Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xpathex.exe"Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.dll"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.exe"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xajsha5.exe"Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field"
Note - not be mistaken for the MSN Messenger file of the same name!"
Note the filename has a ""0"" rather than an upper case ""o"""
Y!1_pgaccountpgaccount.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system and this is essential for PG to work properly"
Y!1_ProcessGuard_Startupprocguard.exe"DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background as well as a variety of other attacks"
U!AVG Anti-Spywareavgas.exe"Part of AVG Anti-Spyware from Grisoft"
N!NoLoadwinrecon.exe"WinRecon keystroke logger/monitoring program - remove unless you installed it yourself!"
U"aimb.exe"" -h"aimb.exe"IMSufSentinel is a spy program which can record IM conversations log keystrokes record URLs visited and take screenshots. If you didn't install this yourself remove it"
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sos$sys$.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up software
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up software
N%FP%AIRTEL fts.exefts.exe"Bharti Airtel Broadband - Indian ISP software front-end"
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-end
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up software
X(*)API MachinewinSOCKS.exe"Homepage hijacker see here (* = any digit)"
X(*)Runwin32API.exe"Homepage hijacker see here (* = any digit)"
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)NOTEPAD.exe"Added by the RUSTY WORM! Note - not to be confused with the valid Windows ""NOTEPAD"" text editor! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)[random filename].exe"Added by the BLACKMAL WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)twunk_32.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winhelp.exe"Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winbas12.exe"Adware CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Systrsy.exe"Added by the CDTRAY TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)llsass.exe"Added by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)syspol.exe"Added by the DREMN-B TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winlog.exe"Unidentified adware. Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(default)rundll32.exe [path to DLL file]Do98Work"Added by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)winligom.exe"Added by the RBOT-GAI WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)5640.exe"Added by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKCU\Run HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)fada.exe"Detected by Trend Micro as the VB.HEI TROJAN! See here. Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Mcafee.exe"Detected by Kaspersky as the AGENT.AY TROJAN! See here. Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the ""(Default)"" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)QQUpdate.exe"Added by the QUADRULE.A WORM! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X*Bandookmsdll.exe"Added by an unidentified TROJAN - see here"
X*JanisRuckenbrodIIjanis.com"Added by the POPS WORM!"
X*Microsoft Updatectxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatecxma.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewstcl.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewucxt.exe"Added by the STMU TROJAN!"
X*Microsoft Updatewuytc.exe"Added by the STMU TROJAN!"
X*MS Setup[random filename]"Virtumondo adware also known as the VUNDO TROJAN!"
X*MSConfig32aecache.exe"Detected by F-Secure as the OBFUSCATED.GP TROJAN!"
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!
N*WerKernelReportingWerFault.exe"Part of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see here"
X*windows updatewrauclt.exe"Added by the RBOT-QU WORM!"
X*windows updatewuanclt.exe"Added by the RBOT-PG WORM!"
X*windows updatewuaucrlt.exe"Added by the SPYBOT.HUR WORM!"
X*windows updatewuraclt.exe"Added by the RBOT-PO WORM!"
X*windows updatewurauclt.exe"Added by the RBOT-SY WORM!"
X*windows updatewsctl.exe"Added by the SPYBOT.PR WORM!"
X*windows updatewkmst.exe"Added by the SDBOT.AVD WORM!"
X*windows updatewscxt.exe"Added by the RBOT.AOS WORM!"
X*windows updatewaurclt.exe"Added by a variant of the RBOT WORM!"
X*Windows [filename] Checker[filename]"Added by the KEDEBE-B WORM!"
X*WindowsAudiosystemupd.exe"Added by the AGENT-TH WORM!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
X*winstatswinstats.exe"Added by the GARGAFX TROJAN!"
X*wuauclt.exew****.exe [* = random char]"Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe wtmsv.exe wxmst.exe wmsvc.exe and so on..."
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X..ABC2007.exe"Added by the DLOADR-ASH TROJAN!"
X.mscdrlassa.exe"Added by the WEBUS.C TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.protectedN/A"Smitfraud variant"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
X.WMAudiocsrss.exe"Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.WMAudiolsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
N/l:engN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file but it's easily available using the search function
?00DSKSVR00desksaver.exe"Related to Advanced Desktop Shield"
?00DSKSVR01desksaver.exe"Related to Advanced Desktop Shield"
Y00PCTFWFirewallGUI.exe"PC Tools Firewall Plus - ""powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network"""
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X0mcamcap0mcamcap.exe"Added by the COSIAM-H TROJAN!"
X0utlook Express*****.exe [* = random char]"Added by the RBOT-CC WORM! Note the first letter is actually the digit ""0"" and not a capital ""o"""
X1lsass.scr"Added by the BANCOS.V TROJAN!"
N1&1 EasyLoginEasyLogin.exe"1&1 EasyLogin - quick access to webhost 1&1's Control Panel Web-Mail and other applications via the System Tray"
X1-sukarnosukarno.exe"Added by the BRONTOK-CR WORM!"
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
X1111swapmgr.exe1111swapmgr.exe"Added by the BDOOR-IC BACKDOOR!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X123MonitorSpywareFreeMonitor.exe"1-2-3 Spyware Free rogue spyware remover - not recommended see here"
U12Ghosts Backup12backup.exe"12Ghosts Backup - ""Automatic Backups HyperBackup for Multiple Versions Registry Backup"""
U12Ghosts JustAWindow12window.exe"12Ghosts JustAWindow - ""Cover annoying ads animated gifs things you don't want to see"""
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons restore after a crash"""
U12Ghosts Wash12wash.exe"12Ghosts Wash - ""Protect your privacy clear browser history delete and overwrite cache files"""
?17779Proj2002N/A"??"
X180adsolution180adsolution.exe"NCase adware"
X180ax180ax.exe"NCase adware"
X180ClientStubInstallstubinstaller****.exe [* = digit]"180Solutions adware related"
X180ClientStubInstall[path to trojan]"180Solutions adware related"
X180ClientStubInstall******.tmp [* = random digit/char]"180Solutions adware related"
N1A:MacVisionTrayMonitorTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
Y1A:Stardock MCPmcpserver.exeMaster Control Program for Stardock apps in development. People should leave it running if they're using any of the Stardock applications
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
?1CmailSNETMAIL.EXE"??"
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
X1WinCfg32WebMailSpy.exe"WebMailSpy spyware"
X2-suhartosuharto.exe"Added by the BRONTOK-CR WORM!"
X2020Downloadermssvr.exe"2020Search Toolbar"
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
U24Online ClientCyberoamClient.exe"Related to Cyberroam from Elitecore Technologies Ltd"
X2Searchmain.exe"2Search adware"
X2thousandbuck[path to file]"Added by the RANKY.L TROJAN!"
U2wSysTray2portalmon.exe"2Wire Homeportal user interface"
X3-habibiehabibie.exe"Added by the BRONTOK-CR WORM!"
Y36X Raid ConfigurerJMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
X388529725448AutomaticUpdates.exe"Added by the SDBOT-DEN WORM!"
Y3capplnk3capplnk.exeUS Robotics Modem driver
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US Robotics
U3Deep Control Panel3DeepCTL.EXE"3Deep® from E-Color corrects lighting shading and color for all your 2D and 3D games. Now superseded by 3DxWizzard™"
X3Dfx AccGFXACC.EXE"Added by the GIBE WORM!"
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
?3Dlabs Taskbar Display Manager3DLman.exe"3DLabs graphics driver related. System Tray access to display settings?"
U3DLabsHelperDemon3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore) so it should take zero CPU time and virtually zero memory since it will all be paged out to the hard drive." In most cases it can be safely disabled
Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
X4da92ad5.exe4da92ad5.exe"Added by the DLOADR-WZ TROJAN!"
X4wd!!!Natal!.pif"Added by the OPASERV.AI WORM!"
X5-1-61-96members-area.exeAdult content dialler
X5-megawatimegawati.exe"Added by the BRONTOK-CR WORM!"
X5p4m[path to trojan]"Added by the LITEBOT-C TROJAN!"
X666Ska.exe"Added by the PIPES TROJAN!"
X678lsas32.exe"Added by the SLSORVE-B TROJAN!"
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN Utility
U802.11g Wireless AdatperMonitor.exe"Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to ""Wireless Connection Status"" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Detected by McAfee as the FAKEALERT-AH TROJAN! See here"
Y9xadiras9xadiras.exe"Allied Telesyn AT series router/modem related - apparently required"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
X;Rundll[filename]"Added by the PWSLEGMIR.E TROJAN!"
