntlXvid32cntl.ExeAdded by a CRYPTER.A trojan infection
    vidcntlXvidcntl.ExeAdded by a CRYPTER.A trojan infection
    VidcompatXVidcompat.exeAdded by the GEMA TROJAN!
    vidctrlXvidctrl.exe Delfin_Promulgate adware variant
    VideoXexplored.exeAdded by the GAOBOT.RF WORM!
    VideoXwinamp32.exeAdded by the W32/AGOBOT-NG WORM!
    Video Card Driver (do not remove)Xtsasi.exeAdded by the W32/Spybot-EF WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Video Lan PlayerXVideoLanPlayer.exeAdded by the W32/RBOT-MY WORM!
    Video ManagerXvideomgr.exeAdded by the PANDEM.C VIRUS!
    Video Multimedia DriverXndrives32.exeAdded by a W32/Rbot-DK worm infection
    Video ProcesXwinaps.exeAdded by the AGOBOT.HD WORM!
    Video ProcessXsysconf.exeAdded by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!
    Video ProcessXnetsvcs.exeAdded by the AGOBOT.LH WORM!
    Video ProcessXMS32x16.exeAdded by a RBOT.RH worm infection
    Video ProcessXMSlti64.exeAdded by the AGOBOT.UE WORM!
    Video ProcessX[random filename]Added by the RBOT-LM WORM!
    Video ProcessXwinasp.exeAdded by the W32/AGOBOT-IS WORM!
    Video ProcessXmsn5.exeAdded by W32/Agobot-TW WORM!
    Video ServicesXexplore.exeAdded by a W32.Gaobot.GL worm infection
    Video ServicesXvideol_32.exeAdded by the W32/Agobot-DM WORM!
    Video ServicesXsys32.exeAdded by the AGOBOT.PS WORM!
    VideocntlXVideocntl.exeAdded by a variant of the Win32.GEMA.D TROJAN!
    VideoDriverX(filename)Added by the GSPOT20.A VIRUS!
    VideoDriverXvideodrv.exeAdded by the W32.MIMAIL.A WORM!
    VideoDriverXgspotbot.exeAdded by the SPIGOT.C VIRUS!
    Videool32XVIDEOL32.EXEAdded by the AGOBOT.EC WORM!
    videoporno.exeXvideoporno.exePremium rate adult content dialer
    vidmonXVIDMON.EXE Delphin_Media_Viewer adware related
    VidSvrNvidsvr.exeMS WebTV for Windows Channel Guide. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
    vietato.exeXvietato.exeAdult content dialler
    VIEW POINT DRIVERSXphqghum.exeAdded by the RBOT.BRX WORM!
    VIEW POINT DRIVERS FOR WIN32Xphqghu.exeAdded by a variant of the WIN32.RBOT WORM!
    ViewMgrNViewMgr.exe Viewpoint_Manager - automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc). Can be run manually via Start -> Settings -> Control Panel by enabling auto-updates temporarily, re-booting and then disabling again
    Vinny?????
    Virt.exeXVirt.exeAdded by the REMADM-C TROJAN!
    VirtuaGirlUVg.exeVirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request...
    VirtuaGirl2UVirtuaGirl2VirtuaGirl is a shareware program featuring scantily dressed girls on your desktop. They say hi in the morning, remind you of your appointments and dance for you on request...
    virtualXwinit.exeAdded by a variant of W32.Mugly.A WORM!
    virtualXwinprotect.exeAdded by the W32.MUGLY.C WORM!
    virtualXwini.exeAdded by the W32/RBOT-YX WORM!
    Virtual Access SchedulerUVASCHD32.EXEThe scheduler for mail and usenet tool
    Virtual BouncerXVirtualBouncer.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here and here
    Virtual CD v6Xgrplscd.exeAdded by the W32/Rbot-AXV WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Virtual CDROMXdeamon.exeAdded by the RBOT.VP WORM!
    virtual-ieXwinlogi.exeMalware - detected by Kaspersky antivirus as Trojan-Dropper.Win32.WinAD.h
    virtual-machineXsvchosts.exeAdded by the W32/RBOT-US WORM!
    virtual-machineXwinlogin.exeAdded by the W32/RBOT-VU WORM!
    virtual-machineXwini.exeAdded by the W32/RBOT-WR WORM!
    VirtualCloneDriveNVCDDaemon.exeVirtual Clone Drive, part of CloneCD CD/DVD copying sofware; discontinued
    VirtualDriveNVDTask.exeVirtualDrive from Farstone - virtual CD drive emulator. Available via Start -> Programs
    VirtuaReminderUVirtuaReminder.exe VirtuaReminder is a tool allowing the user to create reminders for such things as important appointments, birthdays, etc.
    Virtuele KatjaUVKatja.exe Virtuele_Katja - have an attractive moviestar parade on your Desktop and help you search the Dutch "Gouden_Gids" business directory too...
    VirusXAnti.exeAdded by the WIN32.SEENBOT.O WORM!
    Virus ProtectXvrsprtc.exeAdded by the W32/RBOT-APR WORM!
    Virus Removal ToolX(pathname of the Trojan executable)Added by the Troj/Tometa-B Trojan!
    Virus ScanXvirscana.exeAdded by a VIRUS!
    VirusCheckIIXAVIRCHK.EXEAdded by the DASMIN VIRUS!
    VirusScan OnlineYmcvsshld.exeMcAfee VirusScan On-line. See also McAgentExe entry
    VirusScan OnlineXmcagent.exeAdded by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
    VirusScanMSC?VsStat.exePart of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe), McAfee SecurityCenter integration or something else? Is it required?
    Virus_ScannerXVirus_Cleaner.exeAdded by the PANOL VIRUS!
    visionGSNVISIONGS.EXEvisionGS webcam software
    VistascanNvistascan.exeIncluded in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users, you'll see a scanner icon in the Windows Tray of the Taskbar. Click this icon and a menu opens
    Visual Element FX5X[various file names]ClearStream Accelerator adware
    VisualStudioXmsorunner.exeAdded by a variant of the WIN32.TACTSLAY TROJAN!
    VITAL BOOT PROCESSXtaskmnsgr.exeAdded by the W32/Rbot-VY WORM!
    VITAL BOOT PROCESSXtaskmngr.exeAdded by a variant of the WIN32.RBOT WORM!
    Vital Load ProcessXSpoolsvr.exeAdded by the RBOT.AIF WORM!
    VividGalutXVividGalut.exeAdult content related web downloader
    vmcleanerXgxlib.exeAdded by the TROJ/SMALL-HS TROJAN!
    VMDFWYvmdfw.exeVirusMD Personal Firewall
    vmlibXvmlib.exeAdded by the Troj/LowZone-AQ TROJAN!
    Vmmon32Xvmmon32.exebrowser hijacker
    vmsnGraberXVMSNGRABER.EXEAdded by the ENVID.B WORM!
    vmssXvmss.exe Delfin_Media_Viewer or "Promulgate" adware variant
    vmtunerXgclib.exeHijacker - detected by Kaspersky antivirus as Trojan-Clicker.Win32.Small.fh
    vmtunerXgglib.exeAdded by the Troj/QLowZon-D TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    VnCplUpdateXmsdm.exeMasssend - spam relayer. Listens on a port for the spammers to feed it a list of addresses and what to send out. More information in this advisory
    vnmispoisn_downloader.exeXvnmispoisn_downloader.exeSearchBarCash adware variant
    VOBIDUInstantDrive.exePinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
    VOBRegCheckYVOBRegCheck.exePart of Pinnacle Systems InstantCD/DVD and InstantCopy CD/DVD copying software that verifies drive settings. Once loaded it doesn\'t use any resources so you can leave it enabled
    VolControlXvolumec.exe -iAdded by the Troj/Bckdr-CUP TROJAN! Note: This trojan file is found in the Windows(95/98/ME/XP) or WINNT (NT/2000) folder.
    Voltage ManagerX[random file name]"Added by the W32.DREFFORT WORM!
    Volume ControllerXVolumeControl.exeAdded by the SDBOT.AYI WORM!
    VonageUclick2call.exe Vonage Voice over IP Internet phone service
    VoodooBansheeUrundll32.exe 3DBBps.dll, BansheeLoadSettingsLoads the configuration settings for a 3dfx Voodoo Banshee chipset based graphics card. If you change some of the settings from default you probably need this - otherwise maybe not 
    voowsmcr?huhdir.exe??
    Vortex TrayNasp4setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    VortexTrayNau30setp.exe asp4tray.exe asp4setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
    VoyetraTrayNvtray.exeThis provides an abbreviated Control Group for the Turtle Beach Montego II sound functions/associated with AudioStation 3 and 32
    VPCUserServicesUVMUSrvc.exePart of "DOS_Virtual_Machine_Additions" for Microsoft Virtual_PC , software virtualization software that allows you to run multiple PC-based operating systems simultaneously on one workstation. This process provides additional functionalities such as Shared Folders.
    VPCUserServicesXVMUSrvc.exeAdded by an unidentified TROJAN!
    Vpop3 Mail ServerUvpop3.exeMail server from Paul Smith Computer Services. Runs in system tray to collect mail. Can be run from a shortcut and if it isn't running then it won't get your email!
    vptrayUvptray.exeSystem Tray icon for Norton Anti-Virus Corporate Edition. Gives access to the options available and may not be required. Some users may have problems - refer here
    VrmonYvrmonnt.exeHAURI Anti-Virus
    VrmonYvrmonnt.exe HAURI Anti-Virus
    VrScheduleYVrres.exeHAURI Anti-Virus
    VS.VSNYPart of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added
    vsadminXsmrs.exeAdded by the W32/AGOBOT-RC WORM!
    VsampleXwinxpsock.exeAdded by the SDBOT.BLK WORM!
    vsc32cnfNvsc32cnf.exePart of Roland's Virtual_Sound_Canvas software synthesizer gives the "ability to turn MIDI files into a stereo wave file with the touch of a button"
    vscannerXspooll32.exeAdded by the OPTIXPRO VIRUS!
    vscvolNvscvol.exePart of Roland's Virtual_Sound_Canvas software synthesizer gives the "ability to turn MIDI files into a stereo wave file with the touch of a button"
    VsEcomrEXENVSECOMR.EXEFrom McAfee VirusScan up to version 4.x. This executable is responsible for the periodic "update" prompts
    Vshwin32EXEYVSHWIN32.EXEFrom McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
    VSNNVSN.exeSoftware to share photographs across the internet
    VSOCheckTaskYMCMNHDLR.EXEPart of McAfee's SecurityCenter and Virusscan Online. Must be enabled for scanning to work
    VSOCheckTaskXmcagent.exeAdded by the TROJ/ANTIMCA-A TROJAN! - do NOT confuse with the McAfee VirusScan executable as described here
    vspdfprsrv.exeNvspdfprsrv.exeVisage PDF Printer
    VsStatEXEYVSSTAT.EXEFrom McAfee VirusScan up to version 4.x and Dr Solomon\'s VirusScan. Communicates between VSSTAT.EXE and the VShield System Scan module. Can be started automatically or available via Start -> Programs
    vTPassNvtpassld.exePart of vTrails - a live media delivery solution. vTPass is the driver enabling the system to work. If unavailable via Start -> Programs, create your own shortcut for the "vtpass.exe" file
    VTPresetUVTPreset.exeSavage Pro S3 graphics software
    vTTIMERUVTTIMER.EXEA device driver for VIA/S3G UniChrome IGP graphics controller and VIA/S3G KM400/KN400 graphics card. It is located in \WINDOWS\SYSTEM\ on Windows 95/98/ME and \WINDOWS\SYSTEM32\ on Windows XP and \WINNT\SYSTEM32\ on Windows NT/2000 Viaarena
    vTunerStartUpNvTuner.exevTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet"
    vuaaaXreg.exeAdded by a variant of the WIN32.RBOT WORM!
    VVSNXVVSN.exe SaveNow adware
    vwinXQ4Keygen.exeAdded by the W32/Mircnuf-A WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    VZAccess ManagerUVZAccess Manager.exeVerizon Access manager for enterprises
    W1NTASKXtaskgmr.exeAdded by the W32/MYTOB-BZ WORM!
    w32Xw32.exeAdded by the SOKEVEN VIRUS!
    W32.ScranXScran.exeAdded by the W32.Narcs WORM!
    w32alanisXmope.scrAdded by the SINALA VIRUS!
    W32dataXeworo.exeAdded by a variant of the WIN32.RBOT WORM!
    W32LoadX(random name).scrAdded by the CASPID VIRUS!
    W32PluginsDownloaderXMLHTTPSelfClearing7520Xwiper.exeAdded by the Troj/Proxyser-M TROJAN!
    w32supXw32sup.exeAdult content dialler
    W32TcXWTC32.scrAdded by the VOTE.D or VOTE.K VIRUSES!
    W3KNetworkXrundll32.exe w3knet.dll, dllinitrunAdvertising spyware. Check here for more info on this particular one
    W75P2PSERVERYW75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
    w98Eject?w98Eject.exeRelated to USB support for Sigmatel MP3 audio decoder -what does it do, and is it required?
    wait4IPUwait4IP.exePackard Bell net2Plug allows you to network PCs anywhere in your house
    wallchgr.exe wstartUWallchgr.exeBlue Tree Software
    WallPaperXtaskimgr.exeAdded by the Troj/Banker-GX TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    Wanadoo Messenger.exeNWanadoo Messenger.exeWanadoo ISP instant messenger client
    WanMPSvcYWanMPSvc.exeAn AOL component, the Wan miniport (ATW) service. If you delete this and logon, AOL reports a problem with your internet connection, and reinstalling AOL doesn’t help
    WAPIXwts**.exe (* = random char) PurityScan/Clickspring adware
    war-ftpd.exeNWAR-FTPD.EXEWar FTP Daemon from JGAA's Internet - FTP client
    WardoXsyslaunch.exeAdded by the ADLCICKER.G VIRUS!
    WareOutXWareOut.exeMalware masquerading as a spyware and dialer remover, see here
    warezNwarez.exe Warez P2P client
    WarnerUwarner.exeAlso known as "CyberWarner". From G-Tek Technologies and pre-installed on some Packard Bell PCs. Protects critical files
    WarnetUwarnet.exeWarnet - system cleanup software
    Warning: do not remove it!Ufpplock.exePart of Folder Password Expert by ZQS Software Team - "a software program to restrict access to the folders that contain your sensitive data"
    WARSVRNwar-ftpd.exe"War FTP Daemon - the original free FTP server for windows"
    WashAndGo - Cleanup of old BackupfilesUchecker.exeWashAndGo - temp file cleaner
    WasherNwasher.exeWindows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
    Washerie.exeNwasherie.exeCookie Washer for Internet Explorer from Webroot Software. Light version of Windows Washer, specific for cleaning the IE cache and cookies. Available via Start -> Programs
    washindexUwashidx.exeWindows Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG
    WastXwast.exeGrokster ads updater
    wastXwast2.exeGrokster ads updater
    WatchNwatch.exeFound to be used by a Trust USB scanner for auto starting the scanning software when the lid is lifted
    Watch?1200UBWATCH.EXE??
    Watch Dog ProgramNwatchdog.exeFor Compaq PC's. Associated with Compaq's internet services. Not required if you don't use services provided by them and may not be required even if you do
    WatchdogNWatchdog.exeDefinitely part of the Mustek scanner drivers and software (for 600 III EP Plus and maybe others), launches from the Startup folder in the Start Menu, but not required as they give instructions on removing it on their webpage
    WaveTop LauncherNWaveTop.exeWaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
    WaveTop Receiver 1NN/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
    WaveTop Receiver 2NN/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
    WaveTop Upload ManagerNN/A WaveTop - "Get push content from TV without an Internet connection" - now possibly a defunct system in the US included as an optional part of WebTV in Win98
    WbiffNWbiff.exeWbiff! E-mail checker - automatically checks your e-mail and notifies you if any new e-mail has been received
    Wbutton?Wbutton.exeRelated to the Wacom Penabled driver on Acer Tablet PCs. Appears to do nothing so is it required?
    WCESCOMMNWCESCOMM.EXEActive sync for use with Windows CE based palm PC
    WCESMngrXWCEMNGR.EXEAdded by the W32/AGOBOT-QX WORM!
    WCESMngrXspoolsb.exeAdded by the W32/AGOBOT-QZ WORM!
    wcmdmgrUwcmdmgrl.exeChecks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information
    wcmdmgr.exeNwcmdmgr.exeIt will periodically contact Wild Tangent servers to see if an update is available for your system and allows us to make the product exceptionally reliable. You can control its behavior, or disable it completely, inside your Windows Control Panel. Note that Wild Tanget's privacy policy used to stae they also collect and share individuals information, but this is no longer the case
    WCOLOREALUcoloreal.exeMakes colours sharper and brighter, but will only work with coloreal capable monitors
    WCPCXwintsvcc.exe PurityScan/Clickspring adware
    WCPIXwintsvit.exe PurityScan/Clickspring adware
    WCPSXWint**.exe (* = random char) PurityScan/Clickspring adware
    WCPTXwintsvtr.exe PurityScan/Clickspring adware
    wcsysXwcsys.exeAdded by the Troj/Keylog-AP TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WD Button ManagerUWDBtnMgr.exeButton manager installed with a western digital external disk drive. Allows you to back up your system with one click.
    WDInfoXwdinfo.exeAdded by the DOWNLOADER.DLUCA.B TROJAN!
    WDNS SYSTEMXwdns33.exeAdded by the MYTOB.EV and W32/Mytob-BY WORMS!
    WDNS SYSTEMXskybotx.exeAdded by the W32/Mytob-BY WORM!
    WDNS SYSTEMXnibie.exeAdded by the W32/Mytob-BY WORM!
    wdskctlX(path to file)Added by a Waltun-A trojan infection
    wdskctlXwdskctl.exe IePlugin adware
    wdwctrlXwdwctrl.exeAdded by the Troj/Dload-DC TROJAN!
    WEATHERNWEATHER.EXEWeatherbug provides current outdoor temperature in the System Tray, also weather alerts. Available via Start -> Programs
    WeatherCastNWeather.exeWeather reporting in the System Tray. Available via Start -> Programs. Installed via Radlight
    WeatherOnTrayXWeatherOnTray.exe Hotbar' s Weather Forecast tool for your desktop
    WeatherscopeXWeatherscope.exe WeatherScope software - bundles Gain/Gator adware
    WeatherWatcherNww.exeWeatherWatcher - weather reporting in the System Tray
    webX******.exe (* = random char)Added by a variant of the Win32/TrojanDownloader.Easto.A TROJAN!
    WEB DRIVERS FOR WIN32Xphqgh.exeAdded by a variant of the WIN32.RBOT WORM!
    Web OfferXEZSTUB22.EXEeZula TopText adware
    Web OfferXezStub.exeeZula TopText adware
    Web OfferXvl_ezstub.exeeZula TopText adware
    Web OfferXezPopStub.exeAdded by eZula ADWARE!
    Web Search?????
    Web ServiceX[random file name].exeAdded by the ADMINCASH TROJAN!
    Web ServiceXsm.exeAdded by the W32/BUBE-F VIRUS!
    Web ServiceXMSXMIDI.EXE CoolWebSearch parasite variant, identified by Kaspersky_antivirus as TrojanDropper.Win32.Small.cw
    Web2PopUWeb2Pop.exe Web2Pop allows you to retrieve your web-based accounts messages to read them in your favorite e-mail client.
    web3trapYweb3trap.exePC-Cillin 2000 anti-virus software -> ActiveX filter. Guards against malicious ActiveX programs, etc 
    webalizeXwebalize.exeSearchcentrix hijacker
    WebArmyKnifeNWAK.exe Web_Army_Knife , a suite of web site developer's tools.
    webassistXwebassist.exeAdware popup generator
    Webcam Go Sti Service Application?wbcgosvc.exeControl software for the portable Creative Video Blaster Webcam Go digital camera/PC web cam. What does it do and is it required?
    WebcamRT.exeNWEBCAMRT.exeFor Logitech Web Cams. Not required - camera works fine without it
    WebceleratorXwebcel.exeWebcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Spyware and troublesome - see here
    WebCheckXWebCheck.pifAdded by the CONE.C or CONE.F VIRUSES!
    WebCpr0XWebCpr0.exe Web_CPR/TopMoxie adware
    Webdav.exeXwebdav.exeIRC DDoS bot which gives the hacker full control over your system
    WebHancer AgentXwhagent.exeSystem Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
    webHancer Survey CompanionXwhSurvey.exeWebHancer foistware - traffic measurement service that uses a client agent that is stealth installed on user machines, gathering detailed data about sites visited, their performance and, most important, what the user actually does while there
    WebInstall, WebInstall2XWebInstall.exeClipGenie adware downloader
    WebKeyNWebKey.exeWebKey from JB Utilities. Utility to keep track of login data required when browsing the internet
    WebLinkNWebLink.exeSoftex WebLink is a "cost-effective way to provide software updates, technical support or new product information to specific end-users - it can silently provide end-users with software updates, technical support and new product information customized to their specific needs through a a persistent link."
    WebOutfitterTrayNsttray.exeIntel WebOutfitter service System Tray icon
    Webposition Gold 2Nwpsche~1.exeScheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines
    WebRebates0XWebRebates0.exe WebRebates adware
    WebRunXweb.exeAdded by the Adwareloader TROJAN!
    WebRunXwmplayer.exeAdded by the ADWARELOADER TROJAN!
    WebRunXsm.exeAdded by the ADWARELOADER TROJAN!
    WebRunXmsxmidi.exeAdded by the ADWARELOADER TROJAN!
    WebRunX[random file name]Added by the ADWARELOADER TROJAN!
    websaverliveUwebsaverlive.exeWebSaver Live! is a companion program to Websaver that retrieves information from the Internet on a schedule and displays it on your screen when your computer is idle
    WebSavingsfromEbatesXWebSavingsfromEbatesrun.exe"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
    WebSavingsFromEbates0XWebSavingsFromEbates0.exe"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
    WebScanNDEFSCANGUI.EXEeAcceleration Stop-Sign related; not recommended; see note
    webscanNstopsignav.exeeAcceleration Stop-Sign related; not recommended; see note
    WebScanXYWebScanX.exeFrom McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs, etc
    websearchXwjview ...websearch.exe"Web Savings" From Ebates Software, a shopping tool that opens pop-up windows
    WebSecureAlertXWebSecureAlert.exeWebSecureAlert. "Can help protect your browser security and privacy"; however, it's by GAIN Publishing, and will display pop up ads on your computer screen based on your online Web surfing behavior
    WebSecureAlertXWebSecureAlert.exe WebSecureAlert software - - bundles Claria/Gain/Gator adware
    WebServer?VBI_SE~1.EXERelated to a Pinnacle sound card. What does it do and is it needed?
    WebshotsUWebshots Tray.exe Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web.
    WebshotsULauncher.exe Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web.
    WebshotsUwebsho~1.exe Webshots - software that displays photos as your screensaver and wallpaper, and provides tools for sharing your personal photos on the web.
    Website Administrator InfoXwebadmin.exeAdded by the W32/FORBOT-FY WORM!
    WebSpecialsXrundll32 [path] webspec.dll WebSpecials adware downloader
    WebsxXInt*****.exeAdult content dialler - where ***** are random
    WebtrapYwebtrap.exePart of PC-Cillin anti-virus software. Checks web-sites for malicious Java and ActiveX elements in a similar way to McAfee WebScanX. A few users find it infuriating
    WebTrapNT.exeYWebTrapNT.exePart of PC-Cillin Anti-Virus software. Checks visited web-sites for malicious Java and ActiveX elements
    WebWasherUwwasher.exeFree Pop-up/ad/javascript filter program from Siemens. If not running then browsers will not be protected but will still work. Available via Start -> Programs
    WeirdOnTheWebXWeirdOnTheWeb.exeAdded by the Adware.WeirdOnTheWeb ADWARE!
    WelcomeNWelcome.exeLaunches the Welcome to Windows tutorial on boot up
    WEPstat?Wepstat.exeCisco Aironet 340 Series PC Card driver. If it can be started manually it shouldn't be required if you don't use the PC card facility regularily - hence the status could be "U". Can anybody confirm this?
    wersdsXdoriot.exeAdded by the JECT.C VIRUS!
    wesumuXwiustv.exeAdded by the Troj/QQPass-L TROJAN!
    WetSockNwetsock.exeRoboMagic Wetsock - weather reporting in the System Tray
    WFGStartupNWFGStartup.exeWorld Weather. "This midlet displays the current weather conditions for major cities around the world. This version is for memory limited mobile phones"
    wfipsUiphider.exeICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here
    WFXCTL32.EXENWFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
    wfxsnt40Ywfxsnt40.exeWinFax 10.0 and maybe earlier versions. The program that opens the port for WinFax and not normally in the start menu. Needed if you want to run WinFax
    WFXSwtch?WFXSWTCH.exeRelated to WinFax. What does it do and is it required?
    WG511WLUYWG511WLU.exeNetgear configuration programme for the 54g wireless lan card - required to monitor and manage the lan card
    WGWLocalManagerUWGWLocalManager.exePart of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution, which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so. It could be started by creating a shortcut, running it only when connecting to the internet. If internet is used often, it's recommended to leave it in startup so it starts with the system
    whagentXwhagent.exeSystem Tray application that starts up Webhancer software. Software that optimizes your web browser and is also advertising spyware that you can find out about here
    WhatPulseUWHATPU~1.EXE WhatPulse keeps track of your keystrokes, allowing you to find out just how much you type a day.
    WheelMouseU4DMAIN.EXEMouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn\'t be needed if you don\'t use any enhanced features it may provide
    WheelMouseUAMOUMAIN.EXEA4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features
    WheelsMouseX(Path to Trojan)Added by the Troj/SocksPr-D TROJAN!
