Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Note the filename has a ""0"" rather than an upper case ""o"""
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-end
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
X(Default)5640.exe"Added by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X..ABC2007.exe"Added by the DLOADR-ASH TROJAN!"
U000pit.exe"PrivateEye surveillance software. Uninstall this software unless you put it there yourself"
X000hpdllhoshpdllhost.exe"LZIO.com adware downloader"
U000StTHK000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc Fn-F1 (lock) Fn-F2 Fn-F3 Fn-F4 Fn-F5 (switching between laptop and CRT display output) etc...)
X0050726-007-i32-10050726-007-i32-1.exe"Added by the BANCBAN-EC TROJAN!"
?00DSKSVR00desksaver.exe"Related to Advanced Desktop Shield"
?00DSKSVR01desksaver.exe"Related to Advanced Desktop Shield"
Y00PCTFWFirewallGUI.exe"PC Tools Firewall Plus - ""powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network"""
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U00THotkey00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons play stop next prev.
U00THotkeysystem32THotkey.exeFor Toshiba Satellite notebook series to use the front buttons play stop next prev
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
U101Clips101Clips.exe"101Clips - ""the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"""
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"NCase adware"
X180ax180ax.exe"NCase adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
X196_150_ni196_150_ni.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
X2020Downloadermssvr.exe"2020Search Toolbar"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd"3Com WinModem driver. See here for more WinModem information"
X4684735485910netdll32.exe"Added by the SDBOT-DEV WORM!"
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X98D0CE0C16B1rundll32.exe D0CE0C16B1 D0CE0C16B1"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X@iexpl0res.exe"Added by the RBOT.AEX WORM!"
UA1000 Settings Utilitycpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan print copy and fax. Only required if you use these features
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EBrundll32.exe E6F1873B.DLL D9EBC318C"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
NAccessRamp Monitor01ARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
NAccessRampLAN01ARUpld32.exeVersion of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
Xadtech2005adtech2005.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xadtech2006adtech2006.exe"Detected by Kaspersky as the VB.KC WORM!"
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 spyware remover - not recommended see here"
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xaimaol ml097eaimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended see here"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus2008yantvrs.exe"Antivirus 2008 rogue security software - not recommended see here"
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
YATI Remote ControlATIX10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
YATIX10atix10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status checking ink levels etc etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX7800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
NAUXXTRAYau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
UBACPI10bacpi10a.exeKnown as "PowerKey" - a minimalistic keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win95/98/NT4). Also adds an icon to the system tray
UBestSync 2008BestSyncApp.exe"System Tray access to BestSync® 2008 from Risefly Software - ""a professional utility for synchronizing files between your local folders and Network Drives FTP servers Removable Media (such as an USB disk)"""
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout added by version 7 of the Nero digital media suite (CD & DVD burning authoring etc). Thanks to Help2Go.com if you feel this is draining more resources that necessary you can disable it by clicking here"
UBHODemon 2.0BHODemon.exe"BHODemon ""protects you from unknown Browser Helper Objects (BHOs) by letting you enable/disable them individually. When running it also monitors your Registry and alerts you when a BHO is installed. Best of all BHODemon knows about the most common BHOs - the good ones and the not-so-good ones!"". If you prefer forgoing resident protection the application can also be run on demand"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources"
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"""
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
YBOC-420BOC420.exe"NSClean (now Comodo) BOClean anti-malware software - ""Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely"". Version 4.20"
XBsoft lppt01Bsoft.exe"RapidBlaster variant (in a ""BelmontSoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBT00003*abcdefg23.exe"Added by the VB-VT TROJAN where * = 56 or 7!"
XBT00003*hiklmnop27.exe"Added by the VB-VT TROJAN where * = 23 or 4!"
NCalendar 200X Remindercalendar.exe"Calendar 200X - shows holidays reminders of various anniversariestasks etc"
?Canon PC1200 iC D600 iR1200G Status WindowCAPM1LAK.EXE"Cannon printer related - is it required in startup?"
NCapture Express 2000capexp.exe"Capture Express - screen capture utility"
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
XCare20Care20.exe"TopMoxie adware"
XCassandra[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
UCHotKeyMK9805.EXEEnables special keys on Chicony keyboards. Special combinations include Internet E-mail vol+ vol- mute etc. Only required for extended features
NClipmate6CLIPMT60.EXE"Clip Mate 6 by Thornsoft. Utility that allows you to store more than one item in the clipboard. Available via Start -> Programs"
?Clotusorgreg0prtStart.exe [path] Orgprt.exe"IBM Lotus SmartSuite related. In a LotusOrgReg folder. Unclear what exactly it does?"
Xcmt101cmt101.exe"Added by a variant of the CRYPTER.C TROJAN!"
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information tips ideas and special offers from HP and our partners especially designed for HP and Compaq desktop computer owners"". * can be any digit"
XCompaq Print Faxcpqa1000.exe"Added by the SDBOT.BCV WORM! Please take note of the difference between the legitimate Compaq Fax Utility Name (A1000 Settings Utility) and the name (Compaq Print Fax) used by this worm"
XConfiguration LoaderIEXPL0RE.EXE"Added by the LOADCFG or SDBOT TROJANS!"
XConfiguration Loader10ip7.exe"Added by the AGOBOT-ANZ WORM!"
XControl handler[10 to 14 random char]THD.EXE"Added by the KREPPER-AI TROJAN!"
NControlCenter2.0brctrcen.exeBrother scanner 'Control Center' application - can be started manually
XControlPanelpopcorn320.exe rundll.dll LoadMouseProfile"Added by a variant of the DLOADER-RA TROJAN!"
NCorelCENTRAL 10I_26dadCC.exe"CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs"
UCPATR10CPATR10.EXEDritek/Compal ATR10 Easy Button driver. Used on certain laptops (e.g. Toshiba Compaq) to translate special hotkeys such as Play/Pause and Constrast
NCplBTQ00CplBTQ00.EXERelated to EZbutton quick launcher for the Media player app that comes with certain laptops
NCPLDBL10CPLDBL10.exeRelated to EZbutton quick launcher for the Media player app that comes with certain laptops
NCreateCD50Createcd50.exeAdaptec Easy CD Creator version 5 system tray application. Available via Start -> Programs
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCTFM0N.exeCTFM0N.exe"Added by the STARTPAGE.P TROJAN! Notice the digit ""0"" in both columns rather than the upper case ""o"""
XCTin10CTin10.exe"Added by the BANCOS.E TROJAN!"
UCustomizer2000logon.exe"Automatic logon feature of Customizer 2000 - ""a special utility which is designed to optimize Win9x/ME performance. The program lets you explore the many hidden settings in Windows and make changes"""
UCyber-Defender 2003uwcdsvr.exe"Cyber Defender 2003"
ND-Link AirPlus DWL-650+ UtilityWLANMON.exeD-Link Air Plus Wireless PC modem connection monitor
ND066UUtilityD066UUTY.EXETWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
UDAEMON Tools-1033Daemon.exe"Daemon Tools - used to map an image-file (.iso .bin etc) to a virtual CD/DVD-drive"
XDanBtR270414DanBtR270414.exe"Added by the VB-NIB WORM!"
UDC300 Monitorcmonitor.exeMonitor for a Acer DC300 digital camera
UDeko550Deko550.exe"Associated with the Deko550 entry-level SD real-time graphics system from Avid Technology"
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
NDesktop PlantAZARE10S.PLT"Vritual plant from here - this version is an Azalea there are others so the filename may be different"
UDeviceDiscoveryhpotdd01.exeDetection of new imaging printing and other peripherals on HP machines such as USB printers cameras and Bluetooth products
NDigiGuideclient01.exeTV guide and reminder
?Disable EHCInousb20.exe"??"
NDistiller Assistant 3.01DISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
Xdjtopr1150.exedjtopr1150.exe"WebRebates adware"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NDLF_00000B00Vcdlf.exe"Known to cause problems with "Out of memory" errors (see here). Otherwise it's purpose is unknown"
Xdnamd140113.a.Stub.EXE"Added by the STUB_A TROJAN!"