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
N@Hoc ToolbarAtHoc.exe"One-click activated browsing toolbar used by various web-sites. See here for more info"
N@lohareminder.exe"Registration reminder for @loha@home E-mail utility"
Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
Xajesse.exe"Added by the MELO-A WORM!"
XA New Windows Updaterw32NTupdt.exe"Added by the MYTOB.BM WORM!"
NA NoteA Note.exe"""A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"""
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ua-squareda2guard.exe"a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature"
Ya-squared Anti-Dialera2adguard.exe"a-sqaured Anti-Dialer"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion WinPoET is attractive to equipment providers modem suppliers RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking"
UA1000 Settings Utilitycpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan print copy and fax. Only required if you use these features
UA4ProxyA4Proxy.exe"Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites"
XA5118r_default32142.pif"Added by the BRONTOK-AK WORM and variants!"
XA5118rj6321422.exe"Added by the BRONTOK-AK WORM and variants!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EBrundll32.exe E6F1873B.DLL D9EBC318C"BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
Ua?a2guard.exe"a-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection feature"
Xaa bbcc dde effgghh jjupdate.exe"Added by a variant of the IRCBOT BACKDOOR!"
?AAACLEANAAACLEAN.INF"??"
?AAAKeyboard??"??"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide show restore icons that are lost in an Explorer crash remove dead tray icons minimize any window to the System Tray"
UAAKaak.exe"Advanced Anti-Keylogger - ""Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"""
UaaLDISCN32LDISCN32.EXE"LANDesk® Management Suite software component"
UaaLDTaskCompletionamclient.EXE"LANDesk® Management Suite software component"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!
XAaouamee.exe"PurityScan/Clickspring adware"
XAappadprot.exe"AdBlaster adware"
?aauclientACNUpdater.exe"Appears to be related to software from Accenture.com"
UAAWAd-Aware.exe"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"
UAAWTrayAAWTray.exe"System Tray access to Ad-aware from Lavasoft - popular spyware/adware removal tool"
?ab EazySchedulerezsched.exe"??"
Xabassabass.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself!
Xabcdefghabcdefgh.exe"EPJ TROJAN!"
UABIT uGuruuGuru.exe"ABIT ?Guru - on motherboards incorporating the ?Guru processor this provides quick access to ""hardware monitoring overclocking BIOS flashing and audio tweakin"
NABITEQabiteq.exeMonitoring utility for ABIT Motherboards. Displays system voltages temperatures and fan speeds
XAbrada WIN32abrada.exe"Added by the DERMON-G TROJAN!"
YABRegmonABregmon.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
UAbsolute Shielddseraser.exe"Absolute Shield Evidence Eliminator - internet history eraser"
UAbsolute StartUp monitorASMon.exe"Absolute Startup - startup monitor from F-Group Software"
UAbsoluteShield Internet Erasercseraser.exe"AbsoluteShield Internet Eraser - ""protects your privacy by cleaning up all the tracks of your Internet and computer activities"""
XABsrabsr.exe"Added by the AUTOUPDER TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
Xabtump3serch.exe"Loads the executable for Lop.com - final version"
Xabtulopsearch.exe"Loads the executable for Lop.com - beta version"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Detected by Kaspersky as the VB.AXG TROJAN! See here"
UAcBtnMgr_X63AcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
UAcBtnMgr_X73AcBtnMgr_X73.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
UAcBtnMgr_X83AcBtnMgr_X83.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"""Lexmark Scan & Copy Control Program"" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan scan to E-mail copy etc"
Uaccacc.exe"Advanced Call Center - ""full-featured yet easy-to-use answering machine software for your voice modem"""
XACCDEFRAGINFO[path to worm]"Added by the DARBY-O WORM!"
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
XAccess Control Appwinsto.exe"Detected by Kaspersky as the AGENT.DGO TROJAN! See here"
NAccess Ramp Monitorarmon32.exeMonitors your progress on the internet; hang-ups connection speeds internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
XAccess WebControl[path to file]"Added by the PPDOOR-M TROJAN!"
UAccessManagerAccessMgr.exe"Part of SmartPipes SecureSite software. ""SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management access control management and key management"""
XAccessMedia P2P Loaderamp2pl.exeMy AccessMedia toolbar related stealth installed!
UAccessoriesPlusclockplus.exe"Clock Plus part of Accessories Plus allows you to select from dozens of alternatives for the Windows clock"
NAccessRamp Monitor01ARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
NAccessRampLAN01ARUpld32.exeVersion of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
UAcctMgrAcctMgr.exe"Norton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information and retrieves the data needed for email logins shopping orders banking and other online activities - all from the safety of your own PC"
NAccuWeather.com® DesktopAccuWeatherDesktop.exe"Desktop weather from AccuWeather"
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exe"Weather alerts for AccuWeather.com Desktop which ""provides you with the most accurate late-breaking weather conditions for the United States"""
Xaccwizz.exeaccwizz.exe"Added by the RULAND.A WORM!"
Xaccwizzz.exeaccwizzz.exe"Added by the RULAND.A WORM!"
Xacdllib3bcdlmem.exe"Added by the MAILBOT-BA TROJAN!"
NACDSeeACDSee8Pro.exe"ACDSee 8 photo software. Organize manage enhance and share all your valued photo memories"
?Ace bowsAce bows.exe"??"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates driver updates or full product updates and automatically download and install them according to user configuration"""
UAcer ePower ManagementAcer ePower Management.exe"Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles or to create their own customized profiles"""
NAcer ePresentation HPDePresentation.exeAllows you to connect your Acer laptop to a projector
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completed
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptop
UAcerGotoAcerGoto.exe"Acer Computer ""Goto Drive"" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files or easy importation of data from user's previous computer"
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3
XAcess2007aaccess2007a.exe"Added by the GAOBOT.PQA WORM!"
XAceu[random filename]"PurityScan/Clickspring adware"
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity Inc. Smart card-based strong authentication software - for photo IDs proximity badges for facility access and as digital identification and authentication"
UAClntUsrAClntUsr.exe"Altiris AClient Service Windows Tray Icon"
NAcme.PCHButtonpchbutton.exeUsed by HP Instant Support
UACMonitor_X63ACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X63.exeACMonitor_X63.exe"Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X63.exe"""
UACMonitor_X73ACMonitor_X73.exe"Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X73.exe"""
UACMonitor_X83ACMonitor_X83.exe"Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X83.exe"""
UACMonitor_X84-X85ACMonitor_X84-X85.exe"Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the ""Lexmark Scan & Copy Control Program"" button manager whose filename is ""AcBtnMgr_X84-X85.exe"""
Xacocashfastdown.exeAdult content dialler
XacocashFASTFOWN.EXEAdult content dialler
UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
XAcontiaconti.exeAdult content dialler
Uacousticacoustic.exe"Control panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained"
Nacpartagpart11.exeProgram for finding trucks on-line
XAcrobatacrmon32.exe"Added by the SMALL-ECT TROJAN!"
UAcrobat Assistant *.*ACROTRAY.EXE"Essential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the ""U"" recommendation. *.* represents the version"
XAcrobat Readacroup32.exe"Added by the VANBOT-BQ TROJAN!"
NAcrobat Speed Launchacrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
UACROMOUSEACROMAPP.exe"Related to ACROMOUSE Laser mouse control"
UAcronis Popup BlockerRunDll32.exe [path] Blocker.dll Run"Part of Acronis Privacy Expert - anti-spyware and security suite"
UAcronis Scheduler Helperschedhlp.exe"Part of Acronis True Image backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
UAcronis True ImageTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronis True Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis TrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
NAcronis*True*Image MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAcronisTimounterMonitorTimounterMonitor.exe"Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive"
NAcronisTrueImage MonitorTrueImageMonitor.exe"Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage"
UAct! PreloaderAct8.exe"Sage Software's ACT! ""enables individuals and small business customers to instantly access key contact and customer information manage and prioritize activities and track all contact-related communications so you can grow productive business relationships"""
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
?ActionAgentactionagent.exe"""A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client"". Is it required?"
