| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1807 results found for A
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| A Note | N | A Note.exe | "A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop" | No |
| ShellOS | X | A+++.exe | Added by the AV TROJAN! | No |
| fast | X | A-fast.exe | A-fast Antivirus rogue security software - not recommended, removal instructions here | No |
| A-[8 to 10 numbers] | X | A-[8 to 10 numbers].exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %AppData% and %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (7/Vista) or %UserProfile%\Start Menu\Programs\Startup (XP) and its presence here ensures it runs when Windows starts | No |
| a | X | a.exe | Commercials file that registers itself in the system registry and redirects IE to a certain commercial website | No |
| a0a6fcba38a07659eef7df3f74171249 | X | a0a6fcba38a07659eef7df3f74171249.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| WindowsK | X | a1.exe | Added by the MSNDIABLO.A WORM! | No |
| A1216280217 | X | A1216280217.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %AppData% and %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (7/Vista) or %UserProfile%\Start Menu\Programs\Startup (XP) and its presence here ensures it runs when Windows starts | No |
| A1255100880 | X | A1255100880.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AD. Note - the file is located in %AppData% and %UserStartup% and %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
| A1360385615 | X | A1360385615.exe | Detected by Dr.Web as Trojan.DownLoader6.51392. Note - the file is located in %AppData% and %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (7/Vista) or %UserProfile%\Start Menu\Programs\Startup (XP) and its presence here ensures it runs when Windows starts | No |
| a13khWLwrQo | X | a13khWLwrQo.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.ZB. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| load= | X | a1g.exe | Added by the ATAK.B WORM! | No |
| A228533698 | X | A228533698.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %AppData% and %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (7/Vista) or %UserProfile%\Start Menu\Programs\Startup (XP) and its presence here ensures it runs when Windows starts | No |
| a2abfc2cbc7857ee33ac527ade190621 | X | a2abfc2cbc7857ee33ac527ade190621.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| a2adguard | Y | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" | Yes |
| a-squared | Y | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" | Yes |
| a-squared Anti-Dialer | Y | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" | Yes |
| a2dservice | ? | a2dservice.exe | Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required? | No |
| Air2Data | ? | a2dservice.exe | Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required? | No |
| a² | Y | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" | No |
| a2guard | Y | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" | Yes |
| a-squared | Y | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" | Yes |
| Emsisoft Anti-Malware | Y | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" | Yes |
| ADSL_A2 | ? | A2Installed | Associated with an Integrated Telecom Express (ITeX) ADSL driver installation. What does it do and is it required? | No |
| Aureal A3D Interactive Audio Init | Y | A3dInit.exe | For Aureal based 3D soundcards. A3D sound features won't work with this disabled | No |
| a3f3ce52c6b752619b1e6ed73ef85eae | X | a3f3ce52c6b752619b1e6ed73ef85eae.exe | Detected by McAfee as Trojan-FAUE!76AE25775E3D and by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| A4Proxy | U | A4Proxy.exe | Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites | No |
| A59769930 | X | A59769930.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. Note - the file is located in %AppData% and %UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (7/Vista) or %UserProfile%\Start Menu\Programs\Startup (XP) and its presence here ensures it runs when Windows starts | No |
| A813794408 | X | A813794408.exe | Detected by Malwarebytes Anti-Malware as Trojan.Keylogger. Note - the file is located in %AppData% and %UserStartup% and its presence there ensures it runs when Windows starts | No |
| 5K8Y81WZANWO | X | A8F8FWMF.exe | Detected by McAfee as RDN/Generic Dropper!df and by Malwarebytes Anti-Malware as Trojan.Agent.RND | No |
| a96233fc156e042876b9d1cb7b94e7ad | X | a96233fc156e042876b9d1cb7b94e7ad.exe | Detected by McAfee as Generic PWS.y and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| MicrosoftWindows | X | a@26m.exe | Added by the KILLPAR-B TROJAN! | No |
| APOLLOPROJECTMODULE2 | X | AA58327EA88F5140E1526316B77E27806CD1125D | Detected by Malwarebytes Anti-Malware as Trojan.Agent.APLGen. The file is located in %Temp% | No |
| aaa | X | aaa.exe | Added by the POISON.PG BACKDOOR! | No |
| index | X | aaa.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %ProgramFiles% | No |
| vbwg cute | X | aaa.exe | Added by the VB-DZG TROJAN! | No |
| aaaaaaaa | X | aaaaaaaa .exe | Detected by Kaspersky as Virus.Win32.Sality.bh. The file is located in %System% | No |
| aaaaaaaa | X | aaaaaaaa .exe | Detected by Kaspersky as Virus.Win32.Virut.ce. The file is located in %UserProfile% | No |
| aaaaaaaa� | X | aaaaaaaa�.exe | Detected by Kaspersky as Virus.Win32.Sality.bh. The file is located in %System% | No |
| aaaaaaaa� | X | aaaaaaaa�.exe | Detected by Kaspersky as Virus.Win32.Sality.l. The file is located in %UserProfile% | No |
| aaaaaaaa+ | X | aaaaaaaa+.exe | Detected by Kaspersky as Virus.Win32.Sality.bh. The file is located in %System% | No |
| aaaaaaaa+ | X | aaaaaaaa+.exe | Detected by Kaspersky as Virus.Win32.Sality.l. The file is located in %UserProfile% | No |
| aacmeyf | X | aacmeyf.exe | Added by the AF.20 TROJAN! | No |
| Microsoft Driver Setup | X | aadrive32.exe | Added by the AGENT-SCH TROJAN! | No |
| AAK | U | aak.exe | Advanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere" | No |
| Ashampoo Anti-Malware Guard | Y | AAMW_Guard.exe | Ashampoo Anti-Malware - antispyware and antivirus | No |
| AANYVKCF | X | aanyvkcf.exe | SafeSearch adware | No |
| Antivirus Agent Pro | X | aap.exe | Antivirus Agent Pro rogue security software - not recommended, removal instructions here | No |
| Microsoft Synchronization Manager | X | aapie.exe | Added by the SDBOT-OZ WORM! | No |
| Intelprc | X | Aas3lovu.exe | Added by the SILLYFDC-CG WORM! | No |
| Noha | X | aasd.exe | PurityScan adware | No |
| stat | X | aata.bat | Detected by Sophos as Troj/Agent-ABFD and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| stat2 | X | aata.bat | Detected by Sophos as Troj/Agent-ABFD and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft Update | X | aaupdt.exe | Added by the RBOT-RQ WORM! | No |
| Antivirus | X | aav.exe | Advanced Antivirus rogue security software - not recommended, removal instructions here | No |
| AAWTray | U | AAWTray.exe | System Tray access to older versions of the Lavasoft Ad-Aware anti-malware tool | No |
| Ad-Watch | U | AAWTray.exe | System Tray access to older versions of the Lavasoft Ad-Aware anti-malware tool | No |
| Argentum Backup | U | ab.exe | Argentum Backup - a small backup program that lets you easily back up your documents and folders | No |
| Anti-Virus | X | Abaddon.exe | Added by the NODDABA WORM! | No |
| abass | X | abass.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| abb278f5f94f5be17c28e4761048b650 | X | abb278f5f94f5be17c28e4761048b650.exe | Detected by Dr.Web as Trojan.DownLoader8.19299 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| FineReader7NewsReaderPro | N | AbbyyNewsReader.exe | ABBYY FineReader OCR software - version 7 | No |
| f99a910d3f4e230e93f6f52797fa3578 | X | abc.exe | Detected by Dr.Web as Trojan.DownLoader8.37173 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| wina | X | abc.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject. The file is located in %AppData% | No |
| .. | X | ABC2007.exe | Added by the DLOADR-ASH TROJAN! | No |
| abccafaeffad | X | abccafaeffad.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.FAD. The file is located in %AppData%\a7bcc1a4-f7a4-4502-8650-8579e607f7f7ad - see here | No |
| FILE | X | abcdefg.exe | Added by the KELVIR.DD WORM! | No |
| System | X | abcdefg.exe | Added by the HARWIG-B WORM! | No |
| BT00003* | X | abcdefg23.exe | Added by the VB-VT TROJAN where * = 5,6 or 7! | No |
| abcdefgh | X | abcdefgh.exe | EPJ TROJAN! | No |
| abcMover1.3 | U | abcMov13.exe | AbcMover allows you to pre-define input information - which will let you complete the input of thousands of items of information automatically, send out greetings to thousands of customers and complete a verification test for thousands of times automatically | Yes |
| [various names] | X | ABCXYZ.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| a0a6fcba38a07659eef7df3f74171249 | X | abdenour.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| AntivirusBEST | X | abest.exe | AntivirusBEST rogue security software - not recommended, removal instructions here | No |
| Application Layer Browser | X | abgsvc.exe | Added by the ULPM.FX TROJAN! | No |
| ABITEQ | N | abiteq.exe | Monitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds | No |
| Service Drivers | X | abl.exe | Added by the SDBOT-YX WORM! | No |
| Album Fast Start | N | ABMTSR.EXE | Scanner software, not required for scanner to work | No |
| ACTIVBOARD | U | ABoard.exe | Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys | No |
| Adobe ARM Manager | X | AbodeARM.exe | Detected by McAfee as Generic.dx. Note - this is not the legitimate Adobe update manager with the same filename which is normally located in %CommonFiles%\Adobe\ARM\1.0. This one is located in %AppData% | No |
| abot | X | abot | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData% | No |
| aboutagent | X | aboutagent.exe | Detected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %ProgramFiles%\abouttopbar | No |
| AdobeALM | X | aboveinda.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %UserTemp% | No |
| AdobeALM | X | aboveinda.exe | Detected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %System% | No |
| Abox | X | Abox.exe | Adultbox adware | No |
| Abrada WIN32 | X | abrada.exe | Added by the DERMON-G TROJAN! | No |
| ABRegmon | Y | ABregmon.exe | Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do? | No |
| [various names] | X | abrek.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Active Bit Station | X | abs.exe | Added by the MYTOB.BZ WORM! | No |
| Office Monitor Secure Systema | X | absecure32.exe | Added by the RBOT.FPW WORM! | No |
| AbsoluteControl | U | AbsoluteControl.exe | AbsoluteControl from Kamatoz - "system control software offers wide range of OS control tools available on single click. It can set your screen resolution with highest possible refresh rate, open\close your CD drives, reboot, shutdown, poweroff, hibernate and send to standby mode your system" | No |
| ABsr | X | absr.exe | Added by the AUTOUPDER TROJAN! | No |
| Application Adapter | X | abvsvc.exe | Added by the CHECKOUT WORM! | No |
| AbyssWebServer | U | abyssws.exe | Abyss web server | No |
| CCWC7a | U | ac.exe | Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free | No |
| ac81fa871a4336b2440cb3826cd12647 | X | ac81fa871a4336b2440cb3826cd12647.exe | Detected by Dr.Web as Trojan.DownLoader7.21651 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| aca | U | aca.exe | Access Controller - "a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection, define a password in Options, and select the Lock command. Password protection can be automatically activated on boot or with a click of an icon in the system tray." The same program as 1 Click & Lock and Access Lock (and maybe others) - the same file for the same version is used by all programs but the filename is different in each case | Yes |
| aca.exe | U | aca.exe | Access Controller - "a desktop locking security utility you can use to protect your desktop when you are not near your PC. To activate protection, define a password in Options, and select the Lock command. Password protection can be automatically activated on boot or with a click of an icon in the system tray." The same program as 1 Click & Lock and Access Lock (and maybe others) - the same file for the same version is used by all programs but the filename is different in each case | Yes |
| Osus | X | acao.exe | PurityScan adware | No |
| acappaa | Y | acappaa.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. The exact purpose of this entry is unknown at present but it appears to be associated with incomplete upgrade/update downloads. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| Quick Heal AntiVirus | Y | acappaa.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. The exact purpose of this entry is unknown at present but it appears to be associated with incomplete upgrade/update downloads. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| ResumeQuickupDownload | Y | acappaa.exe | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. The exact purpose of this entry is unknown at present but it appears to be associated with incomplete upgrade/update downloads. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon | Yes |
| Audio HD Driver | X | ACB5IsQ0qju.exe | Detected by Sophos as Troj/Agent-OAL | No |
| AcBtnMgr_X63.exe | U | AcBtnMgr_X63.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| AcBtnMgr_X73 | U | AcBtnMgr_X73.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| Lexmark X73 Button Manager | U | AcBtnMgr_X73.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| AcBtnMgr_X83 | U | AcBtnMgr_X83.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| Lexmark X83 Button Manager | U | AcBtnMgr_X83.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| AcBtnMgr_X84-X85 | U | AcBtnMgr_X84-X85.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| Lexmark X84-X85 Button Manager | U | AcBtnMgr_X84-X85.exe | "Lexmark Scan & Copy Control Program" for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Button manager for features such as scan, scan to E-mail, copy, etc | No |
| acc | U | acc.exe | Advanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem" | No |
| aedecadd | X | accadd.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieData | No |
| aediescadd | X | accadd.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieData | No |
| AOLCC | ? | ACCAgnt.exe | AOL ISP software related, file located in a "AOL Computer Check-Up" folder. What does it do and is it required? | No |
| Accelerate | U | accelerate.exe | Webroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection | No |
| AccelerometerSt | Y | AccelerometerSt.exe | HP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed | No |
| AccelerometerSysTrayApplet | Y | AccelerometerSt.exe | HP 3D DriveGuard uses a digital accelerometer protects your disk drive by parking and halting I/O requests if you drop your PC or if you move your PC with the display lid closed | No |
| Microsoft Service Access Manager | X | Access.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Acess2007a | X | access2007a.exe | Added by the GAOBOT.PQA WORM! | No |
| accessessy | X | accessessy.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.Clicker.Gen | No |
| ALTOOLS | U | AccessL.exe | ALTools family of PC utilities | No |
| AccessManager | U | AccessMgr.exe | Part of SmartPipes SecureSite software. "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management" | No |
| Drivers for Internet Explorer | X | accesweb.exe | Added by the STARTPAGE.FW TROJAN! | No |
| Windows Task Manager | X | ACCOUNT_DETAILS.DOC.exe | Added by the QUATERS.A WORM! | No |
| accrdsub | Y | accrdsub.exe | ActivIdentity ActivClient - security software from ActivIdentity Corporation which "enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login" | No |
| Verizon Online Account Setup | ? | Accstp4.0.exe | Related to the Verizon Online ISP service | No |
| AcctMgr | U | AcctMgr.exe | Norton Password Manager from Symantec - which stores passwords and other personal information and retrieves the data needed for email logins, shopping orders, banking, and other online activities. Now discontinued, it was available as a standalone product or as part of the Norton SystemWorks suite | Yes |
| accuweather | U | accuweather.exe | Desktop weather status/forecast widget from AccuWeather included with Dell Stage on their range of PCs | Yes |
| AccuWeatherWidget | U | accuweather.exe | Desktop weather status/forecast widget from AccuWeather included with Dell Stage on their range of PCs | Yes |
| AccuWeather.com® Desktop | N | AccuWeatherDesktop.exe | Desktop weather from AccuWeather | No |
| AccuWeatherDesktopAlerts | N | AccuWeatherDesktopAlerts.exe | Weather alerts for AccuWeather.com Desktop which "provides you with the most accurate, late-breaking weather conditions for the United States" | No |
| accwizz.exe | X | accwizz.exe | Added by the RULAND.A WORM! | No |
| MeuPrograma | X | accwizz.exe | Added by the RULAND.A WORM! | No |
| accwizzz.exe | X | accwizzz.exe | Added by the RULAND.A WORM! | No |
| ACDaemon | N | ACDaemon.exe | Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia, PhotoStudio 6 and Print Creations. Set the associated ArcSoft Connect Daemon (ACService.exe) service to Manual (via Start → Control Panel → Administrative Tools → Services) and run this entry manually via the Start menu when required | Yes |
| ArcSoft Connect | N | ACDaemon.exe | Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia, PhotoStudio 6 and Print Creations. Set the associated ArcSoft Connect Daemon (ACService.exe) service to Manual (via Start → Control Panel → Administrative Tools → Services) and run this entry manually via the Start menu when required | Yes |
| ArcSoft Connection Service | N | ACDaemon.exe | Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia, PhotoStudio 6 and Print Creations. Set the associated ArcSoft Connect Daemon (ACService.exe) service to Manual (via Start → Control Panel → Administrative Tools → Services) and run this entry manually via the Start menu when required | Yes |
| CNG Volume File Defragmenter | X | acdcndvz.exe | Detected by Sophos as Mal/Slenfbot-E and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\ziopjjhddxkff | No |
| system xp | X | acdsee demo.exe | Added by the SALGA.A WORM! | No |
| ACDSee | N | ACDSee8Pro.exe | ACDSee 8 photo software. Organize, manage, enhance, and share all your valued photo memories | No |
| Ace bows | ? | Ace bows.exe | ?? | No |
| Acer Product Registration | N | ACE1.exe | Acer Product Registration - remove when registration is completed | No |
| WindowsACEbar | X | acebarupdate.exe | BarACE adware | No |
| Acer ePower Management | U | Acer ePower Management.exe | Part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles" | No |
| ACER.exe | X | ACER.exe | Added by the AUTORUN.AJX WORM! | No |
| GlobalFlagACER | X | ACER.exe | Added by the VB.BL WORM! | No |
| AcerGoto | U | AcerGoto.exe | Acer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer | No |
| Windows Acer Service | X | acersv.exe | Added by the IRCBOT.YFQ BACKDOOR! | No |
| AspireTimeMachine | Y | acertmb.exe | System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP, allowing you to restore a PC back to a working state with minimal re-entry | No |
| acevents | Y | acevents.exe | ActivIdentity ActivClient - security software from ActivIdentity Corporation which "enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login" | No |
| acEventServ | Y | acevtsrv.exe | ActivCard Gold from ActivIdentity Corporation. Smart card-based strong authentication software - for photo IDs, proximity badges for facility access and as digital identification and authentication | No |
| necix | X | aceyukujy.exe | Added by the SDBOT-UE WORM! | No |
| MS32DLL | X | achi.dll.vbs | Added by the ACHI-A TROJAN! | No |
| AClntUsr | U | AClntUsr.exe | Altiris AClient Service Windows Tray Icon | No |
| AClntUsr | U | AClntUsr.EXE | Part of Altiris (by Symantec) "service-oriented management solutions provide a modular and future-proof approach to managing highly diverse and widely distributed IT infrastructures" | No |
| aclobe | X | aclobe.exe | Detected by Microsoft as Trojan:Win32/Dusvext.B | No |
| ACMON | Y | ACMON.exe | ASUS Splendid "is a breathtaking innovation that brings the video viewing experience on PC to the next level. Built into the driver of ASUS graphics cards, Splendid Video Enhancing Technology detects activation and usage of video applications and automatically optimizes image quality for the best visual result" | No |
| ACMonitor_X63 | U | ACMonitor_X63.exe | Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe" | No |
| ACMonitor_X63.exe | U | ACMonitor_X63.exe | Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe" | No |
| Lexmark X63 Button Monitor | U | ACMonitor_X63.exe | Button monitor for the Lexmark X63 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X63.exe" | No |
| ACMonitor_X73 | U | ACMonitor_X73.exe | Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe" | No |
| Lexmark X73 Button Monitor | U | ACMonitor_X73.exe | Button monitor for the Lexmark X73 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X73.exe" | No |
| ACMonitor_X83 | U | ACMonitor_X83.exe | Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe" | No |
| Lexmark X83 Button Monitor | U | ACMonitor_X83.exe | Button monitor for the Lexmark X83 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X83.exe" | No |
| ACMonitor_X84-X85 | U | ACMonitor_X84-X85.exe | Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X84-X85.exe" | No |
| Lexmark X84-X85 Button Monitor | U | ACMonitor_X84-X85.exe | Button monitor for the Lexmark X84-X85 all-in-one multifunction printer/copier/scanner. Works in conjunction with the "Lexmark Scan & Copy Control Program" button manager whose filename is "AcBtnMgr_X84-X85.exe" | No |
| Application Manager | X | acnsvc.exe | Added by a variant of W32.IRCBot. The file is located in %System% | No |
| aauclient | ? | ACNUpdater.exe | Appears to be related to software from Accenture.com | No |
| Acombo3dmouse | U | Acombo3d.exe | Mouse driver - required if you use non-standard Windows driver features | No |
| {BB87203E-EBAD-7A2C-8F8F-FF9626E7B87B} | X | aconi.exe | Added by the AGENT-OZR TROJAN! | No |
| Aconti | X | aconti.exe | Adult content dialler | No |
| acoustic | U | acoustic.exe | Control panel program for the Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained | No |
| TBTray | U | acoustic.exe | Control panel program for the Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained | No |
| imwinsrvc | X | acpmonsrv.exe | Added by the SLAPER.E TROJAN! | No |
| Active CPU | N | acpu.exe | Active CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity" | No |
| Acrobat | X | acrmon32.exe | Added by the SMALL-ECT TROJAN! | No |
| Windows Updates | X | Acrobat.exe | Detected by Sophos as Troj/Keylog-NV and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| ctfmon | X | acrobat32.exe | Detected by McAfee as PWS-Banker and by Malwarebytes Anti-Malware as Spyware.Banker | No |
| Acrobat Speed Launch | N | acrobat_sl.exe | Speeds up the time it takes to load older versions of the Adobe Acrobat PDF creation/editing utility. Loads "acrobat_sl.exe" which quickly opens and closes all of the files that Acrobat will use when the application starts - allowing virus protection software to check these programs and add them to the list of safe files. Not required for Acrobat to function properly | No |
| Acrobat_sl | N | Acrobat_sl.exe | Speeds up the time it takes to load the Adobe Acrobat PDF creation/editing utility. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Acrobat to function properly | Yes |
| Adobe Acrobat | N | Acrobat_sl.exe | Speeds up the time it takes to load the Adobe Acrobat PDF creation/editing utility. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Acrobat to function properly | Yes |
| Adobe Acrobat Speed Launcher | N | Acrobat_sl.exe | Speeds up the time it takes to load the Adobe Acrobat PDF creation/editing utility. "The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files". Not required for Acrobat to function properly | Yes |
| ACROMOUSE | U | ACROMAPP.exe | Related to ACROMOUSE Laser mouse control | No |
| Acroread | X | AcroRD32.exe | Added by the DLOADR-BDK TROJAN! Note - this is not the popular Adobe Reader | No |
| Adobe Reader32 | X | Acrord32.exe | Added by the RBOT-BLC WORM! Note - this is not the popular Adobe Reader | No |
| 5KM7C0424P42 | X | AcroRd32.exe.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\Adobe | No |
| MBUJ218E | X | AcroRd32.exe.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\Adobe | No |
| WinUpdates | X | AcroRd32.exe.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\Adobe | No |
| Acrobat Assistant | U | AcroTray.exe | Installed with older versions of the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) | No |
| Acrobat Assistant 7.0 | U | Acrotray.exe | Installed with older versions of the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) | Yes |
| Acrobat Assistant 8.0 | U | Acrotray.exe | Installed with the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) | Yes |
| Acrotray | U | Acrotray.exe | Installed with the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) | Yes |
| AcroTray - Adobe Acrobat Distiller helper application. | U | Acrotray.exe | Installed with the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) | Yes |
| Adobe Acrobat Distiller Application | X | acrotray.exe | Added by the RANDEX.DFJ WORM! Note that the legitimate Adobe file (if installed) would normally be found in %ProgramFiles%\Adobe%\%ProgramName% (where %ProgramName% is Acrobat 9.0\Acrobat or Acrobat 7.0\Distillr for example) whereas this one is located in %System% | No |
| Adobe_Reader | X | acrotray.exe | Added by the AGENT-LNS TROJAN! Note that the legitimate Adobe file (if installed) would normally be found in %ProgramFiles%\Adobe\%ProgramName% (where %ProgramName% is Acrobat 9.0\Acrobat or Acrobat 7.0\Distillr for example) whereas this one is located in %ProgramFiles%\Adobe | No |
| Acrobat Read | X | acroup32.exe | Added by the VANBOT-BQ TROJAN! | No |
| ActivClient Agent | Y | acsagent.exe | Part of ActivIdentity ActivClient - security software from ActivIdentity Corporation which "enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login" | No |
| AolAcsDaemon1 | Y | Acsd.exe | AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AutoCAD Startup Accelerator | N | acstart16.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings | No |
| AutoCAD | N | acstart17.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings | Yes |
| AutoCAD Startup Accelerator | N | acstart17.exe | Preloads part of AutoCAD into disk cache at startup to speed up the launch of the main program when needed. Not required as most AutoCAD users tend to either open the program once and leave it open or open it occasionally to check drawings | Yes |
| mvsyswina | X | acsysiom.exe | Added by a variant of W32/Sdbot.worm | No |
| Ashampoo Core Tuner 2 | U | ACT2.exe | Ashampoo® Core Tuner 2 - a utility which helps you to get the most out of a multi-processor (or dual core) computer. This entry loads Core Tuner with Windows (required if you use any optimized profiles) and gives System Tray access | No |
| Act! Preloader | U | Act8.exe | Sage Software's ACT! "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships" | No |
| DyFuCA Active Alert | X | actalert.exe | Adult content dialler - see here | No |
| Microsoft boot system cfg32 | X | actboost.exe | Detected by Symantec as W32.Bropia.R | No |
| Activity | U | actik.exe | ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| ActionAgent | ? | actionagent.exe | "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required? | No |
| [various names] | X | ActionScr.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| kernel system daemon | X | ACTIVAT0R.exe | Added by the RANDEX.AW WORM! | No |
| Activate Scanner | ? | ACTIVATE.EXE | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon. What does it do and is it required? | No |
| Quick Office | X | activate.exe | Added by the RANSOMLOCK.D TROJAN! Note - this infection hooks the keyboard to prevent anything except numbers from being typed and displays a Russian message requesting a valid license key | No |
| Activation | N | Activation.exe | Part of MS Money 2002 | No |
| MoneyStartUp10.0 | N | Activation.exe | Part of MS Money 2002 | No |
| ActivDRVAutostart | Y | ACTIVcontrol.exe | Part of the ActivDriver driver updates for Promethean's ActivBoard range of interactive whiteboards | No |
| ActivControl | Y | ActivControl2.exe | Part of the ActivDriver driver updates for Promethean's ActivBoard range of interactive whiteboards | No |
| online cdrom | ? | Active acid.exe | ?? | No |
| ATITech | X | Active.exe | Added by the ROAMER-A TROJAN! | No |
| MS Decryption Software | X | active.exe | MediaTickets adware variant | No |
| ACTIVEDS | X | ACTIVEDS.EXE | Added by the OPASERV.T WORM! | No |
| ActiveEyes | N | ActiveEyes.exe | ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start → Programs, create your own shortcut | No |
| ActiveMenu | U | ActiveMenu.exe | WildTangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| HPGamesActiveMenu | U | ActiveMenu.exe | WildTangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| HPLaptopGamesActiveMenu | U | ActiveMenu.exe | WildTangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| ActivePlus | U | activeplus.exe | Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) | No |
| PWSActivePrint_5 | U | ActivePrintSystem.exe | ActivePrint from Pocket Watch LLC - "Windows Mobile users are given the invaluable capability of printing from their mobile devices to any Windows 2000/XP/2003/Vista compatible printer without the necessity of wireless hardware" | No |
| ActiveScan Antivirus | X | ActiveScan.exe | Added by the RBOT-FKQ WORM! | No |
| Active shield | U | Activeshield.exe | Active Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses" | No |
| Roam04 | X | ActiveX.exe | Added by the ROAMER-A TROJAN! | No |
| ACTIVfilter | Y | ACTIVfilter.exe | Part of the ActivDriver driver updates for Promethean's ActivBoard range of interactive whiteboards | No |
| ActMaker | U | ActMak25.exe | ActMaker mouse recorder that "can record your operations under Windows, and preset a time for its launch into operation. This mouse recorder can reduce your work pressure to a great extent" | No |
| Access Connections | U | ACTray.exe | System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" | Yes |
