Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 8/7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 28th April, 2016
49109 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1030 results found for B
Startup Item or Name | Status | Command or Data | Description | Tested |
---|---|---|---|---|
b.exe | X | b.exe | Added by the SDBOT.BND WORM! | No |
GoogleTalke | X | B.exe | Detected by Dr.Web as Trojan.DownLoader1.54591 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
Startname | X | b.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.WB | No |
RingtoneFanatic EPM Support | U | b0medint.exe | RingtoneFanatic toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\RingtoneFanatic_b0\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
RingtoneFanatic Search Scope Monitor | U | b0srchmn.exe | RingtoneFanatic toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\RingtoneFanatic_b0\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Mi7sft sdce | X | b0yz.exe | Added by the RBOT.CWG WORM! | No |
6CCAHM2L6VPT | X | B1IKOIS1.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
ISUSPM STARTUP | X | B25135~1 | Detected by Intel Security/McAfee as W32/Ramnit.a | No |
b4 | X | b4.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL.Keylogger. The file is located in %AppData% | No |
b4aOTB | U | b4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)" | Yes |
Backup4all 3 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 3.* | Yes |
Backup4all OTB Agent | U | b4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)" | Yes |
Backup4all Professional 4 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for Backup4all Professional. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.* | Yes |
Backup4all Standard 4 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for Backup4all Standard. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.* | Yes |
System Service | X | b4db0yz.exe | Detected by Sophos as W32/Rbot-CLO | No |
b5857819bb096c04134249d6f4e71934.exesecurity-hilla# | X | b5857819bb096c04134249d6f4e71934.exesecurity-hilla# | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.Agent - where # represents a digit. The file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
security-hilla# | X | b5857819bb096c04134249d6f4e71934.exesecurity-hilla# | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.Agent - where # represents a digit. The file is located in %UserStartup% | No |
4Y3Y0C3AVF7W1VXDNTJTQ | X | B6232F3ABCC.exe | Detected by Malwarebytes Anti-Malware as Trojan.SpyEyes. The file is located in %Root%\Recycle.Bin | No |
F3CCE815 | X | B6EA.exe | Detected by Intel Security/McAfee as RDN/Generic.grp!gg and by Malwarebytes Anti-Malware as Backdoor.Messa.E | No |
MyTransitGuide EPM Support | U | b7medint.exe | MyTransitGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\MyTransitGuide_b7\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
6IG7WSE42UU4 | X | B7MI2O4K.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
MyTransitGuide Search Scope Monitor | U | b7srchmn.exe | MyTransitGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\MyTransitGuide_b7\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
TotalDatingGuide EPM Support | U | b8medint.exe | TotalDatingGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\TotalDatingGuide_b8\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
b9 | Y | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" | Yes |
Firetrust Benign | Y | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" | Yes |
HKCU | X | baby.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System% | No |
HKLM | X | baby.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System% | No |
Policies | X | baby.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System% | No |
Babylon | X | Babylon.exe | Detected by Dr.Web as Trojan.Siggen6.3731 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
Babylon Client | N | Babylon.exe | Core program for the Babylon translation and dictionary tool | No |
Babylon Translator | N | Babylon.exe | Part of an older version of the Babylon translation and dictionary tool | No |
BabylonToolbar | N | BabylonToolbarsrv.exe | Toolbar installed with the Babylon translation and dictionary tool | No |
Back2zip | U | Back2zip.exe | Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up | No |
Services | X | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe | No |
Service | X | back32.exe service.exe | Detected by Symantec as Backdoor.IRC.Aladinz.H. Both files are located in %System%\CAB | No |
[various names] | X | backd.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
notepad.exe | X | background.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData% | No |
BacKGround Agent | ? | BackgroundAgent.exe | Part of the Acer Open Platform (AOP) Framework - "Leveraging its established cloud and application services know-how, Acer is creating new solutions and platform alliances, helping software and hardware developers build their own cloud apps based on the AOP that offers major advantages including high scalability and reliability, and security" | No |
BackgroundSwitcher | U | BackgroundSwitcher.exe | John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting | No |
[various names] | X | backorif.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
Timed Backups Manager Startup | N | BACKTIME.EXE | Backup Plus by Avantrix - "allows you to easily and quickly back up all your important data. Its features include the ability to back up to just about any device, including a disk, a Zip drive, a Jaz drive, and even formatted CD-RW/DVD-RW discs." No longer supported | No |
Display | X | backup.exe | Added by the BRONTOK-CR WORM! | No |
Firewall | X | Backup.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.E. The file is located in %Root%\File Backup | No |
System Service | X | backup.exe | Added by the PACKBOT.AA WORM! The file is located in %System% | No |
Backup Service | X | backup.svc | Unidentified adware | No |
Backup4all | U | Backup4all.exe | Backup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage" | Yes |
Backup4all 3 | U | Backup4all.exe | Backup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage." Version 3.* | Yes |
Backup4all Lite 4 | U | Backup4all.exe | Backup4all Lite by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
Backup4all Professional 4 | U | Backup4all.exe | Backup4all Professional by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
Backup4all Standard 4 | U | Backup4all.exe | Backup4all Standard by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
BackupAgent | U | BackupAgent.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.StrongVault. The file is located in %ProgramFiles%\Strongvault Online Backup. If bundled with another installer or not installed by choice then remove it | No |
backupClient-steg | U | backupClient-steg.exe | System Tray access to, and notifications for Steganos Backup by Steganos Software GmbH - which is no longer in their main product line but is still supported | Yes |
backupClient-steg.exe | U | backupClient-steg.exe | System Tray access to, and notifications for Steganos Backup by Steganos Software GmbH - which is no longer in their main product line but is still supported | Yes |
Steganos Backup | U | backupClient-steg.exe | System Tray access to, and notifications for Steganos Backup by Steganos Software GmbH - which is no longer in their main product line but is still supported | Yes |
BackupGenie | U | BackupGenie.exe | BackupGenie online backup solution - with which "your files are automatically and silently backed up in the background without interfering with your work." Detected by Malwarebytes Anti-Malware as PUP.Optional.BackupGenie. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\BackupGenie. If bundled with another installer or not installed by choice then remove it | No |
BackupManagerTray | ? | BackupManagerTray.exe | Acer Backup Manager, Packard Bell MyBackup and Gateway MyBackup - OEM backup software by NewTech Infosystems, Inc, makers of NTI Backup Now EZ and NTI Backup Now | No |
BackupNotify | N | backupnotify.exe | System Tray "balloon" backup reminder for HP Image Zone Plus | No |
BackupNowEZtray | U | BackupNowEZtray.exe | System Tray access to the Backup Now EZ backup utility from NTI Corporation | No |
MSbackups | X | backups.exe | Detected by Sophos as Troj/Banload-TL | No |
System Backup Services | X | backups32.exe | Added by a variant of Backdoor:Win32/Rbot. The file is located in %System% | No |
BackUpSecurity | X | BackUpSecurity.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.DE. The file is located in %LocalAppData% | No |
STO Backup Service | U | BackUpSvr.exe | Backup feature of Samsung's SmarThru Office - "a powerful document management application for Office users. It creates, stores and edits scan images, and delivers them to each application" | No |
BackupSys | X | BackupSys.exe | Detected by Intel Security/McAfee as Generic PWS.di and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BackUp[8 or more digits] | X | BackUp[8 or more digits].exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.WNTE. The file is located in %AppData% - see an example here | No |
hp center | N | BackWeb-137903.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
Updates from HP | N | BackWeb-137903.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
Compaq Connections | N | BackWeb-1940576.exe | Automatically detects an internet connection and downloads any available updates for Compaq PCs along with messages and product offers | No |
ActivSurf | N | backweb-4448364.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates | No |
Kodak Software Updater | N | backWeb-7288971.exe | Software updater for Kodak products - automatically detects an internet connection and downloads any available updates | No |
Data LifeGuard | N | backWeb-8263142.exe | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updates | No |
backWeb-8876480 | N | backweb-8876480.exe | Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech | Yes |
LDM | N | backweb-8876480.exe | Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech | Yes |
BackWeb | N | backweb.exe | Automatically detects an internet connection and downloads any available updates along with messages and product offers. Typical on Compaq and HP PC's but not restricted to those OEM's | No |
HP Updates | N | backweb.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
Updates from HP | N | backweb.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
Data LifeGuard | N | BACKWE~1.EXE | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updates | No |
Backwork | N | Backwork.exe | Backwork anti-trojan by Framework Executive - "Keep your system secure with this anti-Trojan horse software. You can easily detect and remove over 150 Trojan horses, which are pieces of malicious code that can overwrite your data, allow other users access to your computer, and cause other damage." No longer available | No |
bacon | X | bacon.exe | Detected by Intel Security/McAfee as Generic.bfg and by Malwarebytes Anti-Malware as Adware.KorAd | No |
BACPI10 | U | bacpi10a.exe | Known as "PowerKey" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray | No |
BacsTray | N | BacsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems | No |
BaCuTuR | X | BaCuTuR.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.E. The file is located in %LocalAppData% | No |
SYS2 | X | bad1.exe | Detected by Sophos as W32/SillyFDC-AP and by Malwarebytes Anti-Malware as Worm.AutoRun.E | No |
SYS3 | X | bad2.exe | Detected by Sophos as W32/SillyFDC-AP and by Malwarebytes Anti-Malware as Trojan.Agent | No |
SYS4 | X | bad3.exe | Detected by Sophos as W32/SillyFDC-AP and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Wupdate driver | X | BADDATE.EXE | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
good | X | badvir.exe | Detected by Sophos as W32/Silov-B | No |
[32 random hex numbers] | X | badware-protector.exe | Badware Protector rogue security software - not recommended, removal instructions here | No |
Quicken Scheduled Updates | N | bagent.exe | Quicken background downloading module | No |
hohoba | X | bahomaname.exe | Detected by Sophos as Troj/Agent-ABXF | No |
apphide | Y | baidu.exe | Part of Baidu Antivirus. Required if you use it but not recommended as better alternatives are available - see here | No |
BaiduAnTray | Y | BaiduAnTray.exe | Part of Baidu Antivirus. Required if you use it but not recommended as better alternatives are available - see here | No |
baidusdTray | Y | BaiduSdTray.exe | Part of Baidu Antivirus. Required if you use it but not recommended as better alternatives are available - see here | No |
Baigoo.exe | U | Baigoo.exe | Baigoo surveillance software. Uninstall this software unless you put it there yourself | No |
X | BakBakim.exe | Detected by Intel Security/McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent | No | |
FlashUpdate | X | BakBakim.exe | Detected by Dr.Web as Trojan.DownLoader10.53560 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Microsoft Personal Firewalls | X | bakw.exe | Detected by Sophos as W32/Rbot-KS | No |
Ball | X | Ball.exe | Detected by Dr.Web as Trojan.DownLoader7.25886 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
Ball.exe | X | Ball.exe | Detected by Dr.Web as Trojan.DownLoader7.25886 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - the file is located in %AllUsersStartup% and %UserStartup% and its presence there ensures it runs when Windows starts | No |
Windows Service Pack Auto Update | X | ballin.exe | Added by an unidentified WORM or TROJAN! | No |
HorngTech4D | Y | bally4d.exe | HorngTech 4D mouse driver | No |
Bamboo Dock | U | Bamboo Dock.exe | Bamboo Dock by Wacom "is a cross platform desktop application allowing you to publish your apps based on the Adobe Flash Platform to a large community of creative users" | No |
BanannaStand | X | bananna.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BN. The file is located in %MyDocuments%\bstand | No |
WIN32SNDS | X | banc.exe | Added by an unidentified WORM or TROJAN! | No |
Bandicam Crack | X | Bandicam Crack.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
Bandicam | X | Bandicam.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
bandmon | U | bandmon.exe | Rokario Bandwidth Monitor | No |
TOOLS | X | bandtools.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.E. The file is located in %LocalAppData% | No |
Bandwidth Monitor Pro | U | Bandwidth Monitor Pro.exe | Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP | No |
Bandwidth Meter Pro | N | BandwidthMeterPro.exe | System Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time" | Yes |
BandwidthMeterPro | N | BandwidthMeterPro.exe | System Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time" | Yes |
banegygafaci | X | banegygafaci.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
Banker.exe | X | Banker.exe | Detected by Dr.Web as BackDoor.Bulknet.1050 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
bank_ganster_info.exe | X | bank_ganster_info.exe | Detected by Dr.Web as Trojan.Siggen6.24011 and by Malwarebytes Anti-Malware as Backdoor.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
AtariBanner | N | Banner.exe | Related to the Atari Anniversary Edition Volume 2 games collection from Infogrames | No |
Alcohol120 | X | bannyhop.exe | Detected by Dr.Web as Trojan.Siggen5.37516 and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
Banpopup by Pratik | U | Banpopup.exe | Banpopup - popup killer | No |
bantool | X | bantool.exe | Malware installed by different rogue security software including SpyKillerPro | No |
FUKLBAR | X | bar.exe | Detected by Symantec as Adware.PurityScan - also see the archived version of Andrew Clover's page. The file is located in %Root% | No |
bargains | X | bargainbuddy.exe | BargainBuddy adware | No |
bargains | X | bargains.exe | BargainBuddy adware | No |
BullsEye Network | X | bargains.exe | Bullseye adware | No |
[various names] | X | barint.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BaroSearch | X | barosearchs.exe | Detected by Intel Security/McAfee as Generic.tfr | No |
svchoost | X | Bartek.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SVC. The file is located in %WinTemp% | No |
BarTheme | X | bartent32.exe | Detected by Sophos as W32/Agobot-UG | No |
bascstray | N | BascsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems | No |
AntiVituS | X | Base.exe | Detected by Trend Micro as WORM_BAS.A | No |
