Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xsvchost.exe"Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.dll"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.exe"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
Xdllvirtual.js"Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field"
U!AVG Anti-Spywareavgas.exe"Part of AVG Anti-Spyware from Grisoft"
X"Vaganza-XPloit-[User Name]"""[user name].exe"Added by the GAVGENT.A WORM!"
X$sys$crash$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$drv$sys$drv.exe"Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer"
X$sys$momomomochin$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$WeLoveMcCOL.exe"Added by the WELOMOCH TROJAN!"
U$Volumouse$volumouse.exe"Volumouse from Nirsoft. ""Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"""
X(Default)media_driver.exe"Added by the TUPEG VIRUS! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)Shania.vbs"Added by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(Default)spolsvr2.exe"Added by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the ""(Default)"" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank"
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pif"Added by the ASSIRAL.B WORM!"
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exe"Added by the ASSIRAL.B WORM!"
X.mscdrlsvchost.exe"Added by the WEBUS.D TROJAN!"
X.mscdsrlsvchost.exe"Added by the BDOOR-CR BACKDOOR!"
X.mscsblsvhost.exe"Added by the CMQ TROJAN!"
X.msfupdatemsveup.exe"Added by the ALLOCUP.A WORM!"
X.nvsvcsmss.exe"Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
X.nvsvcbsmssb.exe"Added by the BOXED.CG TROJAN!"
X.Progservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X.svchostCSRSS.EXE"Added by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVcsrss.exe"Added by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X.TEXTCONVlsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder"
?00DSKSVR00desksaver.exe"Related to Advanced Desktop Shield"
?00DSKSVR01desksaver.exe"Related to Advanced Desktop Shield"
X1svchost.scr"Added by the BANCOS.X TROJAN!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Detected by McAfee as the FAKEALERT-AM TROJAN! See here"
U12Ghosts SaveLayout12autosl.exe"12Ghosts SaveLayout - ""Always (always!) keep the layout of your desktop icons"""
U12Ghosts TrayProtect12srvc.exe"12Ghosts TrayProtect - ""Hide tray icons restore after a crash"""
N12Voip12Voip.exe"12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
N1:hpdrv.exeHP utility for monitoring when and how many recoveries have been done
N1A:MacVisionTrayMonitorTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
Y1A:Stardock MCPmcpserver.exeMaster Control Program for Stardock apps in development. People should leave it running if they're using any of the Stardock applications
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
U1Srv32SpyAgent4.exe"SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC.""
X2020Downloadermssvr.exe"2020Search Toolbar"
X27slsorve.exe"Added by the SLSORVE-A TROJAN!"
X32-bit Thunking servicethunk32.exe"Added by the DERDERO.A WORM!"
X333svchost.exe"Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a ""Syswm1i"" directory"
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
X?ekio Startups?nksvc32.exe"Added by the AGOBOT-OV WORM where ? is a random character"
UA Verizon AppVERIZO~1.EXE"Part of Verizon Online Support Manager"
Ya-winpoet-servicewinpppoverethernet.exe"WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion WinPoET is attractive to equipment providers modem suppliers RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking"
NAAATraySaverTraySaver.exe"System Tray management utility from Mike Lin which allows you to hide show restore icons that are lost in an Explorer crash remove dead tray icons minimize any window to the System Tray"
XAAMSFree702Avengine.com"Added by the DELF.LJ TROJAN!"
Xabsrmwsvm.exe"SeekSeek search hijacker related - see here"
UAbyssWebServerabyssws.exe"Abyss web server"
XAc97Soundsnddrv.exe"Detected by Kaspersky as the VB.AXG TROJAN! See here"
NAceGain LiveUpdateLiveUpdate.exe"""AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates driver updates or full product updates and automatically download and install them according to user configuration"""
YacEventServacevtsrv.exe"ActivCard Gold from ActivIdentity Inc. Smart card-based strong authentication software - for photo IDs proximity badges for facility access and as digital identification and authentication"
UAcronis Scheduler2 Serviceschedhlp.exe"Part of Acronis True Image - backup software. Co-operates with the ""schedul2.exe"" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images"
NActivationActivation.exePart of Microsoft Money
UActivboardMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock Caps Lock Scroll Lock keys
XActive Bit Stationabs.exe"Added by the MYTOB.BZ WORM!"
NActive CPUacpu.exe"Active CPU - ""easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"""
UActive Desktop CalendarADC.EXE"XemiComputers Active Desktop Calendar"
UActive Email Monitoraem25.exe"Active Email Monitor checks multiple accounts for email serves as a SPAM filter and can also protect you from harmful items that can be sent via email"
UActive shieldActiveshield.exe"Active Shield is ""an heuristic screen that actively protects your computer from trojans spyware adware trackware dialers keyloggers and even some special kinds of viruses"""
XActiveDesktopsystray32.exe"Added by the DABOOM WORM!"
XACTIVEDSACTIVEDS.EXE"Added by the OPASERV.T WORM!"
NActiveEyesActiveEyes.exeActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs create your own shortcut
UActiveKeys.AAB635BD7D054a37A576akeys.exe"""Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"""
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
UActivePlusactiveplus.exe"Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on)"
XActiveScan AntivirusActiveScan.exe"Added by the RBOT-FKQ WORM!"
XActiveScript32nod.exe"Added by the SOHANA-AJ WORM!"
YActiveShieldMCVSSHLD.EXEMcAfee VirusScan On-line. See also the McAgentExe entry
NActiveSpeedAS.exe"Ascentive ActiveSpeed internet optimizer - not recommended see here and here"
XActiveSyncwcescom32.exe"Added by the MANCSYN-E TROJAN!"
NActiveWordsAWMonitor.exe"ActiveWords from ActiveWord Systems Inc. Like macro programs ActiveWords sits in the background and watches as you type. When it recognizes that you?ve typed an ActiveWord it takes the associated action such as replacing your keystrokes with the text you?ve defined"
XActiveX File Registration Servicefilereg.exe"Added by the RBOT-DVD WORM!"
XActiveX Streamermsgfix.exe"Added by the SDBOT.NQ WORM!"
XActiveXUpdatesvcss.exe"Added by a variant of the DEDLER.C TROJAN!"
UActivityactik.exe"ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself!"
NActivSurfbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
XACTX1v1201.exe"Added by the VB.IS TROJAN!"
XADDITIONAL Servicespkgadd.exe"Added by a variant of the IRCBOT TROJAN!"
XAdmilli ServiceAdmilliServ.exeWindupdates adware variant
XAdministratorsvchost.scr"Added by the NOVACAL TROJAN!"
XAdminSoftsysfile.vbs"Added by the STARGRUB-A WORM!"
UAdobe Version Cue CS2VersionCueCS2Tray.exe"File manager that's part of Adobe Creative Suite 2 - ""find files fast track versions across applications link files together and share them in creative collaboration without fear of overwriting someone else's work"""
XAdobeReaderPromsnserve.exe"Added by the SDBOT-AKH WORM!"
NAdobeVersionCueVersionCueTray.exe"""An exclusive feature of the Adobe? Creative Suite Version Cue? helps you find files fast track multiple versions of your files and share your files for creative collaboration"""
?Adobe_ID0EYTHMVERSIO~2.EXE"Part of an Adobe product. What does it do and is it required?"
XAdope File Managerlsasv.exeAdded by an unidentified WORM or TROJAN!
XADriverwindrv.exe"Added by the DELF.WG TROJAN!"
XAdRotator.Applicationservices.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
XADS Adware RemoverADS Adware Remover.exe"ADS Adware Remover - not recommended see here"
UADServiceADService.exe"Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98/ME"
?ADSLSYSTEMTRAYSystemtrayV100B.exe"Apparently Annex A ADSL modem related. What does it do and is it required?"
Xadstartupautomove.exe"Adlogix adware variant"
XAdStatus ServiceAdStatServ.exe"WindUpdates AdStatus Service adware"
XAdtools ServiceAdTools.exe"Windupdates Adware"
XAdvanced DHTML Enableexo32.exe"Added by the RANCK-FI TROJAN!"
XAdvanced DHTML Enable[path to trojan]"Added by the AGENT.GLQ TROJAN!"
XAdvanced Internet Protocolcerf.exe"Added by a variant of the SPYBOT WORM!"
XAdvanced Protection Systemadvpsys.exe"Added by a variant of the RBOT WORM!"
UAdvanced Spyware RemoverAsr.exe"Advanced Spyware Remover anti spyware tool"
UAdvanced SystemCare 3AWC.exe"Advanced SystemCare from IObit - ""helps protect optimize clean and repair your computer and Registry."" The PRO version adds automation anti-spyware privacy protection and performance tune-ups"
XAdvanced Tool Checksadvchks.exe"Added by a variant of the RBOT WORM!"
NAdvanced Tools CheckADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvanced Uninstaller PRO Installation Monitormonitor.exe"Innovative Solutions Advanced Uninstaller PRO - ""easy-to-use suite for uninstalling applications and keeping your computer fast clean and in its best shape"""
XAdvancedCleaner FreeUADC.exe"AdvancedCleaner misleading security software - not recommended see here"
XAdVantageAdVantage.exe"MediaAdVantage adware"
Xadvap32[path to trojan]"Detected by Trend Micro as the MUTANT.AT TROJAN! See here"
XAdvapiAdvapi.exe"Added by the NETDEVIL.12 WORM!"
NADVCHKADVCHK.EXEChecks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget
UAdvertising KillerAkiller.exe"Advertising Killer - popup stopper"
Xadvmon32advmon32.exe"Added by a variant of the CRYPTER.C TROJAN!"
XAdwareRemover2007AdwareRemover2007.exe"AdwareRemover2007 spyware remover - not recommended see here"
XAERVICESNAERVICESN.exe"Added by the RANDON-AO WORM!"
NAeXAgentLogonAeXAgentActivate.exe"Altiris Agent transmits information about your machine for the purpose of asset management and deployment"
Xagentsvragentsvr.exe"Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder"
?AidemHotKeyDVMAIN.EXE"Keyboard related"
UAJC Active BackupAJCActBk.exe"AJC Active Backup from AJC Software - ""Instantly backup files you change on your PC and keep multiple versions to undo"""
XAKEYNAMEWinServ.exe"Added by the EVILBOT.C TROJAN!"
Xaldefr ere servicetay0x.exe"Added by the RBOT-XS WORM!"
XAlevirAlevir.exe"Added by the OPASERV-A WORM!"
XAlevirOld[worm filename]"Added by the OPASERV WORM!"
XAlive SYstemscchost.exe"Added by the TOFDROP-B TROJAN!"
XAlive SYstemscchostc.exe"Added by the TOFDROP-B TROJAN!"
XAll Sea screen saverTaskTray.exeFree screensaver installs lots of foistware - remove it
UAlogservAlogserv.exeFrom McAfee VirusScan for logging scanning activities. In some cases if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6 this is a critical component of McAfee and disabling it can cause a PC to lock up
Xalphasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
YAlps Electric USB ServerMonserv.exe"Alps Electric USB Server - required according to this article"
?ALServALServ.exe"Altec Lansing AMS speaker related. What does it do and is it required?"
