Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

740 results found for B

Startup Item or Name Status Command or Data Description Tested
b.exeXb.exeAdded by the SDBOT.BND WORM!No
Mi7sft sdceXb0yz.exeAdded by the RBOT.CWG WORM!No
ISUSPM STARTUPXB25135~1Detected by McAfee as W32/Ramnit.aNo
b357f652fdd7a1734e0c6bf1888108b6Xb357f652fdd7a1734e0c6bf1888108b6.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
b4ada7daa19b8b7f8c9d2810d3477ea5Xb4ada7daa19b8b7f8c9d2810d3477ea5.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
b4aOTBUb4aOTB.exeSupports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)"Yes
Backup4all 3 OTB AgentUB4aOTB.exeSupports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 3.*Yes
Backup4all OTB AgentUb4aOTB.exeSupports the "one-touch" backup button on external hard drives for versions of Backup4all that support this feature. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)"Yes
Backup4all Professional 4 OTB AgentUB4aOTB.exeSupports the "one-touch" backup button on external hard drives for Backup4all Professional. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.*Yes
Backup4all Standard 4 OTB AgentUB4aOTB.exeSupports the "one-touch" backup button on external hard drives for Backup4all Standard. "Some USB enclosures have a button to start the execution of an associated program. If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)." Version 4.*Yes
System ServiceXb4db0yz.exeAdded by the RBOT-CLO WORM!No
b5857819bb096c04134249d6f4e71934Xb5857819bb096c04134249d6f4e71934.exeDetected by Dr.Web as Trojan.DownLoader7.3003 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
b5b3ee2ed23a8038ea5de5e1871ca463Xb5b3ee2ed23a8038ea5de5e1871ca463.exeDetected by Dr.Web as Trojan.DownLoader8.24573 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
b5ef36bacffc0e6068630cae16e5a0c9Xb5ef36bacffc0e6068630cae16e5a0c9.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
b60511fd42ef6c7d1c6ac6218d09f059Xb60511fd42ef6c7d1c6ac6218d09f059.exeDetected by Dr.Web as Trojan.DownLoader8.32059 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
4Y3Y0C3AVF7W1VXDNTJTQXB6232F3ABCC.exeDetected by Malwarebytes Anti-Malware as Trojan.SpyEyes. The file is located in %Root%\Recycle.BinNo
NetscapeXB6BAFF.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. Loaded via the HKCU\..\Policies\Explorer\Run key, the file is located in %AppData%No
b769a63eba6827200acac1af038bfb34Xb769a63eba6827200acac1af038bfb34.exeDetected by Dr.Web as Trojan.DownLoader7.2082 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
b7a6b3f1a13aae96b96b0c63d16d969cXb7a6b3f1a13aae96b96b0c63d16d969c.exeDetected by Dr.Web as Trojan.DownLoader6.47225 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
6IG7WSE42UU4XB7MI2O4K.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
b9YB9.exeFireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"Yes
Firetrust BenignYB9.exeFireTrust Benign - allows you to receive e-mail which is safe from viruses, worms, scripts, web bugs, privacy threats and other security risks, without affecting your e-mail. "Benign neutralizes or strips out the code that makes viruses, worms, scripts and other potentially harmful things run"Yes
ba36334ad9883cdf49fcccd0d285d289Xba36334ad9883cdf49fcccd0d285d289.exeDetected by McAfee as RDN/Generic PWS.y!l and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ba4c12bee3027d94da5c81db2d196bfdXba4c12bee3027d94da5c81db2d196bfd.exeDetected by Dr.Web as Trojan.DownLoader6.45251 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ba4c12bee3027d94da5c81db2d196bfdXba4c12bee3027d94da5c81db2d196bfd.exeDetected by Dr.Web as Trojan.DownLoader7.24429 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
babe8364d0b44de2ea6e4bcccd70281eXbabe8364d0b44de2ea6e4bcccd70281e.exeDetected by McAfee as RDN/Generic PWS.y!lt and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
HKCUXbaby.exeDetected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System%No
HKLMXbaby.exeDetected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System%No
PoliciesXbaby.exeDetected by Malwarebytes Anti-Malware as Trojan.Picture. The file is located in %System%No
Babylon ClientNBabylon.exeCore program for the Babylon translation and dictionary toolNo
Babylon TranslatorNBabylon.exePart of an older version of the Babylon translation and dictionary toolNo
BabylonToolbarNBabylonToolbarsrv.exeToolbar installed with the Babylon translation and dictionary toolNo
Back2zipUBack2zip.exeBack2zip is a simple and elegant backup solution which uses the industry's most powerful ZIP and ZIP-64 technologies to constantly monitor your documents and make sure that they are always properly backed upNo
ServicesXback32.exe ...service.exeAdded by an unidentified VIRUS, WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exeNo
ServiceXback32.exe service.exeDetected by Symantec as Backdoor.IRC.Aladinz.H. Both files are located in %System%\CABNo
[various names]Xbackd.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
notepad.exeXbackground.exeDetected by Malwarebytes Anti-Malware as Trojan.Delf. The file is located in %LocalAppData%No
BackgroundSwitcherUBackgroundSwitcher.exeJohn's Background Switcher (or JBS for short) periodically changes the background image on your computer (like every hour or every day) to something interestingNo
[various names]Xbackorif.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Timed Backups Manager StartupNBACKTIME.EXEBackup Plus - backup softwareNo
DisplayXbackup.exeAdded by the BRONTOK-CR WORM!No
System ServiceXbackup.exeAdded by the PACKBOT.AA WORM!No
Backup ServiceXbackup.svcUnidentified adwareNo
Backup4allUBackup4all.exeBackup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage"Yes
Backup4all 3UBackup4all.exeBackup4all by Softland SRL - "is a backup program for Windows that protects your data from partial or total loss. It automates the backup process saving you time, compresses the data to save storage space (using standard zip format) and encrypts your backup to protect from unauthorized usage." Version 3.*Yes
Backup4all Lite 4UBackup4all.exeBackup4all Lite by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.*Yes
Backup4all Professional 4UBackup4all.exeBackup4all Professional by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.*Yes
Backup4all Standard 4UBackup4all.exeBackup4all Standard by Softland SRL - is a backup program for Windows that is "designed to protect your valuable data from partial or total loss by automating backup tasks, password protecting and compressing it to save storage space." Version 4.*Yes
BackupManagerTray?BackupManagerTray.exeAcer Backup Manager, Packard Bell MyBackup and Gateway MyBackup - OEM backup software by NewTech Infosystems, Inc, makers of NTI Backup Now EZ and NTI Backup NowNo
BackupNotifyNbackupnotify.exeSystem Tray "balloon" backup reminder for HP Image Zone PlusNo
BackupNowEZtrayUBackupNowEZtray.exeSystem Tray access to the Backup Now EZ backup utility from NTI CorporationNo
MSbackupsXbackups.exeAdded by the BANLOAD-TL TROJAN!No
System Backup ServicesXbackups32.exeAdded by a variant of Win32/RbotNo
STO Backup ServiceUBackUpSvr.exeBackup feature of Samsung's SmarThru Office - "a powerful document management application for Office users. It creates, stores and edits scan images, and delivers them to each application"No
hp centerNBackWeb-137903.exeAutomatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offersNo
Updates from HPNBackWeb-137903.exeAutomatically detects an internet connection and downloads any available updates for HP PCsNo
Compaq ConnectionsNBackWeb-1940576.exeAutomatically detects an internet connection and downloads any available updates for Compaq PCs along with messages and product offersNo
ActivSurfNbackweb-4448364.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updatesNo
Kodak Software UpdaterNbackWeb-7288971.exeSoftware updater for Kodak products - automatically detects an internet connection and downloads any available updatesNo
Data LifeGuardNbackWeb-8263142.exePart of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updatesNo
backWeb-8876480Nbackweb-8876480.exeInstalled with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from LogitechYes
LDMNbackweb-8876480.exeInstalled with older versions of the software for Logitech products. Automatically checks for software upgrades and new products, services and special offers from LogitechYes
BackWebNbackweb.exeAutomatically detects an internet connection and downloads any available updates along with messages and product offers. Typical on Compaq and HP PC's but not restricted to those OEM'sNo
HP UpdatesNbackweb.exeAutomatically detects an internet connection and downloads any available updates for HP PCs along with messages and product offersNo
Updates from HPNbackweb.exeAutomatically detects an internet connection and downloads any available updatesNo
Data LifeGuardNBACKWE~1.EXEPart of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives - automatically detects an internet connection and downloads any available updatesNo
BackworkNBackwork.exeBackwork trojan detectorNo
BACPI10Ubacpi10a.exeKnown as "PowerKey" - a minimalist keyboard driver that allows power management keys on BTC keyboards to function properly in older OS's (i.e. Win9x/NT4). Also adds an icon to the system trayNo
BacsTrayNBacsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problemsNo
SYS2Xbad1.exeAdded by the SILLYFDC-AP WORM!No
SYS3Xbad2.exeAdded by the SILLYFDC-AP WORM!No
SYS4Xbad3.exeAdded by the SILLYFDC-AP WORM!No
BADDATEXBADDATE.EXEAdded by an unidentified VIRUS, WORM or TROJAN!No
goodXbadvir.exeAdded by the SILOV-B WORM!No
[32 random hex numbers]Xbadware-protector.exeBadware Protector rogue security software - not recommended, removal instructions hereNo
Quicken Scheduled UpdatesNbagent.exeQuicken background downloading moduleNo
Baigoo.exeUBaigoo.exeBaigoo surveillance software. Uninstall this software unless you put it there yourselfNo
Microsoft Personal FirewallsXbakw.exeAdded by the RBOT-KS WORM!No
