Name Filename Status Description
%cmpmixtitle% Unknown N Possibly related to C-Media Mixer Control panel?
3cpipe-USRpdA USRmlnkA.exe Y Modem driver files from US Robotics
ABIT uGuru uGuru.exe U Provides quick access to several Abit motherboard utilities - such as monitoring cpu temperature, fan speeds, overclocking, flashing of BIOS
Automatic Windows Updater Update.exe X Added by the GAOBOT.AO WORM!
AV UPDATE-28062004.exe[25 blank spaces].vbs X Added by the MIDFIN WORM!
AVG Grisoft Updater updater.exe X Added by the AGOBOT-OT WORM!
Bulldog Service upsd.exe U Belkin's Bulldog Plus control software which runs under Windows 95 or later and monitors the UPS (Uninterrupted Power Supply) via a serial or USB link
Cyber-Defender 2003 uwcdsvr.exe U Cyber Defender 2003
Gene USB Monitor USBMonit.exe U Monitors USB ports for insertion of Sandisk USB flashdrives
Genie USB Monitor USBmonitor.exe Y Port monitor for an external USB hard drive. Required to enable access to the drive
I-Worm.GiGu uGiG.eXe X Added by the GINK WORM!
farfel update_checker.exe X FilesFrog Update Checker is a program that is commonly installed without your knowledge when you download and install free programs off of the Internet. This program will scan your computer for programs and then tell if you new updates are available. If they are, then it will open the FileFrog.com site where you can download these updates. The program itself is not bad, but its method of installation leave something to be desired.
Internet Exploere Services urlmon32.dll.exe X Added by the EVIAN.C WORM!
iRiver Updater Updater.exe N Updates for the iRiver Music Manager - used with their digital music players
M1cr0s0ft Upd4t4zS update32.exe X Added by the RBOT-MI WORM!
McAfeeUpdaterUI UpdaterUI.exe ? Associated with McAfee VirusScan
Microsoft Update Mechene Updatez.exe X Added by the RBOT-GI WORM!
msconfig.exe uline.exe X Added by a variant of the AGENT.AH downloader TROJAN!
NetLogon userint.exe X Added by the SDBOT-BC WORM!
notepad.exe upx.exe X Added by a variant of the AGENT.AH TROJAN!
OrbitUpdate update.exe X Xupiter OrbitExplorer toolbar, drive-by foistware
PLoader umsd.exe ? USB Mass Storage Disk related tray icon. Is it required?
PrintScreen UNWISE.EXE N Gadwin PrintScreen - utility to capture, print or save the current window
RunWindowsUpdate uptodate.exe X BrowserAid/BrowserPal foistware
SQUpdatesChecker uc.exe X Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants
sr1exe updtSup3.exe ? Found on a Dell computer, in a Documents and SettingsAll UsersApplication DataDellAlert2 subfolder
SSC_UserPrompt UsrPrmpt.exe ? Part of Symantec (Norton) Security Centre. What does it do, and is it required?
Start Service upssrv.exe U Cyber Power PowerPanelPlus software. "In the event of a power outage, PowerPanelPlus Software automatically saves and closes all open files, and then shuts down the computer system in an intelligent and orderly manner"
svwin32 unninst32.exe X Added by the AGOBOT-NF WORM!
system check updater.exe X Unidentified adware downloader
System Update2 update.exe X Added by the AUTOTROJ-C TROJAN!
SYSTRAY UNMT.EXE X Added by the SDBOT WORM!
tlc update911.js X Hijacker installer
tpcupdater updatetc.exe X Adware, probably 180Solutions related
UBSShell UBSShell.exe U UBS (United Bank of Switzerland) banking software
UC_SMB ucstart.exe N Part of IBM Update connector on IBM PCs for updating drivers on a new installation. Once you manually run the IBM Update connector program (shortcut) this entry is removed
uc_start ucstartup.exe N Auto updater feature for IBM machines that tries to connect to IBM to see if there are any new drivers, patches and etc
UD Agent.lnk UD.EXE U The United Devices Agent can recycle your PC's unused resources and use them to perform valuable scientific and medical research without disturbing your usual computer use - similar to SETI@home but for medical research. Available via Start -> Programs
Ueproc32 UEPROC32.exe U Part of Norton Utilities - most likely associated with the Unerase Wizard in older versions
Uidler Uidler.exe N Uniloc Titlewave Browser used with some shareware
UIWatcher UIWatcher.exe N Ashampoo Uninstaller Suite - installation watcher. Available via Start -> Programs
UKVideo2 ukvideo2.exe X Adult content dialler
UltimateZip Quick Start uzqkst.exe N UltimateZip - file compression utility
UMonit umonit.exe U Alerts when USB device is plugged in
umxagent umxagent.exe Y Tiny Personal Firewall V4 - main engine
umxldra umxldra.exe Y User mode executive module DLL loader - part of Tiny Personal Firewall V4
UMXLDRW UMXLDRW.exe Y Tiny Personal Firewall (pre V4)
un32info un32info.Exe X Added by the CRYPTER.A TROJAN!
Uninstall**** upd.exe X Adult content based screen saver where **** can be any number
UninstallAbility uability.exe N UninstallAbility uninstaller
UniSc Unisc.exe U McAfee UnInstaller
uniucu uniucu.exe ? ??
unldr16 unldr16.exe X Added by a variant of the CRYPTER.C TROJAN!
unldr32 unldr32.exe X Added by a variant of the CRYPTER.C TROJAN!
untray untray.exe Y Part of Command AntiVirus
UpConfgVer UpgConf.exe N Panda Antivirus Platinum. Purpose unclear, but according to Panda Software not required for the AV to function
Update UPDATE-28062004.exe[25 blank spaces].vbs X Added by the MIDFIN WORM!
Update Manager UpdateManager.exe N Searches for updates for the Rogers Yahoo! Browser - can be run manually
Update Service Update.exe Y Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall
UpdateMedia UpdateMedia.exe X MediaUpdate foistware
updatemgr.exe updatemgr.exe N Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually
updater updater.exe ? ??
Updatestats Updatestats.exe N Statblaster - "Get officially liscensed MLB pitch-by-pitch real time updates from every stadium around the league. StatBlaster provides live streaming statistics for each fantasy matchup you want tracked either in one league or across all your leagues"
updatev01 updatev01.exe N Ultra-networks.com software updater/downloader
Updatewiz updatewiz.exe ? ??
UPDATE~1 updatemgr.exe N Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually
Updmgr updmgr.exe X eUniverse/KeenValue adware variant
UpdReg Updreg.exe N Reminder to register Creative Labs SoundBlaster Live! cards
UPERVGAS UPERVGAS.exe ? ??
UPS ups.exe Y PowerChute v5.02 - UPS Monitoring Module (which loads iconclnt - the tray icon)
UPSentry 2000 upsd.exe Y Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
UPSlim upsd.exe Y Used with Belkin UPS (Uninterruptable Power Supply) for support in the event of a power-loss
Uptimer4 Uptimer4.exe U Uptimer4 is an appbar which displays time, date, uptime, free ram, free pagefile, cpu usage, disk free space, battery power, IP addresses, TCP throughput, list of running processes, netstat and several more things
UpToDate uptodate.exe X BrowserAid/BrowserPal foistware
UrlLstCk UrlLstCk.exe Y Part of Norton Internet Security. From Symantec - "UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled"
URLMAP Urlmap.exe N Installed by MS Money, and runs whenever you start IE. All it does is bring up an annoying sidebar (kind of like the search window) with 'financial links' when the web page supports it
UrtSvcExe Urt95Svc.exe Y "Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"
Usb Usb.exe ? HP related - not sure whether it's required
USB Hardware Monitoring USBhardware.exe X Added by the RBOT-NN WORM!
USB Host Service usbsvc.exe X Added by the RBOT-GG WORM!
Usbd usb_d.exe X Added by the CIDRA-A TROJAN!
USBDetector USBDetector.exe U USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware
USBDetector UDetect.exe ? USB detector, apparently for an MP3 player - any further information appreciated!
USBMMKBD usbmmkbd.exe U USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version (available here) no longer pings a server when on-line wheras the older version did but did not transmit any user information
usbn usbn.exe X Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa
USBPNP USBPNP.exe Y SiPix digital camera Twain USB driver
USBTA usbtapnp.exe N System Tray access for the BeWAN Gazel 128 USB ISDN adapter
User Services usersvc.exe X Added by the REVCUSS.A TROJAN!