    WhenUSaveXSave.exe SaveNow adware
    WhenUSearchXSearch.exe SaveNow adware
    WhenUSearchWHSEXwhse.exe SaveNow adware
    WhistlerXwhismng.exeAdded by the WHISTLER-F TROJAN!
    WhitechixXbrightx.exeAdded by a variant of the W32/SDBOT WORM!
    WhvlxdXWhvlxd.exeAdded by the W32.LXD.Mirc VIRUS!
    WIAWizardMenuNRUNDLL32.EXE sti_ci.dll, WiaCreateWizardMenuStill Image Class Installer - installed with a webcam
    Widnows Xp Web scanXxpscan.exeAdded by a variant of the W32/SDBOT WORM!
    wifemanXwifeman.exeUnidentified malware
    WildFlicsXWildFlics.exeAdded by the Dial/Direct-B DIALER! Note: This is a premium rate dialer application for accessing sites containing adult material. The file is found in the Windows or Winnt folder.
    WildTangent CDANRUNDLL32.exe cdaEngine0400.dll",cdaEngineMain WildTangent on-line games related; not required for the games to work.
    WildTangent Web Driver updaterUwcmdmgrl.exeChecks for periodic updates of Wild Tangent Web Driver over the web. A multimedia extension/plug-in. Note that Wild Tanget's privacy policy states they also collect and share individuals information
    Wildwire MonitorNWWMon.exeThis places a status icon on the taskbar for the DSL WildWire Tiger Modem. This is also a shortcut to the diagnostics utility for the DSL modem
    Willow RoadNWillowRoad.exeWillow Road Screen Saver
    winXregedit -s ..win.dllAdded by the SEEKER.K VIRUS!
    winXxwinxrpc32.exeAdded by the W32/Agobot-MV WORM!
    winXxwinxrpc.exeAdded by the AGOBOT-MV WORM!
    WINXehshell.exeAdded by the W32/Mytob-CQ Worm\Trojan!
    WINXwindows.exeAdded by the W32.Reatle.C WORM!
    Win ChimesUwinchi~1.exeWinChimes - enhancement software for the system clock that runs in the system tray
    Win CommXWinComm.exe WebRebates related adware
    Win CommandXcommand32.exeAdded by the AGOBOT.XQ WORM!
    win ctl appXwuctl.exeAdded by a variant of the W32/SDBOT WORM!
    Win Drivers SSLXhpws.exeAdded by the WIN32/IRCBOT.67098 WORM!
    Win Drivers SSLXTASKMAN4.exeAdded by a variant of the WIN32.RBOT WORM!
    WIN HOST PROCESSXWIN HOST PROCESS.EXEAdded by the KEYLOGGER.CLONE VIRUS!
    Win l5oahderXwinampa.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Win LoginXwinlogin.exeAdded by W32/Rbot-AWE WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Win Microsoft 98Xwin14.exeAdded by the W32/RBOT-AKX WORM!
    Win Microsoft ConfigXwnmsconfig.exeAdded by a variant of the WIN32.RBOT WORM!
    win name?stat.exe??
    Win PatchXntldr.exeAdded by the W32/SDBOT-GS WORM!
    Win Secure UpdateX(Random file name)Added by the W32/Rbot-AGI WORM!
    Win SecurityXmsw32.pifAdded by the W32/RBOT-AQT WORM!
    Win ServerXwinserv.exeAdded by the IMISERV.A TROJAN!
    Win Server UpdtXwupdt.exe IEPlugin adware
    Win Server UpdtXwinserver.exeAdded by a variant of the WIN32.IMISERV TROJAN!
    Win Server UpdtXpxckdla.exe IEPlugin adware component
    Win TaskLoaderXmsgmr.exeAdded by the W32.MYTOB.L WORM!
    win updateXwupda32.exeAdded by a SDBOT.J worm infection
    win updateXwapdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Win UpdateXSysUpdate.exeAdded by the W32/Agobot-TN WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Win UpdaterXWINUPDATER.EXEAdded by the RBOT.IP WORM!
    Win Updator ServicesXctfnom.exeAdded by a variant of the W32/WOOTBOT WORM!
    WIN USB 2.0Xusbsystem.exeAdded by an unidentified WORM of TROJAN!
    WIN USB 2.0Xwinusb.exeAdded by a variant of the WIN32.RBOT WORM!
    Win USB 2.0 USB DriverXHPPrint.exeAdded by the SPYBOT.DNB WORM!
    WIN USB SUPPORTXgrxsrv.exeAdded by a variant of the WIN32.RBOT WORM!
    Win WinAmpXwinamp.exeAdded by the RBOT.AGF WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
    win************* ( * = random digit)Xwin*************.exe ( * = random digit) WINBO adware component
    WIN-BUGSFIXXWIN-BUGSFIX.EXEAdded by the LOVELETTER (I LOVE YOU) VIRUS!
    win-xpXwinis.exeAdded by the BROPIA.O WORM!
    win-xpXwinis.exeAdded by the W32.Bropia.N WORM!
    win-xpXnvsc32.exeAdded by the W32.Bropia.N WORM!
    win.exeXwin.exeAdded by the Troj/Podrop-C TROJAN! Note: This trojan file is found in the Windows\temp folder or Winnt\temp folder. Read the link, rootkit type stealth involved.
    win16.dllUwin16dll.exe Screenspy captures screenshots silently. If you didn't install this yourself, remove it.
    Win2DrvX(worm filename)Added by the WINTOO VIRUS!
    WIN32XWIN32.EXEAdded by the WIN32/MYTOB.AD WORM!
    win32XShakira_1997_Part_1_.Mpeg_.scrAdded by the MYLIFE.N VIRUS!
    win32XSetup_32.exeWinSetup.exeAdded by the EVILBOT.B VIRUS!
    Win32XWin32.exeAdded by the ISRAZ.A VIRUS!
    win32Xwinsrv32.exeAdded by the ADUENT VIRUS! Acts as a hi-jacker redirecting to Surferbar.com and adult content sites
    Win32Xsystem32.vbsAdded by the VBS.SWERUN VIRUS!
    Win32XGame.exe.vbsAdded by the VBS.Scafene WORM!
    win32Xwinhost.exeAdded by the W32.BROPIA.J WORM!
    Win32Xarsetup.exeAdded by the WIN32.SPAZBOX.A TROJAN!
    Win32 BiosXWinbios.exeAdded by the W32/SEMAPI-A WORM!
    Win32 ConfigurationXvideosd32.exe WORM_SDBOT.TT
    Win32 ConfigurationXdllhelp.exeAdded by a SDBOT.UL infection
    Win32 ConfigurationXmplayer.exeAdded by the W32/FORBOT-BZ WORM!
    WIN32 DDOSSERXdos.exeAdded by the W32.Kelvir.F WORM!
    Win32 Debug ManagerXWin32Debug.exeAdded by a variant of the W32/WOOTBOT WORM!
    Win32 Debug ManagerXmicrosoftupd.exeAdded by a variant of the W32/WOOTBOT WORM!
    Win32 Device LoaderXWin32ldr.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Win32 DriverXsvchosts.exeAdded by the W32/Forbot-FD WORM!
    Win32 DriversXwinlogons.exeAdded by the W32/Forbot-FG WORM!
    Win32 DRK DriverXwdrk32.exeAdded by the WOOTBOT.CY WORM!
    Win32 exe fileXwinstr32.exe W32.SpyBot worm variant
    Win32 ExplorerXExplorer32.exe StartPa-MN homepage hijacker
    Win32 Firewall DriverXwinfw.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 FRT DriverXmsfr32.exeAdded by a variant of the W32/FORBOT WORM!
    win32 internet serverXwinserver.exeAdded by the TROJ/DERMON-D TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Win32 Kernel core componentXKernel32.pifAdded by the MOKS VIRUS!
    Win32 LSA DriverXlsa.exeAdded by the W32/Forbot-FJ WORM!
    Win32 Ms Auto UpdaterXAutomsUPD.exe Win32.Rbot worm variant
    Win32 NDIS DriverXxpndis.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 Network DriverXcrss.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Win32 NT Adv ServicesXtaskmngr.exeAdded by the W32/Rbot-ADE WORM!
    Win32 nvcXnvcva.exeAdded by the W32/RBOT-ABF WORM!
    Win32 NVIDIA DriverXMSPMSPSU.EXEAdded by a variant of the WOOTBOT.Y WORM!
    win32 regeditXmsn32.exeAdded by an unidentified WORM or TROJAN!
    Win32 Rundll LoaderXRundll32.exeAdded by the SDBOT.A WORM! Note: Rundll32.exe is a valid Windows application called "Run a DLL as an App" and stored in the C:\Windows directory. The version created by this virus is saved in the C:\Windows\System directory
    Win32 SecureXmsconfigsvc.exeAdded by a variant of the W32/SDBOT WORM!
    Win32 ServiceXbazzi.exeAdded by the AHKER.E WORM!
    Win32 Services ConfigXwinwkys.exeAdded by the RBOT.BKY WORM!
    Win32 Services1Xwuamngr1.exeAdded by a W32/Sdbot-PV worm infection
    Win32 Src ServiceXwin32src.exeAdded by the W32/RBOT-SX WORM!
    Win32 SSL DriverXwinssv.exeAdded by the W32/FORBOT-BH WORM!
    Win32 Svchosts DriverXsvchosts.exeAdded by the W32/Forbot-FO WORM! Note: (svchosts.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (svchost.exe) should not be seen in Msconfig or as a Startup item. This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    win32 system serverXwinserver.exeAdded by the TROJ/DERMON-C TROJAN!
    Win32 System SpoolXspoolsvc.exe WORM_SDBOT.UK
    Win32 TestXbleatest.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 USB DriverXwinxpinit.exeAdded by the SDBOT.AA WORM!
    Win32 Usb DriverXsvhosint32.exeAdded by the W32/FORBOT-BE WORM!
    Win32 USB DriverXmvsecn.exeAdded by the W32/FORBOT-BK WORM!
    Win32 Usb DriverXusb32.exeAdded by the W32/SDBOT-OV WORM!
    Win32 USB DriverXwinxpinit.exeAdded by the BACKDOOR.SDBOT.AA TROJAN!
    Win32 Usb DriverXAvpG.exeAdded by the W32/FORBOT-BX WORM!
    Win32 USB2Xwins32.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 USB2 DriverXsmsc.exeAdded by the SDBOT.FO WORM!
    Win32 USB2 DriverXsys32.exe WORM_WOOTBOT.X
    Win32 USB2 DriverXwin32usb.exe W32.Spybot.DHV worm
    Win32 USB2 DriverXwind32.exe W32/Forbot-AH worm
    Win32 USB2 DriverXsvchosting.exeAdded by a W32/Forbot.J or SDBOT.HU worm infection
    Win32 USB2 DriverXwinupdate.exeAdded by the AGOBOT.YE WORM!
    Win32 USB2 DriverXsys32snd.exeAdded by a W32/Forbot-AN worm infection
    Win32 USB2 DriverXupdatemgr.exeAdded by a variant of the W32/FORBOT WORM!
    Win32 USB2 DriverXwinsnd32.exeAdded by a variant of the W32/SDBOT WORM!
    Win32 USB2 DriverXmsn.exeAdded by the W32/FORBOT-EX WORM!
    Win32 USB2 DriverXsyscfg32.exeAdded by the W32/FORBOT-R WORM!
    Win32 USB2.0 DriverX386.exeW32.IRCBot.D worm
    Win32 USB2.0 DriverXw32usb2.exe WORM_SPYBOT.DN
    Win32 USB2.0 DriverXrundll16.exe WORM_WOOTBOT.H
    Win32 USB2.0 DriverXservice.exeAdded by the W32/SDBOT-QF WORM!
    Win32 USB3 DriverXwin32tool.exeAdded by a variant of the WIN32.RBOT WORM!
    Win32 Wmls DriverXwinitr32.exeAdded by the WOOTBOT.B worm
    Win32 Word ServicesXmsword32.exeAdded by a variant of the WIN32.RBOT WORM!
    win32.exeXwin32.exeAdded by the STARTPAGE VIRUS!
    Win32.exeXWin32.exeAdded by the BKDR_AWQ.A TROJAN!
    win32appXwinpup32.exeAdded by the ADCLICKER VIRUS!
    Win32BaseServiceMODXWintask.exeAdded by the NAVIDAD VIRUS!
    win32betaXwin32sys4.exeAdded by the Troj/Banker-DA Trojan!
    win32clfXwin32clf.exeAdded by an unidentified VIRUS!
    Win32DLLXWin32DLL.vbsAdded by the LOVELETTER (I LOVE YOU) VIRUS!
    Win32dllXWin32dll.exeAdded by the BANPAES VIRUS!
    WIN32DSXclienttimer.exeAdded by Eziin adware
    Win32GXKernel32.comScandisk.comAdded by the ESTRELLA VIRUS!
    win32gbXwin32gb.exeAll-In-One-Telcom (adult content dialler) variant
    Win32Host ProcessXwebemir.exeAdded by the Troj/Turgen-A TROJAN!
    win32infoXwin32info.exeAdded by a Win32.Dluca.C downloader trojan infection
    win32iniXsystroy.exeAdded by the IRC.ALADINZ.C VIRUS!
    WIN32ioXclienttimer.exeAdded by Eziin adware
    Win32RXServer.comAdded by the ESTRELLA VIRUS!
    WIn32S Java DLLXkavsvx.exeAdded by the W32/AGOBOT-RZ WORM!
    win32servvXms1.exe iSearch adware component
    win32servvXload.exeAdded by an unidentified trojan or adware
    WIN32SLYWin32sl.exePart of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. The specific function of this is to load MIF's in order for Dell OpenManage Client to work
    WIN32SNDSXbanc.exeAdded by an unidentified WORM or TROJAN!
    Win32systemX(random filename)Added by the DDV.B VIRUS!
    Win32SystemXwin32s.exeAdded by the W32.Mydoom.V WORM!
    Win32SystemMonitorX***.exe (* = random char)browser hijacker
    Win32SysVXxin.exeAdded by the W32/FORBOT-EO WORM!
    win32usXwin32us.exe All-In-One-Telcom (adult content dialler) variant
    win32usbdXssrs.exeAdded by the W32/RBOT-RA WORM!
    WIN32WNXsystem_wc.exeAdded by Eziin adware
    win32_i lptt01 or win32_i ml097eXwin32_i.exeVariant of the RapidBlaster parasite (in a "win32_i" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    Win386XWin386.exeAdded by the GOSUSUB VIRUS!
    Win386Xsp32.dllHomepage hijacker. Not a dll but a regfile in disguise
    WIN3S2SNDSXwinabsmod.exe, winiprtx.exeAdded by a TrojanDownloader.Win32.Agent.dn infection; known to BOClean as "CWS/INDEX" , "shuts down anything that wants to open and is used as a spam proxy as well"
    Win64 Compatibility CheckXload win64.drv CoolWebSearch parasite related.
    WIN95DEFVIEWXcsmss.exeAdded by the TROJ/DEDLER-D TROJAN!
    win98 DNSXwingrd.exeAdded by a variant of the WIN32.RBOT WORM!
    WinAC v4Xklsuicbn.exeAdded by the W32/FORBOT-CS WORM!
    WinacsrUWinacsr.exe AceScreenSpy keystroke logger/monitoring program - remove unless you installed it yourself!
    winactiveXWINACTIVE.EXEActive variant of LOP.com hijacker - see here
    WinActiveJXWinActiveJ.exeAdded by the ROTARRAN VIRUS!
    Winad ClientXWinad.exeWinAd adware by eXact Advertising
    WinAdCnt.exeXWinAdCnt.exeAdded by the TROJ/BANKER-BU TROJAN!
    winadmXwinadm.exeBrowser hijacker - redirecting to Search-World.net. Related to the SMALL.LR TROJAN!
    WinAgent?WinAgent.exeStandard Life Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup.
    Winahlp.exeXWinahlp.exeAdded by a variant of the VAGRNOCKER VIRUS!
    winallapXwinallap.exeAdded by the DELF.E VIRUS!
    winallapuXwinallapu.exeAdded by the DELF.E VIRUS!
    WinampXwinamp.htare-directing to adult content sites. Note - this isn't the real Winamp
    winampXwinamp.exeAdded by the AGOBOT-MC WORM! Note - this is NOT the Winamp Media Player (WinAmpa.exe)
    WinAMPXwinamp62.exeAdded by the W32/SDBOT-WN WORM!
    Winamp AgentXwinamp.exeAdded by the W32/POEBOT-I WORM! NOTE - this is NOT the Winamp Media Player executable (WinAmpa.exe)
    Winamp media playerXwinapa.exeUnidentified worm
    WinAmp PlayerXwinampp.exeAdded by the W32/Rbot-AQI WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Winamp to Google TalkUwinamptogoogletalk.exeWinamp to Google Talk, available here shows your current Winamp track in your Google_Talk status
    Winamp Updateyhn.exeAdded by the W32/Sdbot-ACR WORM!
    WinampaUWINAMPa.exeLoads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
    WinampaXwinampa.exeAdded by the W32/AGOBOT-GS WORM!
    Winampa AgentXWINAMPA.EXEAdded by the W32/SPYBOT-BR WORM! - NOTE: this is NOT the Winamp Media Player, as described here
    WinampAgentUWINAMPa.exeLoads the System Tray icon for the WinAmp media player. Can be used to mantain file associations so programs like QuickTime and RealPlayer don't take over as default player for various media types. Available via Start -> Programs
    WinAmpAgentXsvchst.exeAdded by the TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here
    WinAmpAgentXWinagent.exeAdded by the TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here
    WinAmpAgentXShch.exeAdded by the TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here
    WinAmpAgentXMsexploren.exeAdded by the TROJ/BDOOR-EB TROJAN! - NOTE: this is NOT a WinAmp mediaplayer file, as described here
    WinAmpAgentXwinagent.exeAdded by the WIN32.TACTSLAY.B TROJAN!
    WinAntiSpyware 2005Xwas5.exeWinAntiSpyware: MALWARE, posing as a spyware remover - for more information, search the Spywarewarrior_List of non-Recommended anti parasite sites/software for "WinAntiSpyware 2005"
    WinApiXwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
    WINAPLOGUPDXWINAPLOGUPD.EXEAdded by the W32/CAPSIDE-C WORM!
    WinappXwinpup32.exeProduces popup ads to adult content sites
    WinApp32Xmsapp.exeAdded by the RSBOT VIRUS!
    WinAppLogUsvchost.exe StingKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! - NOTE - this file is placed in a C:\Program Files\StingWare folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    WinAuthXwinlogon.exeHijacker, also indentified as the STRTPAGE.BE TROJAN!
    WinAwkXWinAwk.exeAdded by the 2/SDBOT-AYF WORM!
    WinBackup SchedulerUWbsched.exeLIUtilities WinBackup scheduler - backup software
    WinBarUWinBar.exe"WinBar is a free and compact program that lets you monitor your system and provides easy access to frequently used controls"
    winbar.pifXpacke.pifAdded by the W32/Rbot-AVI WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    winbas12Xwinbas12.exeAdware, CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    winbas12Xwinbas12.exeAdware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du
    WinbedXwinbed.exeHijacker
    WinbinXswchost.exeAdded by the RBOT.CLS WORM!
    winbin32Xwin32exe.exeAdded by the W32/RBOT-ZL WORM!
    winbotXwinbot.exeAdded by the Troj/Midrug-A TROJAN!
    WinCheckXWinCheck.exeAdded by the PWS-CY VIRUS!
    WinCheckXservices.exeAdded by the W32.Sober.S WORM! Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.
    winchostXwinchost.exeAdded by the Troj/Dloader-PV TROJAN!
    WINCINEMAMGRNWinCinemaMgr.exe WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    WINCINEMAMGRNWINCIN~1.EXE WinCinema_Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs
    wincmapXwincmapp.exeCasClient adware variant - also known as Trojan.Cmapp
    wincmsXwincms.exeAdded by the RBOT.CBR WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot. Name field may be empty.
    WinCRT32Xwincrt32.exeAdded by the W32/Dogbot-D WORM! Note: This worm\trojan file is found in the System\CRT (95/98/ME) or System32\CRT (NT/2000/XP) folder.
    WinCSRSSXMSGRT32.EXEAdded by the Troj/Rewindo-A TROJAN!
    WINCXXwincore332.exeAdded by the W32/AGOBOT-MG WORM!
    Wind Logd FileXservicelogd.exeAdded by a variant of the WIN32.RBOT WORM!
    Wind SecurityXmswi32.pifAdded by the W32/Rbot-ARH WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    wind.exeXwind.exeThis Trojan allows the infected computer to be used as a proxy mail server. Trojan horse Proxy.5.AP, TrojanProxy.Win32.Mitglieder.bd More info on TrojanProxy
    WIND0WSXWIND0WS.exe WORM_SPYBOT.DQ
    WIND0WSXmella.batAdded by the VBS.ALLEM WORM!
    Wind0wsXwordpad.exeAdded by the W32/Agobot-TL WORM! Note: This is not the legitimate Windows application wordpad.exe (Which is found in the Program Files\Accessories folder.) The legitimate Windows application should not be seen in Msconfig or as a Startup item. This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Wind0ws SharingXssprotecter.exeAdded by the W32/RBOT-AHW WORM!
    WinDatesNwindates.exeWinDates is a calendar, date organizer and event reminder program from Rockin\' Software
    windbsXwinxtc.exeAdded by the W32/Agobot-WD WORM!
    WindeXwinde.exeAdded by the DLUCA VIRUS!
    windefXWin32sp.vbs -quietAdded by the W32.ANPES WORM!
    windefXwindef.exeAdded by the W32/Wurmark-O WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder, and replaces taskmgr.exe with the copy of itself.
    Windeows NetStart Service2Xtesakrmger.exeAdded by the W32/Rbot-AMY WORM!
    windhost.exeXoswin32.exeAdded by an unidentified password-stealing "Banker" TROJAN!
    windhost.exeXosrwin32.exeAdded by the BANKER-CB TROJAN!
    windhost.exeXwinos.exeAdded by the TROJ/PWSAGENT-A WORM!
    windhost.exeXwindhost.exeAdded by the TROJ/BANKER-BV TROJAN!
    windirXwinrun.exeAdded by the WINBUR.B VIRUS!
    WindllXWindll.exeAdded by the TRYNOMA VIRUS!
    WINDLLUWSYS.EXESTARR key logger. "It logs almost everything that goes through the box. It logs all key strokes, all passwords transacted even if they weren\'t keyed in, all web sites visited, every program launched including the path to that program, and more"
    windllXwindll32.exeAdded by the ASTEF or RESPAN VIRUSES!
    Windll.exeXWindll.exeAdded by the STEALER VIRUS!
    Windll32XWindll32.exeAdded by the MSNPWS VIRUS!
    WinDll32X_WIN32.EXEAdded by the LEGMIR.AQ TROJAN!
    windllsys32.exeXwindllsys32.exeAdded by a variant of the Win32.Mitglieder.by TROJAN!
    WinDNSXwindns32.exeAdded by the GAOBOT.WX WORM!
    Windoes KernelXkernel32.exeAdded by the KICKIN.A (or CYDOG.C) VIRUS!
    WindowXexplore.exeAdded by the GAOBOT.ADW WORM!
    Window LoaderXDos32.exeAdded by the GAOBOT.AO WORM!
    Window MonitorXwinmon32.exeAdded by a SDBOT.RT worm infection
    Window serviceX[random file name]Added by the W32/RBOT-ACH WORM!
    Window WasherUwwDisp.exeWebroot Window Washer - "Wash away online and offline traces of PC and Internet activity to protect your privacy and improve PC performance"
    window.exeXwindow.exeAdded by the MITGLIEDER.H or MITGLIEDER.J VIRUS!
    window2Xssvchost.exeAdded by the IRCBOT.H VIRUS!
    WindowBlindsUwbload.exeWindowBlinds from Stardock. Skin application to change the appearence on Windows desktops. Available as an individual download or as part of Object Desktop. Required to restore settings if you use it. Available via right-click on the Desktop -> Properties -> Skins
    WindowEnhancerXWinex.exeSCbar foistware variant
    WindowFXUwfxload.exeStardock WindowFX - "Allows you to add an unprecedented number of special effects to windows"
    windownXwiusyt.exeAdded by the Troj/QQPass-M TROJAN!
    WindowRegKey updateXwins.exeAdded by the SPYBOT.I WORM!
    WindowsXKernel32.exeAdded by the TENDOOLF VIRUS!
    WindowsXmsdos98.exeAdded by the PWSTEAL VIRUS!
    WindowsXWindows.exeAdded by the KAZMOR, BOBBINS& ALADINZ.D VIRUSES!
    WindowsXexplorer.exeAdded by an unidentified VIRUS! Note - this is not the valid Windows Explorer (explorer.exe). It was found in the C:\Windows directory on a WinNT machine and the wheras the valid explorer.exe would be found in C:\Winnt
    windowsX(path to trojan)Added by the AIMWIN VIRUS!
    windowsXhkey.exeAdded by the GAOBOT.AFW WORM!
    WindowsXservices.exeAdded by the W32/Sober-Z WORM!
    windowsXsystem copy.exeAdded by the W23.SALGA.A WORM!
    WindowsXsystem.exeAdded by the W32.Spybot.OBB WORM!
    WindowsXrun.exeAdded by the W32.SPYBOT.OFN WORM!
    WindowsXgearsec.exeAdded by the W32/STUBBOT-B TROJAN!
    WINDOWSX\windows.exeAdded by the Troj/Monbot-A TROJAN!
    WindowsXexplorer.exe Troj/Bancban-HJ is a password-stealing TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows (random character)Xdiskcheck.exeAdded by the BACKDOOR.SINGU.B TROJAN!
    Windows .Net ManagerXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Windows .Net ManagerXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Windows 128 ModuleXwin128.exeAdded by the W32/FORBOT-ES WORM!