BallXBall.exeDetected by Dr.Web as Trojan.DownLoader7.25886 and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - the file is located in %Windir% and %UserStartup% and %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
Windows Service Pack Auto UpdateXballin.exeAdded by an unidentified WORM or TROJAN!No
HorngTech4DYbally4d.exeHorngTech 4D mouse driverNo
WIN32SNDSXbanc.exeAdded by an unidentified WORM or TROJAN!No
Bandicam CrackXBandicam Crack.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
BandicamXBandicam.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %AppData%No
bandmonUbandmon.exeRokario Bandwidth MonitorNo
Bandwidth Monitor ProUBandwidth Monitor Pro.exeBandwidth Monitor Pro - utililty to track your current download/upload limit that may be set by your ISPNo
Bandwidth Meter ProNBandwidthMeterPro.exeSystem Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"Yes
BandwidthMeterProNBandwidthMeterPro.exeSystem Tray access to Bandwidth Meter Pro - "an easy-to-use network software for bandwidth usage monitoring and reporting. It monitors traffic of all network connections on your computer and displays graphical and numerical download and upload speeds in real-time"Yes
AtariBannerNBanner.exeRelated to the Atari Anniversary Edition Volume 2 games collection from InfogramesNo
Banpopup by PratikUBanpopup.exeBanpopup - popup killerNo
bantoolXbantool.exeMalware installed by different rogue security software including SpyKillerProNo
FUKLBARXbar.exePurityScan adwareNo
wowXbar.exePurityScan adwareNo
bargainsXbargainbuddy.exeBargainBuddy adwareNo
bargainsXbargains.exeBargainBuddy adwareNo
BullsEyeXbargains.exeBargainBuddy adwareNo
BullsEye NetworkXbargains.exeBargainBuddy adwareNo
[various names]Xbarint.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BaroSearchXbarosearchs.exeDetected by McAfee as Generic.tfrNo
BarThemeXbartent32.exeAdded by the AGOBOT-UG WORM!No
bascstrayNBascsTray.exeBroadcom Advanced Control Suite - for modems and set top boxes based upon Broadcom chipsets. Not required unless you have networking problemsNo
AntiVituSXBase.exeDetected by Trend Micro as WORM_BAS.ANo
Windows Service BaseXbase.EXEDetected by Sophos as Troj/VB-GLW and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
BasicPrivacyXBasicPrivacy.exeBasicPrivacy rogue security software - not recommended, removal instructions hereNo
BasicSafeMainXBasicSafe.exeBasicSafe rogue security software - not recommended, removal instructions hereNo
WinSetBrowseXBasicUpdate.dll.vbsAdded by the BISCUIT.A WORM!No
typeXbat.exeAdded by the ANSKYA-A WORM!No
adobeupdateXbat99.batDetected by McAfee as Generic PUP.x and by Malwarebytes Anti-Malware as Trojan.BCMinerNo
adobeupdatessXbat99.batDetected by Malwarebytes Anti-Malware as Trojan.BCMiner. The file is located in %AppData%\UpdateNo
BatangINXBatangIN.exeAdded by the DBOT-G MALWARE!No
POS-Partnerbatchprocessor?BATCH.EXEVISA credit card batch processing related to Appcon. Is it needed or can it be started manually via Start → Programs or a manually created shortcut?No
BATINDICATORUBATINDICATOR.exeBattery level indicator for the HP Mainstream KeyboardNo
[12 random characters]Xbatmeter.exeIeDriver adware variantNo
Battery ScopeUbatmgr.exeMonitors battery levels on a notebook/laptop PCNo
BatSrvXbatserv2.exeAdded by the LOCKSKY.T WORM!No
BatteryBarUbatterybar.exeBatteryBar - displays battery usage, and the current percentage of battery power leftNo
Power GearUBatteryLife.exeASUS Power4Gear power management utility for their notebooksNo
Power_GearUBatteryLife.exeASUS Power4Gear power management utility for their notebooksNo
BatteryManagerUBatteryManager.exeBattery manager for Samsung laptopsNo
batterymiserYbatterymiser.exeBattery Miser power management utility for LG NotebooksNo
BatteryMiser 5YBatteryMiser5.exeBattery Miser 5 power management utility for LG NotebooksNo
Critical Update CheckXbattlenet.exeDetected by Sophos as Troj/Delf-LBNo
BatzBackXBatzBack.scrAdded by the BACKZAT WORM!No
BAUSBUBAUSB.exeBoston Acoustics Audio, USB driverNo
bawindoXbawindo.exeAdded by the BEAGLE.AR or BEAGLE.AU WORMS!No
BayswapUbayswap.exeHot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devicesNo
Generic Host Process for Win32 ServicesXbazzi.exeAdded by the AHKER.E WORM!No
Microsoft AntiSpywareXBazzi.exeDetected by Trend Micro as WORM_AHKER.JNo
Win32 ServiceXbazzi.exeAdded by the AHKER.E WORM!No
Best Antivirus SoftwareXBA[random].exeBest Antivirus Software rogue security software - not recommended, removal instructions hereNo
upbbXbb.exeAdded by the SCAR.CLVU TROJAN!No
bb02079412d1d28920dbb066871f104bXbb02079412d1d28920dbb066871f104b.exeDetected by McAfee as RDN/Generic.tfr!a and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
LAUNCHQUICKXbbaka14.exeAdded by the DOWNLOADER-CJD TROJAN!No
MSCJACCELERATORXbbaka14.exeAdded by the DOWNLOADER-CJD TROJAN!No
this freeXbbb.exeAdded by the VB-DZG TROJAN!No
168b4aa5e3ad509936dadf65a297923fXbbbbbbbbb.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
HKCUXbbbbbbbbb.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
HKLMXbbbbbbbbb.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
BBC iPlayer DesktopUBBC iPlayer Desktop.exeBBC iPlayer Desktop allows you to download your favourite shows from the last 30 days, watch them online or offline and automatically download future episodesNo
BBC AlertsNBBC_Alerts.exeBBC Alerts - "You can now have all the latest news and sports headlines delivered straight to your desktop with the new BBC Alerts service"No
d3dupdate.exeXbbeagle.exeAdded by the BEAGLE.A WORM!No
BBLauncher.exeNBBLauncher.exeBounceBack Professional - back-up softwareNo
Bron-Spizaetus-cfgmktoqXbbm-qotkmgfc.exeAdded by the BRONTOK-M WORM!No
Bron-Spizaetus-cfgmmnruXbbm-urnmmgfc.exeAdded by the BRONTOK-N WORM!No
BBoxSearchBarOSXBBoxSearchBar.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\BomulBox\BBoxSearchBarNo
KernelXbboy.exeDetected by Microsoft as Worm:Win32/Mumu.A. The file is located in %windir%No
BbPrintMonitorUBBPrint.exePrinter support for PDF software from Bluebeam Software, Inc. What does it do and is it required?No
gdagdgajsXbbsbw.exeAdded by the SDBOT-QX WORM!No
MSN Messenger BETA 7Xbbsdf.exeAdded by the RANKY.AA TROJAN!No
NetVideoNewsUBBsee.exeBBSee adwareNo
Bb-SegXBbSeg.exeDetected by Sophos as Troj/Agent-JVWNo
bbSysTrayNbbSysTray.exePhilips CD-RW related - "the 'Blue Button' feature gives users the chance to receive convenient online support for their possible device problems or questions"No
bbuiUbbui.exeAOL DSL status monitor displaying a red/green icon indicating if you have a connectionNo
Broadband WizardNbbwiz.exeStarts Broadband Wizard so it runs in the System Tray. This application tests and optimizes your Cable or DSL connection. Available via Start → ProgramsNo
bcaUbca.exeBeClean Agent - registry, history, temp files, etc cleanerNo
Microsoft Driver SetupXBCB.EXEDetected by Avira as Worm/Kolab.effNo
BCDetectUbcdetect.exeBcdetect.exe searches the system to make sure Creative drivers are installed for the video card. It loads the BlasterControl when the drivers are detected. Your choice - try it and seeNo
acdllib3Xbcdlmem.exeAdded by the MAILBOT-BA TROJAN!No
bcmXbcm.exeDetected by Kaspersky as Trojan.NSIS.Miner.aNo
USCServiceUBcmDeviceAndTaskStatusService.exePart of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution"No
BCMDMMSGYbcmdmmsg.exeBCM voicemodem driver. Required for dial-up if you have one of these modemsNo
Broadcom Wireless Manager UIUbcmntray.exeRelated to Broadcom Network Adapters for additional configuration options for these devices. Should not be terminated unless suspected to be causing problemsNo
BCMSMMSGYBCMSMMSG.exeBCM voicemodem driver. Required for dial-up if you have one of these modemsNo
bcmwltry?bcmwltry.exeBroadcom Corporation Wireless Network Tray Applet. Is it required?No
BCNTNbcnt.exeAWS Weatherbug related. What does it do?No
BCPCXbcpc.exeAdded by a variant of Adware.BroadcastpcNo
bcpc_cXbcpc_c.exeAdded by a variant of Adware.BroadcastpcNo
BregXbcre.exeAdded by a variant of Adware.BroadcastpcNo
BCSSyncUBCSSync.exePart of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see hereNo
Microsoft Office 2010UBCSSync.exePart of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. "Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances." For more information - see hereNo
LoadDBackUpXBcTool.exeAdded by the GIBE WORM!No
BCTweakUbctweak.exeBlasterControl for Creative video cards - controls for desktop settings, monitor configuration, colour adjustments and performance tuning. May be needed to retain settingsNo
*1534741411XBCU.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.BSM. The file is located in %Windir%\1534741411No
BCUNBCU.exeBrowser Configuration Utility for Gigabyte motherboards by DeviceVM - which is "an easy-to-install, easy-to-use, powerful search engine." It sits in the Address Bar of IE6/7/8, allowing you to search for a string of characters - with the default search engine being Yandex (Russian), Baidu (Simplified Chinese) or Yahoo (for all others). May disrupt your preferred search engineNo
BCUpdateUBCUP.exeBocaiToolbar adwareNo
bcveimXbcveim.exeDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %UserProfile%No
Bcvsrv32Xbcvsrv32.exeAdded by the GAOBOT.BQJ WORM!No
BCWipeTMNBCWipeTM.exeBCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when neededNo
BCWipeTM StartupNBCWipeTM.exeBCWipe Task Manager - scheduler for BCWipe so that it runs at convenient times. You can set a time for running the task, as well as special options for the task. Run manually when neededNo
Windows Computer BrowserXbcwsvc.exeDetected by Trend Micro as WORM_RBOT.JMNo
bd29411177661e07f018c457c7359458Xbd29411177661e07f018c457c7359458.exeDetected by Dr.Web as Trojan.DownLoader8.37156 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
bd5fe50093d5f1ccb4a558c1e0ec7e5dXbd5fe50093d5f1ccb4a558c1e0ec7e5d.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
BDAgentYbdagent.exeBitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYes
BitDefender 2009Ybdagent.exeBitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either "Manual" or "Automatic". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYes
IntelXBDE3B7.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.H. The file is located in %AppData%No
TaskmanXbdepdf.exeAdded by the AGENT-OAP TROJAN!No
b3dXBDEsecureinstall.exeB3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start → Settings → Control Panel → Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in the "System" directory. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contentsNo
BitDefender Live! InitYbdinit.exePart of older versions of BitDefender anti-malware productsNo
kfgpeTkwXbDM5c2IZ.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\DXDMqcZSNo
BDMConYBdmcon.exePart of older versions of BitDefender anti-malware productsNo
BDNewsAgentYbdnagent.exePart of older versions of BitDefender anti-malware productsNo
BDOESRVYbdoesrv.exePart of older versions of BitDefender anti-malware productsNo
BDXXBDQX.EXEDetected by Kaspersky as Backdoor.Win32.Hupigon.madj and by Malwarebytes Anti-Malware as Backdoor.AgentNo
C:\lanmao.exeXBDQX.EXEDetected by Microsoft as Backdoor:Win32/Bigdipper.A and by Malwarebytes Anti-Malware as Trojan.AgentNo
BDXXBDQX[random].EXEDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%No
ADOBEARM UPDATEXbds.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPTNo
bds32Xbds32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
BitDefender Scan ServerYbdss.exePart of older versions of BitDefender anti-malware productsNo
BDSwitchAgentYbdswitch.exePart of older versions of BitDefender anti-malware productsNo
BDWizRegYbdwizreg.exeConfiguration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-freeYes
BitDefender 12Ybdwizreg.exeConfiguration wizard for BitDefender internet security products. Only runs once the product has been installed. Guides you through the steps necessary to configure the BitDefender modules, applies settings to cover your requirements and security needs and takes the first actions to making your computer virus-freeYes
BEA StartUBEA.exeDetected by Malwarebytes Anti-Malware as PUP.Ardamax. Remove unless you installed it yourself. The file is located in %CommonAppData%\BTURUSNo
bead739c11b6815884fb1a13a48ced96Xbead739c11b6815884fb1a13a48ced96.exeDetected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
bead739c11b6815884fb1a13a48ced96Xbead739c11b6815884fb1a13a48ced96.exeDetected by Dr.Web as Trojan.DownLoader7.9439 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
BunxXbeagle.exeAdded by the LEBREAT-E WORM!No
BearFlixUBearFlix.exeBearFlix is optimized for the fast download of video filesNo
BearShareNbearshare.exeBearShare file sharing client. Versions known to include spyware - see hereNo
BeatNik Internet ClockUBeatNik.exeBeatNik Internet Clock is a Windows clock add-on that supports 'skins'. It can also synchronize your computer's clock with an atomic clockNo
Animated WallpaperUBeautiful Fishing Lake.exeBeautiful Fishing Lake animated desktop wallpaper from Desktop AnimatedNo
beautifuldayXbeautifulday.exeDetected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuffNo
Animated WallpaperUBeauty.exeBeauty animated desktop wallpaper from Desktop AnimatedNo
bee0c4d45bcdd7deadce6b70f4861060Xbee0c4d45bcdd7deadce6b70f4861060.exeDetected by Dr.Web as Trojan.DownLoader8.31864 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Beegees UpdateXbeegees.exeAdded by the SDBOT-ADK WORM!No
BEEI?beei.exe??No
BeFasterUbefaster3.exeBeFaster internet connection optimization toolNo
BEHL?BEHL.exe??No
BEHLO?BEHLO.exe??No
beidsystemtrayUbeidsystemtray.exeRelated to Belgium Identity Card card readerNo
ASDPLUGINXbelgium_nm.exeAsdPlug premium rate adult content dialerNo
Belkin Tray ApplicationUBelkinRouterMonitor.exeSystem Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled softwareYes
BelkinRouterMonitorUBelkinRouterMonitor.exeSystem Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled softwareYes
InstaLANUBelkinRouterMonitor.exeSystem Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled softwareYes
Belkin F5D8013 N Wireless Notebook Card UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D8013 N Wireless Notebook CardNo
Belkin F5D8053 N Wireless USB Adapter UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D8053 N Wireless USB AdapterNo
Belkin F5D8073 N Wireless ExpressCard Adapter UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D8073 N Wireless ExpressCard AdapterNo
Belkin Wireless G Notebook Card Client UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D701F Wireless G Notebook CardNo
Belkin Wireless G USB Adapter Client UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D7050 Wireless G USB AdapterNo
Belkin Wireless Networking UtilityUBelkinwcui.exeWireless configuration utility for some Belkin cards such as the F5D8053 N Wireless USB Adapter and F5D8051 N1 Wireless USB AdapterNo
Belkin Wireless USB UtilityUBelkinwcui.exeWireless configuration utility for the Belkin F5D7050 Wireless G USB AdapterNo
Belkin Wireless UtilityUBelkinwcui.exeWireless configuration utility for some Belkin cards such as the F5D7000 Wireless G Desktop CardNo
F5D7050v3UBelkinwcui.exeWireless configuration utility for the Belkin F5D7050 Wireless G USB AdapterNo
F5D8001UBelkinwcui.exeWireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop CardNo
F5D8011UBelkinwcui.exeWireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook CardNo
F5D8051v3UBelkinwcui.exeWireless configuration utility for the Belkin F5D8051 N1 Wireless USB AdapterNo
F5D8055v1UBelkinwcui.exeWireless configuration utility for the Belkin F5D8055 Wireless N+ USB AdapterNo
F5D8055v2UBelkinwcui.exeWireless configuration utility for the Belkin F5D8055 Wireless N+ USB AdapterNo
F5D8071UBelkinwcui.exeWireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCardNo
F5D9010UBelkinwcui.exeWireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network AdapterNo
F5D9050UBelkinwcui.exeWireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network AdapterNo
BellSouthAlertManager.exeUBellSouthAlertManager.exeRelated to BellSouth Alert ManagerNo
BELORVBI?BELORVBI.exe??No
Belsta.exe?Belsta.exeConfiguration tool for Belkin wireless network cards. Required to change the card's configuration. Is it required for correct operation once the confuiguration is changed?No
BeltXBelt.exeVX2.Transponder parasite updater/installer relatedNo
BelvedereUBelvedere.exeBelvedere "is designed to help support problem-based collaborative learning scenarios with concept and evidence moodels, and provides multiple representational views (tables and graphs) on those models"No
Benadril Alert ToolXbenadrilalert.exePlug-in for WeatherBug advising when pollen count in your area is high - prompting you to buy BenadrilNo
BengalsScreenServerUBengalsScreenServer.exeScreensaver for the Cincinnati Bengals NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
BackupExecSchedulerUBESCH.EXEScheduler for Backup Exec data backup and recovery software from Symantec (formerly Veritas)No
BestBoanXBestBoan.exeBestBoan rogue security software - not recommended, removal instructions hereNo
BestCrypt Auto OpenUBestCrypt.exeBestCrypt from Jetico, Inc. "Keeps your confidential data in a strongly encrypted form on your disk and provides you with transparent access"No
BestPopUpKillerXBestPopupKiller.exePopup killer by Swanksoft - not recommended, see hereNo
BestSync 2008UBestSyncApp.exeSystem Tray access to BestSync® 2008 from Risefly Software - "a professional utility for synchronizing files between your local folders and Network Drives, FTP servers, Removable Media (such as an USB disk)"No
BeSysXBEsys.exeBeSys adwareNo
WINDOWS SYSTEMXbeta.exeAdded by the MYTOB.DF WORM!No
BullsEye Tracker?BeTrack.exeBullseye - intelligent research assistantNo
BeyluxeMessengerNBeyluxe Messenger.exeBeyluxe Messenger by Beyluxe Communication S.R - "is a free popular Internet voice and video Chat program used by millions of people, and thousands of organizations, to communicate, share, play and work with each other on the internet around the world"No
System ConfigXBF3.EXEAdded by the SPYBOT-DT WORM!No
BF4PXbf4p.exeDetected by SUPERAntiSpyware as Trojan.BF4P.Process. The file is located in %System%No
bf8feb67afc2238269222493247f1c23Xbf8feb67afc2238269222493247f1c23.exeDetected by McAfee as Generic.dx!bh3h and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
load=YBfrecv.exeBitware modem driverNo
userinitXbfvkjs.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.AgentNo
BGInfoUBginfo.exeBGinfo automatically displays relevant information about a Windows computer on the desktop's background, such as the computer name, IP address, service pack version, and moreNo
BGNewsAgentYbgnewsag.exeBullGuard antivirus updaterNo
bgoomain.exeXbgoomain.exeBaigoo.a malwareNo
bgsmsndNbgsmsnd.exePrinter driver to generate PDF files from any programNo
BackgroundSwitcherUbgswitch.exeOriginally included with Microsoft's XP PowerToys (but now withdrawn - see here, Background Switcher allows your desktop background to periodically changeNo
bgz0ueitgyXbgz0ueitgy.exeDetected by Microsoft as Trojan:Win32/Scar.Q and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
MS32DLLXBha.dll.vbsAdded by the BUTSUR-A WORM!No
Browser Hijack BlasterYbhblaster.exeBrowser Hijack Blaster - protects your system from browser hijackers and spyware that alters your IE settings. Now replaced by SpywareGuardNo
MozillaIEXBHC.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %Windir%No
BHOCopNBHOCop.exePC Magazine's BHO Cop that lets you see what browser helper objects are installed. Useful for detecting spywareNo
BHODemon 2.0UBHODemon.exeBHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on demandNo
[various names]Xbhoserv.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BHRUBHR.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
BHR2.1UBHR2.1.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
BHR3.5UBHR3.5.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