USRobotics 802.11g Wireless Network Utility USRWLANG.exe N USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck "Use Windows to configure my wireless settings" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties
USRSTA USRSTA.exe ? Wireless Card controller. What does it do and is it required?
USSShReg USSSHREG.EXE N Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers
Utility Ping UTILIT~1.EXE ? ??
UtilityPro UtilityPro.exe N IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions
uwyrl uwyrl.exe X Added by the PHEL.A TROJAN!
WIN USB 2.0 usbsystem.exe X Added by an unidentified WORM of TROJAN!
Win32 Usb Driver usb32.exe X Added by the SDBOT-OV WORM!
Win32 USB2 Driver updatemgr.exe X Added by a variant of the FORBOT WORM!
windows update uddater.exe X Added by the LEOX TROJAN!
Windows Update Update.exe X Added by the DELF-FN TROJAN!
WindowsUpdate USRINIT.EXE X Added by the MADDIS.B WORM!
Windows_VXD user32.exe X Added by the PWSTEAL.PPORT TROJAN!
winlocatorupdate updatewinlocator.exe X Locator adult content toolbar related
winlogon service urx.exe X Added by the SPYBOT.EN WORM!
yahoo groups upgrdmgr.exe X Added by a variant of the RBOT WORM!
zervpack2 update2.exe X Added by the SDBOT.WD WORM!
rfv url_mon32.exe X Added by the PWSteal.Tarno.M infection. Found in the %Windir%z~c directory.
asejet uyohuvax.exe X Added by the W32/Sdbot-VE WORM! Found in the Windows system folder.
uwanah uwanah.exe X Added by the W32/Sdbot-VL infection! File is found in the Windows system folder.
foxhonz5568 unicox.exe X Added by the Troj/Bancos-BH password stealing TROJAN!
USB 2.0 Driver updateXP.exe X Added by W32/Agobot-QP, a Worm/IRC backdoor, found in the Windows system folder.
[random] unicox.exe X Added by Troj/Bancos-BK. This TROJAN may be found in the Windows sytem folder, also as "Carteiro2.exe", and in the Windows help folder.
AV UpDate Update.exe X Added by the Troj/Furoot-A TROJAN!
USB 2.0 Driver updateXPSPC.exe X W32/Agobot-QU adds the file, acting much like othe variants of this WORM/IRC backdoor.
Ulead Burning Helper ULCDRSvr.exe Y This program is part of the Ulead DVD Workshop, and may be bundled with other products from this company. It should be left alone in order to guarantee the stable operation of these products.
UFD Utility9382 UFDTool.exe ? Part of a USB Flashdisk software. Anyone know if it's required?
UFD Monitor9382 ufdlmon.exe ? Part of a USB Flashdisk software. Anyone know if it's required?
user user32.exe X Added by the BINGHE backdoor Trojan! It has the ability to log your keystrokes, steal data, and execute commands.
MsUpdater System udpsys32.exe X Added by the RBOT.AAA WORM!
USBMonit.exe USBMonit.exe U Monitors USB ports for insertion of Sandisk USB flashdrives
foxwudy9912 unicox.exe X Added by the Troj/Bancos-BT TROJAN!
xpupdate updates.exe X Added by the W32.Bropia.L WORM!
msupdate update.exe X Added by a variant of the W32/SDBOT WORM!
SysUpdt UpdatesWin.exe X Added by the Troj/Nopir-A TROJAN!
SecuROM User Access Service (V7) UAService7.exe Y Used by virtual CD programs like Alcohol to access CD images protected by SecureROM.
Upromise0 Upromise0.exe U Software for the Upromise College Savings Program. If you have this software installed and visit an online store that is part of this program, it will display a notification that the store is part of the program and how to use it to get money contributed to a college fund.
USB Driver4 updatexp2.exe X An SDBOT variant.
Ulead Systems ULCDRSvr.exe X Added by W32/Codbot-H as a service, with a displayname of Ulead Systems System Files on Windows NT/2000/XP versions.
USB Hardware326 Monitoring USBhardware326.exe X Added by a variant of the W32.SPYBOT WORM!
Microsoft Update update_w.exe X Added by the W32/RBOT-EW WORM!
Microsoft Updater UPDATER.EXE X Added by the W32/Rbot-AZ trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. It also may log keystrokes and windows text to a file called %System%keys.txt.
Windows Task Manager-Emulator ukenme.exe X Added by the W32/Rbot-CF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows Task Manager-Emulator uswtme.exe X Added by the W32/Rbot-CG trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Microsoft Update UPDATEX.EXE X Added by the W32/Rbot-FD trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. This infection may also attempt to log keystrokes to a file called keys.txt.
AntiVirus Update updates.exe X Added by the W32/Rbot-JF trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
zerzvpack2 uzpdate2.exe X Added by the W32/Rbot-KA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Ulead Sservice System Files ulcdrsf.exe X Added by the W32/Codbot-S network worm and backdoor trojan.
[not used] userinit32.exe X Added by the W32/Rbot-YE irc backdoor trojan.
svchost Up100.exe X Added by the Troj/Dloader-KT trojan.
UltraEdit uledit.exe X Added by the W32/Sdbot-TO worm. When started this infection connects to an IRC server where it waits for remote commands.
USB Hardware32c Monitoring USBHARDWARE32C.EXE X Added by the W32/Rbot-UU worm. When started, this infection connects to an IRC server where it waits for remote commands.
MS UPDATER update.exe X Added by the W32/Rbot-VC worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Tiny unknown X Added by the Troj/Small-DJ, which will sit on port 1 and allow a remote user to run a command prompt on an infected machine.
Task Scheduler unknown X Added by the Troj/PcClient-R as a display name used when it overwrites the existing service named Service.
USB 2.0 Driver UpdateXPSP.exe X Added by the W32/Agobot-QD worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
[various names] Uint32.exe X Added by a NTRootKit TROJAN variant!
back updates Uninstall.log.vbs X Added by the VBS.YPSAN.D WORM!
ASDPLUGIN uk_nm.exe X Added by Dialer.Asdplug dialer variant.
uninstall#### upd.exe X Adult content based screen saver where #### can be any number
Windows Service Manager userint32.exe X Added by the W32/Oscabot-C worm. When started, this infection connects to an IRC where it waits for remote commands to execute.
urllstck.exe UrlLstCk.exe Y Part of Norton Internet Security. From Symantec - "UrlLstCk.exe is a necessary file that will be present in C:\Program Files\Norton Internet Security. It is a URL Checklist. It should not be disabled"
UsrManagementConf umcss.exe X Added by the Troj/IRCBot-W backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
usb driver4 UpdateXP6.exe X Added by a variant of the W32/SDBOT WORM!
qh live update scheduler UPSCHD.EXE Y Program updater for the Quick Heal Anti-Virus program.
userint32 userint32.exe X Added by an unidentified TROJAN via an Instant Message that says, "This was cool, check it out here." Also contains Aurora popups
Configuration Loader update.exe X Added by the W32/Sdbot-OS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Ultra Edit v5.1 ultraedit.exe X Added by the W32/Sdbot-RK worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
ups UPS32.exe X Added by the W32.Femot.O
User Logger UsrLog.exe U Added by the Spyware.UserLogger surveillance software. If you did not install this software you should remove it immediately.
Windows Security Engine update.exe X Added by the PWS-Hangame.
Windows Security Engine updata32.exe X Added by the Trojan.Maocal trojan.
userun32 userun32.exe X Added by the Troj/Lydra-B trojan.
tlc update13.js X Used by the searchcentral.cc hijacker to hijack your browser settings when you start your computer.
updatelavasoft updatelavasoft.exe X Added by an unidentified Proxy Trojan variant. A PT is a backdoor trojan which allows a remote hacker to connect to other systems via the compromised system.
upnp manager upnpman.exe X Added by a variant of the Win32.Agobot.gen WORM!
SVCHOST updater32.exe X Added by the W32.Rants.A@mm mass-mailing worm.
microsoft unpaccker system unpak32.exe X Added by a variant of the WIN32.RBOT WORM!
winupdate updsys.exe X Added by a variant of the WIN32.RBOT WORM!
winuser32k usr32wink.exe X Added by the Win32.VB.hk backdoor TROJAN!
printer spool updater.exe X Added by a variant of the WIN32.RBOT WORM!
ncao urpo.exe X PurityScan/Clickspring adware
usb2 usb2.sys X Added by the Backdoor.Fuwudoor backdoor.
winhelp Updadv.exe X Added by the Troj/QQPass-N password-stealing Trojan.
expler Updadv.exe X Added by the Troj/QQPass-N password-stealing Trojan.
Rundil32 Updadv.exe X Added by the Troj/QQPass-N password-stealing Trojan.
Regexit Updadv.exe X Added by the Troj/QQPass-N password-stealing Trojan.
sdsr Updadv.exe X Added by the Troj/QQPass-N password-stealing Trojan.
MS Windows Security Updater updater.pif X Added by the W32/Rbot-AKY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Update Service update32.pif X Added by the W32/Rbot-ALC worm.
Msn Update Service userx.exe X Added by the W32.Mytob.JF@mm backdoor and IRC worm.
Windows Updating Service updating.pif X Added by the W32/Rbot-ALW backdoor and IRC worm.
System Updates Service updates.pif X Added by the W32/Rbot-AMA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
system updata updata.exe X Added by the Troj/Lineage-C password-stealing Trojan for the online game Lineage.
System Update Service update.pif X Added by the W32.Spybot.WOE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MouseDrv update.exe X Added by the WORM_ZOTOB.N worm.
Java Auto Update ujm.exe X Added by the W32/Sdbot-ADH worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
epoxusdm USDM.EXE N EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps, Fan Speeds, Voltages...etc
ni.uwfx5 UWFX5NetInstaller.exe X WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
ni.uwfx5lp_0001_0802 UWFX5LP_0001_0802NetInstaller.exe X WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
ni.uwfx5lp_0001_0803 UWFX5LP_0001_0803NetInstaller.exe X WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
ni.uwfx5v_0001_0802 UWFX5V_0001_0802NetInstaller.exe X WinFixer web installer - Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
unspypc UnSpyPC.exe X The main executable for the rogue anti-spyware application UnSpyPC. UnSpyPC is a Security Risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.
USBTest USBTest.sys X Added by the Troj/Lecna-D backdoor Trojan.
NI.UWFX5T UWFX5TNetInstaller.exe X Added by the Troj/DownLdr-BO Trojan. This infections is part of the Winfixer 2005 adware/malware.
User Logon usrh.exe X Added by the Troj/Junet-A password-stealing Trojan.
Up Service up32.pif X Added by the W32/Rbot-ARI worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
wnxpupdate updatexp.exe X Added by the Troj/Dadobra-H Trojan.
updatemgr updmgr.exe X Added by the SouthBeachTel premium rate adult content dialer.
usrpda USRmlnkA.exe Y US_Robotics modem driver
Internet Service Unknown X Added by the Adware.SweetBar adware that display pop-up ads.
WinFixer2005 uwfx5.exe X "Spyware remover" of dubious repute - see the SpywareWarrior_List of Rogue/Suspect Anti-Spyware Products & Web Sites
upsmon UPSMON.exe U UPSMON Power Management software
yx uu.exe X Added by the W32/Agobot-YX
miniport usb2chk.exe X Added by the Troj/Lazar-A backdoor Trojan.
System Updates unve.exe X Added by the W32/Rbot-AWG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Debugging Tools updatecfg.exe X Added by the W32/Rbot-AXU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Updated updatr.exe X Added by the W32/Rbot-AYB worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
startkey update.exe X Added by the Troj/Bifrose-DG Trojan.
Updt Service updt.pif X Added by the W32/Rbot-AYU worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
updat updat.exe X Added by the W32/Rbot-AZZ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows Updater update.exe X Added by the Troj/YSpy-A constructor Trojan.
[not used] userlogon.exe X Added by the Troj/Stawin-I keylogging Trojan.
GPU HL interface updB1.sys X Added by the TROJ_HANLO.J Trojan.
1qaw3edr5 userinit.exe X Added by the Troj/Kbroy-B keylogging Trojan.
upd.exe upd.exe X Added by the Troj/Delf-AJW backdoor Trojan.
Microsoft Windows Update XP64 updatexp64.exe X Added by the W32/Sdbot-AIM worm and IRC backdoor.
Schedule usbdrv.exe X Added by the . This infection also creates the file c:\Windows\System32\usbdrvw.dll.
NAVMD25 UpdtNv28.exe ? Added by Symantec for updating the MicroDefs for their AV products. Though this is a legitimate file, it is unknown whether or not it needs to be running at startup. The command may just show C:\WINDOWS\UpdtNv28.exe without the /2003 if you are running NAV 2004.
UpdaterUI UpdaterUI.exe X Added by the Troj/Agent-TM Trojan.
Windows USB 2.0 Driver usb2ctrl.exe X Added by the W32/Rbot-BIW worm and IRC backdoor.
Autozncupdate update_.exe X Added by the Troj/DownLdr-QT Trojan.
Microsoft usbcontrol.exe X Added by the W32/Rbot-BJH worm and IRC backdoor.
Windows USB Hub Manager usbhub.exe X Added by the W32/Rbot-BJX worm and IRC backdoor. This infection also creates the C:\Windows\SoftWareProtector\Skonk_out.pr.
{CD5AC91B-AE7B-E83A-0C4C-E616075972F3} userinit.exe X Added by the JS_FEEBS.I malicious javascript file.
Windows USB 2.0 Driver usbtskmgr.exe X Added by the W32/Rbot-BKG worm and IRC backdoor.
MoodLogic Updater Updater.exe N Installed with iRiver software that comes with your iRiver device.
[Various Names] Uint32.exe X Part of the Wareout infection as described here.
[Various Names] UserSp1.exe X Part of the Wareout infection as described here.
[Various Names] uio.exe X Part of the Wareout infection as described here.
[Various Names] utsgmon.exe X Part of the Wareout infection as described here.
{00212521-4FEF-4AD3-B3AA-E0531B8DC123} usbadpt32.dll X Added by the Troj/Dloadr-EO Trojan.
Windows USB 2.0 Driver usbservice.exe X Added by the W32/Rbot-BLF worm and IRC backdoor.
winup32 updated.exe X Added by the Troj/Banload-IY Trojan.
unicox.exe unicox.exe X Added by the Troj/Bancos-LX Trojan.
Windows Service Hosting USERINIT.exe X Added by the W32/Gommer-A worm.
unlockerassistant UnlockerAssistant.exe U Related to Unlocker utility to unlock files when the OS reports the file is being used by an other person or program.
usbtooltip USBTip.exe ? Related to Pinnacle_Systems Inc. What does it do and is it required?
winfixer2006 uwfx6.exe X "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here
Microsot NT Support Unknown X Added by the W32/Rbot-CTI worm and IRC backdoor.
uvu-channel uvu-channel.exe X Added by the Trojan.Hachilem.B Trojan.
[STRING 1]Software Update[STRING 2] updtscheduler.exe X Added by the W32.Kedebe.I@mm mass-mailing worm. String 1 can be one of following: *, Windows, Microsoft Windows and string 2 can consist of:# Checker, Monitor, Control.
windows update microsoft updatem.exe X Added by the W32/Rbot-CHE worm and IRC backdoor
Userinit Logon Verification userinit.exe X Added by the W32/Tilebot-EV worm and IRC backdoor. This infection should not be confused with the legitimate file found at C:\Windows\System32\userinit.exe.
[not used] usrs445F8764.dll X Added by the Troj/Opnis-D Trojan.
Comclg32 utlsrv.exe X Added by the Trojan.Checkraise password stealing Trojan for online poker sites.
{24c60b9b-26b5-4201-9f7a-fb9219356ae9} ulztc.dll X A file used by the rogue antispyware app, SpyFalcon, to issue fake security alerts on your taskbar.
Microsoft USA Plug usaplug.exe X Added by the W32/Rbot-DVC worm and IRC backdoor.
user logon user logon.exe X Added by the W32.Pahatia.A worm.
{c3786a8d-6426-4c29-a23f-f36e47b31e0c} ucbrrt.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
<non alphabetical characters>IPX/SPX usbmini.sys X Added by the Troj/Proxy-CY rootkit.
BrowseZilla update.exe X Added by the Downloader.Browsilla downloader Trojan.
utasvc utasvc.dll X Added by the W32/Akbot-AB worm and backdoor Trojan. This infection will also modify the HOSTS file.
upnp upnp.exe X Added by the Troj/Dloadr-YT downloading Trojan.
wmc_rebootcheck unregmp2.exe N Related to Media_Player The main purpose of this software program is to update information in the registry related to the video player. More info
ni.uersm_0001_n68m1602 UERSM_0001_N68M1602NetInstaller.exe X Added by the ErrorSafe Installer ErrorSafe is a Security Risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats.
suscheduler UCLauncher.exe U Related to Lenovo ThinkVantage Technologies. ThinkVantage Technologies help make ThinkPad/ThinkCentre PCs less dependent on IT staff.
DriveCleaner 2006 Free UDC2006.exe X Added by the DriveCleaner security risk.