UAltoMB_serviceAltoMBsrv.exe"Alto Memory Booster from Alto Software - boost the computers performance via more intelligent and efficient memory management. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
NALU Scheduler ServiceALUSchedulerSvc.exeSymantec LiveUpdate scheduler for programs such as Norton AV or Internet Security
Xamvaamvo.exe"Added by the SILLYFDC-BR WORM!"
Xanbv32nabv32.exe"Added by the TITOG.C WORM!"
YANIWZCS2ServiceWZCSLDR2.exe"ALPHA Networks wireless driver"
?ANIWZCSServiceWZCSLDR.exeD-Link wireless PCI adapter related. In some cases reported to cause excessive CPU activity
Xansjava[path to worm]"Added by the RANDON-AN WORM!"
XAnti Spam Servicespamsvc.exe"Added by the MYTOB-BK WORM!"
XAnti-Virusvpms.exe"Added by a variant of the SLAPER TROJAN!"
XAnti-Virus[random filename].exe"Added by the CAPROBAD-A TROJAN!"
XAnti-Virus Product Sync[unprintable character][3 characters]log.exe"Added by the KEDEBE.D WORM!"
XAnti-Virus Update Scheduler[path to trojan]"Added by the SPAMMIT-A TROJAN!"
XAnti-Virus Update Schedulerwinsp3.exe"Malware - detected by Kaspersky as the AGENT.FP TROJAN!"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe kaspersky.exe nrton.exe wins.exe gah32.exe 1.tmp syste.exe alg.exe socks.exe winxpsp2.exe tek9.exe sks.exe hihi.exe s.exe xps2.exe dns2.exe ikav32.exe and more..."
XAntiClickerSVCHST32.EXE"Added by the CBH TROJAN!"
XantispyANTIVIR.exe"IE AntiVirus rogue security software - not recommended see here"
XantispyANTIVIRUS.exe"IE AntiVirus rogue security software - not recommended see here"
Xantispyieav.exe"IE AntiVirus rogue security software - not recommended see here"
XAntiVerminserAntiVerminser.exe"AntiVerminser spyware remover - not recommended see here"
Xantiviirusantiviirus.exeAdded by a variant of the AGENT.KEU TROJAN!
XAntivirsvchst.exe"Added by the RAGRUK-A TROJAN!"
XAntiVirscvhost.exe"Added by the AGENT-DSF TROJAN!"
XAntiVirwinlog.exe"Added by the IRCBOT-TJ TROJAN!"
YAntiVir XPAVwin.exe"AntiVir® PersonalEdition Classic - antivirus"
XAntivir64Antivir64.exe"Antivir64 rogue security software - not recommended see here"
XAntiVirGear *.*AntiVirGear *.*.exe"AntiVirGear misleading security software where *.* represents the version number - not recommended see here"
XAntivirusav.exe"Added by the SINKIN TROJAN! Resets IE start page to realphx.com"
XAntivirusmaja.exe"Added by the NETSKY.H WORM!"
XAntivirusiexpl0res.exeAdded by an unidentified WORM or TROJAN!
XAntiViruskaspery.exe"Added by a variant of the RBOT WORM!"
XAntiVirusAntiVirus.exe"Added by the BANKER-EHB TROJAN!"
XAntivirusantvrs.exe"Antivirus 2008 rogue security software - not recommended see here"
XAntivirusavm.exe"Antivirus Master rogue security software - not recommended see "
XAntivirusvav.exe"Vista Antivirus 2008 rogue security software - not recommended see here"
XAntivirus Installer[path to trojan]"Added by the BADGENT-A TROJAN!"
XAntiVirus Processvirprot.exe"Added by a variant of the SDBOT WORM!"
XAntivirus Protection Servicesccapp2.exe"Added by the RBOT.EXI WORM!"
XAntiVirus Updateupdates.exe"Added by the RBOT-JF WORM!"
XAntiVirus Updateantivirus.exe"Added by the RBOT-IF WORM!"
XAntivirus-2008.exeAntivirus-2008.exe"Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN!"
Xantivirus-2008pro.exeantivirus-2008pro.exe"Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN!"
XAntivirus-GoldenAntivirus-Golden.exe"Antivirus-Golden misleading security software - not recommended see here"
XAntivirus2008yantvrs.exe"Antivirus 2008 rogue security software - not recommended see here"
Xantivirus32antivirus.exe"Added by the SPYBOT.KAI WORM!"
XAntivirusGoldAntivirusGold.exe"AntivirusGold malware"
XAntiVirusProAntiVirusPro.exe"AntiVirusPro misleading security software - not recommended see here"
XAntiVirusProMFCAntivirus Pro.exe"AntiVirusPro misleading security software - not recommended see here"
?AntiVirusProtectionqumk.exe"??"
XAntiVituSBase.exe"Added by the BAS.A WORM!"
YAnVirAnVir.exe"AnVir Task Manager - protects computer against viruses and manages running processes and startup files"
YAnVir Task ManagerAnVir.exe"AnVir Task Manager - protects computer against viruses and manages running processes and startup files"
Uanvshellanvshell.exeSystem Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel -> Display Properties -> Advanced as well as the System Tray shortcuts toolbar
UAnyDVDAnyDVD.exe"AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the ""U"" recommendation"
UAnyDVDAnyDVDtray.exe"System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts"
Yaolavp.exe"AOL's Active Virus Shield (by Kaspersky) - found in an AOLActive Virus Shield sub-directory"
XAOL Services Hostsaolserviceshosts.exeAdded by an unidentified WORM or TROJAN!
XAOLRegKey32AOREGSVR512.EXE"Unidentified malware - see here"
?AOLSAVAOLAgent.exe"AOL ISP related. What does it do and is it required?"
Xaoueisysrtmvs.exe"Chivio dialer"
UAPC_SERVICEmainserv.exe"APC PowerChute® Personal Edition - ""safe system shutdown software with sophisticated power management functions."" Appears as a service in XP/Vista and under the ""RunServices"" registry key in Win98"
Xapisvc.exeapisvc.exe"Added by a variant of the LAMEBOT TROJAN!"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UAppconvAppCon.exe"Vital Application Console - part of POS-partner 2000 point-of-sale software from Vital. This is the taskbar icon and is enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established"
XApplication Adapterabvsvc.exe"Added by the CHECKOUT WORM! See here"
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Layer Browserabgsvc.exe"Added by the ULPM.FX TROJAN!"
XApplication Layer Browserapnsvc.exe"Added by the CHECKOUT WORM! See here"
XApplication Layer Gateway Servicealgs.exe"Added by the LINKBOT.M WORM!"
XApplication Layer Scheduleragtsvc.exe"Detected by PCTools as the IRCBOT.BJJ TROJAN! See here"
XApplication Layer Servicesavrsvc.exe"Detected by PCTools as the IRCBOT.BJM TROJAN! See here"
XApplication Manageracnsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XApplicationProtocolRunsmsbvl32.exe"Added by the IRCBOT-CX TROJAN!"
YApvxdAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YApvxdwinAPVXDWIN.EXE"Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection"
YAPVXDWINClShield.exe"""Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam spyware dangerous or time-wasting content phishing scams hackers and intruders"""
?ArabLionZ DriveArabLionZ.Drive.exe"ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required?"
XArchivearchive.exe"Adware - detected by Kaspersky as the CENTIM.A TROJAN!"
XARCHIVE CONTROLfixupdattr.exe"Added by the MYTOB.GU WORM!"
NARCSolo RecoveryN/ABackup software by Computer Associates - no longer supported
YashAvastashAvast.exe"Part of Avast antivirus"
YashMaiSvashmaisv.exe"Part of Avast! anti-virus software - E-mail scanner"
UAsioRegregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
UAsioThk32Regrregsvr32.exe ctasio.dll"ASIO (Audio Stream In/Out) drivers for the SoundBlaster Audigy 2 series soundcards - for recording and home project studios. Required if you use this functionality"
XASocksrvSocksA.exe"Added by the VB.CBW WORM!"
Xasp-srvcasp-srvc.exe"Added by the AGOBOT-KG WORM!"
XASP.NET State Servicecsrss.exe"Added by the DLOADER-QI TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XASP.NET State Servicecrsass.exe"Added by the BANLOAD-M TROJAN!"
XASP.NET State Serviceservicos..exe"Added by the DADOBRA-I TROJAN!"
?ASUS Camera ScreenSaverASScrProlog.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe according to PREVX and InCode Solutions. Can any ASUS owners with this file confirm? File is located in %Windir%"
NASUS Live UpdateALU.exeASUS Live Update utility for their motherboards
?ASUS Screen Saver ProtectorASScrPro.exe"Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe according to PREVX and InCode Solutions. Can any ASUS owners with this file confirm? File is located in %Windir%"
UASUS SmartDoctorVGAProbe.exeASUS video card fan/thermal monitor
NASUSKeyV38SHELL.EXESystem tray Icon for quickly changing video modes
Xatapidrvatapidrv.exe"Added by the AGOBOT-SL WORM!"
XATI Active Graphics Card Monitoratievx.exe"Added by the IRCBOT-TL WORM!"
NATI DeviceDetectATIDtct.EXEUtility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled
XATI Display Driveratixd.exe"Added by the RBOT-FOV WORM!"
XAti Display Settingsatividx.exe"Added by the RBOT-GAS WORM!"
XATI Video Driver Controlatigfx.exe"Added by the RBOT-FWL WORM!"
XATI Video Driver Controlbtorrent.exe"Added by a variant of the IRCBOT TROJAN!"
XATI Video Driver Controls[path to worm]"Added by the SDBOT-DDS WORM!"
XATI VIDEO REGKEYati2vid.exe"Added by the SDBOT.UR WORM!"
XAti2evxxAti2evxx.comAdded by the BACKDOOR-CPC TROJAN!
XAtiDisplayDrvatidrvxx.exe"Added by the RBOT-VZ WORM!"
XatidriverreaIplayer.exe"Added by the WARPIGS-E WORM! Note the uppercase ""I"" in the filename rather than a lower case ""L"""
UATIPOLABati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resources on some computers but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
UATIPOLABati2evae.exeATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks
UATIPOLLati2evxx.exeATI External Event Utility EXE Module. This task can comsume lots of CPU resources on some computers but it can help with graphics card problems. Leave enabled unless it consumes too many CPU resources
XATITechActive.exe"Added by the ROAMER-A TROJAN!"
Xativopenativopen.exePremium rate adult content dialler
XAttuneDiscoveryattune_di.exe"Aveo Attune automated helpdesk software - adware/spyware"
XAudio Device Managerwinfp.exe"Detected by PCTools as the IRCBOT.BIV TROJAN! See here"
XAudio Device ManagerWinNT.exe"Added by the BANKER.BTG TROJAN!"
XAudio Device ManagerWNDXP.exe"Detected by Kaspersky as the IRCBOT.AJL TROJAN! See here"
XAudiodrvaudiodrv.exe"Added by the CRYPTER-C TROJAN!"
UAudioDrvEmulatorDLLML.exe AudDrvEm.dll"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system but should not be terminated unless suspected to be causing problems"
Xaupdsymcsvc.exe"Added by the ABWIZ.D TROJAN!"
Xaupdsysvcs.exe"Added by the ABWIZ.C TROJAN!"
