Start-Up Applications - All

Last database update :- 31st March, 2009
18311 items listed

Introduction

This page presents a comprehensive list of the programs you may find that run when you switch on your PC as typically identified by MSCONFIG or the registry "Run" keys - and whether you need them.

Close Program/Task Manager

This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Operating System Differences

A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry.

To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions.

Random startup entry/filename viruses

There are viruses and other pests that can add any number of different entries to the startups. They make additional entries under the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run and RunOnce keys, allowing them to run at startup.

  1. PE_BISTRO - adds "XXXX"="C:\WINDOWS\XXXX.EXE" - where XXXX is the randomly chosen filename of the dropped file
  2. MAGISTR.A - adds "[Virus file name]"="[Virus Path and file name].EXE"
  3. BUGBEAR.A or BUGBEAR.C or BUGBEAR.E - adds ""=%System%\"[random filename].EXE"
  4. OPTIXPRO.11 - adds "%Registry entry%"="%Path%\%Filename%"
  5. Lop.com homepage hijacker - adds multiple and random startup entries
  6. FreeScratchAndWin - adds multiple and random startup entries as it includes LOP above
  7. nCase (or n-Case) parasite - adds multiple and random startup entries
  8. LORAC - adds "[four random characters]"="%Sysdir%\abcdef.exe"
  9. MOSUCK - random name and filename in C:\Windows or C:\Winnt
  10. DEBORMS.D - adds one of a number of valid Name/Startup Item entries but points to the path of the worm file dropped
  11. GIBE.C - adds random name and filename in C:\Windows or C:\Winnt
  12. SWEN.A - adds random name and filename
  13. ZOMBAM.B - adds random name and filename
  14. WANADO or REUR - adds "XXXXXXXX"="%Sysdir%\XXXXXXXX.exe" where X can be any random hexadecimal (0-9, A-F) number
  15. SINCOM - adds random name and filename in C:\Windows or C:\Winnt with "Run:Auto" appended to the command/data column entry
  16. SOBER family - adds "[random string]"="%system%\[random filename.exe]"
  17. BRANCOS.C - adds "win_[4 random characters][4 random numbers 0-9]"="%System%\SYS_386X\[4 random characters][4 random numbers 0-9].exe"
  18. IRC.BOT.B - adds random name and filename
  19. COREFLOO-C - adds "[random filename]"="rundll32 %SYSTEM% [random filename].dll,Init 1"
  20. [random digits].exe = [random digits].exe - 8 random digits, example: 77231997.exe = 77231997.exe. Winpup.exe adult content downloader
  21. DRAGONQQ - "[Trojan's filename]"="[Path to the Trojan]", "[Random name]"="C:\WINNT\[Random name].exe", "[Random name]"="C:\Program Files\[Random name].exe" or "[Random name]"="C:\WINDOWS\[Random name].exe"
  22. FORMADOR - adds "[executed file name]"="%System%\[executed file name].exe"
  23. NETTRASH - adds "[file name]"="[path to filename].exe"
  24. OPTIXPRO.13B - adds "[registry value name]"="[path to trojan].exe"
  25. MYDOOM.F or MYDOOM.G or MYDOOM.H - adds "[4 to 8 random, lowercase letters]"="[worm filename]"
  26. ANNIL - adds random name and filename
  27. ANTINNY.G and ANTINNY.K - adds "[random name]"="[path to worm]"
  28. KILLAV.D - adds "[Trojan filename]"="%Windir%\[Trojan file name]" where %Windir% is C:\Windows or C:\Winnt
  29. MYPOO - adds "[value name]"="[Trojan file name]" where [value name] is configurable
  30. BLACKMAL or BLACKMAL.B - adds "[random_file_name1].exe"="%System%\[random_file_name1].exe"
  31. ERKEX.A - adds "[random_file_name]"="%System%\[random_file_name].exe"
  32. OPASA - adds "[random_file_name]"="%System%\[random_file_name].exe"
  33. GAOBOT.ADN - adds random name and filename
  34. ADWAHECK - adds "[trojan name]"="%System%\[trojan filename]"
  35. GOBOT.A - adds random name and filename in C:\Windows or C:\Winnt
  36. Sandboxer adware - adds random name and filename
  37. AGENT.B - adds "[1-5 random characters]"="RUNDLL32 %System%\[DLL filename].dll,StreamingDeviceSetup"
  38. EXRUNTEL - adds "[original filename]"="%System%\[original filename]"
  39. Margoc adware - adds random name and filename
  40. Winpup adware - adds random name and filename in %System%
  41. KETCH - adds "[word]"="%System%\[word][number].exe"
  42. DARBY.B - adds "[random worm filename]"="%System%\[random worm filename]"
  43. VUNDO - adds "*[trojan name]"="[trojan path]"
  44. BEAKER.A - adds "[5 random lower-case char]"="[5 random lower-case char].exe" in the System, system32, Temp and Fonts sub-directories of %Windir%
  45. LIFEFORENOW - adds "[random filename]"="%System%\[random filename].exe"
  46. DIMI - adds "[random value name]"="%System%\[random filename].exe"
  47. ABEBOT - adds "[random service name]"="[random filename].exe -services"
  48. OMEGA - adds "[random value]" = "%Windir%\[random file name].exe"
  49. NAMSHARE - adds "[Random service name]" = "[Random file name]"
  50. REANET.B - adds "[file name]" = "[path to file name]"
  51. BANCOS.Q - adds "[filename prefix]" = "[path to filename]"
  52. SPYBOTER.GEN - adds "[key name]" = "[file name of Trojan]"
  53. BOTUK - adds "[random characters]Srv32" = "[random characters]srv.exe"
  54. MADTOL-A - adds "[trojan filename]" = "%System%\[trojan filename]"
  55. HESIVE - adds "[trojan filename]" = "[path to trojan]"

