|
The table below includes any process titles beginning with numbers, from which further information can be found by clicking on the process title. The icon beside the information can be used to quickly determine if this is a safe file in combination with the key below:
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z] |
Processes beginning with numbers:
| File Type | Process Name and Information |
![]() |
Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field |
![]() |
Added by the IRCBOT-ZL TROJAN! |
![]() |
!1_pgaccount
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
![]() |
!1_ProcessGuard_Startup
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
![]() |
!AVG Anti-Spyware
Part of AVG Anti-Spyware from Grisoft |
![]() |
!ewido
Part of Ewido anti-spyware |
![]() |
!NoLoad
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
![]() |
#NAME?
Internet Security Suite used by ISPs to protect customers against many attacks |
![]() |
$EnterNet
Connection manager for the EnterNet ISP. You can also use RASPPOE |
![]() |
$sys$cmp
Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
![]() |
$sys$crash
Added by the WELOMOCH TROJAN! |
![]() |
$sys$crash
Added by the WELOMOCH TROJAN! |
![]() |
$sys$crash
Added by the WELOMOCH TROJAN! |
![]() |
$sys$drv
Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
![]() |
$sys$momomomochin
Added by the WELOMOCH TROJAN! |
![]() |
$sys$momomomochin
Added by the WELOMOCH TROJAN! |
![]() |
$sys$momomomochin
Added by the WELOMOCH TROJAN! |
![]() |
$sys$umaiyo
Added by the WELOMOCH TROJAN! |
![]() |
$sys$umaiyo
Added by the WELOMOCH TROJAN! |
![]() |
$sys$umaiyo
Added by the WELOMOCH TROJAN! |
![]() |
$Volumouse$
Volumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse" |
![]() |
$WindowsRegKey%update
Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
![]() |
%cmpmixtitle%
Possibly related to C-Media Mixer Control panel? |
![]() |
%FP%012-L2TP fts.exe
012.Net.il Israeli ISP software front-end |
![]() |
%FP%012-L2TP FWPortal.exe
012.Net.il Israeli ISP dial-up software |
![]() |
%FP%1776 Internet fts.exe
1776 Internet US ISP software ISP software front-end |
![]() |
%FP%1776 Internet FWPortal.exe
1776 Internet US ISP dial-up software |
![]() |
%FP%AIRTEL fts.exe
Bharti Airtel Broadband - Indian ISP software front-end |
![]() |
%FP%Barak013 fts.exe
Barak013 Israeli ISP software front-end |
![]() |
%FP%Barak013 FWPortal.exe
Barak013 Israeli ISP dial-up software |
![]() |
%FP%Friendly fts.exe
Friendly ISP software front-end |
![]() |
(*)API Machine
Homepage hijacker, see here (* = any digit) |
![]() |
(*)Run
Homepage hijacker, see here (* = any digit) |
![]() |
(default)
Added by the BLACKMAL WORM! |
![]() |
(default)
Added by the HESIVE.B TROJAN! |
![]() |
(Default)
Added by the DOWNLD-ABF TROJAN! |
![]() |
(L4r1$$4) (4nt1) (V1ruz)
Added by the ASSIRAL.B WORM! |
![]() |
*Bandook
Added by an unidentified TROJAN - see here |
![]() |
*JanisRuckenbrodII
Added by the POPS WORM! |
![]() |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
*Microsoft Update
Added by the STMU TROJAN! |
![]() |
*MS Setup
Virtumondo adware, also known as the VUNDO TROJAN! |
![]() |
*MSConfig32
Detected by F-secure as the OBFUSCATED.GP TROJAN! |
![]() |
*Security Center
Added by the SDBOT.BRO WORM! |
![]() |
*StateMgr
Windows ME default for System Restore. Do NOT disable! |
![]() |
*windows update
Added by the RBOT-QU WORM! |
![]() |
*windows update
Added by the RBOT-PG WORM! |
![]() |
*windows update
Added by the SPYBOT.HUR WORM! |
![]() |
*windows update
Added by the RBOT-PO WORM! |
![]() |
*windows update
Added by the RBOT-SY WORM! |
![]() |
*windows update
Added by the SPYBOT.PR WORM! |
![]() |
*windows update
Added by the SDBOT.AVD WORM! |
![]() |
*windows update
Added by the RBOT.AOS WORM! |
![]() |
*windows update
Added by a variant of the RBOT WORM! |
![]() |
*Windows [filename] Checker
Added by the KEDEBE-B WORM! |
![]() |
*WindowsAudio
Added by the AGENT-TH WORM! |
![]() |
*WinLogon
Added by the VUNDO TROJAN! |
![]() |
*winstats
Added by the GARGAFX TROJAN! |
![]() |
*wuauclt.exe
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
![]() |
,main drive Loader
Suspected malware as it appears in 3 different registry locations - see here |
![]() |
-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+
Added by the ASSIRAL.B WORM! |
![]() |
..
Added by the DLOADR-ASH TROJAN! |
![]() |
.mscdr
Added by the WEBUS.C TROJAN! |
![]() |
.mscdr
Added by the WEBUS.D TROJAN! |
![]() |
.mscdsr
Added by the CR TROJAN! |
![]() |
.mscsbl
Added by the CMQ TROJAN! |
![]() |
.msfupdate
Added by the ALLOCUP.A WORM! |
![]() |
.mssecure
Added by the DDOS_BOXED.X TROJAN! |
![]() |
.NET config
?? |
![]() |
.NET.
Added by the DELF.AYF WORM! |
![]() |
.norton
Added by the BOXED-H TROJAN! |
![]() |
.nvsvc
Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
![]() |
.nvsvcb
Added by the BOXED.CG TROJAN! |
![]() |
.Prog
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
![]() |
.Prog
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
![]() |
.protected
Smitfraud variant |
![]() |
.svchost
Added by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
![]() |
.TEXTCONV
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
![]() |
.TEXTCONV
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
![]() |
.WMAudio
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
![]() |
.WMAudio
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
![]() |
/l:eng
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
![]() |
0
PrivateEye surveillance software. Uninstall this software unless you put it there yourself |
![]() |
000hpdllhos
LZIO.com adware downloader |
![]() |
000StTHK
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...) |
![]() |
0050726-007-i32-1
Added by the BANCBAN-EC TROJAN! |
![]() |
00DSKSVR00
Related to Advanced Desktop Shield |
![]() |
00DSKSVR01
Related to Advanced Desktop Shield |
![]() |
00PCTFW
PC Tools Firewall Plus - "powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network" |
![]() |
00TCrdMain
Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards |
![]() |
00THotkey
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
![]() |
00THotkey
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
![]() |
0190 Warner
Anti-dialer program (Germany) |
![]() |
01:00
HP utility for monitoring when and how many recoveries have been done |
![]() |
0900 Warner
Anti-dialer program (Germany) |
![]() |
0mcamcap
Added by the COSIAM-H TROJAN! |
![]() |
0utlook Express
Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o" |
![]() |
1
Added by the ESTEEMS TROJAN! |
![]() |
1
Added by the BANCOS.V TROJAN! |
![]() |
1
Added by the BANCOS.X TROJAN! |
![]() |
1&1 EasyLogin
1&1 EasyLogin - quick access to webhost 1&1's Control Panel, Web-Mail and other applications via the System Tray |
![]() |
1029BB4B-16A9-4E77-AA3D-96930BD68EEC
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
1111swapmgr.exe
Added by the IC TROJAN! |
![]() |
123456
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
![]() |
12Ghosts Backup
12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup" |
![]() |
12Ghosts Clip
12Ghosts Clip - "Screen shots made easy" |
![]() |
12Ghosts JustAWindow
12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see" |
![]() |
12Ghosts Popup-Killer
12Ghosts Popup-Killer |
![]() |
12Ghosts SaveLayout
12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons" |
![]() |
12Ghosts SetColor
12Ghosts SetColor - "Change your desktop icon text colors, also to transparent" |
![]() |
12Ghosts ShowTime
12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones" |
![]() |
12Ghosts Synchronize
12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet" |
![]() |
12Ghosts Tower
12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)" |
![]() |
12Ghosts TrayProtect
12Ghosts TrayProtect - "Hide tray icons, restore after a crash" |
![]() |
12Ghosts Wash
12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files" |
![]() |
17779Proj2002
?? |
![]() |
180adsolution
NCase adware |
![]() |
180ax
NCase adware |
![]() |
180ClientStubInstall
180Solutions adware related |
![]() |
180ClientStubInstall
180Solutions adware related |
![]() |
180ClientStubInstall
180Solutions adware related |
![]() |
1916435341.exe
Added by the DLOADR-AXU TROJAN! |
![]() |
196_150_ni
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
![]() |
197_150_ni_3
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
![]() |
1A:MacVisionTrayMonitor
Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) |
![]() |
1A:Stardock MCP
Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications |
![]() |
1A:Stardock TrayMonitor
For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX |
![]() |
1CmailS
?? |
![]() |
1on1
Adult content dialler |
![]() |
1Srv32
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
![]() |
1u7
Added by the MURBAC-A TROJAN! |
![]() |
1Win32Cfg
SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
![]() |
1Win32Cfg
Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself! |
![]() |
1WinCfg32
WebMailSpy spyware |
![]() |
2020Downloader
2020Search Toolbar |
![]() |
2177F056-0AA6-4D6C-A944-13F71F341C29
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
24Online Client
Related to Cyberroam from Elitecore Technologies Ltd |
![]() |
252
Added by the LEGMIR-AT TROJAN! |
![]() |
27
Added by the SLSORVE-A TROJAN! |
![]() |
27
Added by the SLSORVE-D TROJAN! |
![]() |
27
Added by the SLSORVE-E TROJAN! |
![]() |
2Search
2Search adware |
![]() |
2thousandbuck
Added by the RANKY.L TROJAN! |
![]() |
2wSysTray
2Wire Homeportal user interface |
![]() |
3.8853E+11
Added by the SDBOT-DEN WORM! |
![]() |
32-bit Thunking service
Added by the DERDERO.A WORM! |
![]() |
333
Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
![]() |
39ELTFH25Z8SKF
Seems to be associated with software by Resplendence SP ? |
![]() |
3c1807pd
3Com WinModem driver. See here for more WinModem information |
![]() |
3capplnk
US Robotics Modem driver |
![]() |
3cdminic
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
![]() |
3CM Link
Required for a US Robotics WinModem as it provides the link to Windows - won't work without it |
![]() |
3Cmlink
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information |
![]() |
3ComDMIAgent
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
![]() |
3cpipe-USRpdA
Modem driver files from US Robotics |
![]() |
3D Text
Added by the JERMY.A WORM! |
![]() |
3Deep Control Panel
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games |
![]() |
3Dfx Acc
Added by the GIBE WORM! |
![]() |
3dfx Task Manager
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
![]() |
3dfx Tools
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards |
![]() |
3dfxv2ps.dll
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
![]() |
3Dlabs Taskbar Display Manager
3DLabs graphics driver related. System Tray access to display settings? |
![]() |
3DLabsHelperDemon
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled |
![]() |
3DMouse.EXE
Dritek System Inc. 3D Mouse driver |
![]() |
3d_sound
Added by the RIADOS-A TROJAN! |
![]() |
3qdctl.exe
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ |
![]() |
3ware 3DM
Monitors status of the disk array on 3ware IDE RAID controllers |
![]() |
4.68474E+12
Added by the SDBOT-DEV WORM! |
![]() |
456655
Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder |
![]() |
4da92ad5.exe
Added by the DLOADR-WZ TROJAN! |
![]() |
4oD
Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
![]() |
4wd!!!
Added by the OPASERV.AI WORM! |
![]() |
5-1-61-96
Adult content dialler |
![]() |
5-2-46-112
Adult content pop-up dialler. Removal instructions here |
![]() |
55278
Added by the LINEAGE-S TROJAN! |
![]() |
5p4m
Added by the LITEBOT-C TROJAN! |
![]() |
5whgue21
ClearSearch adware |
![]() |
666
Added by the PIPES TROJAN! |
![]() |
678
Added by the SLSORVE-B TROJAN! |
![]() |
756349DC-6D9E-4F2A-9B24-269661F073C3
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
7f8e
Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder |
![]() |
802.11b+g USB Wireless LAN Utility
802.11b+g USB Wireless LAN Utility |
![]() |
802.11g Wireless Adatper
Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled |
![]() |
852EBF20-A95D-4F1F-B9C2-B2CD24350F3E
Detected by McAfee as the FAKEALERT-AH TROJAN! See here |
![]() |
98D0CE0C16B1
BrowserAid/BrowserPal foistware |
![]() |
9m
Added by the LEGMIR-AQK TROJAN! |
![]() |
9xadiras
Allied Telesyn AT series router/modem related - apparently required |
![]() |
9xHtProtect
Added by the NETSKY.M WORM! |
![]() |
;Rundll
Added by the PWSLEGMIR.E TROJAN! |
![]() |
?ekio Startups
Added by the AGOBOT-OV WORM where ? is a random character |
![]() |
@
Added by the SEEKER.K TROJAN! |
![]() |
@Hoc Toolbar
One-click activated browsing toolbar used by various web-sites. See here for more info |
![]() |
@loha
Registration reminder for @loha@home E-mail utility |
![]() |
@tour_ww
Adult content dialler |
![]() |
[3-4 random letters]
PurityScan/Clickspring adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder |
![]() |
[3-4 random letters]Srv32
Added by the BANCSADE-A TROJAN! |
![]() |
[decimal number]
Added by the OPOSSUM-A WORM! The decimal number can be anything, eg, 0.12345678 |
![]() |
[default]
Added by the DREMN TROJAN! |
![]() |
[Entry name]
Added by the NETHIEF-N TROJAN! |
![]() |
[Ephemeral 2.5] by TreeHugger,
Added by the LEMOOR-C WORM! |
![]() |
[Ephemeral 2.x] by TreeHugger,
Added by the LEMOOR.A WORM! where "x" represents 3 or 4 |
![]() |
[executed file name]
Added by the WAXPOW WORM! |
![]() |
[executed file name]
Added by the SOUTHGHOST WORM! |
![]() |
[filename]
Added by the BANKER-CC TROJAN! |
![]() |
[original filename]
Added by the BANCBAN-CX TROJAN! |
![]() |
[original filename]
Added by the BANCBAN-HM TROJAN! |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random 12 digit number]
Adsrv.com/IeDriver adware variant |
![]() |
[random characters]
Added by the OPTIXP-N TROJAN! Note - this trojan file is found in the System (9x/Me) or System32 (NT/2K/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted |
![]() |
[random characters]
Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN! |
![]() |
[random filename]
QuickLinks adware |
![]() |
[random names]
MediaMotor adware |
![]() |
[random name]
Added by the SDBOT.N TROJAN! |
![]() |
[random name]
Added by an unidentified VIRUS, WORM or TROJAN! |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware. Note - do not confuse with the Microsoft utility of the same name as described here |
![]() |
[random name]
AproposMedia adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware. Unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2K/NT always be located in the WinntSystem32 or WindowsSystem32 folder, and ought moreover NOT to figure among the startups! |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware. Do not confuse with the legitimate Microsoft Printer Spooler Service (spoolsv.exe) |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) |
![]() |
[random name]
Added by the BANCOS-DR TROJAN! |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup! |
![]() |
[random name]
PurityScan/Clickspring adware |
![]() |
[random name]
Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder |
![]() |
[random name]
SearchNet adware |
![]() |
[random name]
Added by the ULPM.BD TROJAN! |
![]() |
[random name]
Added by the GAMPASS-L TROJAN! |
![]() |
[random name]
Added by the LEGMIR-AQM TROJAN! |
![]() |
[random name]
Detected by Trend Micro as the AGENT.EBC TROJAN! See here |
![]() |
[Random name]
Detected by Panda as the SDSCAN.A TROJAN! |
![]() |
[random name]
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
![]() |
[random number]
Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one copies it's self under 9 additional file names in the System (9x/Me) or System32 (NT/2K/XP) folder |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[Randomly chosen existing folder name]
Added by the ANTINNY-L WORM! |
![]() |
[random]
Added by the BANCBAN-CW TROJAN! |
![]() |
[random]
Added by the BANCBAN-CY TROJAN! |
![]() |
[trojan filename]
Added by the BANCBAN-FS TROJAN! |
![]() |
[trojan name]
Added by the BANCBAN-CL TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
![]() |
[username] config
Added by the MOSUCK-H TROJAN! |
![]() |
[various filenames]
Added by the WEBDOR.Y TROJAN |
![]() |
[various names]
Elf is a hacker program, tied to a trojan server |
![]() |
[various names]
Added by the FORBOT-AK WORM! |
![]() |
[various names]
Added by any of a number of WORM or TROJAN variants |
![]() |
[various names]
Added by the RBOT-NI WORM! |
![]() |
[various names]
Added by a variant of the RBOT WORM! |
![]() |
[various names]
Added by an unidentified WORM or TROJAN! |
![]() |
[various names]
Added by a variant of the RBOT WORM! |
![]() |
[various names]
Added by the RBOT-DQ WORM! |
![]() |
[various names]
Premium rate adult content dialler |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Adware - detected by Kaspersky as the SMALL.ALW TROJAN! |
![]() |
[various names]
Added by a variant of the AGENT.AH TROJAN! |
![]() |
[various names]
Added by an unidentified TROJAN! |
![]() |
[various names]
Added by a NTROOTKIT TROJAN variant! |
![]() |
[various names]
Added by a NTROOTKIT TROJAN variant! |
![]() |
[various names]
Added by a variant of the SDBOT WORM! |
![]() |
[various names]
Added by a NTROOTKIT TROJAN variant! |
![]() |
[various names]
Added by a NTROOTKIT TROJAN variant! |
![]() |
[various names]
Added by a NTROOTKIT TROJAN variant! |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
![]() |