Xaupdsywsvcs.exe"Added by the ORSE-M TROJAN!"
YAureal A3D Interactive Audiosa3dsrv.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
YAureal A3D Interactive Audio InitA3dInit.exeFor Aureal based 3D soundcards. A3D sound features won't work with this disabled
Xausvcausvc.exe"Added by the AUTOUPDER TROJAN!"
UAuto EPSON Stylus CX5000 Series on XE_FATIBVA.EXE"Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status checking ink levels etc. ""X"" represents the computer's network name ie PAULS-PC PETES-LAPTOP etc"
XAuto File System Conversion Utilityscricon.exe"Added by the SDBOT.EYB WORM!"
XAuto Updatesvchost.exe"Added by the DUMARDI-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
XAuto Updatessvchost.exe"Added by the CHEUKO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
XAutoAdministratorSERVICES.EXE"Added by the PUNYA-A WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
XAutoDiscovery/AutoPurge (ADAP) Servicewmiadapi.exe"Added by the RBOT.FLT WORM!"
XAutoLoaderEnvoloAutoUpdaterauto_update_loader.exe"Envolo/AproposMedia adware updater"
NAutoMate Task Serviceautomate.exe"Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start -> Programs"
XAutomatic Media UpdateCACHE.RVDAdded by an unidentified WORM/TROJAN!
XAutomatic Media UpdateHPLNT32.RVDAdded by an unidentified WORM/TROJAN!
NAutomatically launches the United Devices Agent when you start your computerUD.EXEThe United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start > Programs
XAUTOPROTECTUnavapq32.exeAdded by an unidentified WORM or TROJAN!
?AutoShutdownpssvc.exe"Utility to fix vCard Export in MS Outlook 2000 - although why are these together?"
XAutoupdate Servicekaka.exe"Added by the SYMPE-B TROJAN!"
Xautoupdatev2[path to file]"Added by the DROPPER-BM TROJAN!"
Xautoupdatev2autoupdatev2.exe"Detected by Kaspersky as the AGENT.FQ TROJAN!"
XAutoVirusProtectionciscv.exe"Added by a variant of the RBOT WORM!"
Xauto__antiav__keyantiav_exe.exe"Added by the BAGLEDI-AA TROJAN!"
XauxAudioDeviceaux32.exe"Added by the AIZU WORM!"
XAVUPDATE-28062004.exe[25 blank spaces].vbs"Added by the MIDFIN WORM!"
XAV Clientpatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV Industrypatch31345.exe"Added by the MYDOOM.AD WORM!"
XAV UpDateUpdate.exe"Added by the FUROOT-A TROJAN!"
NAvaFindAvaFind.exe"AvaFind file search utility"
XAVantivirusAvconsol.exe"Added by the MSNVB-D WORM!"
Xavasttroyan.exe"Added by the SMALL.CZ TROJAN!"
YAvast!ashserv.exe"Part of Avast! anti-virus software"
Yavast!ashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner right-click access to other options and event notifications"
Yavast! AntivirusashDisp.exe"System Tray access to and notifications for avast! Antivirus - giving left-click access to the On-Access Scanner right-click access to other options and event notifications"
Yavast! Web ScannerAshwebsv.exe"Part of Avast! anti-virus software"
YAvast32Astart32.exe"Part of Avast! anti-virus software"
Xavcavmon.exeAdded by an unidentified TROJAN!
UAvconsoleEXEAvconsol.exeFrom McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it
XAvengineAvengine.com"Added by the DELF.LJ TROJAN!"
XAveoAttuneatmdlusr.exe"Aveo Attune automated helpdesk software - adware/spyware"
UAVFX EngineStartFX.exe"Advanced Video FX - supported by a number of Creative Web Cameras. ""Have more fun by adding a wide range of special effects and backgrounds to your video chat with Advanced Video FX"""
XAvGsvchost323.exe"Added by the RBOT-ZA WORM!"
YAVG Anti-Virus systemavgcc.exe"AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components settings and updates"
XAvg Antivirusicpldrvx.exe"Added by the BANKER.BYU TROJAN!"
XAVG Grisoft Updaterupdater.exe"Added by the AGOBOT-OT WORM!"
YAVG7_AMSVRAvgamsvr.exe"AVG antivirus related"
YAVG7_CCavgcc.exe"AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components settings and updates"
YAVG7_EMCAVGEMC.exe"AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
YAVG7_Runavgw.exe"AVG Anti-Virus 7.0 related"
UAVG8_TRAYavgtray.exe"System Tray access to AVG internet security software"
Yavgamsvr.exeAvgamsvr.exe"AVG antivirus related"
Yavgcc32avgcc32.exe"AVG anti-virus control center. Also enables scheduled tests Outlook E-mail plug-in and automatic updates"
YAVGCtrlAVGCtrl.exe"Part of AntiVir? PersonalEdition Classic antivirus"
YavgfwsrvAVGFWSRV.EXE"Firewall part of the AVG Plus Firewall Edition"
Yavgmsvr.exeavgmsvr.exe"AVG Anti-Virus 7.0 related"
YAVGntAVGnt.exe"AntiVir® PersonalEdition Classic antivirus. System Tray icon and control program"
YAvgserv9.exeAvgserv9.exe"AVG antivirus background monitoring"
YAVGuardAVGuard.exe"AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently"
YAVG_CCavgcc32.exe"AVG anti-virus control center. Also enables scheduled tests Outlook E-mail plug-in and automatic updates"
YAVG_EMCAVGEMC.exe"AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses"
YAVG_RegCleanerAVGREGCL.exe"AVG Anti-Virus 7.0 Registry Cleaner - for checking the registry for virus additions and other security problems"
Xavidrvdrvsc.exe"Detected by Kaspersky as the AGENT.PH TROJAN!"
XAvimgtAvimgt.exe"Added by the GEMA TROJAN!"
XAvimgt32Avimgt32.exe"Added by the GEMA TROJAN!"
YavinitAVINIT9X.EXE"Command Antivirus related"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
YAVK Mail CheckerAVKPop.exe"eXtendia AVK AntiVirus email checker"
YAVKBarAVKBar.exe"GData AntiVirusKit Anti-virus"
UAVKTrayAVKTray.exe"System Tray access to AntiVirenKit InternetSecurity from G DATA Software AG"
YAvMaiSrvAvmaisrv.exe"Part of Avast! anti-virus software - E-mail scanner"
XAVManagercsrss.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
?AvMenuAVMenu.exe"Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required?"
YAVMWlanClientwlangui.exeRelated to broadband products from avm.de
Xavnortformatsys.exe"Added by the SERFLOG.A WORM!"
Xavnortmsmbw.exe"Added by the SERFLOG.A WORM!"
Xavnortserbw.exe"Added by the SERFLOG.A WORM!"
XAVP[path to trojan]"Added by the MUTBO-A TROJAN!"
Yavpavp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
Xavpavp.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
Xavpwin*.tmp.exe [* is a number]Added by a variant of the ALPHABET TROJAN!
Xavpxar6000v7.exe"Detected by Kaspersky as the ALPHABET.B TROJAN!"
XAVP-SEavp-32.exe"Added by the AGOBOT.FS WORM!"
Xavpaavpo.exe"Added by the LEGMIR-ARK TROJAN!"
Yavpccavpcc.exe"Kaspersky Labs anti-virus"
Yavpmavpm.exe"Kaspersky anti-virus"
XAvpMAvpM.exe"Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in the WINDOWSpchealthUploadLBConfig directory"
Xavpmsavpms.exe"Detected by Kaspersky as the ONLINEGAMES.CPV TROJAN! See here"
XAvpravpr.exe"Added by the MYDOOM.AF WORM!"
XAVPSrvAVPSrv.exe"Added by the ONLINE-GEN TROJAN!"
Xavptask[path to trojan]"Added by the NOFERE-G TROJAN!"
Xavptaskexpl0rer.exe"Added by the AGENT.JJO TROJAN!"
XAvptaskrund1132.exe"Added by the AGENT.PKZ TROJAN!"
XAvpWxWErcx.exe"Detected by Kaspersky as a variant of the AGENT.A TROJAN!"
XAvril Lavigne - Muse[random filename]"Added by the AVRIL-A WORM!"
YAVSCHED32AVSched32.exe"AntiVir® PersonalEdition Classic - antivirus"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
XAvSerdsm.exe"Added by the SERFLOG.B WORM!"
XAvSermsmpatch.exe"Added by the SERFLOG.B WORM!"
XAvSersvosm.exe"Added by the SERFLOG.B WORM!"
XAvSersysup.exe"Added by the SERFLOG.B WORM!"
Xavserve.exeavserve.exe"Added by the SASSER WORM!"
Xavserve2.exeavserve2.exe"Added by the SASSER.B or SASSER.C WORMS!"
Xavserve3.exeavserve3.exe"Added by the SASSER.G WORM!"
UAVStation premiumAVStation agent.exe"Related to Samsung AV Station - instant playback of music photos videos"
Xavtapiavtapi.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" ""Winamp Remote"" ""Windows Media Player"" and ""Futuremark"""
NAvtrayAvtray.exe"Command Antivirus tray icon"
XAVupdate32 UpdateAVupdate32.exe"Added by the RBOT.CNI TROJAN!"
?AVWLPSTAAVWLPSTA.exe"PRISM Status Tray Applet - but what is it for and is it required?"
YAVWUpd32AVWUPD32.EXE"AntiVir® PersonalEdition Classic - updater"
Yavx communicatorxcommsur.exe"Anti-virus part of BitDefender virus scanner/firewall"
YAvxliveavxlive.exe"Bullguard or BitDefender antivirus"
Yavxlniavxinit.exe"Anti-virus part of BitDefender virus scanner/firewall"
?Avxnews??"??"
UAXIS Print System DriverScannerDriverScanner.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery printer driver installation printing on Windows platforms. Printing is enabled by AXIS Print Monitor which is one of the components. Another component in AXIS Print System is AXIS IP Installer."" Now discontinued"
UAXIS Print System DriverServerDriverServer.exe"Part of AXIS Print System from AXIS Communications - ""adds printer discovery printer driver installation printing on Windows platforms. Printing is enabled by AXIS Print Monitor which is one of the components. Another component in AXIS Print System is AXIS IP Installer."" Now discontinued"
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
?a_vpdvpd.exe"Located in the IBMTOOLSVPD sub-directory. What does it do and is it required?"
Xbabsvchst32.exe"Added by the AGENT.Q TROJAN!"
XBack UpdatesUninstall.log.vbs"Added by the YPSAN.D WORM!"
XBackground Intelligent Transfer Servicerundll32.exe"Added by the VB-ZD TROJAN! Note - this file is located in the C:Windowshelp folder and is not to be confused with the legitimate rundll32.exe file!"
XBackup Servicebackup.svcUnidentified adware
XBagleAVcsrss.exe"Added by the NETSKY.AB WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XBaRloNdDiLhepservices.exe"Detected by Kaspersky as the AUTORUN.DIB WORM! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XBatSrvbatserv2.exe"Detected by Kaspersky as the LOCKSY.M WORM!"
XBcvsrv32bcvsrv32.exe"Added by the GAOBOT.BQJ WORM!"