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock Caps Lock Scroll Lock keys
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email serves as a SPAM filter and can also protect you from harmful items that can be sent via email"
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans spyware adware trackware dialers keyloggers and even some special kinds of viruses"""
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exeActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs create your own shortcut
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldMCVSSHLD.EXEMcAfee VirusScan On-line. See also the McAgentExe entry
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended see here and here"
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems Inc. Like macro programs ActiveWords sits in the background and watches as you type. When it recognizes that you?ve typed an ActiveWord it takes the associated action such as replacing your keystrokes with the text you?ve defined"
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
UActMakerActMak25.exe"""ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding nor are you required to know a lot about the computer"""
UActMakerActMaker25.exe"ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload"
UACTrayACTray.exe"System Tray icon for ThinkVantage Access Connections - ""allowing users to seamlessly switch between wired and wireless environments managing security settings printers home page and other location-specific settings automatically"""
UActual Window ManagerActualWindowManagerCenter.exe"Actual Window Manager from Actual Tools - ""an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive convenient and enjoyable"""
UActual Window MinimizerActualWindowMinimizerCenter.exe"Actual Window Minimizer - ""allows minimizing any window to task tray notification area or to the edge of the screen"""
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
UACUACU.exe"Atheros wireless Client Utility"
UACU_QSBACU.exe"Atheros wireless Client Utility"
UACWLIconACWLIcon.exeRelated to IBM ThinkVantage Connectivity Solution
UAd Arrestadarrest.exe"Ad Arrest IE popup killer from GameFools"
UAd Blockerblocker.exe"Ad Blocker - blocks popups and also removes banners image ads and flash ads"
UAd Blocker ProAd Blocker Pro.exeAd Away popup and banner remover
UAd MuncherAdMunch.exe"Ad Muncher removes adverts pop-ups and general annoyances in your browser file-sharing and messenger programs. Causes conflicts with Outlook game sites and web-building applications"
?Ad Online Guideadonlineguide.exe"??"
UAd-AwareAd-Aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAd-AwareAd-Aware.exe"Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
XAd-Eliminatorad-eliminator.exe"Ad-Eliminator spyware remover - not recommended see here"
UAd-MuncherADMUNCH.EXE"Ad Muncher removes adverts pop-ups and general annoyances in your browser file-sharing and messenger programs. Causes conflicts with Outlook game sites and web-building applications"
UAd-Protectad-protect.exe"Ad-Protect spyware and spam monitoring tool"
UAd-watchAd-watch.exe"Part of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system"
UAD2KClientAD2KClient.exe"Executable for Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
NAdaptec DirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
NAdaptecDirectCDDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
XAdAwarewini.exe"Added by the RBOT-XN WORM!"
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
UAdBinAdBin.exe"AdBin - ""Free and easy solution to managing your Window's hosts file. A fun way to block ads"""
XAdd**.exe [* = random char]Add**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XAdd**32.exe [* = random char]Add**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XAddClassAddClass.exe"CoolWebSearch Addclass parasite variant"
XAddClass[Installation_Path]"Added by the STARTPAGE.F hijacker"
XAddClass[path to trojan]"Added by the SECDL-A TROJAN!"
UAdDeleteAdDelete.exeBanner advertisment blocker
XAdDestroyerAdDestroyer.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here"
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
?addproxyaddproxy.exeRelated to Adobe Photoshop
?ADGADG.exe" SoundBlaster Audigy related?"
NADGJdetADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
XaDiradirss.exe"Added by the SPAMSRV-E TROJAN!"
YAdirasAdiras.exeADSL USB modem related
Xadirkaadirka.exe"Added by the TIBS-QT TROJAN!"
UAdKillerAD Defender.exe"Part of Advanced Spyware Remover anti-spyware tool"
Xadlhidppsncc32.exe"Detected by Kaspersky as the SLAPER.AI TROJAN! See here"
XADM Library Loaderadmlib32.exe"Added by a variant of the SDBOT TROJAN!"
XAdmanager ControllerAdManCtl.exeAdware probably a Windupdates variant
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdministratorwinlogon.exe"Added by the RUBBLE-C WORM! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
XAdministrator di DagoDago.exe"Added by the PUNYA-B WORM!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
Uadmtray.exeadmtray.exe"Related to Acer Inc. destop tray"
XAdobeAdobe.exeAdded by an unidentified VIRUS WORM or TROJAN!
XAdobesysconfig.exeAdded by an unidentified WORM or TROJAN!
Xadobegam.exeAdded by an unidentified WORM or TROJAN!
XAdobesysbat32.exe"Added by the LOWZONES.T TROJAN!"
XAdobezteam.exeAdded by an unidentified TROJAN!
NAdobe AcrobatREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader application. Your choice but not required for Adobe Reader to function properly"
XAdobe Acrobat Distiller Applicationacrotray.exe"Added by the RANDEX.DFJ WORM!"
XAdobe Acrobat Reader CFG[random filename]"Added by a variant of the RBOT WORM!"
NAdobe Acrobat Speed Launcheracrobat_sl.exe"Speeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwards"
XAdobe Filter Platformafilterplatform.exe"Added by the RBOT-OP WORM!"
UAdobe Gamma LoaderAdobe Gamma Loader.exeAdjusts monitor colours across all programs including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it. In my case I can verify this as Photoshop loads fine
NAdobe Photo Downloaderapdproxy.exe"Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here)"
NAdobe Reader Speed LaunchREADER~1.EXE"Speeds up the time it takes to load the Adobe Reader application. Your choice but not required for Adobe Reader to function properly"
NAdobe Reader Speed LaunchReader_sl.exe"Speeds up the time it takes to load the Adobe Reader application. Your choice but not required for Adobe Reader to function properly"
NAdobe Reader Speed LauncherReader_sl.exe"Speeds up the time it takes to load the Adobe Reader application. Your choice but not required for Adobe Reader to function properly"
UAdobe Reader SynchronizerAdobeCollabSync.exe"Adobe Synchronizer - installed along with Adobe Reader 8.x. ""Synchronizer is a small application that runs in the background providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it."" See the link for more information"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast track versions across applications link files together and share them in creative collaboration without fear of overwriting someone else's work"""
XAdobeAadobes.exe"Added by the FLOOD.BA TROJAN!"
XAdobeFontsfonts.htaBrowser hijacker - redirecting to Hugesearch.net
XAdobeManagerrundtl.exe"Detected by Trend Micro as the INJECT.IB TROJAN! See here"
Xadobemgradobemgr.exe"Added by the ADCLICKER TROJAN!"
XAdobeReadermsni.exe"Added by the RBOT.DAO TROJAN!"
XAdobeReaderPromsnxpsp.exe"Added by the RBOT-ASK or RBOT-AUS WORMS!"
XAdobeReaderProntkernell32.exe"Added by the RBOT-ATY WORM!"
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
XAdobeReaderProupdt.exe"Added by the IRCBOT-VQ WORM!"
XAdobeReaderProfessionalmsx64.exe"Added by the RBOT-GAT WORM!"
XAdobeReaderProssysmsn.exe"Added by the RBOT-BGH WORM!"
NAdobeUpdaterAdobeUpdater.exeAutomatic updater for Adobe software - run manually
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe? Creative Suite Version Cue? helps you find files fast track multiple versions of your files and share your files for creative collaboration"""
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
Xadodemasteradodemaster.exe"Downloader of Korean origin detected as ADOD.28672"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
Xadpadp.exeSpyware installed by Net2Phone Limewire Cydoor Grokster KaZaa etc
XAdPopupdcf5678.exe"Added by the AGENT-FZ TROJAN!"
Xadprotadprot.exe"AdBlaster adware"
NADQuickAccessAdtray.exeAfter Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRoarUpdateARUpdate.exe"AdRoar adware updater"
XAdRotator.Application[path to csrss.exe]"Added by the SMALL-AQ TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover - not recommended see here"
XAdsBlockerstopAds.exe"AdsBlocker - detected by NOD32 as DIALER.DW!"
UAdsCleanerAdsCleaner.exe"""AdsCleaner is a powerful ad blocking software designed to stop ads (block banners ad kill popup) guard your online privacy"""
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
UAdsGoneAdsgone.exe"AdsGone - pop-up stopper"
NADSL Diagnostic Toolsmapiicon.exeSystem tray access to ADSL modem diagnostic tools. Available via Start -> Programs
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
YAdslTaskBarrundll32.exe stmctrl.dll TaskBarISP software initializes DSL modem
XAdslTaskBarstaskmng.exe"Added by the RBOT-AXZ WORM!"
?ADSL_A2A2Installed"Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required?"
YADSSADSS.exe"ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied"
Xadstartupautomove.exe"Adlogix adware variant"
XAdstartupAdstartup.exe"Adlogix adware"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
UAdSubtractadsub.exe"AdSubtract blocks ads cookies pop-up windows animations music and more. Can be disabled from within AdSubtract. Available via Start -> Programs. Now superseded by
Xadtech2005adtech2005.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xadtech2006adtech2006.exe"Detected by Kaspersky as the VB.KC WORM!"