BHR3UBHR3.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
BHR4.1UBHR4.1.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
BHR4UBHR4.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
Browser Help SvcXBHSV.EXEAdded by the RBOT-AVQ WORM!No
BI1HelperStartUpUBI1Helper.exeScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
BI1HelperStartUpUBI1HEL~1.EXEScreenScenes "Beach Islands" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
LTM2Xbible.exeAdded by the LITMUS.203 BACKDOOR!No
[12 random characters]Xbidispl2.exeIeDriver adware variantNo
tvgvopahXbidjnbvf.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %LocalAppData%No
This is a virus, please delete itXbigbadvirus.exeAdded by the RANDEX.F WORM!No
BigfileSearchXBigfileSearch.exeBigfileSearch adware. File located in %ProgramFiles%\BigfileSearchNo
BigFixNbigfix.exeBigFix can automatically download and read technical support information provided by computer and software manufacturers and other technical support experts (published in the form of Fixlet® Messages) and can automatically check your computer for bugs, configuration conflicts, and security holes. Should only be started manually as it's a resource hogYes
BIGXbiggy.exeAdded by the DELBOT-AG WORM!No
biglowXbiglow.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
bigorisXbigoris.exeAdded by the DORF-AZ TROJAN!No
BigPondWirelessBroadbandCMYBigPond_CM.exeTelstra wireless broadband managerNo
LastwordXBiHNet.exeDetected by ESET as Win32/LastwordNo
bikiniXbikini.exeAdded by the LOWZONE-CX TROJAN!No
BilbulonNBilbulon.exeBilbulon from EcoSoft - swaps text from Hebrew to another language and back. It helps correct typing mistakes which occur if you forget to switch to a different language before starting to type"No
sysfbtrayXbill102.exeAdded by the VB-ENI TROJAN!No
sysfbtrayXbill103.exeAdded by the MDROP-CLF TROJAN!No
sysfbtrayXbill104.exeAdded by the MDROP-CLO TROJAN!No
sysfbtrayXbill106.exeAdded by the MDROP-CLV TROJAN!No
sysfbtrayXbill108.exeAdded by the MDROP-CMW TROJAN!No
sysfbtrayXbill117.exeAdded by the VBKRYPT-E TROJAN!No
TnPopUpUbillbrz.exeRelated to Technesis "award-winning solutions for tracking and managing print, copy, fax and scan activities"No
BillGatesLoh.exeXBillGatesLoh.exeAdded by the AGENT-FZO TROJAN!No
BillminderNBillmind.exeCan be setup in Quicken to remind user of due payments. Available via Start → ProgramsNo
Bimwoheuipuubaxt.exeXBimwoheuipuubaxt.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %AppData%No
BinXBinDetected by McAfee as RDN/Generic.bfr!bg and by Malwarebytes Anti-Malware as Trojan.Agent.AINo
bincdwsaXbincdwsa.exeAdded by the ONLINEGAMES.AKYF TROJAN!No
ShareazaUbindata.exeShareaza P2P client relatedNo
Bing.exeXBing.exeDetected by McAfee as RDN/PWS-Banker and by Malwarebytes Anti-Malware as Trojan.AgentNo
bingoolbarXbing.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp%\bingoolbarNo
BingDesktopUBingDesktop.exeBing Desktop by Microsoft - "With Bing Desktop, make the Bing homepage image your PC desktop wallpaper each day"No
bingdianXBingdian.vbsAdded by the BINGD WORM!No
[various names]Xbingo9.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BinHostXbinhost.exeDetected by Malwarebytes Anti-Malware as Trojan.Inject.AI. The file is located in %AllUsersProfile%\Start Menu\binhostNo
Bionix Wallpaper 5UBionix Wallpaper 5.exeBioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world"No
BioniXWallpaperUBionix Wallpaper 5beta.exeBioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world"No
BioniXWallpaperUBioniX Wallper.exeBioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world"No
BioniXWallpaperUBionixWallpaper5.exeBioniX Wallpaper Changer - "the most advanced wallpaper changer/wallpaper manager software in the world"No
bionliXbionli.exeDetected by Malwarebytes Anti-Malware as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuffNo
1340ee8cbc8bf1647b41ad0df8d12e5eXbios.exeDetected by McAfee as Generic.dx!bhqs and by Malwarebytes Anti-Malware as Trojan.MSILNo
2e81bcb95bfda6135350a9b94e22cde4Xbios.exeDetected by McAfee as RDN/Generic.tfr!bs and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
biosXbios.exeDetected by Sophos as Troj/Bancban-PWNo
BIOS1XBIOS1.EXEAdded by the OPASERV.T WORM!No
BiosXBios32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Terminal UpdateXbiosefui.exeAdded by the PPDOOR-O TROJAN!No
BIOS Net ServiceXBIOSserv.exeAdded by the RBOT-BFL WORM!No
BIOVCIP?BIOVCIP.exe??No
BisonHK?BisonHK.exeRelated to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required?No
Media AdapterXbitblt.exeAdded by the HANSAH-A WORM!No
Microsoft Explorer2Xbitchbot.exeAdded by the SDBOT.EV WORM!No
BitCleanMainXBitClean.exeBitClean rogue security software - not recommended, removal instructions hereNo
BitCometNBitComet.exe"BitComet is a BitTorrent/HTTP/FTP download management software, which is powerful, fast, very easy-to-use, and completely free"No
BitDefender AntivirusXBITDEFENDERX.EXEAdded by a variant of the SPYBOT WORM!No
BitDefender_P2P_StartupUBitDefender_P2P_Startup.exeBitdefender anti-virus for P2P clients - no longer supported at the BitDefender websiteNo
Microsoft Windows DLLHandlerXbitpaint.exeAdded by the SDBOT.AHG WORM!No
Background Intelligent Transfer ServiceXbits.exeDetected by Dr.Web as Trojan.Inject.53759 and by Malwarebytes Anti-Malware as Trojan.AgentNo
MEVEMUJEQzQ2Q0NBMzdFQjXbitsmst.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
µTorrentNbittorrent.exeBitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads. Version 6.1 of BitTorrent is displayed as µTorrent in both Vista MSConfig & Windows DefenderYes
BitTorrentNbittorrent.exeBitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsYes
BittorrentXbittorrent.exeAdded by the RJUMP-D WORM! Note - do not confuse with the legitimate BitTorrent file-sharing client which is normally located in %ProgramFiles%\BitTorrent. This one is located in %Windir%No
bittorrent.exeNbittorrent.exeBitTorrent file sharing client - from BitTorrent, Inc. For more information about the protocol see here. As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsYes
biz_check_1_1Xbiz_check_1_1.exeDetected by McAfee as RDN/Generic.tfr!bf and by Malwarebytes Anti-Malware as Adware.K.BizkeywordNo
BJLaunchEXEUBJLaunch.exeMemory Card Utility for the Canon i470D, i475D and i905D photo printers - which allows "your computer to access the memory card reader feature of your printer"No
MSConfigXbjld.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% - see hereNo
bjmbmgrXbjmbmgr.exeAdded by the AGENT-TKD TROJAN!No
Canon My PrinterUBJMyPrt.exePrinter software for Canon Bubblejet printersNo
CanonMyPrinterUBJMyPrt.exePrinter software for Canon Bubblejet printersNo
Easy-PrintToolBoxUBJPSMAIN.EXEA utility to launch the applications that are bundled with a Canon bubblejet printerNo
BkupTrayUBkupTray.exeSystem Tray access to the NTI Backup Now 5 backup utility from NTI CorporationNo
SupernovaXBlaargh.exeDetected by McAfee as W32/Supova.e.wormNo
Windows ServicesXBlaBhs.exeDetected by Sophos as Mal/Agent-ACY and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
BlackArmorBackupMonitor.exeNBlackArmorBackupMonitor.exePart of Seagate BlackArmor Backup - their implementation of the Acronis True Image backup software for their BlackArmor range of external hard drives and Network Attached Storage (NAS). Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mountingNo
[12 random characters]Xblackbox.exeIeDriver adware variantNo
Black Box HelperUBlackBoxHelper.exeSupport for the M-Audio "Black Box" guitar processor and audio interface with guitar amp modelling, beat-synced effects and drum tracks for computer based recordingNo
Task ManagerXblackCoin.scrDetected by Malwarebytes Anti-Malware as Worm.AutoRun. The file is located in %AppData%No
LoadBlackDYblackd.exe"Intrusion detection system" of the BlackICE PC Protection (was Defender) firewall which loads independently of the "user interface" (BlackICE Utility). BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when they acquired the NetworkICE parent but is no longer available. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
BlackICE PC ProtectionNblackice.exeLoads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackDNo
BlackIce UtilityNblackice.exeLoads the user interface for the BlackICE PC Protection (was Defender) firewall. From the parent site - '(the user interface) starts in the "Startup" menu and adds itself to the taskbar. The user interface is independent from the rest of the system and only displays the output or reconfigures the system. It does not need to be running for the rest of the system to run.' BlackICE was supported by IBM Internet Security Systems (formerly just ISS) when them acquired the NetworkICE parent but is no longer available. See also LoadBlackDNo
STRINGSXBlackMilkProxy.exeDetected by McAfee as RDN/Generic BackDoorNo
HKCUXblackopsmodDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\installNo
HKLMXblackopsmodDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\installNo
PoliciesXblackopsmodDetected by Malwarebytes Anti-Malware as Worm.Autorun. The file is located in %System%\installNo
Razer Blackwidow DriverUBlackwidowTray.exeRazer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macrosNo
Razer Blackwidow DriverUBlackWidowUltimateTray.exeRazer Blackwidow gaming keyboard driver - required if you use the additional features and programmed keys/macrosNo
Distributed File SystemXblade.exeAdded by the MYFIP.AC WORM!No
bladsUblads.exeAd blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea SoftwareNo
BlockAdsUblads.exeAd blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea SoftwareNo
Microsoft machineXblah.exeAdded by a variant of Win32/RbotNo
bldbubgNbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her systemNo
BuildBUNbldbubg.exePart of Dell Alerts which provides customers with an update on latest updates for his/her systemNo
Win32 TestXbleatest.exeAdded by the RBOT.AGJ WORM!No