XBcvsrv32he3.exe"Added by the AGOBOT.AKB WORM!"
XBcvsrv32msxml22.exe"Added by the AGOBOT.AKH WORM!"
XBcvsrv32msc32.exe"Added by the AGOBOT.AKD WORM!"
YBDOESRVbdoesrv.exe"Bitdefender 8 antivirus and firewall"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
UBelNotifyrundll32.exe [path] NPBelv32.dll RunDll32_BelNotify"""BelTech from Belarc enables licensees to offer automated Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page and automatically resolve their problem or point them to the right solution. BelTech Manager allows non-programmers to rapidly and easily deploy and maintain this service"""
?BELORVBIBELORVBI.exe"??"
Xbetasvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
NBigDog303VM303_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
NBigDog305VM305_STI.EXE"Vmicro webcam USB utility - allows the webcam to initiate data transfer to a program. Create a shortcut and start it manually when needed"
?BigDogPathVM_STI.EXE"Bundled with some software for digital cameras that use a USB connection - what does it do and is it required?"
XbingdianBingdian.vbs"Added by the BINGD WORM!"
?BIOVCIPBIOVCIP.exe"??"
XBitDefender AntivirusBITDEFENDERX.EXE"Added by a variant of the SPYBOT WORM!"
YBitDefender Communicatorxcommsvr.exe"BitDefender antivirus"
YBitDefender Live! Initbdinit.exe"BitDefender antivirus"
YBitDefender Scan Serverbdss.exe"BitDefender antivirus"
YBitDefender Virus Shieldvsserv.exe"BitDefender antivirus"
Ybitdefenderliveavxlive.exe"Main program of BitDefender virus scanner/firewall"
UBJPD HID ControlTVMon.exe"Related to Canon Photo viewer"
Xblah servicewinupdate.exe"Added by the GAOBOT.BIA WORM!"
Xblah servicewinsysengine.exe"Added by the RBOT-KI WORM!"
Xblah serviceinternet.exe"Added by a variant of the RBOT WORM!"
Xblah servicesmnp.exe"Added by the RBOT.IZ WORM!"
Xblah servicemsnmsgrr.exe"Added by the RBOT.PZ WORM!"
Xblah servicetazkmgr.exe"Added by the RBOT.UA WORM!"
Xblah serviceFaLeH.exe"Added by the RBOT-AES WORM!"
Xblah servicemicrosoft.exe"Added by a variant of the RBOT WORM!"
Xblah serviceevosys.exe"Added by a variant of the RBOT WORM!"
Xblah servicewin32.exe"Added by the RBOT-AXO WORM!"
XBlah serviceCCAPPS32.EXE"Added by the RBOT.TV WORM!"
Xblah servicesiczw.exe"Added by the RBOT-GMP WORM!"
Xblahh servicemsengine.exe"Added by a variant of the RBOT WORM!"
Xblahx servicemsnjompa.exe"Added by the SDBOT.AML WORM!"
XBlank AntiViriAUT0EXEC.BAT StartUp"Added by the BRONTOK-CJ WORM!"
?BlazeServoToolMediaDetector.exe"Related to BlazeDVD from BlazeVideo - which is ""is leading powerful and easy-to-use DVD player software."" What does it do and is it required?"
XBlue Service[path to trojan]"Added by the BANCOS-BCW TROJAN!"
UBoost XP Servicebxservice.exe"Boost XP from Systweak - WinXP tweaking utility"
XBoot Serverbootserver.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootservice.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Servicebootsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBoot Verifybootvfy.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XBootCfgInstall.log.vbs"Added by the YPSAN.D WORM!"
XBootLoaderBootLoader.exe.vbs"Added by the WATERWORKS WORM!"
XBootsCfgwscript.exe [path] Date.POP.vbs"Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe [path] All Users.vbe"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XBootsCfgwscript.exe Install.log.vbs"Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Install.log.vbs"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
XBootsCfgwscript.exe [path] All Users.vbs"Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
NBose Wave/PC Monitorwavepcmonitor.exe"System Tray access for this system (more info on the system here). Available via Start -> Programs"
XBot Loadersvchostt.exe"Added by the GAOBOT.ALV WORM!"
XBouncer RunStartupLiveUpdate.exe"Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose ""custom"" uninstall as ""automatic"" may remove other programs - see here"
Xboy lovers of bsdilikeboys.exe"Added by the MYTOB.LY WORM!"
XBPCV2BPCV2.exe"BroadcastPC adware"
XBPCv2 rebpc2 re inst.exe"BroadcastPC adware variant"
NBPServerG6FTPSrv.exe"BulletProof FTP Server"
XBraveSentryBraveSentry.exe"BraveSentry spyware remover - not recommended see here"
Xbraviaxbraviax.exe"Added by the FAKEALER.LE TROJAN!"
YBredbandsbolagetservicecenter.exe"Related to the Brebband Swedish Broadband provider"
XBron-SpizaetusCVT.exe"Added by the RONTOKBRO WORM!"
XBrowseProxyFindService.exe"Actual Names (AdvSearch) Internet Keywords parasite"
XBrowser Help SvcBHSV.EXE"Added by the RBOT-AVQ WORM!"
XBSserverFileKan.exe"Added by the VB.CBW WORM!"
XBSVCHOSTSVCH0ST.EXE"Added by the VOXOM TROJAN! Notice the digit ""0"" in the filename rather than the upper case ""o"""
XBTVbtv.exe"BroadcastPC adware"
XBtvCbtvclean.exe"BroadcastPC adware"
UBUFFALO Power Save Utility for HDHDManage.exe"Power Save utility for Buffalo backup hard discs"
Ubugwatcher servicebugwatcher.exe"Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide if available any known solutions to the crashes. It doesn't take up any room in memory just activates in the event of certain program failures"
XBuildLabservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
UBulldog Serviceupsd.exeBelkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
NBulletProof FTP Serverbpftpserver.exe"BulletProof FTP Server"
UBullGuard Updateavxlive.exe"Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions"
YBullGuard XCommXCOMMSVR.EXE"Part of Bullguard antivirus"
YBullGuardInitAVXINIT.EXE"Part of Bullguard antivirus"
UButton Serverbttnserv.exeFound on a Compaq PC for the extra buttons on the keyboard for the speaker volume media player sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them then it isn't required
XBVWORSFMbvworsfm.exe"Added by the DLUCA-AD TROJAN!"
Xcc:archiv~1win.com"Added by the CUYDOC TROJAN!"
YCaAvTrayCAVTray.exe"eTrust? EZ Antivirus system tray application from Computer Associates"
UCadenzaCdzSvc.exe"Cadenza mNotes for Palm and Pocket PC enables users to access Lotus Notes on their mobile devices"
XCall Function System32sddriver.exe"Added by a variant of the SDBOT TROJAN!"
UCallCenter Main ApplicationV3calmcp.exe"""V3 Inc. CallCenter is a free 32-bit integrated fax voicemail and data communications application with a simple to use interface providing fax send and receive functionality basic (single mailbox) answering machine capability and sophistcated data communications."" Main application"
UCallCenter Printer InterfaceV3faxecp.exe"""V3 Inc. CallCenter is a free 32-bit integrated fax voicemail and data communications application with a simple to use interface providing fax send and receive functionality basic (single mailbox) answering machine capability and sophistcated data communications."" Fax printer"
UCamera DetectorDEVDET~*.EXE"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
NCamio Viewer xIXApplet.exeImage viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
Ucarpservcarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker allowing you to listen to the dial-up sounds for example"
XCARPserverCARPserver.exe"Added by the BANKER-AN TROJAN!"
UCARPservicecarpserv.exe"Associated with Zoltrix and Conexant modems - enables the internal modem speaker allowing you to listen to the dial-up sounds for example"
XCasdvqwabmqnzkg.exe"Added by the RANDEX.BE WORM!"
Xcaseyvideocaseyvideo.exeMalware causing adult content popups
Xcaseyvideo[*] [* = digit]caseyvideo[*].exe [* = digit]Malware causing adult content popups
NCashsurfers Cashbar NavigatorCashbar.Exe"Cashsurfers CashBar Navigator - ""The CashBar rotates banner advertisements once per minute and provides you with access to up to date special offers and deals"""
XCashToolbarsvchost.exe"BrowserAid/CashToolbar adware! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XCatalyst Control Centreatixvdm.exe"Added by the RBOT.DMW TROJAN!"
Xcatsrvcatsrv.exe"Added by the PAPLOK TROJAN!"
YCAVRIDCAVRID.exe"eTrust? EZ Antivirus Real Time Infection Report from Computer Associates"
YCAVSCAVS.exe"Cheyenne (now eTrust) antivirus"
XCAZNOVASCAZNOVAS.exe"Added by the CAZNO TROJAN!"
XccAppgcasServ.exe"Added by a variant of the RBOT WORM! Do not confuse with the Microsoft AntiSpyware executable of the same name"
XccApprsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccApprsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccAppsservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
NCcdecoderundll32.exe streamci StreamingDeviceSetupPart of the closed caption decdoder/MS VBI codec. Should only run once
YCcEvtMgrccEvtMgr.exe"Part of Norton AntiVirus 2003. Event manager for scheduling weekly scans and or automatic virus updates. Used to start automatically via ""ccApp"" and was not required as a seperate entry but a recent update changed this"
XccEvtMrg.execcEvtMrg.exe"Added by the RBOT.GZ WORM!"
YCcPxySvcCCPXYSVC.exe"Part of Norton's AntiVirus 2003 Internet Security and Firewall products. E-mail proxy service - required for E-mail scanning and the firewall"
YCcRegVfyccRegVfy.exe"Part of Norton AntiVirus 2003. ""ccRegVfy.exe is responsible for checking the integrity of the NAV registry entries to make sure that the information has not been changed by a malicious threat or a hack"""
XccRegVfYexpIorer.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcrhost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYsvcshost.exe"Added by the TACTSLAY.A TROJAN!"
XccRegVfYoutIook.exe"Added by the TACTSLAY.A TROJAN!"
XccSvcHst.execcSvcHst.exe"Added by the SDBOT-DIW WORM!"
Xccsvit.execcsvit.exe"Added by the STARTPA-HP TROJAN!"
NCDANTSRVCDANTSRV.exeC-Dilla License Management software. Used for any program that uses C-dilla Protection example: 3D Studio Max 4.x. It loads as a service automatically but is not needed unless you run said program. Can be started and stopped manually
Xcddrv32cddrv32.exe"Added by a variant of the CRYPTER.C TROJAN!"
XCDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XCDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
NCesarFTP FTP Serverserver.exe"CesarFTPd - FTP server"
XCEventMgrCell.exe"Added by the BIFROSE-AK TROJAN!"
UCFSServ.exeCFSServ.exeBelongs to Toshiba's configfree utility and searches for Wireless Devices
UCGServercgserver.exe"Associated with an Eicon Networks ISDN or ADSL modem. Call Guard Server (CGserver) watches your modem and blocks incoming or outgoing calls. You need cgard.exe (from Startmenu) to configure cgserver with rules and telephone numbers. Good against unwanted dialer programs"
XCgtask Servicescgtask.exe"Added by the LALA.B TROJAN!"