Windows Service Base | X | base.EXE | Detected by Sophos as Troj/VB-GLW and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
Base64Kernel | X | Base64.exe | Detected by Dr.Web as Trojan.DownLoader11.6540 and by Malwarebytes Anti-Malware as Trojan.Agent.BS | No |
Windows Base Branding | X | basebrd.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!cvj and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BasicPrivacy | X | BasicPrivacy.exe | BasicPrivacy rogue security software - not recommended, removal instructions here | No |
BasicSafeMain | X | BasicSafe.exe | BasicSafe rogue security software - not recommended, removal instructions here | No |
Windows@Basic | X | basicserv.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%\Microsoft | No |
WinSetBrowse | X | BasicUpdate.dll.vbs | Detected by Symantec as VBS.Biscuit.A@mm | No |
type | X | bat.exe | Detected by Sophos as W32/Anskya-A | No |
adobeupdate | X | bat99.bat | Detected by Dr.Web as Tool.BtcMine.140 and by Malwarebytes Anti-Malware as Trojan.Agent.ADB | No |
adobeupdatess | X | bat99.bat | Detected by Malwarebytes Anti-Malware as Trojan.BCMiner. The file is located in %AppData%\Update | No |
BatangIN | X | BatangIN.exe | Detected by Sophos as Mal/Dbot-G | No |
POS-Partnerbatchprocessor | ? | Batch.exe | VISA credit card batch processing related to Appcon. The file is located in %Root%\VISAPC. Is it required at startup? | No |
rundll32_26641_toolbar | X | batchfile.bat | Detected by Dr.Web as Trojan.Siggen6.8070 and by Malwarebytes Anti-Malware as Backdoor.Agent.RDT | No |
BATINDICATOR | U | BATINDICATOR.exe | Battery level indicator for the HP Mainstream Keyboard | No |
[12 random characters] | X | batmeter.exe | IeDriver adware variant | No |
Battery Scope | U | batmgr.exe | Monitors battery levels on a notebook/laptop PC | No |
BatSrv | X | batserv2.exe | Added by the LOCKSKY.T WORM! | No |
BatteryBar | U | batterybar.exe | BatteryBar - displays battery usage, and the current percentage of battery power left | No |
Power Gear | U | BatteryLife.exe | ASUS Power4Gear power management utility for their notebooks | No |
Power_Gear | U | BatteryLife.exe | ASUS Power4Gear power management utility for their notebooks | No |
BatteryManager | U | BatteryManager.exe | Battery manager for Samsung laptops | No |
batterymiser | Y | batterymiser.exe | Battery Miser power management utility for LG Notebooks | No |
BatteryMiser 5 | Y | BatteryMiser5.exe | Battery Miser 5 power management utility for LG Notebooks | No |
Critical Update Check | X | battlenet.exe | Detected by Sophos as Troj/Delf-LB | No |
BatzBack | X | BatzBack.scr | Detected by Symantec as W32.HLLW.Backzat | No |
test | X | bat_starter.exe | Detected by Intel Security/McAfee as RDN/HideWindow and by Malwarebytes Anti-Malware as Trojan.Agent.MNR | No |
BAUSB | U | BAUSB.exe | Boston Acoustics Audio, USB driver | No |
Bavsetup | X | BavSetup.exe | Detected by Malwarebytes Anti-Malware as Hacktool.AVDeleter. The file is located in %AppData%\BayduSecuryt | No |
bawindo | X | bawindo.exe | Detected by Symantec as W32.Beagle.AR@mm | No |
owrnjeka | X | bawpojqj.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent.RWO | No |
Baypass | X | Baypass.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DCE. The file is located in %AppData% | No |
Bayswap | U | bayswap.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices | No |
bazmugvozliq | X | bazmugvozliq.exe | Detected by Intel Security/McAfee as RDN/Downloader.a!qh and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Generic Host Process for Win32 Services | X | bazzi.exe | Detected by Symantec as W32.Ahker.E@mm and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
Microsoft AntiSpyware | X | Bazzi.exe | Detected by Trend Micro as WORM_AHKER.J | No |
Win32 Service | X | bazzi.exe | Detected by Symantec as W32.Ahker.E@mm | No |
Best Antivirus Software | X | BA[random].exe | Best Antivirus Software rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BestAntivirusSoftware | No |
upbb | X | bb.exe | Detected by Trend Micro as TROJ_THINSTAL.TM | No |
winfcmservice | X | bb2e056b-c06f-4c8a-98b6-eb51df2b1a0f.exe | Detected by Dr.Web as Trojan.DownLoader10.45759 and by Malwarebytes Anti-Malware as Trojan.Downloader.Gen | No |
mscjmQuick | X | bbaka11.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent | No |
mscjmMonitor1.00 | X | bbaka12.exe | Detected by Intel Security/McAfee as Downloader-CJD | No |
mscjmQuick | X | bbaka12.exe | Detected by Intel Security/McAfee as Downloader-CJD and by Malwarebytes Anti-Malware as Trojan.Agent | No |
LAUNCHQUICK | X | bbaka14.exe | Detected by Intel Security/McAfee as Downloader-CJD | No |
MSCJACCELERATOR | X | bbaka14.exe | Detected by Intel Security/McAfee as Downloader-CJD | No |
this free | X | bbb.exe | Added by the VB-DZG TROJAN! | No |
HKCU | X | bbbbbbbbb.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDir | No |
HKLM | X | bbbbbbbbb.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDir | No |
SysTrayStartLW | X | BBbLWDB.Scr | Detected by Kaspersky as Email-Worm.Win32.Batzback.j and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
BBC iPlayer Desktop | U | BBC iPlayer Desktop.exe | BBC iPlayer Desktop allows you to download your favourite shows from the last 30 days, watch them online or offline and automatically download future episodes | No |
BBC Alerts | N | BBC_Alerts.exe | BBC Alerts - "You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service" | No |
bbdfdabfc | X | bbdfdabfc.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.TDSS. The file is located in %CommonAppData% | No |
d3dupdate.exe | X | bbeagle.exe | Detected by Symantec as W32.Beagle.A@mm | No |
bbjoin_crr_uninst | U | bbjoin.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.PayByAds. The file is located in %ProgramFiles%\bbjoin\bbjoin\[version]. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
BounceBack Launcher | U | BBLauncher.exe | Launcher for older versions of BounceBack back-up software from CMS Products | No |
Bron-Spizaetus-cfgmktoq | X | bbm-qotkmgfc.exe | Added by the BRONTOK-M WORM! | No |
Bron-Spizaetus-cfgmmnru | X | bbm-urnmmgfc.exe | Added by the BRONTOK-N WORM! | No |
bbm.exe | X | bbm.exe | Detected by Avira as TR/Spy.Gen and by Malwarebytes Anti-Malware as Backdoor.Bot.AI. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
bbm.exe | X | bbm.exe | Detected by Avira as TR/Spy.Gen and by Malwarebytes Anti-Malware as Backdoor.Bot.AI. This entry loads from HKLM\Run and the file is located in %UserTemp% | No |
SkypeCodec | X | bbnlmyqqs.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.UKN. The file is located in %CommonFiles%\SkypeCodec0 | No |
BBoxSearchBarOS | X | BBoxSearchBar.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\BomulBox\BBoxSearchBar | No |
Kernel | X | bboy.exe | Detected by Microsoft as Worm:Win32/Mumu.A. The file is located in %Windir% | No |
BbPrintMonitor | U | BBPrint.exe | Printer support for PDF software from Bluebeam Software, Inc. What does it do and is it required? | No |
BBQLeadsApplication | U | BBQLeadsApplication.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BBQLeads. The file is located in %ProgramFiles%\bbqleads. If bundled with another installer or not installed by choice then remove it | No |
gdagdgajs | X | bbsbw.exe | Added by the SDBOT-QX WORM! | No |
MSN Messenger BETA 7 | X | bbsdf.exe | Added by the RANKY.AA TROJAN! | No |
NetVideoNews | U | BBsee.exe | BBSee adware | No |
Bb-Seg | X | BbSeg.exe | Detected by Sophos as Troj/Agent-JVW | No |
BounceBack Launcher | U | BBStartup.exe | Launcher for BounceBack Ultimate back-up software from CMS Products - where "your backup is an exact duplicate of your computer's internal drive and all your backup files can be viewed using Windows Explorer" | No |
bbSysTray | N | bbSysTray.exe | Philips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions" | No |
bbui | U | bbui.exe | AOL DSL status monitor displaying a red/green icon indicating if you have a connection | No |
Broadband Wizard | N | bbwiz.exe | System Tray access to Broadband Wizard by KISSCO - which tests and optimizes your Cable or DSL connection. No longer available | No |
SystemController | X | bc001.exe | Detected by Dr.Web as Trojan.MulDrop5.9263 and by Malwarebytes Anti-Malware as Trojan.Destiny.DEL | No |
bca | U | bca.exe | BeClean Agent - registry, history, temp files, etc cleaner | No |
Microsoft Driver Setup | X | BCB.EXE | Detected by Avira as Worm/Kolab.eff and by Malwarebytes Anti-Malware as Worm.Palevo | No |
BCDetect | U | bcdetect.exe | Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see | No |
acdllib3 | X | bcdlmem.exe | Detected by Sophos as Troj/Mailbot-BA | No |
Browser companion helper | U | BCHelper.exe | Detected by Malwarebytes Anti-Malware as PUP.Blabbers. The file is located in %ProgramFiles%\BrowserCompanion. If bundled with another installer or not installed by choice then remove it | No |
Bchost | X | Bchost.exe.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %CommonAppData%\Bchost | No |
bcm | X | bcm.exe | Detected by Kaspersky as Trojan.NSIS.Miner.a | No |
USCService | U | BcmDeviceAndTaskStatusService.exe | Part of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution" | No |
BCMDMMSG | Y | bcmdmmsg.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems | No |
Broadcom Wireless Manager UI | U | bcmntray | System tray access to Broadcom wireless network adapter configuration options | No |
Broadcom Wireless Manager UI | X | bcmntray.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.EDAI. Note - this is not the legitimate Broadcom Network Adapters configuration utility entry which shares the same startup name and filename and is typically located in %System%. This one is located in %ProgramFiles%\Adobe\Reader 10.0\Reader\plug_ins | No |
BCMSMMSG | Y | BCMSMMSG.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems | No |
bcmwls32.exe | X | bcmwls32.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!ri and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
bcmwltry | ? | bcmwltry.exe | Broadcom Corporation Wireless Network Tray Applet. Is it required? | No |
BCNT | N | bcnt.exe | WeatherBug related. What does it do? | No |
Bctre | X | Bcore.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
BCPC | X | bcpc.exe | Added by a variant of Adware.Broadcastpc | No |
bcpc_c | X | bcpc_c.exe | Added by a variant of Adware.Broadcastpc | No |
Breg | X | bcre.exe | Added by a variant of Adware.Broadcastpc | No |
Win32 BCS Monitor | U | bcsmon32.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.SystemShieldPro. The file is located in %ProgramFiles%\SystemShield Pro. If bundled with another installer or not installed by choice then remove it. Also detected by Microsoft as Trojan:Win32/Tivmonk.B | No |
BCSSync | U | BCSSync.exe | Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see here | No |
Microsoft Office 2010 | U | BCSSync.exe | Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see here | No |
LoadDBackUp | X | BcTool.exe | Detected by Symantec as W32.Gibe@mm | No |
BCTWEAK | U | bctweak.exe | BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings | No |
*1534741411 | X | BCU.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BSM. The file is located in %Windir%\1534741411 | No |
BCU | N | BCU.exe | Browser Configuration Utility for Gigabyte motherboards by DeviceVM - which is "an easy-to-install, easy-to-use, powerful search engine." It sits in the Address Bar of IE6/7/8, allowing you to search for a string of characters - with the default search engine being Yandex (Russian), Baidu (Simplified Chinese) or Yahoo (for all others). May disrupt your preferred search engine | No |
BCUpdate | U | BCUP.exe | BocaiToolbar adware | No |
bcveim | X | bcveim.exe | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %UserProfile% | No |
Bcvsrv32 | X | bcvsrv32.exe | Detected by Symantec as W32.Gaobot.BQJ | No |
BCWipeTM | N | BCWipeTM.exe | BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed | No |
BCWipeTM Startup | N | BCWipeTM.exe | BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed | No |
Windows Computer Browser | X | bcwsvc.exe | Detected by Trend Micro as WORM_RBOT.JM | No |
BDAgent | Y | bdagent.exe | BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
BitDefender 2009 | Y | bdagent.exe | BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
Intel | X | BDE3B7.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.H. The file is located in %AppData% | No |
b3d | X | BDEsecureinstall.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start → Settings → Control Panel → Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the "System" directory. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents | No |
hao123Setting | X | bdg*.exe | Detected by Malwarebytes Anti-Malware as Trojan.StartPage - where * represents one or more hex numbers. The file is located in %Temp% - see examples here and here | No |
BitDefender Live! Init | Y | bdinit.exe | Part of older versions of BitDefender anti-malware products | No |
kfgpeTkw | X | bDM5c2IZ.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\DXDMqcZS | No |
BDMCon | Y | Bdmcon.exe | Part of older versions of BitDefender anti-malware products | No |
BDNewsAgent | Y | bdnagent.exe | Part of older versions of BitDefender anti-malware products | No |
BDO | X | BDO.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %AppData%\{random} | No |
BDOESRV | Y | bdoesrv.exe | Part of older versions of BitDefender anti-malware products | No |
BDX | X | BDQX.EXE | Detected by Trend Micro as TROJ_DELF.SMID and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
C:\lanmao.exe | X | BDQX.EXE | Detected by Microsoft as Backdoor:Win32/Bigdipper.A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BDX | X | BDQX[random].EXE | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir% | No |
bdraw | U | bdraw.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.OptiAds. The file is located in %ProgramFiles%\bdraw\bdraw\[version]. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
AdobeArm Update | X | bds.exe | Detected by Intel Security/McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
bds32.exe | X | bds32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
ADOBSYS_UPDATE | X | bdshost.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
BitDefender Scan Server | Y | bdss.exe | Part of older versions of BitDefender anti-malware products | No |
BDSwitchAgent | Y | bdswitch.exe | Part of older versions of BitDefender anti-malware products | No |
oethejspmwwssogsprklcvcv | X | bdunzzhcefibr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.FBD. The file is located in %AppData% | No |
BDWizReg | Y | bdwizreg.exe | Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-free | Yes |
BitDefender 12 | Y | bdwizreg.exe | Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-free | Yes |
BEA Start | U | BEA.exe | Detected by Malwarebytes Anti-Malware as PUP.Ardamax. The file is located in %CommonAppData%\BTURUS. If not installed by choice then remove it | No |
Bunx | X | beagle.exe | Detected by Sophos as W32/Lebreat-E and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
Beamrise | U | beamrise.exe | "Beamrise is a next-generation Internet browser that unites browsing and chatting. Seemingly similar to Google Chrome, Safari, and Firefox; Beamrise goes one step further and brings your favorite messenger with you as you surf the Internet." Potentially Unwanted Program (PUP) commonly bundled with other free programs which changes the default search page to "search.beamrise.com" - also see here | No |
BearFlix | U | BearFlix.exe | BearFlix is optimized for the fast download of video files | No |
BearShare | N | BearShare.exe | BearShare file sharing client. Versions known to include spyware - see here | Yes |
BeatNik Internet Clock | U | BeatNik.exe | BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock | No |
Animated Wallpaper | U | Beautiful Fishing Lake.exe | Beautiful Fishing Lake animated desktop wallpaper from Desktop Animated | No |
beautifulday | X | beautifulday.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuff | No |
Animated Wallpaper | U | Beauty.exe | Beauty animated desktop wallpaper from Desktop Animated | No |
Beegees Update | X | beegees.exe | Detected by Sophos as W32/Sdbot-ADK | No |
BeFaster | U | befaster3.exe | BeFaster internet connection optimization tool | No |
befukocsejyr | X | befukocsejyr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
begwacdotmob | X | begwacdotmob.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% | No |