XAdtools ServiceAdTools.exe"Windupdates Adware"
?ADUadu.exe"Related to Cisco Aironet wireless products. What does it do and is it required?"
XAdultXAdultX.exeAdult content dialler and hijacker
XAdult_ChatAdult_Chat.exeAdult content dialler
XAdult_Chat1Adult_Chat1.exeAdult content dialler
XAdUpdatersysupudt.exeUnidentified adware downloader/updater
UADUserMonADUserMon.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk"
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
UAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover anti spyware tool"
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect optimize clean and repair your computer and Registry."" The PRO version adds automation anti-spyware privacy protection and performance tune-ups"
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast clean and in its best shape"""
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner misleading security software - not recommended see here"
XAdVantageAdVantage.exe"MediaAdVantage adware"
Xadvap32[path to trojan]"Detected by Trend Micro as the MUTANT.AT TROJAN! See here"
XAdvapiAdvapi.exe"Added by the NETDEVIL.12 WORM!"
NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
Xadvmon32advmon32.exe"Added by a variant of the CRYPTER.C TROJAN!"
UAdware Agentadware agent.exe"Adware Agent popup blocker"
XAdware SpyAdwareSpy.exe"Adware Spy adware remover - not recommended see here"
UAdwareAlertAdwareAlert.Exe"Adware program previously not recommended (see here). It has now been delisted so make sure you have the latest version"
XAdwareDeleteadwaredelete.exe"AdwareDelete adware remover - not recommended see here"
XAdwareKiller_schedulesschedules.exe"EAdwareKiller spyware remover - not recommended see here"
XAdwareKiller_traytray.exe"EAdwareKiller spyware remover - not recommended see here"
XAdwareProMFCAd-Ware Pro.exe"Ad-Ware Pro rogue security software - not recommended see here"
XAdwareProMFCAntiTrojan Pro.exeAntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 spyware remover - not recommended see here"
?Aeiwlsta.exeAeiwlsta.exe"IBM High Rate Wireless LAN Adapter driver. Is it required?"
NAELaunchAELaunch.exe"Audio Applications Launcher for the Philips Acoustic Edge soundcard"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
?AeXSWDUsrAeXSWDUsr.exe"Altiris Express NS Client Manager software. Is it required?"
UAEZBProcaptezbp.exeIBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation volume control and few quickstart buttons. Keyboard will work without it but you lose the special functions
UAFAFilterwindefault.exe"AFAFilter - internet filter software"
Xafskfask8fsfjasj8.exe"Added by the ONLINEG-L TROJAN!"
NAGEIA PhysX SysTrayTrayIcon.exe"System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution etc regularily use Control Panel -> Display Properties or right-click on the desktop"
NAgentAgent.exe"Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this otherwise can be disabled. Available via Start -> Programs"
XAgentalsys.exe"Added by the DREF-V VIRUS!"
Xagentppl.exe"Added by the DREF-U VIRUS!"
XAgent Browser[random filename]Added by the PPdoor.M-bdr backdoor TROJAN!
XAgent Explorer[random filename]Unidentified adware
?AgenteRemupd.exe"Part of an older version of Panda Antivirus. Is this an update reminder (guess because of the name) virus definition update reminder or something similar?"
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
UAgfaCLnkAgfaCLnk.exeFor Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive
Xagpagp32.exe"Added by the GAOBOT.SY WORM!"
YAGRSMMSGAGRSMMSG.exeIBM AMR modem driver
NAGSatelliteAGSatellite.exeProgram from AudioGalaxy that lets you download some MP3s from their server. Available via Start -> Programs
Uahfpahfp.exe"Advanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view delete or modify them either""
Uahfprogahfp.exe"Advanced Hide Folders - "is powerful file security program. It allows to hide folders or hide files. Advanced Hide Folders is very useful to keep your personal data away from others. Others will not know where your personal files exist and they will not be able to accidentally view delete or modify them either""
YAHNSDAhnSD.exe"AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis"
?AHNUEAHNUE.exe"??"
Xahostahost.exe"Added by a variant of the SDBOT WORM!"
NAHQInitahqinit.exePart of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required
XAhstiebs.exe"PurityScan/Clickspring adware"
XAHU[path to worm]"Added by the ANACON-B WORM!"
XAHUANACON.EXE"Added by the NACO.A WORM!"
Xahui32.exeahui32.exe"Added by the CERTIF-M TROJAN!"
UAi NapAiNap.exe"Part of the ""Ai Suite"" utility supplied with some Asus motherboards. ""With AI Nap users can instantly snooze your PC without terminating the tasks. System will continue operating at minimum power and noise when user is temporarily away"""
UAi Quicker HelpAsRc.exe"ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away such as the M2N DH. ""ASUS DH Remote is a convenient PC remote controller that gives users unprecedented control over their PCs from the comfort of their couches"""
XAicatuaa.exe"PurityScan/Clickspring adware"
XAidattuh.exe"PurityScan/Clickspring adware"
XAidaeetu.exe"PurityScan/Clickspring adware"
?AidemHotKeyDVMAIN.EXE"Keyboard related"
?AidemHotKeyKEYAPP.EXE"Keyboard related"
Uaiepkaiepk2.exe"Another IE Popup Killer - pop-up stopper"
NAIMaim.exeAOL Instant Messenger. If connected to the internet automatically runs up AIM. Convenience more than anything. Available via Start -> Programs
UAIMAIM+.exeAIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software
XAIM Instant Message Cookies[random filename]"Added by the RBOT-AFV WORM!"
NAIM LoggerAIMLogger.exe"AIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM"
XAim Pluginaimplugin.exe"Added by the GUAP-F WORM!"
XAIM reminderAIM reminder.exe"Added by the BUDDY.E TROJAN!"
NAim6AOLLaunch.exe"AOL Instant Messenger - start it when you want to use it"
NAim6aim6.exe"AOL Instant Messenger - start it when you want to use it"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
Xaimaol lptt01aimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xaimaol ml097eaimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NAimingClickAimingClick.exe"AimingClick from AimingTech. Web searching tool. Available via Start -> Programs"
UAIMProaimpro.exe"AIM Pro - secure instant messaging video conferencing on-line meetings and desktop and file sharing"
NAIMster??Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs
NAIMWDInstallAIMWDInstall.exe"Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
YAiptek Graphics Tablet (USB)atwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
Xaircityaircity.exe"Related to ""Prutect"" malware from e2Give"
UAirPort Base Station AgentAPAgent.exe"Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. ""Wireless solution for home school and business. As it blankets your space with a blazing-fast secure wireless network it opens up a world of possibilities for home entertainment backups printing and more"""
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
Uakeysakeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
UAKillerakiller.exe"Advertising Killer - popup stopper"
Uala.exeala.exe"Access Lock is a system-tray security utility you can use to secure your desktop when you are away from your computer"
UAlarm ManagerAlarmapp.exePalm alarm event reminder that coordinates what is on your Palm with settings on your desktop
?AlarmWatcherAlarmWatcher.exe"Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?"
NAlbum Fast StartABMTSR.EXEScanner software not required for scanner to work
?AlcFDMonitorALCFDRTM.EXE"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
?ALCFDRTM16ALCFDRTM16.com"RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup?"
XAlchemAlchem.exe"ClickAlchemy adware"
UAlcmtrAlcmtr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
UAlcoholAlcohol.exe"Alcohol 120% - CD/DVD emulation/writing/copying software"
UAlcohol AutorunAlcohol.exe"Alcohol 120% - CD/DVD emulation/writing/copying software"
UAlcoholAutomountaxcmd.exe"Alcohol 120% is a powerful Windows application that makes it easy to create backups of DVDs* and CDs. In addition the program lets you store your most used CDs as images on your computer so you can call them up at the click of a button. This part automounts images disc images"
?Alcom PCL CaptureFMW_PCAP.EXE"??"
NAlcWzrdALCWZRD.EXERealTek High Definition audio driver related - detects new devices when plugged in then pops up a dialog box. If everything works as expected you should be able to disable this one
UAlcxMonitorAlcxmntr.exe"Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
Xalerteralerter.exe"MAHA.F spyware"
XAlevirAlevir.exe"Added by the OPASERV-A WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
NAlexaalexa.exe"Related to Alexa. Note - collects and stores information about the web pages you view the data you enter in online forms and search programs and with versions 5.0 and higher the products you purchase online whilst using the toolbar. Although Alexa state's they do not attempt to analyze the data it may collect about you to determine who you are some of your information collected by the software is personally identifiable. Please read the Privacy Policy. Not Recommended"
XAlexaToolbaralt.exe"Detected by Ewido Security Suite as the DELF.EB hijacker!"