    Windows 2004XCSRSS.exeAdded by a Troj/Banker-DY trojan infection
    Windows 32 EditorXWin32edit.exeAdded by the WOOTBOT.GQ WORM!
    Windows 32 RescueXwin32resc.exeAdded by the W32/FORBOT-EU WORM!
    Windows 32 UpdateXWindows-Update.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows AcceleratorsUsetup.exeKeySpy keylogger (monitoring program). Given a "U" recommendation because it depends if you intentionally installed it. If you didn't treat it as "X" and uninstall or remove
    Windows AdControlXWinAdCtl.exeWindUpdates adware variant
    Windows AdServiceXWinAdServ.exeWindUpdates WinAdServ adware variant
    Windows AdStatusXWinStat.exeAdded by the W32.Bleshare!dr VIRUS!
    Windows AdToolsXWinAdTools.exeWindUpdates Windows_AdTools adware
    Windows Anti-Virus Built 32XAntiVirus32.exeAdded by the SDBOT-BG WORM!
    Windows API Control TaskXapitsk32.exeAdded by the W32.MYTOB.HI WORM!
    Windows Application LayerXwalg32.exeAdded by the AGOBOT.ATN WORM!
    Windows Application Layer GatewayXwalg32.exeAdded by the W32/AGOBOT-AAZ WORM!
    Windows ASN ServiceX[random file name]Added by the W32/AGOBOT-TC WORM!
    Windows ASN ServiceXrge.exeAdded by the W32/Rbot-AOK WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    windows auto updateXpenis32.exeAdded by the BLASTER (or MSBLAST.A) VIRUS!
    windows auto updateXmsblast.exeAdded by the BLASTER.B VIRUS!
    Windows Auto UpdateXwinupdater.exeAdded by the SDBOT.TF WORM!
    Windows auto updateXbazzi.exeAdded by the AHKER.E WORM!
    Windows auto updateXLSASS.exeAdded by the W32.AHKER.G WORM! - Note - this is NOT the legitimate Windows lsass.exe process, which should NOT figure in Msconfig/Startup!
    Windows Automatic UpdateXwuamgrder.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Automatic UpdatesXdvldr.exeAdded by the RBOT.MF WORM!
    Windows AutomaticUpdaterXrunddls.exeAdded by a variant of the WIN32.RBOT WORM!
    windows automationXmslaugh.exeAdded by the BLASTER.E VIRUS!
    Windows AutomationXmsdspr.exeAdded by the SOLAME.A VIRUS!
    Windows Autostart LoaderXnotepad32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows backupXsystemss.exe W32.SpyBot worm variant
    Windows Backup ConfigurationXIEXPLORER.exeAdded by the GAOBOT.AZ WORM!. Note - iexplorer.exe is not to be confused with Internet Explorer (iexplore.exe)
    Windows Baţlangýç DosyasýXsistem.exeAdded by the MUZK VIRUS!
    Windows BootupXms-wks32.exeAdded by the W32/Rbot-AFM Worm!
    Windows BootupXSystemwks32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows BootupXtask-mngr.exeAdded by the W32/Rbot-AWP WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Client Service 32Xcsrss.exeAdded by the W32/Rbot-ALB WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Windows Client/Server Runtime ServerXcsrs.exeAdded by the RBOT.KD WORM!
    Windows CommandXwincmd.exeAdded by the RBOT.ANV WORM!
    Windows CommunicatorXwincomm.exeAdded by the AGOBOT-BH WORM!
    Windows CompliantXwinole.exeAdded by a variant of the W32/SDBOT WORM!
    Windows CompliantX(random file name)Added by a W32/Rbot-IR worm infection
    Windows ConfigXSSYS.EXEAdded by a W32/Spybot-DA worm infection
    Windows ConfigXwins.exeAdded by the SPYBOT.JR WORM!
    Windows ConfigXRUNDLL.EXEAdded by the W32/SPYBOT-DX WORM! - - NOTE: this is NOT the Windows system file of the same name as described here
    Windows Config LoaderXWincfg32.exeAdded by the SILVERFTP VIRUS!
    Windows Config ManagerXwinconf.exeAdded by the W32/RBOT-AIT WORM!
    Windows ConfigurationXwsys32.exeAdded by the GAOBOT.FB WORM!
    Windows ConfigurationXwincfg32.exeAdded by the W32.Mytob.ED WORM!
    Windows connection managerXInternet.exeAdded by the W32/Rbot-APN WORM! Note: This worm\trojan file is found in the Windows or Winnt folder. Make sue you check the link on this one, it copies it's self under three other file names and folder locations.
    Windows Console MonitorX[path to worm]Added by W32.Kedebe WORM!
    Windows Console MonitorXgcasAV32.exeAdded by the W32/KEDEBE-A WORM!
    Windows ControlXControl.exeBrowser hijacker. NOTE - On Win9x systems it will overwrite the Windows file of the same name in the Windows directory, so therefore it will be necessary to extract a fresh copy of the file from the Windows setup cabs!
    Windows ControlAdXWinCtlAd.exeWindUpdates WinCtrlAd adware
    Windows CPU hostXwinbog32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Data ServerXautodisc.exeAdded by the W32/SPYBOT-CB WORM!
    Windows Data ServerX(Random name).exeAdded by the W32/Spybot-DS WORM!
    Windows DatabaseXWinDat.exeAdded by an unidentified WORM or TROJAN!
    Windows DatabaseXwiinsvc.exeAdded by the W32/AGOBOT-RU WORM!
    Windows Dcom2 FixXmscom32.exeAdded by the W32/RBOT-QT WORM!
    Windows DDE LoaderXwindde32.exeAdded by the W32/SDBOT-UZ WORM!
    Windows debug loggingXwinlogg.exeAdded by the W32/RBOT-OY WORM!
    Windows debug loggingXwinloggs.exeAdded by the W32/RBOT-QN WORM!
    Windows DebuggerXwindbg.exeAdded by an unknown worm or trojan infection!
    Windows DebuggerXmsdbg32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows DebuggerXwindbg32.exeAdded by the W32.Mytob.MC WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Debugging ToolsXupdatecfg.exeAdded by the W32/Rbot-AXU WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WINDOWS DENEMEXdeneme.exeAdded by the W32/Mytob-CR WORM!
    Windows Desktop ControlerXwindesktop.exeAdded by the W32/SDBOT-XH WORM!
    Windows Desktop DaemonXwinpadg.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows Dialup ServiceXdialup.exeAdded by the AGOBOT.AAH WORM!
    Windows DLL hostXwinupd32.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows DLL HostXdllhost32.exeAdded by an unidentified WORM or TROJAN!
    Windows DLL LoaderXRUNDLL16.EXE, SYSCFG16.EXEAdded by the DOMWIS VIRUS!
    Windows DLL LoaderXPASSCFG16.EXEAdded by a W32/Domwis-C IRC backdoor worm infection
    Windows DLL LoaderXdefragfat32z.exeAdded by the W32/EGGDROP-G WORM!
    Windows DLL LoaderXrundll32.exeAdded by the W32/WHIPSER-B WORM! - NOTE: This particular rundll32.exe file is placed in the Windows\System folder, wheras the legitimate Windows file of the same name is located in the Windows folder on Win 98 or ME systems, and in Winnt\System32 or Windows\System32 in Windows 2000 or XP
    Windows DLL LoaderXdefragfat32pi.exeAdded by the W32/RBOT-QQ WORM!
    Windows DLL LoaderXdefragfat39.exeAdded by the W32/POEBOT-C WORM!
    Windows DLL LoaderXdefragfatz.exeAdded by the W32.LINKBOT.H WORM!
    Windows DLL LoaderXdefragfatx.exeAdded by the W32/POEBOT-F WORM!
    Windows DLL LoaderXdefragfat32.exeAdded by the W32/SDBOT-SS WORM!
    Windows DLL LoaderXdefragfat32abc.exeAdded by the W32/RBOT-RG WORM!
    Windows DLL LoaderXwdevice.exeAdded by a variant of the W32/SDBOT WORM!
    Windows DLL LoaderXWINCFG32.EXEAdded by the W32/Agobot-TE WORM!
    Windows DLL LoaderXSYSCFG16.EXEAdded by the W32/Domwis-N WORM!
    Windows DLL ServicesXwinsvc32.exeAdded by the W32/RBOT-ZF WORM!
    Windows DLL ServicesXsystem.exeAdded by the TSPY_AGENT.H spyware.
    Windows DLL TrackerXspoolsrv.exeAdded by a variant of the W32/WOOTBOT WORM!
    Windows DLL VerifierXxptl.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows DNSXwindns.exeAdded by the W32/SDBOT-XU WORM!
    Windows DNS DaemonXwindnsd.exeAdded by the WOOTBOT.AS WORM!
    Windows Domain Name DriversXwindns.exeAdded by the W32/FORBOT-EP WORM!
    Windows DOSXdosw.exeAdded by the W32/Salay-A WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Download ManagerXwindlmngr.exeAdded by an unidentified TROJAN!
    Windows Drive CompatibilityXSystem32Driver32.exeAdded by the SUPOVA.Z VIRUS!
    Windows DriverXwinxpdriver.exeAdded by the WOOTBOT.EE WORM!
    Windows Driver AdapterXsvchost.exe /driver-autoAdded by the W32/Antinny-K WORM!
    Windows Driver ServicesXmsdrvs32.exe WORM_WOOTBOT.L
    Windows driver updateXdmsvc32.exeAdded by a W32/Sdbot-GP worm infection
    Windows drivers updateXwindowsupdate.exeAdded by the W32/RBOT-ACE WORM!
    Windows Dynamic Loading HeaderXwinDLL32.exeAdded by a variant of the W32/SDBOT WORM!
    Windows ExecutableXwinmys.exeAdded by the W32/RBOT-ABO WORM!
    Windows ExpIorerX(Random filename)Added by the W32/Rbot-AKO WORM!
    Windows ExplorerX(filename).exeAdded by the SDBOT WORM! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
    Windows ExplorerXLsas.exeAdded by the GAOBOT.AO WORM! **Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually
    Windows ExplorerXolecom32.exeAdded by an unidentified WORM or TROJAN!
    Windows ExplorerXEEXPLORER.EXEAdded by a variant of the W32.SPYBOT WORM!
    Windows ExplorerXexplorer.exeAdded by the W32/POEBOT-J WORM! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)
    Windows ExplorerXsystem32.exeAdded by the W32/Rbot-AJH WORM!
    Windows ExplorerXexplorer.pifAdded by the W32/Rbot-AID WORM!
    Windows Explorer ShellXWinexec32.exeAdded by the REDIST.B VIRUS!
    Windows Explorer SP2Xcsrss.exeAdded by the Troj/Banker-DM Trojan!
    Windows Explorer Update Build 1142XEXPLORER32.EXEAdded by the KaZaA based KWBOT or KWBOT.Y VIRUSES!
    Windows Explorer-3212XWINRE16.EXEAdded by the HARDOC VIRUS!
    Windows EyesN??For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hear it, and how you hear it. Available via Start -> Programs
    Windows FAT 32XWINFAT32B.exeAdded by the W32/SPYBOT-AGT WORM!
    Windows File ProtectionXwinprotect.exeAdded by the AGOBOT.JB WORM!
    Windows FirewalXLsess.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows FirewallXWindowsFirewall.exeAdded by the W32.MYTOB.AO WORM!
    Windows Firewall LogXwinlog.exeAdded by an unidentified WORM or TROJAN!
    Windows Firewall ManagerXmsfw.exeAdded by the RBOT.WR WORM!
    Windows FirewalllXsphost.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows FirewalllXsvvhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows FirewalllXwinmu.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows FirewalllXscvhost.exeAdded by the W32/RBOT-EK WORM!
    Windows FixXintegator.exeAdded by the SDBOT.ZAB WORM!
    Windows Fixes SystemsXelite.exeAdded by the W32.Mytob.EG WORM!
    Windows FormatAdXWinForm.exe Windupdates adware variant
    Windows Frame WorksXfrmwrks32.exeAdded by a variant of the WIN32.RBOT WORM!
    WINDOWS FUCK BY CLASICXfuck.exeAdded by the ZOTOB.H or W32.Zotob.J WORM!
    Windows Generic ProcXprocmsg.exeAdded by the W32.ALLIM.B WORM!
    Windows GMT32Xwingmt32.exeAdded by the MYTOB.KM WORM!
    Windows Graphics LoadersXwingraphics.exeAdded by the SPYBOT.JG WORM!
    Windows GuardianUthehel1iawgrd32.exeFawgrd32.exePart of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes
    Windows HelpXmailinfo.exeAdded by the MYTOB.JX WORM!
    Windows Help FileXwinhelper32.exeAdded by the W32/SDBOT-QK TROJAN!
    Windows Help ManagerXsvchost32.exeAdded by the W32/RBOT-OZ WORM!
    Windows Help ServiceXwinhelpsv.exeAdded by the W32/Rbot-LP WORM!
    Windows Help ServiceXwinhlp.pifAdded by the W32/Rbot-AKW WORM!
    Windows Help System?Help.pif??
    Windows HostXhosts.exeAdded by the W32.KELVIR.U WORM!
    Windows HostXwinhost.exeAdded by the BACKDOOR.PRYSAT TROJAN!
    Windows Host DeviceXhostsvc.exeAdded by a W32/Zooty-A worm infection
    Windows Host NameXlmass.exeAdded by the GAOBOT.O WORM!
    Windows Host ServiceXscvhosts.exeAdded by the W32.SPYBOT.NLI WORM!
    Windows Host ServiceXhost.exeAdded by W32.Kelvir.AN WORM!
    Windows Host ServiceXsvchosts32.exeAdded by the W32.KELVIR.AW WORM!
    Windows Host ServiceXsvchoste.exeAdded by the W32.KELVIR.BF WORM!
    Windows Host ServiceXsvchosts32.exeAdded by the W32/Kelvir-AK WORM!
    Windows Host32 StarterXhostserv.exeAdded by the W32/SDBOT-WU WORM!
    Windows HostsXhosts.exeAdded by the KELVIR-O TROJAN!
    Windows HTML file readerXSysconf32.exeAdded by a NOOMY.A worm infection
    Windows Icons ManagerXwicomgr.exeAdded by the W32/Rbot-AIF WORM!
    WINDOWS ID SYSTEMXwID32.exeAdded by the MYTOB.LN WORM!
    Windows iMessenger MessengerXwinimsg.exeAdded by the W32.ALLIM.A WORM!
    Windows IncontextXInSearch.exe Z-Quest adware downloader/installer variant
    Windows installerXwinstall.exe SpySheriff malware. For more information on registry key changes see Troj/Spywad-G
    Windows InstallerXntdll.exeAdded by an unidentified WORM or TROJAN!
    Windows installerXwinstall.exeAdded by Troj/Spywad-F TROJAN!
    Windows Internet ProtocolXwinproc32.exe CoolWebSearch parasite related.
    Windows Internet ProtocolXdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
    Windows Internet ServiceXwininet.exeAdded by W32/Rbot-AUX WORM!
    Windows IPv6 DriversXwipv6.exeAdded by the W32/SDBOT-VJ WORM!
    Windows Java UpdateXweatherBug32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows JavaScript DaemonXWinjsd.exeAdded by a WOOTBOT.AF worm infection
    Windows Kernel 64Xkernal64.exeAdded by the W32/Yimp-B WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows kev MessengerXmskev.exeAdded by the W32/SDBOT-XV WORM!
    Windows Load?windows.com??
    Windows LoaderXwstart32.exeAdded by the GAOBOT.CA WORM!
    Windows Loader ServiceXcivsc.exeAdded by a variant of the WIN32.RBOT WORM!
    windows LoadxmXWin_.exeAdded by the Troj/Fodder-A TROJAN!
    Windows Local ServicesXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Local ServicesXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Windows LoggerXwinlog.exeAdded by the Troj/Nshadow-B TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows loggingXwinlogd.exeAdded by the W32/RBOT-ON WORM!
    Windows LoginXexplored.exeAdded by the W32.Gaobot.SY worm
    Windows LoginXwinlog.exeAdded by the AGOBOT.MG WORM!
    Windows Login FolderXwinzep.exeAdded by W32/Agobot-TZ WORM!
    Windows Login SecurityXwinlogin.pifAdded by an unidentified WORM or TROJAN!
    Windows Login ServiceXwinlog.exeAdded by the W32/Rbot-AFN Worm!
    Windows Login ServiceXwinlogin.pifAdded by the W32/Sdbot-ACU WORM! Note: This worm/trojan file (winlogin.pif) is found in the Windows or Winnt folder.
    Windows LogonXwinlogin.exeAdded by the TROJ/SPYBOT-C TROJAN!
    Windows Logon ApplicationXWinIogon.exeAdded by the "Cruel Intentionz" backdoor TROJAN!
    Windows Logon ApplicationXlogon.exeAdded by the W32/POEBOT-J WORM!
    Windows Logon ApplicationXWinIogon.exeAdded by the W32.LINKBOT.M WORM!
    Windows Logon ApplicationXservices.exeAdded by the Troj/Ciadoor-L TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
    Windows Logon ManagerXlogon.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Logon ProcedureXSvchoste.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows Logon ProcedureXSvchosta.exeAdded by a variant of the W32.SPYBOT WORM!
    windows logon procedureXwinlogonpc.exeAdded by the "WinLogon" TROJAN!
    Windows Logon ServiceXwinlogon.pifAdded by the W32/Rbot-AOU WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows Management InstrumentationXmwd.exeAdded by the GRAPS VIRUS!
    Windows Management InstrumentationXwmimgr.exeAdded by W32.Qdens.A Trojan!
    Windows Management InstrumentationX[path to file]Added by the W32/QEDS-A VIRUS!
    WINDOWS MANAGEMENT SYSTEMXwm1exe.exeAdded by the W32/RBOT-VT WORM!
    Windows ManagerXwinmants.exeAdded by the MANTAS VIRUS!
    Windows ManagerXwinsrv.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Windows Manager Update IncXtgb.exeAdded by the W32/Sdbot-ACM WORM!
    Windows mangementXwinlogonn.exeAdded by the RANDEX.FC VIRUS!
    Windows Media APXwinmapp.exeAdded by an unidentified WORM or TROJAN!
    Windows Media APPXwmapp.exeAdded by an unidentified WORM or TROJAN!
    Windows Media DriverXmsnger.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media PlayerXwmediaplayer.exeAdded by the W32/AGOBOT-NQ WORM!
    Windows Media PlayerXWMP23.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media PlayerXMediaPIayer.exeAdded by the SDBOT-QO TROJAN! - (note, the executable is called 'MediapIayer', with an 'i' !)
    Windows Media PlayerXmsass43.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media PlayerXmsa.exeAdded by the W32/RBOT-SI WORM!
    Windows Media PlayerXmcafe32.exeAdded by the W32/RBOT-YO WORM!
    Windows Media PlayerXmpwe.exeAdded by the W32/RBOT-TT WORM!
    Windows Media PlayerXwmplayer.exeAdded by the W32.Kelvir.G or W32.Kelvir.H or W32.Kelvir.I WORM!
    Windows Media PlayerX50cent.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media PlayerXmsams.exeAdded by the RBOT.AHR WORM!
    Windows Media PlayerXvalentine-jessica.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media Player 3.6Xwmpa36.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media Player 3.6bXWMPA36B.EXEAdded by the W32/RBOT-VV WORM!
    Windows Media Player 3.6dXwmpa36d.exeAdded by the W32/RBOT-YA WORM!
    Windows Media Player 3.6dXwmpa36d.exeAdded by the W32/RBOT-YA WORM!
    Windows Media Player 3.9Xwmpa36.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Media Player UpdateX[random filename]Added by the RBOT-ET WORM!
    Windows Media Powerpoint HelperNNSPPTHLP.EXEGerman software (comes with some Toshiba CD writers) that helps convert Powerpoint files to ASF (Streaming Media) files. Available via Start -> Programs
    Windows media serviceXcrvss.exeAdded by the SDBOT.VP WORM!
    Windows media serviceXcrsss.exeAdded by the RBOT.ACY WORM!
    Windows media servicesXcvrsss.exeAdded by the W32/RBOT-MW WORM!
    Windows Media SP.2.37X(random filename)Added by the LEMIR.C VIRUS!
    Windows Media UpdaterXcrease.exeAdded by the W32/Rbot-ATI and W32/Rbot-AVA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Media UtilityXwmediautil.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows MessengerXmsmsgs.exeAdded by a W32/Forbot-BD worm infection
    Windows messengerXmessengers.exeAdded by the W32.Mytob.EI WORM!
    Windows MessengerXmsnsmgs.exeAdded by the W32/RBOT-ANJ WORM!
    Windows Messenger MessengerXwinmsg.exeAdded by W32.Velkbot.A WORM!
    Windows Messenger ServiceXwinsmsgr.exeAdded by the W32/RBOT-VW WORM!
    Windows Messenger ServiceXkaspersky.exeAdded by the MYTOB.HY WORM!
    Windows MeTaLRoCk serviceXmetalrock.exeAdded by the TASTYRED VIRUS!
    Windows Micro DriversXwupdates32.exeAdded by the W32/Rbot-AEH Worm!
    Windows MonitorXwinmon.exeAdded by a SDBOT.VB worm infection
    Windows MonitorXarsetup.exeAdded by the WIN32.SPAZBOX.A TROJAN!
    Windows Monitor ServicesXwinmonitor.exeAdded by the W32/RBOT-XX WORM!
    Windows Monitoring ServiceXwinmon.exeAdded by a variant of the W32/SDBOT WORM!
    Windows More ChoiceXTopContext.exe ZQuest adware
    Windows Mouse UtilitiesXmouseutils.exeAdded by the W32/RBOT-ABU WORM!
    Windows ms DriversXmsnup32.exeAdded by the W32/SDBOT-AAL WORM!
    Windows MSConfig Startup LoggerXwinlog.exeAdded by the RBOT.BCU WORM!
    Windows NetDDeXwrmana32.exeAdded by the W32.Mytob.IM WORM!
    Windows NetsXWinNET.exeAdded by the W32/RBOT-MO WORM!
    Windows NetStart ServiceXwinsN2S.exeAdded by the W32/RBOT-ZX WORM!
    Windows NetStart Service2XwinsN2S.exeAdded by the W32/RBOT-ABN WORM!
    Windows NetStart Service2XwinsN2SD.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Network ControllerXMqguard.exeAdded by the W32/Forbot-CL WORM!
    Windows Network ControllerXWinxPupd.exeAdded by the W32/FORBOT-DK WORM!
    Windows Network ControllerXwinmms32.exeAdded by the W32/FORBOT-ED WORM!
    Windows Network ControllerXwingmt.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Network ControllerXWin9x.exeAdded by the WOOTBOT.I WORM!
    Windows Network FirewallXfirewall.exeAdded by the W32/POEBOT-J WORM!
    Windows Network ServiceXwinvc32.exeAdded by the RBOT.RY WORM!
    Windows NetworkingXwinsys32.exeAdded by the GAOBOT.FL WORM!
    Windows NetworksXnetcog.exeAdded by the MYTOB.FH WORM!
    Windows Nivedia DriverXsysMGT.exe Win32.Rbot worm variant
    Windows NNTX(path to trojan)Added by the RANKY.E VIRUS!
    Windows NT 32Xntlogin32.exeAdded by the W32.RANDEX.BRD WORM!
    Windows NT LoginXntlogin32.exe WORM_SDBOT.WG
    Windows NT Login Session ManagerXWNSM.EXEAdded by the RBOT.BIV WORM!
    Windows NT Logon ApplicationXwinlogon.scrAdded by the W32/Rbot-ALP WORM!
    Windows NT Service NameXwinshock.exeAdded by the W32/RBOT-PK WORM!
    Windows NT Update ManagerXWinlogon.exeAdded by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital "o"
    Windows OEM ToolsXwinres32.exeAdded by a SPYBOT.FD worm infection
    Windows OLE Automation ServerXole32aut.vbe CoolWebSearch parasite related browser hijacker
    Windows Online UpdaterXdllman.exeAdded by the W32/Rbot-TE WORM!
    Windows PcXwinmgr.exeAdded by the W32/BIBOT-A WORM!
    Windows PDGXwinpdg.exeAdded by the W32/Rbot-ADW Worm!
    Windows PNPXwinpnp.exeAdded by the W32/Rbot-AKN WORM!
    Windows PNP ServerXpnpsrv.exeAdded by this variant of the W32/SDBOT WORM!
    Windows Print Spooler?SCVHOSTS.EXESuspicious due to the similarity to the valid "svchost.exe" file
    Windows Print SpoolerXNavAgent32.exeAdded by an unidentified VIRUS!
    Windows Print SpoolerXSVEHOST.EXEAdded by the SPYBOT.H VIRUS!
    Windows Process ManagerXwinproc.exeAdded by an unidentified WORM or TROJAN!
    Windows Processe ManagerXmspn32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows ProtectotXboxide.exeAdded by a variant of the W32/WOOTBOT WORM!
    Windows Reg ServicesXffservice.exeAdded by the Troj/Dloader-PL or Troj/Dloader-XM TROJAN!
    Windows Reg ServicesXlncom.exeAdded by the TROJ/PRORAT-O TROJAN!
    Windows Reg ServicesXlservice.exeAdded by the TROJ/PRORAT-O TROJAN!
    Windows Reg ServicesXwservice.exeAdded by the TROJ/PRORAT-O TROJAN!
    Windows Reg ServicesXfservice.exeAdded by the TROJ/PRORAT-D TROJAN
    Windows Reg ServicesXdservice.exeAdded by the TROJ/PRORAT-D TROJAN
    Windows Reg ServicesXssservice.exeAdded by the TROJ/PRORAT-D TROJAN
    WINDOWS REGISTER EDITXregistr32.exeAdded by an unidentified WORM or TROJAN!
    Windows Register SettingsXsvmhost.exeAdded by a variant of the W32/FORBOT WORM!
    Windows RegistryXmsnmsg.exe Win32.Rbot worm variant
    Windows RegistryXwinhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Registry CleanerXwinclean.exe W32.SpyBot worm variant
    Windows Registry Express LoaderXregexpress.exeAdded by the W32/FORBOT-CJ WORM!
    Windows Registry ManagerXtasksmanagers.exeAdded by the W32.Mytob.ER WORM!
    Windows Registry NameXwinses.exeAdded by the W32/Rbot-ADB Worm!
    Windows Registry NameX(Random filename)Added by the W32/Rbot-AEB Worm!
    Windows Registry ScanXregscan32.exe WORM_RBOT.KE
    Windows Registry ScanXregscan.exeAdded by a W32/Rbot-HA worm infection
    Windows Registry ScanXtimeupdate.exeAdded by the SPYBOT.JE WORM!
    Windows Registry ScanXsvcdll.exeAdded by the W32/RBOT-TP WORM!
    Windows Registry ScanXregscan23.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Registry SecurityXcrss.exeAdded by a variant of the BACKDOOR.IRC.BOT TROJAN!
    Windows Registry StartupXwind32.exeAdded by the W32/Agobot-BZ WORM!
    Windows RepairXtoxikx.exeAdded by the W32/Sdbot-ADL WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows reportXswchost.exeAdded by the Small-BD TROJAN!
    windows runXsystem.exeAdded by the W32/ICPASS-A WORM!
    Windows Run-Time 64bitXwin64rt.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Runtime HelpXwin32hlp.exeWinRunHelp.wrhAdded by a variant of the AIMVISION VIRUS!
    Windows Runtime ProccessX32RUNdll.exeAdded by the SDBOT.QW WORM!
    Windows SAXomniscient.exe BLAZEFIND adware
    Windows ScreensaverXService.exeAdded by the W32.KELVIR.P or KELVIR-L WORMS!
    WINDOWS SCREENSAVERXssaver.scrAdded by the W32/Sdbot-YZ Worm!
    Windows secureXsetver32.exe WORM_SPYBOT.EP
    Windows Secure ConnectionXwinsc.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Secure Messaging SystemXmsnmsgrsrvc.exeAdded by the W32/RBOT-RE WORM!
    WINDOWS SECURITYXwingrd.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows SecurityXwin.pifAdded by the W32/Rbot-APT WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows SecurityXms32.pifAdded by the W32/RBOT-ARN WORM!
    Windows Security AssistantXrundll32.vbe CoolWebSearch parasite related.
    Windows Security AssistantXwinsec.exe CoolWebSearch parasite related.
    Windows Security Authority ServiceXlsass.exeAdded by the W32/KALEL-A WORM! - NOTE - this should NOT be confused with the legitimate Windows lsass.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Windows Security ManagerXwinsecurity.exeAdded by the W32/AGOBOT-KI WORM!
    Windows Security ManagerXwinsecure.exe Affilred.B adware
    Windows Security ModuleXmodule.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Security ServiceX[random file name]Added by the W32/RBOT-ALV WORM!
    Windows Security UpdateXsecurity32.exe Affilred.B adware
    Windows Security UpdaterXWINFRW.exeAdded by the Solufina TROJAN!
    Windows Serv PatchXMcaffe2005.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows ServeAdXWinServAd.exeWindUpdates WinAd adware
    Windows Server InformationXservinfo.exeAdded by the W32/FORBOT-EN WORM!
    Windows Servic2Xwinsy.exeAdded by the W32/Rbot-AIA WORM!
    Windows ServiceXprvdi.exeMalware, recognized by Kaspersky antivirus as Trojan-Dropper.Win32.Small.rd
    Windows ServiceXdddd.exeIdentified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans
    Windows ServiceXpd7.exeAdded by the TROJ_SMALL.VZ TROJAN!
    Windows ServiceXsvvhost.exeAdded by the W32/AGOBOT-HL WORM!
    Windows ServiceXprivate-zone.exeAdded by an unidentified TROJAN.CLICKER !
    Windows ServiceXvideo.exeAdded by an unidentified TROJAN!
    Windows ServiceXdstart4.exeAdded by an unidentified TROJAN!
    Windows ServiceXpd14.exeAdware, detected by TDS-3 as "TrojanDownloader.Win32.Delf.dg"
    Windows ServiceXvideo2.exeAdded by the DOWNLOADER.SMALL.MY TROJAN!
    Windows ServiceXservices.exeAdded by the W32/KALEL-A WORM! - NOTE - this file should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    Windows ServiceXWINSVC.EXEAdded by the SDBOT.CL WORM!
    Windows ServiceXr.exeAdded by a variant of the TROJ_SMALL.VZ TROJAN
    Windows Service ControllerXservices.exeAdded by the W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Windows Service HostXscvhost.exeAdded by the SDBOT.N WORM!
    Windows Service HostXsvchost.exeAdded by the CONE.B VIRUS! This is not the valid svchost.exe as described here. Located in a Windows\Tasks directory, and not in Windows\System32
    Windows Service HostXsvchost.exeAdded by the W32/Kalel-C WORM! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the System folder.
    Windows Service Host ProcessX[path to file]Added by the W32/EZIO-A WORM!
    Windows Service LoaderXWindow.exeAdded by the W32/RBOT-XO WORM!
    Windows Service ManagerXuserint32.exeAdded by the W32/OSCABOT-C WORM!
    Windows Service ManagerXsvcmgr32.exeAdded by the W32/OSCABOT-D WORM!
    Windows Service ManagerXmsgs.exeAdded by the W32/OSCABOT-E WORM!
    Windows Service ManagerXmsnmrg.exeAdded by the W32/OSCABOT-G WORM!
    Windows Service ManagerXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service ManagerXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Service Pack Auto UpdateXwinworks.exeAdware downloader, identified by eScan antivirus as Trojan-Clicker.Win32.Agent.bt
    Windows Service Pack Auto UpdateXballin.exeAdded by an unidentified WORM or TROJAN!
    Windows Service Pack Auto UpdateXfiggaz.exeAdded by a TROJAN.CLICKER - identified by Kaspersky antivirus as Trojan-Clicker.Win32.Agent.bt
    Windows Service Pack Auto UpdateXdel-me.exeAdware, also detected as the Lowzones.BH TROJAN!
    Windows Service Pack2Xsvchhost.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Service Pack2XWIN43.EXEAdded by the GAOBOT.G WORM!
    Windows Service Support CallXSVSS32.EXEAdded by the W32/RBOT-XQ WORM!
    Windows Service UtitityXwinsrvc.exeAdded by the W32/Rbot-ASI or W32/Rbot-AUP WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Service XPXXpFirewall.exeAdded by the W32.MYTOB.AM WORM!
    Windows ServicesXservice.exeAdded by the RANDEX.R VIRUS!
    Windows ServicesXSpool32x.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows ServicesXExplorer.exeAdded by the W32/SDBOT-WT WORM! - NOTE - the valid "explorer.exe" file is located in C:\Windows or C:\Winnt, whereas this one is located in the Windows\System32 or Winnt\System32 folder!
    Windows ServicesXscvhoste.exeAdded by W32.Spybot.OBZ WORM!
    Windows ServicesXwinsvc32.exeAdded by the W32/MYTOB-CB WORM!
    Windows ServicesXscmsg.exeAdded by a variant of the W32/SDBOT WORM!
    Windows ServicesXNetworkDriver32.exeAdded by the W32/RBOT-ACR WORM!
    Windows ServicesXNetworkDrivers.exeAdded by the W32/Sdbot-YO Worm!
    Windows ServicesXsmsc.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Services HostXsvchost.exeAdded by the CONE or CONE.E VIRUSES!. This is not the valid svchost.exe as described here. Located in the Windows directory, and not in Windows\System32
    Windows Services HostsXsvhosts.exeAdded by the TROJ/SDBOT-YH TROJAN!
    Windows Services Ink Platform Tablet Input SubsystemXwsiptis.exeAdded by the RBOT.APC WORM!
    Windows Services UpdateXsvch0st.exeAdded by a variant of the WIN32.RBOT WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    Windows Session ManagerXsmss32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Session Manager SubsystemXsmss.exeAdded by the W32/Kalel-B WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Windows shell?win70.exe??
    Windows ShellXshell.exeAdded by the W32/MYTOB-CA WORM!
    Windows ShellXtaskgmr.exeAdded by the WIN32/MYTOB.BV WORM!
    Windows Shell Library LoaderXload shell.dll /c /set CoolWebSearch parasite related.
    windows shellext.32Xmschost.exeAdded by the BLASTER.K VIRUS!
    WINDOWS SKYXsky.exeAdded by the W32.MYTOB.CH WORM!
    Windows Smart ManagerXsmart.exeAdded by the W32/RBOT-SL WORM!
    Windows SocketheaderX[random filename]Added by the ANIXMA.A WORM!
    Windows Sound DriverXSndMon32.exe W32.SpyBot worm variant
    Windows Sound ManagerXSndMon32.exeAdded by the W32/FORBOT-BU WORM!
    Windows Sound ManagerXSndMon16.exeAdded by a variant of the W32/FORBOT WORM!
    Windows SP2 FirewallXwfirewall7.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows SP2 UpdateXSp2update.exeAdded by the WOOTBOT.BS WORM!
    Windows SP2 Version LoadXwuauclt32.exeAdded by the GAOBOT.CX WORM!
    Windows SP4XdirectCC.exeAdded by the W32/RBOT-ACX WORM!
    Windows Spool ServerXspoolsrv.exeAdded by the W32/Sdbot-ACT WORM! Note: This is not the legitimate Windows process spoolsv.exe (Notice the difference in the spelling). This trojan file (spoolsrv.exe) is also located in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows SpoolaPrint ServiceXspoolasrv.exeAdded by the W32/Sdbot-AYD WORM!
    Windows SpoolerXSPOOLSRV.EXEAdded by the SPYBOT.P VIRUS!
    Windows SpoolerXspoolsv32.exeAdded by an unidentified WORM or TROJAN!
    Windows Spooler ServicesXspool.exeAdded by the W32/AGOBOT-AMO WORM!
    Windows SpoolPrint ServiceXspoolersrv.exeAdded by the W32/Sdbot-ZT WORM!
    Windows Spools SVXwinsv.exeAdded by W32/Rbot-AUQ WORM!
    Windows spoolservr ServiceXspoolservr.exeAdded by the W32/Sdbot-AAN WORM!
    Windows Spoolsre ServiceXspoolsre.exeAdded by the W32/Sdbot-AAE WORM!
    windows spoolsrv serviceXspoolssv.exeAdded by the W32/Sdbot-AWV Worm!
    Windows Spoolsrv ServiceXspoolmsv.exeAdded by the W32/Sdbot-ZS WORM!
    Windows Spoolsurf ServiceXspoolsurf.exeAdded by the W32/SDBOT-ZZ WORM!
    Windows SpooltPrint ServiceXspooltsrv.exeAdded by the W32/SDBOT-AYE WORM!
    Windows Spoolvvv ServiceXspoolvvv.exeAdded by the W32/SDBOT-AAW WORM!
    Windows sq DriversXwinmsn32.exeAdded by the W32/Rbot-ADI Worm!
    Windows Sql Service For Windows 32 BitXwinsql32.exeAdded by the W32/FORBOT-FC WORM!
    Windows SSH ClientXwinssh.exeAdded by the W32/Rbot-AXC WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows SSL FileXwinssv.exeAdded by the WOOTBOT.CA WORM!
    Windows Stand Sound DriversXSounddrv.exeAdded by the W32/SDBOT-XF WORM!
    Windows Standard SecurtyX(Random 3-letter filename)Added by the W32/Rbot-ALF WORM! Note: May use DOZ.EXE for file name.
    Windows Start Server 2000Xtraficy.exeAdded by the W32/Rbot-AHM WORM!
    Windows StartupXwinsta~1.exe Go-Hip browser add-on
    Windows StartupXWdrun32.exeAdded by the GAOBOT.AO WORM!
    Windows StartupXservices21.exeAdded by the W32/Agobot-MX WORM!
    Windows StartupXwinstartup.exe Go-Hip browser add-on
    Windows Startup 32 BitsXsysrun32.exeDarkSun trojan variant
    Windows Streams ServerXlocalsrv.exeAdded by the SDBOT.LN WORM!
    Windows SubsysXwinload.exeAdded by the NETSPREE.C WORM!
    WINDOWS SVCXwinsvc.exeAdded by the W32/MYTOB-EY WORM!
    Windows SyncroAdXSyncroAd.exe Windupdates adware variant
    WINDOWS SYSTEMXnec.exeAdded by the W32/Mytob-L or W32/Mytob-CM and W32/Mytob-CN Worms!
    WINDOWS SYSTEMXxxx.exeAdded by the W32.Mytob.CZ WORM!
    Windows SystemXWINSYS.exeAdded by the W32/Mytob-M or W32/Mytob-EK WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    WINDOWS SYSTEMXbeta.exeAdded by the W32.Mytob.DF WORM!
    WINDOWS SYSTEMXtest.exeAdded by the W32.Mytob.DJ WORM!
    WINDOWS SYSTEMXtest2.exeAdded by the W32.Mytob.DJ WORM!
    WINDOWS SYSTEMXtest3.exeAdded by the W32.Mytob.DV WORM!
    WINDOWS SYSTEMXskybot.exeAdded by the W32/Mytob-CX or W32.Mytob.EB or W32/Mytob-BO or W32/Mytob-BP WORM!
    WINDOWS SYSTEMXwinsys33.exeAdded by the W32.Mytob.EK WORM!
    WINDOWS SYSTEMXmsdev32.exeAdded by the W32.Mytob.EH WORM!
    WINDOWS SYSTEMXdcomuser.exeAdded by the W32.Mytob.EO WORM!
    WINDOWS SYSTEMXwinligon.exeAdded by the W32.Mytob.EP WORM!
    WINDOWS SYSTEMXwinvnc.exeAdded by the W32.Mytob.EU WORM!
    WINDOWS SYSTEMXwin.exe.exeAdded by the W32.Mytob.FA WORM!
    Windows SystemXnibie.exeAdded by the W32.Mytob.FO WORM!
    WINDOWS SYSTEMXnec.exeAdded by the W32/Mytob-BH Worm!
    WINDOWS SYSTEMXninfoie.exeAdded by the W32/Mytob-EP Worm!
    WINDOWS SYSTEMXskybotx.exeAdded by the W32.Mytob.FT WORM!
    WINDOWS SYSTEMXsmoc.exeAdded by the W32.MYTOB.FU WORM!
    WINDOWS SYSTEMXwinxpserv.exeAdded by the W32/Mytob-BQ Worm!
    WINDOWS SYSTEMXsmsc.exeAdded by the W32/MYTOB-BR WORM!
    WINDOWS SYSTEMXwinmon.exeAdded by the W32.Mytob.GB WORM!
    WINDOWS SYSTEMXlf66prc.exeAdded by the W32.Mytob.GC WORM!
    WINDOWS SYSTEMXnibie.exeAdded by the W32/Mytob-BY WORM!
    WINDOWS SYSTEMXskybotx.exeAdded by the W32/Mytob-BY WORM!
    WINDOWS SYSTEMXwdns33.exeAdded by the W32/Mytob-BY WORM!
    WINDOWS SYSTEMXwinsvc32.exeAdded by the W32.MYTOB.HH WORM!
    WINDOWS SYSTEMXwinNTsys32.exeAdded by the W32/MYTOB-DM WORM!
    WINDOWS SYSTEMXwinaup.exeAdded by the W32/Mytob-DN WORM!
    WINDOWS SYSTEMXlogic.exeAdded by the W32.MYTOB.IC WORM!
    WINDOWS SYSTEMXmtrnqs.exeAdded by the W32.MYTOB.IG WORM!
    WINDOWS SYSTEMXgothica.exeAdded by the MYTOB.HU WORM!
    WINDOWS SYSTEMXmsnl.exeAdded by the W32.Mytob.IK WORM!
    WINDOWS SYSTEMXbotzor.exeAdded by the W32/ZOTOB WORM!
    WINDOWS SYSTEMXper.exeAdded by the W32/ZOTOB.C WORM!
    WINDOWS SYSTEMX\skybot.exeAdded by the MYTOB.JU WORM!
    WINDOWS SYSTEMXtwunk_65.exeAdded by the W32/MYTOB-EG WORM!
    WINDOWS SYSTEMXservises.exeAdded by the W32/Zotob-I WORM! Note: (servises.exe) is not the legitimate Windows Process. (Notice the difference in the spelling.) The legitimate Windows Process (services.exe) should not be seen in Msconfig or as a Startup item.
    WINDOWS SYSTEMXservce.exeAdded by the W32/Mytob-EI WORM! Note: This trojan/worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    WINDOWS SYSTEMXxpupdate.exeAdded by the W32/ZOTOB-G WORM!
    WINDOWS SYSTEMXsky.exeAdded by the MYTOB.LB WORM!
    WINDOWS SYSTEMXwinsvc.exeAdded by the MYTOB.LM WORM!
    WINDOWS SYSTEMXexpI0rer.exeAdded by the W32/Mytob-FI WORM! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Also, please note the spelling of this file as it is different from the Windows system file explorer.exe.
    WINDOWS SYSTEMXWin32IMAPSVR.exeAdded by the W32/Mytob-FQ WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows System 32-Bat ServiceXwin32bat.exeAdded by the W32.Mytob.FI WORM!
    Windows System BackupXSysBackup.exeUnidentified malware
    WINDOWS SYSTEM By FEnRXwindasz-updote.exeAdded by the MYTOB.LR WORM!
    WINDOWS SYSTEM CleanerXh3.exeAdded by the W32.Mytob.EQ WORM!
    WINDOWS SYSTEM CLEANERXiexplore.exeAdded by the W32.Mytob.ET WORM!
    Windows System ConfigurationXSYSCFG16.EXEAdded by the W32/Domwis-N WORM!
    Windows System ConfigurationXWinfrw.exeAdded by the BACKDOOR.SOLUFINA TROJAN or the W32/DOMWIS-J WORM!
    Windows System ConfigurationXPasscfg16.exeAdded by the DOMWIS-E TROJAN!
    Windows System ConfigurationXWINCFG32.EXEAdded by the W32/Agobot-TE WORM!
    Windows System ConfigurationXWinNeth.exeAdded by the W32/Rethe-A WORM!
    Windows System ConfigurationXwincfg.exeAdded by the AGOBOT.OP WORM!
    Windows System ConfigurationXnether.exeAdded by the W32/Opanki-AB WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    WINDOWS SYSTEM DnsXwindsns.exeAdded by the W32.Mytob.EY WORM!
    WINDOWS SYSTEM DNSPOOLXhbmail.exeAdded by the W32.MYTOB.FW WORM!
    Windows System FileXcmxp.exeAdded by the W32.Spybot.KHO WORM!
    WINDOWS SYSTEM FILEXwinload.exeAdded by the MYTOB.DK WORM!
    Windows System GatewayXSPOOLER.EXEAdded by a variant of the WIN32.RBOT WORM!
    Windows System InitXwinit32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows System ManagerXwinsystem.exeAdded by a W32/Rbot-AN worm infection
    Windows System ManagerXsysconf.exeAdded by the W32.MYTOB.AL WORM!
    Windows System ManagerXsmsc.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows System ManagerXcrssm.exeAdded by the W32/Rbot-AFH Worm!
    WINDOWS SYSTEM MANAGERXspoolsvc.exeAdded by the W32/Mytob-LY WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows System Manager LoaderXsmsls.exeAdded by the AGOBOT.TF WORM!
    Windows System Manager ProcXwinsmc.exeAdded by the RBOT.JH WORM!
    Windows System Manager ProcXwinsmc.exeAdded by the RBOT.JH WORM!
    WINDOWS SYSTEM MEMORY LOADERXmemloader.exeAdded by the W32/MYTOB-IN WORM!
    WINDOWS SYSTEM mscdvvsXmscdvvs.exeAdded by the MYTOB.MD WORM!
    windows system notepadXwnpsm.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    Windows System Restore ConfigurationXSblhost.exeAdded by a variant of the SPYBOT.GEN VIRUS!
    Windows System RestorerXSystemRestorer.exeAdded by the DULOAD.C VIRUS!
    Windows System SecurityXwinmp.exeAdded by the RBOT.IV WORM!
    Windows System Securitysys32.pifAdded by the W32/Rbot-AOL WORM! Note: This worm\trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows System Security MonitorX(4 random letters).exeAdded by the W32.Pinkton.A Worm!
    Windows System SerivceXwinserv.exeAdded by a variant of the Win32.Rbot WORM!
    windows system serviceXwinsock.exeAdded by the W32/RBOT-MR WORM!
    Windows System TrayUmsni.exeIambigbrother monitoring software
    Windows System TrayXswhost.exeUnidentified worm or trojan
    Windows System TrayUdlhost.exeRelated to IamBigBrother Internet monitoring software.
    WINDOWS SYSTEM UPDATEXxDcc.exeAdded by the W32/Mytob-EH WORM!
    Windows System32Xwindowsp.exeAdded by the MYTOB.GD WORM!
    Windows System32Xwinsys32.exeAdded by the W32/Sdbot-AHS WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows System32 KernelXsystem32.exeAdded by the W32/SDBOT-AAT WORM!
    WINDOWS SYSTEMnXservicces.exeAdded by the W32/Mytob-EL WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows SystemnmgXstagmr.exeAdded by the W32.MYTOB.S WORM!
    Windows Sz HostXwinshvc.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Task Manager Xtaskmngr.exeAdded by the W32/Rbot-ANM WORM! Note: This worm/trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows Task ManagerXACCOUNT_DETAILS.DOC.exeAdded by the QUATERS.A VIRUS!
    Windows Task ManagerXtaskmgn.exeUnidentified malware, either a variant of the WIN32.RBOT WORM, or part of a Casino Palazzo foistware install.
    Windows Task ManagerXtaskmrg.exeAdded by the W32.MYTOB.AV WORM!
    Windows Task ManagerXtaskgmr.exeAdded by the W32.Mytob.BJ and W32/Mytob-AJ WORMS!
    Windows Task ManagerXtaskmg.exeBrowser hijacker - identified by DrWeb antivirus as "Trojan.StartPage.601"
    Windows Task Manager EmulatorXkennewr.exeAdded by the W32/SPYBOT-FA WORM!
    Windows Task Manager-EmulatorXuswtme.exeAdded by a W32/Rbot-CG infection
    Windows Task SchedulerXasijdie.exeAdded by an unidentified WORM or TROJAN!
    Windows Task Service (32-bits)Xtasksys.exeAdded by the DREFIR.D WORM!
    Windows TaskAdXWintaskad.exeWindUpdates WinTaskAd adware variant
    Windows Taskbar ManagerX(path to file)Added by the W32.PROTORIDE.B WORM!
    Windows Taskbar ManagerXinternat.exeAdded by the PROTORIDE-H WORM!
    Windows TaskmanagerXlsassx.exeAdded by the W32.Kelvir.C or W32.Kelvir.E WORM!
    Windows TCP/IPXwintcp.exeAdded by the W32/AGOBOT-ZH WORM!
    Windows Telnet ServerXwintel.exeAdded by the W32/AGOBOT-MW WORM!
    Windows TimeXwinmgr.exeAdded by the W32/RBOT-XC WORM!
    Windows Time ServerXTimeSRV.exe W32.Spybot.DNC worm
    Windows TMXrundlI32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows TMXSVPHOST.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows TMXwindowssys32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows TMXWinxSys.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows UpateXrundll.exeAdded by the HAKO TROJAN! - NOTE: this is NOT the Windows system file of the same name as described here
    Windows UpdateX(random filename)Added by the NORIO VIRUS! Acts as a hi-jacker redirecting to adult content sites
    Windows UpdateXiexplorere.exeAdded by the GAOBOT.AP WORM!
    windows updateXuddater.exeAdded by the LEOX VIRUS!
    Windows UpdateXwudate.exeAdded by the AGOBOT.ML WORM!
    Windows UpdateXwupdate.exeWengs adware
    windows updateXsychost.exeAdded by the LEOX.B VIRUS!
    Windows UpdateXhost32.exeAdded by the W32/RBOT-GU WORM!
    Windows UpdateXWuamgrd.exe W32.SpyBot worm variant
    Windows UpdateXinetinf.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Windows UpdateXhost32.exeAdded by the W32/RBOT-GU WORM!
    windows updateXwuraclt.exeAdded by the W32/RBOT-PO WORM!
    windows updateXWuanclt.exeAdded by the RBOT.XZ WORM!
    windows updateXWruaclt.exeAdded by the RBOT.XZ WORM!
    windows updateXWuacrlt.exeAdded by the RBOT.XZ WORM!
    Windows UpdateXwindows.exeAdded by the W32/RBOT-RB WORM!
    Windows UpdateXebay.exeAdded by the W32.GAOBOT.BUU WORM!
    windows updateXwuaurlt.exeAdded by the RBOT.ADG WORM!
    Windows UpdateXwuampd.exeAdded by the RBOT.UM WORM!
    windows updateXwuaruclt.exeAdded by a variant of the WIN32.RBOT WORM!
    windows updateXwuaucrlt.exeAdded by the W32.SPYBOT.HUR WORM!
    Windows UpdateXmsnwinsb.exeAdded by the W32/RBOT-AAH WORM!
    windows updateXwuarclt.exeAdded by the W32/RBOT-OF WORM!
    Windows UpdateXwinupdate.exeAdded by the W32/SDBOT-WS WORM!
    Windows UpdateXscvhost.exeAdded by the W32/SDBOT-XT WORM!
    Windows UpdateXUpdate.exeAdded by the TROJ/DELF-FN TROJAN!
    Windows UpdateXtaskmr.exeAdded by the W32/Mytob-GZ Worm!