Browser Extensions | U | BEHelper.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Spigot. The file is located in %AppData%\BrowserExtensions. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
BEHL | ? | BEHL.exe | The file is located in %Windir%. What does it do and is it required? | No |
BEHLO | ? | BEHLO.exe | The file is located in %Windir%. What does it do and is it required? | No |
windirupdate | X | beholder.exe | Detected by Intel Security/McAfee as PWS-Banker!gdm and by Malwarebytes Anti-Malware as Trojan.Agent | No |
beidsystemtray | U | beidsystemtray.exe | Related to Belgium Identity Card card reader | No |
ASDPLUGIN | X | belgium_nm.exe | AsdPlug premium rate adult content dialer | No |
Belkin Tray Application | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
BelkinRouterMonitor | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
InstaLAN | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
Belkin F5D8013 N Wireless Notebook Card Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card | No |
Belkin F5D8053 N Wireless USB Adapter Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter | No |
Belkin F5D8073 N Wireless ExpressCard Adapter Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter | No |
Belkin Wireless G Notebook Card Client Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D701F Wireless G Notebook Card | No |
Belkin Wireless G USB Adapter Client Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
Belkin Wireless Networking Utility | U | Belkinwcui.exe | Wireless configuration utility for some Belkin cards such as the F5D8053 N Wireless USB Adapter and F5D8051 N1 Wireless USB Adapter | No |
Belkin Wireless USB Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
Belkin Wireless Utility | U | Belkinwcui.exe | Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card | No |
F5D7050v3 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
F5D8001 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card | No |
F5D8011 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card | No |
F5D8051v3 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8051 N1 Wireless USB Adapter | No |
F5D8055v1 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter | No |
F5D8055v2 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter | No |
F5D8071 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard | No |
F5D9010 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter | No |
F5D9050 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter | No |
BellSouthAlertManager.exe | U | BellSouthAlertManager.exe | Related to BellSouth Alert Manager | No |
Belkin Wireless LAN Utility | U | belsta.exe | Wireless configuration utility for Belkin network cards | No |
BELSTA.EXE | U | BELSTA.EXE | Wireless configuration utility for Belkin network cards | No |
Belt | X | Belt.exe | VX2.Transponder parasite updater/installer related | No |
Belvedere | U | Belvedere.exe | Belvedere "is designed to help support problem-based collaborative learning scenarios with concept and evidence moodels, and provides multiple representational views (tables and graphs) on those models" | No |
DailyLocalGuide EPM Support | U | bemedint.exe | DailyLocalGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyLocalGuide_be\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Benadril Alert Tool | X | benadrilalert.exe | Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril | No |
BengalsScreenServer | U | BengalsScreenServer.exe | Screensaver for the Cincinnati Bengals NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
BES | X | bes.exe | Detected by Intel Security/McAfee as RDN/Downloader.a!nd and by Malwarebytes Anti-Malware as Trojan.Banker.E | No |
BackupExecScheduler | U | BESCH.EXE | Scheduler for Backup Exec data backup and recovery software from Symantec (formerly Veritas) | No |
besorxualezb | X | besorxualezb.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
DailyLocalGuide Search Scope Monitor | U | besrchmn.exe | DailyLocalGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyLocalGuide_be\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
best.exe | X | best.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
BestBoan | X | BestBoan.exe | BestBoan rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BestBoan | No |
BestCrypt Auto Open | U | BestCrypt.exe | BestCrypt from Jetico, Inc. "Keeps your confidential data in a strongly encrypted form on your disk and provides you with transparent access" | No |
BestPopUpKiller | X | BestPopupKiller.exe | Popup killer by Swanksoft - not recommended, see here | No |
BestSync 2008 | U | BestSyncApp.exe | System Tray access to BestSync® 2008 from Risefly Software - "a professional utility for synchronizing files between your local folders and Network Drives, FTP servers, Removable Media (such as an USB disk)" | No |
BeSys | X | BEsys.exe | BeSys adware | No |
WINDOWS SYSTEM | X | beta.exe | Detected by Symantec as W32.Mytob.DF@mm and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
BullsEye Tracker | X | BeTrack.Exe | Bullseye adware | No |
BeyluxeMessenger | N | Beyluxe Messenger.exe | Beyluxe Messenger by Beyluxe Communication S.R - "is a free popular Internet voice and video Chat program used by millions of people, and thousands of organizations, to communicate, share, play and work with each other on the internet around the world" | No |
System Config | X | BF3.EXE | Detected by Sophos as W32/Spybot-DT | No |
BF4P | X | bf4p.exe | Detected by SUPERAntiSpyware as Trojan.BF4P.Process. The file is located in %System% | No |
BFHP | U | BFHP.exe | BeFrugal toolbar. Detected by Malwarebytes Anti-Malware as PUP.Optional.BeFrugal. The file is located in %CommonFiles%\BeFrugal.com\Toolbar. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
SnapMyScreen EPM Support | U | bfmedint.exe | SnapMyScreen toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\SnapMyScreen_bf\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Keyboard Driver | X | bfscv.exe | Detected by Intel Security/McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.IMN | No |
Windows Keyboard Protection | X | bfscv.exe | Detected by Intel Security/McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.IMN | No |
SnapMyScreen Search Scope Monitor | U | bfsrchmn.exe | SnapMyScreen toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\SnapMyScreen_bf\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
userinit | X | bfvkjs.exe | Detected by Intel Security/McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Wallpaper Changer | U | BGCWPV7.exe | Wallpaper Changer by Bgates Software - will "automatically change your computers desktop wallpaper. The program works with most popular image formats including BMP, JPG, and GIF." No longer supported | No |
BGInfo | U | Bginfo.exe | BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more | No |
Shell | X | bgjsy.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.MTA. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "bgjsy.exe" (which is located in %UserTemp%\FolderName) | No |
DailyHomeGuide EPM Support | U | bgmedint.exe | DailyHomeGuide toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyHomeGuide_bg\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
BGNewsAgent | Y | bgnewsag.exe | BullGuard antivirus updater | No |
WindowsDefender | X | bgocpnen.pyb.exe | Detected by Dr.Web as Trojan.DownLoader9.26359 and by Malwarebytes Anti-Malware as Trojan.Agent.WD | No |
bgoomain.exe | X | bgoomain.exe | Baigoo.a malware | No |
bgsmsnd | N | bgsmsnd.exe | Printer driver to generate PDF files from any program | No |
DailyHomeGuide Search Scope Monitor | U | bgsrchmn.exe | DailyHomeGuide toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyHomeGuide_bg\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
BackgroundSwitcher | U | bgswitch.exe | Originally included with Microsoft's XP PowerToys (but now withdrawn - see here, Background Switcher allows your desktop background to periodically change | No |
mmxogcut | X | bgtufejk.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %LocalAppData% | No |
bgz0ueitgy | X | bgz0ueitgy.exe | Detected by Microsoft as Trojan:Win32/Scar.Q and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
MS32DLL | X | Bha.dll.vbs | Detected by Sophos as VBS/ButSur-A and by Malwarebytes Anti-Malware as VBS.Godzilla | No |
Browser Hijack Blaster | Y | bhblaster.exe | Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard | No |
MozillaIE | X | BHC.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %Windir% | No |
BHOCop | N | BHOCop.exe | PC Magazine's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware | No |
BHODemon | U | BHODemon.exe | BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on demand | No |
BHODemon 2.0 | U | BHODemon.exe | BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on demand | No |
[various names] | X | bhoserv.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BHR | U | BHR.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
BHR2.1 | U | BHR2.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
BHR3.5 | U | BHR3.5.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
BHR3 | U | BHR3.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
BHR4.1 | U | BHR4.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
BHR4 | U | BHR4.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
Browser Help Svc | X | BHSV.EXE | Detected by Sophos as W32/Rbot-AVQ | No |
BI1HelperStartUp | U | BI1Helper.exe | ScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
BI1HelperStartUp | U | BI1HEL~1.EXE | ScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
LTM2 | X | bible.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Litmus. The file is located in %Windir%\litmus | No |
[space]Windows Plugin BIC | X | bic_fmasl.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.E. Note the space at the beginning and end of the "Startup Item" field and the file is located in %AppData% | No |
Windows Plugin BIC | X | bic_rulsw.exe | Detected by Microsoft as TrojanSpy:Win32/Banker.AMH and by Malwarebytes Anti-Malware as Trojan.Banker.E | No |
[12 random characters] | X | bidispl2.exe | IeDriver adware variant | No |
tvgvopah | X | bidjnbvf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %LocalAppData% | No |
Biet-O-Matic | N | Biet-O-Matic.exe | Biet-O-Matic (BOM) (or Bid-O-Matic) is a tool to watch and bid on auctions and "gives you the opportunity to submit automated and timed at online auctions bids. It can also be used to bid if you personally just can not be online" | No |
This is a virus, please delete it | X | bigbadvirus.exe | Detected by Symantec as W32.Randex.F | No |
Bigboysdontcrys | X | Bigboysdontcrys.exe | Detected by Sophos as Troj/Agent-AMFH and by Malwarebytes Anti-Malware as Password.Stealer.E | No |
Bigboysdontcrys.exe | X | Bigboysdontcrys.exe | Detected by Sophos as Troj/Agent-AMFH and by Malwarebytes Anti-Malware as Password.Stealer.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
bigsoft | X | bigdoor.exe | Detected by Trend Micro as WORM_AUTORUN.MAG and by Malwarebytes Anti-Malware as Spyware.OnlineGames | No |
BigfileSearch | X | BigfileSearch.exe | Detected by Malwarebytes Anti-Malware as Adware.BigfileSearch. The file is located in %ProgramFiles%\BigfileSearch | No |
BigFix | N | bigfix.exe | BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog | Yes |
BIG | X | biggy.exe | Detected by Sophos as W32/Delbot-AG | No |
biglow | X | biglow.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
bigoris | X | bigoris.exe | Detected by Sophos as Troj/Dorf-AZ | No |
BigPondWirelessBroadbandCM | Y | BigPond_CM.exe | Telstra wireless broadband manager | No |
Big_Watermelon.exe | X | Big_Watermelon.exe.exe | Detected by Dr.Web as Trojan.Siggen6.17174 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
bihipcotpeze | X | bihipcotpeze.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!jz and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Lastword | X | BiHNet.exe | Detected by ESET as Win32/Lastword | No |
bikini | X | bikini.exe | Detected by Sophos as Troj/LowZone-CX and by Malwarebytes Anti-Malware as Trojan.Agent | No |
bil86.exe | X | bil86.exe | Detected by Dr.Web as Trojan.Inject1.27766 and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
Bilbulon | N | Bilbulon.exe | Bilbulon from EcoSoft - swaps text from Hebrew to another language and back. It helps correct typing mistakes which occur if you forget to switch to a different language before starting to type" | No |
AZOZ | X | Bild (2).exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!zj and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
. | X | bill.exe | Detected by Intel Security/McAfee as RDN/Generic PWS.y!wo and by Malwarebytes Anti-Malware as Backdoor.Agent.DTGen | No |
sysfbtray | X | bill102.exe | Added by the VB-ENI TROJAN! | No |
sysfbtray | X | bill103.exe | Added by the MDROP-CLF TROJAN! | No |
sysfbtray | X | bill104.exe | Added by the MDROP-CLO TROJAN! | No |
sysfbtray | X | bill106.exe | Added by the MDROP-CLV TROJAN! | No |
sysfbtray | X | bill108.exe | Added by the MDROP-CMW TROJAN! | No |
sysfbtray | X | bill117.exe | Added by the VBKRYPT-E TROJAN! | No |
TnPopUp | U | billbrz.exe | Related to Technesis "award-winning solutions for tracking and managing print, copy, fax and scan activities" | No |
BillGatesLoh.exe | X | BillGatesLoh.exe | Added by the AGENT-FZO TROJAN! | No |
Billminder | N | Billmind.exe | Can be setup in Quicken to remind user of due payments. Available via Start → Programs | No |
DailyImageBoard EPM Support | U | bimedint.exe | DailyImageBoard toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyImageBoard_bi\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it, removal instructions here | Yes |
bimopupogsak | X | bimopupogsak.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!vd and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Bimwoheuipuubaxt.exe | X | Bimwoheuipuubaxt.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %AppData% | No |
bimyvypfipag | X | bimyvypfipag.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!hf and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Bin | X | Bin | Detected by Intel Security/McAfee as RDN/Generic.bfr!bg and by Malwarebytes Anti-Malware as Trojan.Agent.AI | No |
[8 hex numbers] | X | bin.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BNIGen. The file is located in %AppData%\[8 hex numbers] | No |
default | X | bin.exe | Detected by Symantec as Trojan.Tinba and by Malwarebytes Anti-Malware as Trojan.Agent | No |
GDI Auto Update | X | binary.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!jw and by Malwarebytes Anti-Malware as Backdoor.Agent.AU | No |
bincdwsa | X | bincdwsa.exe | Added by the ONLINEGAMES.AKYF TROJAN! | No |
bind.exe | X | bind.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BND. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
Shareaza | U | bindata.exe | Shareaza P2P client related | No |
Bing Search2 | X | Bing.exe | Detected by Intel Security/McAfee as RDN/Ransom and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
Bing.exe | X | Bing.exe | Detected by Intel Security/McAfee as RDN/PWS-Banker and by Malwarebytes Anti-Malware as Trojan.Agent | No |
bingoolbar | X | bing.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp%\bingoolbar | No |
BingDesktop | X | BingDesktop.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not the legitimate Bing Desktop by Microsoft which is normally located in %ProgramFiles%\Microsoft\BingDesktop. This one is located in %AppData%\Sun\Java\Deployment\SystemCache\6.0\19 | No |
BingDesktop | X | BingDesktop.exe | Detected by Malwarebytes Anti-Malware as Trojan.Bitcoin. Note - this is not the legitimate Bing Desktop by Microsoft which is normally located in %ProgramFiles%\Microsoft\BingDesktop. This one is located in %AppData%\Sun\Java\Deployment\SystemCache\6.0\20 | No |
BingDesktop | U | BingDesktop.exe | Bing Desktop by Microsoft - "With Bing Desktop, make the Bing homepage image your PC desktop wallpaper each day" | No |
bingdian | X | Bingdian.vbs | Detected by Symantec as VBS.Bingd@mm | No |
[various names] | X | bingo9.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BinHost | X | binhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject.AI. The file is located in %CommonAppData%\Microsoft\Windows\Start Menu\binhost (8/7/Vista) or %AllUsersProfile%\Start Menu\binhost (XP) | No |
GoogleChromeAutoLaunch_[ID] | U | binkiland.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Binkiland. The file is located in %LocalAppData%\Binkiland\Application. If bundled with another installer or not installed by choice then remove it | No |