XAlfaCleanerAlfaCleaner.exe"AlphaCleaner is now a stealth install using exploits on unpatched systems. Seen alongside RazeSpyware"
UAlfaClock ClassicAlfaClock.exe"AlfaClock Free Edition from AlfaSoft Research Labs - ""enhances your taskbar clock (tray clock) with fully customizable clock display alarms time synchronization and more"""
UAlfaClock2AlfaClock2.exe"AlfaClock2 from AlfaSoft Research Labs -""enhances your tray clock functionality. Of course you can customize the look adjusting fonts colors backgrounds and more. But the main goal of this program is to extend your tray clock functionality"""
?ALFY AccelleratorAlfyAC~1.exe"??"
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
XALG32ALG32.EXE"Added by the STARTPAGE.K hijacker"
Xalgchk.exealgchk.exe"Detected by Kaspersky as the VB.ATE TROJAN!"
XALGUALGU.EXE"Added by the CWS-I TROJAN!"
XALGU.exeALGU.exe"Added by the STARTPAGE.O TROJAN!"
UALi5289ALi5289.exe"Related to Uli Integrated Drivers from Uli Electronics Inc"
NAlias SketchBook SnapshotALIASS~2.EXEScreen-capture utility for Alias Sketchbook
NAlienAutopsyTest_BS.exe"Alienware computer technical support software"
YALiSndMgrALiSndMg.exeALi AC97 Sound driver
?AliUSBfixGREENMK.exe"May be realted to a USB 2.0 PCI card - the IOgear GIC220OU?"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
Xalkasr?????.exe"Added by the BALKART TROJAN!"
UAll Aboard Statusstswin.exe"All Aboard! Internet Connection Sharing status icon"
XAll Sea screen saverTaskTray.exeFree screensaver installs lots of foistware - remove it
XAll Sea web linkFWLink.exeFree screensaver installs lots of foistware - remove it
NAllerCalcAllerCalc.exe"AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually"
XAllopassw[path to trojan]"Added by the RANKY.CU TROJAN!"
UAllSeeingEyease.exe"All-Seeing_Eye security software - ""monitors everything that takes place on your computer and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening providing the user with alternatives for possible actions"""
UallSnapallSnap.exe"""allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop"""
UAllToTrayALLTOTRAY.EXE"AlltoTray from DNTSoft - minimize any program to your System Tray"
XAlogrithm Link Queuealq.exe"Added by a variant of the SDBOT WORM!"
UAlogservAlogserv.exeFrom McAfee VirusScan for logging scanning activities. In some cases if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6 this is a critical component of McAfee and disabling it can cause a PC to lock up
UALPassALPass.exe"ALPass password manager"
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
UAlpsPointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
?ALServALServ.exe"Altec Lansing AMS speaker related. What does it do and is it required?"
XAltnetpoints manager.exe"Altnet TopSearch adware"
XAltnetPointsManagerpoints manager.exe"Altnet TopSearch adware"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
UALTOOLSAccessL.exe"ALTools family of PC utilities"
XAltPaymentsAltPayments.exe"WeirdOnTheWeb adware"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
UALUAlertALUNotify.exeNotification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis
NAluria Security CenterSecurityCenter.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU the well known adware company see here"
UAluria's Pop-Up Stoppereps.exeAluria Pop-Stopper
NAluria's Spyware EliminatorASE.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU the well known adware company see here"
UAlwaysOnTopMakerAlwaysOnTopMaker.exe"Always On Top Maker - utilty to enable an application to always be displayed ""on top"" of others on the desktop"
NAlwaysReady Power Message APPARPWRMSG.EXE"Related to HP and Compaq Desktop PCs. Read this article"
XAmazingTensAmazingTens.exePremium rate adult content dialler
UAMD PowerNow!GemBack.exe"AMD PowerNow! - ""an innovative solution available on all AMD mobile processor-based notebooks that can effectively increase notebook battery life while delivering performance on demand"""
Yamd_dc_optamd_dc_opt.exe"AMD Dual-Core Optimizer - ""can help improve some PC gaming video performance by compensating for those applications that bypass the Windows API for timing by directly using the RDTSC (Read Time Stamp Counter) instruction"""
NAmerica Online *.* Tray Iconaoltray.exePuts AOL icon in System Tray (*.* denotes version if present). Connect to AOL via the desktop shortcut or Start -> Programs
NAME_CSArundll32 amecsa.cpl RUN_DLLLoads ADSL modem Control Panel applet
UAModemLockDownModemLockDown.exe"ModemLockDown - allows you to supervise internet access by disabling the modem protects againt dialers accessing dial-up connections etc"
YAmonAMON.EXE"Monitoring part of Eset's NOD32 virus-scanner"
YAmonitoramon.exe"Tiny Personal Firewall"
UAMP WinOFFwinoff.exe"WinOFF is "" a utility designed to shut down Windows computers automatically in a fully configurable way"""
UAMSGAmsg.exe"Part of the IBM ThinkVantage Productivity Center. ""The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online"""
Xamsgupdateams.exeAdded by a variant of the MAILBOT TROJAN!
NAMSNamsn.exe"aMSN Messenger is a multiplatform MSN messenger clone"
Xamsnamsn.exe"Added by the BANKER-BNZ TROJAN!"
Xamvaamvo.exe"Added by the SILLYFDC-BR WORM!"
NAnapod Manageranamgr.exe"Anapod Explorer from Red Chair Software ""is the most advanced Windows iPod® software available offering iPod® management through full Windows Explorer integration under My Computer"""
Xanbv32nabv32.exe"Added by the TITOG.C WORM!"
Xangeleyesmsdll.exe"Detected by Kaspersky as the VB.PI TROJAN! See here"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
?AnnotateCheckAnnCheck.exe"Genius Wizard Pen Tablet driver related. Is it required?"
NAnnouncementsAnnclist.exeMS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
NAnntextAnntext.exeCaere Pagekeeper text annotation server
UAnonymityGatewayAnonymity Gateway.exe"Anonymity Gateway - privacy protection tool that conceals IP address preventing your surfing habits and your internet activity form being tracked by websites or Internet Service Providers"
UAnonymizer Total Net ShieldAnonTns.exe"Anonymizer Total Net Shield - ID protection and privacy software"
UANONYMIZER_SPYWAREKILLERSpyWareKiller.exe"Anonymizer Spyware Killer - now Anti-Spyware"
UANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Spyware Killer - now Anti-Spyware"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnskyaPYSKY.NET.exe"Added by the DLOADER-MW TROJAN!"
XAnswer ProblemdSAFsqs.exe"Added by the SDBOT-SC WORM!"
UAnswerToolAnswerTool.exe"AnswerTool - save your E-mail replies in AnswerTool then reuse them again and again"
XAntiIsass.exe"Added by the BROPIA.K WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
NAnti-Blaxx ManagerAnti-Blaxx.exe"Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives"
UAnti-keylogger checkantikey.exe"Anti-keylogger - protects against keylogger programs monitoring your keystrokes"
UAnti-Trojan-WatchATWatch.exeAnti-Trojan Watch - trojan detector
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe kaspersky.exe nrton.exe wins.exe gah32.exe 1.tmp syste.exe alg.exe socks.exe winxpsp2.exe tek9.exe sks.exe hihi.exe s.exe xps2.exe dns2.exe ikav32.exe and more..."
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
Uantidialer.co.ukDialer_Watcher.exe"Dialer_Watcher is an application that allows you to detect dialers on your computer"
Xantihostahr.exe"Added by the BANCBAN-QJ TROJAN!"