XChckupNetverchk.exe"Covert Sys Exec malware variant"
Xche32che.ocx.vbs"Added by the ADENU-B VIRUS!"
YCheckMsgPlusMsgPlusH.dll VerifyInstallation"Added by MSN Messenger Plus a third party extension to MSN Messenger. This is the auto-update feature - see here for more info."
YCheckVCRIOMagic.exe"Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)"
UCHIPDRIVEPinManagersokscmpn.exe"ChipDrive Smartcard software"
UCHIPDRIVESmartcardManagerSCMgr.exe"ChipDrive Smartcard software"
Xchkdrviemon.exe"Detected by Symantec as the ADCLICKER TROJAN!"
Xchostsvchostsv.exe"Added by the BANPAES.C TROJAN!"
?ChronitelInitTVCHTVINIT.EXE"??"
XCi Svrcisvr.exe"Detected by Trend Micro as the IRCBOT.AWN BACKDOOR! See here"
NCIJxP2PSERVERCIJxP2PS.EXECompaq printer utility which is required in order to make the printer work correctly - "x" depends upon the model ie for IJ300 x=3 for IJ700 x=7
UCisco Systems VPN Clientipsecdialer.exe"Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
UCisco Systems VPN Clientvpngui.exe"Sets up IPSec communications for Cisco's VPN Client"
NCISrvr ProgramCISRVR.EXERelated to internet setup on Compaq PC's
NCitiVANCitiVAN.exe"Option from Citibank to change a credit card number in a random fashion for each purchase. The number will only be used once and never again"
XClassessrv.exe"""Switch"" premium rate adult content dialler variant"
XClassessrv2.exe"""Switch"" premium rate adult content dialler variant"
XClean upservice.exe"Added by the AGENT-FPY TROJAN!"
Xclean_serviceclean_service.cmd"Added by the REFAZ WORM!"
UCleverKeysCK.exe"CleverKeys - ""is free software that provides instant access to definitions at Dictionary.com synonyms at Thesaurus.com facts at Reference.com and more ? from almost all Windows programs including word processors Web browsers and most e-mail programs"""
Xclfmonnvsvca32.exe"Added by the TACTSLAY.E TROJAN!"
XCLI Servicesclisrv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClient Access Check Versioncwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources"
NClient Access ServiceCwbSvStr.Exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources"
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XClient Server Control Process[path to trojan]"Added by the AGENT-HR TROJAN!"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
XClip Service Managerclipmg.exe"Detected by Kaspersky as the DELF.DXJ TROJAN! See here"
XClip Servicerclipsrvc.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XClip Srvclipsv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NClipbook ServiceClipsrv.exeSupports Windows XP ClipBook Viewer which allows pages to be seen by remote ClipBooks
NClipsrvClipsrv.exeSupports Windows XP ClipBook Viewer which allows pages to be seen by remote ClipBooks
XClipSrvclipserv.exe"Added by the SDBOT-AAV and SDBOT-AFE WORMS!"
XClipSrvCLIPBRD3D.EXE"Added by the MOFEI-D WORM!"
XClipsvcclipsv.exe"Added by the BLACKHOLE.F BACKDOOR!"
Xclock[various filenames]"LiveChat Adware - known file names include: mssetup.exe kstatus.exe spoolsv.exe sptsupd.exe osk.exe msswchx.exe netdde.exe msbkup.exe"
Xcmdsvtsqn.dll"Added by a variant of the VUNDO TROJAN!"
NCmFlywaveNameCmFlywav.exe"Driver for Linksys Wireless-G Music Bridge"
UCMPDPSRVCMPDPSRV.EXE"Printer Driver Plus from ViewAhead Technology (formerly DeviceGuys Inc.). ""Printer Driver Plus seamlessly integrates all the necessary components of a printer driver plus more"". Installed with some Compaq and Lexmark printers"
XCmpntDevices2.exe"Added by the TOMPAI-D TROJAN!"
XCmpntmainsv.exe"Added by the TOMPAI-C TROJAN!"
Xcmsiserver.exe"Added by the DLOADER-WK TROJAN!"
Xcmsoundvcpdll.exe"Added by the TCXMEDI-D downloader TROJAN!"
Xcmsoundvcsystem.exe"Added by the TCXMEDI-D downloader TROJAN!"
YcnfgCavCMain.exe"Part of Comodo Antivirus"
YCnwiDeviceAgentcnwida.exe"Part of the Canon imagePROGRAF W8400 printer management software"
UCognizanceTSrundll32.exe [path] AsTsVcc.dll RegisterModule"Cognizance Corp Identity And Access Management suite"
XCOM Servicemscom32.com"Added by the BEASTY.H TROJAN!"
XCOM Servicemsynvr.com"Added by the BEASTY.G TROJAN!"
XCOM Servicemsjclh.com"Added by the BEASTY.E TROJAN!"
XCOM Servicemsdrce.com"Added by the BEASTY.I TROJAN!"
XCOM Servicemsflyx.com"Added by the BEASTDO-O TROJAN!"
XCOM+ Event SystemDRWTSN16.EXE"Added by the LOVGATE.AB WORM!"
XCOM+ EventSystem ServicesECSERVER.EXE"Added by a variant of the SDBOT WORM!"
XCOM++ Systemsvchost.exe..."Added by a variant of the LOVGATE WORM!"
Ucom.codeode.privacymantraprivacymantra.exe"""Privacy Mantra keeps your computer clean from online and offline tracks"""
XComcast Networkribiva.exe"Added by a variant of the IRC TROJAN!"
UCOMDRV32svdhost.exe"Orvell Monitoring 2003 surveillance software. Uninstall this software unless you put it there yourself. Note - asks for permission to contact the IP address of http://www.protectcom.com/"
UComm Drivercommh32.exe"G Data ""PC Spion"". PC monitoring and surveilling software captures all users activity on the PC see here. Disable/remove if you didn't install it yourself!"
Xcommandjavaw.exe"Added by the AGOBOT-LG WORM!"
?Compaq Computer SecurityRundll32.exe SECURE32.CPL Service"??"
XCompaq DriversF1rewalls.exe"Added by the SDBOT-WD WORM!"
XCompaq Jes Driverswinjes.exe"Added by the SDBOT-XR WORM!"
NCompaq Message ServerCOMPAQ-RBA.EXE"Applies to the CPQBootPerfDB entry as well. These files generate some kind of server or servlet that attempts to connect with Compaq online. They are like Trojans but fairly harmless. They send information on the ""Compaq Advisor/Compaq Message Screener"" application that comes with every Compaq computer and provide feedback on how computer users use the Message Advisor. These messages appear occasionally and instruct and advise users on their computer and its use. They generally attempt to get you (these messages) to connect to Compaq's website. They may be safely disabled via (1) MSCONFIG or (2) Start -> Programs -> Compaq Advisor -> Advisor Settings under the ""advanced"" tab. Not required and can cause problems"
XCompaq Service Driverssysteminfos.exe"Added by the SDBOT-XC WORM!"
XCompaq Service Driverscompq.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversnavapqwa.exe"Added by the SDBOT.BBQ WORM!"
XCompaq Service Driversamsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driversmsnt.exe"Added by the SDBOT.CQL WORM!"
XCompaq Service DriversNtKernelSystem.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswincmd.exe"Added by the RBOT.ATV WORM!"
XCompaq Service Driverswind32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverswinmsn.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Driverscompaq.exe"Added by the SDBOT-AFU WORM!"
XCompaq Service Driversmsnsvc.exe"Added by the RBOT.BKT WORM!"
XCompaq Service Driversntsys32.exe"Added by the RBOT.CIW WORM!"
XCompaq Service Driverswinsvc.exe"Added by the SDBOT-AGD WORM!"
XCompaq Service Drivers 32compq32.exe"Added by a variant of the SDBOT WORM!"
XCompaq Service Drivrscopq.exe"Added by a variant of the RBOT WORM!"
XCompaq Services Driversndt32.exe"Added by the RBOT.CQZ WORM!"
XCompaq Sound Drivers For WINDOWSsounddr.exe"Added by the SDBOT-XG WORM!"
NCompaq Video CD Watcher??For Compaq PC's. MPEG viewer
XCompaq32 Service Driversms32.exe"Added by the SDBOT.BWH WORM!"
XCompaq32 Service Driversmsconfig32.exe"Added by the SDBOT-ADC WORM!"
XCompaq32 Service Driversmsnt32.exe"Added by the RBOT.BVF WORM!"
XCompaqs Service Drivercopypad32.exe"Added by the SDBOT.CSO WORM!"
XCompaqs Service Driverscompqs.exe"Added by a variant of the SDBOT WORM!"
XCompatibility Service Processregsvs.exe"Added by the GAOBOT.YN WORM!"
XCompd Service Drivrscodq.exe"Added by a variant of the SDBOT WORM!"
UComproSchedulerDTVComproSchedulerDTV.exe"VideoMate TV tuner and capture card - scheduler"
XConfigservice.exe"Added by the ISRAZ.B WORM!"
XConfigWinService32.exe"Added by the CRUTCHA-A TROJAN!"
XConfig Loadersvchosl.exe"Added by the GAOBOT.P WORM!"
XConfig Loaderscvhost.exe"Added by the GAOBOT.AE or GAOBOT.AO WORMS!"
XConfig Loadersvhost.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
NConfigServicesConfig.exePart of initial setup on a Compaq PC
XConfiguration Loaderservice5.exe"Added by the GAOBOT.AF WORM!"
XConfiguration LoaderService.exe"Added by the GAOBOT.AO WORM!"
XConfiguration LoaderServicess.exe"Added by the GAOBOT.AO WORM!"
XConfiguration Loadersvhst.exe"Added by the GAOBOT.YC WORM!"
XConfiguration Loadermsgcfgsrv.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XConfiguration Loadersvupdate.exe"Added by the RANDEX.DXP WORM!"
XConfiguration Loaderscvhost.exe"Added by the AGOBOT-AAE and SDBOT.AR WORMS!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-A WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
XConfiguration Loadersvchost2.exe"Added by the AGOBOT.JR WORM!"
XConfiguration LoaderDVD-Player.exe"Added by a variant of the SDBOT WORM!"
XConfiguration Loadersvchost.exe"Added by the PARADROP-AI WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
XConfiguration Loadersvschost.exe"Added by the SDBOT-NS WORM!"
XConfiguration Loader ServiceWinsys32.exe"Added by the RBOT-YV WORM!"
XConfiguration Loader Servicedevl32.exe"Added by the SDBOT-XY WORM!"
XConfiguration Loadingsvchos1.exe"Added by the GAOBOT.DK WORM!"
XConfiguration Loading Servicewscel.exe"Added by the SDBOT-WJ WORM!"
XConfiguration Serveciesewins.exe"Added by the SDBOT-COH WORM!"
XConfiguration Servicesuchost.exe"Added by the TREB TROJAN!"
XConfiguration Servicesmswords.exe"Added by the SDBOT-YM WORM!"
XConfigVirservices.exe"Added by the AUTORUN-DV WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~ subfolder"
XConnectivity Tool[path to trojan]"Added by the LITEBOT-E TROJAN!"
