CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

spacer spacer

StartupList Index

Currently 17175 startuplist entries and growing...
Last updated on 2008-08-21 15:41:23 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   


    Full List

    NameStatusFilenameDescription
    XMSPF.EXEAdded by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
    Xsvchost.exeAdded by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field
    Xmstdmc.exeAdded by Trojan-Downloader.Win32.Banload.cil MALWARE! Note: Located in \%WINDIR%\System32\ The startup name is empty This will make sure that it's start at startup.
    Xmsmapiax32.exeIdentified as a variant of the Rootkit.Win32.Agent.uj rootkit. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Xmsmapibx32.exeIdentified as a variant of the Rootkit.Win32.Agent.uj rootkit. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    Added by the W32/Sdbot-DHY, Worm! Read the link, allows remote access Note: located in \%WINDIR%\ Note: Use SDFix under supervision.
    hamachiUhamachi.exeRelated to hamachi Instantly connect multiple computers in a VPN from LogMeIn Inc. Note: Located in \%Program Files%\Hamachi\
    Security PatchXscmss.exeAdded by the W32/RBOT-ZW WORM! Read the link, keylogger/password stealing trojan(s) involved.
    WinCheckXservices.exeAdded by the W32.Sober.V WORM! Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.
    WindowsXservices.exeAdded by the W32.Sober.X WORM! Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.) This worm file is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
    !1_pgaccountYpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
    !1_ProcessGuard_StartupYprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks.
    !AVG Anti-SpywareUavgas.exeRelated to AVG_Anti-Spyware from Grisoft. Note: Located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
    !ewidoUewido.exePart of Ewido anti-spyware
    !NoLoadUwinrecon.exe Winrecon Read the link, keylogger/password stealing trojan(s) involved. - Commercial Keylogger
    $EnterNetUEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOE
    $sys$cmpX$sys$xp.exeAdded by the Backdoor.Ryknos.B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer. Read the link, rootkit type stealth involved.
    $sys$crashX$sys$WeLoveMcCOL.exeAdded by the Welomoch TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY!
    $sys$crashX$sys$sonyTimer.exeAdded by the Welomoch TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY!
    $sys$crashX$sys$sos$sys$.exeAdded by the Welomoch TROJAN! Note: This worm\trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, rootkit type stealth involved. SONY ROOTKIT, THANKS SONY!
    $sys$drvX$sys$drv.exeAdded by the Backdoor.Ryknos TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer. Read the link, rootkit type stealth involved.
    $Volumouse$Uvolumouse.exeRelated to Volumouse from Nirsoft. Provides you a quick and easy way to control the sound volume on your system. Note: Located in C:\Program Files\Volumouse\
    $WindowsRegKey%updateXIEXPLORE.EXEAdded by a W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually!
    %cmpmixtitle%?%cmpmixstr%Possibly related to C-Media Mixer Control panel?
    %FP%012-L2TP fts.exe?fts.exe012.Net ISP software - what does it do and is it required?
    %FP%012-L2TP FWPortal.exe?FWPortal.exe012.Net ISP software - what does it do and is it required?
    %FP%1776 Internet fts.exe?fts.exe1776 Internet ISP software - what does it do and is it required?
    %FP%1776 Internet FWPortal.exe?FWPortal.exe1776 Internet ISP software - what does it do and is it required?
    %FP%AIRTEL fts.exeUfts.exeRelated to AIRTEL-Broadband Part of the Friendly technologies PPPOE DSL Driver. This is customized for use with the AIRTEL-Broadband ISP. Note: Located in \%Program Files%\AIRTEL\AIRTEL-Broadband\
    %FP%Barak013 fts.exe?fts.exe Barak013 ISP software - what does it do and is it required?
    %FP%Barak013 FWPortal.exe?FWPortal.exe Barak013 ISP software - what does it do and is it required?
    %FP%Friendly fts.exe?fts.exeFriendly ISP software - what does it do and is it required?