According to Symantec, "DriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks."
update82 update.exe X Added by the Troj/Dloadr-AJM downloader Trojan.
incestuously urroxtl.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
msmsn upnp.exe X Added by the Troj/Dloadr-AMY Trojan.
navdflp8922 unicox.exe X Added by the Troj/Bancos-AVT Trojan. Troj/Bancos-AVT may attempt to steal account details for certain banking sites and for MSN Messenger, by dispalying fake user input screens.
UpperHost UpperHost.dll X A variant of the Goldun Trojan.
np upnp.exe X Added by the Troj/Dloadr-ANX downloading Trojan.
ScanRegistry update.exe X Added by the Troj/DwnLdr-FSK Trojan.
uTorrent utorrent.exe N µTorrent is a lightweight and efficient BitTorrent client for Windows with many features.
RealUpdate update.exe X Added by the Troj/DwnLdr-FSR Trojan.

Troj/DwnLdr-FSR includes functionality to :

Access the internet and communicate with a remote server via HTTP.
Download, install and run new software.
Windows security FTPd update updtftpini.exe X Added by the W32/Rbot-FUS worm and IRC backdoor.
USDR6cw USDR6cw.exe X Part of the rogue anti-spyware application SystemDoctor 2006. This application is known to install with malware that issues fake security warnings in your taskbar as a goad to scare you into purchasing the full version of this software. You should use the removal guide in the link below to remove this software.
SDR6_Check udcsdr.exe X

Added by the DriveCleaner security risk.

According to Symantec, "DriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks."

PAS_Check udcpas.exe X

Added by the DriveCleaner security risk.

According to Symantec, "DriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks."

UDC6cw UDC6cw.exe X

Added by the DriveCleaner security risk.

According to Symantec, "DriveCleaner is a security assesment tool which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks."