Spyware/Adware/Malware/Foistware & Hijackers

If you want to know more about these types of programs why not start with a search at Wikipedia - the free, community maintained online encyclopedia. Then visit the Safer Networking and BleepingComputer malware forums.

o-----------------------------o

Key:

Variables:

Status Name/Startup Item Command Comments Tested
Xsystem32.exeAdded by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name fieldNo
Xpathex.exeAdded by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name fieldNo
Xsvchost.exeAdded by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name fieldNo
XMSPF.EXEAdded by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name fieldNo
Xdllvirtual.exeAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
Xdllvirtual.dllAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
Xdllvirtual.jsAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
Xajsha5.exeAdded by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name fieldNo
Xne.exeAdded by the IRCBOT-ZL TROJAN!No
Y!1_pgaccountpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properlyNo
Y!1_ProcessGuard_Startupprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacksNo
Y!AVG Anti-Spywareavgas.exeMain application of AVG Anti-Spyware 7.5 from AVG Technologies (was Grisoft). Now superseeded by AVG Anti-Virus which includes Anti-SpywareNo
Y!ewidoewido.exePart of Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseeded by AVG Anti-Virus which includes Anti-SpywareNo
N!NoLoadwinrecon.exeWinRecon keystroke logger/monitoring program - remove unless you installed it yourself!No
U$EnterNetEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOENo
X$sys$cmp$sys$xp.exeAdded by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computerNo
X$sys$crash$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!No
X$sys$crash$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!No
X$sys$crash$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!No
X$sys$drv$sys$drv.exeAdded by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computerNo
X$sys$momomomochin$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!No
X$sys$momomomochin$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!No
X$sys$momomomochin$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!No
X$sys$umaiyo$sys$sonyTimer.exeAdded by the WELOMOCH TROJAN!No
X$sys$umaiyo$sys$sos$sys$.exeAdded by the WELOMOCH TROJAN!No
X$sys$umaiyo$sys$WeLoveMcCOL.exeAdded by the WELOMOCH TROJAN!No
U$Volumouse$volumouse.exeVolumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse"No
X$WindowsRegKey%updateIEXPLORE.EXEAdded by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
?%cmpmixtitle%%cmpmixstr%Possibly related to C-Media Mixer Control panel?No
N%FP%012-L2TP fts.exefts.exe012.Net.il Israeli ISP software front-endNo
U%FP%012-L2TP FWPortal.exeFWPortal.exe012.Net.il Israeli ISP dial-up softwareNo
N%FP%1776 Internet fts.exefts.exe1776 Internet US ISP software ISP software front-endNo
U%FP%1776 Internet FWPortal.exeFWPortal.exe1776 Internet US ISP dial-up softwareNo
N%FP%AIRTEL fts.exefts.exeBharti Airtel Broadband - Indian ISP software front-endNo
N%FP%Barak013 fts.exefts.exeBarak013 Israeli ISP software front-endNo
U%FP%Barak013 FWPortal.exeFWPortal.exeBarak013 Israeli ISP dial-up softwareNo
N%FP%Friendly fts.exefts.exeFriendly ISP software front-endNo
X\NvCpTDaemonwuauqmr.exeAdded by the CULT-B WORM!No
UµTorrentutorrent.exeµTorrent - BitTorrent client for Windows sporting a very small footprint. It was designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clientsNo
X WinCheckservices.exeAdded by the SOBER.V WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus\Microsoft and note the space at the beginning of the "Startup Item" fieldNo
X Windowsservices.exeAdded by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\WinSecurity and note the space at the beginning of the "Startup Item" fieldNo
X WinStartservices.exeAdded by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Connection Wizard\Status and note the space at the beginning of the "Startup Item" fieldNo
X winsystem.syssmss.exeAdded by the SOBER.K WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\msagent\win32 and note the space at the beginning of the "Startup Item" fieldNo
Y'Ashampoo AntiSpyWare 2 Guard'AntiSpyWare2Guard.exePart of Ashampoo® AntiSpyWare 2 from Ashampoo GmbH & Co. KG. This part is the realtime monitor that looks for changes on the users system such as BHO, Winsock LSPs, Windows Hosts file, Autostart entries, etcYes
X(*)API MachinewinSOCKS.exeHomepage hijacker, see here (* = any digit)No
X(*)Runwin32API.exeHomepage hijacker, see here (* = any digit)No
X(Default)media_driver.exeAdded by the TUPEG VIRUS! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)Shania.vbsAdded by the SHANIA BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)NOTEPAD.exeAdded by the RUSTY WORM! Note - not to be confused with the valid Windows "NOTEPAD" text editor! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)[random filename].exeAdded by the BLACKMAL WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)twunk_32.exeAdded by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)winhelp.exeAdded by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)spolsvr2.exeAdded by the EVILSOCK.10 TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)winbas12.exeAdware, CoolWebSearch parasite related - detected by Kaspersky as the VB.DU TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)Systrsy.exeAdded by the CDTRAY TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)llsass.exeAdded by the PROXY-GG TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)syspol.exeAdded by the DREMN-B TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)winlog.exeUnidentified adware. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(default)rundll32.exe [path to DLL file],Do98WorkAdded by the HESIVE.B TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)winligom.exeAdded by the RBOT-GAI WORM! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)5640.exeAdded by the DOWNLD-ABF TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run, HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)QQUpdate.exeAdded by the QUADRULE.A WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)Mcafee.exeDetected by Kaspersky as the AGENT.AY TROJAN! See here. Note - this is not a valid McAfee program and is located in %System%. This malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(Default)fada.exeDetected by Trend Micro as the VB.HEI TROJAN! See here. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run and HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
X(L4r1$$4) (4nt1) (V1ruz)SP00Lsv32.pifAdded by the ASSIRAL.B WORM!No
X*Bandookmsdll.exeAdded by an unidentified TROJAN - see hereNo
X*JanisRuckenbrodIIjanis.comAdded by the POPS WORM!No
X*Microsoft Updatectxma.exeAdded by the STMU TROJAN!No
X*Microsoft Updatecxma.exeAdded by the STMU TROJAN!No
X*Microsoft Updatewstcl.exeAdded by the STMU TROJAN!No
X*Microsoft Updatewucxt.exeAdded by the STMU TROJAN!No
X*Microsoft Updatewuytc.exeAdded by the STMU TROJAN!No
X*MS Setup[random filename]Virtumondo adware, also known as the VUNDO TROJAN!No
X*MSConfig32aecache.exeDetected by F-Secure as the OBFUSCATED.GP TROJAN!No
Y*Restorerstrui.exePart of Windows System Restore and added as a RunOnce registry entry. Leave aloneNo
X*Security Centersecctr.exeAdded by the SDBOT.BRO WORM!No
Y*StateMgrstatemgr.exeWindows ME default for System Restore. Do NOT disable!No
N*WerKernelReportingWerFault.exePart of Windows Error Reporting technology (WER) for Vista. WER captures software crash and hang data from end-users who agree to report it - see hereNo
X*windows updatewrauclt.exeAdded by the RBOT-QU WORM!No
X*windows updatewuanclt.exeAdded by the RBOT-PG WORM!No
X*windows updatewuaucrlt.exeAdded by the SPYBOT.HUR WORM!No
X*windows updatewuraclt.exeAdded by the RBOT-PO WORM!No
X*windows updatewurauclt.exeAdded by the RBOT-SY WORM!No
X*windows updatewsctl.exeAdded by the SPYBOT.PR WORM!No
X*windows updatewkmst.exeAdded by the SDBOT.AVD WORM!No
X*windows updatewscxt.exeAdded by the RBOT.AOS WORM!No
X*windows updatewaurclt.exeAdded by a variant of the RBOT WORM!No
X*Windows [filename] Checker[filename]Added by the KEDEBE-B WORM!No
X*WindowsAudiosystemupd.exeAdded by the AGENT-TH WORM!No
X*WinLogon[trojan path] ren time:[random number]Added by the VUNDO TROJAN!No
X*winstatswinstats.exeAdded by the GARGAFX TROJAN!No
X*wuauclt.exew****.exe [* = random char]Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...No
X,main drive Loaderwininfo.exeSuspected malware as it appears in 3 different registry locations - see hereNo
X-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ISASS.exeAdded by the ASSIRAL.B WORM!No
Y-FreedomNeedsRebootZkRunOnceR.exeInternet Security Suite used by ISPs to protect customers against many attacksNo
X..ABC2007.exeAdded by the DLOADR-ASH TROJAN!No
X.mscdrlassa.exeAdded by the WEBUS.C TROJAN! No
X.mscdrlsvchost.exeAdded by the WEBUS.D TROJAN!No
X.mscdsrlsvchost.exeAdded by the BDOOR-CR BACKDOOR!No
X.mscsblsvhost.exeAdded by the CMQ TROJAN!No
X.msfupdatemsveup.exeAdded by the ALLOCUP.A WORM!No
X.mssecuremssecure.exeAdded by the DDOS_BOXED.X TROJAN!No
?.NET configsysmon32.exe??No
X.NET.msnmgnr.exeAdded by the DELF.AYF WORM!No
X.nortonrchost.exeAdded by the BOXED-H TROJAN!No
X.nvsvcsmss.exeAdded by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! No
X.nvsvcbsmssb.exeAdded by the BOXED.CG TROJAN!No
X.Progservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup!No
X.Progwinlogon.exeAdded by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup!No
X.protectedN/ASmitfraud variantNo
X.svchostCSRSS.EXEAdded by the WEBUS.F TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
X.TEXTCONVcsrss.exeAdded by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
X.TEXTCONVlsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folderNo
X.WMAudiocsrss.exeAdded by the WEBUS TROJAN! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!No
X.WMAudiolsass.exeAdded by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folderNo
N/l:engN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search functionNo
U000pit.exePrivateEye surveillance software. Uninstall this software unless you put it there yourselfNo
X000hpdllhoshpdllhost.exeLZIO.com adware downloaderNo
U000StTHK000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)No
X0050726-007-i32-10050726-007-i32-1.exeAdded by the BANCBAN-EC TROJAN!No
?00DSKSVR00desksaver.exeRelated to Advanced Desktop ShieldNo
?00DSKSVR01desksaver.exeRelated to Advanced Desktop ShieldNo
Y00PCTFWFirewallGUI.exeSystem Tray access to PC Tools Firewall Plus from PC Tools - which "is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"Yes
Y00TCrdMainTCrdMain.exeRelated to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cardsNo
U00THotkey00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.No
U00THotkeysystem32THotkey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prevNo
U0190 WarnerWARN0190.EXEAnti-dialer program (Germany)No
U0900 WarnerWARN0900.EXEAnti-dialer program (Germany)No
X0mcamcap0mcamcap.exeAdded by the COSIAM-H TROJAN! No
X0utlook Express*****.exe [* = random char]Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o"No
X11.exeAdded by the ESTEEMS TROJAN!No
X1lsass.scrAdded by the BANCOS.V TROJAN! No
X1svchost.scrAdded by the BANCOS.X TROJAN!No
X1mrcmgr.exeDetected by Kaspersky as the BANKER.RQK TROJAN! See hereNo
N1&1 EasyLoginEasyLogin.exe1&1 EasyLogin - quick access to webhost 1&1's Control Panel, Web-Mail and other applications via the System TrayNo
X1-sukarnosukarno.exeAdded by the BRONTOK-CR WORM!No
U101Clips101Clips.exe101Clips - "the simplest of all multi-clipboard programs. Just have it running minimized and it captures everything you cut or copy from other programs. It keeps the last 25"No
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exeAdded by the FAKEALERT-AH TROJAN!No
X1111swapmgr.exe1111swapmgr.exeAdded by the BDOOR-IC BACKDOOR!No
X123456rundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit numberNo
X1234klsjdc uiar924c afsxgnsvuxct.exeDetected by McAfee as the FAKEALERT-AM TROJAN! See hereNo
X1234klsjdc uiar924c afsysvtypkbjx.exeDetected by McAfee as the FAKEALERT-AM TROJAN! See hereNo
X123MonitorSpywareFreeMonitor.exe1-2-3 Spyware Free rogue spyware remover - not recommended, see hereNo
U12Ghosts Backup12backup.exe12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup"No
U12Ghosts Clip12clip.exe12Ghosts Clip - "Screen shots made easy"No
U12Ghosts JustAWindow12window.exe12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see"No
U12Ghosts Popup-Killer12popup.exe12Ghosts Popup-KillerNo
U12Ghosts SaveLayout12autosl.exe12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons"No
U12Ghosts SetColor12color.exe12Ghosts SetColor - "Change your desktop icon text colors, also to transparent"No