XContentServicewinservn.exeHomepage hijacker
XContraVirusContraVirusPro.exe"ContraVirus misleading security software - not recommended see here"
Xcontrol panel software servicecprs.exe"Added by the RBOT-FPI WORM!"
XControlled Resource System Servicecrss.exe"Added by the AGOBOT.GH WORM!"
XControlPanelsvcc.exe"WorldSearch adware - re-directing searches to ""world-search.biz"""
XControlPanelprivate.exe internat.dllLoadMouseCarpetProfile"Detected by Norman Virus Control as W32/Downloader. Creates the files sdfff fdsf and zxczxc. In the C:\WINDOWS\SYSTEM32 directory creates the files d.exe s.exe and r.exe. Note - the ""private.exe"" file is found in %System%"
XControlServiceMgrcsmsv.exe"Added by the AGENT-XC TROJAN!"
UCopernic Desktop Search 2DesktopSearchService.exe"Copernic Desktop Search - search agent"
NCorel ReminderNAVBROWSER.EXEIf you don't want to register Corel products and be reminded about it every 2 weeks disable it
NCorel ReminderNAVBrowser.exeRegistration reminder for CorelDRAW 10
XCoreSrvcoresrv.exe"Some IRC trojans/worms use this - see here for more information"
XCounterstrike Service Agentczrzns.exe"Added by the MEDBOT.AR WORM!"
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
Xcpntmgcnavpmc.exe"Added by the SIMCSS TROJAN!"
UCPQEASYACCSTARTDRV.exeFor Compaq PC's. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
Xcprocsvccproc.exeAdded by MSIL.AGENT.C TROJAN!
XCpusaveCpusave.exe"Added by the GEMA TROJAN!"
XCpusave32Cpusave32.exe"Added by the GEMA TROJAN!"
XCPVHOST Settingscpvhost.exe"Added by a variant of the SDBOT TROJAN!"
?CQSCP2P SERVER??""Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually needed"
NCrazyTalk Serverundll32.exe CrazyTalk.dll DIIServeMediaFile"CrazyTalk from Reallusion - "the worlds only facial animation tool that gives you the power to create talking animated images from a single photograph complete with emotions." Can apparently be installed without your knowledge as well as being a legitimate download in it's own right from sites such as TUCOWS"
XCRC Value Verifiercrsss32.exe"Added by a variant of the RBOT WORM!"
XCRC Value VerifierCrsss64.exe"Added by the RBOT-NY WORM!"
XCRC Value Verifiersvchost32.exe"Added by the RBOT-OA WORM!"
XCRC Value Verifiercrsss.exe"Added by the SPYBOT.UK WORM!"
UCreata MailJMSrvr.exe"Creata_Mail. Smileys stationary and more for you email. Required if you want to access the program from Outlook or Outlook Express"
NCreative AGP Wizardagpwiz.exePart of Creative's BlasterControl
XCreative Audio Driverscreative.exe"Added by the RBOT-FKR WORM!"
NCreative DetectorCTDetect.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player selecting Tools then uncheck the Auto Start box. It should not start up automatically again
NCreative LauncherCTLauncher.exeFor Creative Soundblaster Live! series soundcards. Adds a quick-launch bar to the top of the display and a System Tray icon. Available via Start -> Programs
UCreative Live! Cam ManagerCTLCMgr.exe"Creative Live! Cam Manager"
UCreative MediaSource GoCTCMSGo.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
UCreative MediaSource GoCTCMSGoU.exe"Creative MediaSource Go! is a combination of a short-cut bar and launcher for the Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly"""
NCreative PCI Audio Configuration Utilitystarter.exe"System Tray icon to configure a Creative Soundblaster PCI soundcard. Not required and re-instates itself when un-checked. Try one of the solutions on this special page. Similar to EnsoniqMixer"
NCreative Service for CDROM AccessCtsvccda.exeResident program for Creative's PlayCenter included with Soundblaster Audigy sound cards - speeds up detection of some media CDs if the system doesn't natively support them. Available via Start -> Programs
NCreative Software UpdateAutoUpdate.exeAuto-updater for Creative Labs software
NCreative WebCam TrayCamtray.exeCreative WebCam tray control - can be started manually
XCreative.exeCreative.exe"Added by the PROLIN WORM!"
NCreativeDiscNotifierCTNOTIFY.EXEFor Creative Soundblaster Live! series soundcards. Detects when you insert a CD-ROM DVD-ROM etc. Available via Start -> Settings -> Control Panel
UCreativeMixerCTMIX32.EXECreative soundcard System Tray access to for example volume slider controls as normally provided by the "speaker" icon. Not required unless you adjust any settings otherwise available via the standard icon
?CreativeTaskSchedulerCTSched.exe"Creative Task Scheduler. What does it do and is it required?"
XCrnsavascrnsave.pif"Added by the SDBOT-ZV WORM!"
XCryptographic Service******.exe [* = random char]"Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!"
XCS Updatecopy /Y [path] ActivationManager.dll.upd [path] ActivationManager.dllAdded by an unidentified malware
YCSAV_CheckVirusesvchk.exe"Command Antivirus related"
XCSCRS Valuecscrs.exe"Added by the RBOT-AAA WORM!"
XCSCRS Value CheckMsPMSPSd.exe"Added by a variant of the SDBOT WORM!"
XcsrssLevel4csrss.exe"Unidentified malware! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Level4"" subfolder"
Xcsrvsscsrvss.exe"Added by a variant of the SDBOT TROJAN!"
UCSS ServerCSSServer.exe"ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
XCSV10P1CSP001.exe"ClearSearch adware"
XCSV10P70CSv10P070.exe"ClearSearch adware"
XCSV7P26CSV7P26.exe"ClearSearch adware"
XCSV7P70CSV7P070.exe"ClearSearch adware"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Ucsvdeacsvdea.exe"SpyArsenalLog surveillance software. Uninstall this software unless you put it there yourself"
Xcsvhost.execsvhost.exe"Added by the CIMUZ-BD TROJAN!"
XCT Control SettingsCTSVCCD.EXE"Added by the RBOT-YS WORM!"
NCTAVTrayCTAvTray.exeFor Creative Soundblaster Live! series soundcards. Plays the EAX animation on start-up and adds a System Tray icon for it. Available via AudioHQ
XCTDriverundll32.exe drvmod.dll"Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
NCTDVDDetCTDVDDet.exeAuto-detect and play a DVD when using a Creative Soundblaster Audigy2 soundcard. Uses about 2.2 MB of memory. Disable it by heading to the MediaSource DVD Audio Player selecting Tools then uncheck the Auto Start box. It should not start up automatically again
XCTFMON.EXEsvchost.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xctfnom.exeSVOHOST.exe"Added by the DIGIDOR-A TROJAN!"
?CTPDPSRVCTPDPSRV.EXE"Printer driver (in the WINDOWSSystem32spoolDRIVERSW32X86 folder). Is it required?"
UCtrlVolCtrlVol.exeVolume control key on Acer Fujitsu and other laptops
UCTSVolFECTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTSVolFE.exeCTSVolFE.exeCreative Labs Mixer applet for the Sound Blaster Audigy
UCTsysVolCTSYSVOL.exeCreative sound card volume controls
?cttdpsrvcttdpsrv.exe"??"
XCU1VCClient.exeAssociated with the Surf Sidekick adware and should be removed
XCU2VCMain.exeAssociated with the Surf Sidekick adware and should be removed
NcursorScreendragon_VS_Taskbar.exe"ScreenDragon video player"
XCvfjxANACON.EXE"Added by the NACO.A WORM!"
Xcvmonitor.execvmonitor.exe"Added by the SDBOT.BV WORM!"
Xcvmsyslpdsdservss.exe"Added by the MAILBOT-BY TROJAN!"
YCVPNDcvpnd.exeSub-system used by Cisco VPN client for making a connection to a remote IPSec server
Ncwbckvercwbckver.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop browser and wireless access to iSeries servers. Checks the software version on your PC to that of the iSeries it is connected to. Not required - and can be turned off in the Client Access properties. It's a waste of resources"
Ncwbsvstrcwbsvstr.exe"Part of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop browser and wireless access to iSeries servers. Useful if you are going to access the iSeries through Windows Explorer to move files back and forth between Windows folders and iSeries folders. This is a tool that is only used by Client Access administrators (usually) so it is not required - a waste of resources"
UCyber-Defender 2003uwcdsvr.exe"Cyber Defender 2003"
?Cyber-shot Viewer Media Check ToolSPUVolumeWatcher.exe"Part of the Sony Picture Uility software supplied with Sony Cybershot digital cameras. What does it do and is it required?"
XDamedWare Servicesdwdrce.exe"Added by the RBOT-AOJ WORM!"
XDarkDevil.Grasiele.BRGrasiele.VBS"Added by the LEMBRA WORM!"
XDataSystem.dat.vbs"Added by the BISCUIT.A WORM!"
XData Restore Serviceprq8.exe"Added by the KELVIR.AI WORM!"
NDataViz Inc MessengerDvzIncMsgr.exe"Installed with DataViz ""Documents to Go"" software"
NDataViz MessengerDvzMsgr.exe"DataViz Documents to Go - "allows you to use your Word Excel and PowerPoint files on your handheld anywhere anytime. In addition it now synchronizes e-mail with attachments PDF files pictures and Excel-like charts""
UDAZEL Delivery AgentDcDaemon.exeControl and send documents etc to any destination. The Dazel Corporation has now been taken over by HP
Ndbservdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
Xdc2k5SVIQ.EXE"Added by the COIDUNG-A WORM!"
UDCfssvcdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
Udcfssvedcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
NDDCActiveMenuDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
Xddivmwa[random filename]"Added by a variant of the SLAPER TROJAN!"
Uddoctorv2sprtcmd.exe /P ddoctorv2"Comcast Desktop Doctor (provided by SupportSoft Inc) is a free self-help tool for Comcast broadband users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service"
XDDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDDriversvchost.exe"Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDefaultmtask.vbe"Added by the ALLEM WORM!"
XDefault System Researchvhchost.exe"Added by the TARNO.I TROJAN!"
Xdefragsyssvchost.exe"Added by the BIFROSE-TH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
Xdelsubmitrundll32.exe advpack.dll DelNodeRunDLL32 submit.exe"CoolWebSearch parasite variant"
XDenecaVirus salvado"Added by the DELUZ VIRUS!"
?desk-top-servicedesk-top-service.exe"??"
XDeskAd ServiceDeskAdServ.exe"DeskAd.Service adware"
Xdesktopdesktop.ini.vbs"IE-Title malware"
NDesktop Service CentreDSC.exeOptusNet DSL or Dial-Up connection software
?DevconDefaultDBREADREG"Appears to be related to older Creative Soundblaster soundcards"
XDevelopment Environmentdevenv.exe"Added by the DELBOT-AH WORM!"
UDEventAgenteventagt.exeDEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
Xdevenvsmvss.exe"Added by the DEDLER-G TROJAN!"
XDevice Configuration Loadermsdvc32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
UDevice DetectorDevDetect.exe"ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
NDevice Detector 2DevDtct2.exe"Installed by various Olympus products this program detects the active connection of a speech device (voice recorder etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a ""high"" priority level which can negatively impact system resources"
XDevice Hardwaredevicehnd.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice IO Systemdeviceio.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Managerwfxmgr.exe"Added by the RBOT.AJU WORM!"
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Driverdevicesec.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UDeviceDiscoveryhpotdd01.exeDetection of new imaging printing and other peripherals on HP machines such as USB printers cameras and Bluetooth products
XDevicePathProyecto1.exe"Added by the GRUEL WORM!"
XDevicePathRoot.exe"Added by the GRUEL WORM!"
UDevicesolesvr.exe"Salfeld Child Control - parental control software"
XDevicewin[path to trojan]"Added by the BANKER-AEV TROJAN!"
Udevldr16devldr16.exeAssociated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Udevldr16.exedevldr16.exe"Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
?Devlogdevlog.exe"Apparently mainboard/chipset related by a French company called AS Media - what exactly is it and is it required"
XDHCP Serverregsvr.exe"Added by the RBOT-PR WORM!"
XDHCP32services.exe"Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
?DiamondviewDiamondview.exe"Manulife Financial Insurance program. Is it required at startup?"
UDigiSrvDigiSrv.exe"Related to camera software from DigitalDreams"
NDigital Dashboarddevgulp.exeFor Compaq PC's. Loads Digital Dashboard options
NDigital River eBotdownlo~1.exe"Digital River Systems EBOT for downloading software from their site. In some cases if you purchase software online for a download from a software manufacturer you will be sent to this online company's site for the download after the purchase is complete. Read more here"
UDIGServicesDIGServicesCreated by Disney but licensed to ESPN for watching videos
NDIGServicesDIGServices.exeCreated by Disney but licensed to ESPN for watching videos
UDIRECTVDSLDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manually
XDirectX Driverstdhost.exe"Added by a variant of the RBOT WORM! See here"
XDirectX Driverstdhost.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDirectX For Microsoft Windowsdtxservice.exe"Added by the PROGENT TROJAN!"
XDirectX for Microsoft WindowsFservice.exe"Added by the PRORAT TROJAN!"
XDirectX for Microsoft WindowsSservice.exe"Added by the PRORAT TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-P TROJAN!"
XDirectX For Microsoft® Windowsfservice.exe"Added by the PRORAT-L TROJAN!"
XDirectX shell driver[path to trojan]"Added by the MARKTMAN-B TROJAN!"
XDirectx Startup Driversdirect.exe"Detected by PCTools as the RBOT.UXL WORM! See here"
XDirectX Video Driverdxterm5.exe"Added by the WILAB-A TROJAN!"
?discovegdiscoveg.exe"??"
?DISCoverDISCover.exe"Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
NDiscoverDeskshopDeskshop.exe"Discover Deskshop - single use ""virtual"" credit card"
XDisk Defragmentation Loaderpmsvcr.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Essensial Toolsdetsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisk Managerdiskver.exe"Added by the RBOT.AQT WORM!"
XDisk Panel Configurationdpcsvc.exe"Detected by PCTools as the IRCBOT.BSQ TROJAN! See here"
XDisk Panel Setupnpcsvc.exe"Added by a variant of the IRCBOT TROJAN!"
XDisplay Driverscssrs.exe"Added by the AGOBOT.FX WORM!"
XDistributed File SystemDfsvc.exe"Added by the MYFIP.A or MYFIP.K WORMS!"
?Divamon.exeDivamon.exe"Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
Xdivxdivxenc.exe"Added by the SPBOT.B TROJAN!"
XDivxcodll.exe"Added by the GRAVEBOT-A TROJAN!"
XDivX MediaPlayer 7.0Dr.DivX.exe"Added by the ALADINZ.G TROJAN!"
XDivX PlayerDivXPlayer.exe"Added by a variant of the RBOT WORM!"
XDivX UpdaterDivX.Exe"Added by the NALDEM TROJAN or MASTAK VIRUS!"
XDIVX Video PlayerDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!
XDivx4 codecdevldr32.exe"Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
YDkServiceDkService.exeFrom Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled otherwise you could have problems starting it manually.
Ndlbcservdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devices
Xdlcipscldcpavss.exe"Added by the MAILBOT-CB TROJAN!"
NDLF_00000B00Vcdlf.exe"Known to cause problems with "Out of memory" errors (see here). Otherwise it's purpose is unknown"
XDLINK dfe drivers for Windows NTwindfe.exe"Added by the RANDEX.AK WORM!"
XDll Boot Loader on Startup (do not remove this)[various filenames]Added by an unidentified TROJAN!
XDll Linksvchoist.exe"Added by the AUTOSKY WORM!"
XDll Linksvchost.exe"Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
XDLL Service Manager[path to worm]"Added by the RPCBOT.F TROJAN!"
Xdll services[random filename].exe"Added by a variant of the SDBOT WORM!"
XDllCacherv2dllcachev2.exe"Added by the LATEDA TROJAN!"
Xdllcvss[random filename]"Added by a variant of the SLAPER TROJAN!"
XDLLService32dllsvc32.exe"Added by the AGOBOT.VX WORM!"
XDmsvc32Dmsvc32.exe"Added by the AGOBOT.ABU WORM!"
XDM_serverdmserver.exe"Comet Cursor adware"
Xdm_service[path to file]"Added by the MITGLIEDER.P TROJAN!"
XDns Resolverdnsrslve.exe"Added by the RBOT-WS WORM!"
XDNS Servicednsresolver.exe"Added by the RBOT-PQ WORM!"
XDNS Servicednssvc.exe"Added by the DELBOT-Z WORM!"
?DNXVCdnxvc.exe"??"
XDoctor Antivirus 2008antvr.exe"Doctor Antivirus 2008 rogue security software - not recommended see here"
XDomain Name Resolve Servicednsresolver.exe"Added by the KIMAN.A WORM!"
XDomPlayer Servicewakeservice.exe"DomPlayer adware"
NDoroServerDoroServer.exe"Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
XDowmingzuDowmingzu.dll.vbs"Added by the SOLOW-E WORM!"
YDpcnavdpcnav.exe"DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
Xdpnsvr32dpnsvr32.exe"Added by the AOLPASS-B TROJAN!"
Xdreamsserver.exe"Added by a variant of the SDBOT WORM!"
XDrefIWSysDrefIWv2.exe"Added by the DREF-C WORM!"
XDriveCleaner 2006 FreeUDC2006.exe"DriveCleaner rogue security software - not recommended see here"
XDriveCleaner FreeUDC.exe"DriveCleaner misleading security program - not recommended see here"
UDriveIconsDriveIcon.exe"Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
UDriveLEDOODLed.exe"O&O DriveLED - hard disk monitoring and crash prevention"
XDrivergbot.exe"Added by the JUNTADOR.K TROJAN!"
XDriver32Scam32.exe"Added by the SIRCAM WORM!"
XDriverChecksvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder"
XDriverDBsvcmdx32.exe"Added by the BERPI TROJAN!"
XDriverLoadsvchost.exe"Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a C:DriverLoad folder"
UDriverMagicLogondmschedule.exe"Part of DriverMagic - ""the easiest way to locate device drivers"""
NDriverMaxdevices.exe"DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
XDriverModulecsrnvrt.exe"Added by the IRCBOT.I TROJAN!"
XDriverPathsystem32.exe"Added by the PRORAT-S TROJAN!"
XDrivers for Internet Exploreraccesweb.exeAdded by freewebs.com hijacker!
NDriveSelectdriveselect.exe"DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
Udrkly16jrundll32.exe drkly16j.dll ServiceCheck"KidsWatch Time Control parental control software"
Xdrmsrv32stmhosts.exe"Added by the AGENT.AGWU TROJAN!"
Xdrvddll.exedrvddll.exe"Added by the BEAGLE.AP WORM!"
XDrvddll_exedrvddll.exe"Added by the BEAGLE.X WORM!"
UDrvIconDrvIcon.exe"""Vista Drive Icon changes the drive icons shown in Windows ""My Computer"" to a nearly Vista drive icon showing the drive's free space with a smooth colored horizontal bar"""
?DrvListnrDrvListnr.exe"Analog Devices SoundMAX soundcard related. What does it do and is it required?"
Udrvlsnrdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
UDrvMon.exeDrvMon.exe"Alcor drive monitor software"
Xdrvnetwdrvnetw.exe"Added by the BROGGER-B TROJAN!"
Xdrvr32hdrvr32h.exeAdded by an unidentified VIRUS WORM or TROJAN!
Xdrvrmanagerdrvrquery32.exe"Added by the BOOHOO WORM!"
Xdrvsys.exedrvsys.exe"Added by the BEAGLE.W WORM!"
Xdrvsyskithidr.exe"Added by the BAGLE.HR WORM!"
Xdrvupdrundll32 ..drvupd.inf"Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
Xdrv_st_keyhidn.exe"Added by the BEAGLE.FF WORM!"
XDrWeb AntivirusDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!
Udscactivatedsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptop
XDsmSersvosm.exe"Added by the SERFLOG.B WORM!"
XDSServicedmrss.exe"Added by the AGOBOT-XX WORM!"
XDSystemDriverwindrv.exe"Added by the DELF.WG TROJAN!"
XDumeter Servicesdumeter.exe"Added by the SDBOT-AEQ WORM!"
XDUN_SERVICES3dun3.exe"Added by the SOKIRON TROJAN!"
XDVD Upgradedvdupgd.exe"Added by a variant of the IRCBOT BACKDOOR!"
Ndvd43DVD43_Tray.exe"DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
UDVD43DVD43.exe"DVD43 is a small tool that overrides CSS copy-protection found on DVD movies"
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
NDVD@ccessDVDAccess.exe"Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
UDVDBitSetDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
?DVDCheckDVDCheck.exe"Related to an Intervideo program. What does it do and is it required in startup?"
XDvdcompatDvdcompat.exe"Added by the GEMA TROJAN!"
NDVDLauncherDVDLauncher.exe"Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
NDVDSentryDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching they decided to implement an anti-spyware service. Run manually before installation starts
NDVDTrayDVDTray.exeHP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
NDVDUpgradeDVDUpgrd.exe"Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
NDVDXGhostDVDGhost.EXE"DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free and copy/backup DVD to hard disk"""
UdvHighMemcfgmng32.exe"Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
YDvp95Dvp95.exe"Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine"
Ydvpapi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
YDvpInitExeDvpinit.exe"Command Antivirus related"
YdvprptDvprpt.exe"Command Antivirus related"
Xdvraudiodvraudio.exe"Added by a variant of the CRYPTER.C TROJAN!"
Xdvsfssfbsfsdrs.exe"Added by the SDBOT-QA WORM!"
UDVSyncdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
XDvVideo32dvvid32.exe"Detected by Trend Micro as the TINY.FD TROJAN! See here"
XDvxwsxsvc.exe"Delfin Media Viewer or ""Promulgate"" adware variant"
Xdxmsrvdxmsrv.exeAdded by an unidentified WORM or TROJAN!
Xdxviddxvid.exe"Added by the DLUCA-Y TROJAN!"
XDyFuCA Active Alertactalert.exe"Adult content dialler - see here"
?DZKillMeDZSAVEME.EXE"??"