XDNSmc-58-12-0000080.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000120.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-58-12-0000140.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended see here"
NDownload Accelerator Plus 5.0DAP.exe"Download Accelerator Plus from Speedbit. Download manager for resuming downloads amongst other features. Available via Start -> Programs. Note that the free version is adware based"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended see here"
Ndumprep 0 -kdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Ndumprep 0 -udumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
YDWQueuedReportingdwtrig20.exe"Related to System Event Notification Services from Microsoft. Required for Efficient Mobile Network Computing"
UE06DXLRD_7604703EDICT.EXE"Related to Microsoft Encarta dictionary functions"
NEarthLink ToolBar 5.0etoolbar.exeEarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar but you can delete these or add more buttons any time
XEbatesMoeMoneyMaker0EbatesMoeMoneyMaker0.exe"Ebates adware"
UeDonkey2000edonkey2000.exeFile sharing network - not recommended as the free version of this application should be avoided as it installs without permission New.Net Webhancer WebSearch Toolbar and WinTools
XEDxMC110Isass.exe"Added by the VB-NIA WORM!"
UeFax DllCmd 4.0J2GDllCmd.exe"DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications Inc. - which ""is powerful Internet fax software that makes it easy to create annotate sign zoom and print faxes from any computer"""
UeFax Tray Menu 4.0J2GTray.exe"System Tray access to version 4.0 of eFax Messenger from j2 Global Communications Inc. - which ""is powerful Internet fax software that makes it easy to create annotate sign zoom and print faxes from any computer"""
Xefaxs lptt01efaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xefaxs ml097eefaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xei10.exeei10.exe"Added http://www.sophos.com/security/analyses/viruses-and-spyware/w32agobotnk.html"" target=_blank>AGOBOT-NK WORM!"
Xemoc0reemo.exe"Added by the AGOBOT-AGE WORM!"
Xempine121307.exe"Delfin Media Viewer adware related"
Xempine121307.Stub.exe"Delfin Media Viewer adware related"
NEN4060C Taskbaren4060ct.exeComes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF DOC HTML TXT Multi-page TIFF JPG GIF PNG and many more!"" Can be started manually"
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF DOC HTML TXT Multi-page TIFF JPG GIF PNG and many more!"" Can be started manually"
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
UEPSON CardMonitorEPSON CardMonitor1.0.exeMonitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus C40 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C41 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C42 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C43 SeriesE_S08IC1.EXEEpson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C43 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C44 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C46 SeriesE_S4I0T1.EXEEpson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C48 SeriesE_S4I091.EXEEpson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C60 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C61 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status checking ink levels etc
UEpson Stylus C62 SeriesE-S0BIC1.EXEEpson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C62 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C63 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C64 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C66 SeriesE_S4I0S2.EXEEpson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status checking ink levels etc
UEpson Stylus C82 SeriesE_S0HIC1.EXEEpson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C82 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus C84 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXEEpson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX3200E_S10IC2.EXEEpson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXEEpson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX3800 SeriesE_FATIACA.EXEEpson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX4200 SeriesE_FATIAEA.EXEEpson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXEEpson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXEEpson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX5400E_S4I2G1.EXEEpson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX6000 SeriesE_FATIBIA.EXEEpson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXEEpson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXEEpson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXEEpson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX7000F SeriesE_FATIBKA.EXEEpson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX7400 SeriesE_FATICDA.EXEEpson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX7800 SeriesE_FATIAFA.EXEEpson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX8400 SeriesE_FATICEA.EXEEpson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXEEpson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX3800 SeriesE_FATIACE.EXEEpson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX4000 SeriesE_FATIBEE.EXEEpson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX4400 SeriesE_FATICAE.EXEEpson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX4800 SeriesE_FATIADE.EXEEpson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXEEpson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX6000 SeriesE_FATIBIE.EXEEpson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX7400 SeriesE_FATICDE.EXEEpson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX8400 SeriesE_FATICEE.EXEEpson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo 2200E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo 825E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo 925E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R1800E_FATI9LA.EXEEpson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status checking ink levels etc etc
UEPSON Stylus Photo R200 SeriesE_S4I0H2.EXEEpson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R220 SeriesE_S6I2I1.EXEEpson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R220 SeriesE_FATIAIE.EXEEpson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R240 SeriesE_FATIAHE.EXEEpson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R2400E_FATI9SA.EXEEpson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R260 SeriesE_FATIBNA.EXEEpson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R300 SeriesE_S4I2F1.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R300 SeriesE_S10IC2.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R300 SeriesE_S4I0F2.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXEEpson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R380 SeriesE_FATIBOA.EXEEpson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo R800E_FATI9YE.EXEEpson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXEEpson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXEEpson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo RX500E_S4I2K1.EXEEpson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo RX600E_S4I2M1.EXEEpson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Photo RX640 SeriesE_FATIAME.EXEEpson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Pro 4000E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status checking ink levels etc
UEPSON Stylus Pro 7600E_S10IC2.EXEEpson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status checking ink levels etc
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
Xexe lptt01exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xexe ml097eexe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
XExpl0rer softexpl0rer.pif"Added by the RBOT-AQR WORM!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
UE_S10IC2E_S10IC2.EXEEpson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status checking ink levels etc
UE_S23E_SICN03.exeEpson printer status monitor - for checking ink levels etc.
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
YF-Secure 2006fspex.exe"F-Secure Anti-Virus automatic updater"
Xf607f607.exe"Added by the URAT.B TROJAN!"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark MCI Lotus My Software Broderbund Traffic Software and many others"
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark MCI Lotus My Software Broderbund Traffic Software and many others"
NFaxTalk CallControl 6.0FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
UFG1_00frntgate.exe"FrontGate MX - e-mail spam blocker"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile0_0MD1.exe"Added by the DLOADER-OR TROJAN!"
Xfirewallfw_304.exe"Added by the BDOOR-JQ BACKDOOR!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
UFLMK08KBMMKEYBD.EXEMultimedia keyboard manager. Required if you use the additional keys
UFLMK08KBKbdAp32A.exeKeyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
UFooBar 1.0FooBar.exe"FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfqorstub_113_4_0_4_0.exe"TargetSaver adware"
Ufreesurferfs20.exe"EMS Free Surfer mk II - pop-up stopper"
XG00123[worm filename]"Added by the BUGBROS WORM!"
XG0mezG0mez.vbs"Added by the GORMLEZ-A WORM!"
Xgeneral lptt01general.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xgeneral ml097egeneral.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGeography TX 1.0 NTCompuSpeed.vbs"Added by the NEWLEY-A WORM!"
XGetModule20GetModule20.exe"Internet Speed Monitor adware related - see example here"
XGetModule30GetModule30.exe"Internet Speed Monitor adware related"
XGetPack20GetPack20.exe"Internet Speed Monitor adware related - see example here"
Xgf1.0.0.2ggf.exe"Added by the EDFON.A TROJAN!"
XGoogle Service FRGO0GLEFREE.EXE"Added by a variant of the SPYBOT WORM!"
?GSISETUP[path] GsiInst.exe INSTALL [path] V205Res 13"BT Voyager ADSL modem related - what does it do and is it required?"
XHDAudio Driver 1.0[random filename].exe"Added by the TEADOOR-D TROJAN!"
XHDAudio Driver 2.0[random filename].exe"Added by the TEADOOR-E TROJAN!"
XHot 8.0 Livehot.exehttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BANKER.EIE
UHot Key Kbd 2690 DaemonSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
?hp 1000 firmwarefwdl.exe"HP LaserJet 1000 related. Is it a driver or automatic firmware update (based upon the filename)?"
XHP DeskjetHP_DeskJet_500.exe"Added by the FORBOT-DA WORM!"
UHP Digital Imaging Monitorhpqtra08.exeSystem Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera for example
NHP Image Zone Fast Starthpqthb08.exeImproves the startup time of HP Image Zone. If you disable it HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time
?HP OfficeJet Series xxx StartupHPOSTR03.EXE"xxx represents the series number - such as 700. What does it do and it it required?"
?HP OfficeJet Series xxx StartupHPOstr05.exe"xxx represents the series number - such as 700. What does it do and it it required?"