XAntiMalwareGuardamg.exe"AntiMalwareGuard rogue spyware remover - not recommended see here"
UAntiPopUpAntiPopUp.exe"AntiPopUp for IE - pop-up stopper"
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended see here"
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended see here"
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended see here"
Xantispyscan.exe"IE AntiVirus rogue security software - not recommended see here"
XAntiSpyCheckAntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended see here"
XAntiSpyCheck 2.1.0AntiSpyCheck.exe"AntiSpyCheck rogue spyware remover - not recommended see here"
XAntiSpyKit *.*AntiSpyKit *.*.exe"EAdwareKiller spyware remover where *.* represents the version number - not recommended see here"
XAntispyStormAntispyStorm.exe"AntiSpyStorm misleading security software - not recommended see here"
XAntiSpywareAntispyware.exe"AntiSpywareApp spyware remover - not recommended see here"
XAntiSpywareBotAntiSpywareBot.exe"AntiSpywareBot spyware remover - not recommended see here"
XAntiSpywareExpertase.exe"AntiSpywareExpert rogue spyware remover - not recommended see here"
XAntiSpywareMasterasm.exe"AntiSpywareMaster spyware remover - not recommended see here"
XAntiSpywareShieldAntiSpywareShield.exe"AntiSpywareShield spyware remover - not recommended see here"
XAntiVerminserAntiVerminser.exe"AntiVerminser spyware remover - not recommended see here"
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue security software - not recommended see here"
XAntiVirGear *.*AntiVirGear *.*.exe"AntiVirGear misleading security software where *.* represents the version number - not recommended see here"
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusantvrs.exe"Antivirus 2008 rogue security software - not recommended see here"
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended see "
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended see here"
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden misleading security software - not recommended see here"
XAntivirus2008yantvrs.exe"Antivirus 2008 rogue security software - not recommended see here"
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusGoldAntivirusGold.exe"AntivirusGold malware"
XAntiVirusProAntiVirusPro.exe"AntiVirusPro misleading security software - not recommended see here"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirusPro misleading security software - not recommended see here"
?AntiVirusProtectionqumk.exe"??"
XAntiVituSBase.exe"Added by the BAS.A WORM!"
Xantiwareelite***32.exe [*** = random char]"Added by the DLOADER-HW TROJAN!"
UAntiWindowsMessengerAntiMsMsg.exe"Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory"
Xanti_trojanti_troj.exe"Added by the LODEAR.D TROJAN!"
YAnVirAnVir.exe"AnVir Task Manager - protects computer against viruses and manages running processes and startup files"
YAnVir Task ManagerAnVir.exe"AnVir Task Manager - protects computer against viruses and manages running processes and startup files"
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
UAny To-Do Listanytodo.exe"Any To-Do List ""the ultimate software solution to keep yourself organized and reminded"""
?anycom bluetoothftflauncher.exe"Associated with an Anycom bluetooth wireless card. What does it do and is it required?"
UAnyDVDAnyDVD.exe"AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the ""U"" recommendation"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
UAnyTimeAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar to-do list and address book are combined in a familiar interface with hundreds of printable calendars detailed expense reports and a full range of programmable alarms"""
UAnyTime OrganizerAtDem.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar to-do list and address book are combined in a familiar interface with hundreds of printable calendars detailed expense reports and a full range of programmable alarms"""
UAnyTime OrganizerAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar to-do list and address book are combined in a familiar interface with hundreds of printable calendars detailed expense reports and a full range of programmable alarms"""
NAO TrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Yaolavp.exe"AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory"
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
UAOL Broadband Check-Upmatcli.exe"""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address city county etc and gets written to a log file"". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in ""add/remove programs"" some help menus in help and support will not be available. You decide"
NAOL Companioncompanion.exePart of the AOL Connection Suite and installs an icon on the system tray offering easy access to AOL's additional utilities and functions. This program is a non-essential process and is installed for ease of use
XAol Configuration Loaderaimsng.exe"Added by the SDBOT-XE WORM!"
?AOL Fast StartAOL.exe"AOL ISP software related. What does it do and is it required?"
XAOL Instant Messangeraim.exe"Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility"
XAOL Instant Messengaraol.exe"Added by the AGOBOT-FN WORM!"
XAOL Instant MessengerAlM.EXE"Added by unidentified malware. Note - there ia a lower case ""L"" between the A and M in the filename"
XAol Instant Messengeraolmsg.exe"Added by the KELVIR.AL WORM!"
XAOL Instant Messengeraimsgr.exe"Added by the IRCBOT.N TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
XAol Instant Messenger Fixaolfix.exe"Added by the SDBOT-ABJ WORM!"
XAOL Messenger[random filename]Added by an unidentified VIRUS WORM or TROJAN!
XAOL Messengeraolmsngr.exe"Added by the SDBOT-JF WORM!"
XAOL Messenger OptimizedAOLOpt.exe"Added by the AOLOPT TROJAN!"
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
UAOL Spyware ProtectionAOLSP Scheduler.exeAOL's spyware protection program
UAOL TopSpeedMonitoraoltsmon.exe"AOL's TopSpeed web acceleration technology supposedly helps to make web browsing faster. Most important for those users who still access AOL via dial-up"
YAolAcsDaemon1Acsd.exeAOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
YAolAcsDaemon1AOLACSD.EXEAOL Connectivity Service - starts an automatic function that restores the connection should you lose it while online. Negates having to go through the procedure of signing back on manually
?AOLCCACCAgnt.exe"AOL ISP software related file located in a ""AOL Computer Check-Up"" folder. What does it do and is it required?"
XAolConconfig.com"Added by the TAPLAK WORM!"
NAOLDialerAOLDial.exeAOL ISP software dialer - can be activated through a desktop shortcut
NAolFixAolFix.exeRun on Gateway Astra computers and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL to run correctly. Not seen much any more and should only run once
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
XAOLStartAOLStart.exe"Added by the KRAIMER.12 TROJAN!"
Xaolupdater.exeaolupdater.exe"Added by a variant of the IRCBOT TROJAN!"
XAornumaornum.exe"Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware"
NAOTrayAOTray.ExeSystem Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel
Xaoueisysrtmvs.exe"Chivio dialer"
YAPC UPS StatusDisplay.exe"APC PowerChute® Personal Edition status icon"
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Yapc_trayapc_tray.exePart of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure
XAPD123APD123.exe"PacerD Media/Pacimedia.com adware"
XApi**.exe [* = random char]Api**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XApi**32.exe [* = random char]Api**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XAPI32api32.exe"Added by the IRCBOT-B TROJAN!"
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
XAPIMonapimonx.exeAdded by the TIBSER.A downloader TROJAN!
XAPIMonwinapix.exeAdded by a variant of the TIBSER.A downloader TROJAN!
XAPIMonmsreg.exe"Added by the DROPPER.Z TROJAN!"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
UAPLAPL.exe"Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup view load and dialog load times in some areas of the application"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UApointApoint.exeTouchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work
XApp**32.exe [* = random char]App**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XApp.EXEName[path to worm].exe"Added by the BODIRU WORM!"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
Xappconnappconn.exe"Added by the CARGAO WORM!"
UAppExtenderAppExtCB.exe"Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received"
Xappis.exeappis.exe"Added by the AGENT-BC TROJAN!"
NAppleSyncNotifierAppleSyncNotifier.exe"From WinPatrol PLUS by BillP Studios - ""This file installs with iTunes and is used when syncing your iPhone iTouch iPod etc."" See here for more information"
XAppletINITINITIATE.EXE"Added by the AGOBOT.XV TROJAN!"
YApplicationmdmsetsp.exe"Aztech Labs modem driver"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM! See here"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
UApplication LauncherApplication Launcher.exeApplication launcher from the Sony Ericsson PC Suite for their mobile phones
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Browserapnsvc.exe"Added by the CHECKOUT WORM! See here"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Detected by PCTools as the IRCBOT.BJJ TROJAN! See here"
XApplication Layer Servicesavrsvc.exe"Detected by PCTools as the IRCBOT.BJM TROJAN! See here"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
UAppPlusAppPlus.exe"AppPlus - ""menu bar or tray launcher that docks to your desktop floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs Websites e-mail addresses or folders (which open in the AppPlus Menu System)"""
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam spyware dangerous or time-wasting content phishing scams hackers and intruders"""
YApwheelApwheel.exeWheel support for an Alps mouse
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
UAQ3HelperStartUpAQ3HEL~1.EXE"ScreenScenes ""Aquatica Water Worlds"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
Xaqadcup.exeaqadcup.exe"Added by the AGENT.BG WORM!"
YAqua DockAqua Dock.exe"Aqua Dock - 'free program that allows you to have an ""OS X"" style nice animated launchbar/taskbar on your screen that reacts to your mouse when you mouse over it. Users can customize the look of each item on the dock and set various animation options for when the mouse is over an item on the dock. It is very easy to configure'"
XAqujyjax[path to file]"Added by the RANCK-CQ TROJAN!"
XAqujyjaxaqujyjax.exe"Added by the SDBOT-YC WORM!"
Xara-key[random filename]"Added by the ANTINNY WORM!"
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
YArcaCheckArcaCheck.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?"