Bio Security | X | Bio Security.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!dch and by Malwarebytes Anti-Malware as Backdoor.IRCBot.E | No |
Bionix Wallpaper 5 | U | Bionix Wallpaper 5.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
BioniXWallpaper | U | Bionix Wallpaper 5beta.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
BioniXWallpaper | U | BioniX Wallper.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
BioniXWallpaper | U | BionixWallpaper5.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
bionli | X | bionli.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuff | No |
bios | X | bios.exe | Detected by Sophos as Troj/Bancban-PW | No |
bios | X | bios.exe | Detected by Sophos as Troj/Bancban-PW and by Malwarebytes Anti-Malware as Worm.MSN | No |
bios.exe | X | bios.exe | Detected by Sophos as Troj/Bancban-PW and by Malwarebytes Anti-Malware as Worm.MSN. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
BIOS1 | X | BIOS1.EXE | Added by the OPASERV.T WORM! | No |
BIOS | X | Bios32.exe | Detected by Trend Micro as TROJ_BB.A | No |
Terminal Update | X | biosefui.exe | Detected by Sophos as Troj/PPdoor-O | No |
BiosNCS | X | BiosNCS.exe | Detected by Dr.Web as Trojan.Siggen5.41518 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
BIOS Net Service | X | BIOSserv.exe | Added by the RBOT-BFL WORM! | No |
BIOVCIP | ? | BIOVCIP.exe | The file is located in %Windir%. What does it do and is it required? | No |
biozar | X | biozar.exe | Detected by Malwarebytes Anti-Malware as Backdoor.SpyNet. The file is located in %System% | No |
bipwukylyfyh | X | bipwukylyfyh.exe | Detected by Intel Security/McAfee as RDN/Generic.tfr!dz and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Birds | U | birds365.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Birds. The file is located in %LocalAppData%\Birds. If bundled with another installer or not installed by choice then remove it | No |
BisonHK | ? | BisonHK.exe | Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required? | No |
DailyImageBoard Search Scope Monitor | U | bisrchmn.exe | DailyImageBoard toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\DailyImageBoard_bi\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it, removal instructions here | Yes |
Microsoft Explorer2 | X | bitchbot.exe | Detected by Trend Micro as WORM_SDBOT.EV | No |
BitCleanMain | X | BitClean.exe | BitClean rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BitClean | No |
Shell | X | Bitcoin.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!dfw and by Malwarebytes Anti-Malware as Trojan.Agent.MTA. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "Bitcoin.exe" (which is located in %Temp%\FolderName) | No |
fupdater | X | bitcoincz.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!mk and by Malwarebytes Anti-Malware as Trojan.Agent.MNR | No |
BitComet | N | BitComet.exe | "BitComet is a BitTorrent/HTTP/FTP download management software, which is powerful, fast, very easy-to-use, and completely free" | No |
BitDefender Antivirus | X | BITDEFENDERX.EXE | Added by a variant of the SPYBOT WORM! | No |
BitDefender_P2P_Startup | U | BitDefender_P2P_Startup.exe | Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website | No |
Bitminer | U | Bitminer.exe | Detected by Malwarebytes Anti-Malware as PUP.BitCoinMiner. The file is located in %UserTemp%\Bitcoins | No |
Microsoft Windows DLLHandler | X | bitpaint.exe | Detected by Trend Micro as WORM_SDBOT.AHG and by Malwarebytes Anti-Malware as Trojan.MWF.Gen | No |
Background Intelligent Transfer Service | X | bits.exe | Detected by Dr.Web as Trojan.Inject.53759 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
bitsadmin | X | bitsadmin.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BTS. The file is located in %AppData%\Microsoft\Windows\dllcache | No |
MEVEMUJEQzQ2Q0NBMzdFQj | X | bitsmst.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile% | No |
duseript | X | bitsthlp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Spy.Ursnif. The file is located in %UserTemp% | No |
µTorrent | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Version 6.1 of BitTorrent is displayed as µTorrent in both Vista MSConfig & Windows Defender | Yes |
Bit Torrent | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Note that the file is located in %ProgramFiles%\BitTorrent until version 7.8 Build 29039 and in %AppData%\BitTorrent from then onwards | Yes |
BitTorrent | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Note that the file is located in %ProgramFiles%\BitTorrent until version 7.8 Build 29039 and in %AppData%\BitTorrent from then onwards | Yes |
Bittorrent | X | bittorrent.exe | Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir% | No |
bittorrent.exe | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads | Yes |
bityxykyliru | X | bityxykyliru.exe | Detected by Intel Security/McAfee as RDN/Downloader.a!ro and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
bixjapusdice | X | bixjapusdice.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
biz_check_1_1 | X | biz_check_1_1.exe | Detected by Intel Security/McAfee as RDN/Generic.tfr!bf and by Malwarebytes Anti-Malware as Adware.K.Bizkeyword | No |
SlipStream | Y | BI_DA_core.exe | Bell Internet Dial Accelerator customized core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix | No |
Bell Internet Dial Accelerator | Y | BI_DA_gui.exe | Bell Internet Dial Accelerator customized user interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix | No |
awuk7zip23546 | U | BI_RunOnce.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Somoto. The file is located in %UserTemp%. If bundled with another installer or not installed by choice then remove it | No |
BJLaunchEXE | U | BJLaunch.exe | Memory Card Utility for the Canon i470D, i475D and i905D photo printers - which allows "your computer to access the memory card reader feature of your printer" | No |
bjmbmgr | X | bjmbmgr.exe | Added by the AGENT-TKD TROJAN! | No |
Undeaddies EPM Support | U | bjmedint.exe | Undeaddies toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\Undeaddies_bj\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Canon My Printer | U | BJMyPrt.exe | Printer software for Canon Bubblejet printers | No |
CanonMyPrinter | U | BJMyPrt.exe | Printer software for Canon Bubblejet printers | No |
Easy-PrintToolBox | U | BJPSMAIN.EXE | Canon utility included with selected printers giving quick access to some printing utilities | No |
TotalDatingGuide Search Scope Monitor | U | bjsrchmn.exe | TotalDatingGuide toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\TotalDatingGuide_b8\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Undeaddies Search Scope Monitor | U | bjsrchmn.exe | Undeaddies toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\Undeaddies_bj\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Bkr | X | bkr.bat | Detected by Dr.Web as Win32.HLLW.Autoruner1.34949 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
UBKUFPY | X | BKUfpyu.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr!ex and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
BkupTray | U | BkupTray.exe | System Tray access to the NTI Backup Now 5 backup utility from NTI Corporation | No |
Bl4cK-M3t4L.exe | X | Bl4cK-M3t4L.exe | Detected by Dr.Web as Trojan.Inject1.42151 and by Malwarebytes Anti-Malware as Backdoor.Agent.BM. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
Supernova | X | Blaargh.exe | Detected by Intel Security/McAfee as W32/Supova.e.worm and by Malwarebytes Anti-Malware as Worm.Supernova | No |
Windows Services | X | BlaBhs.exe | Detected by Sophos as Mal/Agent-ACY and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
SYSTEM | X | bLack Fanatic.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BLAE. The file is located in %Root% | No |
Black Keylogger | X | Black Keylogger.exe | Detected by Dr.Web as Trojan.Siggen3.64253 and by Malwarebytes Anti-Malware as Trojan.Agent.KLG | No |
Windows | X | black no crypt.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
BlackArmorBackupMonitor.exe | N | BlackArmorBackupMonitor.exe | Part of Seagate BlackArmor Backup - their implementation of the Acronis True Image backup software for their BlackArmor range of external hard drives and Network Attached Storage (NAS). Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
startup | X | blackbetty.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!wv and by Malwarebytes Anti-Malware as Trojan.Agent | No |
[12 random characters] | X | blackbox.exe | IeDriver adware variant | No |
Black Box Helper | U | BlackBoxHelper.exe | Support for the M-Audio "Black Box" guitar processor and audio interface with guitar amp modelling, beat-synced effects and drum tracks for computer based recording | No |
Task Manager | X | blackCoin.scr | Detected by Dr.Web as Trojan.Siggen4.20779 and by Malwarebytes Anti-Malware as Worm.AutoRun | No |
LoadBlackD | Y | blackd.exe | "Intrusion detection system" of the BlackICE firewall which loads independently of the "user interface" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just Internet Security Systems or ISS) when they acquired the NetworkICE parent but is no longer available. Runs as a service on an NT based OS (such as Windows 8/7/Vista/XP) | No |
blackeagle.exe | X | blackeagle.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!cpq and by Malwarebytes Anti-Malware as Trojan.Agent.BLE | No |
blackeagle18.exe | X | blackeagle18.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!cpq and by Malwarebytes Anti-Malware as Trojan.Agent.BLE | No |
BlackICE PC Protection | N | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD | No |
BlackIce Utility | N | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD | No |
run | X | blackice.exe | Detected by Sophos as W32/Blic-A. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "run" value data to include the file "blackice.exe" (which is located in %System%) | No |
STRINGS | X | BlackMilkProxy.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
HKCU | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\install | No |
HKLM | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\install | No |
Policies | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\install | No |
blacksilver | X | blacksilver.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.MNRE. The file is located in %System% | No |
DEXF | X | BlackWeed.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!po and by Malwarebytes Anti-Malware as Backdoor.Messa.E | No |
Razer Blackwidow Driver | U | BlackwidowTray.exe | Razer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
Razer Blackwidow Driver | U | BlackWidowUltimateTray.exe | Razer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
Distributed File System | X | blade.exe | Detected by Symantec as W32.Myfip.AC | No |
blads | U | blads.exe | Ad blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
BlockAds | U | blads.exe | Ad blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
Microsoft machine | X | blah.exe | Added by a variant of Backdoor:Win32/Rbot | No |
NMREDF | X | blastclnd.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
MicroUpdate | X | blay.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen. The file is located in %UserTemp%\windows_old | No |
bldbubg | N | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system | No |
BuildBU | N | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system | No |
Win32 Test | X | bleatest.exe | Added by the RBOT.AGJ WORM! | No |
BLMessagingIntegration | X | blengine.exe | Detected by Intel Security/McAfee as Adware-BuddyLinks | No |
Bluetooth LE Services Update Program | X | BleServicesUpd.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
BLESSONE | X | blessedone.exe | Detected by Dr.Web as Trojan.KillProc.32145 and by Malwarebytes Anti-Malware as Trojan.Banker.E | No |
BLF | X | blf.exe | Detected by Sophos as W32/Delbot-M | No |
borzoi | U | blg.exe | Borzoi surveillance software. Uninstall this software unless you put it there yourself | No |
ESPN BottomLine | N | bline.exe | ESPN BottomLine - "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down" | No |
[various names] | X | bling.exe | Detected by Sophos as W32/Rbot-NI | No |
Microsoft Security Management | X | bling.exe | Detected by Trend Micro as WORM_RBOT.XL | No |
Microsoft Update | X | bling.exe | Detected by Sophos as W32/Rbot-AVK and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
Windows Executer | X | bling.exe | Detected by Sophos as W32/Sdbot-DFT | No |
blinkx | U | blinkx.exe | Related to an older blinkx video search engine product | No |
blinkxgate | N | blinkx.exe | Entry added with an earlier version of blinkx Beat which "is a never-ending playlist of the latest and greatest online videos. Fresh video finds are delivered straight to your screen, so sit back and enjoy, we'll do the work for you" | Yes |
Windows Blob Meter | X | blob.exe | Detected by Dr.Web as Trojan.DownLoader10.14128 and by Malwarebytes Anti-Malware as Backdoor.IRCBot.E. This entry loads from the HKLM\RunOnce and HKCU\RunOnce keys and the file is located in %AppData% | No |
Windows Blob Meter | X | blob.exe | Detected by Dr.Web as Trojan.DownLoader10.14128 and by Malwarebytes Anti-Malware as Backdoor.IRCBot.E. This entry loads from the HKLM\Run and HKCU\Run keys and the file is located in %UserProfile% | No |
BlockChecker | X | Block-checker.exe | BlockChecker adware | No |
BlockAndSurf | U | BlockAndSurf.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BlockAndSurf. The file is located in %ProgramFiles%\*BlockAndSurf* - where * represents anything. If bundled with another installer or not installed by choice then remove it | No |
BlockDefense | X | BlockDefense.exe | BlockDefense rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
Ad Blocker | U | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads | No |
Blocker | X | Blocker.exe | Detected by Intel Security/McAfee as T-RAI-AFV and by Malwarebytes Anti-Malware as HackTool.Agent.TSK | No |
BlockKeeper | X | BlockKeeper.exe | BlockKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
BlockNSurf | U | BlockNSurf.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BlockAndSurf. The file is located in %ProgramFiles%\BlockAndSurf-soft. If bundled with another installer or not installed by choice then remove it | No |
BlockProtector.exe | X | BlockProtector.exe | BlockProtector rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
BlockScanner | X | BlockScanner.exe | BlockScanner rogue security software - not recommended. A member of the WiniGuard family | No |
BlockTracker | N | BlockTracker.exe | If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file | No |
BlockWatcher | X | BlockWatcher.exe | BlockWatcher rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
BloemeGRPH | X | Bloemeren.exe | Detected by Dr.Web as Trojan.Siggen6.3419 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
mdssn | X | blog.exe | Detected by Dr.Web as Trojan.DownLoader7.5792 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
blogde.exe | X | blogde.exe | Detected by Intel Security/McAfee as RDN/Spybot.bfr!p and by Malwarebytes Anti-Malware as Trojan.Banker.JRD. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
blonderwin.exe | X | blonderwin.exe | Detected by Dr.Web as Trojan.Siggen5.42927 and by Malwarebytes Anti-Malware as Backdoor.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
bLrIXoS | X | bLrIXoS.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr!fa and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
blsloader | U | blsloader.exe | BellSouth ISP Internet Tools | No |
spc_w | N | blspc.exe | NetZero Search Enhancements and BlueLight Internet related | No |
blss | X | blss.exe | Detected by Symantec as Backdoor.Blarul | No |
BLSTAPP | N | blstapp.exe | System Tray access to BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning | No |
Blubster | N | Blubster.exe | "Blubster is a file-sharing network that uses a peer-to-peer network similar to Gnutella, with a new private protocol that works without a central server. Once your client program connects with another client, you can search and download MP3 files from the entire network of users." No longer available | No |
BbInstallUser | ? | Bluebeam Admin User.exe | Related to PDF software from Bluebeam Software, Inc. What does it do and is it required? | No |
Bluecol | X | bluecol.exe | Detected by Trend Micro as TROJ_CRYPTER.A | No |
Blue Frog | U | bluefrog.exe | Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive | No |
Startup Name | X | blueprintdesign.exe | Detected by Intel Security/McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.RND | No |
FixBluetooth | X | BlueSoleiI.exe | Detected by Sophos as Troj/Zapchas-EJ | No |
BlueSoleil | U | BLUESO~1.EXE | BlueSoleil Bluetooth wireless manager from IVT Corporation | No |
BlueSpace NE | U | BlueSpaceNE.exe | "BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter". Shortcut available via Start → Programs | No |
Bluetooth##*.cpl | X | Bluetooth##*.cpl | Detected by Malwarebytes Anti-Malware as Trojan.Banker.CB - where ##* represents 2 or more digits. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see an example here | No |
BlueTooth HID | X | Bluetooth.exe | Detected by Intel Security/McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
bluetooth.exe | X | bluetooth.exe | Detected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %AppData% | No |
Bluetooth.exe | X | Bluetooth.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and here | No |
BLUE_LABEL_####.exe | X | BLUE_LABEL_####.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.E - where # represents a digit. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see an example here | No |
Windows LoL Layer | X | blvpnmcny.exe | Detected by Sophos as W32/Rbot-GOR and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
bm | X | bm.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples | No |
BMN | X | bm.exe | Part of VirtualPCGuard, VirusGuardPlus and other members of the AVSystemCare family of rogue security software suites. See here for more examples | No |
Salestart | X | bm.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples | No |
Bmscreen | X | bm2.exe | Detected by Intel Security/McAfee as Generic BackDoor!dmt | No |
Bman | X | BMan1.exe | Added by a variant of Adware.DealHelper | No |
Bmanager | U | BManager.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserFeatures. The file is located in %ProgramFiles%\Browser Features. If bundled with another installer or not installed by choice then remove it | No |
Browser Features | U | BManager.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserFeatures. The file is located in %ProgramFiles%\Browser Features. If bundled with another installer or not installed by choice then remove it | No |
load | X | BMDStreamingServer.exe | Detected by Dr.Web as Trojan.DownLoader9.15424. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "BMDStreamingServer.exe" (which is located in %Root%\{$1284-9213-2940-1289$}) | No |
Blackmagic | X | BMDStreamingServer.exe -rundll32 /SYSTEM32 taskmgr.exe | Detected by Dr.Web as Trojan.DownLoader9.15424 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - do not delete the legitimate taskmgr.exe process which is always located in %System% | No |
bmF8hkNkr0o | X | bmF8hkNkr0o.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr!fc and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
MediaX | X | bmkp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker.IM. The file is located in %AppData%\DropX | No |
BookmarkCentral | N | BMLauncher.exe | Bookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use". No longer available | No |
BMMLREF | N | BMMLREF.EXE | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" status | Yes |
BMMLREF.EXE | N | BMMLREF.EXE | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" status | Yes |
Bmonq | X | bmonq.exe | Added by the CLICKER.HZ TROJAN! | No |
update | X | bmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeKey. The file is located in %ProgramFiles%\install | No |
vchost | X | bmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeKey. The file is located in %ProgramFiles%\install | No |
Casdvqwa | X | bmqnzkg.exe | Detected by Symantec as W32.Randex.BE | No |
BuzMe | N | BMUI.exe | Buzme by RingCentral - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem and no longer supported | No |
BMupdate | N | BMupdate.exe | Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install | No |
idp6 | X | bmusalsv.exe | Detected by Malwarebytes Anti-Malware as Malware.Packer.T. The file is located in %System% | No |
bmw | X | bmw.exe | Detected by Trend Micro as BKDR_AGOBOT.BBV | No |
bmz | X | bmz.exe | 180Search adware | No |
BNDBSJKA.exe | X | BNDBSJKA.exe | Detected by Malwarebytes Anti-Malware as Spyware.Password. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
Bndt32 | X | Bndt32.exe | Detected by Symantec as W32.HLLW.Lacon@mm | No |
Microsoft Update | X | bnmveqfts.exe | Detected by Kaspersky as Trojan-Downloader.Win32.Banload.kwq and by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
RIVFOO | X | bNoLXl.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!tr and by Malwarebytes Anti-Malware as Backdoor.Messa.E | No |
WinCheck | U | bns***.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.MultiPlug - where *** represents 3 characters. The file is located in %LocalAppData%\03000200-1427113612-0500-0006-000700080009. If bundled with another installer or not installed by choice then remove it | No |
[various names] | X | bnui.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BO1HelperStartUp | U | Bo1helper.exe | ScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
BO1HelperStartUp | U | BO1HEL~1.EXE | ScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
Boan119 | X | Boan119.exe | Boan119 rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.Boan119 | No |
BoanCatch | X | BoanCatch.exe | BoanCatch rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanCatch | No |
BoanClear | X | BoanClear.exe | BoanClear rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanClear | No |
BoanCode | X | BoanCode.exe | BoanCode rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanCode | No |
BoanCop | X | BoanCop.exe | BoanCop rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.K.BoanCop | No |
boanguide | X | boanguide_up.exe | BoanGuide rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.K.BoanGuide | No |
boanking | X | boankingrun.exe | BoanKing rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanKing | No |
boankorea | X | boankorearun.exe | BoanKorea rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanKorea | No |
BoanN | X | BoanN.exe | BoanN rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanN | No |
BoanPack 3.0 | X | BoanPack.exe | Detected by Intel Security/McAfee as Generic FakeAlert and by Malwarebytes Anti-Malware as Rogue.BoanPack | No |
boanplus | X | boanplusrun.exe | BoanPlus rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanPlus | No |
BoanPro | X | BoanPro.exe | BoanPro rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanPro | No |
BoanShield | X | BoanShield.exe | BoanShield rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.K.BoanShield | No |
BoanSupport | X | BoanSupport.exe | BoanSupport rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BoanSupport | No |
BoanTab | X | BoanTab.exe | BoanTab rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.K.BoanTab | No |
boaqaa | X | boaqaa.exe | Detected by Malwarebytes Anti-Malware as Trojan.LVBP. The file is located in %UserProfile% | No |
boat32 | X | boat32.exe | Added by a variant of Backdoor:Win32/Rbot. The file is located in %System% | No |
bill | X | bobby.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr!he and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
BoBrowser | U | bobrowser.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BoBrowser. The file is located in %LocalAppData%\BoBrowser\Application. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
bobs | X | bobs.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeFlash. The file is located in %UserTemp% | No |
bobycizusatk | X | bobycizusatk.exe | Detected by Intel Security/McAfee as RDN/Generic.tfr!dz and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
bobyfiboznig | X | bobyfiboznig.exe | Detected by Intel Security/McAfee as RDN/Downloader.a!th and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
BOC-412 | Y | BOC412.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.12 | No |
BOC-420 | Y | BOC420.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.20 | No |
BOC-421 | Y | BOC421.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.21 | No |
BOC-422 | Y | BOC422.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.22 | No |
BOC-423 | Y | BOC423.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.23 | No |
BOC-424 | Y | BOC424.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.24 | No |
BOC-425 | Y | BOC425.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.25 | No |
BOC-426 | Y | BOC426.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.26 | No |
BOC-427 | Y | BOC427.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.27 | No |
BOCleanautostart | Y | Boclean.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters" | No |
Caddais BackupOnDemand | U | BODMon.exe | Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location" | No |
bofkyfkovirz | X | bofkyfkovirz.exe | Detected by Intel Security/McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
bofux | X | bofux.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
[various names] | X | Bogobot.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BoincLogX | U | boinclogx.exe | BoincLgx "makes it possible to log and show information about your processed WUs. In addition to a general log file which supports all BOINC projects, it will create project specific log files with detailed information about the WUs and results of some projects like SETI@home, Einstein@Home and AstroPulse." Add-on for the Boinc project | No |
BOINC Manager | U | boincmgr.exe | BOINC manager is a 'control panel' for BOINC. It provides a graphical interface for monitoring and controlling the BOINC Client (which is sometimes also called the "core client"). The Manager is a separate program and does not have to run all the time. The BOINC Manager can also be used for remote control of a BOINC Client running on another computer (if the client on that computer allows that) | No |
bokoharams | X | bokoharams.exe | Detected by Sophos as Troj/VBdrop-BW and by Malwarebytes Anti-Malware as Trojan.Agent.BKH | No |
bokoharams.exe | X | bokoharams.exe | Detected by Sophos as Troj/VBdrop-BW and by Malwarebytes Anti-Malware as Trojan.Agent.BKH. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
bolenja | X | bolenja.exe | Detected by Total Defense as Wantvi BF. The file is located in %System% | No |
bolenjx | X | bolenjx.exe | Detected by Total Defense as Eldycow O. The file is located in %System% | No |
sysftray2 | X | bolivar19.exe | Detected by Microsoft as Worm:Win32/Koobface.I and by Malwarebytes Anti-Malware as Trojan.Agent | No |
bolufadzoqty | X | bolufadzoqty.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% | No |
bombshel | U | BOMB32.EXE | Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems | No |
bomba | X | bomba.exe | Detected by Dr.Web as Trojan.MulDrop3.58666. The file is located in %System% | No |
bomba | X | bomba.exe | Detected by Dr.Web as Trojan.Siggen3.27560. The file is located in %Windir% | No |
BomulBox | X | BomulBoxC.exe | Detected by AVG as OpenShopper.D and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\BomulBox | No |
HPDESK | X | bonanza.exe | Detected by Intel Security/McAfee as RDN/Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent.BZ | No |
Apple | X | Bonjour.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!bbg and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
ABBYY Screenshot Reader Bonus | N | Bonus.ScreenshotReader.exe | Bonus version of the ABBYY Screenshot Reader utility available to users with registered versions of ABBYY FineReader and ABBYY PDF Transformer. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
ABBYY Screenshot Reader Retail | N | Bonus.ScreenshotReader.exe | ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
Bonus.SSR.FR10 | N | Bonus.ScreenshotReader.exe | Bonus version of the ABBYY Screenshot Reader utility available to registered users of ABBYY FineReader version 10. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
BonusCash | X | BonusCash.exe | Detected by Microsoft as Adware:Win32/Bonuscash and by Malwarebytes Anti-Malware as Adware.KorAd | No |
BonziBUDDY | X | BonziBDY.EXE | BonziBuddy adware - see here for removal instructions | No |
boo | X | boo.exe | Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN! | No |
Book Source | U | Book Source.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BookSource. The file is located in %Windir%\Book Source\Book Source. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
cvchost | X | book.exe | Detected by Dr.Web as Trojan.Siggen6.5935 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
Bookmark | U | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" | Yes |
Bookmark.exe | U | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" | Yes |
bool | X | bool.exe | Detected by Dr.Web as Trojan.Siggen4.26128 | No |
Antivir_boom | X | boom.exe | Detected by Dr.Web as Trojan.DownLoader9.5552 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BoontyBox | X | BoontyBox.exe | BoontyBox - "the ultimate jukebox software for your games. This free software is the best way to discover, download, launch and buy video games for your PC." Before Nexway acquired Boonty and discontinued the download the privacy policy used to state that amongst other thing they shared payment information with third parties - see here | No |
Boost | U | Boost.exe | Shop with Boost browser add-on by Verti Technology Group Inc - "is a safe, easy to use browser app that scours the web to show you the best prices and deals while you shop online." Detected by Malwarebytes Anti-Malware as PUP.Optional.Boost. The file is located in %ProgramFiles%. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
Auslogics BoostSpeed | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
Auslogics BoostSpeed 4 | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
BoostSpeed | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
BoostUpdater | U | BoostUpdater.exe | Updater for the Shop with Boost browser add-on by Verti Technology Group Inc - "is a safe, easy to use browser app that scours the web to show you the best prices and deals while you shop online." Detected by Malwarebytes Anti-Malware as PUP.Optional.Boost. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\Boost. If bundled with another installer or not installed by choice then remove it | No |
Boot Service | X | Boot Service.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BTS. The file is located in %CommonAppData%\Boot | No |
Boot | U | Boot.exe | Part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". The file is located in Acer\Empowering Technology\ePower | No |
boot | X | boot.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!wo and by Malwarebytes Anti-Malware as Backdoor.Agent.BT. The file is located in %Root%\boot | No |
boot | X | boot.exe | Detected by Sophos as Troj/Puppet-A. The file is located in %System% | No |
boot.exe | X | boot.exe | Detected by Symantec as W32.Quadrule.A. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
Font | X | boot.exe | Detected by Sophos as Troj/Agent-LZW | No |
HKCU | X | boot.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!wo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
HKLM | X | boot.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!wo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
load | X | boot.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!wo and by Malwarebytes Anti-Malware as Backdoor.Agent.BT. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "boot.exe" (which is located in %Root%\boot) and also adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" entry pointing to the same file | No |
windows defender | X | boot.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData% - see here | No |
WindowsBoot | X | boot.exe | Detected by Kaspersky as Trojan-Downloader.Win32.Genome.afck | No |
Microsoft Corporation | X | boot.lnk | Detected by Malwarebytes Anti-Malware as Trojan.Agent.E. The file is located in %UserTemp%\Ind | No |
HKCU | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\Microsoft | No |
HKLM | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\Microsoft | No |
Policies | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\Microsoft | No |
MS-DOS Boot Service | X | Boot32.pif | Detected by Sophos as W32/Rbot-AMF | No |
bootcareS | X | bootcareU.exe | BootCare rogue security software - not recommended, removal instructions here. One of the OneScan family of rogue scanner programs | No |