BLMessagingIntegrationXblengine.exeBuddyLinks adwareNo
BLFXblf.exeAdded by the DELBOT-M WORM!No
borzoiUblg.exeBorzoi surveillance software. Uninstall this software unless you put it there yourselfNo
ESPN BottomLineNbline.exeESPN BottomLine. "You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop, without even worrying about a browser. As long you keep the BottomLine running, you will continue to receive live scores and breaking news, and by clicking on any score or news item, you will be taken directly to the corresponding page on ESPN.com for a full break down."No
[various names]Xbling.exeAdded by the RBOT-NI WORM!No
Microsoft Security ManagementXbling.exeAdded by the RBOT.XL WORM!No
Microsoft UpdateXbling.exeAdded by the RBOT-AVK WORM!No
Windows ExecuterXbling.exeAdded by the SDBOT-DFT WORM!No
blinkxUblinkx.exeBlinkx Desktop "Smart Folders" softwareNo
BlockCheckerXBlock-checker.exeBlockChecker adwareNo
BlockDefenseXBlockDefense.exeBlockDefense rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
Ad BlockerUblocker.exeAd Blocker - blocks popups, and also removes banners, image ads and flash adsNo
BlockKeeperXBlockKeeper.exeBlockKeeper rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
BlockProtector.exeXBlockProtector.exeBlockProtector rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
BlockScannerXBlockScanner.exeBlockScanner rogue security software - not recommended. A member of the WiniGuard familyNo
BlockTrackerNBlockTracker.exeIf present on a HP machine it tracks all the processes and logs them to a blocklog.txt fileNo
BlockWatcherXBlockWatcher.exeBlockWatcher rogue security software - not recommended, removal instructions here. A member of the WiniGuard familyNo
mdssnXblog.exeDetected by Dr.Web as Trojan.DownLoader7.5792 and by Malwarebytes Anti-Malware as Trojan.AgentNo
blsloaderUblsloader.exeBellSouth ISP Internet ToolsNo
spc_wNblspc.exeNetZero Search Enhancement relatedNo
blssXblss.exeAdded by the BLARUL TROJAN!No
BLSTAPPNblstapp.exePuts access to Creative's BlasterControl in the System TrayNo
BlubsterNBlubster.exeRelated to Blubster Music sharing serviceNo
BbInstallUser?Bluebeam Admin User.exeRelated to PDF software from Bluebeam Software, Inc. What does it do and is it required?No
BluecolXbluecol.exeAdded by the CRYPTER.A TROJAN!No
Blue FrogUbluefrog.exeBlue Frog by Blue Security Inc. - actively fights spam by posting complaints on the sites advertised by the spam you receiveNo
BlueSoleilUBLUESO~1.EXEBlueSoleil Bluetooth wireless manager from IVT CorporationNo
BlueSpace NEUBlueSpaceNE.exe"BlueSpace NE is a utility program used to run the Bluetooth function on VAIO computers that support the Bluetooth function or on VAIO computers connected to the Bluetooth USB adapter". Shortcut available via Start → ProgramsNo
Bluetooth.exeXBluetooth.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note that the Command field can be either blank or the same as the Name field and located in a sub-folder of %LocalAppData% - see here and hereNo
Windows LoL LayerXblvpnmcny.exeAdded by the RBOT-GOR WORM!No
bmXbm.exePart of the AVSystemCare rogue security software and other members of this family. See here for more examplesNo
BMNXbm.exePart of VirtualPCGuard, VirusGuardPlus and other members of the AVSystemCare family of rogue security software suites. See here for more examplesNo
SalestartXbm.exePart of the AVSystemCare rogue security software and other members of this family. See here for more examplesNo
BmanXBMan1.exeAdded by a variant of Adware.DealHelperNo
BookmarkCentralNBMLauncher.exeBookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use". No longer availableNo
BMMLREFNBMMLREF.EXEPart of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" statusYes
BMMLREF.EXENBMMLREF.EXEPart of the Battery MaxiMiser and Power Management Features set for some IBM/Lenovo Thinkpad notebooks. The purpose of this entry is unknown at present. It doesn't normally appear to be running if left enabled at startup and it doesn't run if the Battery MaxiMiser Wizard is open - hence the "N" statusYes
BmonqXbmonq.exeAdded by the CLICKER.HZ TROJAN!No
CasdvqwaXbmqnzkg.exeAdded by the RANDEX.BE WORM!No
BuzmeNBmui.exeBuzme by RingCentral, Inc - internet call waiting. Intercepts telephone calls like an answering machine and plays the voice message on your PC. Only required when you're on-line and via dial-up modemNo
BMupdateNBMupdate.exeRelated to the BookmarkCentral entry. Typically added after downloading drivers for Visioneer scanners for example, and you install the driver self-installNo
bmwXbmw.exeDetected by Trend Micro as BKDR_AGOBOT.BBVNo
bmzXbmz.exe180Search adwareNo
Bndt32XBndt32.exeAdded by the LACON WORM!No
Microsoft UpdateXbnmveqfts.exeAdded by the BANLOAD.KWQ TROJAN!No
[various names]Xbnui.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BO1HelperStartUpUBo1helper.exeScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
BO1HelperStartUpUBO1HEL~1.EXEScreenScenes "Butterfly Oasis" screensaver. The free version contains GAIN adware by Claria Corporation. An ad-free version was available for a whopping $30!No
Boan119XBoan119.exeBoan119 rogue security software - not recommended, removal instructions hereNo
BoanCatchXBoanCatch.exeBoanCatch rogue security software - not recommended, removal instructions hereNo
BoanClearXBoanClear.exeBoanClear rogue security software - not recommended, removal instructions hereNo
BoanCodeXBoanCode.exeBoanCode rogue security software - not recommended, removal instructions hereNo
BoanCopXBoanCop.exeBoanCop rogue security software - not recommended, removal instructions hereNo
boanguideXboanguide_up.exeBoanGuide rogue security software - not recommended, removal instructions hereNo
boankingXboankingrun.exeBoanKing rogue security software - not recommended, removal instructions hereNo
boankoreaXboankorearun.exeBoanKorea rogue security software - not recommended, removal instructions hereNo
BoanNXBoanN.exeBoanN rogue security software - not recommended, removal instructions hereNo
BoanPack 3.0XBoanPack.exeDetected by McAfee as Generic FakeAlert and by Malwarebytes Anti-Malware as Adware.BoanPackNo
boanplusXboanplusrun.exeBoanPlus rogue security software - not recommended, removal instructions hereNo
BoanProXBoanPro.exeBoanPro rogue security software - not recommended, removal instructions hereNo
BoanShieldXBoanShield.exeBoanShield rogue security software - not recommended, removal instructions hereNo
BoanSupportXBoanSupport.exeBoanSupport rogue security software - not recommended, removal instructions hereNo
BoanTabXBoanTab.exeBoanTab rogue security software - not recommended, removal instructions hereNo
boaqaaXboaqaa.exeDetected by Malwarebytes Anti-Malware as Trojan.LVBP. The file is located in %UserProfile%No
WindefenderXBoat.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData%No
boat32Xboat32.exeAdded by a variant of Win32/RbotNo
BOC-412YBOC412.exeNSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.12No
BOC-420YBOC420.exeNSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.20No
BOC-421YBOC421.exeNSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.21No
BOC-422YBOC422.exeNSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.22No
BOC-423YBOC423.exeComodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.23No
BOC-424YBOC424.exeComodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.24No
BOC-425YBOC425.exeComodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.25No
BOC-426YBOC426.exeComodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.26No
BOC-427YBOC427.exeComodo BOClean anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters." Version 4.27No
BOCleanautostartYBoclean.exeNSClean (now Comodo) BOClean) anti-malware software - "runs silently in the background, monitoring your PC and waiting to root out and destroy malware whenever it enters"No
Caddais BackupOnDemandUBODMon.exeCaddais BackupOnDemand - "runs in the background and monitors your important files for changes. Within seconds of changing, modified files are automatically backed up to an archive location"No
bofkyfkovirzXbofkyfkovirz.exeDetected by McAfee as PWS-Zbot.gen.ari and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
bofuxXbofux.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
[various names]XBogobot.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BoincLogXUboinclogx.exeBoincLgx "makes it possible to log and show information about your processed WUs. In addition to a general log file which supports all BOINC projects, it will create project specific log files with detailed information about the WUs and results of some projects like SETI@home, Einstein@Home and AstroPulse." Add-on for the Boinc projectNo
BOINC ManagerUboincmgr.exeBOINC manager - "controls the use of your computer's disk, network, and processor resources"No
bolenjaXbolenja.exeDetected by Total Defense as Wantvi BF. The file is located in %System%No
bolenjxXbolenjx.exeDetected by Total Defense as Eldycow O. The file is located in %System%No
sysftray2Xbolivar19.exeAdded by the KOOBFACE.I WORM!No
RaseXboln.exePurityScan adwareNo
MSConfigXbolvcvjo.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
bombshelUBOMB32.EXEPart of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problemsNo
bombaXbomba.exeDetected by Dr.Web as Trojan.Siggen3.27560. The file is located in %Windir%No
bombaXbomba.exeDetected by Dr.Web as Trojan.MulDrop3.58666. The file is located in %System%No
BomulBoxXBomulBoxC.exeDetected by AVG as OpenShopper.D and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\BomulBoxNo
ABBYY Screenshot Reader BonusNBonus.ScreenshotReader.exeBonus version of the ABBYY Screenshot Reader utility available to users with registered versions of ABBYY FineReader and ABBYY PDF Transformer. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks'No
ABBYY Screenshot Reader RetailNBonus.ScreenshotReader.exeABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks'No