Xarcaderockstararcaderockstar32.exe"Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean but the TOS and privacy statement say that you agree to allow the program to track/report your surfing and put popup advertising on your computer"
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
UArdamax Keyloggerakl.exe"Ardakey keystroke logger/monitoring program - remove unless you installed it yourself!"
Naresares.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images audio video software documents etc"""
NaresliteAresLite.exe"""Ares is a free open source file sharing program that enables users to share any digital file including images audio video software documents etc"""
UArgentum Backupab.exe"Argentum Backup - a small backup program that lets you easily back up your documents and folders"
XAritimaaritima.exe"Added by the ARITIM WORM!"
UARMOR2NETArmor2net.exe"Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue see here - hence the ""U"" recommendation)"
Xaromisaromis.exe"Added by the NUWAR.JQ WORM!"
NAROReminderaro.exe"Advanced Registry Optimizer - ""scan identify clean and repair errors in your Windows registry with a single click"". Reminder that states that you are in trial mode"
NARPWRMSGARPWRMSG.EXE"Related to HP and Compaq Desktop PCs. Read this article"
UArteraarteraui.exe"Artera Turbo Internet Accelerator - ""surf faster boost download speed"". Only required if you find it helps improve your performance"
?AS00 Gear511Gear511.exe"Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?"
NAS00_Gear511Gear511.exeNetgear wireless LAN configuration utility
UAS00_WN511BWN511B.exe"Netgear RangeMax NEXT wireless adapter configuration utility"
?AS00_WPN511WPN511.exe"NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup?"
XASDPLUGINdsldbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINcanada.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfrance.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINfullgames.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100171be.exe"AsdPlug premium rate adult content dialer"
XASDPLUGIN100176br.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINAustria.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINbelgium_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINczech.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdbaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINdslgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINFinland.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINgeaccess.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINmexico.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINnetherlands.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINturkey.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINuk_nm.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINXadult1.exe"AsdPlug premium rate adult content dialer"
XASDPLUGINtemp532.exe"AsdPlug premium rate adult content dialer"
Xasdsaxcxz13dasxcsx13.exe"Added by the LEGMIR-ARF TROJAN!"
Xasdxxwinrpc32.exe"Added by the AGOBOT.VO WORM!"
NASE SchedulerASE Scheduler.exe"Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU the well known adware company see here and here"
YAshampoo FireWallFireWall.exe"Ashampoo FireWall Free version"
YAshampoo FireWall PROFireWall.exe"Ashampoo FireWall PRO version"
UAshampoo PopUpBlockerPopUpKiller.exe"Ashampoo popup blocker part of Magical Security (was Privacy Protector Plus)"
YashAvastashAvast.exe"Part of Avast antivirus"
YashDispashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner right-click access to other options and event notifications"
XashDsp.exeashDsp.exe"Added by a variant of the SDBOT WORM!"
XASHLTAshlt.exe"Ashlt adware"
YashMaiSvashmaisv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAsicfcicfca.exe"Added by the AGENT.AAJE WORM!"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UASKrundll32.exe [path] ASK.dll rdl"Stealth Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
XaslAslru.exe"Added by the BANCOS-CU TROJAN!"
UASMASMonitor.exe"Active Security Monitor from AOL - helps you determine how vulnerable your PC is to computer viruses spyware and other dangers and learn what steps you can take to improve your protection"
UAsmw Soft Popups Burnerpopups burner.exe"Popup blocker part of Asmw Soft PC Optimizer"
Xasnconsolemsasn.exe"Added by the RBOT.EVU TROJAN!"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
Nasp4trayasp4tray.exeSystem Tray application for Aureal Vortex based soundcards. Can be run manually via Start -> Settings -> Control Panel
YAspireTimeMachineacertmb.exeSystem recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP allowing you to restore a PC back to a working state with minimal re-entry
Xasrupdate.exeasrupdate.exe"Added by the VB.ATZ TROJAN!"
XassistseASSISTSE.EXE"CnsMin (Chinese Keywords) hijacker related"
XASTAST"Added by the VB.AH TROJAN!"
XASTAST.exe"AutoStarter parasite"
UASTARTastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
XAStartAStart"Added by the VB.AH TROJAN!"
NasTrayAstray.exe"Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer"
NAstroAstro.exeChecks for updates to Quicken on a system reboot
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe according to PREVX and InCode Solutions. Can any ASUS owners with this file confirm? File is located in %Windir%"
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
NASUS ProbeAsusProb.exeASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe according to PREVX and InCode Solutions. Can any ASUS owners with this file confirm? File is located in %Windir%"
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
UASUS TweakEnableastart.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
NASUSGamerOSDGamerOSD.exe"GamerOSD by ASUSTek - for ""real-time overclocking benchmarking and video capturing in any PC game."" Free for ASUS graphics cards 30-day trial for non-ASUS graphics cards"
NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
UasustweakenableATweak.exeASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings
NASWDPASWDP.exe"MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market"
XASWnkaswnk.exeAdult content dialler
UAT&T Self Support Toolmatcli.exe"AT&T Resolution Assistant. ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address city state etc and gets written to a log file"". Resolution Assistant is required to run with the Help and Support program. If you uncheck Resolution Assistant and and then run Help and Support it will add another Resolution Assistant in the startup menu. If you remove the Resolution Assistant in the add/remove program some help menus in help and support will not be available. You decide"
UAT-WatchATWatch.exeAnti-Trojan Watch - trojan detector
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
Uatchkatchk.exe"AMT Status Message from Intel. Users can manage this read the article. See here for more information on Intel AMT"
UAthanAthan.exe"Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
XATI AS Filtermsnse.exe"Added by the RBOT-CCY WORM! Note - modifies the HOSTS file by appending numerous lines preventing access to the virus cleaning websites"
NATI Catalyst™ System TrayCLI.exe SystemTray"System Tray access to ATI's Catalyst™ CONTROL CENTER. Note that this has ""SystemTray"" appended to CLI.exe in the ""Command"" column of MSCONFIG. Not required to run the control center - which is available via a right-click on the desktop"
NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
XATI DisplayATIDisplay.exe"Added by the BDOOR-AFH BACKDOOR!"
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
NATI GART Set-up UtilityAtigart.exeProgram that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one once installed it shouldn't be needed
UATI Launchpadlaunchpd.exeConvenient way to start all your Multimedia Center applications (DVD Video CD CD Audio File Player). You can right-click LaunchPad and uncheck Load on Startup in the menu
XATI Rage3d ProAtiRage4dPro.exe"Added by the AGOBOT-OG WORM!"
YATI Remote ControlATIRW.exe"Driver for the ATI REMOTE WONDER? RF remote control for ATI's All-In-Wonder graphic cards and other products. Required if you use it"
YATI Remote ControlATIX10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
NATI SchedulerAtisched.exeComponent that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start -> Programs -> Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see
NATI Task ApplicationAtitkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NATI Task Application (Atikey)Atitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
XATI Technology Startuptechstart.exe"Added by the RBOT-AEU WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
?Ati2cwxxAti2cwxx.exe"For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it"
XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
Xati2f104ati2f104.exe"Added by the DLOADR-BBW TROJAN!"
UAti2mdxxAti2mdxx.exeSystem Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
NATICCCCLIStart.exePuts the ATI Catalyst™ Control Center Icon/Shortcut on the System Tray - available via Start → Programs
Xaticpaxx.exeaticpaxx.exe"Added by the RBOT-XP WORM!"
UAtiCwdAtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwdAti2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32AtiCwd32.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
UAtiCwd32Ati2cwad.exeThis utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename rather than a lower case ""L"""
NAtiGartAtigart.exeProgram that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one once installed it shouldn't be needed
NAtiKeyAtiKey32.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
NAtiKeyatiptkad.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Control Panel → Display
NAtikeyAtitask.exeSystem Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start -> Settings -> Control Panel -> Display
UATIMACEMACE.exeATI Technologies Control Centre - installed alongside ATI graphics hardware and provides additional configuration options for these devices in the Managed Access to Catalyst™ Environment (MACE) component
UATIModeChangeAti2mdxx.exeSystem Tray icon to access ATI graphics card settings and the Hydravision Desktop Manager
XAtiPanelatip.exe"Added by the TACTSLAY.U TROJAN!"
Xatipatxxatipatxx.exe"Added by the SMALL-ED TROJAN!"