MnH8BPqsTcNhl9ZflpU= | X | bootcfg.exe | Detected by Dr.Web as BackDoor.Caphaw.77 and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
ccExecute | X | bootcfg1.exe | Detected by Sophos as W32/Nemsi-B | No |
explorer | X | bootcfgx.exe | Detected by Panda as Banbra.GQU and by Malwarebytes Anti-Malware as Trojan.Agent | No |
SecurePCSolutionsBootCheck | U | BootCheck.exe | 1 Click Fixer PLUS from Secure PC Solutions "takes the guesswork out of locating and solving problems in the Windows registry" | No |
Boot Check | X | bootchk.exe | Added by the DELBOT-AB WORM! | No |
Boot Client | X | bootcli.exe | Detected by Sophos as Troj/IRCbot-ACF and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
bootcmd | X | bootcmd.exe | Detected by Dr.Web as Trojan.Siggen4.26128 | No |
Internat Conf | X | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here | No |
OS Boot Configuration! | X | bootconf.exe | CoolWebSearch BootConf adware | No |
sysPnP | X | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here | No |
Boot Config | X | bootconfig.exe | Added by a variant of Backdoor:Win32/Rbot. The file is located in %System% | No |
Confg | X | bootconfig.exe | Added by the VB-ERB WORM! | No |
OS Boot Configuration | X | bootconfig.exe | Detected by Trend Micro as WORM_IRCBOT.HJ | No |
BootCTRL | X | bootctrl.exe | Added by an unidentified WORM or TROJAN! | No |
explores | X | BootEx.exe | Added by the VB-DWI WORM! | No |
Microsoft Patch Update | X | bootini.exe | Added by the RBOT-FMN WORM! | No |
Microsoft Windows | X | bootini.exe | Detected by Sophos as W32/Vanebot-K and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
Boot K | X | bootk.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
xbtl | U | bootldr.exe | WinSession Logger surveillance software - remove unless you installed it yourself! | No |
OS Boot Load | X | bootload.exe | Detected by Microsoft as | No |
BootLoader | X | BootLoader.exe.vbs | Detected by Symantec as VBS.Waterworks.Worm | No |
MicroUpdate | X | Bootmgr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System% | No |
Boot Manager | X | bootmng.exe | Added by the SDBOT.APK WORM! | No |
bootpd.exe | X | bootpd.exe | Added by the AGENT-DT TROJAN! | No |
Boot Resource Library | X | bootres.exe | Detected by Dr.Web as Trojan.Siggen4.42075 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Microsoft Word | X | BootSector.exe | Added by a variant of Backdoor:Win32/Rbot. The file is located in %System% | No |
Boot Server | X | bootserver.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
Boot Service | X | bootservice.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
BootSkin | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
BootSkin Randomizer | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
BootSkin Startup Jobs | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
bootstartx.exe | X | bootstartx.exe | Detected by Malwarebytes Anti-Malware as Trojan.SpyEyes. The file is located in %Root%\bootstartx.exe - see here | No |
bootstrap | X | bootstrap.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\intelx86 | No |
winstart | X | bootstrap.exe | Detected by Dr.Web as Trojan.MulDrop3.63287 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BootStatus | U | BOOTST~1.EXE | Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resources | No |
Boot Service | X | bootsv.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
Boot Verify | X | bootvfy.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
winservices | X | bootvfy.exe | Added by the VB.AMX TROJAN! | No |
[12 random characters] | X | bootvid2.exe | IeDriver adware variant | No |
[12 random characters] | X | bootvid4.exe | IeDriver adware variant | No |
Bootvrfy | X | bootvrfy.exe | Detected by Malwarebytes Anti-Malware as Worm.Texbot. The file is located in %Windir% | No |
bootvrfy.exe | X | bootvrfy.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeAlert. The file is located in %Temp% | No |
BootWarn | U | BootWarn.exe | Used to warn the end-user that they must reboot their PC when using older versions of Norton AntiVirus in those cases where a reboot did not happen after installation or a significant software update via LiveUpdate. See the AnswersThatWork entry for a more detailed description | Yes |
Windows Update Manager | X | bootwiz.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System% | No |
[random word pair] | X | bopotsvr.exe | Detected by Sophos as Troj/Shed-A | No |
[various names] | X | borlandg.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
boromarl | X | boromarl.exe | Detected by Intel Security/McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.Agent | No |
boromarl2 | X | boromarl.exe | Detected by Intel Security/McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.Agent | No |
borxofhaspac | X | borxofhaspac.exe | Detected by Intel Security/McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
BOS | X | bos.exe | Detected by Microsoft as Trojan:Win32/LockScreen.CI and by Malwarebytes Anti-Malware as Trojan.LockScreen | No |
bosadgypujuz | X | bosadgypujuz.exe | Detected by Intel Security/McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Boss Key | U | bosskey.exe | Boss Key from Mindgems Inc - "will hide and restore the windows (programs) on your screen with the press of a hotkey or a mouse shortcut" | No |
Boston | ? | Boston.exe | Part of the Boston Acoustics USB speaker systems. What does it do and is it required? | No |
Crow | X | bot.exe | Detected by Intel Security/McAfee as Generic.tfr!bi and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
dllhost.exe | X | bot.exe | Detected by Kaspersky as Trojan.Win32.Buzus.hbtx and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
Google Update | X | bot.exe | Added by the AGENT-UDF TROJAN! | No |
gost | X | bot.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
local | X | bot.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% - see here | No |
Microsoft Synchronization Manager | X | bot.exe | Detected by Trend Micro as WORM_SDBOT.IH | No |
svchost | X | bot.exe | Detected by Intel Security/McAfee as Generic.dx!bdwj and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
Windows Defender | X | Bot.exe | Detected by Dr.Web as Trojan.DownLoader8.17510 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
winsockdriver | X | bot.exe | Added by the WARPIGS-D WORM! | No |
WinStartup | X | bot.exe | Detected by Dr.Web as Trojan.DownLoader4.28358 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
Microsoft Update | X | Botnet.exe | Detected by Trend Micro as WORM_RBOT.AFL and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
Microsoft Updates | X | Botnet.exe | Detected by Trend Micro as WORM_RBOT.YS and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
WinNT | X | botoo.exe | Detected by Intel Security/McAfee as RDN/Generic FakeAlert!eo and by Malwarebytes Anti-Malware as Backdoor.Messa.E | No |
Configuration Loader | X | botss.exe | Detected by Sophos as W32/Sdbot-XS and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
WINDOWS SYSTEM | X | botzor.exe | Detected by Intel Security/McAfee as W32/Zotob.worm and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
Gseries | X | boulze.exe | Detected by Trend Micro as WORM_SDBOT.BJL and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
Bouncer RunStartup | X | bouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here | No |
[various names] | X | BoundRec.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
bowuquwubo | X | bowuquwubo.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!km and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
boXer | X | boXer.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.BX | No |
Windows Protectot | X | boxide.exe | Added by a variant of WORM_WOOTBOT.GEN | No |
Boxore | U | boxore.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Boxore.WnskRST. The file is located in %ProgramFiles%\Boxore\Boxore or %CommonAppData%\Boxore\[version]. If bundled with another installer or not installed by choice then remove it | No |
Boxore Client | X | boxore.exe | Detected by Malwarebytes Anti-Malware as Adware.Boxore. The file is located in %ProgramFiles%\Boxore\BoxoreClient | No |
Box Sync | U | BoxSync.exe | Box "offers secure, scalable content-sharing that both users and IT love and adopt" and "Box Sync is a desktop sync application that keeps all your files safe and secure in the cloud, while having them available on your computer and accessible from anywhere, on any device with Box mobile apps. No matter how you work, Box Sync helps you keep your files organized, safe, and always in sync with your business" | No |
bozlosjorodo | X | bozlosjorodo.exe | Detected by Intel Security/McAfee as RDN/Generic Downloader.x!jz and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
RVP | X | bpc.exe | Detected by Symantec as Adware.Broadcastpc | No |
BPCv2_re | X | bpc2_re_inst.exe | Added by a variant of Adware.Broadcastpc | No |
BigPondCable | N | bpcable.exe | Telstra Bigpond Cable login software - can be started manually | No |
bpcpost.exe | U | bpcpost.exe | MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it | No |
BPCV2 | X | BPCV2.exe | Detected by Symantec as Adware.Broadcastpc | No |
Bpdgaydlqdzqpfzn.exe | X | Bpdgaydlqdzqpfzn.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.56346 and by Malwarebytes Anti-Malware as Worm.AutoRun.E | No |
Bill & Pay Desktop Manager | U | bpdm.exe | "Bill & Pay improves cash flow, automates collections and reduces A/R time and costs. In addition to the basic functionality described below, you can activate many additional free features to meet your business needs" | No |
BulletProof FTP Server | N | bpftpserver.exe | BulletProof FTP Server | No |
BPK | U | bpk.exe | Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! The file is typically located in %ProgramFiles%\Perfect Keylogger Lite or %ProgramFiles%\BPK | No |
bpk | X | bpk.exe | Detected by Sophos as Troj/SCLog-AK. The file is located in %System% | No |
Major Microsoft Windows Driver Boot loader | X | bpool.exe | Added by the MYTOB.AJ WORM! | No |
bpsdwgxrm.exe | X | bpsdwgxrm.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.FBD. The file is located in %UserStartup% | No |
ContinueInstall | X | bpsinstall.exe | BrowserAid/BrowserPal foistware | No |
Breg | X | bptre.exe | Added by a variant of Adware.Broadcastpc | No |
Backpack UDF | N | bpudfmon.exe | Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk | No |
BigPond Toolbar | U | bpumTray.exe | Telstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier" | No |
Random | X | BPZ3490.exe | Detected by Dr.Web as Trojan.DownLoader11.12381 and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
(Default) | X | BQCXRdNJ.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData% | No |
rrmso | X | bqhrmug.exe | Detected by Sophos as Troj/Agent-GYY | No |
bqjaon | X | bqjaon.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile% | No |
Google Chrome | X | BQP531G0P6.exe | Detected by Dr.Web as Trojan.DownLoader6.14623. Note - this is not a legitimate Google Chrome browser file | No |
twqcnktc | X | bqslsdwh.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %LocalAppData% | No |
BQTray | U | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually | No |
BurnQuick Queue | N | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually | No |
BisonInst0402 | Y | BR040286.exe | Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye | No |
[various names] | X | br0ken.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
Tok-Cirrhatus-1464 | X | br3951on.exe | Detected by Trend Micro as WORM_BRONTOK.AD | No |
WinShys | X | br3ak.vbs | Detected by Intel Security/McAfee as VBS/Heart | No |
Tok-Cirrhatus-1959 | X | br4941on.exe | Detected by Sophos as W32/Brontok-J | No |
Tok-Cirrhatus-2454 | X | br5931on.exe | Detected by Trend Micro as WORM_BRONTOK.AD | No |
Tok-Cirrhatus-2784 | X | br6591on.exe | Detected by Sophos as W32/Brontok-L | No |
Brasil | X | Brasil.exe | Added by the OPASERV.P WORM! | No |
BrasilOld | X | Brasil.exe | Added by the OPASERV.P WORM! | No |
Brasil | X | Brasil.pif | Added by the OPASERV.E WORM! | No |
brastk | X | brastk.exe | Added by the DORF-BV TROJAN! | No |
BraveSentry | X | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here | No |
Brave-Sentry | X | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here | No |
braviax | X | braviax.exe | Added by the FAKEALER.LE TROJAN! | No |
Brother ControlCenter | N | BrCcBoot.exe | Brother Control Center for their range of AIO printer/scanner/copier/fax machines. Allows the user to perform actions directly from the desktop and "enables you to create user profiles and customize your settings to make printing and scanning more efficient" | Yes |
ControlCenter Launcher | N | BrCcBoot.exe | Brother Control Center for their range of AIO printer/scanner/copier/fax machines. Allows the user to perform actions directly from the desktop and "enables you to create user profiles and customize your settings to make printing and scanning more efficient" | Yes |
ControlCenter4 | N | BrCcBoot.exe | Brother Control Center for their range of AIO printer/scanner/copier/fax machines. Allows the user to perform actions directly from the desktop and "enables you to create user profiles and customize your settings to make printing and scanning more efficient" | Yes |
ControlCenter2.0 | N | brctrcen.exe | Brother Control Center for their range of AIO printer/scanner/copier/fax machines. Allows the user to perform actions directly from the desktop and "enables you to create user profiles and customize your settings to make printing and scanning more efficient" | No |
ControlCenter3 | N | brctrcen.exe | Brother Control Center for their range of AIO printer/scanner/copier/fax machines. Allows the user to perform actions directly from the desktop and "enables you to create user profiles and customize your settings to make printing and scanning more efficient" | No |
Driver Control Manager v3.2 | X | brdevet.exe | Detected by Sophos as W32/AutoRun-BHS and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Break_Reminder | U | BREAK REMINDER.exe | Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here | No |
Break.exe Espanha | X | Break.exe | Added by an unidentified TROJAN! See here | No |
WinUpdateB | X | breatle.exe | Added by the BRATLE.AWORM! | No |
Bredbandsbolaget Servicecenter | Y | Bredbandsbolaget.exe | Servicecenter for broadband services provided by the Swedish ISP Bredbandsbolaget | No |
Breg | X | breg.exe | Detected by Symantec as Adware.Broadcastpc | No |
tbrena | X | brenasa.exe | Detected by Malwarebytes Anti-Malware as Worm.AutoRun.Gen. The file is located in %Recycled%\{SID} | No |
ObjectDock | X | Brico.cmd | Added by the BOBANDY-A WORM! | No |
DellARM32 | X | bridge.cpl | Detected by Malwarebytes Anti-Malware as Trojan.Banker.E. The file is located in %CommonAppData% | No |
Adobe Bridge CS5 | N | Bridge.exe | Adobe Bridge - part of Adobe Creative Suite 5 which "lets you organize the assets you use to create content for print, web, and video. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
AdobeBridge | N | Bridge.exe | Adobe Bridge - part of Adobe Creative Cloud and Adobe Creative Suite (versions 4 thru 6) products which "lets you organize the assets you use to create content for print, web, and video. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
bridge | X | bridge.exe | Detected by Intel Security/McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Bridge | N | Bridge.exe | Adobe Bridge - part of Adobe Creative Cloud and Adobe Creative Suite (versions 4 thru 6) products which "lets you organize the assets you use to create content for print, web, and video. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
electronics | X | bridge_tied_load.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.FKTM. The file is located in %CommonFiles%\Microsoft Shared\ink\ro-RO\star_point | No |
Realtek Semiconductor | X | bridnaptics.cpl | Detected by Intel Security/McAfee as RDN/PWS-Banker!dk and by Malwarebytes Anti-Malware as Trojan.Banker.CPLGen | No |
Whitechix | X | brightx.exe | Added by a variant of W32/Sdbot.worm | No |
windows | X | Brinks.exe | Added by the AGENT-TOA TROJAN! | No |
BriTray | Y | BRITRAY.EXE | Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired | No |
Microsoft MUI Support | X | brloc.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.E. The file is located in %System% | No |
xBrotherMeCom | ? | BrMeCom.exe | Related to Brother MFC-9200c printer. What does it do and is it required? | No |
YourTemplateFinder EPM Support | U | brmedint.exe | YourTemplateFinder toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\YourTemplateFinder_br\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
Status Monitor | N | BrMfcWnd.exe | Brother scanner status monitor - can be started manually | No |
BrmfRmPA | U | BrmfRmPA.exe | Brother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate | No |
BrO_AcT | X | BrO-AcT.exe | Added by the SILLYFDC-D WORM! | No |
Broadbandadvisor | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
Broadbandadvisor.exe | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
Virgin Broadband advisor | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
BroadCamRun | N | broadCam.exe | BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone | No |
ChromeUpdate | X | brocats.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile% | No |
BrokerInfrastructure | X | BrokerInfrastructure.exe | Detected by Intel Security/McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Backdoor.Agent.PDL | No |
[various names] | X | Brong32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
Bron-Spizaetus | X | bronstab.exe | Added by the RONTOKBRO.C WORM! | No |
BRoNToK | X | BRoNToK.exe | Detected by Sophos as W32/Brontok-CG | No |
Brontok.exe | X | Brontok.exe | Detected by Dr.Web as Trojan.DownLoader11.19630 and by Malwarebytes Anti-Malware as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
BrHelp | N | BrotherHelp.exe | Help utility for Brother's range of AIO printer/scanner/copier/fax machines | No |
browext1_en_# | U | browext1_en_#.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Tuto4PC - where # represents one or more digits. The file is located in %ProgramFiles%\browext1_en_#. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
browext1_en_#.exe | U | browext1_en_#.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Tuto4PC - where # represents one or more digits. The file is located in %LocalAppData%\browext1_en_#. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
BrownsScreenServer | U | BrownsScreenServer.exe | Screensaver for the Cleveland Browns NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
browser | X | browse.exe | Detected by Total Defense as Win32.Tactslay.C. The file is located in %Windir% | No |
cpl | X | browse.exe | Detected by Total Defense as Win32.Tactslay.C. The file is located in %Windir% | No |
httpd | X | browse.exe | Detected by Total Defense as Win32.Tactslay.C. The file is located in %Windir% | No |
Messanger | X | browse.exe | Detected by Total Defense as Win32.Tactslay.C. The file is located in %Windir% | No |
StartMenu | X | browse.exe | Detected by Sophos as Troj/Drowsy-C | No |
[various names] | X | browsebar.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
BrowseBlast Web Accelerator | U | browseblast.exe | "BrowseBlast is an exciting new subscription-based product that lets you surf the Internet up to 6 times faster than a typical dial-up connection. BrowseBlast turns dial up connections virtually into broadband and makes broadband connections really take off" | No |
BrowseForTheCause | U | BrowseForTheCause.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowseForTheCause. The file is located in %ProgramFiles%\BrowseForTheCause. If bundled with another installer or not installed by choice then remove it | No |
INITINIT | X | browseinit.exe | Detected by Intel Security/McAfee as RDN/Generic Dropper!um and by Malwarebytes Anti-Malware as Trojan.Agent.INI | No |
Browser Extention Installer | X | Browser Extention Installer.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!c2j and by Malwarebytes Anti-Malware as Trojan.KBayi.FLA | No |
BHR 1.1 | U | BROWSER HIJACK RETALIATOR 1.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
Browser Protect | X | Browser Protect.exe | Detected by Intel Security/McAfee as RDN/Generic Dropper!so and by Malwarebytes Anti-Malware as Trojan.Agent.BP | No |
browser | U | browser.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.AdBlaster. The file is located in %ProgramFiles%\AdBlaster\Application. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
browser.exe | X | browser.exe | Detected by Intel Security/McAfee as PWS-Banker and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Chrome | X | browser.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CHGen. The file is located in %AppData%\Microsoft\Windows\Cookies\cookies | No |
Browser.vbs | X | Browser.vbs | Detected by Malwarebytes Anti-Malware as Trojan.Startup. The file is located in %UserStartup% | No |
Windows Browser Services | X | browser128.exe | Detected by Microsoft as | No |
Windows Browser Services | X | browser32.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
[12 random characters] | X | browser5.exe | IeDriver adware variant | No |
Windows Browser Services | X | browser64.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
[12 random characters] | X | browser8.exe | IeDriver adware variant | No |
browser aid | X | browseraid.exe | BrowserAid/BrowserPal foistware | No |
GoogleChromeAutoLaunch_[ID] | U | BrowserAir.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserAir. The file is located in %LocalAppData%\BrowserAir\Application. If bundled with another installer or not installed by choice then remove it | No |
BrowserChoice | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
Microsoft Browser Choice | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
Microsoft® Windows® Operating System | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
BrowserManager | U | BrowserManager.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserManager. The file is located in %ProgramFiles%\FUPM Browser. If bundled with another installer or not installed by choice then remove it | No |
FUPM Browser | U | BrowserManager.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserManager. The file is located in %ProgramFiles%\FUPM Browser. If bundled with another installer or not installed by choice then remove it | No |
browserr.exe | X | browserr.exe | Detected by Dr.Web as Trojan.KillFiles.12621 and by Malwarebytes Anti-Malware as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
browserr1.exe | X | browserr1.exe | Detected by Dr.Web as Trojan.MulDrop5.7250 and by Malwarebytes Anti-Malware as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
BrowserSafeguard | U | Browsersafeguard.exe | "BrowserSafeguard works alongside your other antivirus software and firewalls to provide the safest computing experience possible. You will not need to uninstall or disable your other layers of protection." Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowserSafeguard. The file is located in %ProgramFiles%\Browsersafeguard or %LocalAppData%\Browsersafeguard. If bundled with another installer or not installed by choice then remove it | No |
Browser Sentinel | U | BrowserSentinel.exe | Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page | No |
WebBrowserFusionPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.FusionPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\FusionPlayer. If bundled with another installer or not installed by choice then remove it | No |
WebBrowserHDQPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.HDQPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\hdqPlayer. If bundled with another installer or not installed by choice then remove it | No |
WebBrowserMixVideoPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.MixVideoPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\MixVideoPlayer. If bundled with another installer or not installed by choice then remove it | No |
WebBrowserQuickVideoPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.QuickVideoPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\QuickVideoPlayer. If bundled with another installer or not installed by choice then remove it | No |
WebBrowserSharPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.SharPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\SharPlayer. If bundled with another installer or not installed by choice then remove it | No |
WebBrowserViPlayer | U | BrowserWeb.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.ViPlayer. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\ViPlayer. If bundled with another installer or not installed by choice then remove it | No |
Browsing Secure | U | browsingsecure.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BrowsingSecure. The file is located in %ProgramFiles%\Browsing Secure\BrowsingSecure\[version]. If bundled with another installer or not installed by choice then remove it - removal instructions here | No |
Windows Browser Services | X | Browsr32.exe | Added by the IRCBOT.BUR BACKDOOR! | No |
Windows Browser Services | X | browsr64.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
System | X | BrO_AcT.exe | Added by the SILLYFDC-AL WORM! | No |
wupdate | X | bro_exe.exe | Added by the DELF.GR TROJAN! | No |
BDRegion | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times. The file is located in %ProgramFiles%\Cyberlink\Shared Files | Yes |
BRS | X | brs.exe | Detected by Intel Security/McAfee as RDN/Generic.dx!df3 and by Malwarebytes Anti-Malware as Backdoor.Agent.BSR. The file is located in %AppData%\Cyberlink | No |
brs | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times. The file is located in %ProgramFiles%\Cyberlink\Shared Files | Yes |
BRS | U | brs.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Groovorio. The file is located in %ProgramFiles%\Groovorio\BRS. If bundled with another installer or not installed by choice then remove it | No |
BRS | U | brs.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.MySearchDial. The file is located in %ProgramFiles%\Mysearchdial\BRS. If bundled with another installer or not installed by choice then remove it | No |
BRS | U | brs.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Astromenda. The file is located in %ProgramFiles%\WSE_Astromenda\BRS. If bundled with another installer or not installed by choice then remove it | No |
cyberlink brs | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times. The file is located in %ProgramFiles%\Cyberlink\Shared Files | Yes |
YourTemplateFinder Search Scope Monitor | U | brsrchmn.exe | YourTemplateFinder toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\YourTemplateFinder_br\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it | Yes |
SetDefPrt | N | BrStDvPt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation | No |
BrStsMon00 | U | BrStMonW.exe | Status monitor for Brother's range of AIO printer/scanner/copier/fax machines - for monitoring printer status, checking ink levels, etc | Yes |
Status Monitor Application | U | BrStMonW.exe | Status monitor for Brother's range of AIO printer/scanner/copier/fax machines - for monitoring printer status, checking ink levels, etc | Yes |
fekhflsm | X | brtworoi.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.EA. The file is located in %LocalAppData% | No |
java | X | BRTXEJJTWR4.exe | Detected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData% | No |
Microsoft Browser Services | X | Brwsr32.exe | Detected by Microsoft as | No |
Microsoft Browser Services | X | Brwsr64.exe | Added by a variant of the SLENFBOT.FT WORM! | No |
Tok-Cirrhatus-[4 random digits] | X | br[4 random digits]on.exe | Detected by Sophos as W32/Brontok-M | No |
Windows Defender | X | BS SERVER.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData% | No |
winupdate | X | BS-Test1-nofud.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
Adobe Update | X | bs.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Andromeda. The file is located in %UserTemp% | No |
qqegubig | X | bsaaxcgl.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom.WSF. The file is located in %LocalAppData% | No |
windows | X | bsade.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
bsavyfmpvjh.exe | X | bsavyfmpvjh.exe | Detected by Intel Security/McAfee as RDN/Generic.bfr!ia and by Malwarebytes Anti-Malware as Trojan.Banker.RND. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
BSBALL.exe | X | BSBALL.exe | Detected by Sophos as Mal/VB-ZS | No |
Microsoft Services | X | bsc32.exe | Detected by Sophos as Troj/Bdoor-AW | No |
BsCLiP | N | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required | No |
B'sCLiP | N | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required | No |
Bsearch | X | bsearch.exe | Detected by Symantec as Download.Adware and by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\barosearch | No |
update.exe | X | bserv2.exe | Detected by Dr.Web as Trojan.PWS.Siggen.38618 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
Bservice | U | bservice.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Bench. The file is located in %ProgramFiles%\Bench\BService or %ProgramFiles%\Bench\BService\[version]. If bundled with another installer or not installed by choice then remove it | No |
BService64 | U | bservice64.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Bench. The file is located in %ProgramFiles%\Bench\BService or %ProgramFiles%\Bench\BService\[version]. If bundled with another installer or not installed by choice then remove it | No |
BearShare Lite | N | BSHARELITE.EXE | BearShare Lite (now replaced by BearShare 10) peer-to-peer (P2P) file-sharing client. As with any P2P client which is used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads | No |
Microsoft Driver Setup | X | BSmBT.exe | Detected by Avira as Worm/Kolab.ehp and by Malwarebytes Anti-Malware as Worm.Palevo | No |
BsMnt | ? | BsMnt.exe | Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required? | No |
Microsoft Driver Setup | X | BSoBT.exe | Detected by Avira as Worm/Kolab.eil and by Malwarebytes Anti-Malware as Worm.Palevo | No |
Blue_Screen_of_Death | X | bsod.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\bsod.exe | No |
BSOD | X | bsod.hta | Detected by Malwarebytes Anti-Malware as Rogue.TechSupportScam. The file is located in %Windir% | No |
bsod.hta | X | bsod.hta | Detected by Malwarebytes Anti-Malware as Rogue.TechSupportScam. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
QwaT[random] | X | bsod.hta | Detected by Malwarebytes Anti-Malware as Rogue.TechSupportScam. The file is located in %AllUsersStartup% | No |
Bsoft lppt01 | X | Bsoft.exe | RapidBlaster variant (in a "BelmontSoft" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
BS Player | N | BSPLAYER.EXE | BS.Player by AB Team d.o.o. - "is the software movie and media player that supports all popular video and audio media file types, containers and formats" | No |
BSPLAYER | N | BSPLAYER.EXE | BS.Player by AB Team d.o.o. - "is the software movie and media player that supports all popular video and audio media file types, containers and formats" | No |
BS Mediaplayer | X | bsplyr.exe | Added by the RBOT-OU WORM! | No |
Internet Security | X | bsprotection.exe | Detected by Dr.Web as Trojan.KillProc.28692 and by Malwarebytes Anti-Malware as Trojan.FakeAV.Gen | No |
Bsqbhzkzykzdvwja.exe | X | Bsqbhzkzykzdvwja.exe | Detected by Sophos as W32/Dorkbot-EQ | No |
Bsqxitat | X | Bsqxita.exe | Added by the AUTORUN-BDL WORM! | No |
winlogon | X | BSserver.exe | Detected by Kaspersky as Trojan.Win32.VBKrypt.cngj and by Malwarebytes Anti-Malware as Trojan.Agent.Trace | No |
javac | X | bsst.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
RUN64 | X | bsteststart.exe | Detected by Intel Security/McAfee as RDN/Generic FakeAlert and by Malwarebytes Anti-Malware as Backdoor.Agent.RNGen | No |
symanteccsysconf | X | bsyys.exe | Detected by Trend Micro as TSPY_BANKER-2.001 | No |
symanteccsysconf | X | bsyys.scr | Added by the VACILL-A WORM! | No |
SymantecFilterCheck | X | bsyys.scr | Detected by Trend Micro as TROJ_BANLOAD.DZC and by Malwarebytes Anti-Malware as Trojan.Agent | No |
bs_netframes | X | bs_netframe.exe | Detected by Intel Security/McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.BS | No |
bs_stealth | X | bs_stealth.exe | Detected by Intel Security/McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.BSGen | No |
local.exe | X | bs_stealth.exe | Detected by Dr.Web as Trojan.DownLoader8.17186 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
BBDial | ? | BT Broadband.exe | Part of BT Broandband - is it required? | No |
syscall1 | X | btc.exe | Detected by Malwarebytes Anti-Malware as Trojan.BitcoinMiner. The file is located in %AppData%\Mining | No |
btclient | U | btclient.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BTClient. The file is located in %ProgramFiles%\dlclient\dlclient\[version]. If bundled with another installer or not installed by choice then remove it, removal instructions here | No |
Internet Security | X | btdefender.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeAV.DFN. The file is located in %CommonAppData% | No |
BitTorrent DNA | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
btdna | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
btdna.exe | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
DNA | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
btbb_McciTrayApp | N | BTHelpNotifier.exe | System tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not required | No |
Motive SmartBridge | N | BTHelpNotifier.exe | System tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not required | No |
[12 random characters] | X | bthserv1.exe | IeDriver adware variant | No |
BTIcon | X | BTIcon.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!uf | No |
BTIconu | X | BTIcon_updater.exe | Detected by Intel Security/McAfee as RDN/Generic BackDoor!uf | No |
BTStackServer | ? | btinst.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? | No |
Cats and Catapults EPM Support | U | btmedint.exe | Cats and Catapults toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\CatsCatapults_bt\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it, removal instructions here | Yes |
BTModemProtection | X | BTModemProtection.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - this is not a legitimate entry for the old BT Privacy Online modem protection software which has the filename BTModemProtection.lnk and loads the file BTModemProtection.exe from %System%. This file is located in %CommonFiles%\System\Ole DB | No |
BTModemProtection | X | BTModemProtection.exe | Detected by Malwarebytes Anti-Malware as Trojan.Bitcoin. Note - this is not a legitimate entry for the old BT Privacy Online modem protection software which has the filename BTModemProtection.lnk and loads the file BTModemProtection.exe from %System%. This file is located in %ProgramFiles%\FreeFileSync\Languages | No |
BTModemProtection | U | BTModemProtection.lnk | BT Privacy Online modem protection software for the old BT dial-up ISP software - by "monitoring dial-up connections our software will alert you anytime your computer attempts to dial a premium rate, international or non-approved number" | No |
btmsre.exe | X | btmsre.exe | Detected by Trend Micro as WORM_SDBOT.AM | No |
btmsrvvw | X | btmsrvvw.exe | Detected by Intel Security/McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Backdoor.Agent.E | No |
LoadBtnHnd | U | BtnHnd.exe | Fujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input | No |
Director Video | X | btnmgern.exe | Added by the MYTOB-KL WORM! | No |
ATI Video Driver Control | X | btorrent.exe | Added by the RBOT.BLL BACKDOOR! | No |
Trap Wired Coordinator SSDP Protection | X | btraogb.exe | Detected by Intel Security/McAfee as Downloader.a!dch and by Malwarebytes Anti-Malware as Trojan.Agent | No |
FBackup 5 Tray Agent | U | bTray.exe | System Tray access to version 5 of the FBackup backup utility from Softland SRL | No |
f73cdc8ee94e | X | btsendto.exe | Associated with mysearchnow.com/searchbar.html | No |
BTSETBOOTKEY | ? | BTSetBootKey.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) | No |
Cats and Catapults Search Scope Monitor | U | btsrchmn.exe | Cats and Catapults toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes Anti-Malware as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\CatsCatapults_bt\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove it, removal instructions here | Yes |
BTStacFrr | X | BTStacFrr.exe | Detected by Microsoft as TrojanSpy:Win32/Bancos.AAI and by Malwarebytes Anti-Malware as Trojan.Banker | No |
BTStacLrj | X | BTStacLrj.exe | Detected by Microsoft as TrojanSpy:Win32/Bancos.AAI and by Malwarebytes Anti-Malware as Trojan.Banker | No |
BTStacPgn | X | BTStacPgn.exe | Detected by Microsoft as TrojanSpy:Win32/Bancos.AAI and by Malwarebytes Anti-Malware as Trojan.Banker | No |
BtStart | U | btstart.exe | Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software | No |
Button Server | U | bttnserv.exe | Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required | No |
BTTray | U | BTTray.exe | System tray icon which shows the status of a Bluetooth wireless module from WIDCOMM, Inc (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) and loads via %AllUsersStartup% | Yes |
BtTray | U | BtTray.exe | Part of the Bluetooth implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. Note - during testing, other than the System Tray icon included as part of the Windows OS this appeared to add no additional icon. Given this it is still recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled. Loads via the HKLM\Run registry key | Yes |
BTUSRBDG | Y | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) | No |
BTV | X | btv.exe | Detected by Symantec as Adware.Broadcastpc | No |
BtvC | X | btvclean.exe | Detected by Symantec as Adware.Broadcastpc | No |
AtherosBtStack | U | BtvStack.exe | Older version of the Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
Bluetooth Software | U | BtvStack.exe | Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
BtvStack | U | BtvStack.exe | Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
BT | X | BTw10.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.MNR. The file is located in %AppData%\BT2 | No |
btwdins.exe | X | btwdins.exe | Added by the AUTORUN-ML WORM! Note - this is not the valid Widcomm/Broadcom Bluetooth file with the same name which is typically located in %ProgramFiles%\WIDCOMM\Bluetooth Software. This one is located in %System%\drivers | No |
Bluetooth Config | X | btwindin32.exe | Detected by Sophos as W32/Sdbot-DFN | No |
BtyTyD4RNoF | X | BtyTyD4RNoF.exe | Detected by Intel Security/McAfee as RDN/Generic Qhost!j and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
Bubble Suite | U | Bubble Suite.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Nosibay. The file is located in %AppData%\Nosibay\Bubble Suite. If bundled with another installer or not installed by choice then remove it | No |
Bubble | Y | Bubble.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyState | Yes |
Windows SteadyState - Bubble Messages | Y | Bubble.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyState | Yes |
Buddyizer | N | Buddyizer.exe | Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network | No |
Buddy Search | X | BuddySetup.exe | Detected by Microsoft as Adware:Win32/Nbar and by Malwarebytes Anti-Malware as Adware.BuddySearch. The file is located in %ProgramFiles%\Buddy Search | No |
BudgetSip | N | BudgetSip.exe | BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
budgyfxaklez | X | budgyfxaklez.exe | Detected by Intel Security/McAfee as RDN/Generic.tfr!dm and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
budspencer | X | budspencer.exe | Detected by Intel Security/McAfee as Generic MSIL.t and by Malwarebytes Anti-Malware as Trojan.Clicker.Gen | No |
buenosearch | U | buenosearch.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.Buenosearch. The file is located in %AppData%\buenosearch\buenosearch\[version]. If bundled with another installer or not installed by choice then remove it | No |
SysMain | X | buff.exe | Detected by Sophos as Troj/Agent-ECW and by Malwarebytes Anti-Malware as Trojan.Agent.E | No |
System Buffer Application | X | buffer32.exe | Detected by Sophos as W32/Sdbot-UD | No |
bufgazulovyz | X | bufgazulovyz.exe | Detected by Dr.Web as Trojan.DownLoader9.55631 and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
BugDoctor | X | BugDoctor.exe | Bug Doctor rogue security software - not recommended, removal instructions here | No |
BuGrAzE | X | BuGrAzE.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %LocalAppData% | No |
bugwatcher service | U | bugwatcher.exe | Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures | No |
Bug Eliminator | N | Bug_Elim.exe | Bug Eliminator - "performs a complete health check on your computer safely, securely, and silently!" No longer available | No |
bui.exe | X | bui.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
Builder | X | Builder.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SB. The file is located in %ProgramFiles%\Microsoft.NET | No |
Builder | X | Builder.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.UKN. The file is located in %ProgramFiles%\SuperSoft | No |
STARTERPACK | X | BuiltCrypt.exe | Detected by Intel Security/McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.DCE | No |
bulirizkonyd | X | bulirizkonyd.exe | Detected by Intel Security/McAfee as RDN/Downloader.a!f and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
bulk | X | bulk.exe | Added by the AGOBOT-ACR WORM! | No |
BullguardoptIn | Y | bulldownload.exe | Part of BullGuard antivirus | No |
bg | Y | bullguard.exe | Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster | No |
BullGuard | Y | BullGuard.exe | Part of BullGuard security software products | No |
msg | X | Bun.bat | Detected by Sophos as Bat/Nub-A | No |
SAHBundle | X | bundle.exe | ShopAtHomeSelect parasite | No |
VBundleOuterDL | X | BundleOuter.EXE | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here | No |
buoquixinorb | X | buoquixinorb.exe | Detected by Intel Security/McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
buritos | X | buritos.exe | Identified as a variant of the Downloader.FraudLoad.C malware | No |
System settings | X | burndl32.exe | Added by the SDBOT-ZO WORM! | No |
Rakyat_Miskin | X | Buruh.exe | Detected by Symantec as W32.SillyFDC.BDM and by Malwarebytes Anti-Malware as Worm.SFDC | No |
GoogleSearchEngine | X | BuscaGoogle.exe | Detected by Kaspersky as Trojan.Win32.Pasta.phb and by Malwarebytes Anti-Malware as Trojan.StartPage | No |
Malwarebytes Anti-Malware | Y | businessmessaging.exe | Part of Malwarebytes Anti-Malware which displays relevant messages | Yes |
butt.exe | X | but.scr | Detected by Malwarebytes Anti-Malware as Trojan.VirTool. The file is located in %UserTemp% - see here | No |
butretiresx | X | butretiresx.exe | Detected by Sophos as Troj/VB-ILL and by Malwarebytes Anti-Malware as Trojan.InfoStealer.AST | No |
butretiresx.exe | X | butretiresx.exe | Detected by Sophos as Troj/VB-ILL and by Malwarebytes Anti-Malware as Trojan.InfoStealer.AST. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
Scan Wizard | ? | button.exe | Associated with Scan Wizard as supplied with Microtek scanners - see also the "Scanner Detector" and "Sdetect" entries. What does it do and is it required? | No |
ButtonGuide | X | ButtonGuideC.exe | Detected by Symantec as Adware.OpenShopper and by Malwarebytes Anti-Malware as Adware.ButtonGuide. The file is located in %ProgramFiles%\ButtonGuide | No |
ButtonKey | N | ButtonKey.exe | CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon on the System Tray. Use your scanners software or run it manually by creating a shortcut | No |
ButtonMonitor | U | ButtonMonitor.exe | Button support utility for some products from Verbatim - probably for their range of desktop and portable hard drives, see here. Located in %ProgramFiles%\Verbatim | No |
Gateway Photo Frame | N | ButtonMonitor.exe | Supports the "Photo Frame" button on selected Gateway models such as the DX4300. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Gateway Photo Frame | No |
Packard Bell Photo Frame | N | ButtonMonitor.exe | Supports the "Photo Frame" button on selected Packard Bell models such as the iExtreme. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Packard Bell Photo Frame | No |
Smart Copy | U | ButtonMonitor.exe | Button support utility for some products from I/O Interconnect - probably for their range of removable storage devices, see here. Located in %ProgramFiles%\IOI\Smart Copy | No |
Windows Defender | X | buy.exe | Detected by Dr.Web as Trojan.AVKill.5830 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
buzkammomzat | X | buzkammomzat.exe | Detected by Intel Security/McAfee as PWS-Zbot-FAQD!881B9819D2E6 and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
Buzof | U | buzof.exe | Buzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes" | No |
Buzzing Dhol.exe | U | Buzzing Dhol.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BuzzingDhol. The file is located in %Windir%\Buzzing Dhol\Buzzing Dhol. If bundled with another installer or not installed by choice then remove it | No |
Buzzing Dhol | U | BuzzingDhol.exe | Detected by Malwarebytes Anti-Malware as PUP.Optional.BuzzingDhol. The file is located in %ProgramFiles%\Buzzing Dhol\Buzzing Dhol. If bundled with another installer or not installed by choice then remove it | No |
RNBc Test | X | bvldv32.exe | Detected by Sophos as W32/Rbot-AJF | No |
SysScan | X | bvt.exe | Detected by Symantec as Backdoor.Autoupder | No |
BVWORSFM | X | bvworsfm.exe | Detected by Sophos as Troj/Dluca-AD | No |
Best Virus Protection | X | BV[random].exe | Best Virus Protection rogue security software - not recommended, removal instructions here. Detected by Malwarebytes Anti-Malware as Rogue.BestVirusProtection | No |
XupiterCfgLoader | X | BWCfgLoader.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
SOUNDMIX32 | X | BwindoS.exe | Detected by Intel Security/McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.ELD | No |
BitWare Print Monitor | N | bwprnmon.exe | Print monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRO | No |
bwprnmon.exe | N | bwprnmon.exe | Print monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRO | No |
Service Connection | N | bwtray.exe | For Compaq PC's. Part of Backweb | No |
oeplugin | U | bxOEPlugin.exe | noHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple text | No |
bxproxy | X | bxproxy.exe | Detected by Trend Micro as BKDR_AGENT.AIW | No |
Boost XP Service | U | bxservice.exe | Boost XP from Systweak - WinXP tweaking utility | No |
Windows Live Messenger | X | bxZLovvPECTRHTQNarw.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData% | No |
Black Keylogger | X | By.dron.exe | Detected by Dr.Web as Trojan.MulDrop5.2534 and by Malwarebytes Anti-Malware as Trojan.Agent.KLG | No |
load | X | Bypass.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BP. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "Bypass.exe" (which is located in %UserTemp%\avg) | No |
byssetebidbi | X | byssetebidbi.exe | Detected by Intel Security/McAfee as BackDoor-FAGP!71303927D4A0 and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
ByteDefender | X | ByteDefender.exe | ByteDefender rogue security software - not recommended, removal instructions here | No |
byzjanpaxnod | X | byzjanpaxnod.exe | Detected by Malwarebytes Anti-Malware as Trojan.Cutwail. The file is located in %UserProfile% | No |
Backblaze | U | bzbui.exe | Backblaze online backup utility for businesses | No |
BZEnvironmentVariableCollector | ? | BZEnvironmentVariableCollector.exe | Part of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships" | No |
Health Credential Audio Config Portable | X | bzgyfcbsoq.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.HCA. The file is located in %System% | No |
bZmq0AK16YY.exe | X | bZmq0AK16YY.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
BZUtilizationCollector | ? | BZUtilizationCollector.exe | Part of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships" | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a list of tasks/processes taken from the Task Manager (CTRL+SHIFT+ESC) "Processes" tab. This displays some startup programs AND other background tasks and "Services". These pages are concerned with startup programs from the common startup locations shown above ONLY. Please do not submit entries collected from this method as they will not be used. For a list of tasks/processes you should try the list at PC Pitstop, the Process Library from Uniblue or one of the many others now available.
Therefore, before ending a task/process via CTRL+SHIFT+ESC just because it has an "X" recommendation, please check whether it's in the registry or common startup locations first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+SHIFT+ESC. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 25K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entries listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program.
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the Windows 8/7/Vista/XP/2K/NT operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2016 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
Privacy Policy | Site Map | Home |