NHP Photosmart Premier Fast Starthpqthb08.exeImproves the startup time of HP Image Zone. If you disable it HP Image Zone takes a long time to start up only the first time you run it. Subsequent startups are much faster than the first time
Uhp psc 2000 Serieshpobnz08.exeSystem Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
Nhpaiodevicehpodev07.exeDirect from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled and the icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
?HPAiODevice(hp officejet g series)hpoavn07.exe"HP Printer related reportedly lets file transfers from an HP device pass files through Windows firewall. Is it required?"
NHPAiODevice(hp psc 900 series) -1hpobrt07.exeInstalled with a Hewlett Packard 900 series colour printer scanner fax photo card slot printer copier. Assumed to perform an identical function to the hpaiodevice entry
NHPAIO_PrintFolderMgrhpoopm07.exeDirectly from HP: "This process has one purpose - detects if the device moves to a different port and notifies other processes to look on the new port." For various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled and the HP icon installed on the desktop that points to "hpodir07.exe" works just fine if you need to use the scanner
UHPDJ Taskbar Utilityhpztsb01.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb06.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb08.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb03.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPDJ Taskbar Utilityhpztsb10.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHPHmon03hphmon03.exeSupports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. Known to cause 100% CPU load in some cases. Only needed if you use this feature
UHPHmon04hphmon04.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 4.0 to 4.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
Uhphmon05hphmon05.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 5.0 to 5.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
UHPHmon06hphmon06.exe"Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 6.0 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
NHPHUPD04hphupd04.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD05hphupd05.exeHP software update checker and wizard launcher. Available via Start -> Programs
UHPHUPD06hphupd06.exeHP software update checker and wizard launcher. Available via Start → Programs
NHPHUPD07hphupd07.exeHP software update checker and wizard launcher. Available via Start -> Programs
NHPHUPD08hphupd08.exeHP software update checker and wizard launcher. Available via Start -> Programs
Nhpoddt01.exeN/A"Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software this program will be started"
Uhpoddt01.exehpotdd01.exeDetection of new imaging printing and other peripherals on HP machines such as USB printers cameras and Bluetooth products
Nhpodlb08hpodlb08.exeHP OfficeJet Scan Button Monitor on a multi-function printer/copier/scanner. Start your scanning software manually
NHPZTS04hpzts04.exeHewlett Packard printer toolbox shortcut that resides in the system tray
Uhpztsb02hpztsb02.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb04hpztsb04.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb05hpztsb05.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb07hpztsb07.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
XIcon lptt01icon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIcon ml097eicon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XICQ Messenger 2002ICQ2002.exe"Added by the SDBOT-ABL WORM!"
Xiedwa104iedwa104.exe"Added by the DLOADR-BBW TROJAN!"
XIEXPL0RERIEXPL0RER.EXE"Added by the AGOBOT-QL WORM!
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
?iHP-100iHPDetect.exe"Drive Letter Searcher iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time?"
Ximxecsvbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
XInstallProvidernewsoftware2007install.exe"WinAntiVirus Pro 2007 and Privacy Protector misleading security software - not recommended see here"
XInstance 001[path to worm]"Added by the ALASROU-A WORM!"
XInstant Accessrundll32.exe EGDHTML_1023.dll InstantAccess"InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Xintdctrridctup20.exe"SafeSurfing adware variant"
XIntel Audio Studio V2.0fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
UIomega Automatic Backup 1.0.1ibackup.exe"Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
XIPInSightLAN 0*ipclient.exe"Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly ""phones home"" and wastes resources. * represents 1 or 2"
NIPInSightMonitor 0*ipmon32.exe"Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. * represents 1 or 2"
NIPO3IP Operator 2005.exe"IP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single button"
XIPOT USB Service DRIVERhpsebc087.exe"Added by the SDBOT-WA WORM!"
XIPOT USB Service DRV32hpsebc08.exe"Added by the SDBOT-WH WORM!"
XJavaUpdate0.07[filename]"Added by the JUPDATE TROJAN!"
XJVM0JVM0.exe"Added by the BANLOA-AX TROJAN!"
XJVM0.12[random filename]"Added by the TEADOOR-A TROJAN!"
XJVM0.14[random filename]"Added by the TEADOOR-B TROJAN!"
Xjxef1104jxef1104.exe"Added by the XIPI-A WORM!"
YKAVPersonal50Kav.exe"Kaspersky Anti-Virus Personal 5.0"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
XKazaa lptt01kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
XKazaa ml097ekazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
XKerne0223Kerne0223.exe"Added by the LEGMIR-ZA TROJAN!"
Xkernel system daemonACTIVAT0R.exe"Added by the RANDEX.AW WORM!"
Xkernel44.dll"taskkill /f /fi ""PID ge 0"" /im *""Added by the VBS.LIDO WORM!"
Nkernelfaultcheckdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Nkernelfaultcheckdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
XKiamat Sudah Dekat_16_04ISASS.exe"Added by the PAHATIA.B WORM!"
UKM9801UMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
UKONICA MINOLTA magicolor 2400W STDMSTMON_S.EXEKonica Minolta Magicolor 2400W colour printer monitor
XKr0n1CKr0n1C.exe"Added by the BRONTOK-BO WORM!"
XKV2005word.EXE"Added by the IW TROJAN!"
Xkv3000lover.vbe"Added by the ZSYANG.B WORM!"
UKX509kx509_kfwk5.exe"Kerberos Secure Authentication for Windows"
XL0adersfaxneti.exe"Added by a variant of the SDBOT TROJAN!"
XlaltinL90112201.Stub.exe"Delfin Media Viewer adware related"
ULanguageMonitorOplmsb01.exeOKI Printer language support monitor
?LanzarL2007[path] setup.exe"??"
ULaplink PDASync 3.0 - LtNts4NtsAgnt.exe"Laplink PDASync for (IBM) Lotus Notes 4 - PDA synchronisation utility"
NLaunch Context 5.0Launch.exe"Context - electronic dictionary"
XLaunch Norton AntiVirus 2000jorgf.exe"Added by the RBOT-AUI WORM!"
NLDMbackweb-8876480.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products services and special offerings from Logitech
ULexmark 1200 Serieslxczbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 1200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark 2200 Serieslxbvbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 2200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark 3100 Serieslxbrbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 3100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark 4200 Serieslxbmbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 4200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark 5000 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 5200 serieslxbtbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark 5200 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark 5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 6500 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 7600 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark 9300 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X1100 Serieslxbkbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X1100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark X5100 Serieslxbabmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X5100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
ULexmark X5400 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
ULexmark X6100 Serieslxbfbmgr.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X6100 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
Xli-rcash00001vldial.exe"Added by the Vl TROJAN!"
Xli01f948rundll32.exe li01f948.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""li01f948.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
NLine Speed Meter V3.0LineSpeedMeter.exe"LineSpeedMeter - detect the download and upload speed of your internet connection"
XLiveUpdate[Windows username]05.exe"Added by the LINEAGE TROJAN!"
Nload=adw30.exeAfter Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95
Yload=01comm32.exe"Related to Elsa CommPro (Communicate Pro) access software for Microlink modems - this software contains answering machine and fax functions plus a terminal program a WWW-browser launch function Internet telephony and address management. Required if you use those"
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
NLogitech Desktop Messengerbackweb-8876480.exeInstalled with the software for Logitech products. Automatically checks for software upgrades AND new products services and special offerings from Logitech
NLogitechQuickCamRibbonquickcam10.exeInstalled with a Logitech Quickcam Messenger. Camera's software which is non-essential. When you open it it allows you to open the quick capture camera settings etc
NLS120 Superdisk??Supposed to accelerate transfer rate on LS-120 contributes to system lockups
XLTM2MSGSRV320.EXE"Added by the LITMUS.C TROJAN!"
XM1cr0s0ft S3rcuritysystemconfig.exe"Added by the RBOT.BKB WORM!"
XM1cr0s0ft Upd4t4zSupdate32.exe"Added by the RBOT-MI WORM!"
