|
Name
|
Filename
|
Status
|
Description
|
|
com servoce
|
|
|
|
|
3c1807pd
|
3cmlink.exe 3cpipe-3c1807pd
|
Y
|
3Com WinModem driver. See here for more WinModem information
|
|
3capplnk
|
3capplnk.exe
|
Y
|
US Robotics Modem driver
|
|
3Cmlink
|
3CmlinkW.exe
|
Y
|
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinMod ... Read More
|
|
3dfx Tools
|
3dfxCmn.dll
|
Y
|
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards ... Read More
|
|
3dfxv2ps.dll
|
3dfxv2ps.dll
|
Y
|
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards ... Read More
|
|
3ware 3DM
|
3dm.exe
|
Y
|
Monitors status of the disk array on 3ware IDE RAID controllers
|
|
FoolProofSweep
|
<unknown>
|
Y
|
Part of FoolProof Security PC security software from SmartStuff
|
|
Initialize8x8
|
8x8_init.exe
|
Y
|
Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay ... Read More
|
|
VS.VSN
|
[unknown]
|
Y
|
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
|
|
3DMouse.EXE
|
3DMouse.EXE
|
Y
|
Dritek System Inc. 3D Mouse drive
|
|
vs.vsn
|
|
Y
|
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
|
|
2kadiras
|
2kadiras.exe
|
Y
|
Allied_Telesyn AT series router/modem related - apparently required
|
|
9xadiras
|
9xadiras.exe
|
Y
|
Allied_Telesyn AT series router/modem related - apparently required ... Read More
|
|
usrpda
|
USRmlnkA.exe
|
Y
|
US_Robotics modem driver ... Read More
|
|
Kodak Camera Connection Software
|
KodakCCS.exe
|
Y
|
Kodak DC File System Driver
|
|
<not used>
|
r3hook.dll
|
Y
|
Related to Kaspersky Antivirus.
|
|
<not used>
|
eNetHook.dll
|
Y
|
Related to Acer's eNet Management software for Acer laptops.
|
|
%cmpmixtitle%
|
Unknown
|
N
|
Possibly related to C-Media Mixer Control panel?
|
|
3cdminic
|
3CDMINIC.EXE
|
N
|
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
|
|
3ComDMIAgent
|
3CDMINIC.EXE
|
N
|
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
|
|
3dfx Task Manager
|
3dfxMan.exe
|
N
|
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs ... Read More
|
|
AccuWeather.com® Desktop
|
<unknown>
|
N
|
Desktop weather from AccuWeather.com
|
|
AIMster
|
<unknown>
|
N
|
Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs ... Read More
|
|
Compaq Video CD Watcher
|
<unknown>
|
N
|
For Compaq PC's. MPEG viewer
|
|
HP Info Express
|
<unknown>
|
N
|
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
|
|
HP Updates
|
<unknown>
|
N
|
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
|
|
Imesh
|
<unknown>
|
N
|
Imesh is a file sharing system
|
|
Imesh Auto Update
|
<unknown>
|
N
|
Update check for the Imesh file sharing system. Turn the update off under "options" ... Read More
|
|
Introduction-Registration
|
<unknown>
|
N
|
For Compaq PC's. Should only run first time, PC Introduction & Compaq registration ... Read More
|
|
LS120 Superdisk
|
<unknown>
|
N
|
Supposed to accelerate transfer rate on LS-120, contributes to system lockups
|
|
McAfee Winguage
|
<unknown>
|
N
|
Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to ... Read More
|
|
One Touch Monitor
|
1tou~2.exe
|
N
|
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
|
|
OneTouchMonitor
|
1tou~2.exe
|
N
|
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
|
|
ONETOU~2
|
1tou~2.exe
|
N
|
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
|
|
Operator
|
<unknown>
|
N
|
Media Pilot operator, in Win.ini. Locks port open
|
|
Printer
|
[path to file]
|
N
|
Added by the LOWTAPER TROJAN!
|
|
SB Audigy 2 Startup Menu
|
/l:eng
|
N
|
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appe ... Read More
|
|
Startup
|
<unknown>
|
N
|
Related to an Iomega drive
|
|
TGCMG
|
<unknown>
|
N
|
Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work ... Read More
|
|
Usrobotics Online Registration
|
<unknown>
|
N
|
Pop-up reminding customers to register their products online at US Robotics
|
|
Windows Eyes
|
<unknown>
|
N
|
For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hea ... Read More
|
|
DumpFaultCheck
|
%system%
|
N
|
Added by the W32/Scanbot-A worm and IRC backdoor. Though this infection adds these entries, they have no effect on your computer other than open the ... Read More
|
|
49ersScreenServer
|
49ersScreenServer.exe
|
N
|
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
|
|
49ersScreenServerSvc
|
49ersScreenServer.exe
|
N
|
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
|
|
MEMSWEEP2
|
<random locations>
|
N
|
Added by the Sophos Anti-Rootkit security software. This service is only used when the software is scanning your computer. Otherwise, it can be remo ... Read More
|
|
000StTHK
|
000StTHK.exe
|
U
|
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output ... Read More
|
|
00THotkey
|
00THotKey.exe
|
U
|
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. ... Read More
|
|
12Ghosts Popup-Killer
|
12popup.exe
|
U
|
12Ghosts Popup-Killer
|
|
2wSysTray
|
2portalmon.exe
|
U
|
2Wire Homeportal user interface
|
|
3Deep Control Panel
|
3DeepCTL.EXE
|
U
|
From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games ... Read More
|
|
3DLabsHelperDemon
|
3dldemon.exe
|
U
|
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits ... Read More
|
|
3qdctl.exe
|
3qdctl.exe
|
U
|
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determine ... Read More
|
|
BelNotify
|
[path] NPBelv32.dll, RunDll32_BelNotify
|
U
|
"BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page ... Read More
|
|
EDRestore
|
<unknown>
|
U
|
Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP" ... Read More
|
|
HP RecordNow
|
<unknown>
|
U
|
From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used." ... Read More
|
|
Primax 3D Mouse
|
3dmoused.exe
|
U
|
Enables the scroll button on the Primax 3-D Scroll mouse
|
|
SMS Win9x Message Agent
|
<unknown>
|
U
|
This program assigns a user to a Systems Management Server site
|
|
WheelMouse
|
4DMAIN.EXE
|
U
|
Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may pro ... Read More
|
|
ZeroAds
|
0
|
U
|
ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually ... Read More
|
|
AWatch
|
Awatch.exe
|
U
|
Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products. ... Read More
|
|
$Volumouse$
|
volumouse.exe
|
U
|
Having this program started allows you to control the sound volume on your computer by using the mouse wheel on your mouse. ... Read More
|
|
PPSVC
|
[path to Spyware.PCPolice]
|
U
|
Added by the PC Police surveillance program. This program should be uninstalled if it was not installed by yourself. ... Read More
|
|
Plug and Play Device Manager
|
$sys$DRMServer.exe
|
U
|
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
|
|
$sys$cor.sys
|
$sys$cor.sys
|
U
|
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
|
|
legalnoticeapplication
|
""
|
U
|
Added by the Spyware.PCProwler surveillance software. If this program was not installed by yourself, it should be uninstalled immediately. ... Read More
|
|
ES Current Services
|
[FILE NAME].exe
|
U
|
Added by the Spyware.123Keylogger surveillance software. pyware.123Keylogger is a spyware program that logs user activity on the compromised computer, ... Read More
|
|
ShowLOMControl
|
(No file name)
|
U
|
Shows as O4 - HKLM\..\Run: [ShowLOMControl] (note strange symbol here) HKLM\Software\Microsoft\Windows\Current Version\Run ShowLOMControl Reg_DWORD ... Read More
|
|
hsys
|
HSYS.EXE
|
U
|
Added by the Spyware.ExpressKeylog surveillance software. Spyware.ExpressKeylog is a spyware program that records keystrokes on the computer. This sof ... Read More
|
|
(default)
|
[random filename].exe
|
X
|
Added by the BLACKMAL WORM!
|
|
*WinLogon
|
[trojan path]
|
X
|
Added by the VUNDO TROJAN!
|
|
180adsolution
|
180adsolution.exe
|
X
|
180Solutions/N-Case adware variant
|
|
180ax
|
180ax.exe
|
X
|
180Solutions/N-Case adware variant
|
|
1on1
|
1on1.exe
|
X
|
Adult content dialler
|
|
2thousandbuck
|
[path to file]
|
X
|
Added by the RANKY.L TROJAN!
|
|
3D Text
|
3D Text.scr
|
X
|
Added by the JERMY.A WORM!
|
|
5-2-46-112
|
5-2-46-112.exe
|
X
|
Adult content pop-up dialler. Removal instructions here
|
|
;Rundll
|
[filename]
|
X
|
Added by the PWSLEGMIR.E TROJAN!
|
|
@tour_ww
|
@tour_ww[1].exe
|
X
|
Adult content dialler
|
|
ACCDEFRAGINFO
|
[path to worm]
|
X
|
Added by the DARBY-O WORM!
|
|
AddClass
|
[Installation_Path]
|
X
|
Added by the STARTPAGE.F TROJAN!
|
|
AHU
|
[path to worm]
|
X
|
Added by the ANACON-B WORM!
|
|
AlevirOld
|
[worm filename]
|
X
|
Added by the OPASERV.G WORM!
|
|
alkasr
|
ÎäÒíÑ.exe
|
X
|
Added by the BALKART TROJAN!
|
|
AOL Messenger
|
[random filename]
|
X
|
Added by an unidentified VIRUS, WORM or TROJAN!
|
|
App.EXEName
|
[path to worm]\.exe
|
X
|
Added by the BODIRU WORM!
|
|
ara-key
|
[random filename]
|
X
|
Added by the ANTINNY WORM!
|
|
*ms setup
|
[random file name]
|
X
|
Virtumondo adware, also known as the VUNDO TROJAN! ... Read More
|
|
Avril Lavigne - Muse
|
[random filename]
|
X
|
Added by the AVRIL-A WORM!
|
|
Band-Aid
|
[path to file]
|
X
|
Added by the RANKY.O TROJAN!
|
|
Bnexe
|
[random filename]
|
X
|
Added by the KITRO.D (or ARGEN.A) WORM!
|
|
Bonzi Buddy
|
<unknown>
|
X
|
Spyware - read here for information and here for removal instructions
|
|
BrasilOld
|
[worm filename]
|
X
|
Added by the OPASERV.P WORM!
|
|
cAgOu
|
[filename].hta
|
X
|
Added by the KAKWORM WORM!
|
|
ccApp
|
[random filename]
|
X
|
Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus ... Read More
|
|
Cekirge
|
[path to worm]
|
X
|
Added by the KERGEZ.A WORM!
|
|
center
|
[random name]32.exe
|
X
|
Added by the BOFRA.A WORM!
|
|
clock
|
[various filenames]
|
X
|
LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe ... Read More
|
|
Configuration
|
[filename]
|
X
|
Added by the SDBOT-ML WORM!
|
|
Control handler
|
***********.exe [* = random char]
|
X
|
CoolWebSearch parasite variant
|
|
ControlPanel
|
[path] cmd32.exe internat.dll, LoadKeyboardProfile
|
X
|
Awmcash.biz foistware
|
|
Cryptographic Service
|
******.exe [* = random char]
|
X
|
Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!
|
|
CSRSWIN
|
[trojan filename]
|
X
|
Added by the WINSHELL.50 TROJAN!
|
|
CSRSX
|
[trojan filename]
|
X
|
Added by the WINSHELL.50.B TROJAN!
|
|
CTime
|
[path to trojan]
|
X
|
Added by the HTTPDOS TROJAN!
|
|
cyberfree.exe
|
****.dat [* = random char]
|
X
|
Unidentified adware
|
|
Danton*
|
[random filename]
|
X
|
Added by the DANTON TROJAN! where * = random number
|
|
DATABASE MySql
|
[path] repcale.exe [path] beird.exe
|
X
|
Added by a variant of the RANDON.AN WORM!
|
|
Disk Master
|
[trojan name]
|
X
|
Added by the DISTER TROJAN! - a spam relayer
|
|
DLL Service Manager
|
[path to worm]
|
X
|
Added by the RPCBOT.F TROJAN!
|
|
DSAcass
|
[path to file]
|
X
|
Added by the RANKY.M TROJAN!
|
|
educational writer
|
[random filename]
|
X
|
Added by the RBOT-LZ WORM!
|
|
Explorer
|
[path to worm]
|
X
|
Added by the AUTEX WORM!
|
|
G00123
|
[worm filename]
|
X
|
Added by the BUGBROS WORM!
|
|
GDAX
|
[path to backdoor]
|
X
|
Added by the RANKY.K TROJAN!
|
|
GustavVED
|
[filename].exe
|
X
|
Added by the OPASERV.H WORM!
|
|
hen
|
[filename].exe
|
X
|
Added by the TARNO.G TROJAN!
|
|
hpsysconf1
|
[random filename]
|
X
|
Added by a variant of the VIVIA.A TROJAN!
|
|
ICQ Center
|
[path to worm]
|
X
|
Added by the RANDIN WORM!
|
|
ICQ Lite Messenger
|
[random filename]
|
X
|
Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program File ... Read More
|
|
InterceptedSystem
|
[path to worm]
|
X
|
Added by the ANACON-B WORM!
|
|
Internal
|
[trojan filename]
|
X
|
Added by the SMOTHER and TRANSLAT TROJANS!
|
|
Irwftp
|
[path to trojan]
|
X
|
Added by the BANCOS.CR TROJAN!
|
|
ist service uninstall
|
[random filename]
|
X
|
ISTBar parasite related
|
|
JavaUpdate0.07
|
[filename]
|
X
|
Added by the JUPDATE TROJAN!
|
|
KAVutil
|
[worm filename]
|
X
|
Added by the WINTOO.B WORM!
|
|
KAZAACuf
|
9
|
X
|
Added by the KITRO.D (or ARGEN.A) WORM!
|
|
kern64dll
|
[random filename]
|
X
|
Added by the TARNO.J TROJAN!
|
|
lar
|
[trojan filename]
|
X
|
Added by the ROXY.C TROJAN!
|
|
LiveUpdate
|
[Windows username]05.exe
|
X
|
Added by the LINEAGE TROJAN!
|
|
load32
|
1111a.exe
|
X
|
Added by the DUMARU.AH WORM!
|
|
LoadOrderVerification
|
[random filename]
|
X
|
Added by the TRON.A TROJAN!
|
|
LoadWindowsFile
|
[filename]
|
X
|
Added by the DELF.B TROJAN! where [filename] is the infected file
|
|
Locator Service
|
[filename]
|
X
|
Added by the AGOBOT-KY TROJAN!
|
|
Login Service
|
[path to file]
|
X
|
Added by the MIGMAF TROJAN!
|
|
LowVersionSupport
|
[filename]
|
X
|
Added by the LASTRAS TROJAN!
|
|
lsass
|
[path to lsass.exe]
|
X
|
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup! ... Read More
|
|
Mantis
|
[filename]
|
X
|
Added by the MANTIBE VIRUS!
|
|
MatrixScreen
|
[filename]
|
X
|
Added by the MATRIXSCREEN TROJAN!
|
|
mdetect
|
[path to trojan]
|
X
|
Added by the SPABOT TROJAN!
|
|
messnger
|
[worm filename]
|
X
|
Added by the DELODER WORM!
|
|
Mickey Mouse Cereal
|
[random filename].exe
|
X
|
Added by the RANKY.Q TROJAN!
|
|
MicroLoad
|
[random filename]
|
X
|
Added by the DARBY WORM!
|
|
Microsoft Corporation
|
[random filename]
|
X
|
Added by various VIRUSES, WORMS & TROJANS!
|
|
Microsoft Diagnostic
|
[random filename]
|
X
|
Added by the ACEBOT TROJAN!
|
|
Microsoft IT Update
|
[random filename]
|
X
|
Added by a variant of the RBOT WORM!
|
|
Microsoft Java Windows Update
|
[filename]
|
X
|
Added by the RBOT-DZ WORM!
|
|
Microsoft Locals 332
|
[random filename]
|
X
|
Added by the RBOT-KU WORM!
|
|
microsoft software
|
****.exe E255 [* = random char]
|
X
|
Added by an unidentified WORM or TROJAN!
|
|
Microsoft Synchronization Manager
|
___synmgr.exe
|
X
|
Added by the MASLAN.A or MASLAN.C WORMS!
|
|
Microsoft Tray
|
[random filename]
|
X
|
Added by the DELF.BZ TROJAN!
|
|
Microsoft Update Loader
|
[random filename]
|
X
|
Added by a variant of the RBOT WORM!
|
|
Microsoft Update Machine
|
[random filename]
|
X
|
Added by a variant of the RBOT WORM!
|
|
Microsoft Windows DHCP
|
___r.exe
|
X
|
Added by the MASLAN.A or MASLAN.C WORMS!
|
|
Microsofts Security Manager
|
****.exe [**** = random char]
|
X
|
Added by the RBOT-WH TROJAN!
|
|
MicrosoftWindows
|
[various filenames]
|
X
|
MagicSearch - a CoolWebSearch parasite variant
|
|
MS-HTML
|
[random filename]
|
X
|
Added by the LATINUS.15 TROJAN!
|
|
MsgApi
|
[path to file]
|
X
|
Added by the DEDLER-D TROJAN!
|
|
Msgmgr
|
[path to worm]
|
X
|
Added by the BABYBEAR WORM!
|
|
MSKCES32
|
[random filename]
|
X
|
Added by the CLONER TROJAN!
|
|
Mspatch69
|
[path to trojan]
|
X
|
Added by the MPROX TROJAN!
|
|
MSSGisg
|
[path to file]
|
X
|
Added by the RANKY.N TROJAN!
|
|
mssvc
|
[path to trojan]
|
X
|
Added by the PSK TROJAN!
|
|
mswspl
|
[random filename]
|
X
|
Added by the SMALL.IQ TROJAN!
|
|
Myapp
|
[filename]
|
X
|
Added by the FATEE.B WORM!
|
|
Narrator
|
******.exe [* = random char]
|
X
|
Transponder/VX2 related adware
|
|
NAV Live Update
|
[path to worm]
|
X
|
Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec ... Read More
|
|
NavScan
|
[filename]
|
X
|
Added by the OBSORB TROJAN!
|
|
NBT System alias
|
[path] repcale.exe [path] beird.exe
|
X
|
Added by a variant of the RANDON.AN WORM!
|
|
Nero.ma
|
***.exe [*** = 2 to 3 digits]
|
X
|
Added by the JONBARR.D WORM!
|
|
Network Host Controller
|
[path to trojan]
|
X
|
Added by the WHISPER TROJAN!
|
|
Network Security Guard
|
**********.exe [* = random char]
|
X
|
CoolWebSearch parasite related
|
|
Nocana
|
[path to worm]
|
X
|
Added by the ANACON-B WORM!
|
|
nssysconf
|
[random filename]
|
X
|
Added by the VIVIA.A TROJAN!
|
|
Ntech.patchs
|
[trojan filename]
|
X
|
Added by the LEMIR.G TROJAN!
|
|
NTP Server
|
[path to trojan]
|
X
|
Added by the RANKY.F TROJAN!
|
|
Nvid
|
[8 random charachters]
|
X
|
Unidentified adware
|
|
OLE
|
[filename]
|
X
|
Added by the STAWIN or TARNO.D TROJANS!
|
|
PAV.EXE
|
%Number%
|
X
|
Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number
|
|
PGStub.exe
|
[various filenames]
|
X
|
Unidentified adware
|
|
pmc
|
764.exe
|
X
|
Adult content dialler
|
|
pnpsvc_lock
|
******.exe [* = random digit]
|
X
|
Browser hijacker
|
|
print sharing
|
[path] hidden32.exe [path] explorer.exe
|
X
|
Added by the ZCREW.B TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) ... Read More
|
|
PrinterSpool
|
|