| ACTray | U | ACTray.exe | System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" | Yes |
| ThinkVantage Access Connections | U | ACTray.exe | System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" | Yes |
| Actual Window Manager | U | ActualWindowManagerCenter.exe | Actual Window Manager from Actual Tools - "an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive, convenient and enjoyable" | No |
| Actual Window Minimizer | U | ActualWindowMinimizerCenter.exe | Actual Window Minimizer - "allows minimizing any window to task tray notification area or to the edge of the screen" | No |
| ACU | U | ACU.exe | Qualcomm Atheros wireless Client Utility | No |
| ACU_QSB | U | ACU.exe | Qualcomm Atheros wireless Client Utility | No |
| ACWLIcon | U | ACWLIcon.exe | Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically." This is the System Tray icon giving notifications of and access to the Wireless Connection Status | Yes |
| ThinkVantage Access Connections | U | ACWLIcon.exe | Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically." This is the System Tray icon giving notifications of and access to the Wireless Connection Status | Yes |
| Ad Blocker Pro | U | Ad Blocker Pro.exe | Ad Away popup and banner remover | No |
| AdKiller | X | AD Defender.exe | Part of the Advanced Spyware Remover rogue spyware remover - not recommended, see here | No |
| AAW | U | Ad-Aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool | No |
| Ad-Aware | X | Ad-Aware.exe | Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware anti-malware tool and is located in %System% | No |
| Ad-Aware | U | Ad-Aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool | No |
| Adaware Bootup | U | Ad-aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool | No |
| Lavasoft Ad-Aware | X | Ad-Aware.exe | Added by the RBOT-SO WORM! Note - this is not the popular Ad-Aware anti-malware tool and is located in %System% | No |
| Ad-Eliminator | X | ad-eliminator.exe | Ad-Eliminator rogue spyware remover - not recommended, see here | No |
| AWMON | U | Ad-Monitor.exe | F-Secure Anti-Spyware | No |
| Ad-Protect | U | ad-protect.exe | Ad-Protect spyware and spam monitoring tool | No |
| AdwareProMFC | X | Ad-Ware Pro.exe | Ad-Ware Pro rogue security software - not recommended | No |
| Ad-watch | U | Ad-watch.exe | Part of older versions of the Plus and Pro versions of Ad-Aware from Lavasoft - realtime monitor watching your memory and registry for malware that tries to install or change your system | No |
| AWMON | U | Ad-Watch.exe | Part of older versions of the Plus and Pro versions of Ad-Aware from Lavasoft - realtime monitor watching your memory and registry for malware that tries to install or change your system | No |
| Lavasoft Adwatch | U | Ad-watch.exe | Part of older versions of the Plus and Pro versions of Ad-Aware from Lavasoft - realtime monitor watching your memory and registry for malware that tries to install or change your system | No |
| ad0cf09be9d9be35254a664a06d4d9b1 | X | ad0cf09be9d9be35254a664a06d4d9b1.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| AD2KClient | U | AD2KClient.exe | Active Disk from Iomega - allows software applications to be run directly from compatible removable media such as Zip®, Rev, FireWire, USB and Mini flash. Required if you wish the applications to launch on insertion of a disk | No |
| Iomega Active Disk | U | AD2KClient.exe | Active Disk from Iomega - allows software applications to be run directly from compatible removable media such as Zip®, Rev, FireWire, USB and Mini flash. Required if you wish the applications to launch on insertion of a disk | No |
| ad4d45303f2237f7bec35a28f3352dd7 | X | ad4d45303f2237f7bec35a28f3352dd7.exe | Detected by McAfee as RDN/Generic.tfr!a and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Ad5beART | X | Ad5beART.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| gdsfdsdad | X | adadssta.exe | Detected by McAfee as RDN/Generic Dropper!j and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Ad Arrest | U | adarrest.exe | Ad Arrest IE popup killer from GameFools | No |
| Adaware lptt01 | X | adaware.exe | RapidBlaster variant (in a "adaware" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Lavasoft Ad-Aware | No |
| Adaware ml097e | X | adaware.exe | RapidBlaster variant (in a "adaware" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Lavasoft Ad-Aware | No |
| Ad-Aware Browsing Protection | Y | adawarebp.exe | Part of the Ad-Aware Security Add-On from Lavasoft - which "protects you from dangerous websites. By checking in real-time URL against a constantly updated list of suspected malware and phishing sites, Ad-Aware Add-On lets you explore the web safely" | No |
| AdBin | U | AdBin.exe | AdBin - "Free and easy solution to managing your Window's hosts file. A fun way to block ads" | No |
| Browser Pal | X | adblck.exe | BrowserAid/BrowserPal foistware | No |
| Systweak Ad and Popup Blocker | U | adblock.exe | Ad & Popup Blocker from the Advanced System Optimizer utility suite by Systweak Inc | No |
| BlockAds | U | AdBlocker.exe | Ad blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| Adobe Driver Update | X | adbreader.exe | Detected by McAfee as PWS-Zbot.gen.hv and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft Adobe Driver Update | X | adbreader.exe | Detected by Sophos as W32/Neeris-Q and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Active Desktop Calendar | U | ADC.EXE | XemiComputers Active Desktop Calendar | No |
| XemiCo | U | ADC.EXE | XemiComputers Active Desktop Calendar | No |
| adcareup | X | adcareup.exe | AdCare rogue security software - not recommended, removal instructions here | No |
| Add**.exe [* = random char] | X | Add**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Add**32.exe [* = random char] | X | Add**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| BB | X | add.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| AddClass | X | AddClass.exe | CoolWebSearch Addclass parasite variant | No |
| AdDelete | U | AdDelete.exe | Banner advertisment blocker | No |
| addenbaragent | X | addenbaragent.exe | Detected by McAfee as Generic.tfr | No |
| Addendum | X | Addendum.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles%\addendum\sidebar | No |
| AddendumAgent | X | AddendumAgent.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles%\addendum\sidebar | No |
| Addendum | X | addendume.exe | Detected by Kaspersky as Trojan.Win32.BHO.budy and by Malwarebytes Anti-Malware as Adware.Addendum | No |
| addendum | X | addeninmgr.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles\addendum | No |
| AddendumAgent | X | addentoolagent.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles%\addentool | No |
| AdDestroyer | X | AdDestroyer.exe | AdDestroyer adware | No |
| 1 | X | addit.exe | Added by the SDBOT-RI WORM! | No |
| addons | X | addon.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here | No |
| HKCU | X | addon.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here | No |
| Policies | X | addon.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here | No |
| AudioDeck | U | ADeck.exe | Via Audio Deck - audio control panel for motherboards with supported on-board VIA audio chipsets | No |
| Ashampoo Magical Defrag | U | aDefragCtrl.exe | System Tray access to the main user interface for Ashampoo® Magical Defrag - which "runs in the background as a service, defragmenting when necessary to keep the hard disk tidy" | Yes |
| NNADFREE | U | AdFree.exe | Ad-Free by Net Nanny - "is customizable software for blocking unwanted Internet advertising in your home, small business or school". No longer available | No |
| ADG | ? | ADG.exe | SoundBlaster Audigy related? | No |
| ADGJdet | N | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection | No |
| Jet Detection | N | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection | No |
| Adiras | Y | Adiras.exe | ADSL USB modem related | No |
| adirka | X | adirka.exe | Added by the TIBS-QT TROJAN! | No |
| adir | X | adirss.exe | Added by the SPAMSRV-E TROJAN! | No |
| sysinter | X | adirss.exe | Detected by Trend Micro as TROJ_AGENT.JVJ and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Popup and Advertisement Killers | X | adkillers.exe | Added by the RBOT-DDH WORM! | No |
| svchost | X | ADMAGIC.EXE | Added by the SMIBAG WORM! | No |
| Admanager Controller | X | AdManCtl.exe | Adware, probably a Windupdates variant | No |
| AdMatching | X | AdMatching.exe | Detected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.AdMatching. The file is located in %ProgramFiles%\AdMatching | No |
| Admilli Service | X | AdmilliServ.exe | Admilli Service adware | No |
| Audio3Dadminchk | X | adminchkwindows5.00.2195.1620.exe | Added by the TRITE-A WORM! | No |
| administration | X | administration.exe | Detected by Microsoft as Trojan:MSIL/Scapfrog.A and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| system3 | X | administrator.exe | Detected by Microsoft as Worm:Win32/Autorun.AEO and by Malwarebytes Anti-Malware as Worm.AutoRun | No |
| ADM Library Loader | X | admlib32.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| [12 random characters] | X | admparse.exe | IeDriver adware variant | No |
| Addendum | X | admrup.exe | Detected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Adware.Addendum | No |
| eadden | X | admrup.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles%\Addendum | No |
| iAdden | X | admrup.exe | Detected by Malwarebytes Anti-Malware as Adware.Addendum. The file is located in %ProgramFiles%\Addendum | No |
| admsys | X | admsys.exe | Detected by Symantec as SponsorKeyword and by Malwarebytes Anti-Malware as Adware.K.AdMatching. The file is located in %ProgramFiles%\AdMatching | No |
| ADMTray.exe | ? | admtray.exe | Part of Acer Empowering Technology. What does it do and is it required? | No |
| Ad Muncher | U | AdMunch.exe | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications | No |
| Ad-Muncher | U | ADMUNCH.EXE | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications | No |
| Acronis Drive Monitor | U | adm_tray.exe | System Tray access to and notifications for Acronis Drive Monitor - which "can help predict when a hard drive is about to fail, giving you the chance to backup your data before disaster strikes. When Acronis Drive Monitor identifies a problem, it generates an email or onscreen alert describing the specific finding. It offers a simple and easy to understand explanation of the alert guiding you to the steps you need to take to remedy the issue" | Yes |
| adm_tray | U | adm_tray.exe | System Tray access to and notifications for Acronis Drive Monitor - which "can help predict when a hard drive is about to fail, giving you the chance to backup your data before disaster strikes. When Acronis Drive Monitor identifies a problem, it generates an email or onscreen alert describing the specific finding. It offers a simple and easy to understand explanation of the alert guiding you to the steps you need to take to remedy the issue" | Yes |
| adm_tray.exe | U | adm_tray.exe | System Tray access to and notifications for Acronis Drive Monitor - which "can help predict when a hard drive is about to fail, giving you the chance to backup your data before disaster strikes. When Acronis Drive Monitor identifies a problem, it generates an email or onscreen alert describing the specific finding. It offers a simple and easy to understand explanation of the alert guiding you to the steps you need to take to remedy the issue" | Yes |
| nmadn | X | adnfm.exe | Detected by Dr.Web as Trojan.DownLoader6.46412 and by Malwarebytes Anti-Malware as Adware.Addendum | No |
| Adobe Gamma | U | Adobe Gamma Loader.exe | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| adobe gamma loader | X | adobe gamma loader.exe | Detected by Microsoft as Trojan:Win32/VB. Note - this is not the legitimate Adobe file of the same name which is normally located in %ProgramFiles%\Common Files\Adobe\Calibration - this one is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Adobe Gamma Loader | U | Adobe Gamma Loader.exe | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Gamma Loader.exe | U | Adobe Gamma Loader.exe | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Systems, Inc. Adobe Gamma Loader | U | Adobe Gamma Loader.exe | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Media Player | N | Adobe Media Player.exe | Adobe Media Player - "a next-generation desktop media player, providing high-quality video playback of streamed, downloaded, or locally stored video content. Now discontinued as a stand-lone download, it is still included in some of the Adobe CS4 and CS5 products | Yes |
| WINUPDATER | X | Adobe reader updater.exe | Detected by McAfee as RDN/Generic PWS.y!j and by Malwarebytes Anti-Malware as Backdoor.Agent.ADB | No |
| Adobe | X | adobe.exe | Detected by Malwarebytes Anti-Malware as Spyware.Password. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Adobe | X | Adobe.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| adobe | X | adobe.exe | Detected by Dr.Web as Trojan.KillProc.18173. Note - the file is located in %UserStartup% and %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
| AdobeUpdater | X | Adobe.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Darkkomet. The file is located in %System% | No |
| d5e680da0c3a0008bbfd086e30868721 | X | Adobe.exe | Detected by Dr.Web as Trojan.DownLoader8.19454 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| ADOBE | X | Adobe.run.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData% | No |
| Adobe_AIR | X | AdobeAIR.exe | Detected by Dr.Web as Trojan.MulDrop3.48888. Note - this is not a legitimate entry for the Adobe AIR flash runtime and the file is located in %System%\Adobe | No |
| DW9WOZ8QBY | X | AdobeAIR.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. Note - this is not a legitimate Adobe AIR flash runtime file and it is located in %AppData% | No |
| Adobe Reader Updaters | X | AdobeAMC.exe | Added by the PROLACO-F WORM! | No |
| Adobe ARM | N | AdobeARM.exe | Adobe Reader and Acrobat Manager (ARM) - update/download manager added with Adobe Acrobat/Reader from version 9.x. Taken from the Adobe user forums - "AdobeARM.exe is a part of new Adobe Acrobat\Reader updater. If you manage updates yourself, it is absolutely safe to remove it from Run registry" - see here. The file is located in %CommonFiles%\Adobe\ARM\1.0 | Yes |
| Adobe ARM | X | AdobeARM.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Adobe update manager with the same filename which is normally located in %CommonFiles%\Adobe\ARM\1.0. This one is located in %Windir%\Windows | No |
| Adobe Reader and Acrobat Manager | N | AdobeARM.exe | Adobe Reader and Acrobat Manager (ARM) - update/download manager added with Adobe Acrobat/Reader from version 9.x. Taken from the Adobe user forums - "AdobeARM.exe is a part of new Adobe Acrobat\Reader updater. If you manage updates yourself, it is absolutely safe to remove it from Run registry" - see here. The file is located in %CommonFiles%\Adobe\ARM\1.0 | Yes |
| AdobeARM | N | AdobeARM.exe | Adobe Reader and Acrobat Manager (ARM) - update/download manager added with Adobe Acrobat/Reader from version 9.x. Taken from the Adobe user forums - "AdobeARM.exe is a part of new Adobe Acrobat\Reader updater. If you manage updates yourself, it is absolutely safe to remove it from Run registry" - see here. The file is located in %CommonFiles%\Adobe\ARM\1.0 | Yes |
| adobeARM | X | adobeARM.exe | Detected by Malwarebytes Anti-Malware as Trojan.Autorun.CR. Note - this is not the legitimate Adobe update manager with the same filename which is normally located in %CommonFiles%\Adobe\ARM\1.0. This one is located in %AppData% | No |
| AdobeARM | X | AdobeARM.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.29605 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Adobe update manager with the same filename which is normally located in %CommonFiles%\Adobe\ARM\1.0. This one is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
| AdobeARMS | X | AdobeARMS.exe | Detected by Kaspersky as Trojan.Win32.Buzus.exmx | No |
| Adobe ARP | X | adobearp.exe | Detected by Kaspersky as Trojan.Win32.Buzus.hmto | No |
| AdobeARP | X | AdobeARP.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| AdobeART | X | AdobeART.exe | Detected by McAfee as Downloader.a!bmw and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Adobeclient | X | AdobeClient.Exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| Acrobat Synchronizer | U | AdobeCollabSync.exe | Entry added with Adobe Acrobat 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | No |
| Adobe Acrobat Synchronizer | U | AdobeCollabSync.exe | Entry added with Adobe Acrobat 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | No |
| Adobe Collaboration Synchronizer | U | AdobeCollabSync.exe | Entry added with Adobe Reader 8.0 and Acrobat 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | Yes |
| Adobe Reader Synchronizer | U | AdobeCollabSync.exe | Entry added with Adobe Reader 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | Yes |
| HKCU | X | adobecorpupdate.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\install | No |
| HKLM | X | adobecorpupdate.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\install | No |
| Policies | X | adobecorpupdate.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\install | No |
| Adobe Reader Updater c2 | X | adobecrn.exe | Added by the PROLACO WORM! | No |
| Adobe Acrobat Synchronizer | U | ADOBEC~1.EXE | Entry added with Adobe Acrobat 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | No |
| Adobe Collaboration Synchronizer | U | ADOBEC~1.EXE | Entry added with Adobe Reader 8.0 and Acrobat 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | Yes |
| Adobe Reader Synchronizer | U | ADOBEC~1.EXE | Entry added with Adobe Reader 8.0. Adobe Synchronizer "is a small application that runs in the background, providing synchronization of document reviews and Tracker subscriptions so that your data is available when you need it". See the link for more information | Yes |
| dlmMgr | N | AdobeDownloadManager.exe | Adobe Download Manager - "can prevent you from having to start from the beginning should your download process be interrupted, and it offers a level of service not possible" | No |
| ALDASHAS | X | adobeflash.exe | Detected by McAfee as RDN/Generic Downloader.x!di and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Adobe Flash Player ActiveX Installer | X | AdobeFlashPlayer.exe | Detected by McAfee as Downloader.a!fe and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Adobe Flash Player | X | AdobeFP.exe | Added by the AUTORUN-BBP WORM! | No |
| Adobe Gamma | U | ADOBEG~1.EXE | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Gamma Loader | U | ADOBEG~1.EXE | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Gamma Loader.exe | U | ADOBEG~1.EXE | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Adobe Systems, Inc. Adobe Gamma Loader | U | ADOBEG~1.EXE | Included with older versions of Adobe Photoshop products. Loads the user created ICC profile which adjusts monitor colours across all programs, including Photoshop. Required by some graphics professionals who want their monitor calibrated. Most home users will not need it | Yes |
| Servicos | X | AdobeLanc.exe | Added by the BANKER-EHR TROJAN! | No |
| adobemgr | X | adobemgr.exe | Added by the ADCLICKER TROJAN! | No |
| Adobe Media Player | N | ADOBEM~1.EXE | Adobe Media Player - "a next-generation desktop media player, providing high-quality video playback of streamed, downloaded, or locally stored video content. Now discontinued as a stand-lone download, it is still included in some of the Adobe CS4 and CS5 products | Yes |
| AVGNT | X | AdobePlus.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. The file is located in %Windir%\Microsoft | No |
| AVIRNT | X | AdobePlus.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\Microsoft | No |
| RavAv | X | AdobeR.exe | Added by the RJUMP.D WORM! | No |
| ADOBECUSTOMUPDATE | X | Adober32ds.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\Adober32ds | No |
| AdobeReader.exe | X | AdobeReader.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and here | No |
| ADOBEUPDATE | X | adoberm.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| AdobeA | X | adobes.exe | Detected by McAfee as IRC/Flood.ba | No |
| AdobeUp | X | adobeup.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| AdobeUpdater | X | AdobeUp.exe | Detected by McAfee as Generic PUP.z. Note - the file is located in %ProgramFiles%\Adobe\Reader 9.0 which is a valid directory for Adobe Reader but this is not an Adobe file. The legitimate "AdobeUpdater.exe" file would normally be located in %CommonFiles%\Adobe\Updater5 | No |
| Adobe Center | X | adobeupd.EXE | Added by the SYSWRT.DVD TROJAN! | No |
| Adobe Center | X | adobeupd.exe | Detected by Trend Micro as BKDR_DLDR.A. Note - this entry loads from the Windows Startup folder and the file is located in %UserTemp% | No |
| 8b026cd9a1e8b3d7a5c7c19ed2d24cb7 | X | Adobeupdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| Adobe Update | X | adobeupdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%\com | No |
| adobe32 | X | adobeupdate.exe | Added by the VBINJEC-CG TROJAN! | No |
| Adobe Update Manager | N | AdobeUpdateManager.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| AdobeUpdateManager | N | AdobeUpdateManager.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| updateMgr | N | AdobeUpdateManager.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| Acroread | X | AdobeUpdater.exe | Detected by Sophos as Troj/DwnLdr-IYR. Note - this is not the legitimate Adobe "AdobeUpdater.exe" file for older versions of Adobe products which is normally located in %CommonFiles%\Adobe\Updater5. This one is located in %UserTemp% | No |
| Adobe Update Manager | X | AdobeUpdater.exe | Detected by Microsoft as TrojanDropper:Win32/Duberath.A. Note - the file is located in %ProgramFiles%\Adobe\Reader 9.0\Reader which is a valid directory for Adobe Reader but this is not an Adobe file. The legitimate "AdobeUpdater.exe" file would normally be located in %CommonFiles%\Adobe\Updater5 | No |
| Adobe Updater | N | AdobeUpdater.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) - normally located in %CommonFiles%\Adobe\Updater5 | No |
| Adobe Updater | X | AdobeUpdater.exe | Detected by Sophos as Troj/Bckdr-RFM. Note - this is not the legitimate Adobe "AdobeUpdater.exe" file for older versions of Adobe products which is normally located in %CommonFiles%\Adobe\Updater5. This one is located in %Windir%. | No |
| AdobeUpdater | N | AdobeUpdater.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) - normally located in %CommonFiles%\Adobe\Updater5 | No |
| Adobeupdater | X | adobeupdater.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Adobe "AdobeUpdater.exe" file for older versions of Adobe products which is normally located in %CommonFiles%\Adobe\Updater5. This one is located in %AppData% | No |
| AdobeAdobeUpdaterInstallMgr | X | adobeupdaterinstallmgrupdater.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - the file is located in %CommonFiles%\Adobe\Updater6 which is a valid directory for common Adobe files but this is not a valid file | No |
| AdobeUpdaterInstallMgrAdobeUpdater | X | adobeupdaterinstallmgrupdater.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - the file is located in %CommonFiles%\Adobe\Updater6 which is a valid directory for common Adobe files but this is not a valid file | No |
| AdobeUpdaterUpdater | X | adobeupdaterinstallmgrupdater.exe | Added by an unidentified VIRUS, WORM or TROJAN! Note - the file is located in %CommonFiles%\Adobe\Updater6 which is a valid directory for common Adobe files but this is not a valid file | No |
| AdobeUpdate | X | Adobeupdt32.exe | Detected by Sophos as Troj/Mdrop-DRR and by Malwarebytes Anti-Malware as Trojan.SHarpro.Pgen | No |
| Adobe Flash Player Update | X | Adobe_Flash_Player.exe | Detected by Malwarebytes Anti-Malware as Worm.Rebhip. The file is located in %Temp% | No |
| ALSrvN | X | adobe_lr.exe | Detected by Dr.Web as Trojan.MulDrop4.1101 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| adobe_sl | X | adobe_sl.exe | Detected by Sophos as Troj/Zbot-EAR and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this entry loads from the Windows Startup folder | No |
| Adobe System Update | X | Adobe_Update.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here. The file is located in %UserTemp%\IXP00[random digit].TMP | No |
| Adobe Updater | N | Adobe_Updater.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| Adobe_Updater | N | Adobe_Updater.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| AdobeUpdater6 | N | Adobe_Updater.exe | Automatic updates for earlier versions of Adobe products such as Adobe Reader (PDF file viewer) and Adobe Acrobat (PDF file creation/editing) | No |
| adodemaster | X | adodemaster.exe | Downloader of Korean origin, detected as ADOD.28672 | No |
| Ad Online Guide | ? | adonlineguide.exe | ?? | No |
| adp | X | adp.exe | Spyware installed by Net2Phone, Limewire, Cydoor, Grokster, KaZaa, etc | No |
| ATM Control | X | adpn.exe | Added by the MMS.A WORM! | No |
| Aapp | X | adprot | AdBlaster adware | No |
| adprot | X | adprot.exe | AdBlaster adware | No |
| [12 random characters] | X | ADPTIF67.exe | IeDriver adware variant | No |
| Adobe_ | X | adqbe.exe | Detected by Dr.Web as BackDoor.Sepultura.81 and by Malwarebytes Anti-Malware as Trojan.Agent.ADB | No |
| adsafer | X | adr.exe | AdSafer rogue security software - not recommended, removal instructions here | No |
| OpenApi | X | adropen.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| ADS Adware Remover | X | ADS Adware Remover.exe | ADS Adware Remover, rogue adware remover - not recommended, removal instructions here | No |
| windows | X | ads.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.WNDGen. The file is located in %AppData% | No |
| AdsAlert | X | AdsAlert.exe | AdsAlert rogue security software - not recommended | No |
| AdsCleaner | U | AdsCleaner.exe | "AdsCleaner is a perfect ad stopper and pop up blocker. It blocks banners by black list, by dimension. It allows shrink page exclude place occupy advertising. Online privacy tool. Advanced bookmark manager with powerful search engine" | No |
| adsacquy | X | adsclick.exe | Detected by Dr.Web as Trojan.DownLoader7.20916 and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| Updater | X | adservernow.exe | AdServerNow adware | No |
| ADService | U | ADService.exe | Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AdsGone | U | Adsgone.exe | AdsGone - pop-up stopper | No |
| AdsGone 2003 | U | Adsgone.exe | AdsGone - pop-up stopper | No |
| AdsGone 2004 | U | Adsgone.exe | AdsGone - pop-up stopper | No |
| AdsGone 2005 | U | Adsgone.exe | AdsGone - pop-up stopper | No |
| AdsGone 2006 | U | Adsgone.exe | AdsGone - pop-up stopper | No |
| SyncMon | X | adslcomdos.exe | Added by the CLUNKY-A TROJAN! | No |
| adsmap.exe | X | adsmap.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\adsmap | No |
| ADSMTray | Y | ADSMTray.exe | ASUS Data Security Manager provides password protected data encryption on ASUS notebooks | No |
| adsnwe | U | adsnwe.exe | EmailSpyMonitor E-mail surveillance software. Uninstall this software unless you put it there yourself | No |
| adsnwk | U | adsnwk.exe | Keylogger Spy Monitor keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| adsnws | U | adsnws.exe | ScreenSpyMonitor surveillance software. Uninstall this software unless you put it there yourself | No |
| adsnwy | U | adsnwy.exe | Yahoo! Messenger Spy Monitor - "spyware program that records Yahoo! Instant Messenger information on the computer and saves it to a log file". Uninstall this software unless you put it there yourself | No |
| aDSProcMngr | U | aDSProcMngr.exe | Part of PC Tools Disk Suite from PC Tools - which "is an all-in-one hard-disk management utility that integrates disk optimization, defragmentation and backup tools in one easy to use package". Proxy (or agent) for the Disk Suite Service. Based upon my experience, if this is disabled it does not appear to adversely affect on-demand or scheduled tasks but has a "U" recommendation as it's function isn't fully known | Yes |
| DiskSuite | U | aDSProcMngr.exe | Part of PC Tools Disk Suite from PC Tools - which "is an all-in-one hard-disk management utility that integrates disk optimization, defragmentation and backup tools in one easy to use package". Proxy (or agent) for the Disk Suite Service. Based upon my experience, if this is disabled it does not appear to adversely affect on-demand or scheduled tasks but has a "U" recommendation as it's function isn't fully known | Yes |
| PC Tools Disk Suite | U | aDSProcMngr.exe | Part of PC Tools Disk Suite from PC Tools - which "is an all-in-one hard-disk management utility that integrates disk optimization, defragmentation and backup tools in one easy to use package". Proxy (or agent) for the Disk Suite Service. Based upon my experience, if this is disabled it does not appear to adversely affect on-demand or scheduled tasks but has a "U" recommendation as it's function isn't fully known | Yes |
| ADSS | Y | ADSS.exe | ADSS is part of Access Denied security and privacy software (Access Denied Security Server) that monitors power status and provides some other services for Screen Guard. Important to keep its running while using Access Denied | No |
| Adstartup | X | Adstartup.exe | Adlogix adware | No |
| AdStatus Service | X | AdStatServ.exe | WindUpdates AdStatus Service adware | No |
| ADSTOP | X | adstopup.exe | AdStop rogue security software - not recommended, removal instructions here | No |
| AdSubtract | U | adsub.exe | AdSubtract blocks ads, cookies, pop-up windows, animations, music, and more. Can be disabled from within AdSubtract. Available via the Start menu. Superseded by Trend Micro AntiSpyware which was subsequently discontinued | No |
| Subtract the Ads | N | AdSub.exe | Removes adverts from web pages. Although useful - not required | No |
| adsup.exe | X | adsup.exe | Detected by Dr.Web as Trojan.DownLoad3.17581 and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| adtech2005 | X | adtech2005.exe | Detected by Kaspersky as the STARTPAGE.AW TROJAN! | No |
| adtech2006 | X | adtech2006.exe | Detected by Kaspersky as the VB.KC WORM! | No |
| Adtools Service | X | AdTools.exe | Adtools adware | No |
| ADQuickAccess | N | Adtray.exe | After Dark for Windows. Screen saver creation program produced before screen savers became integrated into Win95 | No |
| ADU | ? | adu.exe | Related to Cisco Aironet wireless products. What does it do and is it required? | No |