U12Ghosts ShowTime12showtime.exe12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones"No
U12Ghosts Synchronize12sync.exe12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet"No
U12Ghosts Tower12tower.exe12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)"No
U12Ghosts TrayProtect12srvc.exe12Ghosts TrayProtect - "Hide tray icons, restore after a crash"No
U12Ghosts Wash12wash.exe12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files"No
N12Voip12Voip.exe12Voip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeNo
?17779Proj2002N/A??No
X180adsolution180adsolution.exeNCase adwareNo
X180ax180ax.exeNCase adwareNo
X180ClientStubInstallstubinstaller****.exe [* = digit]180Solutions adware relatedNo
X180ClientStubInstall[path to trojan]180Solutions adware relatedNo
X180ClientStubInstall******.tmp [* = random digit/char]180Solutions adware relatedNo
X1916435341.exe1916435341.exeAdded by the DLOADR-AXU TROJAN!No
X196_150_ni196_150_ni.exeWinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see hereNo
X197_150_ni_3197_150_ni_3.exeWinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see hereNo
N1:hpdrv.exeHP utility for monitoring when and how many recoveries have been doneNo
N1A:MacVisionTrayMonitorTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)No
Y1A:Stardock MCPmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applicationsNo
Y1A:Stardock TrayMonitorTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopXNo
?1CmailSNETMAIL.EXE??No
X1on11on1.exeAdult content diallerNo
U1Srv32SpyAgent4.exeSpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."No
X1u71u7.exeAdded by the MURBAC-A TROJAN!No
U1Win32CfgSpyBuddy.exeSpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself!No
U1Win32CfgKeyloggerpro.exeKeyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself!No
X1WinCfg32WebMailSpy.exeWebMailSpy spywareNo
X2-suhartosuharto.exeAdded by the BRONTOK-CR WORM!No
X2020Downloadermssvr.exe2020Search ToolbarNo
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exeAdded by the FAKEALERT-AH TROJAN!No
U24Online ClientCyberoamClient.exeRelated to Cyberroam from Elitecore Technologies LtdNo
X252winmgr.exeAdded by the LEGMIR-AT TROJAN!No
X27slsorve.exeAdded by the SLSORVE-A TROJAN!No
X27csrss32.exeAdded by the SLSORVE-D TROJAN!No
X27msm32.exeAdded by the SLSORVE-E TROJAN!No
X2Searchmain.exe2Search adwareNo
X2thousandbuck[path to file]Added by the RANKY.L TROJAN!No
U2wSysTray2portalmon.exe2Wire Homeportal user interfaceNo
X3-habibiehabibie.exeAdded by the BRONTOK-CR WORM!No
X32-bit Thunking servicethunk32.exeAdded by the DERDERO.A WORM!No
X333svchost.exeAdded by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directoryNo
Y36X Raid ConfigurerJMRaidSetup.exeJMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host ControllersNo
X388529725448AutomaticUpdates.exeAdded by the SDBOT-DEN WORM!No
?39ELTFH25Z8SKFEzg1q5.exeSeems to be associated with software by Resplendence SP ?No
Y3c1807pd3cmlink.exe 3cpipe-3c1807pd3Com WinModem driver. See here for more WinModem informationNo
Y3capplnk3capplnk.exeUS Robotics Modem driverNo
N3cdminic3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cardsNo
Y3CM Link3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without itNo
Y3Cmlink3CmlinkW.exeFor a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem informationNo
N3ComDMIAgent3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cardsNo
Y3cpipe-USRpdAUSRmlnkA.exeModem driver files from US RoboticsNo
X3D Text3D Text.scrAdded by the JERMY.A WORM!No
U3Deep Control Panel3DeepCTL.EXE3Deep® from E-Color corrects lighting, shading and color for all your 2D and 3D games. Now superseded by 3DxWizzard™No
X3Dfx AccGFXACC.EXEAdded by the GIBE WORM! No
N3dfx Task Manager3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> ProgramsNo
Y3dfx Tools3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cardsNo
Y3dfxv2ps.dll3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cardsNo
?3Dlabs Taskbar Display Manager3DLman.exe3DLabs graphics driver related. System Tray access to display settings?No
U3DLabsHelperDemon3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabledNo
Y3DMouse.EXE3DMouse.EXEDritek System Inc. 3D Mouse driverNo
X3d_sound3d_sound.exeAdded by the RIADOS-A TROJAN!No
U3qdctl.exe3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQNo
Y3ware 3DM3dm.exeMonitors status of the disk array on 3ware IDE RAID controllersNo
X4-gusdurgusdur.exeAdded by the BRONTOK-CR WORM!No
X456655explorer.exeAdded by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%No
X4684735485910netdll32.exeAdded by the SDBOT-DEV WORM!No
X4da92ad5.exe4da92ad5.exeAdded by the DLOADR-WZ TROJAN!No
X4k51k44k51k4.exeAdded by the BRONTOK-BH WORM!No
U4oDKHost.exeVerisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktopsNo
X4wd!!!Natal!.pifAdded by the OPASERV.AI WORM!No
X5-1-61-96members-area.exeAdult content diallerNo
X5-2-46-1125-2-46-112.exeAdult content pop-up dialler. Removal instructions hereNo
X5-megawatimegawati.exeAdded by the BRONTOK-CR WORM!No
X55278grepclient1.exeAdded by the LINEAGE-S TROJAN!No
X5p4m[path to trojan]Added by the LITEBOT-C TROJAN!No
X5whgue215whgue21.exeClearSearch adwareNo
X6-susilo bsby.exeAdded by the BRONTOK-CR WORM!No
X65438761234587528rkgnd.exeANG AntiVirus 09 rogue security software - not recommended, removal instructions hereNo
X666Ska.exeAdded by the PIPES TROJAN!No
X678lsas32.exeAdded by the SLSORVE-B TROJAN!No
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exeAdded by the FAKEALERT-AH TROJAN!No
X76112549345328287angpd.exeANG AntiVirus 09 rogue security software - not recommended, removal instructions hereNo
X7f8ez****.exe 9idfDetected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folderNo
U802.11b+g USB Wireless LAN UtilityZDWlan.exe802.11b+g USB Wireless LAN UtilityNo
U802.11g Wireless AdatperMonitor.exeRelated to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelledNo
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exeAdded by the FAKEALERT-AH TROJAN!No
X98D0CE0C16B1rundll32.exe D0CE0C16B1, D0CE0C16B1BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deletedNo
X9mwinlog0n.exeAdded by the LEGMIR-AQK TROJAN!No
Y9xadiras9xadiras.exeAllied Telesyn AT series router/modem related - apparently requiredNo
X9xHtProtectAVprotect9x.exeAdded by the NETSKY.M WORM!No
X;Rundll[filename]Added by the PWSLEGMIR.E TROJAN!No
X?ekio Startups?nksvc32.exeAdded by the AGOBOT-OV WORM where ? is a random character No
X@regedit -s ..win.dllAdded by the SEEKER.K TROJAN!No
X@iexpl0res.exeAdded by the RBOT.AEX WORM!No
X@wincms.exeAdded by the RBOT.CBR WORM!No
N@Hoc ToolbarAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more infoNo
N@lohareminder.exeRegistration reminder for @loha@home E-mail utilityNo
X@tour_ww@tour_ww[1].exeAdult content diallerNo
Xaa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial websiteNo
Xajesse.exeAdded by the MELO-A WORM!No
XA New Windows Updaterw32NTupdt.exeAdded by the MYTOB.BM WORM!No
NA NoteA Note.exe"A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop"No
UA Verizon AppVERIZO~1.EXEPart of Verizon Online Support ManagerNo
Ua-squareda2guard.exea-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection featureNo
Ya-squared Anti-Dialera2adguard.exea-sqaured Anti-DialerNo
Ya-winpoet-servicewinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networkingNo
UA1000 Settings Utilitycpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these featuresNo
UA4ProxyA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sitesNo
XA5118r_default32142.pif Added by the BRONTOK-AK WORM and variants!No
XA5118rj6321422.exe Added by the BRONTOK-AK WORM and variants!No
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EBrundll32.exe E6F1873B.DLL, D9EBC318CBrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deletedNo
Ua?a2guard.exea-Squared antitrojan - can be run on demand but necessary in Startup if you prefer the a? 'Background Guard' real time protection featureNo
Xaa bbcc dde effgghh jjupdate.exeAdded by a variant of the IRCBOT BACKDOOR!No
?AAACLEANAAACLEAN.INF??No
?AAAKeyboard????No
NAAATraySaverTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System TrayNo
UAAKaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"No
UaaLDISCN32LDISCN32.EXELANDesk® Management Suite software componentNo
UaaLDTaskCompletionamclient.EXELANDesk® Management Suite software componentNo
XAAMSFree702Avengine.comAdded by the DELF.LJ TROJAN!No
XAAMSFree702sys.exeAdded by the BACKDOOR-CPC TROJAN!No
XAaouamee.exePurityScan/Clickspring adwareNo
XAappadprot.exeAdBlaster adwareNo
?aauclientACNUpdater.exeAppears to be related to software from Accenture.comNo
UAAWAd-Aware.exeAd-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 FreeNo
UAAWTrayAAWTray.exeSystem Tray access to Ad-aware from Lavasoft - popular spyware/adware removal toolNo
?ab EazySchedulerezsched.exe??No
Xabassabass.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
NABBYY Community AgentCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the softwareNo
UABCkeylogger.exeKeystroke logger/monitoring program - remove unless you installed it yourself! No
Xabcdefghabcdefgh.exeEPJ TROJAN! No
UABIT uGuruuGuru.exeABIT ?Guru - on motherboards incorporating the ?Guru processor this provides quick access to "hardware monitoring, overclocking, BIOS flashing and audio tweakinNo
NABITEQabiteq.exeMonitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speedsNo
XAbrada WIN32abrada.exeAdded by the DERMON-G TROJAN! No
YABRegmonABregmon.exePart of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do?No
UAbsolute Shielddseraser.exeAbsolute Shield Evidence Eliminator - internet history eraser No
UAbsolute StartUp monitorASMon.exeAbsolute Startup - startup monitor from F-Group SoftwareNo
UAbsoluteShield Internet Erasercseraser.exeAbsoluteShield Internet Eraser - "protects your privacy by cleaning up all the tracks of your Internet and computer activities" No
XABsrabsr.exeAdded by the AUTOUPDER TROJAN!No
Xabsrmwsvm.exeSeekSeek search hijacker related - see here No
Xabtump3serch.exeLoads the executable for Lop.com - final versionNo
Xabtulopsearch.exeLoads the executable for Lop.com - beta versionNo
UAbyssWebServerabyssws.exeAbyss web serverNo
XAc97Soundsnddrv.exeDetected by Kaspersky as the VB.AXG TROJAN! See hereNo
UAcBtnMgr_X63AcBtnMgr_X63.exe"Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etcNo
UAcBtnMgr_X63.exeAcBtnMgr_X63.exe"Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etcNo
UAcBtnMgr_X73AcBtnMgr_X73.exe"Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etcNo
UAcBtnMgr_X83AcBtnMgr_X83.exe"Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etcNo
UAcBtnMgr_X84-X85AcBtnMgr_X84-X85.exe"Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etcNo
Uaccacc.exeAdvanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem"No
XACCDEFRAGINFO[path to worm]Added by the DARBY-O WORM!No
UAccelerateaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connectionNo
XAccess Control Appwinsto.exeDetected by Kaspersky as the AGENT.DGO TROJAN! See hereNo
NAccess Ramp Monitorarmon32.exeMonitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try againNo
XAccess WebControl[path to file]Added by the PPDOOR-M TROJAN!No
UAccessManagerAccessMgr.exePart of SmartPipes SecureSite software. "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"No
XAccessMedia P2P Loaderamp2pl.exeMy AccessMedia toolbar related, stealth installed!No
UAccessoriesPlusclockplus.exeClock Plus, part of Accessories Plus allows you to select from dozens of alternatives for the Windows clockNo
NAccessRamp Monitor01ARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."No
NAccessRampLAN01ARUpld32.exeVersion of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003No
UAcctMgrAcctMgr.exeNorton? Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities - all from the safety of your own PCNo
NAccuWeather.com® DesktopAccuWeatherDesktop.exeDesktop weather from AccuWeatherNo
NAccuWeatherDesktopAlertsAccuWeatherDesktopAlerts.exeWeather alerts for AccuWeather.com Desktop which "provides you with the most accurate, late-breaking weather conditions for the United States"No
Xaccwizz.exeaccwizz.exeAdded by the RULAND.A WORM!No
Xaccwizzz.exeaccwizzz.exeAdded by the RULAND.A WORM!No
Xacdllib3bcdlmem.exeAdded by the MAILBOT-BA TROJAN!No
NACDSeeACDSee8Pro.exeACDSee 8 photo software. Organize, manage, enhance, and share all your valued photo memoriesNo
?Ace bowsAce bows.exe??No
NAceGain LiveUpdateLiveUpdate.exe"AceGain LiveUpdate can help to automate and optimize product updates. AceGain LiveUpdate will automatically detect new patch updates, driver updates or full product updates and automatically download and install them according to user configuration"No
UAcer ePower ManagementAcer ePower Management.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles"No
NAcer ePresentation HPDePresentation.exeAllows you to connect your Acer laptop to a projectorNo
NAcer Product RegistrationACE1.exeAcer Product Registration - remove when registration is completedNo
NAcer Tour ReminderReminder.exePopup reminder to take the tour of your new Acer laptopNo
UAcerGotoAcerGoto.exeAcer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computerNo
UAcerNotebookManageralmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settingsNo
UAcerPowerkeyPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3No
XAcess2007aaccess2007a.exeAdded by the GAOBOT.PQA WORM!No
XAceu[random filename]PurityScan/Clickspring adwareNo
YacEventServacevtsrv.exeActivCard Gold from ActivIdentity, Inc. Smart card-based strong authentication software - for photo IDs, proximity badges for facility access and as digital identification and authenticationNo
UAClntUsrAClntUsr.exeAltiris AClient Service Windows Tray IconNo
NAcme.PCHButtonpchbutton.exeUsed by HP Instant SupportNo
UACMonitor_X63ACMonitor_X63.exeButton monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe"No
UACMonitor_X63.exeACMonitor_X63.exeButton monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe"No
UACMonitor_X73ACMonitor_X73.exeButton monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe"No
UACMonitor_X83ACMonitor_X83.exeButton monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe"No
UACMonitor_X84-X85ACMonitor_X84-X85.exeButton monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X84-X85.exe"No
Xacocashfastdown.exeAdult content diallerNo
XacocashFASTFOWN.EXEAdult content diallerNo
UAcombo3dmouseAcombo3d.exeMouse driver - required if you use non-standard Windows driver featuresNo
XAcontiaconti.exeAdult content diallerNo
Uacousticacoustic.exeControl panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retainedNo
Nacpartagpart11.exeProgram for finding trucks on-lineNo
XAcrobatacrmon32.exeAdded by the SMALL-ECT TROJAN!No
UAcrobat Assistant *.*ACROTRAY.EXEEssential for creating PDF files with Adobe Acrobat and Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation. *.* represents the versionNo
XAcrobat Readacroup32.exeAdded by the VANBOT-BQ TROJAN!No
NAcrobat Speed Launchacrobat_sl.exeSpeeds up the time it takes to load Adobe's Acrobat PDF creation and management tool. From version 7.0 onwardsNo
UACROMOUSEACROMAPP.exeRelated to ACROMOUSE Laser mouse controlNo
UAcronis Popup BlockerRunDll32.exe [path] Blocker.dll, RunPart of Acronis Privacy Expert - anti-spyware and security suite No
UAcronis Scheduler Helperschedhlp.exePart of Acronis True Image backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount imagesNo
UAcronis Scheduler2 Serviceschedhlp.exePart of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount imagesNo
UAcronis True ImageTimounterMonitor.exePart of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archiveNo
NAcronis True Image MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImageNo
NAcronis TrueImage MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImageNo
NAcronis*True*Image MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImageNo
UAcronisTimounterMonitorTimounterMonitor.exePart of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archiveNo
NAcronisTrueImage MonitorTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImageNo
UAct! PreloaderAct8.exeSage Software's ACT! "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships"No
NAction Manager 32am32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> ProgramsNo
?ActionAgentactionagent.exe"A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required?No
NActivationActivation.exePart of Microsoft MoneyNo
UActivboardMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keysNo
XActive Bit Stationabs.exeAdded by the MYTOB.BZ WORM!No
NActive CPUacpu.exeActive CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity"No
UActive Desktop CalendarADC.EXEXemiComputers Active Desktop CalendarNo
UActive Email Monitoraem25.exeActive Email Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via emailNo
UActive shieldActiveshield.exeActive Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses"No
XActiveDesktopsystray32.exeAdded by the DABOOM WORM!No
XACTIVEDSACTIVEDS.EXEAdded by the OPASERV.T WORM!No
NActiveEyesActiveEyes.exeActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs, create your own shortcutNo
UActiveKeys.AAB635BD7D054a37A576akeys.exe"Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action"No
UActiveMenuActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
UAct