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista XP and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types including CDs DVDs hard drives floppy Zip Jaz and more!"" Interim patch for an older version? Is it no longer required?"
?Main Executable (HP)HP05T0R5.exe"HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
Xmaskridermaskrider2001.vbs"Added by the SOLOW-G WORM!"
XMi7sft sdceb0yz.exe"Added by the RBOT.CWG WORM!"
XMicr0s0ft Ms D0smsdx.exe"Added by the RBOT-AON WORM!"
XMicr0s0ft Upd4t4zsvchost32.exe"Added by the RBOT.ALF WORM!"
XMicroCQ0explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMicrofinder lptt01mcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrofinder ml097emcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMICROSFT ANTIVIRUS UPDATE SUPPORT[random 10-letter filename].EXE"Added by the RBOT-AQA WORM!"
XMicrosft Corporation Version 2001.12.4414comrel.exe"Added by a variant of the SDBOT TROJAN!"
XMicrosft Corporation Version 2002.12.2414comserv.exe"Added by a variant of the SLAPER TROJAN!"
XMicrosft Windows Adapter 5.1.3013[random filename]"Detected by Kaspersky as the SMALL.HIT TROJAN! See here"
XMicrosoft Agentsvch0st.exe"Added by the VB-DRO WORM!"
XMicrosoft AntiSpywareKT06.pif"Added by the IRCBOT.GEN WORM!"
XMicrosoft Helpsvh0st.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Internetexpl0rer.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft Keyboard Enhance 2.0.iasrecst.exe"Added by the BCKDR-QIL TROJAN!"
XMicrosoft Keyboard Enhance V2.0iasrecst.exe"Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
XMicrosoft Network Hostsvc0host.exe"Added by the SDBOT-AEN WORM!"
UMicrosoft Office OneNote 2003 Quick LaunchONENOTEM.EXEONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2003. It's required for the side note windows to work
XMicrosoft System Firewall 2006.2msmsgr.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Firewall 2006.2msnmsgr.exe"Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility"
XMicrosoft System Firewall 2006.2reg32.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft System Initmtmnr0.exe"Added by the SDBOT.BR TROJAN!"
XMicrosoft UpdateMicr0s0ft.exe"Added by the AGOBOT.AAR WORM!"
XMicrosoft Updatewuamk0032.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Updatewuamk032.exe"Added by the RBOT-AHD WORM!"
XMicrosoft Updatewuamk0p32.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Update Loaders 2005winusers.exe"Added by the RBOT-AIQ WORM!"
XMicrosoft Update Loaders 2006winusersystem32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Update Machineexpl0rer.exe"Added by the SDBOT.OK WORM!"
XMicrosoft Update Machinesystem03.exe"Added by the RBOT-NM WORM!"
XMicrosoft Updating Machinesysc0de.exe"Added by the RBOT.RB WORM!"
XMicroSoft Wind0ws Updaterwinsupdater.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Windowsmstask0.exe"Added by the SDBOT.FQ WORM!"
XMicrosoft Windows 2000Winupdsdgm.exe"Added by the GAOBOT.AO WORM!"
XMicrosoft Windows Expl0rerexpl0rer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoft Windows Visual V2.0msiutil.exe"Added by the DELF.JPH TROJAN!"
XMicrosoft Windows WKS Servicemstask0.exe"Added by the SDBOT.FV WORM!"
XMicrosoft WinUpdatemntcgf032.exe"Added by the RBOT-PF WORM!"
XMicrosoft WinUpdatesvh0st.exe"Added by the SPYBOT.DL WORM!"
Xmicrosoft xdaemon 2.0xdaemon.exe"Added by the DELF.D TROJAN!"
Xmicrosoft420microsoft420.exe"Added by the MENACE.B WORM!"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
Xml00!.exeml00!.exe"Malware detected by Panda as the BWD TROJAN!"
XMlcr0s0ftf DDEs C0ntr0iWAed.pif"Added by the RBOT-BJW WORM!"
XModulo 00FE0F01 Host Internetsyschost.exe"Added by the DELF-KW TROJAN!"
NMoneyStartUp10.0Activation.exePart of MS Money 2002. Available via Start -> Programs
Xmotoinmm15201518.Stub.exe"Delfin Promulgate adware variant"
XMozilla Firebird v0.8 Internet Browsernetstats.exe"Added by the IRCBOT.MC TROJAN!"
XMozilla FirefoxF1REF0X.EXE"Added by a variant of the SDBOT WORM!"
XMS MSN Menssenger 7.0MSMSN7.exe"Added by the RBOT-ACA WORM!"
XMS MSN Menssenger 7.0MSEXPORT.exe"Added by a variant of the SDBOT WORM!"
XMS Unix BinaryNorton2005Update.exe"Added by a variant of the RBOT WORM!"
XMS USB 2.0 Windows Supportmsusb32.exe"Added by a variant of the RBOT WORM!"
Xmscheckrundll32.exe wincheck071008.dll mymain"Detected by Trend Micro as the AGENT.ADXH TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
XMsconfig lptt01msconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
Xmsigdisk10.exe"Added by the BANBRA-KF TROJAN!"
XMSkernel32System.exe 4820"Added by the TUXDER BACKDOOR!"
XMslogon lptt01mslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMslogon ml097emslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMsn 8.0 Livemsn.exehttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BANKER.EIE
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMSN MESSENGER 9.0messengerr.exe"Added by a variant of the RBOT WORM!"
NMSPY2002ImScInst.exePart of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE Outlook and Word
XMsServermsfun80.exe"Added by the VB-CYG WORM!"
XMSService_v1.0realsched.exe"EHU adware. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
XMSService_v1.0vfp02.exe"NewWeb adware"
Xmssurfer lptt01mssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmssync20mssync20.exe"Added by the LDPINC-QC TROJAN!"
XMSVBVM60MSVBVBM60.pif"Added by the SCOLD-B WORM!"
XMSVersionclrschp038.exe"Added by the POPMON.A TROJAN! - also known as PopMonster adware"
Xmsys lptt01msys.exe"RapidBlaster variant (in a ""Msyss"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMS_update_0704_KB74073.exeMS_update_0704_KB74073.exe"Added by a variant of the UPDATEKB TROJAN!"
Xmule_st_keyflec006.exe"Added by the BAGLE.AV TROJAN!"
NMusic01 ServerMusic01 Server.exe"J River Media Jukebox"
?Mustek MDC 3000Mounter.exe"Related to software for the Mustek MDC 3000 digital camera - what does it do and is it required?"
XmyMh2iexpl0re.exe"Added by the DELF.FAI TROJAN!"
XNameIexplorer0.exe"Added by the THREADSYS TROJAN!"
Xnavman_20sysnav32.exe"Hijacker possibly a CoolWebSearch parasite variant"
XNC1565winntsrv -l -p10001 -d -e cmd.exe -L"Added by the NEWLEY-A WORM!"
?NetFxUpdate_v1.0.3705netfxupdate.exe"Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
YNettGain2000WgwMngr.exePart of Flash-Networks NettGain2000 product. NettGain 2000 is a combined hardware/software networking solution which is designed to improve performance of satellite networks by increasing data transmission speeds and maximizing the existing bandwidth for complete utilization when sending TCP/IP applications over a satellite. It is needed when connecting to the internet via satellite to provide speed faster than 60k or so
YNettGain2000 VerifierNettGain2000 Verifier.exePart of the Starband satellite client that attempts to optimize your satellite connection to increase speed
XNewsgroup lptt01newsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNewsgroup ml097enewsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XNI.UERSM_0001_N68M1602UERSM_0001_N68M1602NetInstaller.exe"ErrorSafe misleading security software - not recommended see here"
NNI.UGDC_0002_N108M1007installer_en.exe"MyContentAssistant security program not recommend - see here"
NNI.UGES_0001_N108M2006setup_en.exe"MyContentAssistant security program not recommend - see here"
XNI.UGES_0001_N122M2111mofugclq.exeAdded by an unidentified misleading security program - not recommended
XNI.UWA6P_0001_N56M1001WinAntiVirusPro2006Installer.exe"WinAntiVirus Pro 2006 misleading virus software - not recommended see here"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"WinAntiVirus Pro 2006 misleading virus software - not recommended see here"
XNI.UWA6P_0001_N73M1004WinAntiVirusPro2006FreeInstall.exe"WinAntiVirus Pro 2006 misleading virus software - not recommended see here"
XNI.UWA6P_0001_N91M1807winantiviruspro2006freeinstall[1].exe"WinAntiVirus Pro 2006 misleading virus software - not recommended see here"
XNI.UWA7P_0001_N91M0809winantiviruspro2007freeinstall[1].exe"WinAntiVirus Pro 2007 misleading virus software - not recommended see here"
XNI.UWAS5LP_0001_0811UWAS5LP_0001_0811NetInstaller.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
XNI.UWAS6_0001_N57M1312WinAntiSpyware2006FreeInstall.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended see here"
XNI.UWAS6_0001_N68M2301UWAS6_0001_N68M2301NetInstaller.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
XNI.UWFX6_0001_N68M2301UWFX6_0001_N68M2301NetInstaller.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
XNJG40NJG40.EXE"Added by the BANCOS.D TROJAN!"
UNo-IP DUCDUC20.exe"Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available"
XNod3d2 Free antivirusN0D32KRN.EXE"Added by the RBOT-ABQ WORM!"
XNorton Antivirus 2004SYMANTECAV2.EXE"Added by the SPYBOT-DY WORM! Note - this is not the real Norton AV!"
XNorton Antivirus 7.0a[path to file]"Added by the PERDA-B or RANCK-CT TROJANS!"
NNorton Ghost 10.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
NNorton Ghost 9.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
XNotepad lptt01notepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
XNotepad ml097enotepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
Xnsvcinn20050308.exe"Delfin Media Viewer adware related"
Xntechinn20050308.exe"Delfin Media Viewer adware related"
XNumerical Xterm Agent0x32.exe"Added by the RBOT-FWP WORM!"
Xnvd32 lptt01nvd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xnvd32 ml097envd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UnwssSp0.exe"SpyOutside surveillance software. Uninstall this software unless you put it there yourself"
UOEM02Mon.exeOEM02Mon.exe"Creative Live! Cam Console Auto Launcher"
?OEM07Mon.exeOEM07Mon.exe"Related to Live Camera Console Auto Launcher by Creative Technology LTD. What does it do and is it required?"
XOESETsetup60.exe"Added by the WAREZDL.28672 TROJAN!"
?officejet 6100hposol08.exeAssociated with a HP PSC2110 (and maybe others) all-in-one machine
UOneNote 2007 Screen Clipper and LauncherONENOTEM.EXEONENOTEM.EXE is a part of the note taking program that ships with Microsoft Office 2007. It's required for the side note windows to work
XOpenGL Drivers0penGLD.exe"Added by the YIMP-A WORM!"
XOPQFileregedit.exe /s ...rad03FA6.tmpUnsavoury program that resets your homepage every time you restart - uncheck in MSCONFIG and delete it via a registry edit
XP0w3rF1Ysvchost.exe"Added by the BDOOR-MM BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally fi"
UP3000x_S2PScanToPc.exeDell Laser MFP 1600N network application for scanning files to the PC
UPAC7302_MonitorMonitor.exe"Related to PixArt CMOS image sensors from PixArt Imaging Inc"
NPaperPort PTDpptd40nt.exe"PaperPort" software associated with scanners
XPCMM2007RTpcmm2007.exe"PC MightyMax 2007 rogue security software - not recommended see here"
UPD0620 STISvcP0620Pin.dllCreative Technology Ltd installation plug-in related
Upduip6000dmonPDUiP6000DMon.exe"Canon PIXMA iP6000D printer memory card utility"
UPDUiP6000DTskbrPDUiP6000DTskbr.exe"Canon PIXMA iP6000D printer memory card utility"
XPeqBL100PEQBL100.exe"Added by the ENVID.D WORM!"
NPerfectPrintpfppop70.exePrint engine used by Corel WordPerfect 7 and Presentations 7
UPetit Larousse 2001HIPL2000Popup.exePopup dictionary tool
UPFM3.0PFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device transfer photos from a PC by drag and drop and on this wireless model you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this one"
UPFM30PFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device transfer photos from a PC by drag and drop and on this wireless model you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this one"
Uphc700vphc700.exe"Related to the Philips SPC700NC web camera"
UPhilips PhotoFrame ManagerPFM30.exe"Management software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device transfer photos from a PC by drag and drop and on this wireless model you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this one"
NPhime2002aTINTSETP.EXEPart of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE Outlook and Word
NPHIME2002ASyncTINTSETP.EXEPart of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE Outlook and Word
XPHIME2004CCTFMDN.exe"Added by the DLOADR-AMV TROJAN!"
?PLFFAPHotfixQ0306270.exe"Prolific Technology Inc. USB Flash Disk driver - is it required in startup?"
Xpop06appop06ap2.exe"MediaMotor adware"
Xpop06apeltthiselt.exe"ZenoSearch adware"
XPower-Antivirus-2009Power-Antivirus-2009.exe"Power Antivirus 2009 rogue security software - not recommended see here"
XPowerProfilemfcp30.exe"Added by the RINDAS-A TROJAN!"
?PowerSetRegedit.exe /s ...PowerSet_8100_CU.REG"Appears to be Toshiba power management related"
UPP2000 InstaupdatePPInupdt.exeProtector Plus anti-virus software - instant update program for virus data updates. Not required if you regularly update virus data manually
YPP2000 Real Time ScanPPVstop.exeProtector Plus anti-virus software - real time scanner
YPP2000 Taskbar ControlPPTbc.exeProtector Plus anti-virus software - system tray access
NPP3100bflatbed.exeTwain driver for the Visioneer PaperPort 3100b scanner that allows you to scan fax copy print and easily communicate by simply dragging and dropping scans on your PaperPort Desktop
Npptd40ntpptd40nt.exe"PaperPort" software associated with scanners
NPrintkey2000printkey2000.exeScreen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when required
XProgram Access Service[10 random letters].exe"Detected by Trend Micro as the RBOT.GJJ WORM! See here"
XProtected StorageRUNDLL32.EXE MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
UPUAC v2.0.7Puac.exe"""Peter's Ultimate Alarm Clock"""
UPurgativePURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crack
NQ152404wsript.exe Q152404.VBSAppears to run Scandisk at bootup on NEC PCs
XQdrModule10QdrModule10.exe"Internet Speed Monitor adware"
XQdrPack10QdrPack10.exe"Internet Speed Monitor H adware"
NQSort2000QSORT.EXEUtility that sorts your Start menu and Favourites in alphanumerical order. Not required - at any time you can right-click on these lists and choose "Sort by Name"
NQuickFinder SchedulerQFSCHD100.exeUsed in Corel 2002 & Corel Suite 7 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products)
NQuickFinder SchedulerQFSCHD110.EXE"Used in Corel WordPerfect Office 11 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
NQuickFinder SchedulerQFSCHD130.EXE"Used in Corel WordPerfect Office X3 - finds files faster by indexing your files (similar to Microsoft's Find Fast or Fast Search for its Office products). See here"
XQuicktime Pro 3.0winuodps.exe"Added by the GAOBOT.BH WORM!"
UQWS3270 Sessionssessions.exeQWS3270 Secure terminal emulation software
NRaConfig2500RaConfig2500.exe"RaLink wireless LAN configuration utility"
Xravshellexpl0rer.exe"Added by the DLOADER.MAR TROJAN!"
XRavshellsvch0st.exe"Added by the NSPM.PU TROJAN! Notice the digit ""0"" in the filename rather than the lower case ""O"""
Xravtasksvch0st.exe"Added by the LINEAG-AIN TROJAN!"
Xrb32 lptt01rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xrb32 ml097erb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xreaddb40rundll32.exe readdb40.dll EnableRunDLL32"LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""readdb40.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
Xrealone_nt2003moniker.exe"Added by the SNONE.A WORM!"
Xrealplay lptt01realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
Xrealplay ml097erealplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
XRebateNation0RebateNation0.exe"RebateNation adware"
XRecommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}RH.DLL"SmartPops search hijacker"
XRecycle Bin Handler 2005system.exe"Added by the BDOOR-HO BACKDOOR!"
Ureg2.0SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
XRegcheck~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
URegistryclass0117[random].exe"Blackbox captures emails and chat logs and monitors Internet activity - remove if you didn't intentionally install it"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
YRegx10EXEatix10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
XRemove 54tr10smss.exe"Added by the BRONTOK-CH WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data"
UResChanger2004ResChanger2004.exeEVGA graphic card utility providing easy access to display settings
NRFX_auto_upgraderundll32.exe npvpg005.dll"A browser plugin called the RichFX player. Here is a link to download RichFX's solution to removing the auto upgrade"
Urmoc3260.dll OCXregsvr32.exe rmoc3260.dll"A module that contains COM components for media playback used by both RealPlayer and Windows Media Player - see here. The ""rmoc3260.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
XRoam04ActiveX.exe"Added by the ROAMER-A TROJAN!"
XRun05rundll_32.exe"Added by the BANCOS-DT TROJAN!"
XRundll32_7rundll32.exe MSIEFR40.DLL DllRunServer"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRundll32_8rundll32.exe inetp60.dll DllRunServer"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XRUNLOADl0ad.exe"PurityScan/Clickspring adware"
XRun[0]syscnfg.exe"Added by an unidentified VIRUS WORM or TROJAN! ""syscnfg.exe"" is found in C:windowsfonts (or C:winntfonts) directory where no *.exe files should reside"
XS0undMansvch0st.exe"Added by the LOVGATE.AB WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended see here"
XSAHBundleshop1003.exe"ShopAtHomeSelect parasite"
USay The Time 5.0SAYTIME.EXEThis program has audio cues for the system clock in male and female voices customizes the appearance of the system clock and can synchronize it to a time server regularly
YSC3300CCSC3300CC.exeSiPix digital camera Twain device driver
Xscains030109.Stub.exe"Delfin Media Viewer adware related"
NScreenHunter 4.0 FreeScreenHunter.exe"""ScreenHunter 4.0 Free is a completely free screen capture software for you to easily take screenshots"""
UScroll-In-Mouse V2.0SCROLL.EXE"Toolkit for the Lynx-3D Net scroll mouse from QTronix. Required if you use the special features"
XSDKcore Update Components2SDKC0R3.exe"Added by the RBOT-ABA WORM!"
Xsdkupdate22SDK0mCORE.exe"Added by the FORBOT-DT WORM!"
Usds20svchost.exe"InlookExpress logs keystrokes and captures screenshots. If you didn't install this yourself remove it. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\sds20"
USecond Copy 2000SecCopy.exe"Related to Second Copy? - a files/folders backup utility"
USecureItProSecureitpro470p.exe"SecureIt Pro - lock your computer when you're not there to stop malicious users from accessing your desktop"
Xseptpop06apseptseptpop06apsept.exe"MediaMotor.Popupwithcast adware"
XServer Backboneserver05.exe"Added by the RBOT-ZM WORM!"
XServiceHostsvch0st.exe"Detected by Kaspersky as the VB.HE VIRUS! See here"
XServices004[worm filename]"Added by the BUGBROS WORM!"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
Xservices32mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
Xservices32mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
XSex Terisst01b.exe"Added by the REPAD WORM!"
XShellibm0000*.exe [* = digit]"Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe ibm00002.exe ibm00005.exe and so on"
XShellibm00001.dll"Added by the TORPIG-Q TROJAN!"
?ShowIcon_Justrams_USB Product Driver v2.12r012shwicon.exe"Related to Just Rams USB product driver. Is it required?"
?ShowIcon_SmartDisk Corporation_USB Card Reader v1.14e051shwicon.exe"Card reader for memory cards from digital cameras. Is it required? "
USIA2006SIA2006.exe"Part of Steganos Internet Anonym privacy software"
USinus 1054 data WLAN ManagerWifiusb.exeWireless management utility for the T-Com Sinus 1054 Data WLAN adapter
YSiS7012UtilitySiSAudUt.exeSiS Corporation sound card driver
?SISAM10MSISAM10M.exe"??"
USK60SK60.EXE"SaveKeys keystroke logger/monitoring program - remove unless you installed it yourself!"
USK9910DMSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
Xsms_msn40sms_msn40.exeAdded by an unknown WORM or TROJAN infection
Xsounddrvsndbdrv3104.exe"CoolWebSearch parasite variant"
XSP00LSVSp00lsv.exe"Added by the GRAYBIRD.E TROJAN!"
?SPC610NC_MonitorMonitor.exe"Related to the Philips SPC610NC webcam. What does it do and is it required?"
USpeedport W 100 Stick WLAN ManagerWifiusb.exeWireless management utility for the Speedport W 100 Stick WLAN USB stick
XSpool lptt01spool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpool ml097espool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpyBlocs3.0SpyBlocs3.0.exe"SpyBlocs spyware remover - not recommended see herea>"
XSpybott lptt01spybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpybott ml097espybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareGuarddeinst_qfe001.exe"Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application"
XSpywareguard lptt01Spywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareguard ml097eSpywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XStart aThx Rollf0mered.exe"Added by the RBOT.AAV WORM!"
YStart RF Wireless Mousecm20.exeYuanxun Electronics RF wireless mouse driver
XStartwdrundll32.exe wd081025.dllHook"Detected by Kaspersky as the AGENT.DE TROJAN! See here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wd081025.dll"" file is found in %System%"
UStatus Monitor CLJ1500HPPOUMUI.exeStatus monitor for the HP Color LaserJet 1500 printer from Hewlett-Packard - for monitoring printer status checking ink levels etc
Xstrtasl074.exe"Added by the AGENT-II TROJAN!"
Xstup1db0t_win.exe"Added by a variant of the IRCBOT BACKDOOR!"
Xsuckl0ad.exe"PurityScan/Clickspring adware"
XSurfer lptt01surfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSurfer ml097esurfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSV00LSVSV00LSV.EXE"Added by the GRAYBIRD-C TROJAN!"
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XSvcH0stWINAGENT.EXE"Added by the BDOOR-EB BACKDOOR!"
XSVCH0STspoo1sv.exe"Added by the VB-HF TROJAN!"
XSVCH0STSVCH0ST.EXE"Added by the VB-IK TROJAN! Note - the filename has the digit 0 rather then the uppercase ""o"""
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XSvcH0stsdhch.exe"Added by the TACTSLAY.B TROJAN!"
XSVCH0TSsp00lvs.exe"Added by the LINEAGE-AZ TROJAN!"
XsvchostSvch0st.exe"Added by the GRAYBIRD and GRAYBIRD.B TROJANS! Note - the filename has the digit 0 rather then the uppercase ""o"""
Xsvtcinn20050308.a.Stub.EXE"Added by the N20050308 TROJAN!"
USW20sw20.exe"Related to MSI's Dynamic Overclocking Technology"
XSymantec Antivirus professionalf0dns.exe"Added by the FORBOT-GT WORM!"
NSymantec Fax Starter Edition PortOLFSNT40.EXEOffers a virtual printer as a fax machine. Can be run via a desktop shortcut
Xsys008sys008.exe"Hijacker also detected as the STARTPA-GK TROJAN!"
Xsys009sys009.exe"Added by the STARTPA-ZB TROJAN!"
Xsys201sys209.exe"Added by the STARTPA-ZY TROJAN!"
Xsyscon lptt01syscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsyscon ml097esyscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSyslog lptt01Syslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSyslog ml097eSyslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XsysPersonalFirewalltskm0nitor.exe"Added by a variant of the RBOT WORM!"
XSystemsystem.exe (74295303)"Added by the VB-IU WORM!"
XSystemWINL0G0N.EXE"Added by the BANCOS-DB TROJAN!"
XSystem Serviceexp0lrer.exe"Added by a variant of the RBOT WORM!"
XSystemDoctor 2006 Freesd2006.exe"SystemDoctor misleading security software - not recommended see here"
XSystemssvch0st.exe"Added by the MYDOOM.BI WORM!"
Xtaskmngr lptt01taskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xtaskmngr ml097etaskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NTaskPlusTASKPLUS0.EXETask and calendar management software available as freeware or as a "Professional" version for sharing over a LAN
NTelemeter 3.0telemeter3.exeInternet connection bandwidth meter from a user ISP
XThEwind0s.exeAdded by an unidentified WORM or TROJAN!
XTok-Cirrhatus-1959sarcsv711224030r.exe"Added by the BRONTOK-R WORM!"
Xtrackerx90.th.gsanti_data_exe_by_trackerx90.exe"Added by the BCKDR-QIT BACKDOOR!"
NTranscode360Transcode360Tray.exe"Designed for WinXP Media Center Edition 2005 and the Xbox 360 Transcode360 aims to broaden the support for a wide range of video media including DivX and XviD"
UTraymin900Tray900.exeRelated to the Philips SPC webcam - System Tray manager for Personal 900 series camera
YTrend Micro AntiVirus 2007tavui.exe"Trend Micro AntiVirus"
YTrueMobile 1150 Client Managercmdel.exe"Client Manager for the Dell TrueMobile 1150 Series PC Card - ""a wireless network PC Card that fits into any standard PC Card Type II slot. It has two LED indicators and an integrated antenna"""
Xtsvcinn20050308.exe"Delfin Media Viewer adware related"
XUADC_3240389055UADCcw.exe"Advanced Cleaner misleading security program - not recommended see here"
NUlead Photo Express x.0 Calendarcalcheck.exe"Ulead Calendar Checker - part of Ulead Photo Express where "x" represents the version number. Automatically replaces your calendar desktop wallpaper on a weekly/monthly/yearly basis if you've created them. Not required - change them manually"
XUpdateUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
Xupdater00t.exe"Added by the RBOT-ACO WORM!"
XUPDATEWinUpdater5.0.vbs"Added by the GORMLEZ-A WORM!"
XUpdate ver 1.0Swap.exe"Added by the SWAP-C WORM!"
Nupdatev01updatev01.exeUltra-networks.com software updater/downloader
XUpdateXpSpMS045-XP2.exe"Added by the IRCBOT.NY TROJAN!"
UUpromise0Upromise0.exe"Upromise college savings program"
YUPSentry 2000upsd.exeUsed with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
XUSB 2.0 DriverupdateXPSPC.exe"Added by the AGOBOT-RJ WORM!"
XUSB 2.0 DriverWinsys32.exe"Added by the AGOBOT-QM WORM!"
XUSB 2.0 DriverupdateXP.exe"Added by the AGOBOT-QP WORM!"
XUSB 2.0 Driverwinsystem.exe"Added by the AGOBOT-QS WORM!"
XUSB 2.0 DriverUpdateXPSP.exe"Added by the AGOBOT-QD WORM!"
NUserFaultCheckdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
Xuserinitchoo_003956f4"Added by the PEED.16896 TROJAN!"
XUSERINTERFACE REPORT3RM0USE.exe"Added by the MYTOB.HS WORM!"
NUSRobotics 802.11g Wireless Network UtilityUSRWLANG.exe"USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties"
UUVS10 PreloaduvPL.exe"Related to Ulead VideoStudio video editing and DVD authoring software"
UV0220Mon.exeV0220Mon.exe"Creative Live! Cam Console Auto Launcher"
UV0230Mon.exeV0230Mon.exe"Creative Live! Cam Console Auto Launcher"
YV0250Mon.exeV0250Mon.exePart of Creative Webcam Launcher
Uva10keyva10key.exeOnly required if you use the 10 kay bay unit with a Sony Vaio laptop
XValueS0ft[random filename]"Added by a variant of the SPYBOT WORM! See here"
XVBS_AUTO_UPDATE0548656X.vbs"Added by the GORMLEZ-A WORM!"
?VDI Manager (HP)HPO0VDX05.exe"HP (Hewlett-Packard) related. Now - what does it do?"
XVFW Encoder/Decoder SettingsRUNDLL32.exe MSSIGN30.DLL ondll_reg"Added by the LOVGATE-W WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended see here"
XVirusRL2009VirusRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended see here"
XVnrBlock20VnrBlock20.exe"Berlinads adware"
XVnrPack20VnrPack20.exe"Internet Speed Monitor adware related - see example here"
NVortexTrayau30setp.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
?VX1000vVX1000.exe"Associated with Microsoft's VX-1000 LifeCam webcams. What does it do and is it required?"
?VX3000vVX3000.exe"Associated with Microsoft's VX-3000 LifeCam webcams. What does it do and is it required?"
?VX6000vVX6000.exe"Associated with Microsoft's VX-6000 LifeCam webcams. What does it do and is it required?"
Xw02db700.dll[random filename]"ZenoSearch adware"
XW32PluginsDownloaderXMLHTTPSelfClearing7520wiper.exe"Added by the PROXYSER-M TROJAN!"
UWatch1200UBWATCH.EXEButton press monitor for the Mustek 1200 UB Scanner
Xwblogonubpr01.exe"Added by the AGENT-HFI TROJAN!"
XWebCpr0WebCpr0.exe"WebRebates adware"
XWebRebates0WebRebates0.exe"WebRebates adware"
XWebSavingsFromEbates0WebSavingsFromEbates0.exeWeb Savings From Ebates Software a shopping tool that opens pop-up windows
Nwextract_cleanup0advpack.dll DelNodeRunDLL32 [path] [filename].TMPWextract Cleanup0 is valid and legal software included or sold to help clean up temporary or cab files created by the installer software for a wide variety of software. It should disapear after a restart of the system. If not fix it
Ywfxsnt40wfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application
?WildTangent CDARUNDLL32.exe cdaEngine0400.dll cdaEngineMain"Part of the WildTangent on-line games system. What does it do and is it required?"
XWin Antivir 2008Win Antivir 2008.exe"Win Antivir 2008 rogue security software - not recommended see here"
XWin Antivirus 2008Win Antivirus 2008.exe"Win Antivirus 2008 rogue security software - not recommended see here"
XWin Prosess0r[random filename]"Added by the RBOT-BIT WORM!"
XWIN USB 2.0usbsystem.exeAdded by an unidentified WORM of TROJAN!
XWIN USB 2.0winusb.exe"Added by a variant of the RBOT WORM!"
XWin USB 2.0 USB DriverHPPrint.exe"Added by the SPYBOT.DNB WORM!"
XWin32 USB2.0 Driver386.exe"Added by the IRCBOT.D WORM!"
XWin32 USB2.0 Driverrundll16.exe"Added by the WOOTBOT.H WORM!"
XWin32 USB2.0 Driverw32usb2.exe"Added by the SPYBOT.DN WORM!"
XWin32 USB2.0 Driverservice.exe"Added by the SDBOT-QF WORM!"
Xwin32_i lptt01win32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinAntiSpyware 2005was5.exe"WinAntiSpyware 2005 spyware remover - not recommended see here"
XWinAntiSpyware 2006 Scannerwas6.exe"WinAntiSpyware 2006 rogue spyware remover - not recommended see here"
XWinAntiSpyware 2007was7.exe"WinAntiSpyware 2007 spyware remover - not recommended see here"
XWinAntispyware2008WinAntispyware2008.exe"WinAntispyware2008 rogue spyware remover - not recommended see here"
XWinAntiVirus Pro 2007WinAV.exe"WinAntiVirus Pro 2007 rogue anti-virus software - not recommended see here"
XWinAntiVirusPro2006WinAV.exe"WinAntiVirus Pro 2006 rogue virus software - not recommended see here"
XWIND0WSWIND0WS.exe"Added by the SPYBOT.DQ WORM!"
XWIND0WSmella.bat"Added by the ALLEM WORM!"
XWind0wswordpad.exe"Added by the AGOBOT-TL WORM! Note - this is not the legitimate Windows application wordpad.exe (which is found in the Program FilesAccessories folder) which should not normally be seen in Msconfig or as a Startup item. This file is loacted in the System (9x/Me) or System32 (NT/2K/XP) folder"
XWind0ws Ser7ice Agentcolwindos.exe"Added by the RBOT-GQO TROJAN!"
XWind0ws Sharingssprotecter.exe"Added by the RBOT-AHW WORM!"
XWinDLL (start0s.exe)rundll32.exe start0s.exestart"Added by a variant of the IRCBOT BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""start0s.exe"" file is found in %System%"
XWindows 2004csrss.exe"Added by the BANKER-DY TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Windows 2004\Tools"
XWindows Internet Protocoldeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Media Player50cent.exe"Added by a variant of the RBOT WORM!"
XWindows modez Verifierw1nz0zz0.exe"Added by a variant of the SDBOT WORM!"
XWindows modez Verifierwinl0g0z.exe"Added by the RBOT-FNB WORM!"
XWindows NT Update ManagerWINL0G0N.exe"Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
XWindows Serv PatchMcaffe2005.exe"Added by a variant of the RBOT WORM!"
XWindows Service Agentco0l.exe"Added by the RBOT-GQY WORM!"
XWindows Services Aganters[10 random letters].exe"Detected by Trend Micro as the RBOT.CUN WORM! See here for an example"
XWindows Services Layerwinl0g0.exe"Added by the RBOT-FZQ WORM!"
XWindows Services Updatesvch0st.exe"Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
?Windows shellwin70.exe"??"
XWindows Start Server 2000traficy.exe"Added by the RBOT-AHM WORM!"
XWindows svchosthappy2008.exe"Detected by Kaspersky as the IRCBOT.AYA BACKDOOR! See here"
XWINDOWS SYSTEMexpI0rer.exe"Added by the MYTOB-FI WORM! Note the upper case ""i"" and number ""0"" in the filename"
XWindows UpdateMSDEVS30.exeAdded by the SPYBOT.AHC WORM!
XWindows update 2005[random filename]"Added by the RBOT.ARP WORM!"
XWindows Update Checkerdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update Checkerdeinst_qfe002.exeAdded by a variant of the Win32.Small TROJAN!
XWindows Update ManagerWinlog0n.exe"Added by the AGENT-BO TROJAN!"
XWindows Update ServiceSP00ISS.exe"Added by the SDBOT-ZH WORM!"
XWindows Update Service 2004/2005systemupdate.exe"Added by the RBOT-JE WORM!"
XWindows USB 2.0 Driverusbtskmgr.exe"Added by the RBOT-BKG WORM!"
XWindows USB 2.0 Driverusb2ctrl.exe"Added by the RBOT-BIW WORM!"
XWindowsFZA5281300.so"Variant of the SmitFraud alias FAKEALE-C TROJAN!"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindowz Update V2.0updater.exe"Added by the YODO-C WORM!"
YWinFaxAppPortStarterwfxsnt40.exeWinFax 10.0 and maybe earlier versions. Used to initiate the WinFax port to enable printing to the WinFax printer (send a fax) from any application.
XWinFixer 2005wfx5.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
XWinFixer2006uwfx6.exe"WinFixer web installer. Winfixer is ""Foistware"" pretending to be system optimization protection and recovery software - stealth installed see here"
Xwingerver2.0.exewingerver2.0.exe"Added by the GRAYBRD-AE TROJAN!"
XWINLOG0NWINLOG0N.EXE"Added by the MYDOOM.BI WORM!"
Xwinreg_32Vc030405.exe"Added by the BANCOS-CT TROJAN!"
Xwinsocksvch0st.exe"Added by the SAGE-A WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
XWinsock32driverZoneAlarmPr0.exe"Added by the HACKARMY-B TROJAN!"
XWinSrvkn0x.exe"Added by the HOBBIT.F WORM!"
XWinStart001WinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words with this installed typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge"
XWinStart001.EXEWinStart001.exe"From IGetNet - turns the IE address bar into a keyword engine piped into IGetNet. In other words with this installed typing "car" in the IE address bar will point the browser to the Lexus web site. Foistware - installs components without your knowledge"
Xwinsyslog lptt01winsyslog.exe"RapidBlaster variant (in a ""Winsyslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinwan lptt01winwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwinwan ml097ewinwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xwin_supp00.exeWin Const.exe"Added by the ASSASIN-H TROJAN!"
UWorkPace 3.0workpace.exe"WorkPace - stress injury prevention software"
XWorkstation Ver 5.0vmware.exe"Added by the RBOT-AHB WORM!"
XWUpdate1037v.exe"Added by the CLAGGER-AR TROJAN!"
UX10 Device Network Servicex10nets.exeBelongs to X10 video streaming device(s)
XX10WeaxWTHRTRAY.EXE"WeatherCheck - ""bring the latest local weather to your desktop"". Not recommended as it reportedly pops ads and contains no uninstaller"
YXircWinModem4ltcm000c.exe"WinModem drivers. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information"
XXMLmedia 10.0wmsdkns.exe"Added by the FAKEALERT TROJAN!"
XXordatewuauclt10.exe"Added by the RBOT-GKN WORM!"
Xxp32winxpupdater02.exe"Added by the MOSUCK-A TROJAN!"
Xxupiterstartup2003xupiterstartup2003.exe"Xupiter - adware and homepage hijacker. Use Spybot S&D Adware or similar to detect and remove and to prevent it re-installing in the future see here"
Xxzkadsfk10afslkfasl10.exe"Added by the ONLINEG-R TROJAN!"
Xy1959sarsv711224030r.exe"Added by the BRONTOK-AK WORM and variants!"
XYahoo2000Anti.exe"Added by the RBOT.ATK WORM!"
XYahoo2000Anti.exe"Added by an unknown Malware possibly a variant of the RBOT-RAM WORM!"
Xyahoo_toolbar lptt01yahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xyahoo_toolbar ml097eyahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UZeroAds0"ZeroAds - culls ads cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually"
UZeroAdsLAS0Ads.exe"ZeroAds - culls ads cookies and pop-ups. Required for the cookie interception to work"
XZonavirus0"Added by the KITRO.D (or ARGEN.A) WORM!"
Xzsmsccrundll32.exe zsmscc071001.dll mymain"Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[32 random numbers]av2009.exe"Antivirus 2009 rogue security software - not recommended see here"
X[random name]iexpl0ra.exe"Added by the ULPM.BD TROJAN!"
X[various names]10010.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]321102.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]br0ken.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]defect08.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]Dest068.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]prgsys0984.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]80d0.exe"MediaMotor adware"
U{0228e555-4f9c-4e35-a3ec-b109a192b4c2}gnotify.exe"Google Gmail Notifier. Alerts you when you have new Gmail messages"
X{05CD0D77-4947-4a56-94FA-0DF0DC644D7B}sysqyzwud.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
U{1290A33C-85F5-4164-A1BE-7DD299D4986A}PBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"
X{12EE7A5E-0674-42f9-A76B-000000004D00}rundll32.exe stlb2.dll DllRunMain"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
X{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}sysqkmwfedz.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysavxjgdu.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysawpbkvnq.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysxhtcwbse.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{2CF0B992-5EEB-4143-99C0-5297EF71F444}rundll32.exe stlbdist.dll DllRunMain"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""stlbdist.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X{2CF0B992-5EEB-4143-99C2-5297EF71F44B}rundll32.exe stlbupdt.DLL DllRunMain"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""stlbupdt.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{7DD4A7AC-A3F1-4495-884A-7947C5B89108}sysahbecjh.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}syszweuas.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}sysatjsicj.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sxnwhbvrzc.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sysqrnxstju.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{B081DB1F-4EE6-4021-9DD4-8B300F0D636D}syssngbeh.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista XP and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types including CDs DVDs hard drives floppy Zip Jaz and more!"""
X{B3B48B54-C0EC-4705-8EE8-1981AEF656A7}sysjcyrq.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{BAAA759D-56F0-428c-B8DA-827EA3B08C2C}sysawechod.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}sysfbdgv.exe"Detected by Trend Micro as the CLICKERAGS TROJAN! See here"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysutrnez.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysabmpmfr.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysnxcphmgy.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{E4785213-3EFE-4c26-A9B4-332440E31F6F}sysrxmfdksp.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sxpjbwvahn.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sysyeabdgfp.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list