| ASDPLUGIN | X | adult1.exe | AsdPlug premium rate adult content dialer | No |
| AdultX | X | AdultX.exe | Adult content dialler and hijacker | No |
| Adult_Chat | X | Adult_Chat.exe | RawAsn-B adult content dialler | No |
| Adult_Chat1 | X | Adult_Chat1.exe | Adult content dialler | No |
| ADUserMon | U | ADUserMon.exe | Part of Active Disk from Iomega - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk | No |
| Office Monitor | X | adv32.exe | Detected by Sophos as W32/Sdbot-CWO | No |
| advanceddefender | X | advanceddefender.exe | Advanced Defender rogue security software - not recommended, removal instructions here | No |
| AdVantage | X | AdVantage.exe | MeMedia.AdVantage adware | No |
| AdVantage Setup | X | AdVantageSetup.exe | MeMedia.Advantage adware - optionally installed with older versions of the DAEMON Tools Lite CD emulation tool (if you don't uncheck the "DAEMON Tools sponsor ad module" option during install) and possibly others | Yes |
| [unknown] | X | ADVAP.EXE | Added by the SDBOT-W WORM! | No |
| Advapi | X | Advapi.exe | Added by the NETDEVIL.12 BACKDOOR! | No |
| Advanced Tools Check | N | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget | No |
| ADVCHK | N | ADVCHK.EXE | Checks when you install a new version of a Norton product that you have uninstalled all previous versions. Serves as a reminder if you forget | No |
| Advanced Tool Checks | X | advchks.exe | Added by a variant of Win32/Rbot | No |
| Incredible Keylogger | X | AdvKeylog.exe | IncredibleKeylogger spyware | No |
| Advmon32 | X | advmon32.exe | Added by the GEMA TROJAN! | No |
| wextract_cleanup0 | N | advpack.dll,DelNodeRunDLL32 [path] [filename].TMP | Wextract Cleanup0 is valid and legal software included or sold to help clean up temporary or cab files created by the installer software for a wide variety of software. It should disapear after a restart of the system. If not fix it | No |
| [12 random characters] | X | advpack1.exe | IeDriver adware variant | No |
| Advanced Protection System | X | advpsys.exe | Added by a variant of Win32/Rbot | No |
| load= | N | adw30.exe | After Dark for Windows - screen saver program. Popular before screen savers were integrated into Win95 | No |
| Adware Agent | U | adware agent.exe | Adware Agent popup blocker | No |
| AdwareAlert | U | AdwareAlert.Exe | Adware program, previously not recommended (see here). It has now been delisted, so make sure you have the latest version | No |
| AdwareDelete | X | adwaredelete.exe | AdwareDelete rogue adware remover - not recommended, removal instructions here | No |
| AdwareProtector | X | AdwareProtector.exe | Part of rogue security tools, including SystemDoctor, ErrorSafe and WinFixer | No |
| Adware Punisher | X | AdwarePunisher.exe | Adware Punisher rogue spyware remover - not recommended, removal instructions here | No |
| Adware Punisher Monitor | X | AdwarePunisher_monitor.exe | Adware Punisher rogue spyware remover - not recommended, removal instructions here | No |
| AdwareRemover2007 | X | AdwareRemover2007.exe | AdwareRemover2007 rogue security software - not recommended, removal instructions here | No |
| Adware Spy | X | AdwareSpy.exe | AdwareSpy rogue adware remover - not recommended, removal instructions here | No |
| AdwareSpy | X | AdwareSpy4.exe | AdwareSpy rogue adware remover - not recommended, removal instructions here | No |
| Adware_ProNET | X | Adware_Pro.exe | Adware Pro rogue security software - not recommended, removal instructions here | No |
| Adwarz Spy Remover | X | ADWARZ.EXE | Added by the SPYBOT-EV WORM! | No |
| *MSConfig32 | X | aecache.exe | Detected by F-Secure as the OBFUSCATED.GP TROJAN! | No |
| Machine Works, Inc. | X | aecces.exe | Added by the VB-ELW TROJAN! | No |
| AEFltrs | U | AEFltrs.exe | Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation, graphic equalizer, echo Cancellation and beam forming. The exact purpose of this entry is unknown at present - hence the "U" recommendation | Yes |
| AEFltrs Application | U | AEFltrs.exe | Part of the XP installation of the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation, graphic equalizer, echo Cancellation and beam forming. The exact purpose of this entry is unknown at present - hence the "U" recommendation | Yes |
| Aeiwlsta.exe | ? | Aeiwlsta.exe | IBM High Rate Wireless LAN Adapter driver. Is it required? | No |
| SharkEject | N | AEJCT32.exe | Allows you to eject a disk from the Avatar Shark drive from the system tray. When loaded, there is a desktop icon so this isn't required | No |
| AELaunch | N | AELaunch.exe | Audio Applications Launcher for the Philips Acoustic Edge soundcard | No |
| Active Email Monitor | U | aem25.exe | Active Email Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email | No |
| Aero Gmail | U | Aero Gmail.exe | Aero Gmail widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Aero Gmail.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Aero Gmail.exe | Aero Gmail widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Aero Gmail.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entry | Yes |
| Aero Midnight Clock | U | Aero Midnight Clock.exe | Clock gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight Clock.exe | U | Aero Midnight Clock.exe | Clock gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight RSS Reader | U | Aero Midnight RSS Reader.exe | RSS Reader gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight RSS Reader.exe | U | Aero Midnight RSS Reader.exe | RSS Reader gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight Weather | U | Aero Midnight Weather.exe | Weather gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| Aero Midnight Weather.exe | U | Aero Midnight Weather.exe | Weather gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| Aero Gmail | U | AEROGM~1.EXE | Aero Gmail widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Aero Gmail.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Aero Gmail.exe" is shown as "AEROGM~1.EXE" | Yes |
| DesktopX Widget | U | AEROGM~1.EXE | Aero Gmail widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Aero Gmail.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 entry where "Aero Gmail.exe" is shown as "AEROGM~1.EXE" | Yes |
| Aero Midnight Clock | U | AEROMI~1.EXE | Clock gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight RSS Reader | U | AEROMI~1.EXE | RSS Reader gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation | Yes |
| Aero Midnight Weather | U | AEROMI~1.EXE | Weather gadget included with the Aero Midnight MyColors theme supplied with Theme Manager from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| AeroSnap | U | AeroSnap.exe | "AeroSnap is a simple but powerful application that allows you to resize, arrange or maximize your desktop windows with just drag'n'drop. Simple drag a window to a side of your desktop to snap it or drag it to the top to maximize" | No |
| AERVICESN | X | AERVICESN.exe | Added by the RANDON-AO WORM! | No |
| AeXAgentLogon | N | AeXAgentActivate.exe | Altiris Agent transmits information about your machine for the purpose of asset management and deployment. Now part of Symantec's Altiris Product Family since they acquired Altiris | No |
| AeXAgentLogon | U | AeXAgentActivate.exe | Part of Altiris (by Symantec) "service-oriented management solutions provide a modular and future-proof approach to managing highly diverse and widely distributed IT infrastructures" | No |
| Microsoftz turn Control | X | aexl.exe | Added by the SDBOT.BCO WORM! | No |
| NSHelper | U | aexnsinstallhelper.exe | Altiris Express Notification Server Install helper - monitors integrity of the installation | No |
| AeXSWDUsr | ? | AeXSWDUsr.exe | Altiris Express NS Client Manager software. Now part of Symantec's Altiris Product Family since they acquired Altiris. Is it required? | No |
| af029b7100cbb27d8c0472b97315e8d5 | X | af029b7100cbb27d8c0472b97315e8d5.exe | Detected by Dr.Web as Trojan.DownLoader8.32072 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| af8e95a43cac5319b6cccfe239aa33bd | X | af8e95a43cac5319b6cccfe239aa33bd.exe | Detected by McAfee as RDN/Generic.dx!bc3 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| AFProg | ? | AFController.exe | Part of Hotspot Shield - which "protects your entire web surfing session; securing your connection at both your home Internet network & Public Internet networks (both wired and wireless). Hotspot Shield protects your identity by ensuring that all web transactions (shopping, filling out forms, downloads) are secured through HTTPS" | No |
| Cftmon32 | X | afd.exe | Added by the AUTORUN-AUB WORM! The "afd.exe" file is located in %Windir% | No |
| Cftmon32 | X | afd.exe | Added by the SCAR.AYWK TROJAN! The "afd.exe" file is located in %AppData% | No |
| Adobe Filter Platform | X | afilterplatform.exe | Added by the RBOT-OP WORM! | No |
| afmsmsgs | X | afmsmsgs.exe | Added by the DLOADR-CUX TROJAN! | No |
| xzkadsfk10 | X | afslkfasl10.exe | Added by the ONLINEG-R TROJAN! | No |
| aftrnc | X | aftnc32.exe | Detected by Sophos as Mal/Inject-CY | No |
| MS Agent Protection | X | ag1.exe | Added by the IRCBOT.AZ BACKDOOR! | No |
| yaahaha | X | age yaha.exe | Detected by Microsoft as Backdoor:Win32/Bezigate.A | No |
| Agence | X | Agence.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| Agenda | X | Agenda.exe | Detected by Sophos as Troj/DwnLdr-KQV. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Agendamb | X | Agendamb.exe | Detected by Sophos as Troj/DwnLdr-KQV and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Agent | N | Agent.exe | Cyberlink's Power VCR II 3.0 is a TV tuner recording utility. If you want to schedule recordings you'll need this, otherwise can be disabled. Available via Start → Programs | No |
| agent.exe | X | agent.exe | Part of rogue security tools, including Privacy Center, Privacy Components and Control Center | No |
| Backdoor.NuAgent | X | agent.exe | Added by the AGENT-DP TROJAN! | No |
| bifit_agent | X | agent.exe | Detected by Dr.Web as Trojan.PWS.Ibank.689 and by Malwarebytes Anti-Malware as Trojan.Bifit | No |
| ExtraFilmHemmaAgent | N | Agent.exe | ExtraFilm Photo Assistant | No |
| LookNMeet | N | Agent.exe | LooknMeet dating service | No |
| AgentSpyware | X | AgentSpyware.exe | AgentSpyware rogue spyware remover - not recommended, removal instructions here | No |
| SR Agent | Y | AGENTSVC.EXE | Related to Secure Resolutions - desktop virus protection | No |
| agentsvr | X | agentsvr.exe | Detected by Kaspersky as Monker.A adware. Note - do not confuse with the Microsoft Agent Server application of the same name as described here - the legitimate file will always be located in the Windows\Msagent folder | No |
| RavUptets | X | agetlke.exe | Added by the QQPASS-AK TROJAN! | No |
| RavUptkt | X | agetlktz.exe | Added by the QQPASS-AJ TROJAN! | No |
| AgfaCLnk | U | AgfaCLnk.exe | For Agfa digital cameras connected via USB. Enables Windows to access the contents of the memory stick (while the stick's still on the camera) via a virtual drive | No |
| Windows Service Agent | X | agl23.exe | Added by the RBOT-GQU WORM! | No |
| GroupWise PDA Connect - GrpWse | U | Agnt.exe | GroupWise PDA Connect PDA synchronisation utility - from Novell | No |
| agp | X | agp32.exe | Detected by Symantec as W32.Gaobot.SY | No |
| AGPVideo16 | X | agp6xdrv.exe | Added by the AUTORUN-WZ WORM! | No |
| agpart | N | agpart11.exe | Program for finding trucks on-line | No |
| Creative AGP Wizard | N | agpwiz.exe | Part of Creative's BlasterControl | No |
| QuickPassword | U | agquickp.exe | Smart card-based authentication and digital signature client software | No |
| Forget Me Not | N | AGRemind.exe | Calendar reminder part of Broderbund's American Greetings® CreataCard® | No |
| Agere SoftModem Messaging Applet | U | AGRSMMSG.exe | Installed with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem | Yes |
| AGRSMMSG | U | AGRSMMSG.exe | Installed with the drivers for internal software modems based upon Lucent/Agere Systems chipsets - required if you use the SoftModem Assistant to configure the modem | Yes |
| AGSatellite | N | AGSatellite.exe | Program from AudioGalaxy that lets you download some MP3s from their server. Available via Start → Programs | No |
| AGSeyApp | U | AGSeyApp.exe | GoldenEye surveillance software. Uninstall this software unless you put it there yourself | No |
| Application Layer Scheduler | X | agtsvc.exe | Added by the IRCBOT.BJJ BACKDOOR! | No |
| aha2 | X | aha2.exe | Detected by Malwarebytes Anti-Malware as Trojan.Startrun.RU. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Ashampoo HDD-Control 2 Guard | U | AHDDC2_Guard.exe | Part of Ashampoo® HDD Control 2 - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard 2 component on startup which runs in the background and monitors the hard drives and provides System Tray access | No |
| ahfp | U | ahfp.exe | Advanced Hide Folders - "is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others." Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| ahfprog | U | ahfp.exe | Advanced Hide Folders - "is powerful security program that allows you to hide any number of files or folders. It is very useful to keep your personal data from others." Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Control handler | X | ahjinst.exe | CoolWebSearch parasite variant | No |
| Winsock32 driver | X | ahmadi nejad.exe | Detected by McAfee as MultiDropper-DC | No |
| c0b6b56d66fd455a280a4ddb531e30d5 | X | ahmed.exe | Detected by Dr.Web as Trojan.DownLoader8.17711 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Configuration Loader | X | ahnhst.exe | Detected by Trend Micro as WORM_AGOBOT.MX | No |
| AHNSD | Y | AhnSD.exe | AhnLab V3 antivirus updater - leave enabled unless you manually update on a regular basis | No |
| AHNUE | ? | AHNUE.exe | ?? | No |
| ahost | X | ahost.exe | Added by a variant of W32/Sdbot.worm | No |
| AHQInit | N | ahqinit.exe | Part of AudioHQ for the Soundblaster Live!. Appears as though it makes the AudioHW toolbar drop down from the top of the desktop and isn't required | No |
| AutoEA | N | Ahqrun.exe | For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ | No |
| AudioHQ | N | Ahqtb.exe | For Creative Soundblaster Live! series soundcards. System tray application for SB Live! functions. Available via Start → Programs | No |
| AudioHQU | N | AHQTBU.EXE | System Tray application installed with the drivers for Creative Labs SoundBlaster Live! Can be run from Start → Programs | No |
| antihost | X | ahr.exe | Detected by Sophos as Troj/Bancban-QJ | No |
| ahui32.exe | X | ahui32.exe | Added by the CERTIF-M TROJAN! | No |
| load= | Y | AICLIENT.EXE | Asset Insight from Tangram - asset managing software. Required if an organisation is running a centrally administered asset management system | No |
| aiepk | U | aiepk2.exe | Another IE Popup Killer - pop-up stopper | No |
| Another Internet Explorer Popup Killer | U | aiepk2.exe | Another IE Popup Killer - pop-up stopper | No |
| msvhost | X | aig.exe | Detected by Sophos as Troj/Aimbot-BC | No |
| Testing 123 | X | aightn.exe | Detected by Total Defense as Win32.Randin.A | No |
| MSConfig | X | aikc.exe | Detected by McAfee as PWS-Zbot-FAHQ!77FE1FA59328 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| AIM | U | AIM+.exe | AIM plus - a free add-on to AOL's Instant Messenger for Windows from Big-O Software | No |
| AIM | N | aim.exe | AOL Instant Messenger. If connected to the internet, automatically runs up AIM. Convenience more than anything. Available via Start → Programs | No |
| Aim Quick Start | X | Aim.exe | Added by the FORBOT-BB WORM! Note - this is not the popular AOL Instant Messenger utility | No |
| AOL Instant Messanger | X | aim.exe | Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility | No |
| Microsoft | X | aim.exe | Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility | No |
| Aim6 | N | aim6.exe | AOL Instant Messenger - start it when you want to use it | No |
| AOL Instant Messenger 7.213 | X | aim9283.exe | Added by the SDBOT-ZF WORM! | No |
| AIM95 Startup | X | aim95.exe | Detected by Trend Micro as WORM_AGOBOT.AEE | No |
| Configuration Loader | X | aim95.exe | Added by the SDBOT BACKDOOR! | No |
| aimaol lptt01 | X | aimaol.exe | RapidBlaster variant (in a "aimaol" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| aimaol ml097e | X | aimaol.exe | RapidBlaster variant (in a "aimaol" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| aimb.exe" -h | U | aimb.exe | IMSufSentinel is a spy program which can record IM conversations, log keystrokes, record URLs visited, and take screenshots. If you didn't install this yourself remove it | No |
| AimingClick | N | AimingClick.exe | AimingClick from AimingTech. Web searching tool. Available via Start → Programs | No |
| laim | U | aimlite.exe | "AIM Lite is a reference application for testing some new client technology developed here at AOL®, with the goal of being a simple, fun, light IM client" | No |
| AIM Logger | N | AIMLogger.exe | AIM Logger - saves AIM (AOL Instant Messenger) conversations to log files. Can be started when you are using AIM | No |
| AimMonitor | U | AimMonitor.exe | AIM Monitor Sniffer surveillance software for the AIM instant messenger. Uninstall this software unless you put it there yourself | No |
| WindowsBool | X | aimplg.exe | Added by the SDBOT-CNG WORM! | No |
| Aim Plugin | X | aimplugin.exe | Added by the GUAP-F WORM! | No |
| AIMPro | U | aimpro.exe | AIM Pro - secure instant messaging, video conferencing, on-line meetings and desktop and file sharing | No |
| AOL Instant Messenger | X | aimsgr.exe | Added by the IRCBOT.N TROJAN! | No |
| Aol Configuration Loader | X | aimsng.exe | Added by the SDBOT-XE WORM! | No |
| Aimster | N | Aimster.exe | Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network | No |
| AIMWDInstall | N | AIMWDInstall.exe | Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| AIMWDInstallFilename | N | AIMWDInstall.exe | Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| AIMWDInstallFilename | N | AIMWDI~1.EXE | Version of the WildTangent on-line games installer that came with versions of AOL Instant Messenger. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case | No |
| Ai Nap | U | AiNap.exe | Part of the AI Suite system management utility included with some ASUS motherboards. "AI Nap allows you to minimize the power consumption of your computer whenever you are away. Enable this feature for minimum power consumption and quieter system operation" | Yes |
| AiNap | U | AiNap.exe | Part of the AI Suite system management utility included with some ASUS motherboards. "AI Nap allows you to minimize the power consumption of your computer whenever you are away. Enable this feature for minimum power consumption and quieter system operation" | Yes |
| AiNap.exe | U | AiNap.exe | Part of the AI Suite system management utility included with some ASUS motherboards. "AI Nap allows you to minimize the power consumption of your computer whenever you are away. Enable this feature for minimum power consumption and quieter system operation" | Yes |
| D-Link Air USB Utility | U | AirCFG.exe | D-Link Air USB wireless configuration utility | No |
| D-Link Air Utility | U | AirCFG.exe | D-Link Air PCI wireless configuration utility | No |
| aircity | X | aircity.exe | Related to "Prutect" malware from e2Give | No |
| ethernet | X | airftp.exe | Added by a variant of W32/Sdbot.worm | No |
| AirGCFG | U | AirGCFG.exe | Configuration utility for a number of wireless routers and adapters from D-Link | No |
| D-Link AirPlus G | U | AirGCFG.exe | D-Link Airplus G wireless router configuration utility | No |
| D-Link D-Link DWA-125 | U | AirGCFG.exe | D-Link DWA-125 Wireless 150 USB adapter configuration utility | No |
| D-Link D-Link Wireless G DWA-110 | U | AirGCFG.exe | D-Link DWA-110 Wireless G USB adapter configuration utility | No |
| D-Link D-Link Wireless G DWA-510 | U | AirGCFG.exe | D-Link DWA-510 Wireless G desktop adapter configuration utility | No |
| D-Link D-Link Wireless G DWL-G122_DWA-110 | U | AirGCFG.exe | D-Link DWL-G122 Wireless USB and DWA-110 Wireless G USB adapters configuration utility | No |
| D-Link Wireless G WDA-1320 | U | AirGCFG.exe | D-Link WDA-1320 Wireless G desktop adapter configuration utility | No |
| D-Link Wireless G WUA-1340 | U | AirGCFG.exe | D-Link WUA-1340 Wireless G USB adapter configuration utility | No |
| AirNCFG | U | AirNCFG.exe | Configuration utility for a number of wireless routers and adapters from D-Link | No |
| D-Link D-Link DWA-525 | U | AirNCFG.exe | D-Link DWA-525 Wireless N Desktop PCI adapter configuration utility | No |
| D-Link D-Link RangeBooster N DWA-140 | U | AirNCFG.exe | D-Link DWA-140 RangeBooster N USB adapter configuration utility | No |
| D-Link D-Link Wireless N Dual Band DWA-160 | U | AirNCFG.exe | D-Link DWA-160 Xtreme N Dual Band USB adapter configuration utility | No |
| D-Link D-Link Wireless N DWA-130 | U | AirNCFG.exe | D-Link DWA-130 Wireless N USB adapter configuration utility | No |
| D-Link D-Link Wireless N DWA-140 | U | AirNCFG.exe | D-Link DWA-140 RangeBooster N USB adapter configuration utility | No |
| D-Link D-Link Xtreme N Dual Band DWA-160 | U | AirNCFG.exe | D-Link DWA-160 Xtreme N Dual Band USB adapter configuration utility | No |
| D-Link AirPlus | U | AirPlus.exe | D-Link wireless configuration utility | No |
| D-Link AirPlus G Wireless Utility | U | AirPlus.exe | D-Link AirPlus G wireless configuration utility | No |
| AirPlusCFG | U | AirPlusCFG.exe | Configuration utility for a number of wireless routers and adapters from D-Link | No |
| D-Link AirPlus XtremeG | U | AirPlusCFG.exe | D-Link AirPlus Xtreme G wireless access point configuration utility | No |
| D-Link AirPlus XtremeG DWL-G520 | U | AirPlusCFG.exe | D-Link DWL-G520 AirPlus Xtreme G PCI wireless adapter configuration utility | No |
| D-Link D-Link Wireless 108G DWA-120 | U | AirPlusCFG.exe | D-Link DWA-120 Wireless 108G USB adapter configuration utility | No |
| D-Link D-Link Wireless 108G DWA-520 | U | AirPlusCFG.exe | D-Link DWA-520 Wireless 108G desktop adapter configuration utility | No |
| D-Link RangeBooster G WDA-2320 | U | AirPlusCFG.exe | D-Link WDA-2320 RangeBooster G desktop adapter configuration utility | No |
| D-Link RangeBooster G WUA-2340 | U | AirPlusCFG.exe | D-Link WUA-2340 RangeBooster G USB adapter driver configuration utility | No |
| Media Manager Indexer | U | AIRSVCU.EXE | Part of MS Visual InterDev, Media Manager is an easy media file management system that works in conjunction with Windows Explorer. The Media Manager Indexer is a program that indexes all the information about your media files and puts it into a database | No |
| AJC Active Backup | U | AJCActBk.exe | AJC Active Backup from AJC Software - "Instantly backup files you change on your PC and keep multiple versions to undo" | No |
| (Default) | X | ajsha5.exe | Added by the SPYBOT-NX WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run, HKLM\RunServices and HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| Active Keys Application File | U | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" | No |
| ActiveKeys.AAB635BD7D054a37A576 | U | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" | No |
| akeys | U | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" | No |
| Advertising Killer | U | Akiller.exe | Advertising Killer - popup stopper | No |
| AKiller | U | akiller.exe | Advertising Killer - popup stopper | No |
| Ardamax Keylogger | U | akl.exe | Ardakey keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| Microsoft Synchronization Manager | X | al.exe | Added by the OPTXPRO.132 BACKDOOR! | No |
| ala | U | ala.exe | Access Lock - "an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program, define a password and double click the Access Lock system-tray icon every time you need to disable and hide your desktop." The same program as 1 Click & Lock and Access Controller (and maybe others) - the same file for the same version is used by all programs but the filename is different in each case | Yes |
| ala.exe | U | ala.exe | Access Lock - "an easy-to-use system-tray security utility you can use to secure your desktop when you are away from your computer. Just configure the program, define a password and double click the Access Lock system-tray icon every time you need to disable and hide your desktop." The same program as 1 Click & Lock and Access Controller (and maybe others) - the same file for the same version is used by all programs but the filename is different in each case | Yes |
| shell32.dll | X | alarm.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SHGen. The file is located in %Windir% | No |
| Alarm Manager | U | Alarmapp.exe | Palm alarm event reminder that coordinates what is on your Palm with settings on your desktop | No |
| Calnique Alarm Clock | U | alarmclock.exe | Alarm Clock extra for the Calnique Custom Calculator from Speciality Calendars. No longer available from the publisher | No |
| Plus! Alarm Clock | U | AlarmClock.exe | Alarm Clock function of Microsoft Plus! Digital Media Edition (which is no longer available) | No |
| AlarmWatcher | ? | AlarmWatcher.exe | Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required? | No |
| Acer Launch Tool | Y | Alaunch | Part of Acer eRecovery - "a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager". This entry isn't normally running but once eRecovery starts it's used to re-install the software included with the system | Yes |
| Alaunch | Y | Alaunch | Part of Acer eRecovery - "a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager". This entry isn't normally running but once eRecovery starts it's used to re-install the software included with the system | Yes |
| LaunchApp | Y | Alaunch | Part of Acer eRecovery - "a powerful utility that does away with the need for recovery disks provided by the manufacturer, and also acts as a versatile standalone backup and recovery manager". This entry isn't normally running but once eRecovery starts it's used to re-install the software included with the system | Yes |
| Windows Defender | X | Album.exe | Detected by Dr.Web as Worm.Siggen.6967 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| AlcFDMonitor | ? | ALCFDRTM.EXE | RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup? | No |
| alcfdrtm | X | alcfdrtm.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| ALCFDRTM16 | ? | ALCFDRTM16.com | RealTek related - Real-Time SPDIF-in Monitor for nVidia chipset - is it required in startup? | No |
| Alchem | X | Alchem.exe | ClickAlchemy adware | No |
| Alcmtr | U | ALCMTR.EXE | Realtek Azalia Audio - Event Monitor, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Some users believe that Realtek uses this file in order to gather data about the customer but it's exact purpose is unknown and it doesn't run on an ALC885 based test system or try to access the internet. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation | Yes |
| Realtek AC97 Audio - Event Monitor | U | ALCMTR.EXE | Realtek Azalia Audio - Event Monitor, installed with the XP/2K drivers for on-board Realtek HD audio codecs. Some users believe that Realtek uses this file in order to gather data about the customer but it's exact purpose is unknown and it doesn't run on an ALC885 based test system or try to access the internet. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation | Yes |
| Alcohol | N | Alcohol.exe | Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. Alcohol 120% includes burning capabilities | Yes |
| Alcohol 120% | N | Alcohol.exe | Alcohol 120% CD/DVD emulation and burning utility from Alcohol Soft - which allows you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place | Yes |
| Alcohol 52% | N | Alcohol.exe | Alcohol 52% CD/DVD emulation utility from Alcohol Soft - which allows you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place | Yes |
| Alcohol.exe Autorun | N | Alcohol.exe | Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. Alcohol 120% includes burning capabilities | Yes |
| alcomrg.exe | X | alcomrg.exe | Added by the SDBOT-DNT WORM! | No |
| AlcWzrd | U | ALCWZRD.EXE | RealTek AlcWzrd Application, installed with the drivers for on-board Realtek HD audio codecs. On an ALC885 based test system it runs only once after the drivers have been installed and the startup entry is then removed. Disabling it appears to have no ill effects but it's exact purpose is unknown - hence the "U" recommendation | Yes |
| AlcxMonitor | U | Alcxmntr.exe | Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to gather data about the customer. Some users report problems with their on-board sound if this is disabled - hence the "U" recommendation | No |
| PC Alert III | U | alert.exe | MSI PC Alert III - motherboard monitoring software which allows you to view your System and CPU temperature, fan RPM and more | No |
| alerter | X | alerter.exe | Detected by Trend Micro as TSPY_MAHA.F | No |
| Alevir | X | Alevir.exe | Added by the OPASERV-A WORM! | No |
| Alexa | N | alexa.exe | Related to Alexa. Note - collects and stores information about the web pages you view, the data you enter in online forms and search programs and, with versions 5.0 and higher, the products you purchase online whilst using the toolbar. Although Alexa state's they do not attempt to analyze the data it may collect about you to determine who you are, some of your information collected by the software is personally identifiable. Please read the Privacy Policy. Not Recommended | No |
| AlfaCleaner | X | AlfaCleaner.exe | AlphaCleaner rogue security software - not recommended, removal instructions here | No |
| AlfaClock Classic | U | AlfaClock.exe | AlfaClock Free Edition from AlfaSoft Research Labs - "enhances your taskbar clock (tray clock) with fully customizable clock display, alarms, time synchronization and more" | No |
| AlfaClock2 | U | AlfaClock2.exe | AlfaClock2 from AlfaSoft Research Labs -"enhances your tray clock functionality. Of course, you can customize the look, adjusting fonts, colors, backgrounds and more. But, the main goal of this program is to extend your tray clock functionality" | No |
| ALFY Accellerator | ? | AlfyAC~1.exe | ?? | No |
| alg | X | alg.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker. The file is located in %Root% | No |
| alg | X | alg.exe | Detected by Sophos as Troj/Mdrop-EAA and by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %AppData%\Macromidia | No |
| alg | X | alg.exe | Detected by Sophos as W32/Sdbot-DJC. The file is located in %System% | No |
| ALG | X | ALG.exe | Detected by Trend Micro as BKDR_PROXY.SMP. The file is located in %AppData%\Microsoft | No |
| alg: | X | alg.exe | Detected by Symantec as W32.Kueight | No |