    Windows UpdateXwininfo.exeAdded by the W32.Mytob.GA WORM!
    Windows UpdateXwinlogin.exeAdded by the Troj/Banker-DV or Troj/Banker-FY or Troj/Banker-GB TROJAN!
    windows updateXMicrosoft.exeAdded by the TROJ_LMIR.A TROJAN!
    windows updateXmsnsever.exeAdded by the W32/RBOT-AHN WORM!
    Windows UpdateXupdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows UpdateXmplupdate.exeAdded by the W32.HLLW.MOEGA WORM!
    windows updateXlogonuit.exeAdded by the Troj/LegMir-AO TROJAN!
    Windows UpdateXqtask.exeAdded by the W32/RBOT-AKU WORM! - NOTE: do NOT confuse with the Quicken file of the same name as described here
    windows updateXreal.exeAdded by the TROJ/LEGMIR-AU WORM!
    Windows UpdateXmsnupdates.exeAdded by the W32/Rbot-ALK WORM! Note: This file has nothing to do with Windows updates or MSN.
    Windows UpdateXwindowsx.exeAdded by the TROJ/BANCD-A TROJAN!
    Windows UpdateXwupdmgr.exeAdded by the following Trojans: Troj/Banker-AHO - Troj/Bancban-FC - Troj/Bancban-GP - Troj/Bancban-GQ - Troj/Bancban-HB - Troj/Bancban-HC
    Windows updateXwudupdate.exeAdware downloader - Istbar related
    Windows UpdateXmsnsupdate.exeAdded by the W32/Rbot-AXS WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows Update 32Xwinlogons.exeAdded by the W32/Forbot-FI WORM!
    Windows Update 32Xslsys.exeAdded by a variant of the W32/FORBOT WORM!
    Windows Update 32Xrempss.exeAdded by the W32/Forbot-FW WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Update 63Xshupd64.exeAdded by the W32/Forbot-GA WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Update 64XWinV.exeAdded by the W32/FORBOT-FP WORM!
    Windows Update 64Xnbupd64.exeAdded by a variant of the W32/FORBOT WORM!
    Windows Update Auto UpdateXwuaumgr.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows Update AutoUpdate Client ProductXwuauct.exeAdded by the AGOBOT.ACL WORM!
    Windows Update CenterXsvthx.exeAdded by the W32.STUBBOT.A WORM!
    Windows Update CenterXW32RSA.exeAdded by an unidentified WORM or TROJAN!
    Windows Update CheckerXrandom file namesadware downloader trojan
    Windows Update CheckerXdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
    Windows Update CheckerXdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
    Windows Update CheckerXmsupdte32.exeAdded by the W32/Sdbot-AEF WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Update ClientXwuclient.exeAdded by the WIN32.SMALL.RN downloader TROJAN!
    Windows Update Client ServiceXwindrvl32.exeAdded by the AGOBOT-MM WORM!
    Windows update configXsvhost.exeAdded by a W32/Sdbot-PF worm infection
    windows update configuratorXsvghost.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows Update ControllerXmwoffice.exeAdded by the TROJ/BATTRY-A TROJAN!
    Windows Update FilesXdnetc.exeUnidentified VIRUS! Note - wupdmgr.exe is the real Windows Update
    Windows Update ManagerXwupdmngr.exeAdded by the W32.RANDEX.BTB WORM!
    Windows Update ManagerXWinlog0n.exeAdded by the TROJ/AGENT-BO TROJAN!
    Windows Update ManagerXwupdate.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Update Manager for NTXwupdmgr32.exeAdded by the BACKDOOR.SDBOT.AH WORM!
    Windows Update Monitoring ServiceXwinupdt.exeAdded by the W32/RBOT-PL WORM!
    Windows Update ProcessXwmiprvsc.exeAdded by the W32/SDBOT-CB WORM!
    Windows Update ServiceXcsrs.exeAdded by the W32/AGOBOT-NI WORM!
    Windows Update ServiceXsmcg.exe SDBOT.QY worm
    Windows Update ServiceXregscv.exeAdded by the W32/AGOBOT-AM WORM!
    Windows Update ServiceXSP00ISS.exeAdded by the W32/Sdbot-ZH Worm!
    Windows Update ServiceXupdate32.pifAdded by the W32/Rbot-ALC WORM!
    Windows Update Service 2004/2005Xsystemupdate.exeAdded by a Rbot-JE worm infection
    Windows Update servicesXwservices.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Update servicesXwins32svcs.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows Update SoftwareXsystem.exeAdded by the TOFGER.BX TROJAN!
    Windows Update System ShellXsvhostcs32.exeAdded by the W32/RBOT-AAZ WORM!
    Windows Update V6X(random file name)Added by a W32/Rbot-KT worm infection
    Windows Update.exeXN/AHomepage hijacker, see here
    Windows UpdatedXspoolsae.exeAdded by the W32/Rbot-APM WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows UpdatedXupdatr.exeAdded by the W32/Rbot-AYB WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Windows UpdaterXwupdmgr32.exeAdded by a variant of the DOS.AUTOCAT VIRUS!
    Windows UpdaterXiexplorerrs.exeAdded by the W32/RBOT-TN WORM!
    Windows UpdaterXsvigost.exeAdded by the W32/RBOT-VS WORM!
    Windows UpdaterXwupdate.exeAdded by the WOOTBOT.AJ WORM!
    Windows UpdaterXsdsys.exeAdded by the W32/Forbot-JG WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Windows Updater OnlineXwinupdatexx.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows UpdatesXlsassx.exeAdded by a variant of the W32/SDBOT WORM!
    Windows UpdatesXwinupd32.exeAdded by the W32.MYTOB.CE WORM!
    Windows UpdatesX w32dns.exeAdded by the W32/Sdbot-BFW Worm!
    Windows Updating ServiceXupdating.pifAdded by the W32/RBOT-ALW WORM!
    Windows Updtee MgnrXW1NT45K.exeAdded by the W32.Mytob.DC WORM!
    Windows USB controlerXwinusb.exeAdded by the W32/RBOT-HR WORM!
    Windows USB Driver SupportXWindowsusb.exeAdded by a variant of the W32.SPYBOT WORM!
    Windows USB ServiceX666.exeAdded by the W32.MYTOB.AR WORM!
    Windows USBDXmsifirewall.exeAdded by an unidentified WORM or TROJAN!
    Windows User Mode Driver ManagerXwdfmrg.exeAdded by W32/Sdbot-ZN Worm!
    Windows User StarterXwinuser32.exeAdded by the RBOT.SN WORM!
    Windows Version CheckNver_chk.exeVersion checker for CyberAudioLibrary ("A new way to exchange information through the Internet")
    Windows videoXvide_32.exeAdded by a variant of the GAOBOT/AGOBOT WORM!
    Windows Video Acquisition (WVA)Xwvsvc.exeAdded by the AGOBOT.YM WORM!
    Windows Video DriversXvideons32.exeAdded by the GAOBOT.AZT worm
    Windows Virus ControlXplou.exeAdded by the W32/SDBOT-ACZ WORM!
    Windows Web ServicesXspoolsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXsvcadmin.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXtcpsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXnetsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXwebsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXlocalsvc.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXsvcrun.exeAdded by the Troj/Dloader-NY Trojan!
    Windows Web ServicesXsvcman.exeAdded by the Troj/Dloader-NY Trojan!
    Windows WorkstationXmpci.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows WorkstationXmsup32a.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Workstation ServiceXwkssvc.exeAdded by the W32/Sdbot-AED WORM! Note: Creates Multiple copies of it's self, Read the link.
    Windows Workstation Service (32-bits)Xwkssvc32.exeAdded by a variant of the W32/SDBOT WORM!
    Windows Workstation Start ServiceXmslanmgr.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows XpXnortonguard.exeAdded by the W32/Mytob-DZ WORM!
    Windows XP Automatic UpdateXwXPupdate.exeAdded by the W32/Rbot-AFC Worm!
    Windows Xp Service Pack 2Xsvchost.exeAdded by the Troj/Xplos-A TROJAN! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item.
    Windows XP SP2 KeyGenXWindows XP SP2 KeyGen.exeAdded by the W32/TIBICK-C WORM!
    Windows-SystemXSystem32.exeAdded by the LOGPOLE.C VIRUS!
    Windows-TCP-IPXrfkampig.exeAdded by the GIPMA VIRUS!
    Windows-XP-Service-PackXxpspz.exeAdded by the W32/SDBOT-AAC WORM!
    windows16Xwindows16.exeAdded by the Troj/VB-XU TROJAN!
    Windows32Xrundll.exeAdded by the AGOBOT-LK or AGOBOT-ND WORMS!
    windows32Xwindows32.exeAdded by the Troj/VB-XU TROJAN!
    Windows32Xwuuaclt.exeAdded by the W32.Bratle.B WORM!
    Windows32 Configuration LoaderXmsrf32.exeAdded by the W32/Sdbot-ABX WORM!
    Windows32 Messenger ServiceXmsmsgv.exeAdded by the RBOT.ANS WORM!
    Windows32 Net DatabaseXmsnd32.exeAdded by the W32/RBOT-AAL WORM!
    Windows32 SerivcesXwinser32.exeAdded by the SPYBOT.AAF WORM!
    WindowsAgentXWindowsAgent.exeAdded by the GOP.G VIRUS!
    WindowsAgentXsysexhook.exeAdded by the GOP keyboard logger/TROJAN!
    WindowsAPI.DLLXServer5.exeAdded by the "Fear and Hope" trojan
    WindowsBackupX"%Windir%\WINDOWSBACKUP.EXE"Added by the W32.Stang WORM!
    WindowsCRCXwscrc.exeAdded by the W32/SDBOT-VU WORM!
    WindowsCriticalUpdateXwindows_critical_update.exeAdded by the ASTEF or RESPAN VIRUSES!
    WindowsDiskLogXcstsm.exeAdded by Troj/Stinx-C or Troj/Stinx-D TROJAN!
    WINDOWSflashbrgXsqldata1.exeAdded by a variant of the AGENT-IC TROJAN!
    WindowsfwXwindowsfw.exeAdded by the W32/AGOBOT-TA WORM!
    WindowsFYXwp.exePart of a "Security IGuard" parasite infestation - also detected as TROJAN.DESKTOPHIJACK and Troj/FakeAle-A Worm!
    WindowsFYXbsw.exeAdded by a variant of the DESKTOPHIJACK TROJAN! - for removal see here
    WindowsFZXA5281300.soVariant of the SmitFraud alias FAKEALE-C TROJAN!
    WindowsFZXzloader3.exeVariant of the SmitFraud alias FAKEALE-C TROJAN!
    WindowsFZX(PATH TO EXECUTABLE FILE)Added by the W32.Desktophijack Virus! Also see Trojan.Desktophijack.B Trojan!
    WindowsKeyUpdateXmaster.exeAdded by the W32.JOSAM WORM!
    WindowsMGMXWinmgm32.exeAdded by the SOBIG and LALA.C VIRUSES!
    WindowsRegistrationX(random filename)Added by the W32/RBOT-NO WORM!
    WindowsRegKey AutoupdateXExplorer.exeAdded by a variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Explorer.exe!
    WindowsRegKey AutoupdateXIexplore.exeAdded by a variant of the WIN32.RBOT WORM! NOTE: THis is NOT the legitimate Internet Explorer file!
    WindowsRegKey upd4te2d4teX*********.exe (* = random char)Added by the RBOT.XQ WORM!
    WindowsRegKey updateXWinupdate.exeAdded by the SDBOT.NT WORM!
    WindowsRegKey updateXwin2kup2date.exeAdded by a SPYBOT.FK worm infection
    WindowsRegKey updateXWindowsup.exeAdded by the SDBOT.PU WORM!
    WindowsRegKey updateX[random or different file name]Added by the RBOT.QT WORM!
    WindowsRegKey updateXsvchostc.exeAdded by the RBOT.IF WORM!
    WindowsRegKey updateXwindns.exeAdded by the RBOT.IE WORM!
    WindowsRegKey updateX16winupdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    WindowsRegKey updateXWinUpdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    WindowsRegKey updateXwinupdatexx.exeAdded by the RBOT.LW WORM!
    WindowsRegKey updateXwdnupdate.exeAdded by the SDBOT.QX WORM!
    WindowsRegKey updateXsvchoosts.exeAdded by the RBOT.ADB WORM!
    WindowsRegKey updateXWINUPDATES.EXEAdded by the W32/RBOT-MM WORM!
    WindowsRegKey updateXwinupdat32.exeAdded by the W32/RBOT-AGW WORM!
    WindowsRegKey update XPXwindexv1.exeAdded by the W32/RBOT-ABM WORM!
    WindowsRegKey%$ updateXmsi332.exeAdded by a W32/Rbot-IX worm infection
    WindowsRegKey%updateXethernet32m.exeAdded by the W32/RBOT-EN WORM!
    WindowsRegKeys updateXwinsysi.exeAdded by a SDBOT.WE worm infection
    WindowsRegKeys updateXwindup.exeAdded by a variant of the WIN32.RBOT WORM!
    WindowsSetupX(path to trojan)Added by the EZBOT VIRUS!
    WindowsSQL serviceXboner.exeAdded by the SDBOT.XRM WORM!
    WindowsUpdXWindowsUpd4.exeVirtuMonde adware
    WindowsUpd1.exeXWindowsUpd1.exe VirtuMonde adware
    WindowsUpd2.exeWindowsUpd2.exe VirtuMonde adware
    WindowsUpdateXwindows_update.exeAdded by the LOHACK.B VIRUS!
    WindowsUpdateXsvchost.exeAdded by a number of worms and trojans: TROJ/AGENT-DR , ASTEF , RESPAN and others
    windowsupdateXRPCX1sQ3.exeAdded by the IRCBOT.B VIRUS!
    WindowsUpdateXUSRINIT.EXEAdded by the MADDIS.B VIRUS!
    WindowsUpdateXsvchost.exeAdded by the TROJ/AGENT-V TROJAN!
    windowsupdateXwinupdate.exeAdded by the W32/WARPI WORM!
    WindowsUpdateXsvchost.exe /sAdded by the Troj/Bdoor-IK TROJAN!
    WindowsUpdateXwinnnint.exeAdded by an unidentified WORM or TROJAN!
    WindowsUpdateX[path to file]Added by Troj/Agent-EQ TROJAN!
    WindowsUpdateXdupadupam2.exeAdded by the Troj/Dupa-B TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    WindowsUpdate ServiceXwuautlc.exeAdded by the W32/RBOT-NR WORM!
    Windowsupdate ServiceXcsrss.exeAdded by the BUCHON.E WORM! **Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    WindowsUpdateDirectXdupadirect.exeAdded by the Troj/Dupa-C TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    WindowsUpdatem1X(Path of Executable)Added by the Troj/Agent-AAJ TROJAN! Note: This trojan is a password stealing trojan.
    WindowsUpdateNTXsvwhost.exeAdded by the Troj/Shellot-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WindowsXP ModuleXDirectX3D.exeMalware, reportedly a keylogger - see here
    WindowsXP UpdateXwindowsxpupdate.exeAdded by the W32/RBOT-PB WORM!
    WindowsXPservXsvcnxp32.exeAddee by the NANINF-A TROJAN!
    Windows_ProtectXwinregal.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows_ProtectXwinsystem.exeAdded by a variant of the WIN32.RBOT WORM!
    Windows_ProtectXwincontrol32.exeAdded by the W32/Rbot-ADK Worm!
    Windows_ProtectXlsas.exeAdded by the RBOT.ARO WORM!
    Windows_SerivceXSERVICE.exeAdded by a WOOTBOT.AH worm infection
    Windows_UpdatesXsvthost.exe W32.SpyBot worm variant
    Windows_VXDXuser32.exeAdded by the PWSTEAL.PPORT VIRUS!
    WindowzX(original worm file name).vbsAdded by the VBS.Nukip Worm!
    Windowz Update V2.0XExplorer.exeAdded by the YODO VIRUS! Note - the valid "explorer.exe" is located in C:\Windows or C:\Winnt whereas this one is located in the System32 sub-directory
    Window_ProtectXwinsi32.exeAdded by a variant of the WIN32.RBOT WORM!
    Windoxs Update CenterXW32RfSA.exeAdded by a variant of the W32/SDBOT WORM!
    WinDRXSysDre.exeAdded by the W32/Dref-H WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WinDrg32Xwindrg32.exeAdded by the DRUDGEBOT.A WORM!
    WinDriv32XWinDriv32.exeAdded by the SMALL-BA TROJAN!
    WinDriver ConfigurationXwindrvconf.exeAdded by the AGOBOT-LX WORM!
    WINDRUNXtaskgmrs.exeAdded by the W32/MYTOB-BT WORM!
    windrvXwindrv32.exeUnidentified VIRUS - possibly a strain of OBLIVION or BIONET
    WinDrvXwindrvx.exeAdded by a variant of the TIBSER.A downloader TROJAN!
    WinDSL MTU-AdjustUWinDSL_MTU.exeAdjusts the registry setting of the DUN-Adapters (MTU) and the TCP/IP-Protocol (RWIN) by ENGEL Technologieberatung
    WinDSL_MTU?WinDSL_MTU.exeMay be realted to Tiscali broadband, if so is it required?
    WinDSNXXWin????.exeAdded by the DNSX VIRUS!
    WindUpdatesXWinUpdt.exeWindupdates adware
    WindUpdatesX(path to trojan)Added by the AGENT.BF VIRUS!
    WINDVDpatchNCTHELPER.EXECTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative’s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
    WinDVR SchSvrNSchSvr.exeWinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs
    WinDVRCtrlNWinDVRCtrl.exeControl center software for an AOpen VA1000 TV tuner card
    WinDVRCtrlYWDVRCtrl.exeDriver task installed by the drivers for some TV capture cards; no further information available, so best left alone.
    Windws Configuration LoaderXLEXPLORE.exeAdded by the SODABOT VIRUS!
    WinEssentialXKeyhost.exeHijacker - hailing from jraun.com
    WinEssentialXkeyword.exeJraun.com hijacker
    WinExXlexplore_.exeAdded by the Troj/MSNOpt-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WinExecXWinexec.exe.vbsAdded by the AINESEY.A VIRUS!
    WinExecXWinExec.exeAdded by the W32/Falus-A WORM!
    WinExec32XWinExec32.exeAdded by the KAZWIN VIRUS!
    WinFast ScheduleUWfwiz.exeLeadtek WinFast TV tuner scheduler
    Winfast2KLoadDefaultURundll32.exe Wf2kcpl.dll, DllLoadDefaultSettingsLoads default settings for Leadtek Winfast graphics cards
    Winfast_2KUWF2k.exeSystem Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
    WinFast_GammaURundll32.exe wfcpl.dll, DllLoadGammaRampSettingsLoads if you change the gamma settings on Leadtek WinFast graphics cards
    WinFast_TaskbarUrundll32.exe wftask.dll,WFDllLoadDefaultSettingsLeadtek WinFast graphics cards related taskbar; can be launched manually.
    WinFavoritesXWinFavorites.exe1Loudmarketing.com adware downloader
    WinFax PRO ControllerNWFXCTL32.EXEFrom WinFax 10.0 and possibly earlier versions. Appears if you chose to have WinFax appear in the taskbar (System Tray) during installation and displays a yellow fax/telephone icon. Available via Start -> Programs
    WinFaxAppPortStarterYwfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
    WinFireXWF.exeAdded by the Troj/Delf-SY TROJAN!
    WinFixer 2005Xwfx5.exe"Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    WinFixer2005Xuwfx5.exe"Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
    winfontXwinfont.exeAdded by a Death backdoor trojan infection
    WinFoxV2UWF2k.exeSystem Tray application that starts up the Winfox utility for a Leadtek Winfast grpahics card to restore settings. Can be started manually from Start -> Settings -> Control Panel Display. Only needed if you wish to run things like the hardware monitor or overclock your card
    WinFXXcssrs.exeAdded by the AGOBOT.FX WORM!
    WinGateXWinGate.exeAdded by a variant of the LOVGATE WORM!
    WinGate Engine MonitorUwgengmon.exeWinGate Internet Client Dialup Monitor, component of WinGate proxy server software. Displays the status of the WinGate engine, and appears in the system tray of each workstation on the network reassuring clients that their workstations have connectivity with the WinGate Server.
    WinGate initializeXWinGate.exeAdded by a variant of the LOVGATE WORM!
    wingerver2.0.exeXwingerver2.0.exeAdded by the Troj/GrayBrd-AE TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    wingoXwingo.exeAdded by the W32.BEAGLE.AW or W32.BEAGLE.AV WORM!
    WinGuage ProNWGPRO32.EXEPart of McAfee Nuts & Bolts. "WinGauge is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to potential problems before they become serious". Resource hog. Available via Start -> Programs
    WinguardYWGFE95.EXEDr Solomon's Virex antivirus
    WinGuard ProUwgp.exe Winguard_Pro
    WinHackerNrundll32.exe wh95.dll, HackMeTweaking utility by Wedge Software. There are far better tweakers and, unlike WinHacker, most are free
    WinhelpXwinhelp.exeAdded by a variant of the LOVGATE WORM!
    WinhelpXwinhe1p.exeAdded by the QQPASS.E VIRUS!
    WinHelpXWinHelp.exeAdded by a variant of the LOVGATE WORM!
    WinHelpXrealsched.exeAdded by a variant of the LOVGATE WORM! **Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name
    WinhelpXTkBellExe.exe...Added by a variant of the LOVGATE WORM!
    winhelpXdns32.exeAdded by a variant of the WIN32.RBOT WORM!
    winhelpXUpdadv.exeAdded by the Troj/QQPass-N TROJAN!
    winhlp.exeXwinhlp.exeAdded by the PWSTEAL.FORMGLIEDER TROJAN!
    winhlp3.exeXwinhlp3.exeAdded by a variant of the Win32/TrojanDownloader.Easto.A TROJAN!
    Winhlp32XWscript.exe ..Msexec32.vbsAdded by the GANT.B VIRUS!
    winhlp32.exeXwinhlp32.exeAdded by the Win32/TrojanDownloader.Easto.A TROJAN!
    winhlpp32.exeXwinhlpp32.exeAdded by the GAOBOT.SY WORM!
    WinhostXwintt.exeAdded by the LOLAWEB.B VIRUS!
    WinhostXwin.exeAdded by the Troj/Dloader-AP TROJAN! Note: This worm\trojan file is found in the Windows or Winnt folder.
    WinhostXyahoo.exeAdded by the TROJ/DELF-KM TROJAN!
    WinhostXwinhost.exeAdded by the REATLE.F WORM!
    winhost.exeXwinhost.exeAdded by the TROJ/LOHAV-R TROJAN! or the W32.Beagle.BY WORM!
    winhost32.exeXwinhost32.exeAdded by the Troj/Banito-F TROJAN!
    WinIeRunXwinierun.exeAdded by the Troj/RNWatch-A Worm!
    winimageXwvsvc.exeAdded by the RBOT.TX WORM!
    WinINetXservices.exeAdded by the SOBER.AC WORM! - NOTE - this file is placed in a "%Windows%\ConnectionStatus folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup! WORM! -
    wininetXwininet.exeAdded by the W32/STUBBOT-C WORM!
    wininet32Xwininet32.exe Troj/Raznew-A trojan
    wininetdXwininetd.exeAdded by the WINET VIRUS!
    wininitXwininit.exeAdded by the WOLLF.16 VIRUS!
    WinInitXWin86.exeAdded by the TROJ/SMALL-PB TROJAN!
    winintXwinint.exeAdded by the W32/Sdbot-ADA WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    winipsecXwinipsec.exeUnidentified malware
    WinIRXHelperUWinIRXHelper.exeMSI™ Media Center Deluxe software - see here
    winisXwinis.exeAdded by the W32/RBOT-WI WORM!
    Wink*.exeXWink*.exeAdded by a version of the KLEZ VIRUS! * represents any random characters
    Winkb6Uwinkb6.exePart of We-Blocker, works in tandem with syswb6. Both files are needed to run WeBlocker. Required if We-Blocker is installed
    WinKernelXWinKer.exeAdded by the MIRAB or SERVIDOR VIRUSES!
    WinKernelXAdded by the PLEA.A VIRUS!
    winkernel32XwWin32.comAdded as the result of the BANSAP VIRUS!
    WinKeyUwinkey.exeLoads Copernic's WinKey. Used to map out Windows key hotkey combinations. Not required for the system, but is necessary for this to be running if you use these hotkey combos
    winldrX[path to file]Added by the VIDLO-P TROJAN!
    winldrXRechnung.pdf.exeAdded by the DOWNLOADER-ACS TROJAN!
    winlgz2Xwinlgz2.exeAdded by the TROJ/KILLFIL-Q TROJAN!
    winlibs.exeXwinlibs.exeEVAMAN.C worm
    WinLibUpdateXlibupdate.exeAdded by the BIONET series of VIRUSES such as BIONET.31 or BIONET.310
    WinLibUpdate32Xlibupdate32.exeAdded by the BIONET.405 VIRUS!
    WinLibUpdteXlibupdte.exeAdded by the BIONET.318 VIRUS!
    WinlinkXwinlink32.exeAdded by the GAOBOT.AAY WORM!
    WinlmeXwindll.exeAdded by the GOP.F VIRUS!
    WinLoadUWinload.exe PCTattletale is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. If you didn't install this yourself remove it.
    WinLoaderX(random filename)Added by versions of the SUBSEVEN VIRUS!
    winlocatorupdateXupdatewinlocator.exeLocator adult content toolbar related
    winlogXwinlog.exeUnidentified adware - NOTE: this malware actually changes the default value data of the Registry Run and RunServices keys in order to force Windows to launch it at boot. Name field may be empty.
    winlog managerXwinlog.exeAdded by the DONBOMB.A TROJAN!