UD_V_Tdvt.exe"DICOM Validation Tool - ""DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"""
?D_V_Tdvt.exe"Installation could be a crack/hack to NOD32 here. Seen and removed in many logs. Investigate it further and if this file is present C:d_v_t.reg then it should be fixed. Not to be confused with the DICOM entry here. Both files are located in the Windows/Windir directory"
Xe-Surveiller Stationestation.exe"ESurveiller spyware. Note - ESurveiller is spyware that monitors and records keystrokes and mouse clicks instant message conversations Internet activity and applications used must be manually installed"
Ueabconfg.cplEabServr.exeEasy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
?Eac_rnvdlANTIVIRUS_INSTALL.EXE"??"
XEasyAVEasyAV.exe"Added by the NETSKY.S or NETSKY.T WORMS!"
UEasyLinkAdvisorLinksysAgent.exe"Linksys EasyLink Advisor - ""the free application that provides and easy way to setup view manage and repair your network"""
XeasyServServer.exe"Added by the EASYSERV TROJAN!"
UEasyTuneIVET4Tray.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
UEasyTuneVGUI.exeTuning (overclocking) utility for Gigabyte motherboards. Shortcut available
XEbatesMoeMoneyMakerwjview ...Code"Ebates adware"
Xebmmmebatesmmmv.exe"Ebates adware"
XEdzy AntiVirusdppsfa.exe"Added by a variant of the RBOT WORM!"
NEEventManagerEEventManager.exe"Part of the Epson Creativity Suite supplied with their multi-function printer/scanners Event Manager launches File Manager or PageManager for EPSON automatically when you press the B&W Start or Color Start button on the control panel in Scan mode"
UeFax Live Menu 3.3J2GDllCmd.exe"DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications Inc. - which ""is powerful Internet fax software that makes it easy to create annotate sign zoom and print faxes from any computer"""
NelmElmenv.exeViaTech eLicense for securing distributing and selling music online
UELSAChipGuardelsavect.exeChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed and will halt the system if either are at dangerous levels and restore the default clock speeds upon reboot. Leave enabled if overclocking
YEmailScanmcvsescn.exeRelated to McAfee AntiVirus suite - used to automatically scan incoming e-mails
XeMakeSVEMAKESV.EXE"""Switch"" adult content dialer"
XeMakeSVEMAKE2B.EXE"""Switch"" adult content dialer"
NEnergizer FileSaverEnergizer FileSaver.exe"Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
?ENSApServer2_0APSERVER.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
XEnumerate Servicewsys.exe"Added by the MANIFEST TROJAN!"
YEnvyHFCPLEnMixCPL.exe"VIA Envy24 PCI Audio Controller driver"
NePrint 3.0 ServiceEPRINT3.EXE"LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF DOC HTML TXT Multi-page TIFF JPG GIF PNG and many more!"" Can be started manually"
NePrint 4.0 ServiceEPRINT4.EXE"A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF DOC HTML TXT Multi-page TIFF JPG GIF PNG and many more!"" Can be started manually"
NEPSe_srcv02.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
NEPSe_srcv03.exe"According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
XEpsilon Squaredvmmreg32.exe"Added by the AGENT.MVC TROJAN!"
UEPSON Status Monitor 3E_[various].EXEEpson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status checking ink levels etc
NEPSON Status Monitor 3 Environment Checke_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Checke_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv03.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
NEPSON Status Monitor 3 Environment Check 2e_srcv02.exeAccording to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
UEPSON Stylus CX5000 SeriesE_FATIBVA.EXEEpson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status checking ink levels etc
UEPSON Stylus DX5000 SeriesE_FATIBVE.EXEEpson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status checking ink levels etc
XEQAdviceEQAdvice.exe"NewAds1 adware"
UeRecoveryServicecheck.exeAcer Notebook related. Acer eRecovery allows the user to restore the operating system or backup the current system profile thus ensuring system integrity
UeRecoveryServiceMonitor.exe"Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer and also acts as a versatile standalone backup and recovery manager"""
UeRecoveryServiceeRAgent.exeAcer's eRecovery Management program. This program allows you to create and restore backups of your computer
Xerthgdrsvc.exe"Added by the BEAGLE.BN or BEAGLE.BP WORM!"
Xerthgdr2svc23.exe"Added by the BAGLE.CG WORM!"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
UeScan Scheduleravkserv.exe"MicroWorld eScan antivirus scheduler"
XEthernet Drivercmsrrs.exe"Added by a variant of the RBOT WORM!"
XEthernet Driverssmrrs.exe"Added by the RBOT-AAK WORM!"
XEthernet Driversethernet.exe"Added by the GAOBOT.CEZ WORM!"
XEtrafficJavaRun.exe"TopMoxie adware"
UeTrust PestPatrol Active ProtectionPPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
XEUP Serviceeupsvc.exe"Added by the DELBOT-Q WORM!"
?Event Logeventlog.exe"??"
NEvent Planner RemindersPLNRnote.exeSierra Event Planner tray icon
NEvent Reminderpmremind.exeA calendar/alarm program that installs with Br?derbund Printmaster
XEventApplicationCmdsmschk.exe"Added by the IRCBOT-AO TROJAN!"
UEVENTLISTENEREvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
Neventmgreventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
Xeventwvreventwvr.exe"Added by the COSIAM_G TROJAN!"
?EverioServiceEverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
UEvidence Cleanerecleaner.exe"Evidence Cleaner cleans up tracks left by your PC and Internet activities"
NEvidence Eliminatoree.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
XEvilEvil.exe"Added by the MYTOB.JM WORM!"
Nevntsvcevntsc.exe"Application Scheduler installed along with RealOne Player. Once installed it runs independently of RealOne Player. See here for more information including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
UEVOLOSTAEVOLOSTA.EXEEvolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID peer-to-peer mode channel link speed WEP encryption options and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher as they have this built-in to the control panel. Also if the user is very sure that there is ONLY ONE network available to connect to then they can remove this. If it is not in startup and the user needs to run it they can simply type EVOLOSTA in the Start -> Run dialog to run it
UEvoluent Mouse ManagerEvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
XEvtHtmevthtm.exe"Added by the DLUCA-EJ TROJAN!"
UEW Message Servermsg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
?Excite Private Messenger Pipex8impipe.exe"??"
XExpertAntivirusExpertAntivirus.EXE"ExpertAntiVirus misleading antivirus program - not recommended see here"
XexplerUpdadv.exe"Added by the QQPASS-N TROJAN!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
UE_S[numbers][path] E_[various].EXE [path] E_S[numbers].tmpTemporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status checking ink levels etc
UF-PROT Antivirus Tray applicationFProtTray.exe"System Tray access to F-PROT Antivirus"
XF-Secure 2005svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
UFamilyKeyLoggercisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %System%\CTF"
XFast Homesvcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines however as of this writing it has only been seen in the System32 folder"
XFast Searchsvcnv.exeHomepage Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
XFast startsvcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
XFastStartsvcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFastStartsvcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
XFASTTRACKNETVISIONNETVISION.exe"DialCar-Z premium rate dialer"
UFastTVSyncFastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps you can copy videos to most DVD formats or convert them for smooth flawless viewing on your PSP® or iPod®. With broad format support and unique CopyLater™ technology DVD Copy saves you time and ensures high-quality output like no other copying software"""
Ufatrecovfatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
UFavoriteSyncFavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
UFaxCenterServerfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark MCI Lotus My Software Broderbund Traffic Software and many others"
UFaxCenterServer4_in_1fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark MCI Lotus My Software Broderbund Traffic Software and many others"
UFaxCtrl.exeASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel high-volume software solution from Avaya designed specifically for the intelligent routing and computer telephony integration (CTI) needs of medium-sized contact centers"""
XFDriverwindrv.exe"Added by the DELF.WG TROJAN!"
UFEELitDeviceManagerfeelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
XfegozeSVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
XFen Startupsfensvc32.exe"Added by the RANDEX.CCF WORM!"
XFHStartshdocsvc.exe"Added by the WINHOUND TROJAN!"
UFieldForms SyncSyncService.exe"Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run on a wide range of mobile devices. Supports Microsoft Access databases and provides for synchronization of other data as well"
?file indexing servicemsfindfile.exe"New version of MS FindFast and still a resource hog?"
XFile Mapping Serviceshp-1003.exe"Added by the RBOT.FAN WORM!"
XFile System Servicewmiprvsc.exe"Added by the AGOBOT-HZ TROJAN!"
XFileManager32Wscript.exe ChkMgr32.vbs"Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is found in the System (9x/Me) or System32 (NT/2K/XP) folder"
XFileSoftWscript.exe UpdataFiles.vbs"Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in the Winnt or Windows folder"
UFilmLoopFilmLoopService.exe"Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
YFind Virus Launch Programfvlaunch.exe"Part of Dr. Solomon's Antivirus"
UFinePrint Dispatcher v4fpdisp4.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink paper time and money by controlling and enhancing printed output"""
UFinePrint Dispatcher v4fpdisp4a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink paper time and money by controlling and enhancing printed output"""
UFinePrint Dispatcher v5fpdisp5a.exe"FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink paper time and money by controlling and enhancing printed output"""
XFire Wall services[random filename]"Added by the IRCBOT-QY WORM!"
XFireFox Service Driversssmss.exe"Added by a variant of the SDBOT WORM!"
XFireFox Startup Driverswuaclt.exe"Added by the RBOT.BYX WORM!"
XFirewallActiviescsrss.exe"Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
XFirewallSvrFirewallSvr.exe"Added by the NETSKY.X or NETSKY.Y WORMS!"
XFireWire Driversamx.exe"Added by the SDBOT.AE WORM!"
XFireWire Servicenvscv32.exe"Added by a variant of the SDBOT WORM!"
XFireWire Servicesnvcsv32.exe"Added by a variant of the SPYBOT WORM!"
XFIXWinFIX1.0.vbs"Added by the GORMLEZ-A WORM!"
YFix-it AVmemcheck.exePart of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
XFixnicevcvw.exe"Added by the SDBOT TROJAN!"
NFJUPDNV_Chitosefjdvrupd.exeDriver update for a Fujitsu Siemens Lifebook laptop
XFKS v2.0msngr.exeAdded by an unidentified WORM or TROJAN!
XFlash Driver[path to trojan]"Detected by PCTools as the AGENT.CWVT TROJAN! See here"
XFlash Mediaservices.exe"Added by a variant of the IRCBOT TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup!"
?Flow Go TVflogotv.exe"??"
Xflpsflps.vbs"Added by the BYRON WORM!"
?FLSVCIFLSVCI.exe"??"
XFolder Servicewssdtu.exe"Added by the MANIFEST TROJAN!"
UFolder Viewfolderview.exe"Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
UFolderClone v*.*.*folderclone.exe"Folderclone backup and synchronization software"
XFont Viewerfontviewer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
NfontnavFontNav.exe"Font Navigator from Bitstream Inc. - a font management utility"
XFONTVIEWFONTVIEW.EXE"Added by the OPASERV.T WORM!"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
NFpxmnmsrvc.exeRemote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
XFrancesvchost.exe"Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
NFree DVD DirectFreeDVDDirect.exe"Free DVD Direct - provides a program to access a peer–to–peer (P2P) file–sharing network (see here)"
UFreeMemVn2FreeMem.exe"FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XFriendlyTypeNameservices.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
XFS6519FS