| Help | X | alg.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserTemp% | No |
| OSD | X | ALG.exe | Added by the STARTPAGE-ID TROJAN! | No |
| WindowsRestore | X | alg.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| Networking Service | X | alg2.exe | Added by the RBOT-BDT WORM! | No |
| Microsoft Office Monitor | X | alg2k.exe | Added by the SDBOT-CZO WORM! | No |
| ALG32 | X | ALG32.EXE | Added by the STARTPAGE.K hijacker | No |
| Microsoft ALG32 Protocol | X | alg32.exe | Added by a variant of the SPYBOT WORM! | No |
| Microsoft ALGXP Protocol | X | alg32.exe | Added by a variant of W32/Sdbot.worm | No |
| Office Monitor | X | alg32.exe | Added by the RBOT-GMM WORM! | No |
| rw service | X | alg32.exe | Detected by Trend Micro as ADW_LOOPAD.A | No |
| algchk.exe | X | algchk.exe | Detected by Kaspersky as the VB.ATE TROJAN! | No |
| SystUphes | X | algesetp.exe | Added by the QQPASS-AM TROJAN! | No |
| wblogon | X | algg.exe | Added by the AGENT.AGGI TROJAN! | No |
| Win32 USB2 Driver | X | algg.exe | Added by the TIBS.BF WORM! | No |
| Office Monitorse | X | algose32.exe | Detected by Sophos as W32/Sdbot-CZX | No |
| Offices Monitorse | X | algose32.exe | Added by the RBOT-GDD WORM! | No |
| Application Layer Gateway Service | X | algs.exe | Added by the LINKBOT.M WORM! | No |
| Automatic Updates | X | algs.exe | Added by the IRCBOT-AAM TROJAN! | No |
| Windows System Guard | X | algs.exe | Added by the FAKEAV-DDV TROJAN! | No |
| office | X | algsvc.exe | Detected by Dr.Web as Trojan.Inject1.18895 and by Malwarebytes Anti-Malware as Trojan.Agent.LSM. The file is located in %UserProfile%\AppData\Local (7/Vista) or %UserProfile%\Local Settings (XP) | No |
| ALGU | X | ALGU.EXE | Detected by Sophos as Troj/CWS-I | No |
| ALGU.exe | X | ALGU.exe | Added by the STARTPAGE.O TROJAN! | No |
| algv.exe | X | algv.exe | Added by the AUTORUN-BEA WORM! | No |
| Bandook | X | ali.exe | Added by the EXEMAS-B TROJAN! | No |
| ALi5289 | U | ALi5289.exe | Related to Uli Integrated Drivers from Uli Electronics Inc | No |
| Alias SketchBook Snapshot | N | ALIASS~2.EXE | Screen-capture utility for Alias Sketchbook | No |
| [various names] | X | AliceSD.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Microsoft Synchronization Manager | X | alien.exe | Added by the SDBOT-MV BACKDOOR! | No |
| Alienware News Feed | U | Alienware News Feed.exe | RSS Reader gadget included with the Alienware theme for MyColors from Stardock Corporation | No |
| ALINAhuahs | X | ALINA_[6 letters].exe | Detected by Malwarebytes Anti-Malware as Trojan.Lina. The file is located in %AppData% - see examples here and here | No |
| Windo Servic Agen | X | alirexe.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| ALiSndMgr | Y | ALiSndMg.exe | ALi AC97 Sound driver | No |
| RX4LXWW | X | All.exe | Detected by McAfee as RDN/Generic.bfr!k and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| XPYH5 | X | All.exe | Detected by McAfee as RDN/Generic.bfr!k and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| AllerCalc | N | AllerCalc.exe | AllerCalc is an expression calculator which allows you to directly enter an expression to be evaluated. Can be started manually | No |
| nkurls | X | alligt.exe | Added by the SLURK.A WORM! | No |
| Allmyapps | N | AllmyappsNotifier.exe | Allmyapps Windows application manager | No |
| FaltCheck | X | allps.exe | Added by the AGENT.RAP TROJAN! | No |
| AutoRun | X | allrs.exe | Added by the MUDROP.LJ TROJAN! | No |
| AllShareAgent | N | AllShareAgent.exe | "AllShare is Samsung's content sharing service that allows you to search for and play video, photo, and music files freely across many devices that support AllShare services, such as PC, TV, mobile phone, and digital camera. You can do this either wirelessly or with a cable" | No |
| allSnap | U | allSnap.exe | "allSnap is a small system tray app that makes all top level windows automatically align like they do in programs such as Winamp or Photoshop" | No |
| AllToTray | U | ALLTOTRAY.EXE | AlltoTray from DNTSoft - minimize any program to your System Tray | No |
| ALLUpdate | N | ALLUpdate.exe | Automatic updates for the ALLPlayer "all formats video player with autodownload features" | No |
| AOL Instant Messenger | X | AlM.EXE | Added by unidentified malware. Note - there ia a lower case "L" between the A and M in the filename | No |
| Internet | X | alm7tas.exe | Added by a variant of Win32/Rbot | No |
| AcerNotebookManager | U | almxptray.exe | System Tray access on some Acer Notebooks to give faster access to system settings | No |
| Alogserv | U | Alogserv.exe | From McAfee VirusScan for logging scanning activities. In some cases, if left running it can cause CPU % usage to go between 5-95% or go to and stay at 100%. Disabling it impacts on the reported last scan date. It is reported to cause jerky graphics response in many games. As of version 6, this is a critical component of McAfee and disabling it can cause a PC to lock up | No |
| ALPass | U | ALPass.exe | ALPass password manager | No |
| AlphaAnt | X | alpha.exe | Alpha Antivirus rogue security software - not recommended, removal instructions here | No |
| AlphaAV | X | AlphaAV.exe | Alpha Antivirus rogue security software - not recommended, removal instructions here | No |
| EleFunAnimatedWallpaper | U | Alpine Lake.exe | Alpine Lake animated wallpaper from | No |
| Alogrithm Link Queue | X | alq.exe | Added by a variant of W32/Sdbot.worm | No |
| ALServ | U | ALServ.exe | Utility that enables a user to control the volume and surround sound and select Pro Logic/Stereo on 2 satellite speakers and subwoofer of old Altec Lansing speaker systems. The right-side speaker has 4 controls on top providing same functionality | No |
| Nod32 Service | X | alserv32.exe | Added by the RBOT.DHN WORM! | No |
| LightSensorApp | ? | ALSMON.exe | ?? | No |
| Agent | X | alsys.exe | Added by the DREF-V VIRUS! | No |
| AlexaToolbar | X | alt.exe | Detected by Ewido (Ewido is now part of AVG Technologies) as Hijacker.Delf.eb | No |
| PromoReg | X | alt.exe.exe | Added by a variant of the AGENT.DOM TROJAN! | No |
| AltDesk | U | AltDesk.exe | AltDesk virtual desktop manager by Gladiators Software - "creates several Virtual Desktops you can easily switch. Switching from an office application to your favorite Internet browser can be done in a blink of an eye without maximizing and minimizing numerous windows manually or switching them with the Taskbar" | No |
| AltoMB_service | U | AltoMBsrv.exe | Alto Memory Booster from Alto Software - "boost the computers performance via more intelligent and efficient memory management." No longer supported or available from the authors | No |
| AltPayments | X | AltPayments.exe | WeirdOnTheWeb adware | No |
| Notification Utility | X | altpayV2.exe | AltPay adware | No |
| ASUS Live Update | N | ALU.exe | ASUS Live Update utility for their motherboards | No |
| ALUAlert | U | ALUNotify.exe | Notification reminder for Symantec's LiveUpdate. Leave enabled unless you manually run LiveUpdate on a regular basis | No |
| AluScheduler | X | AluScheduler.exe | Added by the SYGINRE TROJAN! | No |
| ALU Scheduler Service | Y | ALUSchedulerSvc.exe | LiveUpdate scheduler for older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks suite. Leave alone to ensure virus definitions are updated. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| always | X | alw.exe | Detected by Malwarebytes Anti-Malware as Trojan.Yoddos. The file is located in %System% | No |
| AlwaysOnTopMaker | U | AlwaysOnTopMaker.exe | Always On Top Maker - utilty to enable an application to always be displayed "on top" of others on the desktop | No |
| alws | X | alws.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir% | No |
| Action Manager 32 | N | am32.exe | Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start → Programs | No |
| AutoMate5 | U | Am5HkWnd.exe | Version 5 of the AutoMate server and desktop automation software | No |
| CA-AMAgent | U | amagent.exe | Part of Unicenter Asset Management from CA - "is a solution for proactively managing IT assets in a business environment. It provides full-featured asset tracking capabilities through automated discovery, hardware inventory, network inventory, software inventory, configuration management, software usage monitoring, license management and extensive cross-platform reporting" | No |
| EleFunAnimatedWallpaper | U | Amazing Waterfall.exe | Amazing Waterfall animated wallpaper from | No |
| AmazingTens | X | AmazingTens.exe | Premium rate adult content dialler | No |
| AmazonGSDownloaderTray | N | AmazonGSDownloaderTray.exe | System Tray icon for Amazon's Games and Software Downloads digital downloads service | No |
| Personal Anti Malware Center | X | AMC.exe | Registered version of Personal Anti Malware rogue security software - not recommended, removal instructions here | No |
| aaAPMClient | U | amclient.EXE | LANDesk® Management Suite software component | No |
| aaLDTaskCompletion | U | amclient.EXE | LANDesk® Management Suite software component | No |
| IntelAPMClient | U | amclient.exe | LANDesk® Management Suite software component | No |
| Task Completion | U | AMCLIENT.EXE | LANDesk® Management Suite software component | No |
| amd_dc_opt | Y | amd_dc_opt.exe | AMD Dual-Core Optimizer - "can help improve some PC gaming video performance by compensating for those applications that bypass the Windows API for timing by directly using the RDTSC (Read Time Stamp Counter) instruction" | No |
| Aaou | X | amee.exe | PurityScan adware | No |
| AutoMate6 | U | AMEM.exe | Version 6 of the AutoMate server and desktop automation software | No |
| AntiMalwareGuard | X | amg.exe | AntiMalwareGuard rogue security software - not recommended, removal instructions here | No |
| ami.exe | X | ami.exe | Added by the SILLYFDC-AY WORM! | No |
| AmIcoSinglun | U | AmIcoSinglun.exe | Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN, such as the AU6336, AU6439 and AU6431 | No |
| AmIcoSinglun64 | U | AmIcoSinglun64.exe | Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN, such as the AU6336, AU6439 and AU6431 | No |
| Iconutility | U | AmIcoSinglun64.exe | Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN, such as the AU6336, AU6439 and AU6431 | No |
| ammo | X | ammo.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot.Gen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Amon | Y | AMON.EXE | Monitoring part of Eset's NOD32 antivirus | No |
| Amonitor | Y | amon.exe | Tiny Personal Firewall | No |
| WheelMouse | U | AMOUMAIN.EXE | A4Tech wireless mouse driver and utility - required if you use non-standard Windows driver features | No |
| AMO_Taskplaner.exe | U | AMO_Taskplaner.exe | Part of Ashampoo® Magical Optimizer - which removes stagnant and unnecessary hard drive files, deletes Internet tracks and streamlines the registry by erasing invalid and orphaned entries. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | Yes |
| Ashampoo Magical Optimizer Taskplaner | U | AMO_Taskplaner.exe | Part of Ashampoo® Magical Optimizer - which removes stagnant and unnecessary hard drive files, deletes Internet tracks and streamlines the registry by erasing invalid and orphaned entries. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | Yes |
| AMO_TA~1 | U | AMO_TA~1.EXE | Part of Ashampoo® Magical Optimizer - which removes stagnant and unnecessary hard drive files, deletes Internet tracks and streamlines the registry by erasing invalid and orphaned entries. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | Yes |
| AMO_TA~1.EXE | U | AMO_TA~1.EXE | Part of Ashampoo® Magical Optimizer - which removes stagnant and unnecessary hard drive files, deletes Internet tracks and streamlines the registry by erasing invalid and orphaned entries. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | Yes |
| Ashampoo Magical Optimizer Taskplaner | U | AMO_TA~1.EXE | Part of Ashampoo® Magical Optimizer - which removes stagnant and unnecessary hard drive files, deletes Internet tracks and streamlines the registry by erasing invalid and orphaned entries. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | Yes |
| AccessMedia P2P Loader | X | amp2pl.exe | My AccessMedia toolbar related, stealth installed! | No |
| amsgupdate | X | ams.exe | Added by a variant of the MAILBOT TROJAN! | No |
| AntiMalwareSuite | X | AMS.exe | AntiMalwareSuite rogue security software - not recommended, removal instructions here | No |
| AMSG | U | Amsg.exe | Part of the IBM ThinkVantage Productivity Center. "The Message Center sends automatic notification on ThinkVantage Technologies integrated with your system. Once you're online" | No |
| AMSN | N | amsn.exe | aMSN Messenger is a multiplatform MSN messenger clone | No |
| amsn | X | amsn.exe | Added by the BANKER-BNZ TROJAN! | No |
| Compaq Service Drivers | X | amsn.exe | Added by a variant of W32/Sdbot.worm | No |
| lnternet Explorer | X | AMSNDMGR.EXE | Added by the KWBOT.R WORM! Note that the "l" is a lower case "L" and not an upper case "I" | No |
| Clock Manager | X | amsngr.exe | Added by the SDBOT-XM TROJAN! | No |
| WinDynManager | X | amsnmsg.exe | Added by the SDBOT-IA BACKDOOR! | No |
| MSN Service | X | amsnmsgrs.exe | Added by a variant of W32/Sdbot.worm | No |
| SSL Manager | X | amsnmsgs.exe | Added by a variant of W32/Sdbot.worm | No |
| RTHDCPL1 | X | amstreamx.exe | Detected by Dr.Web as Trojan.DownLoader6.27455 and by Malwarebytes Anti-Malware as Trojan.Agent.PLC | No |
| amva | X | amvo.exe | Added by the SILLYFDC-BR WORM! | No |
| AHU | X | ANACON.EXE | Detected by Trend Micro as WORM_NACO.A | No |
| Cvfjx | X | ANACON.EXE | Detected by Trend Micro as WORM_NACO.A | No |
| Hvewsveqmg | X | ANACON.EXE | Detected by Trend Micro as WORM_NACO.A | No |
| ALM | X | anacon32.exe | Added by the ANACON-C WORM! | No |
| Services | X | anacon32.exe | Added by the ANACON-C WORM! | No |
| Under20 | X | anacon32.exe | Added by the ANACON-C WORM! | No |
| Bar Ding lolt | X | Analiz.exe | Added by the RBOT-RP WORM! | No |
| Anapod Manager | N | anamgr.exe | Anapod Explorer from Red Chair Software "is the most advanced Windows iPod® software available, offering iPod® management through full Windows Explorer integration under My Computer." The models supported have been discontinued so the software is no longer available for new sales | No |
| Razer Anansi Driver | U | AnansiSysTray.exe | Razer Anansi gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| AnCamCorder | X | ancamcorderupdate.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\AHNSOFT\AnCamCorder | No |
| AnCamera | X | ancameraup.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\AHNSOFT\ancamera3 | No |
| VoiceCenter | U | AndreaVC.exe | Related to Andrea's Superbeam microphone utility | No |
| Android.exe | X | Android.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and here | No |
| xuri49tkd | X | andy143.exe | Added by the KOOBFACE WORM! | No |
| Utopia Angel | N | Angel.exe | "Utopia Angel is a powerful program which is a set of professional formatters, calculators, optimizers and other tools, working cooperatively, all specifically designed to assist and maximize the Utopian player's productivity." For the text-based massively multiplayer online game Utopia | No |
| 76112549345328287 | X | angpd.exe | ANG AntiVirus 09 rogue security software - not recommended, removal instructions here | No |
| anhxox | X | anhzxc.exe | Added by the PSW-IH TROJAN! | No |
| animalss | X | animalss.exe | Added by the AGOBOT-VE WORM! | No |
| anistio | X | anistio.exe | Added by the PSW-FC TROJAN! | No |
| MSConfig | X | ankubuin.exe | Detected by McAfee as PWS-Zbot-FAHQ!EB3E06FDBD80 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| AnnotateCheck | ? | AnnCheck.exe | Genius Wizard Pen Tablet driver related. Is it required? | No |
| Announcements | N | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it | No |
| Microsoft Announcement Listener | N | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it | No |
| Anntext | N | Anntext.exe | Caere Pagekeeper text annotation server | No |
| ANONYMIZER_SPYWAREKILLER | Y | AnonAntiSpyware.exe | Anonymizer Anti-Spyware - now discontinued | No |
| Anonymizer Total Net Shield | U | AnonTns.exe | Anonymizer Total Net Shield - ID protection and privacy software | No |
| AnonymityGateway | U | Anonymity Gateway.exe | Anonymity Gateway - privacy protection tool that conceals IP address preventing your surfing habits and your internet activity form being tracked by websites or Internet Service Providers | No |
| Will I Ever | X | anqbse.exe | Added by the SDBOT-TK WORM! | No |
| 1-Click Answers | U | answers.exe | 1-Click Answers from Answers.com - allows you to "Alt-Click on any word in any program on your screen for a pop-up window with a concise AnswerTip" | No |
| AnswerTool | U | AnswerTool.exe | AnswerTool - save your E-mail replies in AnswerTool, then reuse them again and again | No |
| HideStyle | X | Ante Browse Trust.exe | IE toolbar taking you to Lop.com. If the exe is running, close it and remove the %ProgramFiles%\Stupidmore directory | No |
| antinetcut2 | U | Anti NetCut.exe | Anti NetCut 2 from Tools4Free.net - "protects you from arp poisoning while working on shared computer networks" | No |
| Anti-Blaxx Manager | N | Anti-Blaxx.exe | Anti-Blaxx - bypass blacklistings from different copy protections bypassing methods like virtual CD or DVD drives | No |
| Virus | X | Anti.exe | Added by the SEENBOT.O WORM! | No |
| Yahoo2000 | X | Anti.exe | Added by a variant of Win32/Rbot | No |
| AntiAdd.exe | X | AntiAdd.exe | AntiAdd rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| AntiAID | X | AntiAID.exe | AntiAID rogue security software - not recommended, removal instructions here. There are number of variants in this family sharing the same user interface - see here | No |
| AntiAvoidMain | X | AntiAvoid.exe | AntiAvoid rogue security software - not recommended, removal instructions here | No |
| auto__antiav__key | X | antiav_exe.exe | Added by the BAGLEDI-AA TROJAN! | No |
| AntiCareMain | X | AntiCare.exe | AntiCare rogue security software - not recommended, removal instructions here | No |
| AnticlearMain | X | Anticlear.exe | Anticlear rogue security software - not recommended | No |
| Digisoft AntiDialer | U | AntiDialer.exe | Digisoft AntiDialer | No |
| AntiFreeze | Y | AntiFreeze.exe | AntiFreeze from Resplendence Software Projects - "offers a last recourse when you find your computer in a hung state". If your system has hung and AntiFreeze is running, a hotkey combination will suspend all but critical processes and allow you to save or recover your work | Yes |
| AntiGuard | X | AntiGuard.exe | AntiGuard rogue security software - not recommended, removal instructions here | No |
| !!!AntiHook | Y | AntiHook.exe | AntiHook - the "ultimate Host Intrusion Prevention System (HIPS) for protection against Malicious Software" | No |
| AntiKeep | X | AntiKeep.exe | AntiKeep rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| AntiKeep.exe | X | AntiKeep.exe | AntiKeep rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Anti-keylogger check | U | antikey.exe | Anti-keylogger - protects against keylogger programs monitoring your keystrokes | No |
| spyshelter | U | antikeylogger.exe | SpyShelter - anti-keylogger protects against keylogger programs monitoring your keystrokes | No |
| AntiLogger | Y | AntiLogger.exe | Zemana AntiLogger is not designed to replace your installed antivirus and antispyware software -- it's designed to detect serious threats that other security products miss. AntiLogger is dramatically different from other anti-malware products that usually only look for virus "fingerprints" which must first be identified by antivirus researchers working in a lab' | No |
| Antimalware Doctor.exe | X | Antimalware Doctor.exe | Antimalware Doctor rogue security software - not recommended, removal instructions here | No |
| AntiMalware | X | AntiMalware.exe | AntiMalware rogue security software - not recommended, removal instructions here | No |
| composite | X | antimalware.exe | Detected by Sophos as Troj/DwnLdr-JUR and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| A_M_P_NET | X | AntiMalwarePro.exe | AntiMalware Pro rogue security software - not recommended, removal instructions here | No |
| A_M_P_NET | X | AntiMalware_Pro.exe | AntiMalwarePro rogue security software - not recommended, removal instructions here | No |
| AntiMalware_ProNET | X | AntiMalware_Pro.exe | AntiMalware Pro rogue security software - not recommended, removal instructions here | No |
| AntiWindowsMessenger | U | AntiMsMsg.exe | Anti-Windows_Messenger is a small application that prevents Windows Messenger from remaining resident in memory | No |
| AntiPopUp | U | AntiPopUp.exe | AntiPopUp for IE - pop-up stopper | No |
| ANTIPROCESS | X | ANTIPROCESS.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| AntiProtect | X | AntiProtect.exe | AntiProtect rogue security software - not recommended, removal instructions here | No |
| AntiSec.exe | X | AntiSecc.exe | Detected by McAfee as W32/Sdbot.worm!mi and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Net CoNN | X | Antispy.exe | Detected by Trend Micro as WORM_AGOBOT.ALK | No |
| ppass | U | Antispy.exe | AntiSpy firewall - "program designed to combat against various types of intrusion and monitoring programs currently in use or presently being developed worldwide" | No |
| AntiSpy2008 | X | AntiSpy2008.exe | Antispy 2008 rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyCheck 2.1 | X | AntiSpyCheck 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| AUTORUN_VAL | X | AntiSpyCheck 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyCheck | X | AntiSpyCheck.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyCheck 2.1.0 | X | AntiSpyCheck.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyGolden | X | AntiSpyGolden 5.1.exe | AntiSpyGolden rogue spyware remover - not recommended | No |
| AntiSpyGolden 5.1 | X | AntiSpyGolden 5.1.exe | AntiSpyGolden rogue spyware remover - not recommended | No |
| AntiSpyGuard | X | AntiSpyGuard.exe | AntiSpyGuard rogue security software - not recommended, removal instructions here | No |
| AntiSpyKit 5.2 | X | AntiSpyKit 5.2.exe | AntiSpyKit rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyKit | X | AntiSpyKit 5.3.exe | AntiSpyKit rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyKit 5.3 | X | AntiSpyKit 5.3.exe | AntiSpyKit rogue spyware remover - not recommended, removal instructions here | No |
| antispyknight | X | antispyknight.exe | AntispyKnight rogue security software - not recommended | No |
| AntiSpyMon | X | AntiSpyMon.exe | Antispyware Protector rogue security software - not recommended | No |
| antispysoldier | X | antispysoldier.exe | AntiSpyware Soldier rogue spyware remover - not recommended, removal instructions here | No |
| AntispySpider | X | antispyspider.exe | AntiSpySpider rogue spyware remover - not recommended, removal instructions here | No |
| AntispyStorm | X | AntispyStorm.exe | AntispyStorm rogue security software - not recommended, removal instructions here | No |
| AntiSpyware Pro | X | AntiSpyware Pro.exe | AntiSpyware Pro 2009 rogue spyware remover - not recommended, removal instructions here | No |
| Antispyware-2008.exe | X | Antispyware-2008.exe | AntiSpyware 2008 rogue security software - not recommended, removal instructions here | No |
| AntiSpyware | X | AntiSpyware.exe | AntiSpywareApp rogue spyware remover - not recommended, see here | No |
| AntiSpyware3000.exe | X | antispyware.exe | AntiSpyware 3000 rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyWare2Guard | Y | AntiSpyWare2Guard.exe | Realtime monitor from Ashampoo® AntiSpyWare 2 that looks for changes on the users system such as BHO, Winsock LSPs, Windows Hosts file, Autostart entries, etc | Yes |
| Ashampoo AntiSpyWare 2 | Y | AntiSpyWare2Guard.exe | Realtime monitor from Ashampoo® AntiSpyWare 2 that looks for changes on the users system such as BHO, Winsock LSPs, Windows Hosts file, Autostart entries, etc | Yes |
| Ashampoo AntiSpyWare 2 Guard | Y | AntiSpyWare2Guard.exe | Realtime monitor from Ashampoo® AntiSpyWare 2 that looks for changes on the users system such as BHO, Winsock LSPs, Windows Hosts file, Autostart entries, etc | No |
| 'Ashampoo AntiSpyWare 2 Guard' | Y | AntiSpyWare2Guard.exe | Realtime monitor from Ashampoo® AntiSpyWare 2 that looks for changes on the users system such as BHO, Winsock LSPs, Windows Hosts file, Autostart entries, etc | Yes |
| AntiSpywareBot | X | AntiSpywareBot.exe | AntiSpywareBot rogue spyware remover - not recommended, removal instructions here | No |
| AntispywareD | X | AntispywareD.exe | AntiSpywareDeluxe rogue security software - not recommended, removal instructions here | No |
| AntiSpywareShield | X | AntiSpywareShield.exe | AntiSpywareShield rogue security software - not recommended, removal instructions here | No |
| AntiSpywareXP 2009 | X | AntiSpywareXP2009.exe | AntiSpywareXP 2009 rogue spyware remover - not recommended, removal instructions here | No |
| AntiSpyZone 4.5 | X | AntiSpyZone 4.5.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| AntiSpyZone 4.6 | X | AntiSpyZone 4.6.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| AntiSpyZone 4.9 | X | AntiSpyZone 4.9.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| AntiSpyZone 5.1 | X | AntiSpyZone 5.1.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| AntiSpyZone 5.4 | X | AntiSpyZone 5.4.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| AntiSpyZone | X | AntiSpyZone.exe | AntiSpyZone rogue spyware remover - not recommended | No |
| shv | X | antit.exe | Detected by Sophos as Troj/Agent-JKU | No |
| AdwareProMFC | X | AntiTrojan Pro.exe | AntiTrojan Pro rogue security software - not recommended. Variant of Ad-Ware Pro | No |
| AntiTroy | X | AntiTroy.exe | AntiTroy rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| AntiTroy.exe | X | AntiTroy.exe | AntiTroy rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Microsoft64 | X | antiv.exe | Added by the SOBER WORM! | No |
| AntiVermeans | X | AntiVermeans.exe | Variant of the Antivermins rogue security software - not recommended, removal instructions here | No |
| AntiVermins 3.0 | X | AntiVermins 3.0.exe | Antivermins rogue security software - not recommended, removal instructions here | No |
| AntiVermins 3.3 | X | AntiVermins 3.3.exe | Antivermins rogue security software - not recommended, removal instructions here | No |
| AntiVermins | X | AntiVermins.exe | Antivermins rogue security software - not recommended, removal instructions here | No |
| AntiVerminser | X | AntiVerminser.exe | Variant of the Antivermins rogue security software - not recommended, removal instructions here | No |
| AntiVerminsPro | X | AntiVerminspro.exe | Antivermins rogue security software - not recommended, removal instructions here | No |
| antiviirus | X | antiviirus.exe | Added by a variant of the AGENT.KEU TROJAN! | No |
| antispy | X | ANTIVIR.exe | IE AntiVirus rogue security software - not recommended, removal instructions here | No |
| AV | X | Antivir.exe | Antivir rogue security software - not recommended, removal instructions here | No |
| startkey | X | antivir.exe | Added by the BIFROSE-TO TROJAN! | No |
| CONFIGURE | X | antivir62.exe | Added by the AGOBOT-ZD BACKDOOR! | No |
| Antivir64 | X | Antivir64.exe | Antivir64 rogue spyware remover - not recommended, removal instructions here | No |
| AntiviralGolden | X | AntiviralGolden.exe | AntiviralGolden rogue security software - not recommended, removal instructions here | No |
| AntiVirGear 3.7 | X | AntiVirGear 3.7.exe | AntiVirGear rogue security software - not recommended, removal instructions here | No |
| AntiVirGear 3.8 | X | AntiVirGear 3.8.exe | AntiVirGear rogue security software - not recommended, removal instructions here | No |
| AntiVirProtect | X | AntiVirProtect.exe | AntiVirProtect rogue security software - not recommended, removal instructions here | No |
| Antivirus 2009 plus | X | Antivirus 2009 plus.exe | AntiVirus 2009 Plus rogue security software - not recommended, removal instructions here | No |
| AntiVirus AntiSpyware 2011 | X | AntiVirus AntiSpyware.exe | Antivirus AntiSpyware 2011 rogue security software - not recommended, removal instructions here | No |
| AntiVirusProMFC | X | Antivirus Pro.exe | AntiVirus Pro rogue security software - not recommended | No |
| AntiVirus Studio 2010 | X | AntiVirus Studio 2010.exe | Antivirus Studio 2010 rogue security software - not recommended, removal instructions here | No |
| Zi5 | X | AntiVirus Update.exe | Added by the ERKEZ.G WORM! | No |
| Antivirus-2008.exe | X | Antivirus-2008.exe | Antivirus 2008 rogue security software - not recommended. Detected by Sophos as the FAKEAV-BK TROJAN! | No |
| antivirus-2008pro.exe | X | antivirus-2008pro.exe | Antivirus 2008 PRO rogue security software - not recommended. Detected by Sophos as the FAKEAV-AW TROJAN! | No |
| Antivirus-Golden | X | Antivirus-Golden.exe | Antivirus-Golden rogue security software - not recommended | No |
| Windows Update | X | antivirus.bat | Detected by Sophos as Troj/Mdrop-EZP and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| antivirus | X | antivirus.cpl | Detected by Malwarebytes Anti-Malware as Trojan.Agent.CPL. The file is located in %LocalAppData% | No |
| antispy | X | ANTIVIRUS.exe | IE AntiVirus rogue security software - not recommended, removal instructions here | No |
| AntiVirus | X | AntiVirus.exe | Added by the BANKER-EHB TROJAN! | No |
| AntiVirus Update | X | antivirus.exe | Added by the RBOT-IF WORM! | No |
| Antivirus.exe | X | Antivirus.exe | Antivirus rogue security software - not recommended, removal instructions here | No |
| antivirus32 | X | antivirus.exe | Added by the SPYBOT.KAI WORM! | No |
| avpl | X | Antivirus.exe | AntiVirus Plasma rogue security software - not recommended, removal instructions here | No |
| Microsoft Internet Antivirus Protection | X | antivirus.exe | Detected by Kaspersky as the IRCBOT.BSK TROJAN! | No |
| System | X | antivirus.vbe | Added by the AUTORUN-AYI WORM! | No |
| Windows Anti-Virus Built 32 | X | AntiVirus32.exe | Added by the SDBOT.JW WORM! | No |
| Windows Config | X | antivirus32.exe | Added by the SPYBOT.DX WORM! | No |
| AV7 | X | antivirus7.exe | Antivirus7 rogue security software - not recommended, removal instructions here | No |
| AntivirusDoc | X | AntivirusDoc.exe | AntivirusDoc rogue security software - not recommended, removal instructions here | No |
| AntivirusGold 5.1 | X | AntivirusGold 5.1.exe | AntivirusGold rogue security software - not recommended, removal instructions here | No |
| AntivirusGold | X | AntivirusGold.exe | AntivirusGold rogue security software - not recommended, removal instructions here | No |