    WINLOG0NXWINLOG0N.EXEAdded by the W32.MYDOOM.BI WORM!
    WinLoginXwinlogin.exeAdded by the AGOBOT-IX WORM!
    winloginXwin32x.exeBrowser hijacker, also detetected as the TROJ/STARTPA-DF TROJAN!
    winlogin.exeXlogfile.exeAdded by the WIN32.AGENT.AH TROJAN!
    Winlogin.exeXlog.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    winlogin.exeXmspaint.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    Winlogin.exeXsteam.exeAdded by a variant of the WIN32.AGENT.AH TROJAN!
    winlogoffXwinlogoff.exeAdded by the W32/AGOBOT-TR WORM!
    winlogonYwinlogon.exeWindows Logon Process - handles user logons described here
    winlogonXwinlogon.exeHijacker or adult content dialler - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file described here
    winlogonXwinlogin.exeAdded by the RANDEX.E or P2LOAD.A WORM!
    winlogonXwinlogon.exeAdded by the TRODAL VIRUS! - file is located in C:\Windows or C:\Winnt, and not in it's System or System32 subdirectory, as is the case with the legitimate winlogon.exe file
    winlogonXmsreg32.exeAdded by the SDBOT.EO WORM!
    WinLogonXlogon.exe AdultBox foistware
    winlogonXwinlogon32.exeAdded by the WIN32/MASLAN.C WORM!
    WINLOGONXwscript.exe (System or System32)\WINLOGON.vbsAdded by the VBS.Ypsan.F@ mm Worm!
    winlogonXwpwlogon.exeAdded by an unidentified WORM or TROJAN!
    winlogon serviceXurx.exeAdded by the SPYBOT.EN WORM!
    Winlogon ShellXExplorer.exe %System%\1032\svchost.exeAdded by the W32.Kipis.M WORM!
    Winlogon.exeXN/A CoolWebSearch parasite related.
    winlogon.exeXhelper.exeAdded by the FAKESPY-A TROJAN!
    winlogon.exeXmsole32.exeAdware, detected as the DOWNLOADER-ACZ TROJAN!
    winlogon32_X(PATH TO FILE)Added by the W32.Ruland.A WORM!
    WinLsassXservicec.exeAdded by the SCANE VIRUS
    WinLsassX(path to file)Added by the W32/WORT-B TROJAN!
    winltmpvXwinln.exeAdded by the TCXMEDI-C TROJAN!
    winltmpvXwutop.exeAdded by the TCXMEDI-C TROJAN!
    WinmainXwinmain.exeOne of the first of a new breed of malware. When run it immediately loads MSHTA.EXE from the Windows folder, placing it on "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as a program! In other words, it's possible for a "rogue" website to actually embed trojans, worms and/or viruses directly into a web page. BOClean's HTA Stop offers an easy way to toggle this capabiltity, or rather vulnerability, on and off. I suggest you leave it disabled!
    WinManager?schost.exe??
    winmatrix.exeUWinMatrixXP.exeWinMatrix XP - wallpaper replacement that shows different matrix effects (including flowing matrix codes from 'The Matrix' movie) on your desktop
    WinMemUWinMem.exeWinMem Cleaner, part of Ultra_WinCleaner_Utility_Suite . Makes more memory available for your programs and the Operating System. It also defragments your system's physical memory increasing the efficiency of your CPU and motherboard cache, which prevents crashes and accelerates your system's performance.
    WinMenssageXwinmax.exeAdded by the BANCOS.B VIRUS!
    WinMessengerXsyshost.exeAdded by the W32/OPANKI-E WORM!
    WinMgmtNWinMgmt.exeUsed for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" - refer here
    WINMGRXtaskgmgr.exeAdded by the W32.MYTOB.AN WORM!
    Winmgr.exeXscvhost.exeAdded by the AGOBOT.AFG WORM!
    WinMgr32Xwinmgr32.exeAdded by the W32.MIMAIL.P WORM!
    WinMineXD4NG3.vbsAdded by the BISCUIT.A VIRUS!
    winmodemYwmexe.exeSoftware for software based modems. Required if you have one of these. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    WinMoviePlugInXWinMoviePlugIn.exe Sfonditalia adult content premium rate dialer
    WinMsrv32XWinMsrv32.exeAdded by the GAOBOT.AFJ WORM!
    WinMXNWinMX.exe WinMX file sharing application
    winmysqladmin or WinMySQLadmin ToolNwinmysqladmin.exeStarts the MySQL database admin tool
    winnetXwinnet.exeCommonName Toolbar spyware. To uninstall see here
    WinNetDDEX[random characters].exeAdded by the NETDEPIX.B TROJAN!
    WinNiteXniteaim.exeAdded by the W32.Opanki.B Worm!
    Winnov Menu?WnvMenu.ExeWinnov Video Capture Card related. What does it do and is it required?
    Winnov Remote?WnvRsvr.ExeWinnov Video Capture Card related. What does it do and is it required?
    Winnov Status?WvStatus.ExeWinnov Video Capture Card related. What does it do and is it required?
    winnt DNS identXwuamgrd32.exeAdded by the W32/RBOT-BAU WORM!
    winnt DNS identXpidchk32.exeAdded by the W32/RBOT-ACY WORM!
    winnt DNS identXwindowxp.exeAdded by a variant of the WIN32.RBOT WORM!
    winnt DNS identXwinupdate32.exeAdded by a variant of the WIN32.RBOT WORM!
    winnt DNS identXiexplorer.exeAdded by a variant of the WIN32.RBOT WORM!
    winnt DNS identXwuamgrd33.exeAdded by a variant of the WIN32.RBOT WORM!
    winnt DNS identXWinupd32.exeAdded by the RBOT.AVU WORM!
    Winnt DNS identXwindowsp.exeAdded by the RBOT.BAL WORM!
    winNT updatcXwupgrd.exeAdded by a variant of the WIN32.RBOT WORM!
    WinNtBBXWinntBB.exeAdded by the DULOAD.C VIRUS!
    WinnupXwin32nls.exeAdded by a variant of the W32.SPYBOT WORM!
    winocx32Xwinocx32.exeAdded by the Win32.Protoride.I WORM!
    WINOWS SYSTEMXwinnt.exeAdded by the MYTOB.ID WORM!
    WINPXwinmic.exeAdded by the W32/Spybot-EB WORM! Note: This trojan file is found in the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    WinpackXwinpack.exeAdware downloader - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Agent.gg
    WinPatrolUWinPatrol.exeWinPatrol - "Manage Startup programs, tasks, cookies; will sniff out Worms, Trojan horses, Cookies, Adware, Spyware, Klez, Assumption and other malicious programs"
    winphonics7536X(path) vbsystem35.exe (path) setups.exe (path) vb.vbAdded by a Mutin-C IRC backdoor trojan infection
    winpipeXwinpipe.exeBrowser hijacker redirecting to wow-access.com
    WinPLOSIONUWinPlosion.exe WinPLOSION allows you to immediately view and select from all the windows running on your computer, just those of the active application, or to minimise all windows and display a clear desktop.
    WinPoetYWinPPPoverEthernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
    WinPopupNWINPOPUP.EXEIntranet chat software provided by windows for chat on small networks. Handy little LAN messaging utility. Has been included in Windows since 95, and maybe in WFWG 3.11. Normally it won\'t set itself up to run unless the user specifically adds it to startup
    winpopupXwinupie.exeAdware by Tradeexit.com
    Winprocer32 UpdateXwinprocer32.exeAdded by the RBOT.GW WORM!
    winprocessor UpdateXwinprocessor.exeAdded by the RBOT.IO WORM!
    WinProfileXCommand.exeAdded by the BUDDY VIRUS!
    WinProfileXsndcfg16.exe Win32.Sndc.A worm
    winprofileXiexpiore.exeAdded by a variant of the MONCHER WORM!
    WinProfileXiexpIore.exeAdded by Troj/Chum-C Trojan!
    WinProtXWinprot.exeserver.exeAdded by the CHUPACABRA VIRUS!
    winprotectXwin32.exeAdded by the W32.MUGLY.E WORM!
    winprotectXwinprotect.exeAdded by the W32/SDBOT-SB WORM!
    WinProxyUWinProxy.EXE"WinProxy is the world-first proxy server and a firewall with integrated mail server for Windows 95/98/ME/NT/2000/XP"
    Winproxy PersonalXWINPROXY.EXEAdded by the SDBOT.BMF WORM!
    winpsdXwinpsd.exeAdded by the W32.Mydoom.Q WORM!
    winpup32XWinpup32.exeAdded by the ADCLICKER VIRUS!
    WinPWD ManagerXwpwdmgr.exeAdded by W32/Rbot-AUT WORM!
    winrapidXwinrapid.exeAdded by a variant of the WIN32.RBOT WORM!
    winrarXwinrar.exe CoolWebSearch parasite related.
    winrarshellXwinrarshell32.exeAdded by the PWSteal.Salira TROJAN!
    winRegXwinReg.exeAdded by the YAHA.H or YAHA.J VIRUSES!
    winregsrvXwinregsrv.exeAdded by the SYNRG VIRUS!
    winreg_32Xsvchosst.exeAdded by the BANCOS-CE TROJAN!
    winreg_32XVc030405.exeAdded by the TROJ/BANCOS-CT TROJAN!
    winreg_32X(path to Trojan)Added by the Troj/Banker-DB Trojan!
    winreg_32Xsysdll.exeAdded by the TROJ/DLOADER-IJ TROJAN!
    WINREMOTEUWinRemote.exeInterVideo WinCinema Manager - needed for the use of WinDVD_Remote_Control
    Winres32visX(path to file)Added by the THRAX.A VIRUS!
    winrestore1Xwinrestore.exeAdded by the TROJ/KILLFIL-Q TROJAN!
    winreupsXwinreups.exeAdded by a variant of the WIN32.RBOT WORM!
    winrouteNwinroute.exeWin-Route 4.27. WinRoute Tray Icon for starting and stopping the WrCtrl.exe process, also to log in to the console to view logs and change settings. Can be unchecked and the engine still runs and functions normally. Can then use provided shortcuts for administration of the program. Loaded in SERVICES on Windows 2k
    winrunXmsconfig.exeAdded by the WINUR VIRUS! Note - this is not the real msconfig.exe
    WINRUNXtaskgmr32.exeAdded by the W32.MYTOB.AP WORM!
    WINRUNXsvchost32.exeAdded by the W32/MYTOB-AI WORM!
    WINRUNXtaskgmr.exeAdded by the W32/MYTOB-BX WORM!
    WINRUN zXW1NT45K.exeAdded by W32.Mytob.BL WORM!
    WinRunnersXWinDrivers.exeAdded by the DULOAD.C VIRUS!
    Wins Service DriverXwinet.exeAdded by the W32/Rbot-APV WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Wins Update 32Xservices32.exeAdded by the W32/Forbot-FN WORM! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    Wins32 OnlineXcfgpwnz.exeAdded by the W32.Bropia.R WORM!
    WinschedulerUWINSCH~1.EXEInterVideo WinDVR scheduler
    WinScMngrXwinsmc.exeAdded by the W32/SDBOT-BPZ WORM!
    WinSecXwinsec16.exeAdded by the AGOBOT.ZF WORM!
    winsecureXwinsecure.exeBrowser hijacker, redirecting to specificsearches.com
    Winsecure AntivirusXSecureantivirus.exeAdded by a variant of the W32.SPYBOT WORM!
    WinSecured32Xssmr.exeAdded by a variant of the W32/FORBOT WORM!
    WinservXWinserv.ilaAdded by the W32.NODMIN WORM!
    winserverXServer.txt.vbsAdded by the DELTAD.A VIRUS!
    WinserviceXwinmain.exeporn related malware
    winserviceXsvchost.exeAdded by the BACKDOOR-CVK TROJAN! - NOTE - this file is placed in a %WinDir% (typically C:\Windows or C:\Winnt) "Services" folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    WinService32Ussmgr.exe007 Spy Software - "stealthy monitoring program which allows you to secretly track all activities of computer users and automatically deliver logs to you via Email or FTP"
    WinService32Xsvchost.exeAdded by the 007_Spy_Software keystroke logger/monitoring program. remove unless self installed! - NOTE - this file is placed in a Program Files\Common Files\Microsoft Shared\DAO\System32 folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    WinServicesXWinServices.exeAdded by the YAHA.K or YAHA.M VIRUSES!
    winservitXcassl.exeAdded by de RBOT.ASG WORM!
    winservnXwinservn.exe PurityScan/Clickspring adware
    winservsXwinservs.exe PurityScan/Clickspring adware
    WinSetBrowseXBasicUpdate.dll.vbsAdded by the BISCUIT.A VIRUS!
    WinshellXremote.exeAdded by the MYTOB.LJ WORM!
    Winshoe?wuadfdqr.exeProbably an unidentified VIRUS! Adds itself to 3 registry "Run" keys and prevents Task Manager being displayed. This is not the Winshoe IRC Client as the visitor did not have it installed
    winshost.exeXwinshost.exeAdded by the Tooso or Tooso.B or Tooso.C or Tooso.D or Tooso.E and Trojan.Tooso.I TROJANS!
    winshost.exeXwinshost.exeAdded by several variants of the BAGLE TROJAN!
    WinShowUpdateXcopy C:\WINDOWS\winshow.new C:\WINDOWS\winshow.dllWinshow parasiate related - from the "RunOnce" keys it replaces "winshow.dll" with a new version
    WinSigXNetXP.exeAdded by the TROJ/BANKER-FN TROJAN!
    winskypeXwinskype.exeAdded by the Troj/Brogger-C TROJAN! Note: This worm file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    winsockXsvch0st.exeAdded by the SAGE-A WORM! Note: This is not the legitimate Windows Process. The legitimate Windows Process should not be seen in Msconfig or as a Startup item. Also there is a number "0" in the executable filename, not a lower/upper case O.
    Winsock driverXwinnt update.exeAdded by the TROJ/SPYBOT-DM TROJAN!
    Winsock driverXwinnt64.exeAdded by the W32/Spybot-DR WORM!
    winsock2Xnetsvr.exeAdded by the AGOBOT.LY WORM!
    Winsock2 driverXSDJOIJE.EXEAdded by the SPYBOT.DR VIRUS!
    Winsock2 driverXMIRC32.exeAdded by the SPYBUZZ VIRUS!
    Winsock2 driverXkgzgjkpcw.exe, ZONEALARM.EXEAdded by the SDBOT.T WORM! Note - ZONEALARM.EXE is not the valid Zone Labs firewall program
    Winsock2 driverXWINCFG.SCR W32.SpyBot worm variant
    Winsock2 driverXwinupdate.exeAdded by a Spybot-BX worm infection
    Winsock2 driverXSPOLSV.EXEAdded by the W32/SPYBOT-CM WORM!
    Winsock2 driverXZonealarmupdate.exeAdded by a variant of the W32.SPYBOT WORM!
    Winsock2 driverXsysreq.exeAdded by the W32/SPYBOT-CC WORM!
    Winsock2 driverXAMSNMGR.EXEAdded by a variant of the W32.SPYBOT WORM!
    Winsock2 driverXWUAUMQR.EXEAdded by the W32/SPYBOT-DP WORM!
    Winsock2 driverXwincfg.exeAdded by the SPYBOT.CO WORM!
    Winsock2 driverXntsys32.exeAdded by the W32/Spybot-DD WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Winsock2 driverXsvchorsst.exeAdded by the W32/Spybot-EE WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    Winsock2.dllXWINLODR.SCRAdded by an unidentified VIRUS!
    Winsock32 driverXTesting.exeAdded by the SPYBOT.B VIRUS!
    Winsock32driverXwin32server.scrAdded by the HACARMY TROJAN!
    Winsock32driverXZoneAlarmPr0.exeAdded by a Hackarmy-B trojan infection
    Winsock32driverXZoneLockup.exeAdded by a Hacarmy.D trojan infection
    Winsock32driverXsp2XPupdate.exeAdded by the BKDR_HACKARMY.S TROJAN!
    Winsock32driverXwin32server.exeAdded by the BackDoor-AZV TROJAN!
    Winsock32driverXwin32server.exeAdded by the HACARMY.F TROJAN!
    Winsock32driverXwinXPupdate.exeAdded by the HACKARMY.9728 TROJAN!
    Winsock32driverXsvchhost.exeAdded by the BKDR_HACKARMY.I TROJAN!
    winsockdriverXtskmg.exeAdded by the SDBOT.GEN or WARPIGS.C WORMS!
    winsockdriverXwinsock2.2.exeAdded by a variant of the SPYBOT VIRUS!
    winsockdriverXiexplor.exeAdded by the W32.BLATIC.A WORM!
    winsockdriverXwinsock3.exeAdded by the W32/SPYBOT-DO WORM!
    winsockdriverXbot.exeAdded by the W32/WarPigs-D WORM!
    WinSocketComponentXnthost.exeAdded by an unidentified VIRUS!
    WINSOS VERIFYUWINSOS.EXE WinSOS - "deletes spyware, optimizes your computer - backs up selected data"
    WinSPX[path] REGEDIT.EXE -s [path] sysreg.regHijacker, variant of the TROJ/STARTPA-ME TROJAN!
    winspd32dllXwinspd32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    WinSPFXwindrv32.exeAdded by the W32.Mydoom.V WORM!
    WinSPFXwinspf32.exeAdded by the W32.Mydoom.P WORM!
    WinsplXwinsplx.exeAdded by a variant of the TROJ/TROLL-A TROJAN!
    WinspoolXspoolsvr.exeAdded by a variant of the W32/SDBOT WORM!
    WinSrvXkn0x.exeAdded by the HOBBIT.F VIRUS!
    WinSrvXSHIZZLE.EXEAdded by the HOBBIT.C VIRUS!
    WinsrvXwinsrv.exeAdded by the OPASERV.T VIRUS!
    winsrvXwinsrv.exeAdded by the Troj/Netsnak-B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Please be aware that this trojan may steal passwords.
    WinsSystemXsyssmss.exeAdded by the BKDR_DELF.IG TROJAN!
    WinStabilizerXWinStabilizer.exeAdded by the W32/Agobot-SW Worm!
    WinStartXWinStart.exeFromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
    WinStartXWscript.exe WinStart.vbsAdded by the CIAN.C VIRUS!
    WinStartXwinstart32.exeAdded by the PUROL VIRUS!
    WinStartXWinStart.pifAdded by the CONE.E VIRUS!
    WinStartXservices.exeAdded by the W32.SOBER.O WORM! - Note - this file is placed in a "%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    winstartXwinstart.exeAdded by the TROJ/SCKEYLO-AB TROJAN!
    WinStart001 or WinStart001.EXEXWinStart001.exeFromIGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words, with this installed, typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge
    winstats Xwinstats.exeAdded by the Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
    Winsta~1Xwinsta~1.exeGoHip foistware
    WinSth16XWinSth16.exeAdded by the CAKE VIRUS!
    winstroXRUN32DLL.exeAdded by the FTP_ANA VIRUS!
    winsupdaterXwinsupdater.exeAdded by an unidentified WORM or TROJAN!
    WinSvc16.exeXWinSvc16.exeAdded by the BACKDOOR.SDBOT.FQ TROJAN!
    winsvc32.exeXwinsvc32.exeAdded by the GREPAGE TROJAN!
    Winsvr managerXDDEsvr.exeAdded by the W32/TIRBOT-C WORM!
    winsy32.exeXwinsy32.exeTrojan, CoolWebSearch parasite related
    winsyncX ******.exe reg_run (* = random char)Added by a variant of the QOOLOGIC TROJAN!
    WinsysUWinsys.exe Win-Spy - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Remove/disable it unless you put it there yourself
    WINSYSX(path to trojan)Added by the TROJ/BANKER-ER TROJAN!
    winsysXexploer.exeAdded by the TROJ/SPYVB-C TROJAN!
    winsysXsyschost.exeAdded by an unidentified TROJAN!
    WinSys32XWinsys32.exeAdded by the CIGIVIP or RECKUS VIRUSES!
    WinSys32XWinsys32.exeAdded by the BACKDOOR.CIGIVIP TROJAN!
    WinSys32XWinsys32.exeAdded by the W32.HLLW.RECKUS or W32/SDBOT-YL WORMS!
    winsys32 DriverXwinsys32.exeAdded by a Loony-O trojan infection
    WinSysAppMonUWinSysRM.exeHome & Family Content Filter related. See here
    winsyslog lptt01Xwinsyslog.exeVariant of the RapidBlaster parasite (in a "Winsyslog" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    WinSysStartUpWKbLwXTaskSystemDll.ExeAdded by the BACKZAT.G VIRUS!
    WinSyst32Xwinsyst32.exeAdded by the MORB VIRUS!
    WinSystemXwinsystem.exeAdded by the WHITEBAIT VIRUS!
    WinsystemXwinsystem.exeAdded by a BANCOS.CR trojan infection
    WinSystemUWinSystems.exe CMKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!
    winsystem.sysXsmss.exeAdded by the W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
    WINTXwcpcc.exe, wcpsvit.exe, wcp****.exe (* = random char) PurityScan/Clickspring adware
    WinTaskXWintask.exeAdded by the HIPO or LEMIR.F VIRUSES!
    WINTASKXtaskgamr.exeAdded by the W32.MYTOB.AU WORM!
    WINTASKXmsmgrxp.exeAdded by the W32.MYTOB.AQ WORM!
    WINTASKXsys32.exeAdded by the W32.MYTOB.K WORM!
    WINTASKXtaskgmr.exeAdded by the W32.MYTOB.I or W32.Mytob.BH and W32/Mytob-AC WORMS!
    WINTASKXtaskgmr32.exeAdded by the W32/MYTOB-AK WORM!
    WINTASKXsys32.exeAdded by the W32/MYTOB-F WORM!
    WINTASKXtaskgmr32.exeAdded by the W32.Mytob.BU WORM!
    WINTASKXiexplorer.exeAdded by the W32/MYTOB-CH WORM!
    WINTASKXt4skgmr.exeAdded by the W32.MYTOB.CM WORM!
    WINTASKXtaskgmr32.exe or t4skmgr.exeAdded by the W32/Mytob-AK Worm!
    WINTASKXtaskgmrs.exeAdded by the W32.Mytob.DH WORM!
    WINTASKXtaskfile.exeAdded by the W32.Mytob.EF WORM!
    WINTASKXtaskgm.exeAdded by the W32/Mytob-AO Worm!
    WINTASKXmsvhost.exeAdded by the W32/Mytob-AR Worm!
    WinTaskXwintask.exe Affilred.B adware
    WINTASKXyahooicons.exeAdded by the W32/MYTOB-HM WORM!
    WINTASK DLLXjusched32.exeAdded by the W32.MYTOB.AI WORM!
    WINTASK DLLXRealPlayer Ath CheckAdded by the W32.MYTOB.AG WORM!
    WINTASK DLL32Xsmsrss.exeAdded by the W32.MYTOB.BS WORM!
    WinTask driverXwintask.exeAdded by the TROJ/DLOADER-NA TROJAN!
    WINTASK32Xtaskgmr32.exeAdded by the W32.MYTOB.BN WORM!
    WINTASK32Xtaskgmrr.exeAdded by the W32.Mytob.FX WORM!
    WINTASKMANXtaskman.exeAdded by the W32.Mytob.JW WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    WINTASKMANAGERXtaskgmr.exeAdded by the W32/MYTOB-AF WORM!
    WINTASKMGRXccsrs.exeAdded by the W32.MYTOB.Q WORM!
    WINTASKSXtaskgmr.exeAdded by the W32.MYTOB.BO or W32.Mytob.DO or W32/Mytob-BM WORM!
    WINTASKSXwinxpro.exeAdded by the W32.Mytob.EZ WORM!
    WinTasks DLL Library (32-bits)Xwinkll.exeAdded by the W32/Rbot-AJZ WORM!
    WinTasks TraybarUwintasks.exeWinTasks - "Efficient Resource and Task Management is absolutely critical if you want to achieve the highest system performance levels possible. WinTasks 4 will not only help you achieve this task, but will actually make your system run faster and more smoothly than ever before"
    wintasks.exeXwintasks.exeAdded by the Evaman worm
    Wintbp.exeXwintbp.exeAdded by the W32.Zotob.E WORM!
    Wintbpx.exeXwintbpx.exeAdded by the W32.Zotob.F WORM!
    wintectiveUwintective.exe Wintective logs keystrokes, captures screenshots, and monitors Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself remove it.
    winterXhappy.exeAdded by the W32/SDBOT-YF WORM!
    Wintercooler ProNWINCOOL.EXEWintercooler Pro - utility that monitors CPU usage, RAM consumption and Internet connection speed
    WinTidyNWinTidy.exeDesktop icon manager from PC Magazine (Ziff-Davis) for Win95. Available via Start -> Programs
    WintimeXWintime.exeAdded by the Harnig TROJAN!
    WinTimeUwintime.exeAdded by WinTime Located in the Windows directory.
    Wintime WtxploadNWxpload.exe WintimePart of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet, if it's not already running. It then starts an application which manages the tablet messages. Since I leave the tablet unplugged unless I need to use it, I don't need this running at startup. I suspect that this program monitors a number of windows messages, so that when it's loaded, my regular mouse slows down - it acts like it 'sticks' entering and leaving windows. Certainly my performance returned to what I expected when I removed this item using MSCONFIG"
    WinTimerXmsupdate.cmdHijacker, detected by Kaspersky antivirus as Trojan.Win32.StartPage.tj
    wintnask32.exeXwintnask32.exeAdded by the W32/Rbot-AFP Worm!
    wintnlXwintnl.exeAdded by a variant of the W32.ZOTOB.K WORM!
    wintnl.exeXwintnl.exeAdded by the W32.Zotob.K WORM!
    wintnpx.exeXwintnpx.exeAdded by the W32.ZOTOB.H WORM!