Bonus.SSR.FR10NBonus.ScreenshotReader.exeBonus version of the ABBYY Screenshot Reader utility available to registered users of ABBYY FineReader version 10. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks'No
BonusCashXBonusCash.exeDetected by Microsoft as Adware:Win32/Bonuscash and by Malwarebytes Anti-Malware as Adware.KorAdNo
BonziBUDDYXBonziBDY.EXEBonziBuddy adware - see here for removal instructionsNo
booXboo.exeAdware downloader - detected by Kaspersky as the FAVADD.O TROJAN!No
BookmarkUbookmark.exeSystem Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks"Yes
Bookmark.exeUbookmark.exeSystem Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks"Yes
BoontyBoxXBoontyBox.exeBoontyBox - "the ultimate jukebox software for your games. This free software is the best way to discover, download, launch and buy video games for your PC." Before Nexway acquired Boonty and discontinued the download the privacy policy used to state that amongst other thing they shared payment information with third parties - see hereNo
Auslogics BoostSpeedUboostspeed.exeSystem Tray access to Auslogics BoostSpeed system optimization utility - which allows you to "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs"Yes
Auslogics BoostSpeed 4Uboostspeed.exeSystem Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs"Yes
BoostSpeedUboostspeed.exeSystem Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs"Yes
6acce2d1e36340ed5fc49a2c6e178f71Xboot.exeDetected by McAfee as RDN/Generic PWS.y!js and by Malwarebytes Anti-Malware as Trojan.Agent.SCNo
bootXboot.exeAdded by the PUPPET-A TROJAN! Located in the %System%No
BootUBoot.exePart of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". Located in Acer\Empowering Technology\ePowerNo
FontXboot.exeAdded by the AGENT-LZW TROJAN!No
HKCUXBoot.tmpDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\MicrosoftNo
HKLMXBoot.tmpDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\MicrosoftNo
PoliciesXBoot.tmpDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\MicrosoftNo
MS-DOS Boot ServiceXBoot32.pifAdded by the RBOT-AMF WORM!No
bootcareSXbootcareU.exeBootCare rogue security software - not recommended, removal instructions here. One of the OneScan family of rogue scanner programsNo
ccExecuteXbootcfg1.exeAdded by the NEMSI-B VIRUS!No
explorerXbootcfgx.exeDetected by Panda as Banbra.GQUNo
SecurePCSolutionsBootCheckUBootCheck.exe1 Click Fixer PLUS from Secure PC Solutions "takes the guesswork out of locating and solving problems in the Windows registry"No
Boot CheckXbootchk.exeAdded by the DELBOT-AB WORM!No
Boot ClientXbootcli.exeAdded by the IRCBOT-ACF BACKDOOR!No
Internat ConfXbootconf.exeHomepage hijacker, redirecting to coolwwwsearch.com; see for example hereNo
OS Boot Configuration!Xbootconf.exeCoolWebSearch BootConf adwareNo
sysPnPXbootconf.exeHomepage hijacker, redirecting to coolwwwsearch.com; see for example hereNo
Boot ConfigXbootconfig.exeAdded by the FLOOD-EV TROJAN!No
ConfgXbootconfig.exeAdded by the VB-ERB WORM!No
OS Boot ConfigurationXbootconfig.exeDetected by Trend Micro as WORM_IRCBOT.HJNo
BootCTRLXbootctrl.exeAdded by an unidentified WORM or TROJAN!No
exploresXBootEx.exeAdded by the VB-DWI WORM!No
Microsoft Patch UpdateXbootini.exeAdded by the RBOT-FMN WORM!No
Microsoft WindowsXbootini.exeAdded by the VANEBOT-K WORM!No
Boot KXbootk.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
xbtlUbootldr.exeWinSession Logger surveillance software - remove unless you installed it yourself!No
OS Boot LoadXbootload.exeAdded by the SLENFBOT.GB WORM!No
BootLoaderXBootLoader.exe.vbsAdded by the WATERWORKS WORM!No
MicroUpdateXBootmgr.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%No
Boot ManagerXbootmng.exeAdded by the SDBOT.APK WORM!No
bootpd.exeXbootpd.exeAdded by the AGENT-DT TROJAN!No
Boot Resource LibraryXbootres.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Templates%No
Microsoft WordXBootSector.exeAdded by a variant of the AGOBOT WORM!No
Boot ServerXbootserver.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Boot ServiceXbootservice.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
BootSkinUBootSkin.exePart of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads pageYes
BootSkin RandomizerUBootSkin.exePart of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads pageYes
BootSkin Startup JobsUBootSkin.exePart of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads pageYes
bootstrapXbootstrap.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\intelx86No
BootStatusUBOOTST~1.EXEVisual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resourcesNo
Boot ServiceXbootsv.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Boot VerifyXbootvfy.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
winservicesXbootvfy.exeAdded by the VB.AMX TROJAN!No
[12 random characters]Xbootvid2.exeIeDriver adware variantNo
[12 random characters]Xbootvid4.exeIeDriver adware variantNo
BootvrfyXbootvrfy.exeDetected by Malwarebytes Anti-Malware as Worm.Texbot. The file is located in %Windir%No
BootWarnUBootWarn.exeUsed to warn the end-user that they must reboot their PC when using older versions of Norton AntiVirus in those cases where a reboot did not happen after installation or a significant software update via LiveUpdate. See the AnswersThatWork entry for a more detailed descriptionYes
Windows Update ManagerXbootwiz.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System%No
word pairXbopotsvr.exeAdded by the SHED-A TROJAN!No
[various names]Xborlandg.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
boromarlXboromarl.exeDetected by McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.AgentNo
boromarl2Xboromarl.exeDetected by McAfee as RDN/Generic Dropper!g and by Malwarebytes Anti-Malware as Trojan.AgentNo
BOSXbos.exeDetected by Microsoft as Trojan:Win32/LockScreen.CI and by Malwarebytes Anti-Malware as Trojan.LockScreenNo
Boss KeyUbosskey.exeBoss Key from Mindgems Inc - "will hide and restore the windows (programs) on your screen with the press of a hotkey or a mouse shortcut"No
Boston?Boston.exePart of the Boston Acoustics USB speaker systems. What does it do and is it required?No
CrowXbot.exeDetected by McAfee as Generic.tfr!bi and by Malwarebytes Anti-Malware as Backdoor.MessaNo
Google UpdateXbot.exeAdded by the AGENT-UDF TROJAN!No
gostXbot.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
Microsoft Synchronization ManagerXbot.exeAdded by the SDBOT.IH WORM!No
svchostXbot.exeDetected by McAfee as Generic.dx!bdwj and by Malwarebytes Anti-Malware as Backdoor.BotNo
Windows DefenderXBot.exeDetected by Dr.Web as Trojan.DownLoader8.17510 and by Malwarebytes Anti-Malware as Backdoor.BlackshadesNETNo
winsockdriverXbot.exeAdded by the WARPIGS-D WORM!No
Microsoft UpdateXBotnet.exeAdded by the RBOT.AFL WORM!No
Microsoft UpdatesXBotnet.exeDetected by Trend Micro as WORM_RBOT.YS and by Malwarebytes Anti-Malware as Backdoor.BotNo
Configuration LoaderXbotss.exeAdded by the SDBOT-XS WORM!No
WINDOWS SYSTEMXbotzor.exeDetected by McAfee as W32/Zotob.wormNo
GseriesXboulze.exeDetected by Trend Micro as WORM_SDBOT.BJL and by Malwarebytes Anti-Malware as Backdoor.BotNo
Bouncer RunStartupXbouncer.exeVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see hereNo
[various names]XBoundRec.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Windows ProtectotXboxide.exeAdded by a variant of the WOOTBOT WORM!No
Boxore ClientXboxore.exeDetected by Malwarebytes Anti-Malware as Adware.Boxore. The file is located in %ProgramFiles%\Boxore\BoxoreClientNo
RVPXbpc.exeDetected by Symantec as Adware.BroadcastpcNo
BPCv2_reXbpc2_re_inst.exeAdded by a variant of Adware.BroadcastpcNo
BigPondCableNbpcable.exeTelstra Bigpond Cable login software - can be started manuallyNo
bpcpost.exeUbpcpost.exeMS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall itNo
BPCV2XBPCV2.exeDetected by Symantec as Adware.BroadcastpcNo
BulletProof FTP ServerNbpftpserver.exeBulletProof FTP ServerNo
BPKUbpk.exeBlazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! The file is typically located in %ProgramFiles%\Perfect Keylogger Lite or %ProgramFiles%\BPKNo
bpkXbpk.exeDetected by Sophos as Troj/SCLog-AK. The file is located in %System%No
Major Microsoft Windows Driver Boot loaderXbpool.exeAdded by the MYTOB.AJ WORM!No
ContinueInstallXbpsinstall.exeBrowserAid/BrowserPal foistwareNo
BregXbptre.exeAdded by a variant of Adware.BroadcastpcNo
Backpack UDFNbpudfmon.exeBackpack UDF packet writing software for Microssolutions' Back Pack external CD-RW drive. Similar to DirectCD. Run manually before insert an appropriately formatted CD-RW diskNo
BigPond ToolbarUbpumTray.exeTelstra BigPond Toolbar - "Introducing the free and easy to use BigPond Toolbar that is designed to make your internet experience and managing your Telstra internet account a whole lot easier"No
rrmsoXbqhrmug.exeDetected by Sophos as Troj/Agent-GYYNo
bqjaonXbqjaon.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %UserProfile%No
Google ChromeXBQP531G0P6.exeDetected by Dr.Web as Trojan.DownLoader6.14623. Note - this is not a legitimate Google Chrome browser fileNo
BQTray.exeUBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manuallyNo
BurnQuick QueueNBQTray.exeSystem Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manuallyNo
BisonInst0402YBR040286.exeDriver for integrated notebook webcams from Bison Electronics Inc - such as the Acer Crystal EyeNo
[various names]Xbr0ken.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Tok-Cirrhatus-1464Xbr3951on.exeDetected by Trend Micro as WORM_BRONTOK.ADNo
Tok-Cirrhatus-1959Xbr4941on.exeDetected by Sophos as W32/Brontok-JNo
Tok-Cirrhatus-2454Xbr5931on.exeDetected by Trend Micro as WORM_BRONTOK.ADNo
Tok-Cirrhatus-2784Xbr6591on.exeDetected by Sophos as W32/Brontok-LNo
BrasilXBrasil.exeAdded by the OPASERV.P WORM!No
BrasilOldXBrasil.exeAdded by the OPASERV.P WORM!No
BrasilXBrasil.pifAdded by the OPASERV.E WORM!No
brastkXbrastk.exeAdded by the DORF-BV TROJAN!No
BraveSentryXBraveSentry.exeBraveSentry rogue security software - not recommended, removal instructions hereNo