| AntivirusGolden | X | AntivirusGolden.exe | AntivirusGolden rogue security software - not recommended, removal instructions here | No |
| AVGT | X | antivirusGT.exe | AntivirusGT rogue security software - not recommended, removal instructions here | No |
| AntiVirusLab2009 | X | AntiVirusLab2009.exe | Antivirus Lab 2009 rogue security software - not recommended, removal instructions here | No |
| AntiVirusPro | X | AntiVirusPro.exe | Anti Virus Pro rogue security software - not recommended | No |
| Antivirus Pro 2009 | X | AntivirusPro2009.exe | AntiVirus Pro 2009 rogue security software - not recommended, removal instructions here | No |
| Antivirus Protection | X | antivirusprotection.exe | Antivirus Protection rogue security software - not recommended | No |
| AntivirusProtection | X | antivirusprotection.exe | Antivirus Protection rogue security software - not recommended | No |
| Antivirus Protection | X | AntivirusProtection2012.exe | Antivirus Protection 2012 rogue security software - not recommended, removal instructions here | No |
| Antivirus Protection 2012 | X | AntivirusProtection2012.exe | Antivirus Protection 2012 rogue security software - not recommended, removal instructions here | No |
| Antivirus Pro 2010 | X | AntivirusPro_2010.exe | Antivirus Pro 2010 rogue security software - not recommended, removal instructions here | No |
| AntivirusXP.exe | X | AntivirusXP.exe | Antivirus XP Pro rogue security software - not recommended, removal instructions here | No |
| Eac_rnvdl | ? | ANTIVIRUS_INSTALL.EXE | ?? | No |
| AntiVirus_ProNET | X | AntiVirus_Pro.exe | AntiVirusPro rogue security software - not recommended, removal instructions here | No |
| AntiVirus Solution 2010 | X | AntiVirus_Solution_2010.exe | AntiVirus Solution 2010 rogue security software - not recommended, removal instructions here | No |
| AntiVirus System 2011 | X | AntiVirus_System_2011.exe | AntiVirus System 2011 rogue security software - not recommended, removal instructions here | No |
| trackerx90.th.gs | X | anti_data_exe_by_trackerx90.exe | Added by the BCKDR-QIT BACKDOOR! | No |
| anti_troj | X | anti_troj.exe | Malware installed by different rogue security software including SpyKillerPro. Also detected as the LODEAR.D TROJAN! | No |
| AntVir | X | AntVir.exe | Detected by Dr.Web as Trojan.MulDrop2.59786 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Doctor Antivirus 2008 | X | antvr.exe | Doctor Antivirus 2008 rogue security software - not recommended, removal instructions here | No |
| Antivirus | X | Antvrs.exe | AntiVirus 2008 rogue security software - not recommended, removal instructions here | No |
| Antivirus2008y | X | antvrs.exe | AntiVirus 2008 rogue security software - not recommended, removal instructions here | No |
| vdsadasw | X | anukem.exe | Added by the MULTIDR-CZ TROJAN! | No |
| AnVir | U | AnVir.exe | AnVir Task Manager - "is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work". Monitors and manages startup programs, processes and services. Also includes system tweaks, security risks, tray icons for monitoring CPU/memory/HDD and other utilities | Yes |
| AnVir Security Suite | U | AnVir.exe | AnVir Security Suite - "is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work". Monitors and manages startup programs, processes and services. Also includes system tweaks, security risks, tray icons for monitoring CPU/memory/HDD and other utilities. This version includes an antivirus scanner and anti-rootkit tool | Yes |
| AnVir Task Manager | U | AnVir.exe | AnVir Task Manager - "is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work". Monitors and manages startup programs, processes and services. Also includes system tweaks, security risks, tray icons for monitoring CPU/memory/HDD and other utilities | Yes |
| AnVir Task Manager Free | U | AnVir.exe | AnVir Task Manager Free - "is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work". Monitors and manages startup programs, processes and services. Also includes system tweaks, security risks, tray icons for monitoring CPU/HDD and other utilities | Yes |
| AnVir Task Manager Pro | U | AnVir.exe | AnVir Task Manager Pro - "is a tool that controls everything running on computer and provides Windows enhancements that help in every-day work". Monitors and manages startup programs, processes and services. Also includes system tweaks, security risks, tray icons for monitoring CPU/memory/HDD and other utilities | Yes |
| anvshell | U | anvshell.exe | System Tray tool for ASUS video cards. If disabled you lose all the ASUS specific video card options in Control Panel → Display Properties → Advanced as well as the System Tray shortcuts toolbar | No |
| NvCplDaemon32 | X | anvshell32.exe | Added by the VB-XU TROJAN! | No |
| anvtirs | X | anvtirs.exe | Added by the AGENT-OIN TROJAN! | No |
| AnvTrgr | X | AnvTrgr.exe | AntivirusTrigger rogue security software - not recommended, removal instructions here | No |
| AnyBoan | X | AnyBoan.exe | AnyBoan rogue security software - not recommended, removal instructions here | No |
| AnyDVD | N | AnyDVD.exe | AnyDVD from Slysoft, Inc - "works in the background to automatically remove the copy protection of a DVD movie as soon as it's inserted into the drive, allowing you then to backup the movie using a DVD backup tool such as CloneDVD and CloneDVD mobile. You can also remove the RPC region code, thereby making the movie region free and viewable on any DVD player and with any DVD player software" | Yes |
| AnyDVD | N | AnyDVDtray.exe | AnyDVD from Slysoft, Inc - "works in the background to automatically remove the copy protection of a DVD movie as soon as it's inserted into the drive, allowing you then to backup the movie using a DVD backup tool such as CloneDVD and CloneDVD mobile. You can also remove the RPC region code, thereby making the movie region free and viewable on any DVD player and with any DVD player software" | Yes |
| AnyDVDtray | N | AnyDVDtray.exe | AnyDVD from Slysoft, Inc - "works in the background to automatically remove the copy protection of a DVD movie as soon as it's inserted into the drive, allowing you then to backup the movie using a DVD backup tool such as CloneDVD and CloneDVD mobile. You can also remove the RPC region code, thereby making the movie region free and viewable on any DVD player and with any DVD player software" | Yes |
| Anysecu main | X | anysecuu.exe | AnySecu rogue security software - not recommended, removal instructions here | No |
| AnysecuS | X | anysecuU.exe | AnySecu rogue security software - not recommended, removal instructions here | No |
| AnytimeDrivers | X | anytime.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %System%\drivers | No |
| Any To-Do List | U | anytodo.exe | Any To-Do List "the ultimate software solution to keep yourself organized and reminded" | No |
| ANYUCC | N | AnyUCC.exe | "AnyUCC is a sweet tool that lets you download any YouTube video in various video or audio formats such as MP3, MP4, FLV for free" | No |
| ugon | ? | aockstrs.exe | ?? | No |
| AODAssist.exe | U | AODAssist.exe | "AMD OverDrive allows user to tune parameters to help system stability, optimize performance, and control cooling/acoustic characteristics" | No |
| AOL | N | AOL.exe | Fast Start loads the AOL integrated email, instant messenger and web browser software in the background when you turn on your computer. This feature lets you quickly open AOL | Yes |
| AOL Fast Start | N | AOL.exe | Fast Start loads the AOL integrated email, instant messenger and web browser software in the background when you turn on your computer. This feature lets you quickly open AOL | Yes |
| AOL Instant Messengar | X | aol.exe | Added by the AGOBOT-FN WORM! | No |
| Microsoft AOL32 Protocol | X | aol32.exe | Added by a variant of the SPYBOT WORM! | No |
| AolAcsDaemon1 | Y | AOLACSD.EXE | AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AOLSAV | ? | AOLAgent.exe | AOL ISP related. What does it do and is it required? | No |
| AOL 9.0 Optimized | X | AOLClient.exe | Added by the SPYBOTER.A TROJAN! | No |
| AOLDialer | N | AOLDial.exe | AOL ISP software dialer - can be activated through a desktop shortcut | No |
| Aol Instant Messenger Fix | X | aolfix.exe | Added by the SDBOT-ABJ WORM! | No |
| AolFix | N | AolFix.exe | Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL to run correctly. Not seen much any more and should only run once | No |
| HostManager | U | AOLHostManager.exe | Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched, increasing launching time | No |
| Aim6 | N | AOLLaunch.exe | AOL Instant Messenger - start it when you want to use it | No |
| Aol Instant Messenger | X | aolmsg.exe | Added by the KELVIR.AL WORM! | No |
| AOL Messenger | X | aolmsngr.exe | Added by the SDBOT-JF WORM! | No |
| AOL Messenger Optimized | X | AOLOpt.exe | Detected by SUPERAntiSpyware as Trojan.AOLOPT/System.Process. The file is typically located in %System% | No |
| AOL Services Hosts | X | aolserviceshosts.exe | Added by an unidentified WORM or TROJAN! | No |
| AOL Service Libraries | N | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" | Yes |
| AOLSoftware | N | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" | Yes |
| HostManager | N | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" | Yes |
| AOL Spyware Protection | U | AOLSP Scheduler.exe | AOL's spyware protection program | No |
| AOLSPScheduler | U | AOLSP Scheduler.exe | AOL's spyware protection program | No |
| AOLSPYWAREREMOVER32 | X | AOLSPYWARECLEANER32.EXE | Added by the SPYBOT-HJ WORM! | No |
| AOLStart | X | AOLStart.exe | Detected by Kaspersky as Trojan-Spy.Win32.Kraimer.12 | No |
| America Online | N | aoltray.exe | Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs | Yes |
| America Online *.* Tray Icon | N | aoltray.exe | Adds the AOL icon in the System Tray (*.* denotes version if present) for versions of AOL up to and including 9.0. Start AOL via the desktop or quick launch shortcuts or via Start → All Programs | Yes |
| AOL TopSpeedMonitor | U | aoltsmon.exe | AOL's TopSpeed "Web acceleration technology is a feature designed to speed up the Web browsing experience on your AOL Desktop Software." Most important for those users who still access AOL via dial-up. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| aolupdater.exe | X | aolupdater.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| AOLUpdate | X | AOLupdt32.exe | Detected by Malwarebytes Anti-Malware as Trojan.SHarpro.Pgen. The file is found in %LocalAppData%\AOL OCP\AOLUpdate | No |
| ccWasher | U | aolwasher.exe | Webroot Cache & Cookie Washer - cleaning browser tracks, including cache, cookies, history, mail trash, drop-down address bar, auto-complete forms and downloaded program files for IE, Netscape and AOL | No |
| t2fview | X | aon32.exe | Detected by Sophos as Mal/Inject-CY | No |
| AOLRegKey32 | X | AOREGSVR512.EXE | Unidentified malware - see here | No |
| Aornum | X | aornum.exe | Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware | No |
| aostiwvxyowqlwaswoa | X | aostiwvxyowqlwaswoa.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| AO Tray | N | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start → Settings → Control Panel | No |
| AOTray | N | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start → Settings → Control Panel | No |
| ap.exe | X | ap.exe | SP Center and Control Center rogue security software - not recommended, removal instructions here and here | No |
| ap9h4qmo | X | ap9h4qmo.exe | ShopAtHomeSelect parasite | No |
| Monitor Apache Servers | U | ApacheMonitor.exe | Monitoring interface tool for the Apache Web Server package. Useful only if you're running such a server on your PC. Available via Start → Programs | No |
| AirPort Base Station Agent | U | APAgent.exe | Airport Base Station Agent utility for Apple's AirPort wi-fi basestations. "Wireless solution for home, school, and business. As it blankets your space with a blazing-fast, secure wireless network, it opens up a world of possibilities for home entertainment, backups, printing, and more" | No |
| SetPanel | ? | APanel.cmd | Display configuration utility for some Acer laptops. Is it required? | No |
| INFO DATA | X | apc.exe | Added by the RANDON.B WORM! | No |
| APcDefender | X | APcDefender.exe | APcDefender rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| DRPU Pc Data manager | U | apcdm.exe | DRPU PC Data Manager surveillance software. Uninstall this software unless you put it there yourself | No |
| Performance Center | N | ApcMain.exe | Ascentive Performance Center - not recommended, see here and here | No |
| APCProtect.exe | X | APCProtect.exe | APCProtect rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| APcSafe | X | APcSafe.exe | APcSafe rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| APcSecure | X | APcSecure.exe | APcSecure rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| apc_tray | Y | apc_tray.exe | Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure | No |
| APD123 | X | APD123.exe | PacerD Media/Pacimedia.com adware | No |
| Adobe Photo Downloader | N | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE and older versions of Photoshop Elements and Photoshop Lightroom image editing tools. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example | Yes |
| Adobe Photo Downloader 3.0 component | N | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE and older versions of Photoshop Elements and Photoshop Lightroom image editing tools. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example | Yes |
| Adobe Photoshop Album Starter Edition | N | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE image editing tool. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example | Yes |
| apdproxy | N | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE and older versions of Photoshop Elements and Photoshop Lightroom image editing tools. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example | Yes |
| apepr | X | apepr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Root% | No |
| AdvancedPrivacyGuard | X | apg.exe | AdvancedPrivacyGuard rogue privacy program - not recommended, removal instructions here | No |
| aphex | X | aphex.exe | Added by the IRCBOT-OH TROJAN! | No |
| Api**.exe [* = random char] | X | Api**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Api**32.exe [* = random char] | X | Api**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| API32 | X | api32.exe | Added by the IRCBOT-B TROJAN! | No |
| apiclass64 | X | apiclass64.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| APIMon | X | apimonx.exe | Added by the TIBSER.A downloader TROJAN! | No |
| api32 | X | apiqq.exe | Detected by Trend Micro as WORM_TATERF.DL and by Malwarebytes Anti-Malware as Worm.Magania. The file is located in %Temp% | No |
| apisvc.exe | X | apisvc.exe | Added by a variant of the LAMEBOT TROJAN! | No |
| Windows API Control Task | X | apitsk32.exe | Added by the MYTOB.HI WORM! | No |
| APL | U | APL.exe | Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application | No |
| aples.exe | X | aples.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\[7 or 8 numbers] - see examples here and here | No |
| apmanager.exe | X | apmanager.exe | AP Manager ransomware download manager - not recommended, removal instructions here | No |
| Apmsrv9x | ? | APMSRV9X.EXE | Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required? | No |
| APMV | X | APMV.exe | Added by the INDUC.B VIRUS! | No |
| Application Manager | X | apnsvc.exe | Added by the SMALLTRO.FN TROJAN! | No |
| apocalyps32 | X | apocalyps32.exe | Detected by Sophos as Troj/Agent-UNK and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| kis | X | apocalyps32.exe | Detected by Malwarebytes Anti-Malware as BackDoor.Bot. The file is located in %Windir% | No |
| Alps Pointing-device Driver | U | Apoint.exe | Touchpad driver from Alps Electric Co., Ltd for a number of laptops including some of those from Panasonic, Sony and Dell. Allows you to configure buttons and touchpad settings - including sensitivity, tap to click and single or multi-finger gestures. Required for proper functioning of the pointing software but not required if you use an external pointing device | Yes |
| AlpsPoint | U | Apoint.exe | Touchpad driver from Alps Electric Co., Ltd for a number of laptops including some of those from Panasonic, Sony and Dell. Allows you to configure buttons and touchpad settings - including sensitivity, tap to click and single or multi-finger gestures. Required for proper functioning of the pointing software but not required if you use an external pointing device | No |
| Apoint | U | Apoint.exe | Touchpad driver from Alps Electric Co., Ltd for a number of laptops including some of those from Panasonic, Sony and Dell. Allows you to configure buttons and touchpad settings - including sensitivity, tap to click and single or multi-finger gestures. Required for proper functioning of the pointing software but not required if you use an external pointing device | Yes |
| Prein | X | APP****.tmp [* = random char or digit] | Unidentified adware | No |
| sman | X | app***.tmp [* = digit] | Unidentified adware | No |
| App**.exe [* = random char] | X | App**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| App**32.exe [* = random char] | X | App**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| [executed file name] | X | App.exe | Added by the WAXPOW WORM! | No |
| app | X | app.exe | Detected by McAfee as RDN/Generic.dx!bbs and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| ApPache System | X | ApPache.exe | Added by the RBOT-YP BACKDOOR! | No |
| Logitech Desktop | X | ApPache.exe | Added by the RBOT-YP WORM! | No |
| Micro Process | X | appconf.exe | Added by an unidentified WORM or TROJAN! | No |
| userinit | X | appconf32.exe | Detected by Microsoft as PWS:Win32/Savnut and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| appconn | X | appconn.exe | Added by the CARGAO WORM! | No |
| Security Center | X | AppControl.exe | Added by the SDBOT.CFT WORM! | No |
| Application Explorer | X | appexplr.exe | Added by the AGENT-NMO TROJAN! | No |
| AppExtender | U | AppExtCB.exe | Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received | No |
| Vmlist | X | apphelps.dll | Added by the ALAMNAHE.A VIRUS! | No |
| configuration | X | apphost.exe | Added by the SDBOT-VP WORM! | No |
| appis.exe | X | appis.exe | Added by the AGENT-BC TROJAN! | No |
| AppLaunch | X | AppLaunch.exe | Detected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData% | No |
| Microsoft Windows Updater | X | apple.vbs | Detected by Malwarebytes Anti-Malware as Trojan.MWF.Gen. The file is located in %AppData% - see here | No |
| ApplePhotoStreams | U | ApplePhotoStreams.exe | With Apple Photo Stream "when you take a photo on one device, it automatically appears on all your other devices. And with Shared Photo Streams, you can easily choose which of your photos you want to share and who you want to share them with." Part of iCloud | No |
| AppleSyncNotifier | U | AppleSyncNotifier.exe | Part of Apple's MobileMe software and also installed with version 7.7 of the iTunes media management software. Enables users of iPhone, iPod Touch and iPad devices to synchronize their emails and calendars on every device and computer they use - whether its a desktop, laptop or a Mac. Also see here for more information | Yes |
| MobileMe | U | AppleSyncNotifier.exe | Part of Apple's MobileMe software and also installed with version 7.7 of the iTunes media management software. Enables users of iPhone, iPod Touch and iPad devices to synchronize their emails and calendars on every device and computer they use - whether its a desktop, laptop or a Mac. Also see here for more information | Yes |
| system applets | X | applets.exe | Detected by McAfee as Comame and by Malwarebytes Anti-Malware as Trojan.Comame | No |
| AppleUpdate | X | AppleUpdate.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file can be found in various locations | No |
| Apple Update | X | Appleupdt32.exe | Detected by Malwarebytes Anti-Malware as Trojan.SHarpro.Pgen. The file is found in %LocalAppData%\Apple\AppleUpdate | No |
| AppleUpdate | X | Appleupdt32.exe | Detected by Malwarebytes Anti-Malware as Trojan.SHarpro.Pgen. The file is found in %LocalAppData%\Apple Computer\AppleUpdate or %LocalAppData%\Apple\AppleUpdate | No |
| WindowsUpdate | X | Application Data1windowsupdate.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot.Gen. The file is located in %UserProfile% | No |
| WindowsUpdate | X | Application Data3windowsupdate.exe | Detected by Malwarebytes Anti-Malware as MSIL.LockScreen. The file is located in %UserProfile% | No |
| HD Audio Process | X | Application DataMicrosoft Search Indexer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| Microsoft Index | X | Application DataMicrosoft Search Indexer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| rundll32 | X | Application DataMSDCC.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| avira security | X | Application Datasvchost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| mumbl configurated | X | Application Datasvchost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| tempManager | X | Application DatatempManager.exe | Detected by Malwarebytes Anti-Malware as Backdoor.MSIL.PGen. The file is located in %UserProfile% | No |
| Windows Authenticity | X | Application Datawinauth.exe | Detected by Dr.Web as Trojan.PWS.Siggen.58623 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Windows Live | X | Application DataWinDir.exe | Detected by Sophos as Troj/Agent-ZHD and by Malwarebytes Anti-Malware as Backdoor.Fynloski | No |
| WindowsUpdate | X | Application Datawindowsupdate.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| Windows Configuration | X | Application Datawinini.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| Windows Live | X | Application Datawinini.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserProfile% | No |
| Windows OS | X | application Datawinini.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see here | No |
| Windows Live | X | Application Datawininie.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %UserProfile% | No |
| Windows Update Service | X | Application Datawinupd.exe | Detected by Sophos as Troj/Fynloski-R and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Application Launcher | N | Application Launcher.exe | System Tray access to the Sony Ericsson PC Suite (now replaced by PC Companion) and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone | Yes |
| Mobile Connectivity Suite | N | Application Launcher.exe | System Tray access to the HTC Sync mobile phone management utility for models including the Hero, Magic and Tattoo. Used to synchronize your computer's Outlook contacts and calendar or your Outlook Express contacts with your phone and can be used to backup this information to your computer. Run manually via the Start Menu before connecting the phone | Yes |
| PC Suite for Smartphones | N | Application Launcher.exe | System Tray access to the Sony Ericsson PC Suite (now replaced by PC Companion) mobile phone management utility for some models, including the P1i and M600i. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone | Yes |
| Sony Ericsson PC Suite | N | Application Launcher.exe | System Tray access to Sony Ericsson PC Suite (now replaced by PC Companion) which "connects your phone to your computer and expands the capabilities of your phone". Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone | Yes |
| applicationform | X | applicationform.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see here | No |
| My Document | X | applicationform.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserStartup% - see here | No |
| [various names] | X | AppMasterCenter.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| AppPlus | U | AppPlus.exe | AppPlus - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)" | No |
| ApproveItForOfficeSetup | ? | ApproveItForOfficeSetup.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? | No |
| Appstart | X | Appstart.exe | Added by the BANKER.CUE TROJAN! | No |
| ATSpooler | U | AppsTraka.exe | DeskTopScout keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| Autoloaderaproposclient | X | Apropos_Client_Loader.exe | AproposMedia adware | No |
| ASUSPRP | N | APRP.EXE | Product registration reminder for ASUS laptops and netbooks | No |
| AprvRemoveLegacyExcelKeys | ? | AprvClean.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? | No |
| AprvRemoveLegacyWordKeys | ? | AprvClean.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? | No |
| AdvancedPrivacySuite | X | APS.exe | AdvancedPrivacySuite rogue privacy program - not recommended, removal instructions here | No |
| Apple Push | ? | APSDaemon.exe | Related to the Apple Push Notification service included with iOS which allows you to "send over-the-air alerts, such as news updates or social networking status changes." Installed with the latest version of iTunes (and possibly other Apple software) | No |
| APSDaemon | ? | APSDaemon.exe | Related to the Apple Push Notification service included with iOS which allows you to "send over-the-air alerts, such as news updates or social networking status changes." Installed with the latest version of iTunes (and possibly other Apple software) | No |
| ENSApServer2_0 | ? | APSERVER.EXE | Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required? | No |
| AEZBProc | U | aptezbp.exe | IBM Aptiva keyboard customizer - enables certain special buttons on keyboard for CD operation, volume control, and few quickstart buttons. Keyboard will work without it but you lose the special functions | No |
| Systweak Scheduler | U | aptplaner.exe | Appointment Planner from the Advanced System Optimizer utility suite by Systweak Inc | No |
| Apvxd | Y | APVXDWIN.EXE | Part of an older version of the Panda Security range of internet security products. Required to enable permanent virus protection | No |
| Apvxdwin | X | APVXDWIN.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate Panda security file with the same name which is located in a %Program Files%\Panda Software sub-directory. This one is located in %System% | No |
| APVXDWIN | Y | APVXDWIN.EXE | Part of the range of internet security products from Panda Security - including Global Protection, Internet Security and Antivirus Pro. Required to enable permanent virus protection | No |
| Apwheel | Y | Apwheel.exe | Wheel support for an Alps mouse | No |
| Antimalware PC Safety | X | AP[random].exe | Antimalware PC Safety rogue security software - not recommended, removal instructions here | No |
| AQ3HelperStartUp | U | AQ3Helper.exe | ScreenScenes "Aquatica Water Worlds" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| AQ3HelperStartUp | U | AQ3HEL~1.EXE | ScreenScenes "Aquatica Water Worlds" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| aqadcup | X | aqadcup.exe | Added by the AGENT.BG BACKDOOR! | No |
| epixowu | X | aqiyutyvo.exe | Added by the SDBOT-UG WORM! | No |
| Microsoft Office Monitor | X | aql32.exe | Added by the RBOT-GCY TROJAN! | No |
| WinDLL (aqls32.exe) | X | aqls32.exe | Added by a variant of W32.IRCBot. The file is located in %System% | No |
| {D792EEBE-2C75-4EAA-09C3-AD660894D8F6} | X | aqlyi.exe | Added by the MDROP-CWR TROJAN! | No |
| coolsos | X | aqoeerw.exe | Added by the AUTORUN.BRHP WORM! | No |
| Aqua Dock | Y | Aqua Dock.exe | Aqua Dock - 'free program that allows you to have an "OS X" style, nice animated launchbar/taskbar on your screen that reacts to your mouse when you mouse over it. Users can customize the look of each item on the dock and set various animation options for when the mouse is over an item on the dock. It is very easy to configure' | No |
| Aquarium Desktop | U | AquariumDesktop.exe | Animated desktop gadget included with the Aquarium Desktop theme for MyColors from Stardock Corporation | No |
| Aquarium Desktop | U | AquariumDesktop2006.exe | Animated desktop gadget included with the Aquarium 2006 theme for MyColors from Stardock Corporation | No |
| AquaSnap | U | AquaSnap.Daemon.exe | AquaSnap by Nurgo Software - "is a free software that greatly enhances the way you can arrange windows on your Desktop. It gives you the possibility to snap windows to the edges or to the corners of the desktop simply by dragging and dropping them where you want" | No |
| Aqujyjax | X | aqujyjax.exe | Added by the SDBOT-YC WORM! | No |
| START | X | ar.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.X. The file is located in %AppData%\win | No |
| ArabLionZ Drive | ? | ArabLionZ.Drive.exe | ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required? | No |
| ArcaCheck | Y | ArcaCheck.exe | Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do? | No |
| 80's Arcade | U | Arcade.exe | 80's Arcade widget included with the DesktopX desktop utility from Stardock Corporation. Allows you to play classic 1980's arcade games such as Pacman and Space Invaders on the desktop. Once started, Arcade.exe loads a file called "DXWidget.exe" and exits | Yes |
| DesktopX Widget | U | Arcade.exe | 80's Arcade widget included with the DesktopX desktop utility from Stardock Corporation. Allows you to play classic 1980's arcade games such as Pacman and Space Invaders on the desktop. Once started, Arcade.exe loads a file called "DXWidget.exe" and exits | Yes |
| ArcadeDeluxeAgent | N | ArcadeDeluxeAgent.exe | Part of the re-branded version of CyberLink's PowerCinema digital home entertainment software included on some Acer systems. Equivalent to the "PCMAgent.exe" entry and speeds up the launch of the main program. Only required on slower/older systems and if disabled it loads when required via an instance of svchost.exe | No |
| ArcadeMovieService | N | ArcadeMovieService.exe | Part of Acer Arcade Deluxe - a default program included with all Acer computers for media management. Movie service by Cyberlink | No |
| arcaderockstar | X | arcaderockstar32.exe | Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean, but the TOS and privacy statement say that you agree to allow the program to track/report your surfing and put popup advertising on your computer | No |
| Adobe Reader 11.0X | X | Arcamax.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.ADB. Note - this is not a legitimate Adobe Reader entry and the file is located in %AppData%\Arcamax | No |
| Intel® Users Interface | X | Arcamax.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.ARC. The file is located in %AppData%\Arcamax | No |
| Archive | X | archive.exe | Adware - detected by Kaspersky as the CENTIM.A TROJAN! | No |