UATIPOLABati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resources on some computers but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
UATIPOLLati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resources on some computers but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
UAtiPTAAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
UAtiPTAAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
UAtiPTAAtiptaab.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start → Settings → Control Panel → Display. Some users may need it if they have optimised their settings
UAtiPTAAAAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
UAtiPTAAAAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
UatiptaxxAti2ptxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
UatiptaxxAtiptaxx.exeControl panel for the ATI series of video cards allowing access to such features as display resolution colour depth etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings
Xatiptextatiptext.exe"Added by the COSIAM-A TROJAN!"
UAtiQiPclAtiQiPcl.exeUsed for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's
UATISmartati2s9ag.exe"ATI's ""SMARTGART"" which is included with the Catalyst™ drivers. When the system boots it runs a couple of bus tests & tries to apply the most stable settings"
UAtiSoundcsrss.exe"WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
Xatisrc2windfind.exe"Added by the WINDFIND-A TROJAN!"
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
Uatitrayatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
UAtiTrayToolsatitray.exeATI Tray Tools - allows quick access to ATI graphics card settings
XatiupdateATIUPDATE5.EXE"Added by the DEBESKI.A TROJAN!"
Xatiupdatemsshed32.exeAdded by the DELF.EP downloader TROJAN!
XATIUpdateratiupdxx.exe"Added by the RBOT-ABX WORM!"
XAtiupdplatiupdpl.exe"Added by the SMALL.AOS TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
YATIX10atix10.exe"ATI Remote Wonder? - PC wireless remote control driver. Required if you use it"
?ATKMEDIADMEDIA.EXE"ATK Media utility for ASUS laptops - what does it do and is it required?"
XAtl**.exe [* = random char]Atl**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XAtl**32.exe [* = random char]Atl**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples see this log"
XATM Controladpn.exe"Added by the MMS.A WORM!"
NATnotesatnotes.exeLoads the ATnotes program for virtual sticky notes for your desktop. Available via Start -> Programs
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
XAtomic-x27Atomic-x27.exe"Added by the KATOMIK-A WORM!"
XAtomic-x27CAtomicpartC.exe"Added by the KATOMIK-A WORM!"
UAtomic.exeAtomic.exe"Atomic Clock Sync - synchronizes your computer's time with the NIST time server"
NAtomicaatomica.exe"Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key"
UAtomicTimeATOMICTIME.EXE"AtomicTime - utility that synchronizes your PC clock to an atomic clock"
UAtrackatrack.exeNew feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker an instant notification feature. The Alert Tracker displays information about events as they happen. This way when a rule has been triggered or an access to the Internet made you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert
UAtrayAtray.exe"Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons"
UATSpoolerAppsTraka.exe"DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself!"
UATTBroadbandUpdateSAUpdate.exe"Big Brother from Quest Software. System and network monitor"
UATTRedUpdateAutoUpdate.exeAdditional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates
XAttuneClientEngineattune_ce.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneContentUpdaterattune_cu.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttunelAttunel.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAttuneSystrayattune_st.exe"Aveo Attune automated helpdesk software - adware/spyware"
NaTuneratuner.exe"aTuner - tweak tool for GeForce based graphics cards"
Yatwtusbatwtusb.exeUSB interface for Aiptek Graphics Tablet (USB)
XAtxBrwIexplor.exe"""Pop Marketing"" adware"
UauDealioAu.exe"Dealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer products"
UAU AgentAUagent.exe"Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon"
Xau.exeau.exe"Added by the BEAGLE.B WORM!"
YAUCBPNPaucbnpn.exeAdaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot
XAucompatAucompat.exe"Added by the GEMA TROJAN!"
XAudcntraudcntr.exe"Added by the GEMA TROJAN!"
?AudCtrlRunDll32 AudCtrl.dll RCMonitor"Audio control panel?"
Xaudi32audi32.exe"Added by the RANCK-FL TROJAN!"
XAUDIOSOUND.exe"Added by the PLOYB-A TROJAN!"
XAudio Device Managerwinfp.exe"Detected by PCTools as the IRCBOT.BIV TROJAN! See here"
XAudio Device ManagerWinNT.exe"Added by the BANKER.BTG TROJAN!"
XAudio Device ManagerWNDXP.exe"Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here"
Xaudiocfg.exeaudiocfg.exeAdded by the VB.ATE WORM!
XAudiocntlaudiocntl.exe"Added by a variant of the CRYPTER.C TROJAN!"
NAudioDeckADeck.exeADeck.exe is a system tray application for VIA's sound cards which offers quick access to a number of sound card related items
XAudiodrvaudiodrv.exe"Added by the CRYPTER-C TROJAN!"
UAudioDrvEmulatorDLLML.exe AudDrvEm.dll"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system but should not be terminated unless suspected to be causing problems"
NAudioHQAhqtb.exeFor Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start -> Programs
XAudioHQaudiohq.exe"Added by the BANKER-EHK TROJAN!"
NAudioHQUAHQTBU.EXESystem Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start -> Programs
Xaudioinfaudioinf.exe"Added by a variant of the CRYPTER.C TROJAN!"
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
Xaudlmne32dcmsxe.exe"Added by the MAILBOT-CF TROJAN!"
Xauloadplxmplprogsm.exe"Added by the SLAPER.K TROJAN!"
XAUNPS2RUNDLL32 AUNPS2.DLL _Run@16"AUNPS adware"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
XAuth Starter Identstartauth.exe"Added by the RBOT-WP WORM!"
YAuthentic-ID Toolbarwintmr.exe"System Tray access to Child Control parental control software by Salfield"
YAuthentic-ID Toolbarrundll32.exe [path] ToolbarATL.dll LoadTrayIcon"Authentic-ID Toolbar - website authentication utility. Warns you when a site is recognized for phishing or isn't authentic for example"
Xauthzauthz.exeAdded by an unidentified VIRUS WORM or TROJAN!
Xautowin32.exe"Added by the SMALL!SD5 TROJAN!"
XAuto CD-ROM Startupcdaccess.exe"Added by the SPYBOT.BLA WORM!"
UAuto EPSON Stylus C45 Series on XE_S4I3T1.EXE"Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C48 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C60 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C62 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C64 Series on XE_S4I2C1.EXE"Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C82 Series on XE_S0HIC1.EXE"Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C84 Series on XE_S4I2D1.EXE"Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus C87 Series on XE_FATIABL.EXE"Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3200 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX3800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX4200 Series on XE_FATIAEA.EXE"Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status checking ink levels etc etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX5400 on XE_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6000 Series on XE_FATIBIA.EXE"Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6400 on XE_S4I2L1.EXE"Epson Status Monitor 3 for the Stylus CX6400 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX7400 Series on XE_FATICDA.EXE"Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX7800 Series on XE_FATIACA.EXE"Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus D78 Series on XE_FATIBGE.EXE"Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus D88 Series on XE_FATIABE.EXE"Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX3800 Series on XE_FATIACE.EXE"Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX4800 Series on XE_FATIADE.EXE"Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus DX6000 Series on XE_FATIBIE.EXE"Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo 820 Series on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 820 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R200 Series on XE_S4I2H1.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R200 Series on XE_S4I0H2.EXE"Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R220 Series on XE_FATIAIE.EXE"Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R260 Series on XE_FATIBNA.EXE"Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R300 Series on XE_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R300 Series on XE_S4I0F2.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX500 on XE_S4I2K1.EXE"Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Photo RX600 on XE_S4I2M1.EXE"Epson Status Monitor 3 for the Stylus Photo RX600 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
UAuto EPSON Stylus Pro 7600 on XE_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
Xauto repair systemqualityx.exe"Added by an unidentified WORM or TROJAN - probably a SPYBOT variant"
UAuto Run Software for Photo FramePhotoManager.exe"Management software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the device"
UAuto SwitchTASKBAR.exeRelated to 2-port Bitronics AutoSwitch kit from Belkin
NAuto T Barautotbar.exeIf you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled
XAuto UpdatWindowsSys32.exe"Added by a variant of the FORBOT WORM!"
XAuto updatcrcss.exe"Added by the SDBOT.AAG WORM!"
XAuto UpdateAUP.exeAdded by an unididentified WORM or TROJAN!
XAuto Updatedma.exe"Added by the RBOT-AVO WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
XAuto WinUpdatetaskmrg.exe"Added by the RBOT-AFA WORM!"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
UAutobarautobar.exeConnect buttons on the keyboard for internet direct access etc. on HP computers
UAutoCAD Startup Acceleratoracstart16.exe"Preloads some libraries that are used by AutoCAD in order to make the software load faster"
Uautoclkautoclk.exe"Autoclik is a Windows utility ""that allows you to perform all mouse activity with absolutely no clicking"""
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
NAutoEAAhqrun.exeFor Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
X