UPnPDevService upnpmngr.exe X Added by the Troj/Small-DMW Trojan.
udzok udzou.exe X Added by the W32/Sdbot-CUS worm and IRC backdoor.
{C0FB7D08-056E-1033-0501-03020730002c} Update.exe X Added by the Troj/Mdrop-BLR Trojan.
Windows Update Managere update.exe X Added by the Troj/GrayBir-EG backdoor Trojan.
uwa6pcw uwa6pcw.exe X Part of WinAntivirus Pro. This program is fake, stealth installed, and bundled with other malware. It is also on the Rogue anti-spyware list.
Microsoft Windows Software Update Scheduler updtscheduler.exe X Added by the W32/Kebede-F backdoor mass-mailing worm.
IPSTK driver ufgrbe.sys X A variant of the Troj/Haxdor-Fam of rootkits.
utgrbe utgrbe.dll X Added by the Troj/Haxdoor-DJ backdoor Trojan. This infection is hidden by the ufgrbe.sys rootkit.
User32 user32.exe X Added by the Troj/EzKilla-A backdoor Trojan.
userinit.exe userinit.exe X An installer for the Troj/Haxdor infections.
C:\WINDOWS\userinit.exe userinit.exe X An installer for the Troj/Haxdor infections.
Network Windows Service urdvxc.exe X Added by the W32.Rahack.W worm. W32.Rahack.W is a polymorphic worm that spreads to computers by exploiting weak passwords for Radmin servers and Windows network shares.
LoadService user32.com X Added by the W32.Burmec worm. W32.Burmec is a worm that spreads by copying itself to removable and mapped drives.
Windows Firewall Updater updatees.exe X Added by the W32/Rbot-GBX worm and IRC backdoor. W32/Rbot-GBX spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012), RealVNC (CVE-2006-2369), Veritas (CAN-2004-1172) and ASN.1 (MS04-007). The worm may also spread via networks shares and MSSQL servers protected by weak passwords.
Updates From HP Updates from HP.exe U Associated with Lightscribe DVD-RW drive that come with certain HP computers.
uwa7pcw uwa7pcw.exe X Startup program associated with WinAntiVirus Pro 2007. WinAntiVirus Pro 2007 is a rogue anti-spyware program that displays fake alerts, and downloads other programs onto user's machine without permission.
System Updaterun.exe X Added by the Troj/QQHelp-Gen downloader Trojan.
Personal Player ud.sarkilari_Web_Hottest_Videos_PersonalPlayer.exe X Added by a program that shows YouTube videos. From the research done by Paperghost we advise that you remove this program. This file is also detected by Avast antivirus as Win32:Hotwebbar.
PrivacyProtector Free UPRP.exe X Rogue privacy protection software that is advertised aggressively through the use of Trojans and other malware.
uprpcw uprpcw.exe X Rogue privacy protection software that is advertised aggressively through the use of Trojans and other malware.
Universal Printer NT Service upnt.exe X Added by the W32/Rbot-GKP worm and IRC backdoor.
uvnx uvcx.exe X Added by the Troj/Dloadr-AWF downloader Trojan.
{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} Uninstall.exe X Added by the W32/SillyFDC-V worm. W32/SillyFDC-V is a worm for the Windows platform that spreads via removeable shared drives.
upxdnd upxdnd.exe X Added by the Troj/JD-A password-stealing Trojan.
URLy Warning URLyWarning.exe U Added by the URLy Warning web page monitoring software.
UVS10 Preload uvPL.exe N Related to Ulead VideoStudio.
Windows Service DC uhpnjcjl.exe X Added by the W32/Rbot-GLY worm and IRC backdoor.
USAR USAR.exe X Added by the UltimateSpyware rogue anti-spyware program. UltimateSpyware is a misleading application that may give exaggerated reports about potential risks on the computer.
AdobeReaderPro updt.exe X Added by the W32/IRCBot-VQ worm and IRC backdoor.
DriveCleaner Free UDC.exe X Added by the DriveCleaner rogue security product. DriveCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks.
aa bbcc dde effgghh jj update.exe X A variant of the IRCBot family of worms and IRC backdoors.
{C0FB7D08-056E-1033-0501-03020730002c} Update.exe X Added by the Troj/Agent-EOG Trojan.
iut75 uzcx.exe X Added by the Troj/Agent-EOF Trojan.
Microsoft windows FTPd updtftpini.exe X Added by the W32/Rbot-GLV worm and IRC backdoor.
Command Interpreter ucmd.exe X A variant of the IRCBot family of worms and IRC backdoors.
Install part II updates.exe X Added by the W32.Relfeer worm. W32.Relfeer is a worm that spreads through network shares and file-sharing applications. It may also attempt to download potentially malicious files on to the compromised computer.
Server Runtime Process unsecapp32.exe X Identified by BitDefender as Backdoor.IRCBot.HBJ. This infection is a variant of the IRCBot familar of worms and IRC backdoors.
Office Monitor Word Exel R u.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
runner1 updater.exe X Identified as Trojan-Downloader.Win32.Agent.bls.
Microsoft updater.exe X Added by the W32/Rbot-GHP worm and IRC backdoor.
<not used> userini.exe X Added by the Troj/Proxy-HP proxy Trojan.
{6ad686b9-ab56-4ebc-a804-9f70b55b4577} uimcu.dll X A Trojan associated with the SpyLocked rogue anti-spyware application.
Asynchronous UPnP Support Services UPnPSvc.dll X Added by the Troj/PWS-ANB password-stealing Trojan.
DRam rare proc updaterarwin.exe X Added by the W32/Rbot-GQW worm and IRC backdoor.
update mon sys updaterar.exe X Identified as the Rbot.cnh worm and IRC backdoor Trojan.
Windows module uient.exe X A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network
Server Runtime Error unsec.exe X Added by the W32/Sdbot-DFA worm and IRC backdoor.
Media Codec Update Service update.exe Y Windows Essentials Codec Pack is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated.
Messenger Journel usnsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Micrsoft DerSystem uqieelpb.exe X Added by the W32/Rbot-GRI worm and IRC backdoor.
erwghjjrjt ucbcg.exe X Identified as the Trojan-Downloader.Win32.Small.cul Trojan.
Print Scheduler usnsvc.exe X Identified as a variant of the Oscarbot.PJ worm and IRC backdoor.
Icarus2 UpdateChk.exe X Added by the Trackware.Icarus spyware.
Shell UPSI_1.exe X Added by the W32/SillyFD-C worm that spreads to removeable storage devices.
Microsoft (R) Windows Update Manager updmgr.exe X Added by the Backdoor.Ranky backdoor Trojan.This infection also creates a Windows service using the same name and filename.
Microsoft (R) Windows Update Manager Tool updmgr.exe X Added by the Backdoor.Ranky backdoor Trojan. This infection also creates a Windows service using the same name and filename.
Ultimate Defender UltimateDefender.exe X Added by the rogue anti-spyware program called Ultimate Defender. This program is typically installed via other malware and through the use of aggressive advertising.
Windowz Update V2.0 updater.exe X Added by the W32/Yodo-C worm.
Update Service updater.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
USIUDF_Eject_Monitor USISrv.exe N Added by Ulead DVD Moviefactory. This pgram monitors your DVD or CD drives and alerts when you eject the media or have no media present.
Microsoft Svchost local services updater.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ThinkVantage System Update UCLauncherService.exe N ThinkVantage System Update service.
Dcom Helper utorrent.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DC6_Check uwasdc.exe X Added by the rogue anti-spyware program WinAntiSpyware.
ERS_Check uwasers.exe X Added by the rogue anti-spyware program WinAntiSpyware.
uwas6cw uwas6cw.exe X Malware related to and installed with the rogue anti-spyware program called WinAntiSpyware 2006 or WinAntiSpyware 2007.
UStorage Server Service UStorSrv.exe U Used by certain USB flash drives that support encryption.
ugdccw UGDCcw.exe X Added by the PCPrivacyTool security risk. PCPrivacyTool is a Security Risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats. This infection is also found with other rogue security programs.
{c704547b-26c0-4222-a034-81653c07b494} ugofuq.dll X Zlob Trojan that installs VirusProtectPro 3.5 and shows fake security alerts from your Windows taskbar.
AdvancedCleaner UADC.exe X Added by the AdvancedCleaner rogue security software. AdvancedCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks.
UADC_104911963 UADCcw.exe X Added by the AdvancedCleaner rogue security software. AdvancedCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks. The number in the name of this startup will be different on each install.
usbmon usbmons.dll X Added by the W32/SillyFDC-AO worm.
UPS COMcontrol upsctrl3.sys X A variant of the Goldun rootkit.
upsctrl0 upsctrl0.dll X Added by a variant of the Trojan.Goldun information stealing Trojan. This infection utilizes the upsctrl3.sys rootkit to hide itself.
{D817EE47-6798-BA2D-1011-5B24CF1C7459} usvr32.exe X A variant of the Backdoor.Bifrose backdoor Trojan.
ugescw ugescw.exe X Added by the ErrClean rogue security software. ErrClean is a misleading application that gives false reports of errors on the computer.
ucdcw ucdcw.exe X Added by the CryptDrive misleading security application. CryptDrive is a misleading application that may give exaggerated reports about potential risks on the computer.
Microsoft usnsvc Service usnsvc.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
uninstx.exe uninstx.exe X Added by the W32.Lecna.H worm. W32.Lecna.H is a worm that spreads by copying itself to mapped drives. It also opens a back door and may download potentially malicious code on to the compromised computer.
USB MS Update USBS.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Userinit Logon Application userinit.exe X Identified as a Spamtrojan variant.
Ultimate Fixer UltimateFixer.exe X Added by the UltimateFixer rogue security product. UltimateFixer is a misleading application that detects and removes privacy violations on the computer. It detects browser cache files, temporary files, and history as privacy violations and displays exagerated alert messages that recommends purchasing a registered version of the software in order to remove detected items.
usnsvc.exe usnsvc.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Microsoft Update update.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
MyCashbag uccbp.exe X Added by the Adware.Mycashbag adware. Adware.Mycashbag is an adware program that displays popup advertisements.
SunshineSpy UNWISE.EXE X Uninstall program for the rogue anti-spyware program called SunshineSpy.
Uninstall UNWISE.EXE X Uninstall program for the rogue anti-spyware program called SunshineSpy.
boardwalk ugbtna.dll X Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar.
<not used> UpDateWinc.exe X Added by the W32.Yahack.A worm. W32.Yahack.A is a worm that spreads through mapped drives. It logs keystrokes, gathers system information, and steals Yahoo! Messenger passwords.
Corporate Microsoft Update uptask.exe X Added by the W32/Rbot-GVB worm and IRC backdoor.
ugcw ugcw.exe X Related to the rogue anti-spyware program called WinSecureAv. This program is installed via the use of malware and display false or exaggerated infection results.
ucookw ucookw.exe X The WinPCDoctor rogue anti-spyware program. This program is installed via the use of malware and display false or exaggerated infection results.
Sygate Personal Firewall un1x.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
UADC_815790765 UADCcw.exe X Related to AdvancedCleaner. AdvancedCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks. The numbers after the UADC_ in the name will be different.
AdvancedCleaner Free UADC.exe X Related to AdvancedCleaner. AdvancedCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks. The numbers after the UADC_ in the name will be different.
Windows update32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
uz uz.exe X Added by the W32/Agent-GGH backdoor worm.
groutiest ucmbegr.dll X Zlob Trojan which installs the Virus Protect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusProtect onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
unsrvc unsrvc.exe X Identified by Kaspersky Anti-Virus as a variant of the Trojan.Win32.VB.bkz Trojan.
graphologists uglgs.dll X Zlob Trojan which installs the VirusProtect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusProtect onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
Digital Patrol Update 5 update.exe U Added by the Digital Patrol anti-malware program.
User Sharing Services usnsvc.exe X A variant of the Win32:IRCBot-CHZ family of worms and IRC backdoor Trojans.
User Sharing Server usnsrv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Userfile Sharing Serv usnsrv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Userfile Sharing Server usnserv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Live Servicer usrserv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ugac ugac.exe X Related to the TrustedAntivirus rogue anti-spyware program. This program is sometimes used by other Rogue anti-spyware programs as well.
ubstcw ubstcw.exe X Related to the AlfaAntivirus rogue anti-spyware program.
Windows Update usnsvc.exe X Added by the W32/Kobot-C worm and IRC backdoor.
Help userinit.exe X Added by the W32.Degnax@mm worm. W32.Degnax@mm is a mass-mailing worm that gathers email addresses from the compromised computer. It also spreads via network/mapped drives. This infection should not be confused with the legitimate C:\Windows\System32\userinit.exe file.
GLSetIT32 update1.exe X Identified as a variant of the OptixPro malware.
Ultimate Cleaner UltimateCleaner.exe X Added by the Ultimate Cleaner rogue anti-spyware program.
User Messages Manager usnmsgs.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Messenger Manager usnmsgr.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Sharing Manager usnsharen.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update update32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update Drive updrvs.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Host usnhost.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Services usnsvcs.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Sharing usrshare.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
USBDeviceService USBDeviceService.exe Y Related to the MyDVD DVD authoring program.
USB Device Server! usbserver.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
User Messages usrmsg.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinUpdater update.exe X Related to the Adware.Deskbar adware program. This program will add a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com.
WebSUpdater upda.exe X Related to the Adware.Deskbar adware program. This program will add a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com.
Microsoft Urlmon urlmon.exe X Added by the Troj/Agent-GOO Trojan.
User Hosting Service usnhost.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSN Manager usnmsn.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Help and Support Service usnsvc.exe X Added by the WORM_RBOT.GEN worm and IRC backdoor.
userinfo32 userinfo32.ggt X Added by the Backdoor.Rustock backdoor rootkit.
Microsoft Internet Firewall Update updater.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Unigray Unigray Antivirus.exe X Added by the Unigray rogue anti-spyware program.
User Sharing Wizard usnshare.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
startkey Update32.exe X Added by the Backdoor.Bifrose backdoor.
uxgrafj uxgrafj.adm X Added by the Backdoor.Rustock backdoor rootkit.
User Debug Manager usndebug.exe X Added by the W32.Spybot.Worm worm and IRC backdoor.
cwriter ucookw.exe X Added by the HardDriveGuard rogue anti-spyware program. This startup entry is used by other rogue anti-spyware products that are in this family.
Transfer Service uiops.exe X Added by the Trojan.Acdropper.C Trojan.
uerj45kj uerj45kj.sys X Added by the Backdoor.Rustock backdoor rootkit.
usbhdd usbhdd.sys X Added by the Trojan.Drondog Trojan.
Uninterruptible Power Supply USP.exe X Added by the Troj/Agent-GVT Trojan.
Messenger Sharing USN Journal Service usnsv.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
uazpiq uazpiq.sys X Added by the Backdoor.Rustock backdoor rootkit.
enswathes uyhjw.dll X Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection.
SecuROM User Access Service UAService.exe Y User Access Service is a SecureROM service that enables users without Windows administrator rights to have the ability to access all SecuROM features.
{Y479C6A0-OTRV-U5KH-S1UE-E0BC10B4E666} UNISNTLV32.exe X Added by the W32/Autorun-EK removable media worm.
UIUCU UIUCU.EXE ? Universal Device Install Application from Conexant Systems, Inc.
HIPS Firewall Helper UmxFwHlp.exe Y Related to the Computer Associate's Personal Firewall.
Windows svchost ups.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Ucu24 Ucu24.sys X Added by the Troj/DwnLdr-HEI Trojan.
Antivirus uav.exe X Added by the Ultimate Antivirus 2008 rogue anti-spyware program.
upsctl upsctl.dll X Identified as a variant of the Trojan.Rootkit.Gen rootkit.
Windows USB Printer unqgod.exe X A variant of the BKDR_RBOT.BKC family of worms and IRC backdoor Trojans.
Uninterruptible Power Supply CRT upscr.sys X Identified as a variant of the Trojan.Rootkit.Gen rootkit.
UPD Client updclient.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
wblogon ubpr01.exe X Added by the Troj/Agent-HFI Trojan.
F5 Networks VPN Adapter urvpndrv.sys Y Added by the F5 networks VPN software for encrypted communication between your computer and a remote network.
F5 Networks StoneWall Filter urfltw2k.sys Y Added by the F5 networks VPN software for encrypted communication between your computer and a remote network.
ArcaBit Update Service update.exe U Related to ArcaVir 2008.
USS USS.exe X Trojan that create fake alerts and popups advertising rogue anti-spyware program. Though the guide below is not for this particular infection, it will remove it.
ULiveServer ULiveServer.exe Y Related to the Unreal Media Server streaming server.
UMediaServer UMediaServer Y Related to the Unreal Media Server streaming server.
updater for windows updater service windows.exe X Added by the Troj/Bckdr-QPE backdoor Trojan.
Cleaner2009 Freeware UCLN.exe X Added by the Cleaner2009 rogue anti-spyware program.
UltraMon UltraMon.exe U UltraMon is a utility for multi-monitor systems, designed to increase productivity and unlock the full potential of multiple monitors.
WInUpdate16 udate32.exe X A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
upascw upascw.exe X Added by the PersonalAntiSpy rogue anti-spyware program.
Windows Updater updater.com X Added by the Troj/Agent-HUS Trojan.
USB Antivirus USBGuard.exe Y Related to USB Disk Security. USB Disk Security protects removable media from becoming infected with malware.
ANTIVIRUS UltraAV.exe X Added by the Ultra Antivirus 2009 rogue anti-spyware program.
explorer UPMSN.exe X Identified as a variant of the Trojan-Downloader.Win32.Banload.woj malware.
uwasfsd uwasfsd.sys X Added by the PersonalAntiSpy rogue anti-spyware program.
NA1Messenger UPSNA1Msgr.exe N Related to the UPS World Ship software.
demobilisation umhzwl.dll X Zlob Trojan which installs the AntivirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install AntivirusTrigger onto your computer without permission. This Trojan pretends to be a fake video codec required to watch videos online.
<not used> userinit.exe Y The userinit.exe is a program that is launched directly after a user logs into Windows. This program restores your profile, fonts, colors, etc for your username. This startup is a required and important system file for Windows.
{Y479C6A0-OTRV-U5KH-S1UE-E0BC10B4E666} UNINSTLV16.exe X Added by the TROJ_RANDSOM.A Trojan.
SoundMax userinit.exe X Added by the W32/Malas-J worm. This infection should not be confused with the legitimate C:\Windows\System32\userinit.exe file.
user user.exe X Added by the Troj/Sivion-B Trojan.
UsbMonitor usbnotify.exe ?

This file is installed with TrueSuite Access Manager developed by AuthenTec Inc. What this particular file does has not been determined.

CamMonitor uCamMonitor.exe Y

This is the service file for ArcSoft Magic-i Visual Effects made by Arcsoft, Inc. which is a webcam application used with video chat.

cbvcs urretnd.exe X Added by the W32/Frethog-C worm.
Update Center Service UpdateCenterService.exe U Service that enables you to find and download updates to your system BIOS, drivers and firmware.
udt udt.dll X Added by the W32/Autorun-VO removable media worm.
UltraMon Utility Driver UltraMonUtility.sys U UltraMon multi-monitor software.
UltraMonMirror UltraMonMirror.sys U Related to the UltraMon multi-monitor software.
<not used> updmngr.exe X Added by the Troj/Agent-JBX. Trojan.
UPNP upnpsvc.exe X Added by the Troj/Clomp-B Trojan.
Ultra Antivir2009 UA2009.exe X Added by the Ultra Antivir2009 rogue anti-spyware program. The folder associated with this malware has a random name.
dorfgwe uret463.exe X Added by the W32/AutoRun-XF removable media worm.
CamMonitor uCamMonitor.exe Y This is the service file for ArcSoft Magic-i Visual Effects 2 HD made by Arcsoft, Inc. which is a webcam application used with video chat.
dorfgwe uret463.exe X Added by the W32/AutoRun-AFV removable media worm.
PCPrivacyDefender Freeware UPSPDAP.exe X Added by the PCPrivacy Defender rogue privacy program.
rad<5randomlettersandnumbers>.tmp umdmgr.exe X Malware file; there may be several present. Other malware files likely present as well.
v USBController.exe X Added by the W32/Autorun-AGU removable media worm.
UnVirex UnVirex.exe X Added by the UnVirex rogue anti-virus program.
USA usa.exe X Added by the USAntiSpy rogue anti-spyware program.
WinSecurity uninstall.exe X Added by the W32.SillyFDC.BCJ worm. W32.SillyFDC.BCJ is a worm that spreads by copying itself to removable drives.
Microsoft USB Windows2 Driver usbautotuner.exe X Added by the W32.SillyFDC.BCL removable media worm.
user users.exe X Added by the removable media worm.
UsrClassEx UsrClassEx.exe X Added by the Troj/Agent-KPU Trojan.
UltimateServices ultsvcs.exe X Added by the Troj/Agent-LGT Trojan.
Microsoft USB Bus Controller usbctl.exe X Added by the WORM_ASPXOR.AB worm.
MicrosoftCorp update.exe X Added by the W32/Autorun-ASG removable media worm.
User Profile Hive Cleanup uphclean.exe Y When users experience logoff or other profile problems in certain Windows operating systems, the solution is to install the User Profile Hive Cleanup Service by Microsoft Corporation.
USBcillin USBcillin.exe X Added by the Troj/USBcill-A removable media worm.
{22d6f312-b0f6-11d0-94ab-0080c74c7e95} unregmp2.exe Y Microsoft Windows Media Player.  This key is what shows the WMP icon in the start menu.  Another key is responsible for the actual shortcut itself.

File path may also be %windir%\inf\unregmp2.exe
UfSeAgnt.exe UfSeAgnt.exe Y

This is a key file for Trend Micro Security Suite.  It is important for this file to run at startup so the security program will function when the computer boots.

Taskman ufxw.exe X Added by the Troj/VBInj-D Trojan.
User Protection usrprot.exe X Added by the User Protection rogue anti-spyware program.
avscan Usbconeted.exe X Added by the Troj/Provis-A Trojan.
Your Protection urpprot.exe X Added by the Your Protection rogue anti-spyware program.
updtr.exe updtr.exe X Added by the Troj/Agent-MXG Trojan.
OTFSDMS UNCFATDMS.exe Y  UNC/FAT is an add-in by Microsoft to Windows Desktop Search for use on networks to index shared folders and FAT drives.  Must run in order for the indexing to work.  If you don't want this feature, uninstall the add-in.
Antivirus 2010 us?rinit.exe X Added by the Antivirus 2010 Security Centre and Antivirus 2010rogue anti-spyware programs.
{6BF52A52-394A-11d3-B153-00C04F79FAA6} unregmp2.exe Y Microsoft Windows Media Player Setup Utility.  This key creates the shortcuts from the WMP icon in the start menu to the player itself.
TotalMedia Backup Monitor uBBMonitor.exe U

Installed with ArcSoft's program TotalMedia Backup used to backup pictures, videos, and other documents.  May be bundled with some Hitachi drives. Note: Some versions of the software include a recording element.  When it does, and Record is part of the file path and command where indicated by the brackets.  That version can also copy CD's and DVD's and search for media files.

Plug and Play umpnpmgr.dll Y This service enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Utility Mangserver Utility Mang.exe X Added by the Mal/Kaukalo-A Trojan.
Trend Micro Client Framework UIWatchDog.exe Y

Part of the UniClient portion of some TrendMicro security products, this file monitors the Session Agent file and if it seems to have stopped abnormally, UIWatchDog.exe will attempt to restart it.

upd32.exe upd32.exe X Added by the Troj/Agent-PDS Trojan.
UNrcJcrVSu.exe UNrcJcrVSu.exe X Added by the Troj/Agent-PPD Trojan.
McAfeeUpdaterUI UdaterUI.exe Y

Installed with various McAfee security products, this file is part of the McAfee Management Agent and is one of two files responsible for the user interface for updates and for the Agent icon in the system tray.

 

update Update.scr X Added by the W32/VB-FMT worm.
usxxxxxxxx.exe usxxxxxxxx.exe X Added by the TSPY_SPYEYE.EXEI Trojan.
<not used> usrinit.exe X Added by the Troj/Calelk-A Trojan.
usbdriverx.exe usbdriverx.exe X Added by the TSPY_SPYEYE.CE spyware.
Windows Services upterd.exe X Added by the W32/Autorun-BNL removable media worm.
webags update.exe X Webags adware.
USB Safely Remove USBSafelyRemove.exe Y USB Safely Remove is a replacement for the Windows safe removal tool for removable media devices.
<random chars> utilmanh.exe X Unknown malware.
UTab utab.exe X Identified as a variant of the Adware/UTab malware.
Windows Generic Host Process uvchost.exe X Added by the Troj/VB-FPI Trojan.
McUpdate Update.exe X Added by the Troj/Agent-TUH Trojan.
unit unit.exe X Unknown malware.
Apple Mobile USB Driver usbaapl64.sys Y Apple Mobile Device USB Driver.
ApnUpdater Updater.exe N This file is bundled with the Ask Toolbar which in turn is often bundled without user's knowledge with other software.  The file is an update for Ask Partner Network - totally unneeded to use the search features for those that want it.  Ask Toolbar itself is generally unwanted.
Upfsfm Upfsfm.exe X Added by the Troj/Mdrop-DVU Trojan.
userlog userlog.exe X Added by the Troj/Luiha-AP Trojan.
Network List System Service ucsvcsh.exe X Added by the ACCDFISA Ransomware.
AdobeAAMUpdater-1.0 UpdaterStartupUtility.exe N Installed with Adobe Application Manager used with Adobe's Creative Suite, for example, this file is the updater for the application manager.
engel updates.exe X Added by the Mal/Cossta-F malware.
WD Backup Monitor uBBMonitor.exe U Preinstalled on certain Western Digital external drives, WD Backup is a customized version of ArcSoft's TotalMedia Backup used to backup pictures, videos, and other documents.
TotalMedia BackUp & Recorder Monitor uBBMonitor.exe U Installed with ArcSoft's program TotalMedia Extreme, this file is part of the Backup & Record and Utilities part of the software.
UNCFAT DMS UNCFATDMS.exe Y  UNC/FAT is an add-in by Microsoft to Windows Desktop Search for use on networks to index shared folders and FAT drives.  Must run in order for the indexing to work.  If you don't want this feature, uninstall the add-in
Skype Updater updater.exe U Installed with the software for Skype, this is the service for automatically updating the software.  The software may be updated manually.
walarm update.exe X A Korean rogue anti-spyware program.
Updater for Analytic Tool Updater for Analytic Tool X Windows Task added by the Overlook potentially unwanted program. This task is used to update the program's configuration.
Volaro Update Updater.exe X Related to the Vonteera adware.
upmbot_gb_508.exe upmbot_gb_508.exe X This startup entry checks for new updates for the MyBestOffersToday adware.
upefas_en_110010107.exe upefas_en_110010107.exe X Added by the eFast Browser adware. This program impersonates Google Chrome and displays advertisements into web sites that you visit.
upgmsd_us_031010037.exe upgmsd_us_031010037.exe X Added by the Games Desktop adware. Games Desktop is an adware program that displays advertisements on your Windows desktop.
Update Mgr SearchWindow updater.exe X Added by the Search Window adware program.
Update Mgr SeeResultsHub updater.exe X Added by the See Results Hub adware program.
Update Mgr SearchMyWindow updater.exe X Added by the Search My Window browser hijacker.
Update Mgr OurSearchWindow updater.exe X Added by the Our Search Window browser hijacker.
Update Mgr GenerousDeal updater.exe X Added by the Generous Deal browser hijacker .
Update Mgr FindSearchWindow updater.exe X Added by the Find Search Window browser hijacker.
Update Mgr InnovateDirect updater.exe X Added by the Innovate Direct browser hijacker.
Update Mgr elementsperuse updater.exe X Added by the Elements Peruse browser hijacker.
Update Mgr CashKitten updater.exe X Added by the Cash Kitten browser hijacker.
Update Mgr JazzSpot updater.exe X Added by the Jazz Spot browser hijacker.
Update Mgr Buzzdoc updater.exe X Added by the Buzzdoc browser hijacker.
Update Mgr NextProgram updater.exe X Added by the Next Program browser hijacker.
Update Mgr nicertogether updater.exe X Added by the Nicer Together browser hijacker.
Update Mgr PopBubbles updater.exe X Added by the Pop Bubbles browser hijacker.
Update Mgr SearchMoreKnow updater.exe X Added by the SearchMoreKnow browser hijacker.
Update Mgr SearchKnow updater.exe X Added by the Search Know adware.
Update Mgr SearchWindowResults updater.exe X Added by the Search Window Results browser hijacker.
Update Mgr OutrageousDeal updater.exe X Added by the Outrageous Deal browser hijacker.
Update Mgr StudySearchWindow updater.exe X Added by the Study Search Window browser hijacker.
userlog userlog.exe X Added by the Coverton Ransomware.
Update Mgr SearchNewWindow updater.exe X Added by the Search New Window browser hijacker.
Update Mgr SearchWebKnow updater.exe X Added by the Search Web Know browser hijacker.
Update Mgr TideSearch updater.exe X Added by the Tide Search browser hijacker.
Update Mgr SearchVoyage updater.exe X Added by the Search Voyage browser hijacker.
Update Mgr HooplaSearch updater.exe X Added by the the HooplaSearch browser hijacker.
Update Mgr SearchExpanse updater.exe X Added by the Search Expanse browser hijacker.
Update Mgr SearchAdventure updater.exe X Added by the Search Adventure browser hijacker.
Window Route Manager Update updservice.exe X Added by the Windows Route Manager.

Login

Remember Me
Sign in anonymously