Brave-SentryXBraveSentry.exeBraveSentry rogue security software - not recommended, removal instructions hereNo
braviaxXbraviax.exeAdded by the FAKEALER.LE TROJAN!No
ControlCenter2.0Nbrctrcen.exeBrother scanner 'Control Center' application - can be started manuallyNo
ControlCenter3Nbrctrcen.exeBrother scanner 'Control Center' application - can be started manuallyNo
Driver Control Manager v3.2Xbrdevet.exeAdded by the AUTORUN-BHS WORM!No
Break_ReminderUBREAK REMINDER.exeBreak Reminder - Remind yourself to take breaks to prevent computer related injuries. See hereNo
Break.exe EspanhaXBreak.exeAdded by an unidentified TROJAN! See hereNo
WinUpdateBXbreatle.exeAdded by the BRATLE.AWORM!No
BregXbreg.exeDetected by Symantec as Adware.BroadcastpcNo
tbrenaXbrenasa.exeDetected by Malwarebytes Anti-Malware as Backdoor.Azbreg. The file is located in %Root%\RECYCLER\S-1-5-21-0243556031-888888379-781863308-14699No
ObjectDockXBrico.cmdAdded by the BOBANDY-A WORM!No
Adobe Bridge CS5NBridge.exeAdobe Bridge - part of Adobe CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access"Yes
AdobeBridgeNBridge.exeAdobe Bridge - part of Adobe CS4 and CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access"Yes
BridgeNBridge.exeAdobe Bridge - part of Adobe CS4 and CS5 products which "lets you organize, browse, and locate the assets you use to create content for print, the web, DVD, video, and mobile devices. Adobe Bridge keeps native Adobe files (such as PSD and PDF) as well as non-Adobe files available for easy access"Yes
bridgeXbridge.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.AgentNo
WhitechixXbrightx.exeAdded by a variant of W32/Sdbot.wormNo
windowsXBrinks.exeAdded by the AGENT-TOA TROJAN!No
Brindys BriTrayYBRITRAY.EXEMain process for the following applications: GEDEX, SICARIO, BRINOTES, BRIRESPA, SICURE, TRASGO, UNDOCS, FRESH & BRIFAME (all of them from Brindys Software). Performs the following tasks [un]installation, web software autoupdate, notification windows, interprocess communication, tray bar icons & menus, alarms (brinotes), and common web launching from the mentioned applications. Can be stopped safely once run if so desiredNo
xBrotherMeCom?BrMeCom.exeRelated to Brother MFC-9200c printer. What does it do and is it required?No
Status MonitorNBrMfcWnd.exeBrother scanner status monitor - can be started manuallyNo
BrmfRmPAUBrmfRmPA.exeBrother resource manager - needed for a Brother MFC printer/copiert/scanner and PC to properly communicateNo
BrO_AcTXBrO-AcT.exeAdded by the SILLYFDC-D WORM!No
BroadbandadvisorYBroadbandadvisor.exeVirgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabledYes
Broadbandadvisor.exeYBroadbandadvisor.exeVirgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabledYes
Virgin Broadband advisorYBroadbandadvisor.exeVirgin Media Broadband Advisor tool installed when you choose to install their older PCGuard or PCGuard Total internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabledYes
BroadCamRunNbroadCam.exeBroadCam is an easy to use video streamer designed to broadcast live video using a webcam (or other camera) and microphoneNo
ChromeUpdateXbrocats.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile%No
[various names]XBrong32.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Bron-SpizaetusXbronstab.exeAdded by the RONTOKBRO.C WORM!No
BRoNToKXBRoNToK.exeDetected by Sophos as W32/Brontok-CGNo
BrownsScreenServerUBrownsScreenServer.exeScreensaver for the Cleveland Browns NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
browserXbrowse.exeAdded by the TACTSLAY.C TROJAN!No
cplXbrowse.exeAdded by the TACTSLAY.C TROJAN!No
httpdXbrowse.exeAdded by the TACTSLAY.C TROJAN!No
MessangerXbrowse.exeAdded by the TACTSLAY.C TROJAN!No
StartMenuXbrowse.exeAdded by the DROWSY-C TROJAN!No
[various names]Xbrowsebar.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BHR 1.1UBROWSER HIJACK RETALIATOR 1.1.exeBrowser Hijack Retaliator from Zamaan's Software. Real-time protection for IE users that helps them avoid getting infected while browsing the web. Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc. No longer supportedNo
Windows Browser ServicesXbrowser128.exeAdded by the SLENFBOT.GN WORM!No
Windows Browser ServicesXbrowser32.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
[12 random characters]Xbrowser5.exeIeDriver adware variantNo
Windows Browser ServicesXbrowser64.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
[12 random characters]Xbrowser8.exeIeDriver adware variantNo
browser aidXbrowseraid.exeBrowserAid/BrowserPal foistwareNo
BrowserChoiceNbrowserchoice.exeIn the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more informationYes
Microsoft Browser ChoiceNbrowserchoice.exeIn the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more informationYes
Microsoft® Windows® Operating SystemNbrowserchoice.exeIn the European Union, Microsoft had to provide the "Browser Choice update to comply with a legal settlement with the European Commission. Microsoft is required to inform customers who currently use Internet Explorer as their default browser that there are other web browser choices available. You can use the Browser Choice update to select and install the web browser you want to use on your computer" - see here for more informationYes
Browser SentinelUBrowserSentinel.exeBrowser Sentinel - notifies you if a program wants to penetrate into Internet explorer, add itself to the Windows auto-run list or change your home pageNo
Windows Browser ServicesXBrowsr32.exeAdded by the IRCBOT.BUR BACKDOOR!No
Windows Browser ServicesXbrowsr64.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
SystemXBrO_AcT.exeAdded by the SILLYFDC-AL WORM!No
wupdateXbro_exe.exeAdded by the DELF.GR TROJAN!No
BDRegionUbrs.exePart of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 timesYes
brsUbrs.exePart of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 timesYes
cyberlink brsUbrs.exePart of CyberLink's PowerDVD Blu-ray and DVD player. Allows the user to change the region coding of their player (as long as it isn't hardware coded) up to a maximum of 5 timesYes
SetDefPrtNBrStDvPt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installationNo
javaXBRTXEJJTWR4.exeDetected by Malwarebytes Anti-Malware as Worm.Ainslot. The file is located in %AppData%No
Microsoft Browser ServicesXBrwsr32.exeAdded by the SLENFBOT.FT WORM!No
Microsoft Browser ServicesXBrwsr64.exeAdded by a variant of the SLENFBOT.FT WORM!No
Tok-Cirrhatus-[4 random digits]Xbr[4 random digits]on.exeDetected by Sophos as W32/Brontok-MNo
winupdateXBS-Test1-nofud.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
windowsXbsade.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %AppData%No
BSBALL.exeXBSBALL.exeAdded by the VB-ZS MALWARE!No
Microsoft ServicesXbsc32.exeDetected by Sophos as Troj/Bdoor-AWNo
BsCLiPNBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't requiredNo
B'sCLiPNBSCLIP.exeCD recording utility that comes with a lot of CDR/CDRW drives and isn't requiredNo
BsearchXbsearch.exeDetected by Symantec as Download.Adware and by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\barosearchNo
BearShare LiteNBSHARELITE.EXEBearShare Lite (now replaced by BearShare 10) peer-to-peer (P2P) file-sharing client. As with any P2P client which is used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsNo
Microsoft Driver SetupXBSmBT.exeDetected by Avira as Worm/Kolab.ehpNo
BsMnt?BsMnt.exeRelated to a Bison webcam - which is used on notebooks from a number of manufacturers including Acer, Asus, Lenovo & Samsung. What does it do and is it required?No
Microsoft Driver SetupXBSoBT.exeDetected by Avira as Worm/Kolab.eilNo
Blue_Screen_of_DeathXbsod.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\bsod.exeNo
Bsoft lppt01XBsoft.exeRapidBlaster variant (in a "BelmontSoft" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
BS PlayerNbsplayer.exeBSplayer - A video player used to play avi, mpg, wmv and other multimedia filesNo
bsplayerNbsplayer.exeBSplayer - a video player used to play avi, mpg, wmv and other multimedia filesNo
BS MediaplayerXbsplyr.exeAdded by the RBOT-OU WORM!No
Bsqbhzkzykzdvwja.exeXBsqbhzkzykzdvwja.exeDetected by Sophos as W32/Dorkbot-EQNo
BsqxitatXBsqxita.exeAdded by the AUTORUN-BDL WORM!No
symanteccsysconfXbsyys.scrAdded by the VACILL-A WORM!No
SymantecFilterCheckXbsyys.scrAdded by the BANLOAD.DZC TROJAN!No
bs_stealthXbs_stealth.exeDetected by Dr.Web as Trojan.DownLoader6.4398 and by Malwarebytes Anti-Malware as Trojan.AgentNo
BBDial?BT Broadband.exePart of BT Broandband - is it required?No
BitTorrent DNANbtdna.exe"BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNAYes
btdnaNbtdna.exe"BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNAYes
btdna.exeNbtdna.exe"BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNAYes
DNANbtdna.exe"BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files". Now a stand-alone product where the user creates the download, DNA used to be included with and used by earlier versions of the main BitTorrent client. As files are downloaded via a file-sharing network make sure you have good, up-to-date virus protection and check any downloads. Start manually via Control Panel → DNAYes
btbb_McciTrayAppNBTHelpNotifier.exeSystem tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not requiredNo
Motive SmartBridgeNBTHelpNotifier.exeSystem tray icon for help from BT Broadband, used to communicate internet problems via the network rather than telephone. Available via desktop shortcut or Start → All Programs - not requiredNo
[12 random characters]Xbthserv1.exeIeDriver adware variantNo
btinst?btinst.exeAssociated with an Anycom bluetooth wireless card. What does it do and is it required?No
BTModemProtectionUBTModemProtection.exeBT Privacy Online modem protection software, see hereNo
btmsre.exeXbtmsre.exeDetected by Trend Micro as WORM_SDBOT.AMNo
LoadBtnHndUBtnHnd.exeFujitsu Siemens Lifebook laptops have some buttons on the case that can be programmed to execute specified programs (like hotkeys). The buttons can also be used as a combination lock inputNo