| ArcSoft MediaImpression Monitor | U | ArcMonitor.exe | Monitor for older versions of Arcsoft MediaImpression multimedia editing/management utility - including the version bundled with Kodak video cameras. Monitors for new media/devices being being attached/inserted | No |
| arcomstart | X | arcom.exe | Detected by Symantec as Backdoor.Arcomrat | No |
| Microsoft machine | X | arcpack.scr.exe | Added by the RBOT.ADF BACKDOOR! | No |
| ares | N | ares.exe | "Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc" | No |
| areslite | N | AresLite.exe | "Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc" | No |
| Aritima | X | aritima.exe | Added by the ARITIM WORM! | No |
| King_ar | X | arking.exe | Added by the PWS-BOS TROJAN! | No |
| MiniEYE-MiniREAD Launch | N | ARLaunch.exe | eyeQ - improve your reading speed | No |
| Adobe Auto Updater | X | ARM.exe | Detected by Malwarebytes Anti-Malware as Trojan.BitcoinMiner. The file is located in %AppData% | No |
| Access Ramp Monitor | N | armon32.exe | Monitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again | No |
| AccessRamp Monitor01 | N | ARMon32a.exe | From a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service" | No |
| ARMOR2NET | U | Armor2net.exe | Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue, see here - hence the "U" recommendation) | No |
| ArmorDefender | X | ArmorDefender.exe | ArmorDefender rogue security software - not recommended, removal instructions here | No |
| AROReminder | N | aro.exe | Advanced Registry Optimizer - "scan, identify, clean and repair errors in your Windows registry with a single click". Reminder that states that you are in trial mode | No |
| aromis | X | aromis.exe | Detected by Trend Micro as WORM_NUWAR.JQ | No |
| Arovax AntiSpyware | U | arovaxantispyware.exe | Part of Arovax AntiSpyware from Arovax, LLC - that offers an "innovating, powerful, speedy and extremely easy to use Spyware protection program". Runs a system scan when Windows starts and adds a System Tray icon | Yes |
| arovaxantispyware | U | arovaxantispyware.exe | Part of Arovax AntiSpyware from Arovax, LLC - that offers an "innovating, powerful, speedy and extremely easy to use Spyware protection program". Runs a system scan when Windows starts and adds a System Tray icon | Yes |
| Arovax Shield | Y | ArovaxShield.exe | Part of Arovax Shield from Arovax, LLC - that "detects and notifies you about all major online threats trying to penetrate your system, isolates & blocks them". Runs the main program in the background and adds a System Tray icon | Yes |
| ArovaxShield | Y | ArovaxShield.exe | Part of Arovax Shield from Arovax, LLC - that "detects and notifies you about all major online threats trying to penetrate your system, isolates & blocks them". Runs the main program in the background and adds a System Tray icon | Yes |
| gwiz | X | arpl.exe | Detected by F-Prot as W32/Downloader-Sml-based | No |
| Shedule Connection | X | arpo412.exe | Added by the PPDOOR-R WORM! | No |
| AlwaysReady Power Message APP | U | ARPWRMSG.EXE | "Away Mode" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input, such as recording television and viewing Media Center Extender sessions. For more information see here | No |
| ARPWRMSG | U | ARPWRMSG.EXE | "Away Mode" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input, such as recording television and viewing Media Center Extender sessions. For more information see here | No |
| MS-RunKey | X | arr.exe | MS-Connect - Switch dialer and hijacker variant, see here. Also detected as the DIALER.DD TROJAN! | No |
| Nortons AVS Systems | X | arse.exe | Detected by Trend Micro as WORM_RBOT.AWY | No |
| Win32 | X | arsetup.exe | Added by the SPAZBOX.A TROJAN! | No |
| Windows Monitor | X | arsetup.exe | Added by the SPAZBOX.A TROJAN! | No |
| Artera | U | arteraui.exe | Artera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance | No |
| AdRoarUpdate | X | ARUpdate.exe | AdRoar adware updater | No |
| AccessRampLAN01 | N | ARUpld32.exe | Version of the AccessRamp Monitor01 entry for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003 | No |
| wacult | X | aryancrypt.exe | Detected by McAfee as W32/Sdbot.bfr!d and by Malwarebytes Anti-Malware as Backdoor.Messa.Gen | No |
| ActiveSpeed | N | AS.exe | Ascentive ActiveSpeed internet optimizer - not recommended, see here and here | No |
| s9201 | X | as2008xp.exe | AntiSpyware XP 2008 rogue spyware remover - not recommended, removal instructions here | No |
| ASA.exe | Y | ASA.exe | Bell Aliant Servicepoint Agent tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| AsusACPIServer | ? | AsAcpiSvr.exe | Part of the ACPI driver for the Asus Eee PC range. What does it do and is it required? | No |
| asccacA | X | asacsqgl.exe | Added by the MULTIDRP.AA TROJAN! | No |
| EeeSplendidAgent | N | AsAgent.exe | Found on the Asus Eee PC range, the Eee Splendid utility lets you adjust your computer's display settings with just a few clicks | No |
| asam | X | asam.exe | Added by the FAKEAV-BGU TROJAN! | No |
| C:\WINDOWS\asam.exe | X | asam.exe | Added by the PEACOMM.E TROJAN! | No |
| yay.exe | X | asass.exe | Added by the AGOBOT-M WORM! | No |
| AntiSpyBoss | X | asb32.exe | AntiSpyBoss rogue security software - not recommended, removal instructions here | No |
| asc32 | X | asc 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| AUTORUN_VAL | X | asc 2.1.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| Microsoft Update | X | ascdl.exe | Detected by Symantec as W32.Gaobot.SY | No |
| Auto Updater | X | asclt.exe | Added by the SLINBOT.CJ BACKDOOR! | No |
| Configurations Asclt | X | asclt.exe | Added by the SDBOT-MX WORM! | No |
| REMOVE ME | X | asclt.exe | Added by the RANDEX-FC WORM! | No |
| Windows Configuration Loader | X | asclt.exe | Added by the SDBOT-OA WORM! | No |
| AsCmd | N | AsCmd.exe | Part of the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content". The exact purpose it unknown and it doesn't remain in memory. Loading AI Direct Link via Start → All Porgrams runs this file which loads the associated System Tray entry (AsShare.exe) | Yes |
| AsCmd.exe | N | AsCmd.exe | Part of the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content". The exact purpose it unknown and it doesn't remain in memory. Loading AI Direct Link via Start → All Porgrams runs this file which loads the associated System Tray entry (AsShare.exe) | Yes |
| Launch As Cmd Runner | N | AsCmd.exe | Part of the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content". The exact purpose it unknown and it doesn't remain in memory. Loading AI Direct Link via Start → All Porgrams runs this file which loads the associated System Tray entry (AsShare.exe) | Yes |
| Auto Scroll Loader | X | ASCRLL.EXE | Added by the SPYBOT-T WORM! | No |
| Advanced SystemCare 4 | U | ASCTray.exe | Advanced SystemCare optimization utility from IObit - "has a one-click approach to help protect, repair, clean, and optimize your PC." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | No |
| Advanced SystemCare 5 | U | ASCTray.exe | Advanced SystemCare optimization utility from IObit - "has a one-click approach to help protect, repair, clean, and optimize your PC." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | No |
| Advanced SystemCare 6 | U | ASCTray.exe | Advanced SystemCare optimization utility from IObit - "has a one-click approach to help protect, repair, clean, and optimize your PC." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | No |
| GMEY | X | asctrlsz.exe | Detected by Dr.Web as Trojan.DownLoader8.37083 | No |
| Windows cfg | X | ascv.exe | Added by the AGOBOT-SZ BACKDOOR! | No |
| Distributed Link Tracking | X | ascvt.exe | Added by the AGOBOT-GH BACKDOOR! | No |
| LoadPowerProfile | X | ASDAPI.EXE | Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll | No |
| ASDd | X | ASDd.exe | AntiSpywareDeluxe rogue security software - not recommended, removal instructions here | No |
| (Default) | X | asdfsd343f.exe | Added by the AUTORUN-BBB WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| ASE Scheduler | N | ASE Scheduler.exe | Aluria Software's spyware removal tool. Not recommended Aluria partnered with WhenU, the well known adware company - see here | No |
| AllSeeingEye | U | ase.exe | All-Seeing_Eye security software - "monitors everything that takes place on your computer, and alerts the user as soon as anything suspicious or out-of-the-ordinary is happening, providing the user with alternatives for possible actions" | No |
| Aluria's Spyware Eliminator | N | ASE.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here | No |
| AntiSpywareExpert | X | ase.exe | AntiSpywareExpert rogue security software - not recommended, removal instructions here | No |
| AdvSecTool | X | asectool.exe | Advanced Security Tool 2010 rogue security software - not recommended, removal instructions here | No |
| Active Security | X | asecurity.exe | Active Security rogue security software - not recommended, removal instructions here | No |
| AsusEPCMonitor | U | AsEPCMon.exe | Part of the ACPI driver for the Asus Eee PC range. Manages the Fn function keys and "on screen display" | No |
| RunAlert | U | AService.exe | MSI PC Alert III - motherboard monitoring software which allows you to view your System and CPU temperature, fan RPM and more. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Spyware Scanner | N | AseScanner.exe | Aluria Software's spyware removal tool - we can't really recommend this product as Aluria have recently partnered with WhenU, the well known adware company, see here and here | No |
| [12 random characters] | X | asferror.exe | IeDriver adware variant | No |
| AntiSpywareGuard | X | asg.exe | AntiSpywareGuard rogue spyware remover - not recommended, removal instructions here | No |
| msnmsg | X | asgag.exe | CoolWebSearch parasite variant | No |
| Microsoft Synchronization Manager | X | asgard.exe | Detected by Trend Micro as WORM_SDBOT.PH | No |
| Windows logging | X | asgasg.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| ashAvast | Y | ashAvast.exe | Part of earlier versions of avast! antivirus products | No |
| ashAvast.exe | Y | ashAvast.exe | Part of earlier versions of avast! antivirus products | No |
| ashDip.exe | X | ashDip.exe | Added by the DROPR-CZ TROJAN! | No |
| ashDisp | Y | ashDisp.exe | System Tray access to and notifications for the version 4.* series of antivirus products from avast! - giving left-click access to the On-Access Scanner, right-click access to other options and event notifications | Yes |
| avast! | Y | ashDisp.exe | System Tray access to and notifications for the version 4.* series of antivirus products from avast! - giving left-click access to the On-Access Scanner, right-click access to other options and event notifications | Yes |
| avast! Antivirus | Y | ashDisp.exe | System Tray access to and notifications for the version 4.* series of antivirus products from avast! - giving left-click access to the On-Access Scanner, right-click access to other options and event notifications | Yes |
| ashDsp.exe | X | ashDsp.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| ASHLT | X | Ashlt.exe | Ashlt adware | No |
| ashMaiSv | Y | ashmaisv.exe | E-mail scanning part of earlier versions of avast! antivirus products. Starts via a registry "Run" key on Windows 98/Me and as a service on Windows 2K/XP/Vista | No |
| Avast! | Y | ashServ.exe | Main part of earlier versions of avast! antivirus products - including the resident protection, virus chest and scheduler. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AshSnap | N | ashsnap.exe | Part of the Snap and Magical Snap Free screenshot capture and editing utilities from Ashampoo | No |
| avast! Web Scanner | Y | Ashwebsv.exe | Web scanning part of earlier versions of avast! antivirus products. Starts via a registry "Run" key on Windows 98/Me and as a service on Windows 2K/XP/Vista | No |
| Windows Task Scheduler | X | asijdie.exe | Added by an unidentified WORM or TROJAN! | No |
| Omega ASIO Control Panel | U | ASIOSysTray.exe | System Tray access to the control panel for the Lexicon Omega ASIO (Audio Streaming I/O) desktop recording studio | No |
| load= | U | asistat.exe | Status monitor for an NEC SuperScript printer | No |
| asl | X | Aslru.exe | Detected by Sophos as Troj/Bancos-CU | No |
| AntiSpywareMaster | X | asm.exe | AntiSpywareMaster rogue security software - not recommended, removal instructions here | No |
| FaxCtrl.exe | U | ASMediaProxyServer.exe | Part of Avaya's Contact Center Express - "a multi-channel, high-volume software solution from Avaya designed specifically for the intelligent routing and computer telephony integration (CTI) needs of medium-sized contact centers" | No |
| Absolute StartUp monitor | U | ASMon.exe | Absolute Startup - startup monitor from F-Group Software | No |
| ASM | U | ASMonitor.exe | Active Security Monitor from AOL - older version of their internet security software which helps you determine how vulnerable your PC is to computer viruses, spyware and other dangers and learn what steps you can take to improve your protection | No |
| Configuration Loader | X | asnclt32.exe | Added by the AGOBOT-EB BACKDOOR! | No |
| ASO | U | aso.exe | Mildware ASO screenshot capturing utility. Uninstall this software unless you put it there yourself | No |
| asp-srvc | X | asp-srvc.exe | Added by the AGOBOT-KG WORM! | No |
| Advanced System Protector | Y | ASP.exe | Advanced System Protector by Systweak Software - "is an effective solution to find and remove malware infections present on your PC. It also provides protection shields against malware threats" | No |
| Vortex Tray | N | asp4setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| VortexTray | N | asp4setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| asp4tray | N | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| VortexTray | N | asp4tray.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| WindowsSystem32 | X | asper.exe | Added by the AGENT-EFP TROJAN! | No |
| APPLECORPHKCU | X | AspireC.exe | Detected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| APPLELXHKLM | X | AspireC.exe | Detected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Policies | X | AspireC.exe | Detected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Backdoor.Agent.PGEn | No |
| AspireService | ? | AspireService.exe | Found on Acer laptops, the process name for this entry is "Win32 Service for Control Board and Remote Control" and it's part of Acer eMode Management. What does it do and is it required? | No |
| Antispyware PRO XP | X | asproxp.exe | AntiSpyware Pro XP rogue spyware remover - not recommended, removal instructions here | No |
| s9201 | X | asproxp.exe | AntiSpyware Pro XP rogue spyware remover - not recommended, removal instructions here | No |
| ASpyC | X | ASpyC.exe | AntiSpyCheck rogue spyware remover - not recommended, removal instructions here | No |
| Advanced Spyware Remover | X | Asr.exe | Advanced Spyware Remover rogue spyware remover - not recommended, see here | No |
| Advanced Spyware Remover Pro | X | Asr.exe | Advanced Spyware Remover rogue spyware remover - not recommended, see here | No |
| asr64_ldm.exe | X | asr64_ldm.exe | Added by the Dr. Guard rogue security software - not recommended, removal instructions here | No |
| Ai Quicker Help | U | AsRc.exe | ASUS DH Remote media portal launcher for their Digital Home range of motherboards that are designed for users to control the computer at a distance away, such as the M2N DH. "ASUS DH Remote is a convenient PC remote controller that gives users unprecedented control over their PCs from the comfort of their couches" | No |
| OpenApi | X | asropen.exe | Detected by Dr.Web as Trojan.DownLoader6.61248 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| AsusStartupHelp | ? | AsRunHelp.exe | Unknown ASUS motherboard utility. What does it do and is it required? | No |
| asrupdate.exe | X | asrupdate.exe | Added by the VB.ATZ TROJAN! | No |
| nvsv32.exe | X | asr_fnt.exe | Added by the WOOTBOT.GE WORM! | No |
| ASUS Screen Saver Protector | U | ASScrPro.exe | Pre-installed screen saver program on some ASUS laptops - such as the F3 and F5 series | No |
| ASUS Camera ScreenSaver | ? | ASScrProlog.exe | Either a valid program on some ASUS laptops - such as the F3 and F5 series or unsafe, according to PREVX and InCode Solutions. Can any ASUS owners with this file confirm? File is located in %Windir% | No |
| DVAScvssdfa | X | AsSDdwd.exe | Added by the LIOTEN.IP TROJAN! | No |
| AsShare | N | AsShare.exe | System Tray access to and notifications for the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content" | Yes |
| AsShare.exe | N | AsShare.exe | System Tray access to and notifications for the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content" | Yes |
| Launch Direct Link | N | AsShare.exe | System Tray access to and notifications for the AI Direct Link data transfer utility included with some ASUS motherboards. "Lightning Fast Data Linkage between Your PC & Laptop AI Direct Link can easily and efficiently transfer large amounts of data via the network cable - saving up to 70% of the total time taken. With AI Direct Link, it becomes easy to backup or share large data files like movies or other media content" | Yes |
| All Project | U | AsShellProcess.exe | Part of ASUS Mobilink which is installed with the AI Suite II set of utilities for selected products in their range of motherboards. Required if you want to use their BT Turbo Remote app on Android, Apple, Windows Mobile and Symbian mobile devices to remotely control your PC | No |
| ASUS ShellProcess Execute | U | AsShellProcess.exe | Part of ASUS Mobilink which is installed with the AI Suite II set of utilities for selected products in their range of motherboards. Required if you want to use their BT Turbo Remote app on Android, Apple, Windows Mobile and Symbian mobile devices to remotely control your PC | No |
| Kooping | X | assist.exe | Detected by Dr.Web as Trojan.StartPage.38694 | No |
| ExciteAssistantEXE | N | ASSISTANT.EXE | With Excite Assistant, you can access a wide variety of online information, including email, news, and stock quotes without having to have a browser window open | No |
| assistse | X | assistse.exe | CnsMin (Chinese Keywords) hijacker related | No |
| assusd_x86 | X | assusd_x86.bat | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| AST | X | AST | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| AST | X | AST.exe | AutoStartup spyware | No |
| Avast! | X | Ast1012.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not a valid Avast entry even though the file is located in %ProgramFiles%\AVAST Software\Avast | No |
| gdsfd | X | asta.exe | Detected by McAfee as Generic.dx!bh3k and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| AStart | X | AStart | Added by the VB.AH TROJAN! | No |
| ASTART | U | astart.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings | No |
| ASUS TweakEnable | U | astart.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings | No |
| Avast32 | Y | Astart32.exe | Part of earlier versions of avast! antivirus products | No |
| Aston2 | Y | Aston2.exe | Aston Windows shell by Gladiators Software - "this surprisingly smart, considered, at once sophisticated and simple shell replaces the standard Windows desktop and makes it more usable, beautiful and customizable" | No |
| asTray | N | Astray.exe | Voyetra Audio Station - part of Voyetra's Ultimate MP3 & CD Manager. MP3 and digital music jukebox/organizer | No |
| AsusTray | U | AsTray.exe | Part of the ACPI driver for the Asus Eee PC range. Watches the sensors of the motherboard such as power and temperature | No |
| Astro | N | Astro.exe | Checks for updates to Quicken on a system reboot | No |
| Quick Controls | U | Astrotoolbar.exe | Gateway Astro Screen and Sound Controls tray icon | No |
| Astrum | X | Astrum.exe | Astrum Antivirus Pro rogue security software - not recommended, removal instructions here | No |
| Asuite | U | ASuite.exe | ASuite launcher for Lupo PenSuite - which "is a completely free suite of portable programs and games. This Suite is designed to simplify the user's life, by collecting the best suites and portable applications available on the Web." Also available as a stand-alone utility | No |
| ASUS VIBE | N | ASUS VIBE.exe | "ASUS @Vibe is a one-stop, preinstalled repository that provides access to a wide variety of content. Users will be able to access content including music, videos, radio stations, games, magazines, e-books, e-learning materials, and Live TV as they please." Similar to Apple's iTunes it provides both free and paid content | No |
| asus | X | asus.exe | Added by the RBOT-OC WORM! | No |
| Asus MotherBoard Utility | X | asus.exe | Detected by Trend Micro as WORM_SPYBOT.IY | No |
| ASUS.exe | X | ASUS.exe | Added by the AUTORUN.AJX WORM! | No |
| ASUS Probe | N | AsusProb.exe | ASUS video card fan/thermal monitor - only required if you overclock your card or live in a hot area | No |
| asussvc | X | asussvc.exe | Added by the AGENT-FPB TROJAN! | No |
| ASUSWebStorage | N | ASUSWSDashBoard.exe | System Tray access to an older version of the ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts | No |
| AsusWSDashBoard | N | ASUSWSDashBoard.exe | System Tray access to an older version of the ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts | No |
| ASUSWebStorage | N | AsusWSPanel.exe | System Tray access to the ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts | Yes |
| AsusWSPanel | N | AsusWSPanel.exe | System Tray access to the ASUS Webstorage online backup and sharing utility which is pre-installed on some ASUS systems or available for free (with 1GB available) for others. Disable unless you want to automatically backup and sync your files every time your system starts | Yes |
| asvhost.exe | X | asvhost.exe | Added by the ICEDOOR-A TROJAN! | No |
| AllegroSurf Tray | U | ASVoyager.exe | System Tray access to the AllegroSurf web accelerating and content filtering proxy server from Rhino Software, Inc - which allows the sharing of a single Internet connection between multiple computers on a LAN | Yes |
| AllegroSurf® Proxy Server | U | ASVoyager.exe | System Tray access to the AllegroSurf web accelerating and content filtering proxy server from Rhino Software, Inc - which allows the sharing of a single Internet connection between multiple computers on a LAN | Yes |
| AllegroSurf Tray | U | ASVOYA~1.EXE | System Tray access to the AllegroSurf web accelerating and content filtering proxy server from Rhino Software, Inc - which allows the sharing of a single Internet connection between multiple computers on a LAN | Yes |
| AllegroSurf® Proxy Server | U | ASVOYA~1.EXE | System Tray access to the AllegroSurf web accelerating and content filtering proxy server from Rhino Software, Inc - which allows the sharing of a single Internet connection between multiple computers on a LAN | Yes |
| AutoSpell 5 | N | ASWATC32.EXE | AutoSpell - spell checker | No |
| ASWDP | N | ASWDP.exe | MLS Pulse - real estate software. Keeps the home buyer/seller continually informed on the status of his/her local/regional real estate market | No |
| ASWnk | X | aswnk.exe | Adult content dialler | No |
| AsxawrC | X | AsxawrC.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\[random]\[random] | No |
| [12 random characters] | X | asycfilt.exe | IeDriver adware variant | No |
| atapidrv | X | atapidrv.exe | Added by the AGOBOT-SL WORM! | No |
| Atari Launcher | N | Atari icon.exe | Launcher for the Atari Arcade Hits 1 game compilation from Hasbro Interactive and Atari Anniversary Edition Volume 1 from Infogrames | No |
| Atari Launcher 2 | N | Atari icon.exe | Launcher for the Atari Arcade Hits 2 game compilation from Atari and Atari Anniversary Edition Volume 1 from Infogrames | No |
| Configurations Loader | X | atask.exe | Added by the RBOT.H WORM! | No |
| The Easy Bee's Hive | U | ATCEgSvr.exe | The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence | No |
| atchk | U | atchk.exe | AMT Status Message from Intel. Users can manage this, read the article. See here for more information on Intel AMT | No |
| UsbPhoneLinker | U | AtcomUsbDialer.exe | Dialer for Atcom USB phones | No |
| AnyTime Organizer | U | AtDem.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" | No |
| MicroDialler | Y | atdialler1.exe | Part of the Freeserve Connection Kit - changed the dial-up for Freeserve AnyTime if access problems were encountered. Freeserve were a UK ISP provider | No |
| Orange Connection Kit | Y | atdialler1.exe | Part of the Orange Connection Kit - changes the dial-up for Orange AnyTime if access problems were encountered. Orange no longer offer a dial-up service | No |
| igamatu | X | atecaca.exe | Detected by Trend Micro as WORM_IRCBOT.R | No |
| atf_reinstall | X | atf.exe | Part of the AVSystemCare rogue security software - not recommended. See here | No |
| Athan | U | Athan.exe | Athan - an application that calculates and reminds the five daily Islamic prayer times for anywhere in the world | No |
| AthBtTray | U | AthBtTray.exe | Part of an older version of the Bluetooth implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. Note - during testing, other than the System Tray icon included as part of the Windows OS this appeared to add no additional icon. Given this it is still recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
| Bluetooth Software | U | AthBtTray.exe | Part of an older version of the Bluetooth implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. Note - during testing, other than the System Tray icon included as part of the Windows OS this appeared to add no additional icon. Given this it is still recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
| @Hoc Toolbar | N | AtHoc.exe | One-click activated browsing toolbar used by various web-sites. See here for more info | No |
| Switchboard.com Toolbar | N | AtHoc.exe | Toolbar for the on-line version of Yellow Pages in the US - Switchboard.com | No |
| CCC | X | ATI .exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located on %UserTemp% | No |
| AtiCwd | U | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card | No |
| AtiCwd32 | U | Ati2cwad.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card | No |
| Ati2cwxx | ? | Ati2cwxx.exe | For some ATI video cards. Probably used to access features and may not be required - for example the ATI Radeon works fine without it | No |
| [12 random characters] | X | ati2dvag.exe | IeDriver adware variant | No |
| ATIPOLAB | U | ati2evae.exe | ATI Polling Program - part of the ATI graphics driver e.g. on some Fujitsu-Siemens Notebooks | No |
| Ati2evxx | X | Ati2evxx.com | Added by the BACKDOOR-CPC TROJAN! | No |
| ATIPOLAB | N | ati2evxx.exe | Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented, they aren't therefore used and it can consume lots of CPU resources on some computers. Unless you use the hotkeys leave it disabled. Starts via a registry "Run" key on Windows 98/Me and as a service on Windows 2K/XP/Vista | No |
| ATIPOLL | N | ati2evxx.exe | Hotkey handler for ATI desktop and mobile graphics chipsets. Users report that most of the hotkeys aren't well documented, they aren't therefore used and it can consume lots of CPU resources on some computers. Unless you use the hotkeys leave it disabled. Starts via a registry "Run" key on Windows 98/Me and as a service on Windows 2K/XP/Vista | No |
| ati2f104 | X | ati2f104.exe | Added by the DLOADR-BBW TROJAN! | No |
| ATI 2D Component | U | Ati2mdxx.exe | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the "U" recommendation | Yes |
| Ati2mdxx | U | Ati2mdxx.exe | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the "U" recommendation | Yes |
| ATIModeChange | U | Ati2mdxx.exe | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. After testing it's exact function isn't known at this time and it doesn't appear to be running even with the startup entry enabled - hence the "U" recommendation | Yes |
| AtiPTA | U | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start → Settings → Control Panel → Display. Some users may need it if they have optimised their settings | No |
| AtiPTAAA | U | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start → Settings → Control Panel → Display. Some users may need it if they have optimised their settings | No |
| atiptaxx | U | Ati2ptxx.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start → Settings → Control Panel → Display. Some users may need it if they have optimised their settings | No |
| ATISmart | U | ati2s9ag.exe | ATI's "SMARTGART", which is included with the Catalyst drivers. When the system boots, it runs a couple of bus tests & tries to apply the most stable settings | No |
| ATI VIDEO REGKEY | X | ati2vid.exe | Added by the SDBOT.UR WORM! | No |
| rxres32 | X | ati2vid.exe | Added by the RBOT-FL WORM! | No |
| Motherboard Config | X | Ati2xxx.exe | Added by the RBOT-AIK WORM! | No |
| Norton AV Protection Startup | X | ati2xxx.exe | Added by a variant of Win32/Rbot | No |
| ATI Video Driver Control | X | ATIControl.exe | Added by the RBOT.DOO BACKDOOR! | No |
| aticpaxx.exe | X | aticpaxx.exe | Added by the RBOT-XP WORM! | No |
| ATI Customer Care | N | ATICustomerCare.exe | Launches registration for ATI graphics cards and sends back bug-reports if a crash occurs (in a game for example) | No |
| ATICustomerCare | N | ATICustomerCare.exe | Launches registration for ATI graphics cards and sends back bug-reports if a crash occurs (in a game for example) | No |
| AtiCwd | U | AtiCwd.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card | No |
| AtiCwd32 | U | AtiCwd32.exe | This utility adds the ATI tab in the advanced display properties (gives the option for TV out). Do not uncheck if there is TV out on the video card | No |
| ATI Display | X | ATIDisplay.exe | Added by the BDOOR-AFH BACKDOOR! | No |
| AtiDisplayDrv | X | atidrvxx.exe | Added by the RBOT-VZ WORM! | No |
| ATI DeviceDetect | N | ATIDtct.EXE | Utility meant for future use of the ATI TV WONDER USB 2.0 video driver and can be disabled | No |
| ATI Active Graphics Card Monitor | X | atievx.exe | Added by the IRCBOT-TL WORM! | No |
| ATI GART Set-up Utility | N | Atigart.exe | Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed | No |
| AtiGart | N | Atigart.exe | Program that checks the motherboard chipset and determines which GART driver bundle to install on ATI video cards. If you have one, once installed it shouldn't be needed | No |
| ATI Video Driver Control | X | atigfx.exe | Added by the RBOT-FWL WORM! | No |
| AtiKey | N | AtiKey32.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start → Settings → Control Panel → Display | No |
| AtiPanel | X | atip.exe | Added by the TACTSLAY.U TROJAN! | No |