    WinToolsXWToolsA.exe WinTools adware
    WinTOTAL SchedulerNguru.exeWinTOTAL Real estate appraisal software related
    WinTrayXwintray.exeAdded by the LEGUARDIEN.B VIRUS!
    wintsk32dllXwintsk32dll.exeAdded by the W32/RBOT-AAJ WORM!
    winudll.exeXwinudll.exeAdded by the Troj/Mitglie-CE TROJAN!
    winuiXz.exeAdded by the Kondeli TROJAN!
    winupated.exeXwinupated.exeAdded by a variant of the W32/SDBOT WORM!
    winupdXRUNDLL32.EXE (random value).dll,_mainRDAdded by the MOTA.A VIRUS!
    winupd.exeXwinupd.exeAdded by the BEAGLE.M or BEAGLE.N WORMS!
    WinUPD32Xexplorer.exeUnidentified VIRUS!
    winupdatXwinupdat.exeWin32.Canbot.A worm
    WinUpdateXRBSKQQBO.EXEAdded by the VBS.Vbswg2b.A VIRUS!
    WinUpdateXwmbem.exeAdded by the REVCUSS.B VIRUS!
    WinUpdateXupdsys.exeAdded by a variant of the WIN32.RBOT WORM!
    winupdateXwinupdate.exe /autoAdded by the WIN32.ALCAN.B WORM!
    WinUpdate LoaderXmsnnm.exeAdded by the UPCHAN TROJAN!
    winupdate********[1]Xwinupdate********[1].exe (* = random digit) Horseserver.net hijacker
    winupdate.exeXwinupdate.exeAdded by the RADO VIRUS!
    winupdate2846X(path) vbsystem35.exe (path) msvbrun.exeAdded by a Mutin-C IRC backdoor trojan infection
    WinUpdateBXbreatle.exeAdded BY the W32.Bratle.A WORM!
    winupdateconnX[path to file]Added by the W32/COMBRA-A WORM!
    winupdateconn_XExplorer.EXEAdded by the W32/Combra-B WORM!
    winupdatefiv_X[path to file]Added by the COMBRA.C WORM!
    WinUpdateProtectionUcsrss.exe ICE_Remote_Spy monitoring software, "secretly monitors everything your spouse, kids or employees do on the Internet and emails the data to you." - Note - this file is installed in a C:\Windowsupdate\Ufp\Irs7 folder, and it is NOT the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which is located in the System32 directory.
    WinUpdateProtectionUcsrss.ex EmployeeWatch is a commercial spyware program designed to monitor user activity on a computer.
    winupdatesXwinupdates.exe /autoAdded by the W32.Alcra.B WORM!
    winupdate_X[path to file]Added by the W32.COMDOR.A WORM!
    WinUpdsvXwinupdsv.exeAdded by the X97M.DROPO Macro VIRUS!
    winupdtXRUNDLL32.EXE [random.dll]Added by the Mabutu.a WORM!
    winupdtlXwinupdtl.exe SecondThought adware variant
    winupdtlXwinupdt.exe 2nd-thought adware variant
    WinUpgraderX(path to EXE)Added by the Troj/Agent-DZ Trojan!
    winusb.dllXwinguard.exeAdded by the W32/FORBOT-CN WORM!
    WinUser32KXusr32wink.exeAdded by the Win32.VB.hk backdoor TROJAN!
    WinUsrXWinUsr.exe K1S2Added by the W32.CLUNK.A WORM!
    Winux Piriax ServiceXPH32.EXEAdded by the RANDEX.G VIRUS!
    winversionXwinversion.exeBrowser hijacker, redirecting to specificsearches.com
    WinVNCUWinVNC.exeWinVNC is an application that allows you to remote control your PC from another PC somewhere on the internet
    WinVNCXiexplorer.exeAdded by the EVIVINC VIRUS!
    winvxd32Xwinvxd32.exeAdded by the W32.Gabloliz.A WORM!
    winwan lptt01 or winwan ml097eXwinwan.exeVariant of the RapidBlaster parasite (in a "Winwan" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    winwordXwinword.exeAdded by the Troj/Torpid-C TROJAN!
    winwsl.exeXwinwsl.exeAdded by the W32/Zotob-J WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    winXPX33.exe/backgroundAdded by the W32.ANPES WORM!
    WinXPXplugin1.exeAdded by the Downloader-JW TROJAN!
    WinXP fixX(path to file)Added by the BACKDOOR.RANKY.P TROJAN!
    WinXp UpdaterXwinxp32.exeAdded by the W32/RBOT-HG WORM!
    WinXP-98XCSRSS.exeAdded by the Troj/Banker-DS TROJAN! Note:This is NOT the legitimate Windows CSRSS.exe process, which should NOT figure in Startup!
    winxpdll32.exeXwinxpdll32.exeAdded by a variant of the Win32.SMALL downloader TROJAN!
    WinXPHomeXplugin2.exeAdded by the malicious VBS_INOR.T script!
    WinXPLoadURundll32 LoadDll, LoadExe WinXPLoad.exeCompaq hotkey related - required if you use the hotkeys
    winxpusbdXwinxp64.exeAdded by a variant of the WIN32.RBOT WORM!
    WinZap CheckXwinzbp.exeAdded by the W32/Rbot-AWZ WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    winzipX(path to trojan)Added by the BANCOS.G VIRUS! Note - not the popular WinZip file compression utility
    WinzipX(See description box.)Added by the W32/Lerpa-A WORM! Note: The file name will be one of the following common.exe or common.pif or common.scr or Sexo.exe or Sexo.jpg.pif or ini_file__.pif or load_me__.tmp or msfile.pif or system_load_.pif or zipped.rar.pif
    WinZip Quick PickNWZQKPICK.EXEAdded with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up
    WinZip UpdateXWinZip.exeAdded by a variant of the WIN32.RBOT WORM!
    Win_api_driverXsystem.exeAdded by the REVIRD VIRUS!
    Win_BooTX(Path of Executable)Added by the Troj/Banker-GI TROJAN! Note: This is a password stealing trojan.
    Win_LibraryXINISvc.exeAdded by the ANARCH VIRUS!
    win_spool2Xwin_spool2.exeAdded by the TROJ_SCKEYLOG.B TROJAN!
    win_supp00.exeXWin Const.exeAdded by the Troj/Assasin-H TROJAN! Note: This trojan file is found in the Windows\Win Types or Winnt\Win Types folder.
    win_upd.exeXWINdirect.exeAdded by the MITGLIEDER.M VIRUS!
    win_upd2.exeXWINdirect.exeAdded by the BEAGLE.AO WORM!
    Win_vaderXWin_vader.vbsAdded by the INVASION.A VIRUS!
    WIP Config GUIXWinipcfgs.exeAdded by the W32/RBOT-CN WORM!
    Wireless PCI Card Configuration UtilityUWMP11Cfg.exeUtility used by the LINKSYS wireless PCI card (WMP11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration
    Wireless Provider ServerXwpsvr.exeAdded by a W32/Forbot-AD worm infection
    Wireless-G Notebook AdapterYGcc.exeLinkSys Wireless-G Notebook Adapter diver
    Wireless-G Notebook Adapter UtilityUWPC54CFG.EXEUtility used by the LINKSYS Wireless-G Notebook Adapter (WPC54G)
    wiseXclockwise.exeAdded by the Troj/Lazar-A TROJAN!
    Wise-FTP SchedulerUWF_Scheduler.exe WISE-FTP file transfer software scheduler
    wjviewNwjview.exeMS tool used to view window-based Java applications from the command line
    wkcalremNwkcalrem.exeProduces a pop-up reminder of events scheduled using the MS Works Calendar
    WkDetectNWkDetect.exeChecks for updates to MS Works
    wkfudNwkfud.exeA marketing program for MS Works
    WksSbNWksSb.exeThe Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file
    WksSVCXEXPLORER.exeAdded by the W32/MYTOB-BW WORM! - NOTE - the valid "explorer.exe" will always be located in C:\Windows or C:\Winnt folder whereas this one is found in the C:\Windows\System folder (Win 98/ME) or in the C:\Winnt\System32 or C:\Windows\System32 subfolder (Windows 2000 and Win XP)
    WkUFindNWkUFind.exeMS Works Update Detection. MS Picture It! (versions 7 to current) use this automatic update feature during the log on process. It can also cause your system to automatically dial into your ISP as it tries to access the internet, if you have your system set to automatically dial when the internet is invoked. To manually update, go to Microsoft's Office/Works update site
    Wlan DrierXWinusb2.exeAdded by the WOOTBOT.DC WORM!
    Wlan DriverXavscan.exeAdded by the WOOTBOT.DH WORM!
    WLAN Status Tray AppletNWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
    wlancfgUwlancfg.exeInventel wireless router related - required in order to automatically connect to the Net at bootup.
    WLANSTA.EXENWLANSTA.EXESystem Tray icon for checking the status of a Wireless LAN
    WLAN_Cfg.exeYWLAN_Cfg.exeLinksys Instant Wireless USB Network Adapter driver
    WM VCRNWMVCR.exe WM_Recorder allows you to record Windows Media™ streaming Video or Audio content. Can be accessed via Start Menu -> Programs
    Wm24PanYWm24Pan.Exe ESI external sound card driver
    wm41a398Xrundll32.exe (path) wm41a398.dll,EnableRunDLL32 LZIO.com adware downloader
    WMAudioXwinlogon.exeNeveg.A worm
    WMAudioXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe) process
    WMBootNN/AAssociated with Logitech Wingman game controllers. Not required but what does it do?
    wmcbaacaXrundll32.exe (path) wmcbaaca.dll,EnableRunDLL32 LZIO.com adware downloader
    WMI Application InterfaceXwmiapi.exeAdded by the W32.SPYBOT.RBY WORM!
    WMIEXE.exeUwmiexe.exeNT component, used by Windows Millennium to detect  Plug and Play-compliant IEEE 1394 devices during the startup process. Since this is important for the computer to work properly if you have these, Windows Millennium protects wmiexe.exe and will restore the file even if it's deleted or renamed. Check here for some details on what to do to stop it loading
    WminfXWminf.exeAdded by the GEMA TROJAN!
    WminfoXWminfo.exeAdded by the GEMA TROJAN!
    wmiprvXwmiprv.exeAdded by the W32/RBOT-WM WORM!
    wmonXjusched.exeAdded by the W32/AGOBOT-OW WORM!
    WMP54Gv4YWMP54Gv4.exeLinksys WMP54G Wireless-G PCI Adapter driver
    wmplayer.exeXwmplayer.exeAdded by the Troj/Bancban-CZ TROJAN!
    WMPVer?WMPVer.EXEDritek System Inc. 3D Mouse related - is it required?
    wmsys32Xwmsys32.exeAdded by the BANPAES.B VIRUS!
    wmvXwinmonv.exeAdded by the TROJ/AGENT-DG TROJAN!
    WM_LOGIN?MSGLOGIN.EXEPart of McAfee Firewall. What is it for and is it needed?
    WN ServicesXwnsvc.exeAdded by the W32/KBBot-A TROJAN! Note: This trojan file is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder.
    WNADXWNAD.EXESpyware Added by running a program called "Yo Mama Osama" (osama.exe). See here for more and how to get rid of it. There are other ways this can show up on your system, and it will manifest itself by periodically opening a new browser window with advertising for copy DVD software and the like
    wnddrvXsvchost.exeAded by an unidentified TROJAN! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    WNILOGONXWNILOGON.exeAdded by the W32/Lewor-M TROJAN! Note: This trojan file is found in the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    WNSCXwns*****.exe (* = random char) PurityScan/Clickspring adware
    Wnsck2 driverXwlogf.exeAdded by the W32/SPYBOT-AF WORM!
    WNSIXwnscpsu.exe PurityScan/Clickspring adware
    WNSIXwnscpsv.exe PurityScan/Clickspring adware
    WNSIXwnscp**.exe (* = random char) PurityScan/Clickspring adware
    WNSTXwns*****.exe (* = random char) PurityScan/Clickspring adware
    wntlgnsXwntlgns.exeAdded by a CoolWebSearch parasite related TROJAN!
    WnxpupdateXupdatexp.exeAdded by the COMBRA.G WORM!
    wnxupdateXupdatexp.exeAdded by the W32/Combra-G WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    won updateXWAPDATE.EXEAdded by the WIN32.RBOT.N WORM!
    WooCnxMonNCnxMon.exeWanadoo ISP software related - not required - here's how to bypass it.
    WOOTASKBARICONNTaskbarIcon.exeWanadoo ISP taskbar icon - not required
    WoowatchNWatch.exeWanadoo ISP software, not required
    word pairXbopotsvr.exeAdded by the TROJ/SHED-A TROJAN!
    WordQ carat flagYWordQcrs.exeRelated to WordQ Writing Aid Software
    WordWebNwweb32.exeWordWeb - free theasaurus and dictionary. Start manually
    Workflo?workflow.exeRelated to BroadJump Client Foundation - broadband troubleshooting software installed by various companies. Is it required?
    Working System AnalyzerXsyswork.exeAdded by the W32/FORBOT-FZ WORM!
    worknote1X[FILE NAME].exeAdded by the W32.Meetot WORM!
    Works Calendar ReminderNwkcalrem.exeProduces a pop-up reminder of events scheduled using the MS Works Calendar
    WorksFUDNwkfud.exeA marketing program for MS Works
    Workstation SchedulerUwm95.exeDesktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled, it is required, otherwise, it is useless and a memory hog
    Workstation ServicesXwrkstn.exeAdded by the W32/RBOT-OJ WORM!
    Workstation Ver 5.0Xvmware.exeAdded by the W32/RBOT-AHB WORM!
    WorldAntiSpyXworldantispy.exeWorldAntiSpy, "rogue" spyware remover, installed as part of this_scam
    Worm DetectorUwd.exeWorm Detector - antivirus add-on for Outlook 2K or XP for handling worms and spam
    wormexeXwinstart.exeAdded by the EARLYBIRD VIRUS!
    wovaxXwovax.exe Win32.Daqa.A trojan
    wowXbar.exeAdware related downloader, detected as TrojanDropper.Win32.PurityScan.g
    wowXwwf.exeAdded by the TROJ/LINEAGE-Y TROJAN!
    Wpctrl or wpctrl95Nwpctrlnt.exe wpctrl95.exeWinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens, for example). Shortcut available via Display Properties
    WPCycle.exeYWpCycleWin.exeAdded when selecting Mplayer2 to open media files. Forces other codes to Wait for Previous instructions to end, preventing instability of your CPU (freezing)
    wpds.exeXdoriot.exeAdded by the TROJ/SMALL-KY TROJAN!
    wpwmgrsXwpwmgrs.exeAdded by the W32/MYTOB-DH WORM!
    WQKXWQK.exeAdded by a version of the KLEZ VIRUS!
    wr?WR.EXE??
    WR Command?wr.exe??
    WrCtrlNWrCtrl.exeWin-Route 4.27 NAT engine on Win2k Pro for connection sharing and security using Win-Route by Tiny Software. A connection sharing/Firewall Application. If service is disabled the program does not work, but you can manually start/stop the service with a shortcut the program installs at any time
    WRDialerXWrDialer.exeWinPoet DSL dialler
    WRECK GUARD?????
    WregBios?wregbios.exeDesktop Management BIOS (DMI BIOS) related. Apparently invokes the DosBios.exe file. Is it required?
    wrexecUwrexec.exeWatch Right - monitoring program, part of the PowerTools add-on for AOL. Records instant messages, E-mail, chat. Watch Right appears to be, and functions as an online clock updater which connects with the U.S. National Institute of Standards and Technology. It was designed for parents who wish to keep an eye on what their children are doing online
    wriste?wriste.exe??
    Write DVD-R!Usaimon.exeSaimon's WriteDVD! "gives total support for DVD-RAM drives. It provides many functions such as setting partitions on DVD-RAM disks and FixDVD! can diagnose and repair UDF formatted disks".
    ws2helpXws2help.exeAdded by a variant of the TROJ_SMALL.AN downloader TROJAN!
    ws2_32Xsvchst.exeAdded by the TROJ/VOKEN-A TROJAN!
    WSAConfigurationXsvchostt.exeAdded by the AGOBOT.ZT WORM!
    WSAConfigurationXwmon32.exeAdded by the W32.Gaobot.BAJ WORM!
    WSAConfigurationXwinlogon32.exeAdded by the W32/AGOBOT-WC WORM!
    WSAConfigurationXrpcxmn32.exeAdded by the AGOBOT.ABG WORM!
    WSAConfigurationXwin32upd.exeAdded by a variant of the WIN32.RBOT WORM!
    WSAConfigurationXdrrss.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    WSAConfigurationXntguard32.exeAdded by a variant of the AGOBOT/GAOBOT WORM!
    WSAConfigurationXcsrsvcs.exeAdded by the AGOBOT.VI WORM!
    WSAConfiguration1Xcsass.exeAdded by the AGOBOT.WH WORM!
    wsbklite?wsbklite.exeRelated to the Acer Soft Button on Acer Tablet PCs. Appears to do nothing so is it required?
    WSchedulerUWScheduler.exeWindows Scheduler - "schedule unattended running of applications, batch files, scripts and much more. Also, you can schedule popup reminders so you'll never forget reminders, tasks and other events."
    wscript.exeXvabian.vbsAdded by the VABI VIRUS!
    wscsvc.exeXwscsvc.exeAdded by a password stealing Banker TROJAN!
    Wsdata serviceXWSconf.exeAdded by the SDBOT.ZU WORM!
    wserverXwserver.exeAdded by the W32.NETSKY.AC WORM!
    WServiceUWService.exeTablet client Driver for UC-Logic Pen/Graphics Tablet
    wsg32Uwsg32.exe GoldenKeylog keystroke logger/monitoring program - remove unless you installed it yourself!
    wskrnlUwskrnl.exeAdded by the Spyware.ActMon surveillance software. Uninstall this software unless you put it there yourself.
    wsock32Xsvchost.exeAdded by the TROJ/HORST-A WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows svchost.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    wsock32Xwsock32.exeAdded by an unidentified WORM or TROJAN!
    wsrv32Xwsrv32.exeAdded by a TROJAN.CLICKER - identified by Kaspersky antivirus as Win32.Agent.ep
    WSSAConfigurationXwmmon32.exeAdded by the W32/Agobot-KC WORM!
    wssysUwssys.exe WebPI logs keystrokes and captures screenshots. If you didn't install this yourself remove it
    Wstat32 driverXWstat32.exeAdded by the LOONBOT VIRUS!
    wstimebYwstimeb.exeUsed with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
    WSVCSUSERVICES.EXE WALogger is a spyware program that logs keystrokes. If you didn't install this yourself remove it.
    wswpdYwswpd.exeUsed with some models of Panasonic, Epson and NEC printers. Some older drivers known to have a "memory leak". Needed for printing to work 
    wsys.exeUwsys.exe SpyloPCMonitor is a spyware program that monitors user activity, logs keystrokes, and takes screenshots. It ends the processes of anti-spyware programs. If you didn't install this yourself remove it.
    WT Game Channel or WT GameChannelNGameChannel.exe wtgamechannel.exeWild Tangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that Wild Tanget's privacy policy used to state they also collect and share individuals information, but that is no longer the case
    WTF TestXwtftest.exeAdded by the W32/RBOT-ACM WORM!
    WTIndicatorUSchedInd.exeWinTask - software that automates a variety of routine tasks quickly and simply
    WTSIXwapisvit.exe PurityScan/Clickspring adware
    WTSSXwapicc.exe PurityScan/Clickspring adware
    WTSSXwapisvsu.exe PurityScan/Clickspring adware
    WTSSXwapisu.exe PurityScan/Clickspring adware
    WTSSXwapiit.exe PurityScan/Clickspring adware
    WTSSXwap***.exe (* = random char) PurityScan/Clickspring adware
    WTSTXwapisvtr.exe PurityScan/Clickspring adware
    wuanguardXwuanguard32.exeAdded by the W32/RBOT-AAF WORM!
    wuauonX(Random Filename).exeAdded by the Troj/Bdoor-MC TROJAN!
    WUOLServiceYWUOLService9x.exeRemote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)
    wuosdialXwuosdial.exeAdded by a variant of the WIN32.RBOT WORM!
    WUPDXiglmtray.exeAdded by the TZET VIRUS!
    wupdXwin32.exeAdded by the TROJ/ORSE-C TROJAN!
    wupdXsymcsvc.exeAdded by the ABWIZ.C TROJAN!
    wupdateXwisvccz.exeAdded by the TROJ/ORSE-B TROJAN!
    wupdateXwi32.exeDownloader trojan, detected by Panda antivirus as Adware/Trustbid
    Wupdate driverX[various file names]Added by a variant of the W32.SPYBOT WORM!
    Wupdm32XWupdm32.exeAdded by the W32.MIDLAK WORM!
    wupdmgr32.exeXwupdmgr32.exeAdded by the Troj/Certif-I TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    wupdtXwupdt.exeAdded by the IMISERV.A TROJAN!
    WUSB11B.exeYWUSB11B.exeLinksys WUSB11 WLAN USB adapter
    WUSB54Gv2YInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be required
    WUSB54Gv4YWUSB54Gv4.exeWireless-G USB Wireless Network Adapter related - would appear to be required
    wuviewerXwuviewer.exeAdded by a Proxy_Trojan variant
    WUx_RegSvr?RegSvr32.exex is any number??
    wvsvcXwvsvc.exeAdded by the AGOBOT.YM WORM!
    WWKSXwsass.exeAdded by the W32/SDBOT-BT WORM!
    www.hidro.4t.comXenbiei.exeAdded by the BLASTER.F VIRUS!
    www.symantec.comXoz11111.exeAdded by the W32.Mydoom.W WORM!
    WXcmeinstX[path to file]Added by the RANCK-CD TROJAN!
    Wxp4XNorton Update.exeAdded by the W32.ERKEZ.D WORM!
    WXProcMgr ModuleNWXprocMgr.exeTVTonic from Wavexpress - "enjoy 3 full-screen, DVD-quality video channels for FREE". Allows data content to be downloaded and synchronized on your system
    wzhelperXwzhelper.exeSearchcentrix hijacker
    wzserviceXhess.exeAdded by the Backdoor.Win32.Hackarmy.w TROJAN!
    X ServerUX.exe"XoftWare for Windows" enables you to run network-based UNIX programs ("X programs" or "clients") side-by-side with Windows applications on your personal computer. You can also share programs and computing resources with host computers connected to your PC over a network
    x(Number from 1 to 7)Xx1.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx2.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx3.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx4.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx5.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx6.exeAdded by the Troj/Dadobra-A TROJAN!
    x(Number from 1 to 7)Xx7.exeAdded by the Troj/Dadobra-A TROJAN!
    X-Cleaner DeluxeUxcleaner.exe X-Cleaner_Deluxe - privacy and anti-spy application
    X-Cleaner FreewareUXCLEAN~1.EXE X-Cleaner_Freeware
    X-GrabberNsswizard.exeScreenShot Wizard
    X10 Device Network ServiceUx10nets.exeBelongs to X10 video streaming device(s).
    X10WeaxXWTHRTRAY.EXE WeatherCheck "bring the latest local weather to your desktop". Not recommended as it reportedly pops ads, and contains no uninstaller.
    x3watchUx3watch.exe"program helping with online integrity. Whenever you browse the internet and accesses a site which may contain questionable material, the program will save the site name on your computer. Approximately every 30 days, a person of your choice (an accountabiltiy partner) will receive an e-mail containing all possible questionable sites you may have visited within the month. This information is meant to encourage an open and honest conversation between friends and help us all be more accountable"
    x3yyX(path to trojan)Added by a TANNICK trojan infection
    XanaduNXanadu.exeXanadu - free language and translation wizard from Foreignword
    xBrotherMeCom?BrMeCom.exeRelated to Brother MFC-9200c printer. What does it do and is it required?
    xbtlUbootldr.exeAdded by the WSLogger surveillance software. Uninstall this software unless you put it there yourself.
    Xcpy1XXcpy1.exe BroadcastPC adware variant
    xdxqaXdewa.exeAdded by the W32/SDBOT-YB WORM!
    XE 8x LM StatusUlmsxxe.exeXerox XE8 series laser printer status monitor
    Xecuter.batXpsexec.batAdded by the BOOHOO VIRUS!
    XemiCoNADC.EXEXemiComputers Active Desktop Calendar
    XfireNXfire.exeTerratec DMXFire 1024 soundcard controlpanel
    xflashXxflash.exeAdded by the TROJ/BANCJ-A TROJAN!
    xflashXxflash.exeAdded by W32/YURIST-K WORM!
    xftpGraberXXftpgraber.exeAdded by the W32.ENVID.C WORM!
    XGIWatchDog?XWatDog.exeRelated to XGI Technology's Volari graphics cards - what does it do and is it required?
    xhiXxhi.exeAdded by the Troj/SCLog-A TROJAN!
    xhrmyXXhrmy.exe HyperLinker adware
    xicon?xicon.exePart of the IBM/XPoint Rapid Restore utility. What does it do and is it required?
    XiDXmmx.exeAdded by the ANALOGX VIRUS!
    XircWinModem4Yltcm000c.exeWinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information
    xitamiUXiwin32.exeXitami Multiplatform Open Source web server
    xkstartup?RunDll32 InstZ82.dll, SetUsbPrinterPortOn a system with a Lexmark printer
    xload32Xnetdd.exeAdded by the NETSPY TROJAN!
    XML ServiceXmsxml.exeAdded by the W32/RBOT-HD WORM!
    XNSearchAssistantXSrchAsst.exeiWon Search Assistant - spyware
    XoftSpyUXoftSpy.exeXoftSpy antispyware software
    xorXsvchost.exeAdded by the XORDOOR TROJAN! This is not the valid svchost.exe as described here
    xpXwinis.exeAdded by the W32/RBOT-WO WORM!
    xp service pack 2Xxpsp2.exeSdded as result of a W32/Rbot-KW worm infection
    xp32winXxpupdater02.exeAdded by the TROJ/MOSUCK-A TROJAN!
    Xpagent?xpagent.exePart of the IBM/XPoint Rapid Restore utility. What does it do and is it required?
    xpcfg?xpcfg.exe??
    Xpclient?xpclient.exePart of the IBM/XPoint Rapid Restore utility. What does it do and is it required?
    XPCPHOST SettingsXxpcphost.exeAdded by a variant of the WIN32.RBOT WORM!
    xpiupdateXxpiupdate.exeAdded by the W32/RBOT-AAB WORM!
    xpiupdateXxpiupdate.exeAdded by the W32/RBOT-AFY WORM!
    XPSoftXCVDAsDW.exeAdded by the W32/SDBOT-SY WORM!
    XPSP2 FirewallXxpsp2fw.exeAdded by the WIN32.SMALL.RN downloader TROJAN!
    xpstartXwini.exeAdded by the W32.PICRATE.A WORM!
    xpstatXwinlogins.exeAdded by the W32/RBOT-AAR WORM!
    XPsysXXPsys.exeAdded by the DELF-KQ or Troj/Dloader-SG TROJAN!
    xpsystemXservices.exe CoolWebSearch parasite related.
    xpsystemXMSXMIDI.EXE CoolWebSearch parasite variant, identified by Kaspersky_antivirus as TrojanDropper.Win32.Small.cw
    xpsystemXy.exe CoolWebSearch parasite related
    xpupdateXupdates.exeAdded by the W32.Bropia.L WORM!
    xp_systemXservices.exe Krepper-G TROJAN, a CoolWebSearch parasite variant or Troj/Krepper-R Note - this is NOT the legitimate services.exe process, which should NOT figure in Msconfig/Startup!
    xp_systemXwinlogon.exe Krepper-G trojan, a CoolWebSearch parasite variant - Note - this is NOT the legitimate Windows winlogon.exe process, which should NOT figure in Msconfig/Startup!
    xp_systemXservices.exeAdded by the W32.Conycspa.G WORM!
    xservX(Trojan executable)Added by the Troj/Stumpy-A TROJAN!
    XStop95UXStop95.exeXStop - internet filter
    xswinNxswin.exeInstalled with a Xerox Work Centre Pro 555. Unchecking it removes an "out of system memory" error
    XTCsgloader?XTCsgloader.exeAnother Xupiter toolbar variant??
    XTN Service DriversXwinxtn.exeAdded by the W32/Sdbot-YK WORM!
    XTNDConnect PC - 3CmPlmUAutodet.exeComponent of EasySync Pro. Synchronisation between Palm PDAs  and Microsoft Outlook
    XTNDConnect PC - ErPhn2UErPhn2.exeComponent of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook
    XTNDConnect PC - ErTrayUErTray.exeComponent of EasySync Pro. Synchronisation between SonyEricsson mobile phones and Microsoft Outlook
    XTNDConnect PC - LtNts4UNtsAgnt.exeComponent of EasySync Pro
    XtrayXxtray_link.exeTROJ_VB.JL trojan
    XtreamLok License ManagerUxl.exeLicense manager for xLok (XtreamLok) - prevents software being reverse engineered
    Xtrem parental controlUpcx.exeAdded by the ParentXtreme SPYWARE! **Note - If you didn't intentionally install this software remove it.
    XTServiceUpdateXXTServiceUpdate.exehahame.net adware downloader
    XtTb.exeXXtTb.exeTop-banners.com adware
    xuio.exe?xuio.exe??
    Xupiter StartupXXupiterStartup.exeXupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
    XupiterCfgLoaderXXTCfgLoader.exeBWCfgLoader.exeXupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
    xupiterstartup2003Xxupiterstartup2003.exeXupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
    XupiterToolbarLoaderXXupiterToolbarLoader.exeXupiter - adware and homepage hijacker. To remove Xupiter go here and to prevent it re-installing in the future see here
    xv_ctrlUv_ctrl.exe3dfx Underground Tools - "Gives direct hardware control to your video graphics adapter"
    xwareXxware.exeMalware downloader from xxsware.com, causes porn popups
    xwareXcskware.exeMalware downloader from xxsware.com, produces porn popups.
    XWMSUSBAPI?XWMSAPI.EXEPart of the installation of a Xerox WorkCentre printer/scanner. Is it required?
    xxcmXsys.exeAdded by the W32/KRISWORM-A WORM!
    xxsrSrv32Xxxsrsrv.exeAdded by the TROJ/BANCSDE-E TROJAN!
    XXXmpegXXXXmpeg.exeAdult content dialler
    xxxvideoXxxxvideo.exe AccessPlugin premium rate adult material dialer
    Y!TunnelBasicUYTBasic.exe Y!TunnelBasic software provides additional features to Yahoo! Messenger.
    Y!TunnelProUYTunnelPro.exeSpam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia
    Y!TunnelProUYTPro.exeSpam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia
    yaemu.exeXyaemu.exeAdded by the WIN32.DNSCHANGER.S TROJAN!
    yahoo groupsXupgrdmgr.exeAdded by a variant of the WIN32.RBOT WORM!
    Yahoo HP Reminder 1.1?yr.exe??
    Yahoo Instant MessengarXYahooMsgr.exeAdded by the WIN32.SDBOT.GEN TROJAN!
    Yahoo MessengerXYahoomsg.exeAdded by an unidentified WORM or TROJAN!
    Yahoo MessengerXYPager.exeAdded by the W32/RBOT-QO WORM!
    Yahoo UpdateXYahoo.exeAdded by the Yahoo! TROJAN!
    Yahoo UpdaterXMessenger.exeAdded by the W32/Forbot-FE WORM!
    Yahoo! Pager or ypagerNypager.exeYahoo! Messenger allows you to send instant messages. Available via Start -> Programs
    Yahoo2000XAnti.exeAdded by the RBOT.ATK WORM!
    YahooStockXystckAO32.exe Adtomi adware
    YahooStockXPrmvr.exe Adtomi adware
    yahoo_toolbar lptt01 or yahoo_toolbar ml097eXyahoo_toolbar.exeVariant of the RapidBlaster parasite (in a "yahoo_toolbar" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
    YAMAHA AC-XG Power Utility?yacpower.exeYAMAHA AC-XG Power Utility - what does it do and is it required?
    YAMAHA DS-XG LauncherNdslaunch.exeSystem Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups
    Yankee Clipper IIINYankClip.exeYankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar "Outlook" interface'. Freeware
    YBrowserNybrwicon.exeSBC Yahoo! Browser system tray icon
    yeahdude.exeXhallowelt.exeAdded by the GAOBOT.RS or GAOBOT.SA WORMS!
    YOPNyop.exeDashboard Module for SBC Yahoo! Online_Protection
    You've Got Pictures ScreensaverUygpsstra.exeAOL You've Got Pictures® Screensaver
    YOW tuner?WatchPNM.exe??
    YPCUypc.exeYahoo Parental controls - "Let you decide what type of sites and Yahoo! services your kids can access"
    YTrayMagic Lite 1YYTRAYMAGIC.EXEYTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored
    YugoslaviaXyugoslavia.exePremium rate adult content dialer
    Yumgo's Homepage Protector V1UYumgoHomepageProtector.exe Yumgo's Homepage Protector
    ywwvc.exeXywwvc.exeAdded by the Troj/StartPa-HR TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ywzizdonXywzizdon.exeFree_Scratch_Cards foistware
    yxXuu.exeAdded by the W32/Agobot-YX WORM! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    yyyyyyyyX(path to trojan)Added by the MUMUBOY.B VIRUS!
    yz.exeXyz.exeAdded by the VARDO VIRUS!
    YZHXYZH.exeAdded by the W32/LegMir-BM Virus! Note: This Keylogging virus file is found in the Windows or Winnt folder.
    YZH.SYSXYZH.exeAdded by the W32.SOPHILY VIRUS!
    z-WrDialerUWrDialer.exeWinPoet DSL dialer
    ZaCkerX(filename).PIFAdded by the HOLAR.A VIRUS! where <filename> is the worm filename
    ZackerXZacker.exeAdded by the GEMEL VIRUS!
    zangoXzango.exe 180Solutions/N-Case adware variant
    Zango SiteFinderXZangoSiteFinder.exe180Solutions ZangoSearch adware variant
    Zango TvTimesXZANGOT~1.EXE ZangoSearch adware
    zanuXzanu.exe 180Solutions/N-Case adware variant
    ZaproYZapro.exeFirewall program from Zonelabs - paid for version
    zBrowser LauncherUiTouch.exeFor a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn\'t have them
    zBrowser LauncherUCommandr.exeFor a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc. if it doesn't have them
    ZcfgsvcUZCfgSvc.exeZero Config MFC Application, part of Intel’s ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing “Not Responding” or “End this Program” shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have Windows XP/2003, try setting the “Wireless Zero Configuration” service to Disabled.
    zcprooXqssstiej.exePossible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguise. see this thread
    ZDConfig?ZDConfig.exeRelated to various brands of Wireless USB LAN Adapter - what does it do and is it required?
    zdnetNkontiki.exeKontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops
    ZebusNmsdc32.exeRuns a HTML tutorial on the Zebus web-site
    Zekio StartupsXznksvc32.exeAdded by the W32/AGOBOT-AGI WORM!
    Zen.AX(path to trojan)Added by a Perl/Zoomen-A trojan infection
    ZenetXrundll32 CNBabe.dll, DllStartupCommonName Toolbar spyware. To uninstall see here
    ZenoX*sys****.exe (* = random char/digit)Added by ZenoSearch adware - filenames spotted include rsyssx2d.exe, rsyssx2d.exe, rsystu2d.exe, ysysyz2d.exe and so on.
    ZENRCYzenrc32.exeThe main component of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management".Leave well alone
    ZENRC Tray IconYzentray.exePart of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management".Best left alone
    ZENworks Imaging ServiceYZISWin.exeImaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management"
    ZeroAdsU0ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually
    ZeroAdsULAS0Ads.exeZeroAds - culls ads, cookies and pop-ups. Required for the cookie interception to work
    ZeroSpywareUZeroSpyware.exeFBM Software ZeroSpyware 2004 spyware detector and remover
    zervpack2Xupdate2.exeAdded by the SDBOT.WD WORM!
    zerzvpack2Xuzpdate2.exeAdded by a Rbot-KA worm infection
    ZGNUBI?ZGNUBI.exe??
    Zi5XAntiVirus Update.exeAdded by the W32.Erkez.G WORM! Note: This worm file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    ZIBMACCXrundll.exe -> ZIBMACC.INFZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435)
    ZingSpoolerUZingSpooler.exeWas used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums
    Zinio DLMNZDLM.EXEZinio - used to read magazines in digital rather than paper format
    Zip Driver LoaderXmsload32.exeAdded by the OBLIVION TROJAN!
    Zip Driver LoaderXZipLoader.exeAdded by the OBLIVION TROJAN!
    ZipDisk IconsUIMGICON.EXEDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
    ZipGenius CleanNzg.exeZipGenius file compression utility
    ziphelpXziphelp.exe CoolWebSearch parasite related.
    ZipMagicNzm32.exeZip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first
    zlclient or Zone Labs ClientYzlclient.exeFirewall program from Zonelabs. Pro version inlcudes other online security options
    ZLHUZLH.EXESystem Tray icon for Norman Antivirus
    ZonavirusX0Added by the KITRO.D (or ARGEN.A) VIRUS!
    Zone AlarmXvsmon.exe WORM_RBOT.BO
    Zone Labs Client ExXsvchost.exeAdded by the W.32NETSKY.F WORM! **Note This is not the valid svchost.exe as described for WinXP or Win2K . Located in a Windows directory, and not in Windows\System32
    Zone systemXszchost.exeAdded by the TROJ/MULTIDR-AC TROJAN!
    ZoneAlarmYzonealarm.exeFirewall program from Zonelabs - free version
    zonealarmXmcmm.exe, random file namesAdded by an unknown worm or trojan infection
    ZonealarmXRemoveme.exeAdded by the W32/FORBOT-BG WORM!
    ZoneAlarm PlusYzaplus.exeFirewall program from Zonelabs - paid for version
    ZoneAlarm ProYZapro.exeFirewall program from Zonelabs - paid for version
    ZoomUzoom.exeZoom - speeds up Windows startup and manages startup applications
    ZoomingHook?ZoomingHook.exeRelated to the Toshiba Zooming Utility for Tablet PC - what does it do and is it required?
    ZPOINT32YZPOINT32.exeUSB graphics/writing tablet driver
    zSearchXZstb.exeTotalVelocity zSearch parasite
    zsmsXsmss.exeAdded by the BANCOS-CK TROJAN! - Note - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows smss.exe process, located in the Winnt/System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    zsmsgsXiservice.exeAdded by the TROJ/BANCOS-BU TROJAN!
    zsmssXsmss.exeAdded by the Troj/Bancos-DD TROJAN! Note: This is not the legitimate Windows Process. (Which is found in the System32 folder.) The legitimate Windows Process should not be seen in Msconfig or as a Startup item. This trojan file is found in the Windows or Winnt folder.
    zSPGuardUSpguard.exe"StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'."
    ZStartX[various file names]Adware, probably VX2/Transponder related - filenames spotted include rdxregpp.exe, tdxregrs.exe and more.
    ZstartXcxdxregt.exe ZenoSearch adware component
    ZtgServerSwitchXserver.vbsZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
    ZupdateXZupdate.exeB3d Projector - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents
    zzbXzzb.exe IAGold_adware downloader
    zzb2Xzzb2.exe IAGold_adware downloader
    zzgshpXgshp.vbsHomepage hi-jacker that re-defines your IE or Netscape start page
    zztpXsvchost.exeAdded by the TANNICK.B TROJAN! - Note - this is NOT the legitimate Windows svchost.exe process, which should NOT figure in Msconfig/Startup!
    zzz-hpi-boot?hpi-boot.exeAssociated with HP Photosmart printers
    zzzCamlnSuitelll?setup.exe 46***??
    zzzhpsetup?setup.exe??
    [default]X[original folder]\DrWatson32.exeAdded by the Dremn TROJAN!
    [default]X"%System%\syscache\DrWatson32.exe"Added by the Dremn TROJAN!
    [Ephemeral 2.5] by TreeHuggerX(Path to worm)Added by the W32/Lemoor-C WORM!
    [Ephemeral 2.x] by TreeHuggerX(path to worm)Added by the LEMOOR.A WORM! where "x" represents 3 or 4
    [file name]X[path to file name]Added by the PWSteal.Reanet.B TROJAN!
    [filename]Xsvchost.scrAdded by the BANKER-CC TROJAN!
    [random characters]Srv32X\[random characters]srv.exeAdded by the PWSteal.Botuk TROJAN!
    [random name]Xw?nlogon.exe PurityScan adware variant
    [random name]Xr?ndll32.exe PurityScan adware variant
    [random name]X??xplore.exe PurityScan adware variant
    [random name]Xw?nword.exe PurityScan adware variant
    [random name]X??oolsv.exe PurityScan adware variant
    [random name]Xse?vices.exe PurityScan adware variant
    [random name]X??chost.exe PurityScan adware variant
    [random name]Xt?skmgr.exe PurityScan/Clickspring adware
    [random name]Xl?gonui.exe PurityScan/Clickspring adware
    [random name]Xw?auboot.exe PurityScan/Clickspring adware
    [random name]Xw?auclt.exe PurityScan/Clickspring adware
    [random name]X??erinit.exe PurityScan/Clickspring adware
    [random name]Xr?gsvr32.exe PurityScan/Clickspring adware
    [random name]Xn?tepad.exe PurityScan/Clickspring adware
    [random name]Xw?wexec.exe PurityScan/Clickspring adware
    [random name]Xw?crtupd.exe PurityScan/Clickspring adware
    [random name]X??plorer.exe PurityScan/Clickspring adware
    [random name]X?hkdsk.exe PurityScan/Clickspring adware
    [random name]Xd?dplay.exe PurityScan/Clickspring adware
    [random name]Xm?iexec.exe PurityScan/Clickspring adware
    [random name]X?hkntfs.exe PurityScan/Clickspring adware
    [random name]Xj?vaw.exe PurityScan/Clickspring adware
    [random name]Xn?pdb.exe PurityScan/Clickspring adware
    [random name]Xn?lookup.exe PurityScan/Clickspring adware
    [random name]Xm?config.exe PurityScan/Clickspring adware
    [random name]X?ttrib.exe PurityScan/Clickspring adware
    [random name]Xl?ass.exe PurityScan/Clickspring adware
    [random name]X??anregw.exe PurityScan/Clickspring adware
    [random name]Xd?xplore.exe PurityScan/Clickspring adware
    [random name]Xw?aclt.exe PurityScan/Clickspring adware
    [random name]Xdexplore.exe PurityScan/Clickspring adware
    [random name]Xwucrtupd.exe PurityScan/Clickspring adware - do NOT confuse with the Windows Critical Update Notification application as described here
    [random name]Xdvdplay.exe PurityScan/Clickspring adware
    [random name]X??ool32.exe PurityScan/Clickspring adware
    [random name]Xspoolsv.exe PurityScan/Clickspring adware
    [random name]X??rvices.exe PurityScan/Clickspring adware
    [random name]Xchkdsk.exe PurityScan/Clickspring adware - unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2000/NT always be located in the Winnt\System32 or Windows\System32 folder, and ought moreover NOT to figure among the startups!
    [random name]X?ti2evxx.exe PurityScan/Clickspring adware
    [random name]X??rss.exe PurityScan/Clickspring adware
    [random name]Xr?gedit.exe PurityScan/Clickspring adware
    [random name]Xscanregw.exe PurityScan/Clickspring adware
    [random name]Xwuauboot.exe PurityScan/Clickspring adware = NOTE: Do NOT confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup!
    [random name]Xn?tdde.exe PurityScan/Clickspring adware
    [random name]Xr?ndll.exe PurityScan/Clickspring adware
    [random name]Xping.exe PurityScan/Clickspring adware - NOTE - do not confuse with the Microsoft utility of the same name as described here
    [random name]Xw?nspool.exe PurityScan/Clickspring adware.
    [random name]XCXTPLS_LOADER.EXE AproposMedia adware
    [random name]Xm?dtc.exe PurityScan/Clickspring adware
    [Random service name]X"%System%\[Random file name]"Added by the W32.Namshare WORM!
    [System Mechanic Professional Update [Incinerator.dll]NREREG: [path] Incinerator.dll System_Mechanic's "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again.
    [various filenames]Xqtsks.exeAdded by the WEBDOR.Y TROJAN
    [various names]XSYSTRAV.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xcontrol64.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xnewbreed.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xstuffmon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XParisM.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XRtlFindVal.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xcmon14.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XEXE32EXE.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xms-its.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xiehelper.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X_ctcp.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbnui.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbingo9.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTestimonials.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTorontoMail.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xgabber.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XNsCplTray.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XActionScr.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xprogmen.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsound64.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xdstart2.exeAdware - recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.alw
    [various names]Xmsdos32.exeAdded by a variant of the WIN32.AGENT.AH downloader TROJAN!
    [various names]Xsitebar.exeAdded by an unidentified TROJAN!
    [various names]Xtmservice.exeAdded by a variant of the WIN32.RBOT WORM!
    [various names]Xdriver32.exeAdded by a variant of the W32/SDBOT WORM!
    [various names]XUint32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbackorif.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbhoserv.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xhyandex.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XShaitan1678.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X34763.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XMNTP.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XWinInitDll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xzxc.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XDest068.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xxxtoolbar.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xkillall.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XKargo.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsysmon12.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xdialer423.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsrbho.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xprgsys0984.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsysconf16.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xmedia64.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XStartCpl.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xabrek.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XscanSYS.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTrayz.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XMsNetHelper.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xinstall2.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbr0ken.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xatl_helper.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XDCC_send.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XUserSp1.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xftbar.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xclamav.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xslamm.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xnew32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XPreliminary.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xpanel_its.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XBogobot.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XSAPSTR.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xcmon14.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XBrong32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xdiskserv.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xawinrar.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTRPT.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xmoniter.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XXTermInit.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XNSYSCPLSTR.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbarint.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xuio.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XLOPTCON.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XWTFCTF.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xzantu.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XDTOURS.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xavpmondll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XSetupExeDll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xtypeconf.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xmsag.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xpizda.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xprcmon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xexpoler.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X10010.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XKeywordFinder.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xcnftips.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xwormexe.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xinit32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XExchangeMaster.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XSpyElim.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XBoundRec.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X321102.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xopenstre.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xforces_elite.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XNopeZ.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XServiceprocess.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xutsgmon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xstartman.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xjopplerg.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xssweeper.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xbackd.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xmozilla-text.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XMON76234.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XFLKPT.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xkeybdll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsbin.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTemplateDongle.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xsyspanel.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xteqq32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xnmdllw.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XInpriseMon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XSysEntry.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xdefect08.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XAppMasterCenter.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XWhatsNewBot.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XCToolBar.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XERTYDF.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xdriver64.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xiesetupdll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xborlandg.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XAliceSD.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XPrcIdle.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xtrycrt.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xvxdman.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XStatusCheck.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XATLIEHELPER.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X321102.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xcorrida.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XNukeSpan.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xpowerdll.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xqwe.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XSysSupport.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XTForm1.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xxwiz.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XJAguAr.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XABCXYZ.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]XdePloy.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]Xexe81.exe MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on.
    [various names]Xseli.exe MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on.
    [various names]Xexe82.exe MediaMotor/Popuppers adware variant. Names spotted include SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on.
    [various names]XMSTCPDLL.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    [various names]X80d0.exe MediaMotor/Popuppers adware variant. Names spotted include 80d0, SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on
    IEService.exeXIEService.exeFastFind parasite variant
    Pribi.exeXPribi.exe FastFind adware variant
    \TOOLS.exeXtools.exeLycos SideSearch/Fastfind.org adware
    ^`d}qZxuX~`d}qzxu3zYFAdded by the GAOBOT.GEN!POLY WORM!
    _AntiSpywareUMssCli.exeMcAfee AntiSpyware
    _Cat1Xnmmst.exeAdded by the TROJ_SMALL.SD TROJAN!
    _Cat2Xnmstt.exeAdded by the TROJ/SMALL-DT downloader TROJAN!
    _Cat3Xmsmsgrxp.exeAdded by a variant of the TROJ/SMALL-DT downloader TROJAN
    _Cat4Xmsmsgr2.exeAdded by the TROJ/SMALL-EB TROJAN!
    _HazafibbX(path to file name)Added by a ZAFI.B WORM! infection
    _ntrdlhostX_Ntrdlhost.exeAdded by the TROJ/DLOADER-JV TROJAN!
    _ntrRescueServiceX_ntrrs.exeAdded by the TROJ/DLOADER-JV TROJAN!
    _pnd_Panda AntivirusX_pnd_*****.exe (* = random char/digit)Malware! - detected by ESET's Nod32 antivirus as Win32/TrojanDropper.Agent.NAK
    _SetvXSetv.comAdded by the W32.Besam WORM! Note: This worm\trojan file is found in the Windows or Winnt folder.
    _svchost.conXsvchost.comAdded by the W32.ERKEZ.C WORM!
    _SystemBootXservices.exeAdded by the TROJ/SOBER-Q TROJAN!! - NOTE - this file is placed in a "%Windir%\Help\Help" folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    _SystemDriverXcsrss.exeAdded by the ASCETIC.B TROJAN - Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, and which should NOT figure in Msconfig!
    _System_RunX_svchost_.exeAdded by the Troj/Lineage-Z TROJAN!
    _tdiserv_X_tdicli_.exeAdded by the W32/Tdibd-A WORM!
    _tdiserv_X_tdicli_.exeAdded by the W32.TDISERV.A WORM!
    _winadmUwinadm.exeParents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC"
    _WinCheckXservices.exeAdded by the W32.Sober.V WORM! Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.
    _WindowsXservices.exeAdded by the W32.Sober.X WORM! Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.) This worm file (services.exe) is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
    _WinMainXwinexec.exeAdded by the Troj/Dloader-XX TROJAN! Note: Copies itself to the Windows (95/98/ME/XP) or WINNT (NT/2000) folder.
    _WinStartXservices.exeAdded by the W32.SOBER.O WORM! - Note - this file is placed in a "%Windir%\Connection Wizard\Status folder, and should NOT be confused with the legitimate Windows services.exe process, located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    _winsystem.sysXsmss.exeAdded by the W32.Sober.K WORM! ** Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup!
    _x-FinderX_x-Finder.exeDisconnects and redials an ISP modem to an adult content site
    __ZF5X(Path to worm file)Added by the W32.Erkez.F WORM! Note: Be sure to check the link for this one, it use's 5 and 11 digit random file names and Anti-Virus vendor folder names.
    {0228e555-4f9c-4e35-a3ec-b109a192b4c2}Ugnotify.exeGoogle Gmail_notifier . Alerts you when you have new Gmail messages.
    {12EE7A5E-0674-42f9-A76B-000000004D00}Xrundll32.exe stlb2.dll,DllRunMain BrowserAid/Startium parasite
    {2CF0B992-5EEB-4143-99C0-5297EF71F444}Xrundll32.exe stlbdist.dll, DllRunMainBrowserAid/Startium parasite
    {2CF0B992-5EEB-4143-99C2-5297EF71F44B}Xrundll32.exe stlbupdt.DLL, DllRunMainBrowserAid/Startium parasite
    {357AA41A-B7A8-4632-A27D-5B980B25CF43}X(Path to Trojan executable)Added by the Troj/Small-EP TROJAN!
    ®Windows UpdateXsvchosts.exeAdded by the FRUTCA TROJAN!
    This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
    If you find the information on these pages useful, why not make a donation to help towards its maintenance :- or E-mail me.


    Engine Version 2.0 by CastleCops