Director VideoXbtnmgern.exeAdded by the MYTOB-KL WORM!No
ATI Video Driver ControlXbtorrent.exeAdded by the RBOT.BLL BACKDOOR!No
Trap Wired Coordinator SSDP ProtectionXbtraogb.exeDetected by McAfee as Downloader.a!dch and by Malwarebytes Anti-Malware as Trojan.AgentNo
f73cdc8ee94eXbtsendto.exeAssociated with mysearchnow.com/searchbar.htmlNo
BTSETBOOTKEY?BTSetBootKey.exeRelated to a USB Bluetooth adaptor. What does it do and is it required?No
BTSETBOOTKEY?BTSetBootKey.exeUsed with a Mitsumi USB Bluetooth adaptor (and maybe others)No
BTStacFrrXBTStacFrr.exeAdded by the BANCOS.AAI TROJAN!No
BTStacLrjXBTStacLrj.exeAdded by the BANCOS.AAI TROJAN!No
BTStacPgnXBTStacPgn.exeAdded by the BANCOS.AAI TROJAN!No
BtStartUbtstart.exeBroadcom (formerly WIDCOMM) Bluetooth Connectivity SoftwareNo
Button ServerUbttnserv.exeFound on a Compaq PC, for the extra buttons on the keyboard for the speaker volume, media player, sleep and internet buttons. If the buttons aren't used on the keyboard or your's doesn't have them, then it isn't requiredNo
BtTrayUBtTray.exePart of the Bluetooth implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. Note - during testing, other than the System Tray icon included as part of the Windows OS this appeared to add no additional icon. Given this it is still recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabled. Loads via the HKLM\Run registry keyYes
BTTrayUBTTray.exeSystem tray icon which shows the status of a Bluetooth wireless module from WIDCOMM, Inc (either integrated or via an adapter). Most systems with such a module installed can enable/disable the module and the icon changes from blue/white to blue/red when the module is turned off. Required in order to successfully "pair" your system with a Bluetooth device (such as a mobile phone, PDA, headset) using this wireless protocol (via a PIN) and loads via %AllUsersStartup%Yes
BTUSRBDGYBtUsrBdg.exeUsed with a Mitsumi USB Bluetooth adaptor (and maybe others)No
BTVXbtv.exeDetected by Symantec as Adware.BroadcastpcNo
BtvCXbtvclean.exeDetected by Symantec as Adware.BroadcastpcNo
AtherosBtStackUBtvStack.exeOlder version of the Bluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabledYes
Bluetooth SoftwareUBtvStack.exeBluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabledYes
BtvStackUBtvStack.exeBluetooth stack implementation from Qualcomm Atheros (was just Atheros) - installed as part of their Bluetooth Suite and available to user via their motherboard or external device suppliers. It is recommended if you "pair" Bluetooth devices (such as a mobile phone, PDA, headset) using this wireless protocol to leave this enabledYes
btwdins.exeXbtwdins.exeAdded by the AUTORUN-ML WORM! Note - this is not the valid Widcomm/Broadcom Bluetooth file with the same name which is typically located in %ProgramFiles%\WIDCOMM\Bluetooth Software. This one is located in %System%\driversNo
Bluetooth ConfigXbtwindin32.exeAdded by the SDBOT-DFN WORM!No
BubbleYBubble.exePart of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyStateYes
Windows SteadyState - Bubble MessagesYBubble.exePart of Windows SteadyState, which is designed to make life easier for people who set up and maintain shared computers - enabling the system administrator to prevent users from making changes to the system configuration, windows desktop, restricting program access, etc. It's intended for shared user environments such as internet cafés, libraries and schools but can be used in any environment. Bubble allows notification messages to appear on a computer managed by Windows SteadyStateYes
BuddyizerNBuddyizer.exePart of the AIMster Peer to Peer (P2P) file sharing application that runs over the AOL Instant Messenger networkNo
Buddy SearchXBuddySetup.exeDetected by Microsoft as Adware:Win32/Nbar and by Malwarebytes Anti-Malware as Adware.BuddySearch. The file is located in %ProgramFiles%\Buddy SearchNo
BudgetSipNBudgetSip.exeBudgetSip - internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
budspencerXbudspencer.exeDetected by McAfee as Generic MSIL.t and by Malwarebytes Anti-Malware as Trojan.Clicker.GenNo
SysMainXbuff.exeAdded by the AGENT-ECW TROJAN!No
System Buffer ApplicationXbuffer32.exeAdded by the SDBOT-UD WORM!No
BugDoctorXBugDoctor.exeBug Doctor rogue security software - not recommended, removal instructions hereNo
bugwatcher serviceUbugwatcher.exeBugtoaster is a service that sends reports on system/program crashes (certain types) back to Bugtoaster. They relay information to program authors and provide, if available, any known solutions to the crashes. It doesn't take up any room in memory, just activates in the event of certain program failuresNo
Bug EliminatorNBug_Elim.exeBug Eliminator - "performs a complete health check on your computer safely, securely, and silently!"No
bui.exeXbui.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
BuilderXBuilder.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.SB. The file is located in %ProgramFiles%\Microsoft.NETNo
bulirizkonydXbulirizkonyd.exeDetected by McAfee as RDN/Downloader.a!f and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
bulkXbulk.exeAdded by the AGOBOT-ACR WORM!No
BullguardoptInYbulldownload.exePart of Bullguard antivirusNo
bgYbullguard.exeBullguard antivirus and firewall. The P2P version is free with KaZaA Media Desktop and GroksterNo
BullGuardYBullGuard.exePart of BullGuard antivirusNo
msgXBun.batAdded by the NUB-A WORM!No
SAHBundleXbundle.exeShopAtHomeSelect parasiteNo
VBundleOuterDLXBundleOuter.EXEVirtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see hereNo
buritosXburitos.exeIdentified as a variant of the Downloader.FraudLoad.C malwareNo
System settingsXburndl32.exeAdded by the SDBOT-ZO WORM!No
Rakyat_MiskinXBuruh.exeAdded by the SILLYFDC.BDM WORM!No
Scan Wizard?button.exeAssociated with Scan Wizard as supplied with Microtek scanners - see also the "Scanner Detector" and "Sdetect" entries. What does it do and is it required?No
ButtonGuideXButtonGuideC.exeDetected by Symantec as Adware.OpenShopper and by Malwarebytes Anti-Malware as Adware.ButtonGuide. The file is located in %ProgramFiles%\ButtonGuideNo
ButtonKeyNButtonKey.exeCyberView TWAIN driver for the Pacific Image range of 35mm film scanners. Enables the one touch scanning button and places an icon an the System Tray. Use your scanners software or run it manually by creating a shortcutNo
ButtonMonitorUButtonMonitor.exeButton support utility for some products from Verbatim - probably for their range of desktop and portable hard drives, see here. Located in %ProgramFiles%\VerbatimNo
Gateway Photo FrameNButtonMonitor.exeSupports the "Photo Frame" button on selected Gateway models such as the DX4300. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Gateway Photo FrameNo
Packard Bell Photo FrameNButtonMonitor.exeSupports the "Photo Frame" button on selected Packard Bell models such as the iExtreme. When pressed, the computer searches any attached flash drives or memory cards for photos and displays them in a slideshow. Located in %ProgramFiles%\Packard Bell Photo FrameNo
Smart CopyUButtonMonitor.exeButton support utility for some products from I/O Interconnect - probably for their range of removable storage devices, see here. Located in %ProgramFiles%\IOI\Smart CopyNo
Windows DefenderXbuy.exeDetected by Dr.Web as Trojan.AVKill.5830 and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
BuzofUbuzof.exeBuzof from Basta Computing "enables you to automatically answer, close or minimize virtually any recurring window including messages, prompts, and dialog boxes"No
RNBc TestXbvldv32.exeAdded by the RBOT-AJF WORM!No
SysScanXbvt.exeAdded by the AUTOUPDER TROJAN!No
BVWORSFMXbvworsfm.exeAdded by the DLUCA-AD TROJAN!No
Best Virus ProtectionXBV[random].exeBest Virus Protection rogue security software - not recommended, removal instructions hereNo
XupiterCfgLoaderXBWCfgLoader.exeXupiter - adware and homepage hijacker. Use Malwarebytes, Spybot S&D, Ad-Aware or similar to detect and remove and to prevent it re-installing in the futureNo
BitWare Print MonitorNbwprnmon.exePrint monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRONo
bwprnmon.exeNbwprnmon.exePrint monitor for Bitware from 2Point Communications, Inc - "a Windows based solution that allows users to integrate your voice messaging and faxing to an individual PC." Now known as Simply Messenger PRONo
Service ConnectionNbwtray.exeFor Compaq PC's. Part of BackwebNo
oepluginUbxOEPlugin.exenoHTML for Outlook Express is an add-on that protects Outlook Express from email viruses and email scripts by converting incoming email messages from HTML format to simple textNo
bxproxyXbxproxy.exeDetected by Trend Micro as BKDR_AGENT.AIWNo
Boost XP ServiceUbxservice.exeBoost XP from Systweak - WinXP tweaking utilityNo
Windows Live MessengerXbxZLovvPECTRHTQNarw.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%No
byssetebidbiXbyssetebidbi.exeDetected by McAfee as BackDoor-FAGP!71303927D4A0 and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
ByteDefenderXByteDefender.exeByteDefender rogue security software - not recommended, removal instructions hereNo
byzjanpaxnodXbyzjanpaxnod.exeDetected by Malwarebytes Anti-Malware as Trojan.Cutwail. The file is located in %UserProfile%No
BackblazeUbzbui.exeBackblaze online backup utility for businessesNo
BZEnvironmentVariableCollector?BZEnvironmentVariableCollector.exePart of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships". What does it do and is it required?No
Health Credential Audio Config PortableXbzgyfcbsoq.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.HCA. The file is located in %System%No
bZmq0AK16YYXbZmq0AK16YY.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
BZUtilizationCollector?BZUtilizationCollector.exePart of BlazentAgent from Blazent who provide "outsourcing governance automation for IT Outsourcing (ITO) relationships". What does it do and is it required?No

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home