    (*)API MachineXwinSOCKS.exeHomepage hijacker, see here (* = any digit)
    (*)RunXwin32API.exeHomepage hijacker, see here (* = any digit)
    (default)X(random filename).exeAdded by the BLACKMAL VIRUS!
    (Default)XSystrsy.exe Added by the Trojan.Cdtray TROJAN! Note: This trojan file is found in the Internet Explorer folder.
    (default)Xllsass.exeAdded by the TROJ/PROXY-GG TROJAN!
    (Default)Xwebcam.exeAdded by the Troj/Monad-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    (Default)Xsyspol.exeAdded by the Dremm.b TROJAN!
    (default)Xrundll32.exe (path to) Zykheptd.dllAdded by the Backdoor.Hesive.B TROJAN! Read the link, rootkit type stealth involved.
    (Default)X5640.exe Troj/DownLd-ABF
    (Entry name)XSystem.exeAdded by the Troj/Nethief-N Trojan!
    (Global Startup)XSkunk.exeAdded by the W32/Sunk-A WORM! Note: This worm\trojan file is found in the Root folder. (C:\), (D:\), (E:\) etc, etc.
    (L4r1$$4) (4nt1) (V1ruz)XSP00Lsv32.pifAdded by the ASSIRAL.B WORM!
    (original file name)Xsvchost.scrAdded by Troj/Bancban-CX and Troj/Bancban-DA TROJANS! Read the link, keylogger/password stealing TROJAN(S) involved.
    (original filename)Xxphost.scrAdded by the Troj/Bancban-HM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Read the link, keylogger/password stealing TROJAN(S) involved.
    (Original Trojan Filename)Xinstall.exeAdded by the Troj/Bancban-FS TROJAN! Note: This trojan file is found in the Windows or Winnt folder. Read the link, keylogger/password stealing TROJAN(S) involved.
    (random 12 digit number)Xactxprxy.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavicap32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbrowser8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavifile5.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcdmodem4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xacctres8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xautodisc.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcabview1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xatitvo32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadvpack1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbatmeter.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbidispl2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xasferror.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcatsrvps.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xaudiosrv.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadmparse.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcmpbk321.exe Adsrv.com/IeDriver adware variant
    (Random characters)Xsecurewinload32x.exeAdded by the Troj/OptixP-N TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted.
    (random filename - format **-**-**-**-**)Xdwdsregt.exeAdded by Adware.ZenoSearch ADAWARE!
    (random filename - format **-**-**-**-**)Xqndsregn.exeAdded by ZenoSearch ADAWARE!
    (random filename)Xslk8x2peu.exeAdded by QuickLinks_Process ADAWARE!
    (random name)Xiexpl0ra.exe TROJ_ULPM.BD
    (Random Name)Xcsrssc.exeIdentified as a variant of the Win32/TrojanDownloader.Small.CYF malware. Note: Located in \%Temp%\ Note: Use SDFix under supervision.
    (Random number)Xexplorer.exeAdded by the Troj/Keylog-AN TROJAN! Note: This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder. Keylogger/password stealing TROJAN(S) involved.
    (Random number)Xexplorer.exeAdded by the Troj/Keylog-AN TROJAN! Note: This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder. Keylogger/password stealing TROJAN(S) involved.
    (random)Xlsass.scrAdded by Troj/Bancban-CW TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    (random)Xsvchost.scrAdded by Troj/Bancban-CY Trojan! Read the link, keylogger/password stealing TROJAN(S) involved.
    (Random)Xsvshost.exeAdded by the W32/Kelvir-AX WORM! Note: This worm\trojan file is found in the System\(random folder name) (95/98/ME) or System32\(random folder name) (NT/2000/XP) folder.
    (random)Xsvchost.exeAdded by the Troj/Bancban-JC TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    (Randomly chosen existing folder name)X_cfg.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_login.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_start.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_config.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_autorun.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_loader.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_env.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_setup.exeAdded by the W32/Antinny-L WORM!
    (Registry Value Name)Xroses.exeAdded by the W32/Rbot-AFT Worm! Read the link, keylogger/password stealing TROJAN(S) involved.
    (unknown)Xcharmapnt.exeAdded by the Troj/Bancos-DR TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    (User name) configX(Path to Trojan exe)Added by the Troj/Mosuck-H TROJAN!
    (various file names)Xmediaplayer32.exeAdded by a variant of the WIN32.RBOT WORM!
    (various file names)Xbling.exeAdded by the W32/RBOT-NI WORM! Read the link, keylogger/password stealing TROJAN(S) involved.
    (various names)Xwin32snd.exeAdded by the W32/RBOT-DQ WORM!
    (various names)Xsvchostss.exeAdded by a variant of the WIN32.RBOT WORM!
    (various names)XPasswdMon.exeAdded by Wareout Rogue Software
    (various names)Xrunload32.exeAdded by Wareout Rogue Software
    )Start ServiceUupssrv.exeCyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner."
    *Xtwain_32.exeIdentified as Trj/Downloader.SV by Panda. TROJAN! Note: located in \%WINDIR%\
    ******** (* = random char or digit)Xrsbmsc.exeAdded by what AntiVir antivirus detects as the BDS/Agent.adt TROJAN!
    *BandookXmsdll.exeAdd a variant of the Trojan/Backdoor TROJAN! Note: Located in \%WINDIR%\System32\
    *JanisRuckenbrodIIXjanis.comAdded by the POPS VIRUS!
    *Microsoft UpdateXwucxt.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwuytc.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXctxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwstcl.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXcxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *microsoft updateXcxma.exeAdded by the W32.HLLW.STMU TROJAN
    *MS SetupX[random file name]Virtumondo adware, also known as the VUNDO TROJAN!
    *MSConfig32Xaecache.exe Detected as Trojan.Win32.Obfuscated.gp by F-secure
    *Security CenterXsecctr.exeAdded by the SDBOT.BRO WORM!
    *StateMgrYstatemgr.exeWindows ME default for System Restore. Do NOT disable!
    *WerKernelReportingNWerFault.exeRelated to Windows_Error_Reporting technology (WER) on Vista Computers. WER captures software crash and hang data from end-users who agree to report it. Note: Located in \%WINDIR%\System32\
    *windows updateXwurauclt.exeAdded by the W32/RBOT-SY WORM!
    *windows updateXwsctl.exeAdded by the SPYBOT.PR WORM!
    *windows updateXwscxt.exeAdded by the RBOT.AOS WORM!
    *windows updateXwkmst.exeAdded by the SDBOT.AVD WORM!
    *windows updateXwuaucrlt.exeAdded by the SPYBOT.HUR WORM! Read the link, keylogger/password stealing TROJAN(S) involved.
    *windows updateXwaurclt.exeAdded by a variant of the WIN32.RBOT WORM!
    *WinLogonX[trojan path] ren time:[random number]Added by the VUNDO TROJAN!
    *winstatsXwinstats.exeAdded by the Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
    *wuauclt.exeXw****.exe (* = random char)Added by a variant of the W32/RBOT-UG WORM! - NOTE: * in the file name represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
    *wuauclt.exeXwmsvc.exeAdded by the W32/RBOT-UG WORM! Read the link, keylogger/password stealing TROJAN(S) involved.
    ,main drive LoaderXwininfo.exeSuspected malware as it appears in 3 different registry locations - see here
    -FreedomNeedsRebootYZkRunOnceR.exeRelated to Internet_Security_Suite used by Internet providers to protect customers against many attacks. Read the article Note: Located in \%Program Files%\(Internet provider)\(Internet provider) Internet Security Suite\
    ..XABC2007.exeAdded by the Troj/Dloadr-ASH TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    .mscdrXlassa.exeAdded by the WEBUS.C TROJAN!
    .mscdrXlsvchost.exeAdded by the WEBUS.D TROJAN!
    .mscdsrXlsvchost.exeAdded by the Troj/Bdoor-CR Trojan!
    .mscsblXsvhost.exeAdded by the BACKDOOR-CMQ TROJAN!
    .msfupdateXmsveup.exeAdded by the W32.ALLOCUP.A WORM!
    .mssecureXmssecure.exeAdded by the DDOS_BOXED.X TROJAN!
    .mssecureXmssecure.exeAdded by the Troj/Borobot-B Trojan!
    .NET config?sysmon32.exe??
    .NET.Xmsnmgnr.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    .nortonXrchost.exeAdded by a variant of the BOXED-A TROJAN!
    .nvsvcXsmss.exeAdded by the BackDoor-CXT TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System (XP/WinNT/2K) and not in it's System32 subdirectory, as is the case with the legitimate Smss.exe system file.
    .nvsvcbXsmssb.exeAdded by the Win32/Boxed.CG TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) Will attempt to disable antivirus, firewall and Windows Update software
    .ProgXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process
    .ProgXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    .protectedX(no name)Added by a Smithfraud infection.
    .svchostXCSRSS.EXEAdded by the WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    .TEXTCONVXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    .WMAudioXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process" which provides text window support, shutdown, and hard-error handling
    .WMAudioXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    /l:engNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup
    000Upit.exeAdded by the PrivateEye SPYWARE! **Note - If you did not intentionally install this remove it.
    0006 - C:Documents and SettingsCompaq_OwnerStart
    MenuProgramsHP Internet Connection Center
    Ncommand.comRelated to HP_Internet_Connection_Center provides access to a variety of valuable offers from Internet Service Providers.
    0008 - C:Documents and SettingsCompaq_OwnerStart
    MenuProgramshp deskjet 990c series v3.0
    Ncommand.comRelated to HP_Internet_Connection_Center provides access to a variety of valuable offers from Internet Service Providers.
    000hpdllhosXhpdllhost.exe LZIO.com adware downloader
    000StTHKU000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
    0050726-007-i32-1X0050726-007-i32-1.exeAdded by the Troj/Bancban-EC TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    00DSKSVR00Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00DSKSVR01Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00ERSRRRNKYUeraser.exeRelated to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here
    00ERSRRRNKYUerasrv.exeRelated to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here
    00PCTFWYFirewallGUI.exeRelated to PC_Tools Firewall. Note: Located in \%Program Files%\PC Tools Firewall Plus\
    00TCrdMainYTCrdMain.exeRelated to flash_card slot on the Toshiba laptop. Ending this process will disable access to the flash cards. Note: located in %ProgramFiles%\TOSHIBA\FlashCards\
    00THotkeyU00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    00THotkeyUsystem32THotkey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    0190 WarnerUWARN0190.EXEAnti-dialer program (Germany)
    0900 WarnerUWARN0900.EXEAnti-dialer program (Germany)
    09734482329566253820889118044258Xav2009.exeAdded by the Antivirus_2009 rogue anti-spyware program. Note: Located in \%Program Files%\Antivirus 2009\
    0mcamcapX0mcamcap.exeAdded by Troj/Cosiam-H TROJAN! Prevx identifies it has Haxdoor Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    0utlook ExpressX*****.exe (where * = random char)Added by the W32/RBOT-CC WORM!
    1X1.exeAdded by the ESTEEMS TROJAN!
    1Xsvchost.scrAdded by PWSteal.Bancos.X Trojan. Read the link, keylogger/password stealing TROJAN(S) involved.
    1X lsass.scrAdded by the PWSteal.Bancos.V TROJAN! Read the link, keylogger/password stealing TROJAN(S) involved.
    1Xmrcmgr.exeIdentified as a variant of the Trojan-Banker.Win32.Banker.rqk malware. Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    1&1 EasyLoginUEasyLogin.exeRelated to 1&1_EasyLogin an Internet Provider. Note: Located in \%Program Files%\1&1\1&1 EasyLogin\
    101ClipsU101Clips.exeRelated to 101Clips 101 is the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. Note: Located in \%Program Files%\101 Clips\
    1029BB4B-16A9-4E77-AA3D-96930BD68EECXsysockeu.exeAdded by the SmitFraud Trojan
    108Mbps Wireless LAN AdapteUTRENDnet.exeRelated to TRENDnet Wireless LAN Adapter. Note: Located in \%Program Files%\TRENDnet\Model number\
    11Xfaxcomdos.exeAdded by the Tuimer TROJAN!
    1111swapmgr.exeX1111swapmgr.exeAdded by the BDOOR-IC TROJAN!
    123456Xrundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) VIRUS! 123456 can be any random 3 to 6 digit number
    1234567Xsvcost.exeAdded by the Backdoor.Bifrose.YA family of trojan. Note: This worm\trojan is located in C:\%WINDIR%\System32\dllcache\ (XP/WinNT/2K)
    1234klsjdc uiar924c afXsxgnsvuxct.exeAdded by the Smitfraud Trojan
    1290A33C-85F5-4164-A1BE-7DD299D4986AUPBKScheduler.exeScheduler for CyberLink PowerBackup - archiving/backup utility
    12EE7A5E-0674-42f9-A76B-000000004D00Xrundll32.exe stlb2.dll,DllRunMain BrowserAid/BrowserPal Foistware
    12Ghosts Popup-KillerU12popup.exe12Ghosts Popup-Killer
    12Ghosts ShowTimeU12showtime.exeRelated to 12Ghosts Power Tools for Windows users. Note: Located in \%Program Files%\12Ghosts ShowTime\
    12Ghosts SynchronizeU12sync.exeRelated to 12Ghosts Power Tools for Windows users. Note: Located in \%Program Files%\12Ghosts ShowTime\
    17779Proj2002?N/A??
    180adsolutionX180adsolution.exencase adware
    180axX180ax.exencase adware
    180ClientStubInstallXstubinstaller****.exe (* = digit) 180Solutions adware related
    180ClientStubInstallX******.exe (* = random digit/character) 180Solutions adware related
    180ClientStubInstallX******.tmp (* = random digit/character) 180Solutions adware related
    1916435341.exeX1916435341.exe Troj/Dloadr-AXU
    196_150_niX196_150_ni.exeAdded by WinSoftware/WinFixer.Process TROJAN!
    197_150_ni_3X197_150_ni_3.exeA variant TROJAN!
    1:Nhpdrv.exeHP utility for monitoring when and how many recoveries have been done
    1A:MacVisionTrayMonitorNTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
    1A:Stardock MCPYmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
    1A:Stardock TrayMonitorYTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
    1CmailS?NETMAIL.EXE??
    1on1X1on1.exeAdult content dialler
    1Srv32USpyAgent4.exeSpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
    1u7X1u7.exeAdded by the Troj/Murbac-A TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K)
    1Win32CfgUSpyBuddy.exe SpyBuddy monitoring software. Read the link, keylogger/password stealing trojan(s) involved.
    1Win32CfgUKeyloggerpro.exe Keyloggerpro monitoring software. Read the link, keylogger/password stealing trojan(s) involved.
    1WinCfg32X"\WebMailSpy.exeAdded by WebMailSpy SPYWARE!
    2020DownloaderXmssvr.exe 2020Search Toolbar
    2177F056-0AA6-4D6C-A944-13F71F341C29Xsysokuaw.exeAdded by the SmitFraud Trojan
    24Online ClientUCyberoamClient.exeRelated to Cyberroam from Elitecore Technologies Ltd. Note: Located in \%Program Files%\eLitecore\Cyberoam Client for 24Online\
    250Xwinmgr.exeAdded by the Troj/LegMir-AT TROJAN! Read the link, keylogger/password stealing trojan(s) involved.
    27Xslsorve.exeAdded by the SLSORVE-A TROJAN!
    27Xcsrss32.exeAdded by the TROJ/SLSORVE-D TROJAN!
    27Xmsm32.exeAdded by the TROJ/SLSORVE-E TROJAN!
    2CF0B992-5EEB-4143-99C0-5297EF71F444Xrundll32.exe stlbdist.dll, DllRunMain BrowserAid/BrowserPal Foistware
    2CF0B992-5EEB-4143-99C2-5297EF71F44BXrundll32.exe stlbupdt.DLL, DllRunMain BrowserAid/BrowserPal Foistware
    2chkdskX******.dll VirtuMonde/Vundo adware variant
    2kadirasY2kadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    2SearchXmain.exeAdded by Adware.2Search ADAWARE! Note: located in C:\Program Files\2search\
    2thousandbuckX(path to file)Added by the RANKY.L TROJAN!
    2wSysTrayU2portalmon.exe2Wire Homeportal user interface
    32-bit Thunking serviceXthunk32.exeAdded by the W32.Derdero.A WORM!
    333Xsvchost.exe Troj/JD-A Read the link, steals information
    357AA41A-B7A8-4632-A27D-5B980B25CF43X[path to svchost.exe]Added by the SMALL-AQ TROJAN!
    357AA41A-B7A8-4632-A27D-5B980B25CF43Xservices.exeAdded by FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    36X Raid ConfigurerYJMRaidSetup.exeRelated to Raid_Configurer Disk Partitioning Setup. Note: Located in \%WINDIR%\System32\
    388529725448XAutomaticUpdates.exe W32/Sdbot-DEN Read the link, allows remote access
    38921398152773197389309440455459Xav2009.exeAdded by the Antivirus_2009 rogue anti-spyware program. Note: Located in \%Program Files%\Antivirus 2009\ Note: Use SDFix under supervision. Note: Random numbers in the Start up name.
    3c1807pdY3cmlink.exe 3cpipe-3c1807pd3Com WinModem driver. See here for more WinModem information
    3capplnkY3capplnk.exeUS Robotics Modem driver
    3cdminicN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3CM LinkY3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it.
    3CmlinkY3CmlinkW.exeFor a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
    3ComDMIAgentN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3D TextN3D Text.scrAdded by the JERMY.A VIRUS!
    3Deep Control PanelU3DeepCTL.EXEFrom LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games
    3Dfx AccXGFXACC.EXEAdded by the GIBE VIRUS!
    3dfx Task ManagerN3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
    3dfx ToolsY3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
    3dfxv2ps.dllY3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
    3Dlabs Taskbar Display Manager?3DLman.exe3DLabs graphics driver related. System Tray access to display settings?
    3DLabsHelperDemonU3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
    3DMouse.EXEY3DMouse.EXEDritek System Inc. 3D Mouse driver
    3d_soundX3d_sound.exeAdded by the Troj/Riados-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    3P_UDECXAntvrsInstall.exeInstaller for the Antivirus_2008 rogue anti-spyware program. Note: Use Malwarebytes RogueRemover tool.
    3qdctl.exeU3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
    3ware 3DMY3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
    4684735485910Xnetdll32.exe W32/Sdbot-DEV Read the link, allows remote access
    4da92ad5.exeX4da92ad5.exe Troj/Dloadr-WZ
    4oDUKHost.exe Kontiki_Delivery_Manager - Windows-based client software that enables secure delivery of content to users' desktops
    4wd!!!XNatal!.pifAdded by the OPASERV.AI VIRUS!
    5-1-61-96Xmembers-area.exeAdult content dialler
    5-2-46-112X5-2-46-112.exeAdult content pop-up dialler. Removal instructions here
    55278Xgrepclient1.exeAdded by the Troj/Lineage-S Trojan! Read the link, keylogger/password stealing trojan(s) involved.
    5p4mX(Path to Trojan)Added by the Troj/Litebot-C TROJAN!
    666XSka.exeAdded by the Troj/Pipes TROJAN!
    678Xlsas32.exeAdded by the Troj/Slsorve-C TROJAN!
    756349DC-6D9E-4F2A-9B24-269661F073C3Xsysoghcx.exeAdded by the SmitFraud Trojan
    7f8eXz****.exe 9idfDetected by NOD32 as Win32/TrojanDropper.Small.ALI , Note: it creates a number of extra z****.dll files in the system32 folder
    7v3jXz1844.exe gdtghAdded by an unidentified TROJAN! Note: of the Win32/Rbot Family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) The file name is random z(Random Number).exe followed by gdtgh
    802.11b+g USB Wireless LAN UtilityUZDWlan.exeRelated to USB_Wifi_device Wireless Lan. Note: Located in \%Program Files%\WLAN\802.11b g USB WLAN\
    802.11g Wireless AdatperUMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled.
    85Xrundl132.exeAdded by the Troj/Gampass-L TROJAN! Note: This worm\trojan is located in C:\%WINDIR%\TEMP\ Monitor user activity and log keystrokes. It also attempts to suppress detection alerts for an anti-virus product (random key name).
    852EBF20-A95D-4F1F-B9C2-B2CD24350F3EXsysodkcs.exeAdded by the SmitFraud Trojan
    98D0CE0C16B1Xrundll32.exe D0CE0C16B1,D0CE0C16B1 BrowserAid/BrowserPal Foistware
    9mXwinlog0n.exe Troj/LegMir-AQK Read the link, steals information
    9xadirasY9xadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    9xHtProtectXAVprotect9x.exeAdded by the W32.NETSKY.M WORM!
    ;RundllX(random filename)Added by the PWSLEGMIR.E VIRUS!
    XRegsrv32.comAdded by the SOUTHGHOST VIRUS!
    XApp.exeAdded by the WAXPOW VIRUS! where <filename> is the executed filename
    Xwincpu.exeAdded by an unidentified VIRUS!
    Xelf.exeElf is a hacker program, tied to a trojan server
    ??QQ?QQ.exeRelated to QQ_IM program popular in China. (It's similar to MSN Messenger.) there are many add-ons created for QQ and of course, some add-ons are malware. If you didn't get his QQ from the official site, or you installed some add-ons it is suggested that you remove it and have install a fresh copy from the official Tencent Inc. site. Note: Located in \%Program Files%\Tencent\QQ\
    ?ekio StartupsX?nksvc32.exeAdded by the W32/AGOBOT-OV WORM! Read the link, keylogger/password stealing trojan(s) involved.
    @Xregedit -s ..win.dllAdded by the SEEKER.K VIRUS!
    @Hoc ToolbarNAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
    @lohaNreminder.exeRegistration reminder for @loha@home E-mail utility
    @tour_wwX@tour_ww[1].exeAdult content dialler
    aXa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
    aXjesse.exeAdded by the W32/Melo-A WORM! Note: This worm file is found in the system32\drivers\etc folder.
    A New Windows UpdaterXw32NTupdt.exeAdded by W32.Mytob.BM WORM!
    A NoteUA Note.exeRelated to A_Note A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop. Note: Located in \%Program Files%\A Note\
    A Verizon AppUVERIZO~1Related to Verizon_Online Help support/ Note: Located in C:\PROGRA~1\VERIZO~1\HELPSU~1\
    a-squaredUa2guard.exe a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the aČ 'Background Guard' real time protection feature
    a-winpoet-serviceYwinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
    A1000 Settings UtilityUcpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
    A4ProxyUA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
    A70F6A1D-0195-42a2-934C-D8AC0F7C08EBXrundll32.exe E6F1873B.DLL,D9EBC318C BrowserAid/BrowserPal Foistware
    aa bbcc dde effgghh jjXupdate.exeAdded by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision.
    AAACLEAN?AAACLEAN.INF??
    AAAKeyboard?????
    AAATraySaverNTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
    AAKUaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"