| atipatxx | X | atipatxx.exe | Added by the SMALL-ED TROJAN! | No |
| Ati Control Panel | X | atiphexx.exe | Detected by Sophos as W32/Rbot-BR | No |
| ATI Cpanel | X | atiphexx.exe | Detected by Sophos as W32/Agobot-NV | No |
| AtiCpanel | X | atiphexx.exe | Added by the AGOBOT.IL WORM! | No |
| AtiPTA | U | Atiptaab.exe | Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Some users may need it if they have optimised their settings. Available via Control Panel | No |
| ATI Desktop Component | U | ATIPTAXX.EXE | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution, color depth and multi-display schemes), help and troubleshooting. Unless you often change your display settings this isn't really required as all the settings are available via the system Control Panel under "Display" | Yes |
| ATIPTA | U | ATIPTAXX.EXE | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution, color depth and multi-display schemes), help and troubleshooting. Unless you often change your display settings this isn't really required as all the settings are available via the system Control Panel under "Display" | Yes |
| AtiPTAAA | U | ATIPTAXX.EXE | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution, color depth and multi-display schemes), help and troubleshooting. Unless you often change your display settings this isn't really required as all the settings are available via the system Control Panel under "Display" | No |
| ATIPTAXX | U | ATIPTAXX.EXE | Installed with the drivers for some ATI based discrete graphics cards and on-board/mobile chipsets. Provides System Tray access to display settings (including desktop resolution, color depth and multi-display schemes), help and troubleshooting. Unless you often change your display settings this isn't really required as all the settings are available via the system Control Panel under "Display" | Yes |
| atiptext | X | atiptext.exe | Added by the COSIAM-A TROJAN! | No |
| AtiKey | N | atiptkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Control Panel → Display | No |
| AtiQiPcl | U | AtiQiPcl.exe | Used for hardware DVD decoding on ATI video cards supporting this feature. Not required unless you regularly play DVD's | No |
| System | X | Atira.exe | Added by the KOTIRA VIRUS! | No |
| atiradeonx86.bat | X | atiradeonx86.bat | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| ATI Rage3d Pro | X | AtiRage4dPro.exe | Added by the AGOBOT-OG WORM! | No |
| ATI Remote Control | Y | ATIRW.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it | No |
| ATI Scheduler | N | Atisched.exe | Component that remains resident in memory and automatically launches the ATI VIDEO PLAYER at a user selected time and date. Delete the shortcut in the Start → Programs → Startup folder as well. Functions could re-enable the program to load at start-up and re-introduce the shortcut. Try it and see | No |
| ATI Task Application (Atikey) | N | Atitask.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start → Settings → Control Panel → Display | No |
| Atikey | N | Atitask.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start → Settings → Control Panel → Display | No |
| anything | X | ATITAX.exe | Added by the FORBOT-DP WORM! | No |
| ATI Task Application | N | Atitkad.exe | System Tray access and key-combo shortcuts to common display functions on ATI video cards. Can be run from Start → Settings → Control Panel → Display | No |
| atitray | U | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings | No |
| AtiTrayTools | U | atitray.exe | ATI Tray Tools - allows quick access to ATI graphics card settings | No |
| [12 random characters] | X | atitvo32.exe | IeDriver adware variant | No |
| atiupdate | X | ATIUPDATE5.EXE | Added by the DEBESKI.A VIRUS! | No |
| Atiupdpl | X | atiupdpl.exe | Added by the SMALL.AOS TROJAN! | No |
| ATIUpdater | X | atiupdxx.exe | Added by the RBOT-ABX WORM! | No |
| Ati Display Settings | X | atividx.exe | Added by the RBOT-GAS WORM! | No |
| AtivOpen | X | ativopen.exe | Switch dialer and hijacker variant, see here | No |
| ATI Remote Control | Y | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it | No |
| ATIRmtWndr | Y | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it | No |
| ATIX10 | Y | atix10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it | No |
| Regx10EXE | Y | ATIX10.exe | ATI Remote Wonder - PC wireless remote control driver. Required if you use it | No |
| ATI Display Driver | X | atixd.exe | Added by the RBOT-FOV WORM! | No |
| Catalyst Control Centre | X | atixvdm.exe | Added by the RBOT.DMW BACKDOOR! Note - this is not related to any legitimate AMD graphics software | No |
| ATKOSD2 | U | ATKOSD2.exe | On-screen display utility bundled with laptops from ASUS. If this utility is not installed then you will not be able to properly use other AsusTek utilities such as Splendid and Power Gear | No |
| Atl**.exe [* = random char] | X | Atl**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Atl**32.exe [* = random char] | X | Atl**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| [12 random characters] | X | atl91036.exe | IeDriver adware variant | No |
| atlcontrol | U | atlcontrole.exe | Atlcontrol adware | No |
| [various names] | X | ATLIEHELPER.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| cwingllib | X | atllsimm.exe | Added by the PROXY.HV TROJAN! | No |
| Gblpluginst | X | atlsys1.exe | Detected by McAfee as PWS-Banker!hbd | No |
| GBLTRAY | X | atlsys1.exe | Detected by McAfee as RDN/Generic Downloader.x!bv and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| [various names] | X | atl_helper.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| microAttuneDownload | N | atmdlusr.exe | Application Launcher, MS Office application. USR (US Robotics) modem auto updater. May be a sub-set of Attune | No |
| Miramar Systems, Inc. | U | atmsg.exe | Miramar PC/Mac networking software | No |
| ATnotes | N | atnotes.exe | Loads the ATnotes program for virtual sticky notes for your desktop. Available via Start → Programs | No |
| Atomic-x27 | X | Atomic-x27.exe | Added by the KATOMIK-A WORM! | No |
| Atomic.exe | U | Atomic.exe | Atomic Clock Sync - synchronizes your computer's time with the NIST time server | No |
| Atomica | N | atomica.exe | Atomica runs from the System Tray and allows the user to find out more about a word or phrase on any screen by pointing at it with the mouse and clicking button one while holding down the Alt key | No |
| SkinClock | U | AtomicAlarmClock.exe | Atomic Alarm Clock by Drive Software - "Alert yourself about important events with different alarms and replace your computer tray clock using different skins. Computer Alarm clock that will play any MP3 file. It can also run a program, log off, wake up, reboot, shut down, turn off etc..." | No |
| Atomic-x27C | X | AtomicpartC.exe | Added by the KATOMIK-A WORM! | No |
| AtomicTime | U | ATOMICTIME.EXE | AtomicTime - utility that synchronizes your PC clock to an atomic clock | No |
| Atomic-Win-Clock | U | AtomicWinClock.exe | Atomic-Win-Clock from Tools&More - freeware utility that synchronizes your PC clock to a high precision atomic time clock. Now replaced by YACC (Yet Another Atomic Clock) | No |
| AtomSync | U | atomsync.exe | AtomSync - "this NTP client synchronizes your PC clock with an internet atomic time server or with a time server on your LAN" | Yes |
| PxDotNetLoader | N | ATPStartupAssistant.exe | Fidelity Active Trader Pro stock market trading utility from Fidelity Investments - "designed to provide the power, price, and service you need to help you trade the way you want" | No |
| Atrack | U | atrack.exe | New feature of Norton Internet Security (NIS) and Norton Personal Firewall (NPF) 3.0 is the Alert Tracker, an instant notification feature. The Alert Tracker displays information about events as they happen. This way, when a rule has been triggered or an access to the Internet made, you know about it immediately rather than finding out about it when you check your logs or notice that the NIS icon indicates a security alert | No |
| Atray | U | Atray.exe | Active Tray is a utility which lets you configure the system tray. You can also create your own tray icons | No |
| AT&T Communication Manager | U | ATTCM.exe | AT&T Communication Manager - "is a software application that works with your AT&T mobile broadband device to provide high-speed, wireless Internet connectivity so you can stay in touch" | No |
| Attune Download | X | Attunel.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| Attunel | X | Attunel.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| AttuneClientEngine | X | attune_ce.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| AttuneContentUpdater | X | attune_cu.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| AttuneDiscovery | X | attune_di.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| AttuneSystray | X | attune_st.exe | Aveo Attune automated helpdesk software - regarded as adware | No |
| a9z1eizA1e | X | atulabov.exe | Detected by Sophos as Troj/Agent-GWD | No |
| aTuner | N | atuner.exe | aTuner - tweak tool for GeForce based graphics cards | No |
| AnyTime | U | Atw.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" | No |
| AnyTime Organizer | U | Atw.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" | No |
| Anti-Trojan-Watch | U | ATWatch.exe | Anti-Trojan Watch - trojan detector | No |
| AT-Watch | U | ATWatch.exe | Anti-Trojan Watch - trojan detector | No |
| asustweakenable | U | ATweak.exe | ASUS TweakEnable - restores manually changed settings for ASUS based video cards such as overclocking. Only required if you use non-standard settings | No |
| Aiptek Graphics Tablet (USB) | Y | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) | No |
| atwtusb | Y | atwtusb.exe | USB interface for Aiptek Graphics Tablet (USB) | No |
| au.exe | X | au.exe | Added by the BEAGLE.B WORM! | No |
| AUXXTRAY | N | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| VortexTray | N | au30setp.exe | System Tray application for Aureal Vortex based soundcards. Can be run manually via Start → Settings → Control Panel | No |
| AU Agent | U | AUagent.exe | Au Agent from Zilab Software. Win2K/NT enhancement tool. Allows you to run applications under any security context without closing the whole logon session to process a new logon | No |
| AUCBPNP | Y | aucbnpn.exe | Adaptec USB CardBus Safe-Eject - driver for the Adaptec USB 2.0 CardBus which provides USB 2.0 ports for laptop users via a PCMCIA card slot | No |
| Aucompat | X | Aucompat.exe | Added by the GEMA TROJAN! | No |
| Audcntr | X | audcntr.exe | Added by the GEMA TROJAN! | No |
| Phone Connection Monitor | U | audevicemgr.exe | Connection monitor part of the Sony Ericsson PC Suite (now replaced by PC Companion) mobile phone management utility for some models, including the P800 and P910i | Yes |
| audi32 | X | audi32.exe | Added by the RANCK-FL TROJAN! | No |
| Microsoft Windows Operating System | X | audiadg.exe | Detected by McAfee as Generic BackDoor!dtw | No |
| Microsoft® Windows® Operating System | X | audiadg.exe | Detected by Sophos as Troj/MSILSpy-A and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| HD Intel Audio | X | Audio Intel HD.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%\Microsoft | No |
| Windows-Audio-HD-Driver-Component | X | Audio-HD-Service.exe | Detected by Dr.Web as Trojan.DownLoader8.11735 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| windowsaudiocodec | X | audio32.exe | Detected by Malwarebytes Anti-Malware as Backdoor.BlackShadesNET. The file is located in %AppData% | No |
| audiocfg.exe | X | audiocfg.exe | Added by the VB.ATE WORM! | No |
| Audiocntl | X | audiocntl.exe | Added by the GEMA TROJAN! | No |
| AudioCommander | N | AudioCommander.exe | System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation, graphic equalizer, echo Cancellation and beam forming | Yes |
| AudioCommander Application | N | AudioCommander.exe | System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation, graphic equalizer, echo Cancellation and beam forming. This entry is taken from the XP version of Windows Defender | Yes |
| AudioCommanderVista | N | AudioCommander.exe | System Tray access to the AudioCommander user interface for Andrea USB devices - including features such as noise cancellation, graphic equalizer, echo Cancellation and beam forming. This entry is taken from the registry "Run" key in the Vista version | Yes |
| Codec Audio | X | Audiodg.exe | Detected by McAfee as Generic PWS.y!1x3 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Codec Reader | X | Audiodg.exe | Detected by McAfee as Generic Dropper and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| Codec Reader | X | Audiodg.exe | Detected by Sophos as Troj/PWS-CAI and by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%\Microsoft | No |
| Gabest | X | audiodg.exe | Detected by McAfee as Backdoor-CEP.gen.ad and byMalwarebytes Anti-Malware as Backdoor.Agent | No |
| MicrosoftActivex | X | audiodg.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| windows | X | Audiodg.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| Windows Audio Device | X | audiodg.exe | Detected by Dr.Web as Trojan.Siggen3.56762 | No |
| audiodgi | X | audiodgi.exe | Detected by McAfee as Generic.bfr | No |
| Policies | X | audiodgi.exe | Detected by Sophos as Troj/Agent-SZG and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen | No |
| audiodg_US.exe | X | audiodg_US.exe | Detected by Dr.Web as Trojan.DownLoader6.43967 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| audiodriver | X | audiodriver.exe | Detected by Malwarebytes Anti-Malware as Trojan.Fakealert. The file is located in %AppData%\AudioSetup | No |
| audiodriver | X | audiodriver.exe | Detected by McAfee as Generic.dx!bbm4 and by Malwarebytes Anti-Malware as Trojan.Fakealert. The file is located in %AppData% | No |
| AudioDriver | X | AudioDriver32.exe | Detected by McAfee as Generic.dx!bdjr | No |
| Audiodrv | X | audiodrv.exe | Added by the CRYPTER.A TROJAN! | No |
| Realtek Sound System Driver | X | audiodrvx.exe | Detected by Trend Micro as TROJ_DLOADER.AU and by Malwarebytes Anti-Malware as Trojan.Agent. Note that this is not a valid Realtek process | No |
| Audio Install | X | Audiofix.exe | Detected by Sophos as Troj/VBInj-DR and by Malwarebytes Anti-Malware as Trojan.VBAgent | No |
| Windows Audio Driver | X | audiohd.exe | Added by the BANLOAD.ZS TROJAN! | No |
| Windows Audio HDi Driver | X | audiohd.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| HD Audio Controller Helper | X | audiohdr.exe | Detected by Microsoft as Backdoor:MSIL/Blahavi.A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| IDT PC Audio | X | AudioHelper.exe | Detected by McAfee as Generic PWS.y!1x3 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| AudioHQ | X | audiohq.exe | Added by the BANKER-EHK TROJAN! | No |
| Windows Update | X | audiohu.exe | Detected by Sophos as Troj/Agent-QJV and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Audioinf | X | audioinf.exe | Added by the CRYPTER.A TROJAN! | No |
| [12 random characters] | X | audiosrv.exe | IeDriver adware variant | No |
| Printer | X | auditchk.exe | Detected by Sophos as W32/Rbot-BPE | No |
| nodriver | X | AUEKXRZ.EXE | Added by a variant of the SPYBOT WORM! | No |
| augmsg | X | AUGMSG.EXE | Added by the SPYBOT-CO WORM! | No |
| Auto Update | X | AUP.exe | Added by the RBOT.ACD WORM! | No |
| MS Updates | X | aupd.exe | Spyware web downloader | No |
| AutoUpdater | X | aupdate.exe | Tinybar variant | No |
| ASDPLUGIN | X | Austria.exe | AsdPlug premium rate adult content dialer | No |
| ausvc | X | ausvc.exe | Added by the AUTOUPDER TROJAN! | No |
| Blank AntiViri | X | AUT0EXEC.BAT StartUp | Added by the BRONTOK-CJ WORM! | No |
| Windows UDP Control Center | X | auth.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Authorization Framework | X | authz.exe | Detected by McAfee as RDN/Generic.bfr!be and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| authz | X | authz.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| auto | X | auto.exe | Detected by McAfee as BackDoor-DOQ.gen.y | No |
| kb | X | AUTO.txt | Added by the BRONTOK-CV WORM! | No |
| ERUNT AutoBackup | U | AUTOBACK.EXE | ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots, resulting in numerous backups that can be restored | No |
| Autobar | U | autobar.exe | Connect buttons on the keyboard for internet direct access, etc. on HP computers | No |
| ConfigSafe | U | AUTOCHK.EXE | ConfigSafe - lets you identify changes to the registry, INI files, System asset files, system hardware, network connections, and operating system versions -- provides a restore function. Your choice | No |
| MurGee.com Auto Clicker | U | AutoClicker.exe | MurGee.com Auto Clicker utility which allows you to assign a keyboard shortcut to the left mouse button | No |
| autoclk | U | autoclk.exe | Autoclik is a Windows utility "that allows you to perform all mouse activity with absolutely no clicking" | No |
| EasySync Pro - 3CmPlm | U | AutoDet.exe | 3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - "a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems" | No |
| GroupWise PDA Connect - 3CmPlm | U | AutoDet.exe | 3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell | No |
| XTNDConnect PC - 3CmPlm | U | Autodet.exe | 3Com Palm PC specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications" | No |
| EasySync Pro - PocketPC | U | AutoDetect.exe | Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - "a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems" | No |
| XTNDConnect PC - PocketPC | U | AutoDetect.exe | Windows Mobile Pocket PC specific translator for XTNDConnect PC - "award-winning desktop-sync application that enables you to easily synchronize your contacts, calendar, tasks, email and notes between your mobile devices and popular PC applications" | No |
| EasySync Pro - PocketPC | U | AUTODE~1.EXE | Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - "a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems" | No |
| GroupWise PDA Connect - PocketPC | U | AUTODE~1.EXE | Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell | No |
| Laplink PDASync 3.1 - PocketPC | U | AUTODE~1.EXE | Laplink PDASync for Windows Mobile Pocket PC - PDA synchronisation utility | No |
| [12 random characters] | X | autodisc.exe | Added by a variant of Adware.IEDriver | No |
| Windows Data Server | X | autodisc.exe | Added by the SPYBOT-CB WORM! | No |
| WOOZ | X | autodisc.exe | Added by the AGENT-CPS TROJAN! | No |
| AUTOEXE | X | AUTOEXE.exe | Added by the SEMAPI-A WORM! | No |
| regedit | X | autoexe.exe | Added by the SDBOT.BSE BACKDOOR! | No |
| autoexec.bat | X | autoexec.bat | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| chkdsk | X | autoexec.bat | Added by the ANPES WORM! | No |
| none | X | AUTOEXEC.BAT | Added by the AGENT-MOV TROJAN! | No |
| run | X | Autoexec.com | Added by the HOLCAS.A WORM! | No |
| run= | X | Autoexec.com | Added by the HOLCAS.A WORM! | No |
| Extranet AutoDial | ? | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software | No |
| Symantec Antivirus professional | X | autoformat.exe | Added by the CIADOOR.BZJ BACKDOOR! | No |
| Drag'n'Drop_Autolaunch | N | Autolaunch.exe | Iomega HotBurn - CD-RW burning software | No |
| MotionSD STUDIO - SD Browser auto start - | N | AutoLauncher.exe | MotionSD STUDIO software supplied with Panasonic SD camcorders (such as the SDR-S100) which allows pictures to be acquired from the unit, edited and output | No |
| AutoMate Task Service | N | automate.exe | Task scheduler for Unisyn Automate 4 task automation/macro running software. Available via a desktop shortcut or Start → Programs | No |
| CompleteSecurityUpdate | Y | AutomaticUpdate.exe | Automatic updates for Defender Pro Private Surf - now incorporated Defender Pro 15-in-1 and 5-in-1 | No |
| 388529725448 | X | AutomaticUpdates.exe | Added by the SDBOT-DEN WORM! | No |
| Microsoft Update | X | automgr32.exe | Added by a variant of Win32/Rbot | No |
| adstartup | X | automove.exe | Adlogix adware variant | No |
| Win32 Ms Auto Updater | X | AutomsUPD.exe | Added by a variant of Win32/Rbot | No |
| Autopdate | X | Autopdate.exe | Added by the RBOT-AGL WORM! | No |
| REGRUNM | X | autoprotect.exe | Added by an unidentified WORM or TROJAN! | No |
| AutoProtect | X | AutoProtect.vbs | Added by the KILLBAT-C WORM! | No |
| MaxtorReg | U | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of | No |
| autorn | X | autorn.exe | Added by the SILLYFDC.BCY WORM! | No |
| AutoRsbotsRSB.exe | X | AutoRsbotsRSB.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% - see here | No |
| taengtae | X | AutoRun.bat | Added by the GATINA-B WORM! | No |
| TANG_INA_MO | X | AutoRun.bat | Added by the FILUKIN.A WORM! | No |
| autorun | X | autorun.exe | Added by the AUTOM-B WORM! | No |
| QBCD autorun | N | autorun.exe | Quick Books CD | No |
| WinRun | X | AutoRun.ini | Added by the LOVELET-AD WORM! | No |
| AutorunRemover.exe | Y | AutorunRemover.exe | Autorun Virus Remover - "uses proactive technology to permanently remove autorun & autorun.inf viruses, also it can block any autorun/autorun.inf viruses trying to infect the system via USB drives(pendrive, external hard disk, iPod, etc)" | No |
| AutoSizer | U | AUTOSIZER.EXE | AutoSizer - utility that automatically maximizes windows when they're opened | No |
| Autoroute SMTP | U | AutoSmtp.exe | Autoroute SMTP - "automatic switching between SMTP servers depending on what network you are currently working in." You need to have two Internet service providers | No |
| AutoSpell | N | autospel.exe | AutoSpell - spell checker (version 6.*) | No |
| AutoStart-Manager | U | AutoStart-Manager.exe | AutoStart-Manager from Tools&More - German startup program manager | No |
| AutoStart-Manager 2006 | U | AutoStart-Manager.exe | AutoStart-Manager from Tools&More - German startup program manager | No |
| Audio HD Driver | X | AutoStart.exe | Detected by Dr.Web as Trojan.Siggen3.12899 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| HP JetSpeed Autostart | N | AUTOSTART.EXE | Autostart executable for the old multiplayer game HP Jetspeed | No |
| Tweak-XP Pro | U | autostart.exe | Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| AutoSys | U | autosys.exe | Winguardian surveillance software. Uninstall this software unless you put it there yourself | No |
| Auto T Bar | N | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled | No |
| autotbar | N | autotbar.exe | If you disable the HP VIEW toolbar in IE and rearrange the toolbars on a reboot they will be back as they were before if this is left enabled | No |
| AutoTKit | N | AUTOTKIT.EXE | On HP PC's. Unclear what purpose it serves - but there's a known issue with Internet Explorer Toolbar settings not being saved with it enabled | No |
| autoupd | X | autoupd.exe | Added by an unidentified VIRUS, WORM or TROJAN! - found in a folder of the same name | No |
| autoupd | N | autoupd.exe | Raxco Software auto update utility | No |
| ATTRedUpdate | U | AutoUpdate.exe | Additional item added to start-ups after AT&T took over the now bankrupt Excite@home high-speed internet service. Included for automatically downloading and installing updates. Leave it unless you plan to regularly run it to check for updates | No |
| AutoUpdater | X | AutoUpdate.exe | PeopleonPage foistware | No |
| Creative Software Update | N | AutoUpdate.exe | Auto-updater for Creative Labs software | No |
| EMBASSY Trust Suite Secure Update | U | AutoUpdate.exe | Updates for Wave Systems Corp. Embassy Trust Suite - "delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today" | No |
| LG Intelligent Update | N | autoupdate.exe | Automatic update utility for LG Notebooks | No |
| SpyFighterUpdate | X | AutoUpdate.exe | SpyFighter rogue spyware remover - not recommended, removal instructions here | No |
| windowsupdate | X | autoupdate.exe | Added by the IRCBOT-P BACKDOOR! | No |
| autoupdater | X | autoupdater.exe | Detected by Malwarebytes Anti-Malware as Adware.EoRezo. The file is located in %AppData%\PCTuto\PCTuto | No |
| AutoUpdater | X | autoupdater.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\keywordpop | No |
| Windows SoftwareUpdater Helper | X | AutoUpdater.exe | Detected by Dr.Web as Trojan.DownLoader7.20458 and by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\SoftWareUpdate | No |
| autoupdatev2 | X | autoupdatev2.exe | Detected by Sophos as Troj/Dropper-BM | No |
| Nod32 Service | X | AutoUpdateWin32.exe | Added by the SDBOT-DJG WORM! | No |
| AutoVaccineMain | X | AutoVaccine.exe | AutoVaccine rogue security software - not recommended, removal instructions here | No |
| Microsoft Windows Autowxckn | X | autowxckn.exe | Added by the RBOT.DYZ BACKDOOR! | No |
| AutoLoaderEnvoloAutoUpdater | X | auto_update_loader.exe | Envolo/AproposMedia adware updater | No |
| EleFunAnimatedWallpaper | U | Autumn Sunset.exe | Autumn Sunset animated wallpaper from | No |
| aux.exe | X | aux.exe | Added by the ZINS TROJAN! | No |
| auxAudioDevice | X | aux32.exe | Added by the AIZU WORM! | No |
| [random name] | X | AV Protection 2011v121.exe | AV Protection 2011 rogue security software - not recommended, removal instructions here | No |
| [random name] | X | AV Security 2012v121.exe | AV Security 2012 rogue security software - not recommended, removal instructions here | No |
| Antivirus | X | av.exe | Added by the SINKIN TROJAN! Resets IE start page to realphx.com | No |
| Secure AntiVirus Pro | X | av.exe | Secure AntiVirus Pro rogue security software - not recommended, removal instructions here | No |
| Win Antispyware Center | X | av.exe | Win Antispyware Center rogue security software - not recommended, removal instructions here | No |
| Drives swap | X | AV1i.exe | Anti-Virus Number-1 rogue security software - not recommended, removal instructions here | No |
| Monitor calibration | X | AV1i.exe | Anti-Virus-1 rogue security software - not recommended, removal instructions here | No |
| s9201 | X | av2008xp.exe | Antivirus 2008 XP rogue security software - not recommended, removal instructions here | No |
| [32 random numbers] | X | av2009.exe | AntiVirus 2009 rogue security software - not recommended, removal instructions here | No |
| Antivirus 2009 | X | av2009.exe | AntiVirus'09 rogue security software - not recommended, removal instructions here | No |
| icrosof Avps32 Control | X | av32.pif | Detected by Sophos as W32/Rbot-AVC | No |
| Microsof Avps32 Control | X | av32.pif | Detected by Trend Micro as WORM_RBOT.CBE | No |
| [32 random numbers] | X | av360.exe | Antivirus 360 rogue security software - not recommended, removal instructions here | No |
| AV8 | X | av8.exe | Antivirus8 rogue security software - not recommended, removal instructions here | No |
| AV AntiSpyware | X | ava.exe | AV AntiSpyware rogue security software - not recommended, removal instructions here | No |
| AvaFind | N | AvaFind.exe | AvaFind file search utility | No |
| SunJavaSched Updater | X | avamx.exe | Added by the RBOT-ABJ WORM! | No |
| Norton Live Updater | X | Avapsvc.exe | Added by the AGOBOT-BG BACKDOOR! | No |
| 77f0aa23de45744aaf29aebbce172f81 | X | avast.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| af029b7100cbb27d8c0472b97315e8d5 | X | avast.exe | Detected by Dr.Web as Trojan.DownLoader8.32072 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| Controle Avast | X | avast.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\Microsoft | No |
| avast | Y | avastUI.exe | System Tray access to and notifications for the version 6.* series of antivirus and internet security products from avast! - giving left-click access to the main user interface, right-click access to other options and event notifications | Yes |
| avast! Antivirus | Y | avastUI.exe | System Tray access to and notifications for the version 5.* and 6.* series of antivirus and internet security products from avast! - giving left-click access to the main user interface, right-click access to other options and event notifications | Yes |
| avast5 | Y | avastUI.exe | System Tray access to and notifications for the version 5.* series of antivirus and internet security products from avast! - giving left-click access to the main user interface, right-click access to other options and event notifications | Yes |
| avastUI | Y | avastUI.exe | System Tray access to and notifications for the version 5.* and 6.* series of antivirus and internet security products from avast! - giving left-click access to the main user interface, right-click access to other options and event notifications | Yes |
| MSInfo | X | AVBgle.exe | Added by the NETSKY.O WORM! | No |
| AntivirusClean | X | avc2011.exe | Antivirus Clean 2011 rogue security software - not recommended, removal instructions here | No |
| AV Care | X | AvCare.exe | AvCare rogue security software - not recommended, removal instructions here | No |
| AVClean | X | AVClean.exe | AVClean rogue security software - not recommended, removal instructions here | No |
| AVantivirus | X | Avconsol.exe | Added by the MSNVB-D WORM! | No |
| AvconsoleEXE | U | Avconsol.exe | From McAfee VirusScan up to version 4.x and Dr Solomon's VirusScan. Used to schedule regular scans. If you don't have scans scheduled you don't need it | No |
| TrendMicro Antivirus | Y | Aveagent.exe | Virus scanner | No |
| AAMSFree702 | X | Avengine.com | Added by the DELF.LJ TROJAN! | No |
| Avengine | X | Avengine.com | Added by the DELF.LJ TROJAN! | No |
| AVer HID Receiver | N | AVerHIDReceiver.exe | Support for HD TV receiver/capture products from AVerMedia | No |
| AVerQuick | N | AVerQuick.exe | Launcher for HD TV receiver/capture products from AVerMedia | No |
| (Default) | X | avg.exe | Added by the BANKER-ETV TROJAN! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| AVG Antivirus 2011 | X | avg.exe | AVG Antivirus 2011 rogue security software - not recommended, removal instructions here. Note - this should not be confused with the popular and legitimate AVG Anti-Virus 2011 by AVG Technologies | No |
| Video Process | X | Avg123.exe | Added by the AGOBOT-MS WORM! | No |
| AVG7_AMSVR | Y | AVGAMSVR.EXE | This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher | No |
| avgamsvr.exe | Y | Avgamsvr.exe | This is the AVG7 Alert Manager for the 7.* series of anti-virus products from AVG Technologies. It is essential for both scheduled activities (such as automatic updates and scans) and for displaying alerts and reports via the Control Center (avgcc.exe). Appears in 9x/Me as a startup entry and as a service in 2K and higher | No |
| !AVG Anti-Spyware | Y | avgas.exe | System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware | Yes |
| AVG Anti-Spyware | Y | avgas.exe | System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware | Yes |
| avgas | Y | avgas.exe | System Tray access to and notifications for AVG Anti-Spyware 7.5. This has now been superseded by AVG Anti-Virus which includes Anti-Spyware | Yes |
| AVG Anti-Virus system | Y | avgcc.exe | System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled, the core product functions will work properly but you will lose quick access to the Control Center and miss notifications of potential problems and updates | Yes |
| AVG7_CC | Y | avgcc.exe | System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled, the core product functions will work properly but you will lose quick access to the Control Center and miss notifications of potential problems and updates | Yes |
| avgcc | Y | avgcc.exe | System Tray access to and notifications for the 7.* series of anti-virus products from AVG Technologies. If this entry is disabled, the core product functions will work properly but you will lose quick access to the Control Center and miss notifications of potential problems and updates | Yes |
| AVG_CC | Y | avgcc32.exe | System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates | No |
| avgcc32 | Y | avgcc32.exe | System Tray access to and notifications for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies. Also enables scheduled tests, Outlook E-mail plug-in and automatic updates | No |
| AVGCtrl | Y | AVGCtrl.exe | Part of AntiVir® PersonalEdition Classic antivirus | No |
| AVG Anti-Virus System | Y | avgemc.exe | E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry, it loads as a service in 2K and higher | Yes |
| AVG_EMC | Y | AVGEMC.exe | AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses | No |
| AVG7_EMC | Y | avgemc.exe | E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry, it loads as a service in 2K and higher | Yes |
| avgemc | Y | avgemc.exe | E-mail scanner for the 7.* series of anti-virus products from AVG Technologies. This process scans incoming and outgoing E-mails for viruses and other malware. From version 7.1 onwards this entry only appears in 9x/Me as a startup entry, it loads as a service in 2K and higher | Yes |
| avgfwsrv | Y | AVGFWSRV.EXE | Integrated firewall for the 7.* series of anti-virus products from AVG Technologies. Protects the users computer from outside attacks, typically from the internet. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| AVG IDS | Y | AVGIDSUI.exe | System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. "Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web, make yourself secure in the knowledge that your passwords, account information, credit card numbers, social security numbers and other valuables are safe from identity thieves." It also loads the background activity monitoring process (AVGIDSMonitor.exe) | Yes |
| AVGIDS | Y | AVGIDSUI.exe | System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. "Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web, make yourself secure in the knowledge that your passwords, account information, credit card numbers, social security numbers and other valuables are safe from identity thieves." It also loads the background activity monitoring process (AVGIDSMonitor.exe) | Yes |
| AVGIDSUI | Y | AVGIDSUI.exe | System Tray access to and notifications for AVG Identity Protection - identity theft prevention which is available as a stand-alone product or included with AVG Internet Security. "Always-on identity theft prevention for Windows from one of the world's most trusted security companies. Shop and ensure safe surfing of the web, make yourself secure in the knowledge that your passwords, account information, credit card numbers, social security numbers and other valuables are safe from identity thieves." It also loads the background activity monitoring process (AVGIDSMonitor.exe) | Yes |
| AVG LiveKive | U | avglivekive.exe | AVG LiveKive® by AVG Technologies - "automatically backs up and synchronizes all your files from your devices, enabling you to view and share data safely anytime, anywhere. Think of it as your very own virtual archive" | No |
| avgmsvr.exe | Y | avgmsvr.exe | AVG Anti-Virus 7.0 related | No |
| avgnt | Y | avgnt.exe | System Tray access to and notifications for the range of internet security products from Avira Operations GmbH & Co. KG - including Internet Security, Antivirus Premium and Free Antivirus | Yes |
| AVGNT | X | avgnt1.exe | Detected by McAfee as Generic.hra!k and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| AVIRNT | X | avgnt1.exe | Detected by McAfee as Generic.hra!k and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Policies | X | avgnt1.exe | Detected by McAfee as Generic.hra!k and by Malwarebytes Anti-Malware as Backdoor.Agent.Pgen | No |
| AVG7_RegCleaner | Y | avgregcl.exe | Boot time registry cleaner for the 7.* series of anti-virus products from AVG Technologies - for checking the registry for virus additions and other security problems | No |
| AVG AntiVirus Scanner | X | avgscnx.exe | Added by the SILLYFDC.BBE WORM! Note - this is not a legitimate AVG entry | No |
| Avgserv9.exe | Y | Avgserv9.exe | Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the "RunServices" registry key | No |
| AVG Internet Security | U | avgtray.exe | System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free and LinkScanner®. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVG_TRAY | U | avgtray.exe | System Tray access to and notifications for the 2011/2012 range of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVG8_TRAY | U | avgtray.exe | System Tray access to and notifications for the 8.* series of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free and LinkScanner®. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVG9_TRAY | U | avgtray.exe | System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free and LinkScanner®. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| avgtray | U | avgtray.exe | System Tray access to and notifications for the range of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free and LinkScanner®. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVGuard | Y | AVGuard.exe | AntiVir® PersonalEdition Classic antivirus. Background task which scans files transparently | No |
| Special Firewall Service | X | avguard.exe | Added by the NETSKY.G WORM! Note - do not confuse with AntiVir® antivirus which uses the same filename. This one is located in %Windir% | No |
| AVG_UI | U | avgui.exe | System Tray access to and notifications for the 2013 range of internet security products from AVG Technologies - including Internet Security, Anti-Virus and their free products such as Anti-Virus Free. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVG Anti-Virus System | Y | avgw.exe | This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts | Yes |
| AVG7_Run | Y | avgw.exe | This entry is included with the 7.* series of anti-virus products from AVG Technologies. Once installed (or on first run for a different user) it runs the configuration sequence to set up the product and doesn't run on subsequent restarts | Yes |
| AVG AntiVirus Updater | X | avgwusv.exe | Added by the SILLYFDC.BAX WORM! Note - this is not a legitimate AVG entry | No |
| [12 random characters] | X | avifile5.exe | IeDriver adware variant | No |
| HD Audio Process | X | avifWindow.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| Avimgt | X | Avimgt.exe | Added by the GEMA TROJAN! | No |
| Avimgt32 | X | Avimgt32.exe | Added by the GEMA TROJAN! | No |
| avinit | Y | AVINIT9X.EXE | Part of Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch) | No |
| AVFuck | X | avira.cmd | Detected by Dr.Web as Trojan.PWS.Siggen.36856 | No |
| Avira_Loader | X | aviraautoloader.exe | Added by the BANKER.YL TROJAN! | No |
| Avira System Speedup | U | AviraSpeedup.exe | Avira System Speedup optimization utility - "boldly goes where no user can, safely and thoroughly removing unused programs and files, optimizing Windows to bring back the fast, error-free performance you deserve!" | Yes |
| AviraSpeedup | U | AviraSpeedup.exe | Avira System Speedup optimization utility - "boldly goes where no user can, safely and thoroughly removing unused programs and files, optimizing Windows to bring back the fast, error-free performance you deserve!" | Yes |
| VirusCheckII | X | AVIRCHK.EXE | Added by the DASMIN TROJAN! | No |
| AvirS | X | AvirS.exe | Detected by Dr.Web as Trojan.PWS.Gamania.36011 and by Malwarebytes Anti-Malware as Spyware.OnLineGames | No |
| AvirTr | X | AvirTr.exe | AntivirusTrigger rogue security software - not recommended, removal instructions here | No |
| AVKBar | Y | AVKBar.exe | GData AntiVirusKit Anti-virus | No |
| Windows Update | X | avkir.exe | Detected by Sophos as W32/Rbot-GJP and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| AVK Mail Checker | Y | AVKPop.exe | eXtendia AVK AntiVirus email checker | No |
| eScan Scheduler | U | avkserv.exe | MicroWorld eScan antivirus scheduler | No |
| Ad-Aware Total Security | Y | AVKTray.exe | System Tray access to and notifications for Lavasoft's Ad-Aware Total Security internet security product (which is based upon TotalSecurity from G Data Software AG). If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| AVKTray | Y | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security | Yes |
| G DATA AntiVirus Tray Application | Y | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security | Yes |
| G DATA AntiVirus Trayapplication | Y | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalCare, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates | Yes |
| G Data InternetSecurity | Y | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security | Yes |
| G Data Security Software | Y | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security | Yes |
| eScan Monitor | Y | AVKWCTL9X.EXE | MicroWorld eScan antivirus | No |
| Antivirus | X | avm.exe | Antivirus Master rogue security software - not recommended, removal instructions here | No |
| AvMaiSrv | Y | Avmaisrv.exe | Part of Avast! anti-virus software - E-mail scanner | No |
| AvMenu | ? | AVMenu.exe | Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do and is it required? | No |
| avc | X | avmon.exe | Added by unidentified malware. The file is located in %System% | No |
| QuickShock | X | AvMsUpd.exe | Added by the BANLOAD.ADPD TROJAN! | No |
| Microsoft iexplorer11 | X | avntsc.exe | Added by the NEERIS-C WORM! | No |
| AVP-SE | X | avp-32.exe | Detected by Trend Micro as WORM_AGOBOT.FS | No |
| Active Virus Shield | Y | avp.exe | System Tray access to and notifications for AOL's now discontinued Active Virus Shield (by Kaspersky) - found in %ProgramFiles%\AOL\Active Virus Shield. Runs together with a related service - Active Virus Shield (AVP) - which runs a separate instance of the same file | No |
| aol | Y | avp.exe | System Tray access to and notifications for AOL's now discontinued Active Virus Shield (by Kaspersky) - found in %ProgramFiles%\AOL\Active Virus Shield. Runs together with a related service - Active Virus Shield (AVP) - which runs a separate instance of the same file | No |
| avp | X | avp.exe | Detected by Sophos as Troj/DwnLdr-GWB. Not to be confused with Kaspersky internet security products and AOL's now discontinued Active Virus Shield (by Kaspersky) - which are found in either a Kaspersky or AOL sub-directory. This one is located in %Windir% | No |
| AVP | Y | avp.exe | System Tray access to and notifications for the range of internet security products from Kaspersky Lab - including PURE, Internet Security and Anti-Virus. Runs together with a related service - such as "Kaspersky Internet Security (AVP)" - which runs a separate instance of the same file. Also AOL's Active Virus Shield and Steganos AntiVirus 2007 - both by Kaspersky and now discontinued. Found in either a Kaspersky, AOL or Steganos sub-directory | Yes |
| ExplorerRun | X | avp.exe | Detected by Kaspersky as Trojan.Win32.Pincav.cqu. Not to be confused with Kaspersky internet security products, AOL's Active Virus Shield and Steganos AntiVirus 2007 (both by Kaspersky and now discontinued) - which are found in either a Kaspersky, AOL or Steganos sub-directory. This one is located in %UserTemp% | No |
| hagent | X | avp.exe | Added by the "Herman Agent" remote access TROJAN! | No |
| Kaspersky Anti-Virus | X | avp.exe | Added by an unidentified VIRUS, WORM or TROJAN! Not to be confused with Kaspersky internet security products, AOL's Active Virus Shield and Steganos AntiVirus 2007 (both by Kaspersky and now discontinued) - which are found in either a Kaspersky, AOL or Steganos sub-directory. This one is located in %System% | No |
| Kaspersky Anti-Virus | Y | avp.exe | System Tray access to and notifications for the range of internet security products from Kaspersky Lab - including PURE, Internet Security and Anti-Virus. Runs together with a related service - such as "Kaspersky Internet Security (AVP)" - which runs a separate instance of the same file | Yes |
| Kaspersky Anti-Virus 2006 | Y | avp.exe | System Tray access to and notifications for Kaspersky Anti-Virus 2006 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file | No |
| Kaspersky Anti-Virus 2006 (Beta) | Y | avp.exe | System Tray access to and notifications for Kaspersky Anti-Virus 2006 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file | No |
| Kaspersky Anti-Virus 2009 | Y | avp.exe | System Tray access to and notifications for Kaspersky Anti-Virus 2009 from Kaspersky Lab. Runs together with a related service - Kaspersky Anti-Virus (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Anti-Virus 6.0 | Y | avp.exe | System Tray access to and notifications for Kasperksy Anti-Virus 6.0 from Kaspersky Lab. Runs together with a related service - Kaspersky Anti-Virus 6.0 (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Anti-Virus 7.0 | Y | avp.exe | System Tray access to and notifications for Kasperksy Anti-Virus 7.0 from Kaspersky Lab. Runs together with a related service - Kaspersky Anti-Virus 7.0 (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Internet Security | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 7.0 from Kaspersky Lab. Runs together with a related service - Kaspersky Internet Security 7.0 (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Internet Security 2006 | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 2006 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file | No |
| Kaspersky Internet Security 2006 (Beta) | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 2006 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file | No |
| Kaspersky Internet Security 2009 | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 200#9 from Kaspersky Lab. Runs together with a related service - Kaspersky Internet Security (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Internet Security 6.0 | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 6.0 from Kaspersky Lab. Runs together with a related service - Kaspersky Internet Security 6.0 (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Internet Security 7.0 | Y | avp.exe | System Tray access to and notifications for Kasperksy Internet Security 7.0 from Kaspersky Lab. Runs together with a related service - Kaspersky Internet Security 7.0 (AVP) - which runs a separate instance of the same file | No |
| Kaspersky Total Security | Y | avp.exe | System Tray access to and notifications for an earlier version of the Kaspersky PURE security software. Runs together with a related service - Kaspersky PURE (AVP) - which runs a separate instance of the same file. This is the Vista/7 MSConfig and Windows Defender entry | Yes |
| kav | Y | avp.exe | System Tray access to and notifications for older versions of internet security products from Kaspersky Lab - including Internet Security and Anti-Virus. Runs together with a related service - such as Kaspersky Internet Security (AVP) - which runs a separate instance of the same file. Also AOL's Active Virus Shield (by Kaspersky) - now discontinued. Found in either a Kaspersky or AOL sub-directory | No |
| kis | Y | avp.exe | System Tray access to and notifications for Kaspersky Internet Security 6.0 from Kaspersky Lab. Runs together with a related service - AVP - which runs a separate instance of the same file. Also Steganos Internet Security 2007 - by Kaspersky and now discontinued. Found in either a Kaspersky or Steganos sub-directory | No |
| McAfee Online virus Scanner | X | avp.exe | Detected by Sophos as W32/Rbot-GCV. Not to be confused with Kaspersky internet security products and AOL's now discontinued Active Virus Shield (by Kaspersky) - which are found in either a Kaspersky or AOL sub-directory. This one is located in %System% | No |
| TlcR | ? | avp.exe | ?? | No |
| Antivirus PC 2009 | X | avpc2009.exe | Antivirus PC 2009 rogue security software - not recommended, removal instructions here | No |
| AVPCC | Y | avpcc.exe | Part of an older version of Kaspersky Anti-Virus from Kaspersky Labs. Runs together with a related service - AVP Control Centre Service (AVPCC) - which runs a separate instance of the same file | No |
| Win32 Usb Driver | X | AvpG.exe | Detected by Sophos as W32/Forbot-BX | No |
| MyAV | X | avpguard.exe | Added by the NETSKY.J WORM! | No |
| AntiVirus Plus | X | avplus.exe | AntiVirus Plus rogue security software - not recommended, removal instructions here | No |
| AvpM | X | AvpM.exe | Added by the STARTPAGE-ID TROJAN! Note - this is not the popular Kaspersky antivirus and this file is located in %Windir%\pchealth\UploadLB\Config | No |
| Kaspersky Anti-Virus Lite | Y | AvpM.exe | Kaspersky Anti-Virus Lite - no longer available. Licensed by other companies such as Defender Pro, CyberScrub and AVForce | No |
| Kaspersky Anti-Virus Monitor | Y | AvpM.exe | Kaspersky Anti-Virus Lite - no longer available | No |
| [various names] | X | avpmondll.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| avpms | X | avpms.exe | Added by the ONLINEGAMES.CPV TROJAN! | No |
| avpnes | X | avpnes.exe | Detected by Dr.Web as Trojan.DownLoader7.25774 and by Malwarebytes Anti-Malware as Trojan.Banker.Gen | No |
| avpnez | X | avpnez.exe | Detected by Dr.Web as Trojan.DownLoader7.25774 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| avpa | X | avpo.exe | Added by the LEGMIR-ARK TROJAN! | No |
| Avpr | X | avpr.exe | Added by the MYDOOM.AF WORM! | No |
| HtProtect | X | AVprotect.exe | Added by the NETSKY.L WORM! | No |
| 9xHtProtect | X | AVprotect9x.exe | Added by the NETSKY.M WORM! | No |
| AVPSrv | X | AVPSrv.exe | Added by the ONLINE-GEN TROJAN! | No |
| icrosoftf Avpx Control | X | avpx.exe | Added by the RBOT-AYN WORM! | No |
| (Default) | X | avr.exe | Detected by Dr.Web as Trojan.PWS.Banker1.6571 and by Malwarebytes Anti-Malware as Trojan.Banker. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %Windir% | No |
| Advanced Virus Remover | X | AVR.exe | Advanced Virus Remover rogue security software - not recommended, removal instructions here | No |
| avrlabs | X | avrlabs.exe | VirusResponse Lab 2009 rogue security software - not recommended | No |
| VZRemoteCommander | U | AvRmtCtr.exe | Related to Sony's VAIO Zone Remote Commander | No |
| Windows Anti Virus Control Center | X | avrscan.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Application Layer Services | X | avrsvc.exe | Added by the IRCBOT.BJM BACKDOOR! | No |
| [32 random numbers] | X | AVS.exe | Antivirus Sentry rogue security software - not recommended, removal instructions here | No |
| ANTIVIRUS | X | AVS.exe | Antivirus Sentry rogue security software - not recommended, removal instructions here | No |
| AvScan | X | avscan.exe | Antivirus System PRO and Spyware Protect 2009 rogue security software. The file is located in %ProgramFiles%\[rogue name] | No |
| avscan | X | avscan.exe | Detected by Symantec as W32.SillyFDC.BCR. The file is located in %Temp% | No |
| Wlan Driver | X | avscan.exe | Added by the WOOTBOT.DH WORM! | No |
| avscanengine | X | avscanengine.exe | Detected by McAfee as Generic MSIL.t and by Malwarebytes Anti-Malware as Trojan.Clicker.Gen | No |
| AVSCHED32 | Y | AVSched32.exe | AntiVir® PersonalEdition Classic - antivirus | No |
| AVScheduler | X | AVSCHSVC.EXE | Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended, removal instructions here | No |
| Windows svchost | X | avserv.exe | Added by the PUSHBOT.FM WORM! | No |
| avserve.exe | X | avserve.exe | Added by the SASSER WORM! | No |
| avserve2.exe | X | avserve2.exe | Added by the SASSER.B or SASSER.C WORMS! | No |
| avserve3.exe | X | avserve3.exe | Added by the SASSER.G WORM! | No |
| avservice | X | avservice.exe | Antivirus Clean 2011 rogue security software - not recommended, removal instructions here | No |
| Antivirus | X | avskill.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %AppData%\%Root%\ProgramData | No |
| avsnes | X | avsnes.exe | Detected by McAfee as Generic.hra!k and by Malwarebytes Anti-Malware as Trojan.Agent.QH | No |
| avsnesa | X | avsnesa.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AVN. The file is located in %Windir% | No |
| Windows Services | X | avsrv32.exe | Detected by Trend Micro as WORM_IRCBOT.ZXY and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| AVStation premium | U | AVStation agent.exe | Related to Samsung AV Station - instant playback of music, photos, videos | No |
| Microsoft iexplorer11 | X | avstc.exe | Added by the AUTORUN-BHK WORM! | No |
| WinAntivirus | X | AVSVC.EXE | Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended, removal instructions here | No |
| McAfeeVirusScanService | Y | Avsynmgr.exe | From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe), WebScanX (Webscanx.exe), VirusScan System Scan (Vshwin32.exe) and VirusScan Console (Avconsol.exe) under one application | No |
| MSMcAfeee | X | Avsynmgr32e.exe | Added by the FRAMAR TROJAN! | No |
| MSMcAfeeh | X | Avsynmgr32h.exe | Added by the FRANGO TROJAN! | No |
| MSMcAfeeS | X | Avsynmgr32S.exe | Added by the VOLAC or VOLAC.DR TROJANS! | No |
| avsys | X | avsys.exe | Detected by Kaspersky as Net-Worm.Win32.Kolab.lan | No |
| Antivirus | X | avt.exe | Antivirus rogue security software - not recommended, removal instructions here | No |
| avtapi | X | avtapi.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" | No |
| Avtray | Y | Avtray.exe | Commtouch Command Antivirus (was Authentium) tray icon | No |
| AVTray | X | AVTray.exe | Part of the WinAntiVirus Pro 2005 rogue security software when installed in Win98/Me - not recommended, removal instructions here | No |
| Anti-Virus Update | X | avupdate.exe | Added by the TIOTUA-CO WORM! | No |
| Swf32 | X | AVupdate.exe | Added by the MERKUR.E WORM! | No |
| AVupdate32 Update | X | AVupdate32.exe | Added by the RBOT.CNI TROJAN! | No |
| Avupdater | X | AVupdater.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %AppData% | No |
| Antivirus Updates | X | avupdchk.exe | Added by the AGOBOT-IP WORM! | No |
| AntiVir XP | Y | AVwin.exe | AntiVir® PersonalEdition Classic - antivirus | No |
| AVWLPSTA | ? | AVWLPSTA.exe | PRISM Status Tray Applet - but what is it for and is it required? | No |
| AVWUpd32 | Y | AVWUPD32.EXE | AntiVir® PersonalEdition Classic - updater | No |
| avxlni | Y | avxinit.exe | Anti-virus part of BitDefender virus scanner/firewall | No |
| BullGuardInit | Y | AVXINIT.EXE | Part of Bullguard antivirus | No |
| Avxlive | Y | avxlive.exe | Bullguard or BitDefender antivirus | No |
| bitdefenderlive | Y | avxlive.exe | Main program of BitDefender virus scanner/firewall | No |
| BullGuard Update | U | avxlive.exe | Part of Bullguard antivirus. Leave enabled unless you manually update virus definitions | No |
| Photo | X | AV[random char]SEQ01.DAT.exe | Added by the NAMSALA TROJAN! | No |
| AV Security Essentials | X | AV[random].exe | AV Security Essentials rogue security software - not recommended, removal instructions here | No |
| Surs | X | awab.exe | PurityScan adware | No |
| Awatch | U | Awatch.exe | Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products | No |
| AwaySch | U | AwaySch.EXE | Part of the IBM ThinkVantage Productivity Center. "The Away Manager application allows you preselect and run routine tasks to maintain your system's performance" | No |
| Advanced SystemCare 3 | U | AWC.exe | Advanced SystemCare optimization utility from IObit - "has a one-click approach to help protect, repair, clean, and optimize your PC." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| AWC | U | AWC.exe | Advanced SystemCare optimization utility from IObit - "has a one-click approach to help protect, repair, clean, and optimize your PC." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| Advanced WindowsCare V2 Personal | U | Awcl.exe | Advanced WindowsCare V2 optimization utility from IObit - "helps protect, optimize, clean, and repair your computer and Registry". The PRO version adds automation, scheduling, registry deep clean and performance tune-ups. Note - runs via the Task Scheduler on Vista/7. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| Awcl | U | Awcl.exe | Advanced WindowsCare V2 optimization utility from IObit - "helps protect, optimize, clean, and repair your computer and Registry". The PRO version adds automation, scheduling, registry deep clean and performance tune-ups. Note - runs via the Task Scheduler on Vista/7. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| JA Config 32 | X | Awesome32.exe | Added by a variant of W32/Sdbot.worm | No |
| awhost32 | N | awhost32.exe | Part of Symantec's pcAnywhere remote PC management software. Provides an automatic startup of the client PC in host mode in conjuction with a host-definition file, so system administrators can access the machine. Can cause a 10% reduction in speed and not recommended | No |
| [various names] | X | awinrar.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| NAVAPW32 | X | AWKsxyeeX8h.exe | Added by the GBOT-I TROJAN! | No |
| AWM | U | AWM.exe | Advanced Wallpaper Manager from PUSH Software | No |
| awm | X | AWM.exe | AWM Antivirus rogue security software - not recommended, removal instructions here. Note - this is not the same as Advanced Wallpaper Manager from PUSH Software and is located in %AppData%\AWM | No |
| ActiveWords | N | AWMonitor.exe | ActiveWords from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in the background and watches as you type. When it recognizes that you've typed an ActiveWord, it takes the associated action, such as replacing your keystrokes with the text you've defined | No |
| Awola | X | Awola.exe | Awola rogue spyware remover - not recommended | No |
| Awola6 | X | Awola6.exe | Awola AntiSpyware 6.0 rogue spyware remover - not recommended, removal instructions here | No |
| awplite | U | awplite.exe | AllWallpapers Lite desktop wallpaper changer | No |
| AWUSGSTA | ? | AWUSGSTA.exe | Reportedly related to a USB Wifi Adapter - is it required at startup? | No |
| awxDTools | U | awxDTools.dll,awxRegisterDll | AwxDTools related - a Windows Shell-Extension for the Daemon-Tools. It extends the context-menu of ImageFiles supported by Daemon-Tools (i.e.: *.cue, *.iso, *.ccd ...) | No |
| ax.exe | X | ax.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\wina | No |
| axaa.exe | X | axaa.exe | Added by the MDROP-DRM TROJAN! | No |
| Alcohol Virtual Drive Auto-mount Service | N | AxAutoMntSrv.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present from version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| AlcoholAutomount | N | AxAutoMntSrv.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present from version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| AxAutoMntSrv | N | AxAutoMntSrv.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present from version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| Alcohol Soft Development Team | N | axcmd.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present prior to version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| AlcoholAutomount | N | axcmd.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present prior to version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| axcmd | N | axcmd.exe | Part of the Alcohol 52% and Alcohol 120% CD/DVD emulation utilities from Alcohol Soft - which allow you to store your most used CDs and DVDs as images on your computer (where loading times are significantly reduced as the virtual drive is much faster) and keep the originals in a safe place. This entry is present prior to version 2.* and automatically re-loads a disk image in the virtual CD/DVD drive on a system reboot | Yes |
| xcanxbwv | X | axcvqvzk.exe | Added by the RANDEX.AR WORM! | No |
| Vanyzim | X | axepis.exe | Added by the SDBOT.AXJ WORM! | No |
| (Default) | X | axeWen.exe | Added by the SCAR-AL WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| MSUpdateDevKit | X | axfd.exe | Added by the SDBOT-ZD WORM! | No |
| AXPDefender | X | AXPDefender.exe | Advanced XP Defender rogue security software - not recommended, removal instructions here | No |
| AXPFixer | X | AXPFixer.exe | AdvancedXPFixer rogue security software - not recommended, removal instructions here | No |
| ActiveX Update | X | AxUpdateMS.exe | Added by the BANKER-FIX TROJAN! | No |
| AXVenore | X | AXVenore.exe | Added by an unidentified malware | No |
| ayRmyfbCTPl | X | ayRmyfbCTPl.exe | Added by the FAKEAV-DTZ TROJAN! | No |
| AZOZ | X | az.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\Microsoft | No |
| Desktop Plant | N | AZARE10S.PLT | Vritual plant from here - this version is an Azalea, there are others so the filename may be different | No |
| azmodem | Y | azexe.exe | Aztech Labs modem driver | No |
| AzMixerSel | U | AzMixerSel.exe | Related to Realtek_Azalia Mixer Selector | No |
| azmjaweon | X | azmjaweon.exe | Security Shield rogue security software - not recommended, removal instructions here | No |
| RDFCNUQzMTAzNEFERDk0QT | X | azractm.exe | Detected by Sophos as Troj/DwnLdr-KFX and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Azureus Installer | N | Azureus-Installer.exe | Azureus Installer - free software that allows you to launch the setup of the Azureus (now Vuze) Bittorent client | No |
| Windows LoL Layer | X | azypbrx.exe | Added by the RBOT-GMZ WORM! | No |
| Microsoft Intell Management | X | A[3 numbers].exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData% | No |
| AMsnMonitor | U | A_MSN_Monitor.exe | Msn Chat Monitor & Sniffer by AwinSoft Inc - "is a handy network-control utility for capture and observe MSN chat conversations on all computers in network". Surveillance software - uninstall this software unless you put it there yourself | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |