| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
740 results found for B
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| b.exe | X | b.exe | Added by the SDBOT.BND WORM! | No |
| Mi7sft sdce | X | b0yz.exe | Added by the RBOT.CWG WORM! | No |
| ISUSPM STARTUP | X | B25135~1 | Detected by McAfee as W32/Ramnit.a | No |
| b357f652fdd7a1734e0c6bf1888108b6 | X | b357f652fdd7a1734e0c6bf1888108b6.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| b4ada7daa19b8b7f8c9d2810d3477ea5 | X | b4ada7daa19b8b7f8c9d2810d3477ea5.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| b4aOTB | U | b4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)" | Yes |
| Backup4all 3 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 3.* | Yes |
| Backup4all OTB Agent | U | b4aOTB.exe | Supports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)" | Yes |
| Backup4all Professional 4 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for Backup4all Professional. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.* | Yes |
| Backup4all Standard 4 OTB Agent | U | B4aOTB.exe | Supports the "one-touch" backup button on external hard drives for Backup4all Standard. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.* | Yes |
| System Service | X | b4db0yz.exe | Added by the RBOT-CLO WORM! | No |
| b5857819bb096c04134249d6f4e71934 | X | b5857819bb096c04134249d6f4e71934.exe | Detected by Dr.Web as Trojan.DownLoader7.3003 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| b5b3ee2ed23a8038ea5de5e1871ca463 | X | b5b3ee2ed23a8038ea5de5e1871ca463.exe | Detected by Dr.Web as Trojan.DownLoader8.24573 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| b5ef36bacffc0e6068630cae16e5a0c9 | X | b5ef36bacffc0e6068630cae16e5a0c9.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| b60511fd42ef6c7d1c6ac6218d09f059 | X | b60511fd42ef6c7d1c6ac6218d09f059.exe | Detected by Dr.Web as Trojan.DownLoader8.32059 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| 4Y3Y0C3AVF7W1VXDNTJTQ | X | B6232F3ABCC.exe | Detected by Malwarebytes Anti-Malware as Trojan.SpyEyes. The file is located in %Root%\Recycle.Bin | No |
| Netscape | X | B6BAFF.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. Loaded via the HKCU\..\Policies\Explorer\Run key, the file is located in %AppData% | No |
| b769a63eba6827200acac1af038bfb34 | X | b769a63eba6827200acac1af038bfb34.exe | Detected by Dr.Web as Trojan.DownLoader7.2082 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
| b7a6b3f1a13aae96b96b0c63d16d969c | X | b7a6b3f1a13aae96b96b0c63d16d969c.exe | Detected by Dr.Web as Trojan.DownLoader6.47225 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| 6IG7WSE42UU4 | X | B7MI2O4K.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| b9 | Y | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" | Yes |
| Firetrust Benign | Y | B9.exe | FireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run" | Yes |
| ba36334ad9883cdf49fcccd0d285d289 | X | ba36334ad9883cdf49fcccd0d285d289.exe | Detected by McAfee as RDN/Generic PWS.y!l and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| ba4c12bee3027d94da5c81db2d196bfd | X | ba4c12bee3027d94da5c81db2d196bfd.exe | Detected by Dr.Web as Trojan.DownLoader6.45251 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| ba4c12bee3027d94da5c81db2d196bfd | X | ba4c12bee3027d94da5c81db2d196bfd.exe | Detected by Dr.Web as Trojan.DownLoader7.24429 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| babe8364d0b44de2ea6e4bcccd70281e | X | babe8364d0b44de2ea6e4bcccd70281e.exe | Detected by McAfee as RDN/Generic PWS.y!lt and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| HKCU | X | baby.exe | Detected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System% | No |
| HKLM | X | baby.exe | Detected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System% | No |
| Policies | X | baby.exe | Detected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System% | No |
| Babylon Client | N | Babylon.exe | Core program for the Babylon translation and dictionary tool | No |
| Babylon Translator | N | Babylon.exe | Part of an older version of the Babylon translation and dictionary tool | No |
| BabylonToolbar | N | BabylonToolbarsrv.exe | Toolbar installed with the Babylon translation and dictionary tool | No |
| Back2zip | U | Back2zip.exe | Back2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed up | No |
| Services | X | back32.exe ...service.exe | Added by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe | No |
| Service | X | back32.exe service.exe | Detected by Symantec as Backdoor.IRC.Aladinz.H. Both files are located in %System%\CAB | No |
| [various names] | X | backd.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| notepad.exe | X | background.exe | Detected by Malwarebytes Anti-Malware as Trojan.Delf. The file is located in %LocalAppData% | No |
| BackgroundSwitcher | U | BackgroundSwitcher.exe | John's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interesting | No |
| [various names] | X | backorif.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Timed Backups Manager Startup | N | BACKTIME.EXE | Backup Plus - backup software | No |
| Display | X | backup.exe | Added by the BRONTOK-CR WORM! | No |
| System Service | X | backup.exe | Added by the PACKBOT.AA WORM! | No |
| Backup Service | X | backup.svc | Unidentified adware | No |
| Backup4all | U | Backup4all.exe | Backup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage" | Yes |
| Backup4all 3 | U | Backup4all.exe | Backup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage." Version 3.* | Yes |
| Backup4all Lite 4 | U | Backup4all.exe | Backup4all Lite by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
| Backup4all Professional 4 | U | Backup4all.exe | Backup4all Professional by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
| Backup4all Standard 4 | U | Backup4all.exe | Backup4all Standard by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.* | Yes |
| BackupManagerTray | ? | BackupManagerTray.exe | Acer Backup Manager, Packard Bell MyBackup and Gateway MyBackup - OEM backup software by NewTech Infosystems, Inc, makers of NTI Backup Now EZ and NTI Backup Now | No |
| BackupNotify | N | backupnotify.exe | System Tray "balloon" backup reminder for HP Image Zone Plus | No |
| BackupNowEZtray | U | BackupNowEZtray.exe | System Tray access to the Backup Now EZ backup utility from NTI Corporation | No |
| MSbackups | X | backups.exe | Added by the BANLOAD-TL TROJAN! | No |
| System Backup Services | X | backups32.exe | Added by a variant of Win32/Rbot | No |
| STO Backup Service | U | BackUpSvr.exe | Backup feature of Samsung's SmarThru Office - "a powerful document management application for Office users. It creates, stores and edits scan images, and delivers them to each application" | No |
| hp center | N | BackWeb-137903.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
| Updates from HP | N | BackWeb-137903.exe | Automatically detects an internet connection and downloads any available updates for HP PCs | No |
| Compaq Connections | N | BackWeb-1940576.exe | Automatically detects an internet connection and downloads any available updates for Compaq PCs along with messages and product offers | No |
| ActivSurf | N | backweb-4448364.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates | No |
| Kodak Software Updater | N | backWeb-7288971.exe | Software updater for Kodak products - automatically detects an internet connection and downloads any available updates | No |
| Data LifeGuard | N | backWeb-8263142.exe | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updates | No |
| backWeb-8876480 | N | backweb-8876480.exe | Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech | Yes |
| LDM | N | backweb-8876480.exe | Installed with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from Logitech | Yes |
| BackWeb | N | backweb.exe | Automatically detects an internet connection and downloads any available updates along with messages and product offers. Typical on Compaq and HP PC's but not restricted to those OEM's | No |
| HP Updates | N | backweb.exe | Automatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offers | No |
| Updates from HP | N | backweb.exe | Automatically detects an internet connection and downloads any available updates | No |
| Data LifeGuard | N | BACKWE~1.EXE | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updates | No |
| Backwork | N | Backwork.exe | Backwork trojan detector | No |
| BACPI10 | U | bacpi10a.exe | Known as "PowerKey" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system tray | No |
| BacsTray | N | BacsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems | No |
| SYS2 | X | bad1.exe | Added by the SILLYFDC-AP WORM! | No |
| SYS3 | X | bad2.exe | Added by the SILLYFDC-AP WORM! | No |
| SYS4 | X | bad3.exe | Added by the SILLYFDC-AP WORM! | No |
| BADDATE | X | BADDATE.EXE | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| good | X | badvir.exe | Added by the SILOV-B WORM! | No |
| [32 random hex numbers] | X | badware-protector.exe | Badware Protector rogue security software - not recommended, removal instructions here | No |
| Quicken Scheduled Updates | N | bagent.exe | Quicken background downloading module | No |
| Baigoo.exe | U | Baigoo.exe | Baigoo surveillance software. Uninstall this software unless you put it there yourself | No |
| Microsoft Personal Firewalls | X | bakw.exe | Added by the RBOT-KS WORM! | No |
| Ball | X | Ball.exe | Detected by Dr.Web as Trojan.DownLoader7.25886 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - the file is located in %Windir% and %UserStartup% and %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
| Windows Service Pack Auto Update | X | ballin.exe | Added by an unidentified WORM or TROJAN! | No |
| HorngTech4D | Y | bally4d.exe | HorngTech 4D mouse driver | No |
| WIN32SNDS | X | banc.exe | Added by an unidentified WORM or TROJAN! | No |
| Bandicam Crack | X | Bandicam Crack.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| Bandicam | X | Bandicam.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData% | No |
| bandmon | U | bandmon.exe | Rokario Bandwidth Monitor | No |
| Bandwidth Monitor Pro | U | Bandwidth Monitor Pro.exe | Bandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISP | No |
| Bandwidth Meter Pro | N | BandwidthMeterPro.exe | System Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time" | Yes |
| BandwidthMeterPro | N | BandwidthMeterPro.exe | System Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time" | Yes |
| AtariBanner | N | Banner.exe | Related to the Atari Anniversary Edition Volume 2 games collection from Infogrames | No |
| Banpopup by Pratik | U | Banpopup.exe | Banpopup - popup killer | No |
| bantool | X | bantool.exe | Malware installed by different rogue security software including SpyKillerPro | No |
| FUKLBAR | X | bar.exe | PurityScan adware | No |
| wow | X | bar.exe | PurityScan adware | No |
| bargains | X | bargainbuddy.exe | BargainBuddy adware | No |
| bargains | X | bargains.exe | BargainBuddy adware | No |
| BullsEye | X | bargains.exe | BargainBuddy adware | No |
| BullsEye Network | X | bargains.exe | BargainBuddy adware | No |
| [various names] | X | barint.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BaroSearch | X | barosearchs.exe | Detected by McAfee as Generic.tfr | No |
| BarTheme | X | bartent32.exe | Added by the AGOBOT-UG WORM! | No |
| bascstray | N | BascsTray.exe | Broadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problems | No |
| AntiVituS | X | Base.exe | Detected by Trend Micro as WORM_BAS.A | No |
| Windows Service Base | X | base.EXE | Detected by Sophos as Troj/VB-GLW and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| BasicPrivacy | X | BasicPrivacy.exe | BasicPrivacy rogue security software - not recommended, removal instructions here | No |
| BasicSafeMain | X | BasicSafe.exe | BasicSafe rogue security software - not recommended, removal instructions here | No |
| WinSetBrowse | X | BasicUpdate.dll.vbs | Added by the BISCUIT.A WORM! | No |
| type | X | bat.exe | Added by the ANSKYA-A WORM! | No |
| adobeupdate | X | bat99.bat | Detected by McAfee as Generic PUP.x and by Malwarebytes Anti-Malware as Trojan.BCMiner | No |
| adobeupdatess | X | bat99.bat | Detected by Malwarebytes Anti-Malware as Trojan.BCMiner. The file is located in %AppData%\Update | No |
| BatangIN | X | BatangIN.exe | Added by the DBOT-G MALWARE! | No |
| POS-Partnerbatchprocessor | ? | BATCH.EXE | VISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start → Programs or a manually created shortcut? | No |
| BATINDICATOR | U | BATINDICATOR.exe | Battery level indicator for the HP Mainstream Keyboard | No |
| [12 random characters] | X | batmeter.exe | IeDriver adware variant | No |
| Battery Scope | U | batmgr.exe | Monitors battery levels on a notebook/laptop PC | No |
| BatSrv | X | batserv2.exe | Added by the LOCKSKY.T WORM! | No |
| BatteryBar | U | batterybar.exe | BatteryBar - displays battery usage, and the current percentage of battery power left | No |
| Power Gear | U | BatteryLife.exe | ASUS Power4Gear power management utility for their notebooks | No |
| Power_Gear | U | BatteryLife.exe | ASUS Power4Gear power management utility for their notebooks | No |
| BatteryManager | U | BatteryManager.exe | Battery manager for Samsung laptops | No |
| batterymiser | Y | batterymiser.exe | Battery Miser power management utility for LG Notebooks | No |
| BatteryMiser 5 | Y | BatteryMiser5.exe | Battery Miser 5 power management utility for LG Notebooks | No |
| Critical Update Check | X | battlenet.exe | Detected by Sophos as Troj/Delf-LB | No |
| BatzBack | X | BatzBack.scr | Added by the BACKZAT WORM! | No |
| BAUSB | U | BAUSB.exe | Boston Acoustics Audio, USB driver | No |
| bawindo | X | bawindo.exe | Added by the BEAGLE.AR or BEAGLE.AU WORMS! | No |
| Bayswap | U | bayswap.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices | No |
| Generic Host Process for Win32 Services | X | bazzi.exe | Added by the AHKER.E WORM! | No |
| Microsoft AntiSpyware | X | Bazzi.exe | Detected by Trend Micro as WORM_AHKER.J | No |
| Win32 Service | X | bazzi.exe | Added by the AHKER.E WORM! | No |
| Best Antivirus Software | X | BA[random].exe | Best Antivirus Software rogue security software - not recommended, removal instructions here | No |
| upbb | X | bb.exe | Added by the SCAR.CLVU TROJAN! | No |
| bb02079412d1d28920dbb066871f104b | X | bb02079412d1d28920dbb066871f104b.exe | Detected by McAfee as RDN/Generic.tfr!a and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| LAUNCHQUICK | X | bbaka14.exe | Added by the DOWNLOADER-CJD TROJAN! | No |
| MSCJACCELERATOR | X | bbaka14.exe | Added by the DOWNLOADER-CJD TROJAN! | No |
| this free | X | bbb.exe | Added by the VB-DZG TROJAN! | No |
| 168b4aa5e3ad509936dadf65a297923f | X | bbbbbbbbb.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| HKCU | X | bbbbbbbbb.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDir | No |
| HKLM | X | bbbbbbbbb.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDir | No |
| BBC iPlayer Desktop | U | BBC iPlayer Desktop.exe | BBC iPlayer Desktop allows you to download your favourite shows from the last 30 days, watch them online or offline and automatically download future episodes | No |
| BBC Alerts | N | BBC_Alerts.exe | BBC Alerts - "You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service" | No |
| d3dupdate.exe | X | bbeagle.exe | Added by the BEAGLE.A WORM! | No |
| BBLauncher.exe | N | BBLauncher.exe | BounceBack Professional - back-up software | No |
| Bron-Spizaetus-cfgmktoq | X | bbm-qotkmgfc.exe | Added by the BRONTOK-M WORM! | No |
| Bron-Spizaetus-cfgmmnru | X | bbm-urnmmgfc.exe | Added by the BRONTOK-N WORM! | No |
| BBoxSearchBarOS | X | BBoxSearchBar.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\BomulBox\BBoxSearchBar | No |
| Kernel | X | bboy.exe | Detected by Microsoft as Worm:Win32/Mumu.A. The file is located in %windir% | No |
| BbPrintMonitor | U | BBPrint.exe | Printer support for PDF software from Bluebeam Software, Inc. What does it do and is it required? | No |
| gdagdgajs | X | bbsbw.exe | Added by the SDBOT-QX WORM! | No |
| MSN Messenger BETA 7 | X | bbsdf.exe | Added by the RANKY.AA TROJAN! | No |
| NetVideoNews | U | BBsee.exe | BBSee adware | No |
| Bb-Seg | X | BbSeg.exe | Detected by Sophos as Troj/Agent-JVW | No |
| bbSysTray | N | bbSysTray.exe | Philips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions" | No |
| bbui | U | bbui.exe | AOL DSL status monitor displaying a red/green icon indicating if you have a connection | No |
| Broadband Wizard | N | bbwiz.exe | Starts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start → Programs | No |
| bca | U | bca.exe | BeClean Agent - registry, history, temp files, etc cleaner | No |
| Microsoft Driver Setup | X | BCB.EXE | Detected by Avira as Worm/Kolab.eff | No |
| BCDetect | U | bcdetect.exe | Bcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and see | No |
| acdllib3 | X | bcdlmem.exe | Added by the MAILBOT-BA TROJAN! | No |
| bcm | X | bcm.exe | Detected by Kaspersky as Trojan.NSIS.Miner.a | No |
| USCService | U | BcmDeviceAndTaskStatusService.exe | Part of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution" | No |
| BCMDMMSG | Y | bcmdmmsg.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems | No |
| Broadcom Wireless Manager UI | U | bcmntray.exe | Related to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problems | No |
| BCMSMMSG | Y | BCMSMMSG.exe | BCM voicemodem driver. Required for dial-up if you have one of these modems | No |
| bcmwltry | ? | bcmwltry.exe | Broadcom Corporation Wireless Network Tray Applet. Is it required? | No |
| BCNT | N | bcnt.exe | AWS Weatherbug related. What does it do? | No |
| BCPC | X | bcpc.exe | Added by a variant of Adware.Broadcastpc | No |
| bcpc_c | X | bcpc_c.exe | Added by a variant of Adware.Broadcastpc | No |
| Breg | X | bcre.exe | Added by a variant of Adware.Broadcastpc | No |
| BCSSync | U | BCSSync.exe | Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see here | No |
| Microsoft Office 2010 | U | BCSSync.exe | Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see here | No |
| LoadDBackUp | X | BcTool.exe | Added by the GIBE WORM! | No |
| BCTweak | U | bctweak.exe | BlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settings | No |
| *1534741411 | X | BCU.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BSM. The file is located in %Windir%\1534741411 | No |
| BCU | N | BCU.exe | Browser Configuration Utility for Gigabyte motherboards by DeviceVM - which is "an easy-to-install, easy-to-use, powerful search engine." It sits in the Address Bar of IE6/7/8, allowing you to search for a string of characters - with the default search engine being Yandex (Russian), Baidu (Simplified Chinese) or Yahoo (for all others). May disrupt your preferred search engine | No |
| BCUpdate | U | BCUP.exe | BocaiToolbar adware | No |
| bcveim | X | bcveim.exe | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %UserProfile% | No |
| Bcvsrv32 | X | bcvsrv32.exe | Added by the GAOBOT.BQJ WORM! | No |
| BCWipeTM | N | BCWipeTM.exe | BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed | No |
| BCWipeTM Startup | N | BCWipeTM.exe | BCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when needed | No |
| Windows Computer Browser | X | bcwsvc.exe | Detected by Trend Micro as WORM_RBOT.JM | No |
| bd29411177661e07f018c457c7359458 | X | bd29411177661e07f018c457c7359458.exe | Detected by Dr.Web as Trojan.DownLoader8.37156 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| bd5fe50093d5f1ccb4a558c1e0ec7e5d | X | bd5fe50093d5f1ccb4a558c1e0ec7e5d.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| BDAgent | Y | bdagent.exe | BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
| BitDefender 2009 | Y | bdagent.exe | BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
| Intel | X | BDE3B7.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.H. The file is located in %AppData% | No |
| Taskman | X | bdepdf.exe | Added by the AGENT-OAP TROJAN! | No |
| b3d | X | BDEsecureinstall.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start → Settings → Control Panel → Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the "System" directory. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents | No |
| BitDefender Live! Init | Y | bdinit.exe | Part of older versions of BitDefender anti-malware products | No |
| kfgpeTkw | X | bDM5c2IZ.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\DXDMqcZS | No |
| BDMCon | Y | Bdmcon.exe | Part of older versions of BitDefender anti-malware products | No |
| BDNewsAgent | Y | bdnagent.exe | Part of older versions of BitDefender anti-malware products | No |
| BDOESRV | Y | bdoesrv.exe | Part of older versions of BitDefender anti-malware products | No |
| BDX | X | BDQX.EXE | Detected by Kaspersky as Backdoor.Win32.Hupigon.madj and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| C:\lanmao.exe | X | BDQX.EXE | Detected by Microsoft as Backdoor:Win32/Bigdipper.A and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| BDX | X | BDQX[random].EXE | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir% | No |
| ADOBEARM UPDATE | X | bds.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPT | No |
| bds32 | X | bds32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows starts | No |
| BitDefender Scan Server | Y | bdss.exe | Part of older versions of BitDefender anti-malware products | No |
| BDSwitchAgent | Y | bdswitch.exe | Part of older versions of BitDefender anti-malware products | No |
| BDWizReg | Y | bdwizreg.exe | Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-free | Yes |
| BitDefender 12 | Y | bdwizreg.exe | Configuration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-free | Yes |
| BEA Start | U | BEA.exe | Detected by Malwarebytes Anti-Malware as PUP.Ardamax. Remove unless you installed it yourself. The file is located in %CommonAppData%\BTURUS | No |
| bead739c11b6815884fb1a13a48ced96 | X | bead739c11b6815884fb1a13a48ced96.exe | Detected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| bead739c11b6815884fb1a13a48ced96 | X | bead739c11b6815884fb1a13a48ced96.exe | Detected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Bunx | X | beagle.exe | Added by the LEBREAT-E WORM! | No |
| BearFlix | U | BearFlix.exe | BearFlix is optimized for the fast download of video files | No |
| BearShare | N | bearshare.exe | BearShare file sharing client. Versions known to include spyware - see here | No |
| BeatNik Internet Clock | U | BeatNik.exe | BeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clock | No |
| Animated Wallpaper | U | Beautiful Fishing Lake.exe | Beautiful Fishing Lake animated desktop wallpaper from Desktop Animated | No |
| beautifulday | X | beautifulday.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuff | No |
| Animated Wallpaper | U | Beauty.exe | Beauty animated desktop wallpaper from Desktop Animated | No |
| bee0c4d45bcdd7deadce6b70f4861060 | X | bee0c4d45bcdd7deadce6b70f4861060.exe | Detected by Dr.Web as Trojan.DownLoader8.31864 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Beegees Update | X | beegees.exe | Added by the SDBOT-ADK WORM! | No |
| BEEI | ? | beei.exe | ?? | No |
| BeFaster | U | befaster3.exe | BeFaster internet connection optimization tool | No |
| BEHL | ? | BEHL.exe | ?? | No |
| BEHLO | ? | BEHLO.exe | ?? | No |
| beidsystemtray | U | beidsystemtray.exe | Related to Belgium Identity Card card reader | No |
| ASDPLUGIN | X | belgium_nm.exe | AsdPlug premium rate adult content dialer | No |
| Belkin Tray Application | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
| BelkinRouterMonitor | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
| InstaLAN | U | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software | Yes |
| Belkin F5D8013 N Wireless Notebook Card Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8013 N Wireless Notebook Card | No |
| Belkin F5D8053 N Wireless USB Adapter Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8053 N Wireless USB Adapter | No |
| Belkin F5D8073 N Wireless ExpressCard Adapter Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard Adapter | No |
| Belkin Wireless G Notebook Card Client Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D701F Wireless G Notebook Card | No |
| Belkin Wireless G USB Adapter Client Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
| Belkin Wireless Networking Utility | U | Belkinwcui.exe | Wireless configuration utility for some Belkin cards such as the F5D8053 N Wireless USB Adapter and F5D8051 N1 Wireless USB Adapter | No |
| Belkin Wireless USB Utility | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
| Belkin Wireless Utility | U | Belkinwcui.exe | Wireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop Card | No |
| F5D7050v3 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter | No |
| F5D8001 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card | No |
| F5D8011 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card | No |
| F5D8051v3 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8051 N1 Wireless USB Adapter | No |
| F5D8055v1 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter | No |
| F5D8055v2 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter | No |
| F5D8071 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard | No |
| F5D9010 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter | No |
| F5D9050 | U | Belkinwcui.exe | Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter | No |
| BellSouthAlertManager.exe | U | BellSouthAlertManager.exe | Related to BellSouth Alert Manager | No |
| BELORVBI | ? | BELORVBI.exe | ?? | No |
| Belsta.exe | ? | Belsta.exe | Configuration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed? | No |
| Belt | X | Belt.exe | VX2.Transponder parasite updater/installer related | No |
| Belvedere | U | Belvedere.exe | Belvedere "is designed to help support problem-based collaborative learning scenarios with concept and evidence moodels, and provides multiple representational views (tables and graphs) on those models" | No |
| Benadril Alert Tool | X | benadrilalert.exe | Plug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy Benadril | No |
| BengalsScreenServer | U | BengalsScreenServer.exe | Screensaver for the Cincinnati Bengals NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
| BackupExecScheduler | U | BESCH.EXE | Scheduler for Backup Exec data backup and recovery software from Symantec (formerly Veritas) | No |
| BestBoan | X | BestBoan.exe | BestBoan rogue security software - not recommended, removal instructions here | No |
| BestCrypt Auto Open | U | BestCrypt.exe | BestCrypt from Jetico, Inc. "Keeps your confidential data in a strongly encrypted form on your disk and provides you with transparent access" | No |
| BestPopUpKiller | X | BestPopupKiller.exe | Popup killer by Swanksoft - not recommended, see here | No |
| BestSync 2008 | U | BestSyncApp.exe | System Tray access to BestSync® 2008 from Risefly Software - "a professional utility for synchronizing files between your local folders and Network Drives, FTP servers, Removable Media (such as an USB disk)" | No |
| BeSys | X | BEsys.exe | BeSys adware | No |
| WINDOWS SYSTEM | X | beta.exe | Added by the MYTOB.DF WORM! | No |
| BullsEye Tracker | ? | BeTrack.exe | Bullseye - intelligent research assistant | No |
| BeyluxeMessenger | N | Beyluxe Messenger.exe | Beyluxe Messenger by Beyluxe Communication S.R - "is a free popular Internet voice and video Chat program used by millions of people, and thousands of organizations, to communicate, share, play and work with each other on the internet around the world" | No |
| System Config | X | BF3.EXE | Added by the SPYBOT-DT WORM! | No |
| BF4P | X | bf4p.exe | Detected by SUPERAntiSpyware as Trojan.BF4P.Process. The file is located in %System% | No |
| bf8feb67afc2238269222493247f1c23 | X | bf8feb67afc2238269222493247f1c23.exe | Detected by McAfee as Generic.dx!bh3h and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| load= | Y | Bfrecv.exe | Bitware modem driver | No |
| userinit | X | bfvkjs.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| BGInfo | U | Bginfo.exe | BGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and more | No |
| BGNewsAgent | Y | bgnewsag.exe | BullGuard antivirus updater | No |
| bgoomain.exe | X | bgoomain.exe | Baigoo.a malware | No |
| bgsmsnd | N | bgsmsnd.exe | Printer driver to generate PDF files from any program | No |
| BackgroundSwitcher | U | bgswitch.exe | Originally included with Microsoft's XP PowerToys (but now withdrawn - see here, Background Switcher allows your desktop background to periodically change | No |
| bgz0ueitgy | X | bgz0ueitgy.exe | Detected by Microsoft as Trojan:Win32/Scar.Q and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| MS32DLL | X | Bha.dll.vbs | Added by the BUTSUR-A WORM! | No |
| Browser Hijack Blaster | Y | bhblaster.exe | Browser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuard | No |
| MozillaIE | X | BHC.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %Windir% | No |
| BHOCop | N | BHOCop.exe | PC Magazine's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spyware | No |
| BHODemon 2.0 | U | BHODemon.exe | BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on demand | No |
| [various names] | X | bhoserv.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BHR | U | BHR.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| BHR2.1 | U | BHR2.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| BHR3.5 | U | BHR3.5.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| BHR3 | U | BHR3.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| BHR4.1 | U | BHR4.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| BHR4 | U | BHR4.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| Browser Help Svc | X | BHSV.EXE | Added by the RBOT-AVQ WORM! | No |
| BI1HelperStartUp | U | BI1Helper.exe | ScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| BI1HelperStartUp | U | BI1HEL~1.EXE | ScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| LTM2 | X | bible.exe | Added by the LITMUS.203 BACKDOOR! | No |
| [12 random characters] | X | bidispl2.exe | IeDriver adware variant | No |
| tvgvopah | X | bidjnbvf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %LocalAppData% | No |
| This is a virus, please delete it | X | bigbadvirus.exe | Added by the RANDEX.F WORM! | No |
| BigfileSearch | X | BigfileSearch.exe | BigfileSearch adware. File located in %ProgramFiles%\BigfileSearch | No |
| BigFix | N | bigfix.exe | BigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hog | Yes |
| BIG | X | biggy.exe | Added by the DELBOT-AG WORM! | No |
| biglow | X | biglow.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| bigoris | X | bigoris.exe | Added by the DORF-AZ TROJAN! | No |
| BigPondWirelessBroadbandCM | Y | BigPond_CM.exe | Telstra wireless broadband manager | No |
| Lastword | X | BiHNet.exe | Detected by ESET as Win32/Lastword | No |
| bikini | X | bikini.exe | Added by the LOWZONE-CX TROJAN! | No |
| Bilbulon | N | Bilbulon.exe | Bilbulon from EcoSoft - swaps text from Hebrew to another language and back. It helps correct typing mistakes which occur if you forget to switch to a different language before starting to type" | No |
| sysfbtray | X | bill102.exe | Added by the VB-ENI TROJAN! | No |
| sysfbtray | X | bill103.exe | Added by the MDROP-CLF TROJAN! | No |
| sysfbtray | X | bill104.exe | Added by the MDROP-CLO TROJAN! | No |
| sysfbtray | X | bill106.exe | Added by the MDROP-CLV TROJAN! | No |
| sysfbtray | X | bill108.exe | Added by the MDROP-CMW TROJAN! | No |
| sysfbtray | X | bill117.exe | Added by the VBKRYPT-E TROJAN! | No |
| TnPopUp | U | billbrz.exe | Related to Technesis "award-winning solutions for tracking and managing print, copy, fax and scan activities" | No |
| BillGatesLoh.exe | X | BillGatesLoh.exe | Added by the AGENT-FZO TROJAN! | No |
| Billminder | N | Billmind.exe | Can be setup in Quicken to remind user of due payments. Available via Start → Programs | No |
| Bimwoheuipuubaxt.exe | X | Bimwoheuipuubaxt.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %AppData% | No |
| Bin | X | Bin | Detected by McAfee as RDN/Generic.bfr!bg and by Malwarebytes Anti-Malware as Trojan.Agent.AI | No |
| bincdwsa | X | bincdwsa.exe | Added by the ONLINEGAMES.AKYF TROJAN! | No |
| Shareaza | U | bindata.exe | Shareaza P2P client related | No |
| Bing.exe | X | Bing.exe | Detected by McAfee as RDN/PWS-Banker and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| bingoolbar | X | bing.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp%\bingoolbar | No |
| BingDesktop | U | BingDesktop.exe | Bing Desktop by Microsoft - "With Bing Desktop, make the Bing homepage image your PC desktop wallpaper each day" | No |
| bingdian | X | Bingdian.vbs | Added by the BINGD WORM! | No |
| [various names] | X | bingo9.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BinHost | X | binhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Inject.AI. The file is located in %AllUsersProfile%\Start Menu\binhost | No |
| Bionix Wallpaper 5 | U | Bionix Wallpaper 5.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
| BioniXWallpaper | U | Bionix Wallpaper 5beta.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
| BioniXWallpaper | U | BioniX Wallper.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
| BioniXWallpaper | U | BionixWallpaper5.exe | BioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world" | No |
| bionli | X | bionli.exe | Detected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuff | No |
| 1340ee8cbc8bf1647b41ad0df8d12e5e | X | bios.exe | Detected by McAfee as Generic.dx!bhqs and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 2e81bcb95bfda6135350a9b94e22cde4 | X | bios.exe | Detected by McAfee as RDN/Generic.tfr!bs and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| bios | X | bios.exe | Detected by Sophos as Troj/Bancban-PW | No |
| BIOS1 | X | BIOS1.EXE | Added by the OPASERV.T WORM! | No |
| Bios | X | Bios32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Terminal Update | X | biosefui.exe | Added by the PPDOOR-O TROJAN! | No |
| BIOS Net Service | X | BIOSserv.exe | Added by the RBOT-BFL WORM! | No |
| BIOVCIP | ? | BIOVCIP.exe | ?? | No |
| BisonHK | ? | BisonHK.exe | Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required? | No |
| Media Adapter | X | bitblt.exe | Added by the HANSAH-A WORM! | No |
| Microsoft Explorer2 | X | bitchbot.exe | Added by the SDBOT.EV WORM! | No |
| BitCleanMain | X | BitClean.exe | BitClean rogue security software - not recommended, removal instructions here | No |
| BitComet | N | BitComet.exe | "BitComet is a BitTorrent/HTTP/FTP download management software, which is powerful, fast, very easy-to-use, and completely free" | No |
| BitDefender Antivirus | X | BITDEFENDERX.EXE | Added by a variant of the SPYBOT WORM! | No |
| BitDefender_P2P_Startup | U | BitDefender_P2P_Startup.exe | Bitdefender anti-virus for P2P clients - no longer supported at the BitDefender website | No |
| Microsoft Windows DLLHandler | X | bitpaint.exe | Added by the SDBOT.AHG WORM! | No |
| Background Intelligent Transfer Service | X | bits.exe | Detected by Dr.Web as Trojan.Inject.53759 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| MEVEMUJEQzQ2Q0NBMzdFQj | X | bitsmst.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile% | No |
| µTorrent | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Version 6.1 of BitTorrent is displayed as µTorrent in both Vista MSConfig & Windows Defender | Yes |
| BitTorrent | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads | Yes |
| Bittorrent | X | bittorrent.exe | Added by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir% | No |
| bittorrent.exe | N | bittorrent.exe | BitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads | Yes |
| biz_check_1_1 | X | biz_check_1_1.exe | Detected by McAfee as RDN/Generic.tfr!bf and by Malwarebytes Anti-Malware as Adware.K.Bizkeyword | No |
| BJLaunchEXE | U | BJLaunch.exe | Memory Card Utility for the Canon i470D, i475D and i905D photo printers - which allows "your computer to access the memory card reader feature of your printer" | No |
| MSConfig | X | bjld.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see here | No |
| bjmbmgr | X | bjmbmgr.exe | Added by the AGENT-TKD TROJAN! | No |
| Canon My Printer | U | BJMyPrt.exe | Printer software for Canon Bubblejet printers | No |
| CanonMyPrinter | U | BJMyPrt.exe | Printer software for Canon Bubblejet printers | No |
| Easy-PrintToolBox | U | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer | No |
| BkupTray | U | BkupTray.exe | System Tray access to the NTI Backup Now 5 backup utility from NTI Corporation | No |
| Supernova | X | Blaargh.exe | Detected by McAfee as W32/Supova.e.worm | No |
| Windows Services | X | BlaBhs.exe | Detected by Sophos as Mal/Agent-ACY and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| BlackArmorBackupMonitor.exe | N | BlackArmorBackupMonitor.exe | Part of Seagate BlackArmor Backup - their implementation of the Acronis True Image backup software for their BlackArmor range of external hard drives and Network Attached Storage (NAS). Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
| [12 random characters] | X | blackbox.exe | IeDriver adware variant | No |
| Black Box Helper | U | BlackBoxHelper.exe | Support for the M-Audio "Black Box" guitar processor and audio interface with guitar amp modelling, beat-synced effects and drum tracks for computer based recording | No |
| Task Manager | X | blackCoin.scr | Detected by Malwarebytes Anti-Malware as Worm.AutoRun. The file is located in %AppData% | No |
| LoadBlackD | Y | blackd.exe | "Intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when they acquired the NetworkICE parent but is no longer available. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| BlackICE PC Protection | N | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD | No |
| BlackIce Utility | N | blackice.exe | Loads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackD | No |
| STRINGS | X | BlackMilkProxy.exe | Detected by McAfee as RDN/Generic BackDoor | No |
| HKCU | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\install | No |
| HKLM | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\install | No |
| Policies | X | blackopsmod | Detected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\install | No |
| Razer Blackwidow Driver | U | BlackwidowTray.exe | Razer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Razer Blackwidow Driver | U | BlackWidowUltimateTray.exe | Razer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macros | No |
| Distributed File System | X | blade.exe | Added by the MYFIP.AC WORM! | No |
| blads | U | blads.exe | Ad blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| BlockAds | U | blads.exe | Ad blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| Microsoft machine | X | blah.exe | Added by a variant of Win32/Rbot | No |
| bldbubg | N | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system | No |
| BuildBU | N | bldbubg.exe | Part of Dell Alerts which provides customers with an update on latest updates for his/her system | No |
| Win32 Test | X | bleatest.exe | Added by the RBOT.AGJ WORM! | No |
| BLMessagingIntegration | X | blengine.exe | BuddyLinks adware | No |
| BLF | X | blf.exe | Added by the DELBOT-M WORM! | No |
| borzoi | U | blg.exe | Borzoi surveillance software. Uninstall this software unless you put it there yourself | No |
| ESPN BottomLine | N | bline.exe | ESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down." | No |
| [various names] | X | bling.exe | Added by the RBOT-NI WORM! | No |
| Microsoft Security Management | X | bling.exe | Added by the RBOT.XL WORM! | No |
| Microsoft Update | X | bling.exe | Added by the RBOT-AVK WORM! | No |
| Windows Executer | X | bling.exe | Added by the SDBOT-DFT WORM! | No |
| blinkx | U | blinkx.exe | Blinkx Desktop "Smart Folders" software | No |
| BlockChecker | X | Block-checker.exe | BlockChecker adware | No |
| BlockDefense | X | BlockDefense.exe | BlockDefense rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| Ad Blocker | U | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads | No |
| BlockKeeper | X | BlockKeeper.exe | BlockKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| BlockProtector.exe | X | BlockProtector.exe | BlockProtector rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| BlockScanner | X | BlockScanner.exe | BlockScanner rogue security software - not recommended. A member of the WiniGuard family | No |
| BlockTracker | N | BlockTracker.exe | If present on a HP machine it tracks all the processes and logs them to a blocklog.txt file | No |
| BlockWatcher | X | BlockWatcher.exe | BlockWatcher rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| mdssn | X | blog.exe | Detected by Dr.Web as Trojan.DownLoader7.5792 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| blsloader | U | blsloader.exe | BellSouth ISP Internet Tools | No |
| spc_w | N | blspc.exe | NetZero Search Enhancement related | No |
| blss | X | blss.exe | Added by the BLARUL TROJAN! | No |
| BLSTAPP | N | blstapp.exe | Puts access to Creative's BlasterControl in the System Tray | No |
| Blubster | N | Blubster.exe | Related to Blubster Music sharing service | No |
| BbInstallUser | ? | Bluebeam Admin User.exe | Related to PDF software from Bluebeam Software, Inc. What does it do and is it required? | No |
| Bluecol | X | bluecol.exe | Added by the CRYPTER.A TROJAN! | No |
| Blue Frog | U | bluefrog.exe | Blue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receive | No |
| BlueSoleil | U | BLUESO~1.EXE | BlueSoleil Bluetooth wireless manager from IVT Corporation | No |
| BlueSpace NE | U | BlueSpaceNE.exe | "BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter". Shortcut available via Start → Programs | No |
| Bluetooth.exe | X | Bluetooth.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and here | No |
| Windows LoL Layer | X | blvpnmcny.exe | Added by the RBOT-GOR WORM! | No |
| bm | X | bm.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples | No |
| BMN | X | bm.exe | Part of VirtualPCGuard, VirusGuardPlus and other members of the AVSystemCare family of rogue security software suites. See here for more examples | No |
| Salestart | X | bm.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples | No |
| Bman | X | BMan1.exe | Added by a variant of Adware.DealHelper | No |
| BookmarkCentral | N | BMLauncher.exe | Bookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use". No longer available | No |
| BMMLREF | N | BMMLREF.EXE | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" status | Yes |
| BMMLREF.EXE | N | BMMLREF.EXE | Part of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" status | Yes |
| Bmonq | X | bmonq.exe | Added by the CLICKER.HZ TROJAN! | No |
| Casdvqwa | X | bmqnzkg.exe | Added by the RANDEX.BE WORM! | No |
| Buzme | N | Bmui.exe | Buzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modem | No |
| BMupdate | N | BMupdate.exe | Related to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-install | No |
| bmw | X | bmw.exe | Detected by Trend Micro as BKDR_AGOBOT.BBV | No |
| bmz | X | bmz.exe | 180Search adware | No |
| Bndt32 | X | Bndt32.exe | Added by the LACON WORM! | No |
| Microsoft Update | X | bnmveqfts.exe | Added by the BANLOAD.KWQ TROJAN! | No |
| [various names] | X | bnui.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BO1HelperStartUp | U | Bo1helper.exe | ScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| BO1HelperStartUp | U | BO1HEL~1.EXE | ScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30! | No |
| Boan119 | X | Boan119.exe | Boan119 rogue security software - not recommended, removal instructions here | No |
| BoanCatch | X | BoanCatch.exe | BoanCatch rogue security software - not recommended, removal instructions here | No |
| BoanClear | X | BoanClear.exe | BoanClear rogue security software - not recommended, removal instructions here | No |
| BoanCode | X | BoanCode.exe | BoanCode rogue security software - not recommended, removal instructions here | No |
| BoanCop | X | BoanCop.exe | BoanCop rogue security software - not recommended, removal instructions here | No |
| boanguide | X | boanguide_up.exe | BoanGuide rogue security software - not recommended, removal instructions here | No |
| boanking | X | boankingrun.exe | BoanKing rogue security software - not recommended, removal instructions here | No |
| boankorea | X | boankorearun.exe | BoanKorea rogue security software - not recommended, removal instructions here | No |
| BoanN | X | BoanN.exe | BoanN rogue security software - not recommended, removal instructions here | No |
| BoanPack 3.0 | X | BoanPack.exe | Detected by McAfee as Generic FakeAlert and by Malwarebytes Anti-Malware as Adware.BoanPack | No |
| boanplus | X | boanplusrun.exe | BoanPlus rogue security software - not recommended, removal instructions here | No |
| BoanPro | X | BoanPro.exe | BoanPro rogue security software - not recommended, removal instructions here | No |
| BoanShield | X | BoanShield.exe | BoanShield rogue security software - not recommended, removal instructions here | No |
| BoanSupport | X | BoanSupport.exe | BoanSupport rogue security software - not recommended, removal instructions here | No |
| BoanTab | X | BoanTab.exe | BoanTab rogue security software - not recommended, removal instructions here | No |
| boaqaa | X | boaqaa.exe | Detected by Malwarebytes Anti-Malware as Trojan.LVBP. The file is located in %UserProfile% | No |
| Windefender | X | Boat.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData% | No |
| boat32 | X | boat32.exe | Added by a variant of Win32/Rbot | No |
| BOC-412 | Y | BOC412.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.12 | No |
| BOC-420 | Y | BOC420.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.20 | No |
| BOC-421 | Y | BOC421.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.21 | No |
| BOC-422 | Y | BOC422.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.22 | No |
| BOC-423 | Y | BOC423.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.23 | No |
| BOC-424 | Y | BOC424.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.24 | No |
| BOC-425 | Y | BOC425.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.25 | No |
| BOC-426 | Y | BOC426.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.26 | No |
| BOC-427 | Y | BOC427.exe | Comodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.27 | No |
| BOCleanautostart | Y | Boclean.exe | NSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters" | No |
| Caddais BackupOnDemand | U | BODMon.exe | Caddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location" | No |
| bofkyfkovirz | X | bofkyfkovirz.exe | Detected by McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| bofux | X | bofux.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| [various names] | X | Bogobot.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BoincLogX | U | boinclogx.exe | BoincLgx "makes it possible to log and show information about your processed WUs. In addition to a general log file which supports all BOINC projects, it will create project specific log files with detailed information about the WUs and results of some projects like SETI@home, Einstein@Home and AstroPulse." Add-on for the Boinc project | No |
| BOINC Manager | U | boincmgr.exe | BOINC manager - "controls the use of your computer's disk, network, and processor resources" | No |
| bolenja | X | bolenja.exe | Detected by Total Defense as Wantvi BF. The file is located in %System% | No |
| bolenjx | X | bolenjx.exe | Detected by Total Defense as Eldycow O. The file is located in %System% | No |
| sysftray2 | X | bolivar19.exe | Added by the KOOBFACE.I WORM! | No |
| Rase | X | boln.exe | PurityScan adware | No |
| MSConfig | X | bolvcvjo.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| bombshel | U | BOMB32.EXE | Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems | No |
| bomba | X | bomba.exe | Detected by Dr.Web as Trojan.Siggen3.27560. The file is located in %Windir% | No |
| bomba | X | bomba.exe | Detected by Dr.Web as Trojan.MulDrop3.58666. The file is located in %System% | No |
| BomulBox | X | BomulBoxC.exe | Detected by AVG as OpenShopper.D and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\BomulBox | No |
| ABBYY Screenshot Reader Bonus | N | Bonus.ScreenshotReader.exe | Bonus version of the ABBYY Screenshot Reader utility available to users with registered versions of ABBYY FineReader and ABBYY PDF Transformer. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
| ABBYY Screenshot Reader Retail | N | Bonus.ScreenshotReader.exe | ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
| Bonus.SSR.FR10 | N | Bonus.ScreenshotReader.exe | Bonus version of the ABBYY Screenshot Reader utility available to registered users of ABBYY FineReader version 10. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' | No |
| BonusCash | X | BonusCash.exe | Detected by Microsoft as Adware:Win32/Bonuscash and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| BonziBUDDY | X | BonziBDY.EXE | BonziBuddy adware - see here for removal instructions | No |
| boo | X | boo.exe | Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN! | No |
| Bookmark | U | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" | Yes |
| Bookmark.exe | U | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" | Yes |
| BoontyBox | X | BoontyBox.exe | BoontyBox - "the ultimate jukebox software for your games. This free software is the best way to discover, download, launch and buy video games for your PC." Before Nexway acquired Boonty and discontinued the download the privacy policy used to state that amongst other thing they shared payment information with third parties - see here | No |
| Auslogics BoostSpeed | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed system optimization utility - which allows you to "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
| Auslogics BoostSpeed 4 | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
| BoostSpeed | U | boostspeed.exe | System Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" | Yes |
| 6acce2d1e36340ed5fc49a2c6e178f71 | X | boot.exe | Detected by McAfee as RDN/Generic PWS.y!js and by Malwarebytes Anti-Malware as Trojan.Agent.SC | No |
| boot | X | boot.exe | Added by the PUPPET-A TROJAN! Located in the %System% | No |
| Boot | U | Boot.exe | Part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". Located in Acer\Empowering Technology\ePower | No |
| Font | X | boot.exe | Added by the AGENT-LZW TROJAN! | No |
| HKCU | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\Microsoft | No |
| HKLM | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\Microsoft | No |
| Policies | X | Boot.tmp | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\Microsoft | No |
| MS-DOS Boot Service | X | Boot32.pif | Added by the RBOT-AMF WORM! | No |
| bootcareS | X | bootcareU.exe | BootCare rogue security software - not recommended, removal instructions here. One of the OneScan family of rogue scanner programs | No |
| ccExecute | X | bootcfg1.exe | Added by the NEMSI-B VIRUS! | No |
| explorer | X | bootcfgx.exe | Detected by Panda as Banbra.GQU | No |
| SecurePCSolutionsBootCheck | U | BootCheck.exe | 1 Click Fixer PLUS from Secure PC Solutions "takes the guesswork out of locating and solving problems in the Windows registry" | No |
| Boot Check | X | bootchk.exe | Added by the DELBOT-AB WORM! | No |
| Boot Client | X | bootcli.exe | Added by the IRCBOT-ACF BACKDOOR! | No |
| Internat Conf | X | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here | No |
| OS Boot Configuration! | X | bootconf.exe | CoolWebSearch BootConf adware | No |
| sysPnP | X | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here | No |
| Boot Config | X | bootconfig.exe | Added by the FLOOD-EV TROJAN! | No |
| Confg | X | bootconfig.exe | Added by the VB-ERB WORM! | No |
| OS Boot Configuration | X | bootconfig.exe | Detected by Trend Micro as WORM_IRCBOT.HJ | No |
| BootCTRL | X | bootctrl.exe | Added by an unidentified WORM or TROJAN! | No |
| explores | X | BootEx.exe | Added by the VB-DWI WORM! | No |
| Microsoft Patch Update | X | bootini.exe | Added by the RBOT-FMN WORM! | No |
| Microsoft Windows | X | bootini.exe | Added by the VANEBOT-K WORM! | No |
| Boot K | X | bootk.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| xbtl | U | bootldr.exe | WinSession Logger surveillance software - remove unless you installed it yourself! | No |
| OS Boot Load | X | bootload.exe | Added by the SLENFBOT.GB WORM! | No |
| BootLoader | X | BootLoader.exe.vbs | Added by the WATERWORKS WORM! | No |
| MicroUpdate | X | Bootmgr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System% | No |
| Boot Manager | X | bootmng.exe | Added by the SDBOT.APK WORM! | No |
| bootpd.exe | X | bootpd.exe | Added by the AGENT-DT TROJAN! | No |
| Boot Resource Library | X | bootres.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Templates% | No |
| Microsoft Word | X | BootSector.exe | Added by a variant of the AGOBOT WORM! | No |
| Boot Server | X | bootserver.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Boot Service | X | bootservice.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| BootSkin | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
| BootSkin Randomizer | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
| BootSkin Startup Jobs | U | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page | Yes |
| bootstrap | X | bootstrap.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\intelx86 | No |
| BootStatus | U | BOOTST~1.EXE | Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resources | No |
| Boot Service | X | bootsv.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| Boot Verify | X | bootvfy.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| winservices | X | bootvfy.exe | Added by the VB.AMX TROJAN! | No |
| [12 random characters] | X | bootvid2.exe | IeDriver adware variant | No |
| [12 random characters] | X | bootvid4.exe | IeDriver adware variant | No |
| Bootvrfy | X | bootvrfy.exe | Detected by Malwarebytes Anti-Malware as Worm.Texbot. The file is located in %Windir% | No |
| BootWarn | U | BootWarn.exe | Used to warn the end-user that they must reboot their PC when using older versions of Norton AntiVirus in those cases where a reboot did not happen after installation or a significant software update via LiveUpdate. See the AnswersThatWork entry for a more detailed description | Yes |
| Windows Update Manager | X | bootwiz.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System% | No |
| word pair | X | bopotsvr.exe | Added by the SHED-A TROJAN! | No |
| [various names] | X | borlandg.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| boromarl | X | boromarl.exe | Detected by McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| boromarl2 | X | boromarl.exe | Detected by McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| BOS | X | bos.exe | Detected by Microsoft as Trojan:Win32/LockScreen.CI and by Malwarebytes Anti-Malware as Trojan.LockScreen | No |
| Boss Key | U | bosskey.exe | Boss Key from Mindgems Inc - "will hide and restore the windows (programs) on your screen with the press of a hotkey or a mouse shortcut" | No |
| Boston | ? | Boston.exe | Part of the Boston Acoustics USB speaker systems. What does it do and is it required? | No |
| Crow | X | bot.exe | Detected by McAfee as Generic.tfr!bi and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| Google Update | X | bot.exe | Added by the AGENT-UDF TROJAN! | No |
| gost | X | bot.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Microsoft Synchronization Manager | X | bot.exe | Added by the SDBOT.IH WORM! | No |
| svchost | X | bot.exe | Detected by McAfee as Generic.dx!bdwj and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Windows Defender | X | Bot.exe | Detected by Dr.Web as Trojan.DownLoader8.17510 and by Malwarebytes Anti-Malware as Backdoor.BlackshadesNET | No |
| winsockdriver | X | bot.exe | Added by the WARPIGS-D WORM! | No |
| Microsoft Update | X | Botnet.exe | Added by the RBOT.AFL WORM! | No |
| Microsoft Updates | X | Botnet.exe | Detected by Trend Micro as WORM_RBOT.YS and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Configuration Loader | X | botss.exe | Added by the SDBOT-XS WORM! | No |
| WINDOWS SYSTEM | X | botzor.exe | Detected by McAfee as W32/Zotob.worm | No |
| Gseries | X | boulze.exe | Detected by Trend Micro as WORM_SDBOT.BJL and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Bouncer RunStartup | X | bouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here | No |
| [various names] | X | BoundRec.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Windows Protectot | X | boxide.exe | Added by a variant of the WOOTBOT WORM! | No |
| Boxore Client | X | boxore.exe | Detected by Malwarebytes Anti-Malware as Adware.Boxore. The file is located in %ProgramFiles%\Boxore\BoxoreClient | No |
| RVP | X | bpc.exe | Detected by Symantec as Adware.Broadcastpc | No |
| BPCv2_re | X | bpc2_re_inst.exe | Added by a variant of Adware.Broadcastpc | No |
| BigPondCable | N | bpcable.exe | Telstra Bigpond Cable login software - can be started manually | No |
| bpcpost.exe | U | bpcpost.exe | MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it | No |
| BPCV2 | X | BPCV2.exe | Detected by Symantec as Adware.Broadcastpc | No |
| BulletProof FTP Server | N | bpftpserver.exe | BulletProof FTP Server | No |
| BPK | U | bpk.exe | Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! The file is typically located in %ProgramFiles%\Perfect Keylogger Lite or %ProgramFiles%\BPK | No |
| bpk | X | bpk.exe | Detected by Sophos as Troj/SCLog-AK. The file is located in %System% | No |
| Major Microsoft Windows Driver Boot loader | X | bpool.exe | Added by the MYTOB.AJ WORM! | No |
| ContinueInstall | X | bpsinstall.exe | BrowserAid/BrowserPal foistware | No |
| Breg | X | bptre.exe | Added by a variant of Adware.Broadcastpc | No |
| Backpack UDF | N | bpudfmon.exe | Backpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW disk | No |
| BigPond Toolbar | U | bpumTray.exe | Telstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier" | No |
| rrmso | X | bqhrmug.exe | Detected by Sophos as Troj/Agent-GYY | No |
| bqjaon | X | bqjaon.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile% | No |
| Google Chrome | X | BQP531G0P6.exe | Detected by Dr.Web as Trojan.DownLoader6.14623. Note - this is not a legitimate Google Chrome browser file | No |
| BQTray.exe | U | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually | No |
| BurnQuick Queue | N | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually | No |
| BisonInst0402 | Y | BR040286.exe | Driver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal Eye | No |
| [various names] | X | br0ken.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Tok-Cirrhatus-1464 | X | br3951on.exe | Detected by Trend Micro as WORM_BRONTOK.AD | No |
| Tok-Cirrhatus-1959 | X | br4941on.exe | Detected by Sophos as W32/Brontok-J | No |
| Tok-Cirrhatus-2454 | X | br5931on.exe | Detected by Trend Micro as WORM_BRONTOK.AD | No |
| Tok-Cirrhatus-2784 | X | br6591on.exe | Detected by Sophos as W32/Brontok-L | No |
| Brasil | X | Brasil.exe | Added by the OPASERV.P WORM! | No |
| BrasilOld | X | Brasil.exe | Added by the OPASERV.P WORM! | No |
| Brasil | X | Brasil.pif | Added by the OPASERV.E WORM! | No |
| brastk | X | brastk.exe | Added by the DORF-BV TROJAN! | No |
| BraveSentry | X | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here | No |
| Brave-Sentry | X | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here | No |
| braviax | X | braviax.exe | Added by the FAKEALER.LE TROJAN! | No |
| ControlCenter2.0 | N | brctrcen.exe | Brother scanner 'Control Center' application - can be started manually | No |
| ControlCenter3 | N | brctrcen.exe | Brother scanner 'Control Center' application - can be started manually | No |
| Driver Control Manager v3.2 | X | brdevet.exe | Added by the AUTORUN-BHS WORM! | No |
| Break_Reminder | U | BREAK REMINDER.exe | Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here | No |
| Break.exe Espanha | X | Break.exe | Added by an unidentified TROJAN! See here | No |
| WinUpdateB | X | breatle.exe | Added by the BRATLE.AWORM! | No |
| Breg | X | breg.exe | Detected by Symantec as Adware.Broadcastpc | No |
| tbrena | X | brenasa.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Azbreg. The file is located in %Root%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-14699 | No |
| ObjectDock | X | Brico.cmd | Added by the BOBANDY-A WORM! | No |
| Adobe Bridge CS5 | N | Bridge.exe | Adobe Bridge - part of Adobe CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
| AdobeBridge | N | Bridge.exe | Adobe Bridge - part of Adobe CS4 and CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
| Bridge | N | Bridge.exe | Adobe Bridge - part of Adobe CS4 and CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access" | Yes |
| bridge | X | bridge.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Whitechix | X | brightx.exe | Added by a variant of W32/Sdbot.worm | No |
| windows | X | Brinks.exe | Added by the AGENT-TOA TROJAN! | No |
| Brindys BriTray | Y | BRITRAY.EXE | Main process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desired | No |
| xBrotherMeCom | ? | BrMeCom.exe | Related to Brother MFC-9200c printer. What does it do and is it required? | No |
| Status Monitor | N | BrMfcWnd.exe | Brother scanner status monitor - can be started manually | No |
| BrmfRmPA | U | BrmfRmPA.exe | Brother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicate | No |
| BrO_AcT | X | BrO-AcT.exe | Added by the SILLYFDC-D WORM! | No |
| Broadbandadvisor | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
| Broadbandadvisor.exe | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
| Virgin Broadband advisor | Y | Broadbandadvisor.exe | Virgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | Yes |
| BroadCamRun | N | broadCam.exe | BroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphone | No |
| ChromeUpdate | X | brocats.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile% | No |
| [various names] | X | Brong32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Bron-Spizaetus | X | bronstab.exe | Added by the RONTOKBRO.C WORM! | No |
| BRoNToK | X | BRoNToK.exe | Detected by Sophos as W32/Brontok-CG | No |
| BrownsScreenServer | U | BrownsScreenServer.exe | Screensaver for the Cleveland Browns NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported | No |
| browser | X | browse.exe | Added by the TACTSLAY.C TROJAN! | No |
| cpl | X | browse.exe | Added by the TACTSLAY.C TROJAN! | No |
| httpd | X | browse.exe | Added by the TACTSLAY.C TROJAN! | No |
| Messanger | X | browse.exe | Added by the TACTSLAY.C TROJAN! | No |
| StartMenu | X | browse.exe | Added by the DROWSY-C TROJAN! | No |
| [various names] | X | browsebar.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| BHR 1.1 | U | BROWSER HIJACK RETALIATOR 1.1.exe | Browser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supported | No |
| Windows Browser Services | X | browser128.exe | Added by the SLENFBOT.GN WORM! | No |
| Windows Browser Services | X | browser32.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| [12 random characters] | X | browser5.exe | IeDriver adware variant | No |
| Windows Browser Services | X | browser64.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| [12 random characters] | X | browser8.exe | IeDriver adware variant | No |
| browser aid | X | browseraid.exe | BrowserAid/BrowserPal foistware | No |
| BrowserChoice | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
| Microsoft Browser Choice | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
| Microsoft® Windows® Operating System | N | browserchoice.exe | In the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more information | Yes |
| Browser Sentinel | U | BrowserSentinel.exe | Browser Sentinel - notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home page | No |
| Windows Browser Services | X | Browsr32.exe | Added by the IRCBOT.BUR BACKDOOR! | No |
| Windows Browser Services | X | browsr64.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| System | X | BrO_AcT.exe | Added by the SILLYFDC-AL WORM! | No |
| wupdate | X | bro_exe.exe | Added by the DELF.GR TROJAN! | No |
| BDRegion | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times | Yes |
| brs | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times | Yes |
| cyberlink brs | U | brs.exe | Part of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 times | Yes |
| SetDefPrt | N | BrStDvPt.exe | Used to set a Brother MFC printer/copier/scanner as the default printer after installation | No |
| java | X | BRTXEJJTWR4.exe | Detected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData% | No |
| Microsoft Browser Services | X | Brwsr32.exe | Added by the SLENFBOT.FT WORM! | No |
| Microsoft Browser Services | X | Brwsr64.exe | Added by a variant of the SLENFBOT.FT WORM! | No |
| Tok-Cirrhatus-[4 random digits] | X | br[4 random digits]on.exe | Detected by Sophos as W32/Brontok-M | No |
| winupdate | X | BS-Test1-nofud.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| windows | X | bsade.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData% | No |
| BSBALL.exe | X | BSBALL.exe | Added by the VB-ZS MALWARE! | No |
| Microsoft Services | X | bsc32.exe | Detected by Sophos as Troj/Bdoor-AW | No |
| BsCLiP | N | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required | No |
| B'sCLiP | N | BSCLIP.exe | CD recording utility that comes with a lot of CDR/CDRW drives and isn't required | No |
| Bsearch | X | bsearch.exe | Detected by Symantec as Download.Adware and by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\barosearch | No |
| BearShare Lite | N | BSHARELITE.EXE | BearShare Lite (now replaced by BearShare 10) peer-to-peer (P2P) file-sharing client. As with any P2P client which is used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads | No |
| Microsoft Driver Setup | X | BSmBT.exe | Detected by Avira as Worm/Kolab.ehp | No |
| BsMnt | ? | BsMnt.exe | Related to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required? | No |
| Microsoft Driver Setup | X | BSoBT.exe | Detected by Avira as Worm/Kolab.eil | No |
| Blue_Screen_of_Death | X | bsod.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\bsod.exe | No |
| Bsoft lppt01 | X | Bsoft.exe | RapidBlaster variant (in a "BelmontSoft" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| BS Player | N | bsplayer.exe | BSplayer - A video player used to play avi, mpg, wmv and other multimedia files | No |
| bsplayer | N | bsplayer.exe | BSplayer - a video player used to play avi, mpg, wmv and other multimedia files | No |
| BS Mediaplayer | X | bsplyr.exe | Added by the RBOT-OU WORM! | No |
| Bsqbhzkzykzdvwja.exe | X | Bsqbhzkzykzdvwja.exe | Detected by Sophos as W32/Dorkbot-EQ | No |
| Bsqxitat | X | Bsqxita.exe | Added by the AUTORUN-BDL WORM! | No |
| symanteccsysconf | X | bsyys.scr | Added by the VACILL-A WORM! | No |
| SymantecFilterCheck | X | bsyys.scr | Added by the BANLOAD.DZC TROJAN! | No |
| bs_stealth | X | bs_stealth.exe | Detected by Dr.Web as Trojan.DownLoader6.4398 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| BBDial | ? | BT Broadband.exe | Part of BT Broandband - is it required? | No |
| BitTorrent DNA | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
| btdna | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
| btdna.exe | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
| DNA | N | btdna.exe | "BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNA | Yes |
| btbb_McciTrayApp | N | BTHelpNotifier.exe | System tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not required | No |
| Motive SmartBridge | N | BTHelpNotifier.exe | System tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not required | No |
| [12 random characters] | X | bthserv1.exe | IeDriver adware variant | No |
| btinst | ? | btinst.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? | No |
| BTModemProtection | U | BTModemProtection.exe | BT Privacy Online modem protection software, see here | No |
| btmsre.exe | X | btmsre.exe | Detected by Trend Micro as WORM_SDBOT.AM | No |
| LoadBtnHnd | U | BtnHnd.exe | Fujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock input | No |
| Director Video | X | btnmgern.exe | Added by the MYTOB-KL WORM! | No |
| ATI Video Driver Control | X | btorrent.exe | Added by the RBOT.BLL BACKDOOR! | No |
| Trap Wired Coordinator SSDP Protection | X | btraogb.exe | Detected by McAfee as Downloader.a!dch and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| f73cdc8ee94e | X | btsendto.exe | Associated with mysearchnow.com/searchbar.html | No |
| BTSETBOOTKEY | ? | BTSetBootKey.exe | Related to a USB Bluetooth adaptor. What does it do and is it required? | No |
| BTSETBOOTKEY | ? | BTSetBootKey.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) | No |
| BTStacFrr | X | BTStacFrr.exe | Added by the BANCOS.AAI TROJAN! | No |
| BTStacLrj | X | BTStacLrj.exe | Added by the BANCOS.AAI TROJAN! | No |
| BTStacPgn | X | BTStacPgn.exe | Added by the BANCOS.AAI TROJAN! | No |
| BtStart | U | btstart.exe | Broadcom (formerly WIDCOMM) Bluetooth Connectivity Software | No |
| Button Server | U | bttnserv.exe | Found on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't required | No |
| BtTray | U | BtTray.exe | Part of the Bluetooth implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. Note - during testing, other than the System Tray icon included as part of the Windows OS this appeared to add no additional icon. Given this it is still recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled. Loads via the HKLM\Run registry key | Yes |
| BTTray | U | BTTray.exe | System tray icon which shows the status of a Bluetooth wireless module from WIDCOMM, Inc (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) and loads via %AllUsersStartup% | Yes |
| BTUSRBDG | Y | BtUsrBdg.exe | Used with a Mitsumi USB Bluetooth adaptor (and maybe others) | No |
| BTV | X | btv.exe | Detected by Symantec as Adware.Broadcastpc | No |
| BtvC | X | btvclean.exe | Detected by Symantec as Adware.Broadcastpc | No |
| AtherosBtStack | U | BtvStack.exe | Older version of the Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
| Bluetooth Software | U | BtvStack.exe | Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
| BtvStack | U | BtvStack.exe | Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled | Yes |
| btwdins.exe | X | btwdins.exe | Added by the AUTORUN-ML WORM! Note - this is not the valid Widcomm/Broadcom Bluetooth file with the same name which is typically located in %ProgramFiles%\WIDCOMM\Bluetooth Software. This one is located in %System%\drivers | No |
| Bluetooth Config | X | btwindin32.exe | Added by the SDBOT-DFN WORM! | No |
| Bubble | Y | Bubble.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyState | Yes |
| Windows SteadyState - Bubble Messages | Y | Bubble.exe | Part of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyState | Yes |
| Buddyizer | N | Buddyizer.exe | Part of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger network | No |
| Buddy Search | X | BuddySetup.exe | Detected by Microsoft as Adware:Win32/Nbar and by Malwarebytes Anti-Malware as Adware.BuddySearch. The file is located in %ProgramFiles%\Buddy Search | No |
| BudgetSip | N | BudgetSip.exe | BudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| budspencer | X | budspencer.exe | Detected by McAfee as Generic MSIL.t and by Malwarebytes Anti-Malware as Trojan.Clicker.Gen | No |
| SysMain | X | buff.exe | Added by the AGENT-ECW TROJAN! | No |
| System Buffer Application | X | buffer32.exe | Added by the SDBOT-UD WORM! | No |
| BugDoctor | X | BugDoctor.exe | Bug Doctor rogue security software - not recommended, removal instructions here | No |
| bugwatcher service | U | bugwatcher.exe | Bugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failures | No |
| Bug Eliminator | N | Bug_Elim.exe | Bug Eliminator - "performs a complete health check on your computer safely, securely, and silently!" | No |
| bui.exe | X | bui.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Builder | X | Builder.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.SB. The file is located in %ProgramFiles%\Microsoft.NET | No |
| bulirizkonyd | X | bulirizkonyd.exe | Detected by McAfee as RDN/Downloader.a!f and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| bulk | X | bulk.exe | Added by the AGOBOT-ACR WORM! | No |
| BullguardoptIn | Y | bulldownload.exe | Part of Bullguard antivirus | No |
| bg | Y | bullguard.exe | Bullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and Grokster | No |
| BullGuard | Y | BullGuard.exe | Part of BullGuard antivirus | No |
| msg | X | Bun.bat | Added by the NUB-A WORM! | No |
| SAHBundle | X | bundle.exe | ShopAtHomeSelect parasite | No |
| VBundleOuterDL | X | BundleOuter.EXE | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here | No |
| buritos | X | buritos.exe | Identified as a variant of the Downloader.FraudLoad.C malware | No |
| System settings | X | burndl32.exe | Added by the SDBOT-ZO WORM! | No |
| Rakyat_Miskin | X | Buruh.exe | Added by the SILLYFDC.BDM WORM! | No |
| Scan Wizard | ? | button.exe | Associated with Scan Wizard as supplied with Microtek scanners - see also the "Scanner Detector" and "Sdetect" entries. What does it do and is it required? | No |
| ButtonGuide | X | ButtonGuideC.exe | Detected by Symantec as Adware.OpenShopper and by Malwarebytes Anti-Malware as Adware.ButtonGuide. The file is located in %ProgramFiles%\ButtonGuide | No |
| ButtonKey | N | ButtonKey.exe | CyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcut | No |
| ButtonMonitor | U | ButtonMonitor.exe | Button support utility for some products from Verbatim - probably for their range of desktop and portable hard drives, see here. Located in %ProgramFiles%\Verbatim | No |
| Gateway Photo Frame | N | ButtonMonitor.exe | Supports the "Photo Frame" button on selected Gateway models such as the DX4300. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Gateway Photo Frame | No |
| Packard Bell Photo Frame | N | ButtonMonitor.exe | Supports the "Photo Frame" button on selected Packard Bell models such as the iExtreme. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Packard Bell Photo Frame | No |
| Smart Copy | U | ButtonMonitor.exe | Button support utility for some products from I/O Interconnect - probably for their range of removable storage devices, see here. Located in %ProgramFiles%\IOI\Smart Copy | No |
| Windows Defender | X | buy.exe | Detected by Dr.Web as Trojan.AVKill.5830 and by Malwarebytes Anti-Malware as Trojan.Agent.Gen | No |
| Buzof | U | buzof.exe | Buzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes" | No |
| RNBc Test | X | bvldv32.exe | Added by the RBOT-AJF WORM! | No |
| SysScan | X | bvt.exe | Added by the AUTOUPDER TROJAN! | No |
| BVWORSFM | X | bvworsfm.exe | Added by the DLUCA-AD TROJAN! | No |
| Best Virus Protection | X | BV[random].exe | Best Virus Protection rogue security software - not recommended, removal instructions here | No |
| XupiterCfgLoader | X | BWCfgLoader.exe | Xupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the future | No |
| BitWare Print Monitor | N | bwprnmon.exe | Print monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRO | No |
| bwprnmon.exe | N | bwprnmon.exe | Print monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRO | No |
| Service Connection | N | bwtray.exe | For Compaq PC's. Part of Backweb | No |
| oeplugin | U | bxOEPlugin.exe | noHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple text | No |
| bxproxy | X | bxproxy.exe | Detected by Trend Micro as BKDR_AGENT.AIW | No |
| Boost XP Service | U | bxservice.exe | Boost XP from Systweak - WinXP tweaking utility | No |
| Windows Live Messenger | X | bxZLovvPECTRHTQNarw.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData% | No |
| byssetebidbi | X | byssetebidbi.exe | Detected by McAfee as BackDoor-FAGP!71303927D4A0 and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| ByteDefender | X | ByteDefender.exe | ByteDefender rogue security software - not recommended, removal instructions here | No |
| byzjanpaxnod | X | byzjanpaxnod.exe | Detected by Malwarebytes Anti-Malware as Trojan.Cutwail. The file is located in %UserProfile% | No |
| Backblaze | U | bzbui.exe | Backblaze online backup utility for businesses | No |
| BZEnvironmentVariableCollector | ? | BZEnvironmentVariableCollector.exe | Part of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships". What does it do and is it required? | No |
| Health Credential Audio Config Portable | X | bzgyfcbsoq.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.HCA. The file is located in %System% | No |
| bZmq0AK16YY | X | bZmq0AK16YY.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts | No |
| BZUtilizationCollector | ? | BZUtilizationCollector.exe | Part of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships". What does it do and is it required? | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |