PC Review
Startup Files Database
Letter num
Powered By Pac's Startup list
Startup Files Database
Letter num
Startup Files Database
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]
Yes |
No |
Users Choice |
Warning |
Unknown |
| Normally leave to run at startup | Not Required, often infrequently run tasks that can be run manually. | Depends if the task is deemed necessary | Typically viruses, spyware, adware and resource hogs | An unknown item |
| Required | Process Name / Details | Startup File |
![]() |
Added by the AGOBOT-KU WORM! Note - has a blank entry under the Startup Item/Name field |
system32.exe |
![]() |
Added by the MKMOOSE-A WORM! Note - has a blank entry under the Startup Item/Name field |
pathex.exe |
![]() |
Added by the DELF-UX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
svchost.exe |
![]() |
Added by a variant of the SDBOT WORM! This file is located in the Winnt or Windows folder. Note - has a blank entry under the Startup Item/Name field |
MSPF.EXE |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
dllvirtual.exe |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
dllvirtual.dll |
![]() |
Added by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name field |
dllvirtual.js |
![]() |
Added by the SPYBOT-NX WORM! Note - has a blank entry under the Startup Item/Name field |
ajsha5.exe |
![]() |
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly |
pgaccount.exe |
![]() |
DiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks |
procguard.exe |
![]() |
Part of AVG Anti-Spyware from Grisoft |
avgas.exe |
![]() |
Part of Ewido anti-spyware |
ewido.exe |
![]() |
WinRecon keystroke logger/monitoring program - remove unless you installed it yourself! |
winrecon.exe |
![]() |
Connection manager for the EnterNet ISP. You can also use RASPPOE |
Enternet.exe |
![]() |
Added by the RYKNOS.B TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
$sys$xp.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sonyTimer.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sos$sys$.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$WeLoveMcCOL.exe |
![]() |
Added by the RYKNOS TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer |
$sys$drv.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sonyTimer.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sos$sys$.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$WeLoveMcCOL.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sonyTimer.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$sos$sys$.exe |
![]() |
Added by the WELOMOCH TROJAN! |
$sys$WeLoveMcCOL.exe |
![]() |
Volumouse from Nirsoft. "Provides you a quick and easy way to control the sound volume on your system - simply by rolling the wheel of your wheel mouse" |
volumouse.exe |
![]() |
Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
IEXPLORE.EXE |
![]() |
Possibly related to C-Media Mixer Control panel? |
%cmpmixstr% |
![]() |
012.Net.il Israeli ISP software front-end |
fts.exe |
![]() |
012.Net.il Israeli ISP dial-up software |
FWPortal.exe |
![]() |
1776 Internet US ISP software ISP software front-end |
fts.exe |
![]() |
1776 Internet US ISP dial-up software |
FWPortal.exe |
![]() |
Barak013 Israeli ISP software front-end |
fts.exe |
![]() |
Barak013 Israeli ISP dial-up software |
FWPortal.exe |
![]() |
Friendly ISP software front-end |
fts.exe |
![]() |
Homepage hijacker, see here (* = any digit) |
winSOCKS.exe |
![]() |
Homepage hijacker, see here (* = any digit) |
win32API.exe |
![]() |
Added by the BLACKMAL WORM! |
[random filename].exe |
![]() |
Added by the HESIVE.B TROJAN! |
rundll32.exe [path] Zykheptd.dll |
![]() |
Added by the DOWNLD-ABF TROJAN! |
5640.exe |
![]() |
Added by the ASSIRAL.B WORM! |
SP00Lsv32.pif |
![]() |
Added by the POPS WORM! |
janis.com |
![]() |
Added by the STMU TROJAN! |
ctxma.exe |
![]() |
Added by the STMU TROJAN! |
cxma.exe |
![]() |
Added by the STMU TROJAN! |
wstcl.exe |
![]() |
Added by the STMU TROJAN! |
wucxt.exe |
![]() |
Added by the STMU TROJAN! |
wuytc.exe |
![]() |
Virtumondo adware, also known as the VUNDO TROJAN! |
[random filename] |
![]() |
Detected by F-secure as the OBFUSCATED.GP TROJAN! |
aecache.exe |
![]() |
Added by the SDBOT.BRO WORM! |
secctr.exe |
![]() |
Windows ME default for System Restore. Do NOT disable! |
statemgr.exe |
![]() |
Added by the RBOT-QU WORM! |
wrauclt.exe |
![]() |
Added by the RBOT-PG WORM! |
wuanclt.exe |
![]() |
Added by the SPYBOT.HUR WORM! |
wuaucrlt.exe |
![]() |
Added by the RBOT-PO WORM! |
wuraclt.exe |
![]() |
Added by the RBOT-SY WORM! |
wurauclt.exe |
![]() |
Added by the SPYBOT.PR WORM! |
wsctl.exe |
![]() |
Added by the SDBOT.AVD WORM! |
wkmst.exe |
![]() |
Added by the RBOT.AOS WORM! |
wscxt.exe |
![]() |
Added by a variant of the RBOT WORM! |
waurclt.exe |
![]() |
Added by the KEDEBE-B WORM! |
[filename] |
![]() |
Added by the AGENT-TH WORM! |
systemupd.exe |
![]() |
Added by the VUNDO TROJAN! |
[trojan path] ren time:[random number] |
![]() |
Added by the GARGAFX TROJAN! |
winstats.exe |
![]() |
Added by a variant of the RBOT-UG WORM! Note - * in the filename represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on... |
w****.exe [* = random char] |
![]() |
Suspected malware as it appears in 3 different registry locations - see here |
wininfo.exe |
![]() |
Internet Security Suite used by ISPs to protect customers against many attacks |
ZkRunOnceR.exe |
![]() |
Added by the DLOADR-ASH TROJAN! |
ABC2007.exe |
![]() |
Added by the WEBUS.C TROJAN! |
lassa.exe |
![]() |
Added by the WEBUS.D TROJAN! |
lsvchost.exe |
![]() |
Added by the CR TROJAN! |
lsvchost.exe |
![]() |
Added by the CMQ TROJAN! |
svhost.exe |
![]() |
Added by the ALLOCUP.A WORM! |
msveup.exe |
![]() |
Added by the DDOS_BOXED.X TROJAN! |
mssecure.exe |
![]() |
?? |
sysmon32.exe |
![]() |
Added by the BOXED-H TROJAN! |
rchost.exe |
![]() |
Added by the IRCBOT-FP TROJAN! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup! |
smss.exe |
![]() |
Added by the BOXED.CG TROJAN! |
smssb.exe |
![]() |
Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
services.exe |
![]() |
Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
winlogon.exe |
![]() |
Smitfraud variant |
N/A |
![]() |
Added by the WEBUS.F TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
CSRSS.EXE |
![]() |
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
csrss.exe |
![]() |
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
lsass.exe |
![]() |
Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process, which should not appear in Msconfig/Startup! |
csrss.exe |
![]() |
Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the System folder |
lsass.exe |
![]() |
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup. A patch is available - filename R75304.EXE - that fixes the issue. You can find that file at support.dell.com by typing that name in the 'Search' box available there. It addresses the root of the problem in Creative's software and corrects it. Unfortunately there is no direct link to the file, but it's easily available using the search function |
N/A |
![]() |
PrivateEye surveillance software. Uninstall this software unless you put it there yourself |
pit.exe |
![]() |
LZIO.com adware downloader |
hpdllhost.exe |
![]() |
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...) |
000StTHK.exe |
![]() |
Added by the BANCBAN-EC TROJAN! |
0050726-007-i32-1.exe |
![]() |
Related to Advanced Desktop Shield |
desksaver.exe |
![]() |
Related to Advanced Desktop Shield |
desksaver.exe |
![]() |
PC Tools Firewall Plus - "powerful free personal firewall for Windows that protects your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network" |
FirewallGUI.exe |
![]() |
Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards |
TCrdMain.exe |
![]() |
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. |
00THotKey.exe |
![]() |
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev |
system32THotkey.exe |
![]() |
Anti-dialer program (Germany) |
WARN0190.EXE |
![]() |
Anti-dialer program (Germany) |
WARN0900.EXE |
![]() |
Added by the COSIAM-H TROJAN! |
0mcamcap.exe |
![]() |
Added by the RBOT-CC WORM! Note the first letter is actually the digit "0" and not a capital "o" |
*****.exe [* = random char] |
![]() |
Added by the ESTEEMS TROJAN! |
1.exe |
![]() |
Added by the BANCOS.V TROJAN! |
lsass.scr |
![]() |
Added by the BANCOS.X TROJAN! |
svchost.scr |
![]() |
Added by the IC TROJAN! |
1111swapmgr.exe |
![]() |
Added by the KITRO.C (or DANDI.A) WORM! 123456 can be any random 3 to 6 digit number |
rundll32.exe shell32.dll, Control_RunDLL ...123456.cpl |
![]() |
12Ghosts Backup - "Automatic Backups, HyperBackup for Multiple Versions, Registry Backup" |
12backup.exe |
![]() |
12Ghosts Clip - "Screen shots made easy" |
12clip.exe |
![]() |
12Ghosts JustAWindow - "Cover annoying ads, animated gifs, things you don't want to see" |
12window.exe |
![]() |
12Ghosts Popup-Killer |
12popup.exe |
![]() |
12Ghosts SaveLayout - "Always (always!) keep the layout of your desktop icons" |
12autosl.exe |
![]() |
12Ghosts SetColor - "Change your desktop icon text colors, also to transparent" |
12color.exe |
![]() |
12Ghosts Showtime - "Enhance the clock in your tray with font formatting, colors, date, time zones" |
12showtime.exe |
![]() |
12Ghosts Synchronize - "Sync PC clock with an atomic clock over the Internet" |
12sync.exe |
![]() |
12Ghosts Tower - "Quickly access and manage all Ghosts (included in all packages)" |
12tower.exe |
![]() |
12Ghosts TrayProtect - "Hide tray icons, restore after a crash" |
12srvc.exe |
![]() |
12Ghosts Wash - "Protect your privacy, clear browser history, delete and overwrite cache files" |
12wash.exe |
![]() |
?? |
N/A |
![]() |
NCase adware |
180adsolution.exe |
![]() |
NCase adware |
180ax.exe |
![]() |
180Solutions adware related |
stubinstaller****.exe [* = digit] |
![]() |
180Solutions adware related |
[path to trojan] |
![]() |
180Solutions adware related |
******.tmp [* = random digit/char] |
![]() |
Added by the DLOADR-AXU TROJAN! |
1916435341.exe |
![]() |
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
196_150_ni.exe |
![]() |
WinFixer web installer. Winfixer is "Foistware", pretending to be system optimization, protection and recovery software - stealth installed, see here |
197_150_ni_3.exe |
![]() |
HP utility for monitoring when and how many recoveries have been done |
hpdrv.exe |
![]() |
Comes with the MacVision program for monitoring tray icons (Note : program is by Stardock) |
TrayMonitor.exe |
![]() |
Master Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications |
mcpserver.exe |
![]() |
For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX |
TrayServer.exe |
![]() |
?? |
NETMAIL.EXE |
![]() |
Adult content dialler |
1on1.exe |
![]() |
SpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC." |
SpyAgent4.exe |
![]() |
Added by the MURBAC-A TROJAN! |
1u7.exe |
![]() |
SpyBuddy keystroke logger/monitoring program - remove unless you installed it yourself! |
SpyBuddy.exe |
![]() |
Keyloggerpro keystroke logger/monitoring program - remove unless you installed it yourself! |
Keyloggerpro.exe |
![]() |
WebMailSpy spyware |
WebMailSpy.exe |
![]() |
2020Search Toolbar |
mssvr.exe |
![]() |
Added by the LEGMIR-AT TROJAN! |
winmgr.exe |
![]() |
Added by the SLSORVE-A TROJAN! |
slsorve.exe |
![]() |
Added by the SLSORVE-D TROJAN! |
csrss32.exe |
![]() |
Added by the SLSORVE-E TROJAN! |
msm32.exe |
![]() |
2Search adware |
main.exe |
![]() |
Added by the RANKY.L TROJAN! |
[path to file] |
![]() |
2Wire Homeportal user interface |
2portalmon.exe |
![]() |
Added by the DERDERO.A WORM! |
thunk32.exe |
![]() |
Added by the JD-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This one is located in a "Syswm1i" directory |
svchost.exe |
![]() |
Added by the SDBOT-DEN WORM! |
AutomaticUpdates.exe |
![]() |
Seems to be associated with software by Resplendence SP ? |
Ezg1q5.exe |
![]() |
3Com WinModem driver. See here for more WinModem information |
3cmlink.exe 3cpipe-3c1807pd |
![]() |
US Robotics Modem driver |
3capplnk.exe |
![]() |
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
3CDMINIC.EXE |
![]() |
Required for a US Robotics WinModem as it provides the link to Windows - won't work without it |
3cmcnkw.exe |
![]() |
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information |
3CmlinkW.exe |
![]() |
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards |
3CDMINIC.EXE |
![]() |
Modem driver files from US Robotics |
USRmlnkA.exe |
![]() |
Added by the JERMY.A WORM! |
3D Text.scr |
![]() |
Now superseeded by ColorWizzard - 3Deep corrected lighting, shading and color for all your 2D and 3D games |
3DeepCTL.EXE |
![]() |
Added by the GIBE WORM! |
GFXACC.EXE |
![]() |
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
3dfxMan.exe |
![]() |
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards |
3dfxCmn.dll |
![]() |
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
3dfxv2ps.dll |
![]() |
3DLabs graphics driver related. System Tray access to display settings? |
3DLman.exe |
![]() |
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled |
3dldemon.exe |
![]() |
Dritek System Inc. 3D Mouse driver |
3DMouse.EXE |
![]() |
Added by the RIADOS-A TROJAN! |
3d_sound.exe |
![]() |
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ |
3qdctl.exe |
![]() |
Monitors status of the disk array on 3ware IDE RAID controllers |
3dm.exe |
![]() |
Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder |
explorer.exe |
![]() |
Added by the SDBOT-DEV WORM! |
netdll32.exe |
![]() |
Added by the DLOADR-WZ TROJAN! |
4da92ad5.exe |
![]() |
Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
KHost.exe |
![]() |
Added by the OPASERV.AI WORM! |
Natal!.pif |
![]() |
Adult content dialler |
members-area.exe |
![]() |
Adult content pop-up dialler. Removal instructions here |
5-2-46-112.exe |
![]() |
Added by the LINEAGE-S TROJAN! |
grepclient1.exe |
![]() |
Added by the LITEBOT-C TROJAN! |
[path to trojan] |
![]() |
ClearSearch adware |
5whgue21.exe |
![]() |
Added by the PIPES TROJAN! |
Ska.exe |
![]() |
Added by the SLSORVE-B TROJAN! |
lsas32.exe |
![]() |
Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the system32 folder |
z****.exe 9idf |
![]() |
Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled |
Monitor.exe |
![]() |
BrowserAid/BrowserPal foistware |
rundll32.exe D0CE0C16B1, D0CE0C16B1 |
![]() |
Added by the LEGMIR-AQK TROJAN! |
winlog0n.exe |
![]() |
Allied Telesyn AT series router/modem related - apparently required |
9xadiras.exe |
![]() |
Added by the NETSKY.M WORM! |
AVprotect9x.exe |
![]() |
Added by the PWSLEGMIR.E TROJAN! |
[filename] |
![]() |
Added by the AGOBOT-OV WORM where ? is a random character |
?nksvc32.exe |
![]() |
Added by the SEEKER.K TROJAN! |
regedit -s ..win.dll |
![]() |
One-click activated browsing toolbar used by various web-sites. See here for more info |
AtHoc.exe |
![]() |
Registration reminder for @loha@home E-mail utility |
reminder.exe |
![]() |
Adult content dialler |
@tour_ww[1].exe |
![]() |
PurityScan/Clickspring adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder |
nslookup.exe |
![]() |
Added by the BANCSADE-A TROJAN! |
[path to file] |
![]() |
Added by the OPOSSUM-A WORM! The decimal number can be anything, eg, 0.12345678 |
[path to worm] |
![]() |
Added by the DREMN TROJAN! |
DrWatson32.exe |
![]() |
Added by the NETHIEF-N TROJAN! |
System.exe |
![]() |
Added by the LEMOOR-C WORM! |
[path to worm] |
![]() |
Added by the LEMOOR.A WORM! where "x" represents 3 or 4 |
[path to worm] |
![]() |
Added by the WAXPOW WORM! |
App.exe |
![]() |
Added by the SOUTHGHOST WORM! |
Regsrv32.com |
![]() |
Added by the BANKER-CC TROJAN! |
svchost.scr |
![]() |
Added by the BANCBAN-CX TROJAN! |
svchost.scr |
![]() |
Added by the BANCBAN-HM TROJAN! |
xphost.scr |
![]() |
Adsrv.com/IeDriver adware variant |
avifile5.exe |
![]() |
Adsrv.com/IeDriver adware variant |
bootvid4.exe |
![]() |
Adsrv.com/IeDriver adware variant |
browser8.exe |
![]() |
Adsrv.com/IeDriver adware variant |
atitvo32.exe |
![]() |
Adsrv.com/IeDriver adware variant |
autodisc.exe |
![]() |
Adsrv.com/IeDriver adware variant |
cabview1.exe |
![]() |
Adsrv.com/IeDriver adware variant |
advpack1.exe |
![]() |
Adsrv.com/IeDriver adware variant |
batmeter.exe |
![]() |
Adsrv.com/IeDriver adware variant |
bidispl2.exe |
![]() |
Adsrv.com/IeDriver adware variant |
asferror.exe |
![]() |
Adsrv.com/IeDriver adware variant |
catsrvps.exe |
![]() |
Adsrv.com/IeDriver adware variant |
admparse.exe |
![]() |
Adsrv.com/IeDriver adware variant |
audiosrv.exe |
![]() |
Adsrv.com/IeDriver adware variant |
bootvid2.exe |
![]() |
Adsrv.com/IeDriver adware variant |
cmpbk321.exe |
![]() |
Added by the OPTIXP-N TROJAN! Note - this trojan file is found in the System (9x/Me) or System32 (NT/2K/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted |
securewinload32x.exe |
![]() |
Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN! |
rsbmsc.exe |
![]() |
QuickLinks adware |
slk8x2peu.exe |
![]() |
MediaMotor adware |
eee2.exe |
![]() |
Added by the SDBOT.N TROJAN! |
Svchosts.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! |
wincpu.exe |
![]() |
PurityScan/Clickspring adware |
m?dtc.exe |
![]() |
PurityScan/Clickspring adware. Note - do not confuse with the Microsoft utility of the same name as described here |
ping.exe |
![]() |
AproposMedia adware |
CXTPLS_LOADER.EXE |
![]() |
PurityScan/Clickspring adware |
??plorer.exe |
![]() |
PurityScan/Clickspring adware |
?hkdsk.exe |
![]() |
PurityScan/Clickspring adware |
?hkntfs.exe |
![]() |
PurityScan/Clickspring adware |
l?gonui.exe |
![]() |
PurityScan/Clickspring adware |
m?iexec.exe |
![]() |
PurityScan/Clickspring adware |
r?gsvr32.exe |
![]() |
PurityScan/Clickspring adware |
t?skmgr.exe |
![]() |
PurityScan/Clickspring adware |
w?auboot.exe |
![]() |
PurityScan/Clickspring adware |
w?auclt.exe |
![]() |
PurityScan/Clickspring adware |
w?crtupd.exe |
![]() |
PurityScan/Clickspring adware |
w?wexec.exe |
![]() |
PurityScan/Clickspring adware |
??erinit.exe |
![]() |
PurityScan/Clickspring adware |
d?dplay.exe |
![]() |
PurityScan/Clickspring adware |
n?tepad.exe |
![]() |
PurityScan/Clickspring adware |
??chost.exe |
![]() |
PurityScan/Clickspring adware |
??oolsv.exe |
![]() |
PurityScan/Clickspring adware |
??xplore.exe |
![]() |
PurityScan/Clickspring adware |
r?ndll32.exe |
![]() |
PurityScan/Clickspring adware |
se?vices.exe |
![]() |
PurityScan/Clickspring adware |
w?nlogon.exe |
![]() |
PurityScan/Clickspring adware |
w?nword.exe |
![]() |
PurityScan/Clickspring adware |
??anregw.exe |
![]() |
PurityScan/Clickspring adware |
?ttrib.exe |
![]() |
PurityScan/Clickspring adware |
j?vaw.exe |
![]() |
PurityScan/Clickspring adware |
l?ass.exe |
![]() |
PurityScan/Clickspring adware |
m?config.exe |
![]() |
PurityScan/Clickspring adware |
n?lookup.exe |
![]() |
PurityScan/Clickspring adware |
n?pdb.exe |
![]() |
PurityScan/Clickspring adware |
??ool32.exe |
![]() |
PurityScan/Clickspring adware |
??rss.exe |
![]() |
PurityScan/Clickspring adware |
??rvices.exe |
![]() |
PurityScan/Clickspring adware |
?ti2evxx.exe |
![]() |
PurityScan/Clickspring adware. Unlike this file, the legitimate Windows chkdisk.exe will in Windows XP/2K/NT always be located in the WinntSystem32 or WindowsSystem32 folder, and ought moreover NOT to figure among the startups! |
chkdsk.exe |
![]() |
PurityScan/Clickspring adware |
d?xplore.exe |
![]() |
PurityScan/Clickspring adware |
dvdplay.exe |
![]() |
PurityScan/Clickspring adware. Do not confuse with the legitimate Microsoft Printer Spooler Service (spoolsv.exe) |
spoolsv.exe |
![]() |
PurityScan/Clickspring adware |
w?aclt.exe |
![]() |
PurityScan/Clickspring adware. Do not confuse with the legitimate Windows Critical Update Notification (wucrtupd.exe) |
wucrtupd.exe |
![]() |
Added by the BANCOS-DR TROJAN! |
charmapnt.exe |
![]() |
PurityScan/Clickspring adware |
n?tdde.exe |
![]() |
PurityScan/Clickspring adware |
r?gedit.exe |
![]() |
PurityScan/Clickspring adware |
r?ndll.exe |
![]() |
PurityScan/Clickspring adware |
scanregw.exe |
![]() |
PurityScan/Clickspring adware. Note - do not confuse with the legitimate wuauboot.exe file, which should not figure in Msconfig/Startup! |
wuauboot.exe |
![]() |
PurityScan/Clickspring adware |
w?nspool.exe |
![]() |
Added by the BANCBAN-JC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "config" subfolder of the Winnt or Windows folder |
svchost.exe |
![]() |
SearchNet adware |
[random name].dll |
![]() |
Added by the ULPM.BD TROJAN! |
iexpl0ra.exe |
![]() |
Added by the GAMPASS-L TROJAN! |
rundl13a.exe |
![]() |
Added by the LEGMIR-AQM TROJAN! |
Servere.exe |
![]() |
Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one copies it's self under 9 additional file names in the System (9x/Me) or System32 (NT/2K/XP) folder |
explorer.exe |
![]() |
Added by the ANTINNY-L WORM! |
_autorun.exe |
![]() |
Added by the ANTINNY-L WORM! |
_cfg.exe |
![]() |
Added by the ANTINNY-L WORM! |
_config.exe |
![]() |
Added by the ANTINNY-L WORM! |
_env.exe |
![]() |
Added by the ANTINNY-L WORM! |
_loader.exe |
![]() |
Added by the ANTINNY-L WORM! |
_login.exe |
![]() |
Added by the ANTINNY-L WORM! |
_setup.exe |
![]() |
Added by the ANTINNY-L WORM! |
_start.exe |
![]() |
Added by the BANCBAN-CW TROJAN! |
lsass.scr |
![]() |
Added by the BANCBAN-CY TROJAN! |
svchost.scr |
![]() |
Added by the BANCBAN-FS TROJAN! |
Install.exe |
![]() |
Added by the BANCBAN-CL TROJAN! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
svchost.exe |
![]() |
Added by the MOSUCK-H TROJAN! |
[path to trojan] |
![]() |
Added by the WEBDOR.Y TROJAN |
qtsks.exe |
![]() |
Elf is a hacker program, tied to a trojan server |
elf.exe |
![]() |
Added by the FORBOT-AK WORM! |
crsrs.exe |
![]() |
Added by any of a number of WORM or TROJAN variants |
Windows32.exe |
![]() |
Added by the RBOT-NI WORM! |
bling.exe |
![]() |
Added by a variant of the RBOT WORM! |
mediaplayer32.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
winlogon32.exe |
![]() |
Added by a variant of the RBOT WORM! |
svchostss.exe |
![]() |
Added by the RBOT-DQ WORM! |
win32snd.exe |
![]() |
Premium rate adult content dialler |
shch.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
PasswdMon.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
runload32.exe |
![]() |
Adware - detected by Kaspersky as the SMALL.ALW TROJAN! |
dstart2.exe |
![]() |
Added by a variant of the AGENT.AH TROJAN! |
msdos32.exe |
![]() |
Added by an unidentified TROJAN! |
sitebar.exe |
![]() |
Added by a NTROOTKIT TROJAN variant! |
backorif.exe |
![]() |
Added by a NTROOTKIT TROJAN variant! |
bhoserv.exe |
![]() |
Added by a variant of the SDBOT WORM! |
driver32.exe |
![]() |
Added by a NTROOTKIT TROJAN variant! |
hyandex.exe |
![]() |
Added by a NTROOTKIT TROJAN variant! |
Uint32.exe |
![]() |
Added by a NTROOTKIT TROJAN variant! |
Uint32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
_ctcp.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
10010.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
321102.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
34763.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
abrek.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ActionScr.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
AliceSD.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
AppMasterCenter.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
atl_helper.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ATLIEHELPER.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
avpmondll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
awinrar.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
backd.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
backorif.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
barint.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
bhoserv.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
bingo9.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
bnui.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Bogobot.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
borlandg.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
BoundRec.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
br0ken.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Brong32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
clamav.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
cmon14.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
cnftips.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
control64.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
corrida.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
CToolBar.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
DCC_send.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
defect08.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Dest068.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
dialer423.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
diskserv.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
driver64.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
DTOURS.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ERTYDF.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ExchangeMaster.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
EXE32EXE.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
expoler.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
FLKPT.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
forces_elite.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ftbar.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
gabber.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
hyandex.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
iehelper.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
iesetupdll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
init32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
InpriseMon.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
install2.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
jopplerg.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Kargo.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
keybdll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
KeywordFinder.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
killall.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
LOPTCON.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
media64.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
MNTP.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
MON76234.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
moniter.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
mozilla-text.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
msag.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ms-its.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
MsNetHelper.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
new32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
newbreed.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
nmdllw.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
NopeZ.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
NsCplTray.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
NSYSCPLSTR.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
NukeSpan.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
openstre.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
panel_its.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ParisM.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
pizda.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
powerdll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
PrcIdle.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
prcmon.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Preliminary.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
prgsys0984.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
progmen.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
qwe.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
RtlFindVal.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SAPSTR.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
sbin.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
scanSYS.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Serviceprocess.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SetupExeDll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Shaitan1678.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
slamm.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
sound64.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SpyElim.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
srbho.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ssweeper.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
StartCpl.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
startman.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
StatusCheck.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
stuffmon.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
sysconf16.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SysEntry.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
sysmon12.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
syspanel.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SysSupport.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
SYSTRAV.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
TemplateDongle.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
teqq32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Testimonials.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
TForm1.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
TorontoMail.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Trayz.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
TRPT.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
trycrt.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
typeconf.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
Uint32.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
uio.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
UserSp1.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
utsgmon.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
vxdman.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
WhatsNewBot.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
WinInitDll.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
wormexe.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
WTFCTF.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
XTermInit.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
xwiz.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
xxtoolbar.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
zantu.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
zxc.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
ABCXYZ.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
dePloy.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
JAguAr.exe |
![]() |
MediaMotor adware |
80d0.exe |
![]() |
MediaMotor adware |
exe81.exe |
![]() |
MediaMotor adware |
exe82.exe |
![]() |
Wareout - malware masquerading as a spyware and dialer remover |
MSTCPDLL.exe |
![]() |
MediaMotor adware |
seli.exe |
![]() |
Lycos SideSearch/Fastfind.org adware |
tools.exe |
![]() |
Added by the GAOBOT.GEN!POLY WORM! |
~`d}qzxu3zYF |
![]() |
Part of McAfee AntiSpyware |
MssCli.exe |
![]() |
Part of McAfee AntiSpyware |
masalert.exe |
![]() |
Added by the SMALL.SD TROJAN! |
nmmst.exe |
![]() |
Added by the SMALL-DT TROJAN! |
nmstt.exe |
![]() |
Added by a variant of the SMALL-DT downloader TROJAN |
msmsgrxp.exe |
![]() |
Added by the SMALL-EB TROJAN! |
msmsgr2.exe |
![]() |
Added by the SPEXTA-C TROJAN! |
_explore.exe |
![]() |
Added by the ZAFI.B WORM! |
[path to file] |
![]() |
Added by a variant of the DWNLDR-FTB TROJAN! |
_mzu_stonedrv2.exe |
![]() |
Added by the DWNLDR-FTB TROJAN! |
_mzu_stonedrv3.exe |
![]() |
Added by a variant of the FTB TROJAN! |
_mzu_stonedrv7.exe |
![]() |
Added by the DLOADER-JV TROJAN! |
_Ntrdlhost.exe |
![]() |
Added by the DLOADER-JV TROJAN! |
_ntrrs.exe |
![]() |
Added by the AGENT.NAK TROJAN! |
_pnd_*****.exe [* = random char/digit] |
![]() |
Added by the BESAM WORM! |
Setv.com |
![]() |
Added by the ERKEZ.C WORM! |
svchost.com |
![]() |
Added by the SOBER-Q TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a HelpHelp subfolder of the Windows or Winnt folder |
services.exe |
![]() |
Added by the ASCETIC.B TROJAN! Note - this is not the legitimate csrss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a addinsexplorer subfolder of the Winnt or Windows folder |
csrss.exe |
![]() |
Added by the LINEAGE-Z TROJAN! |
_svchost_.exe |
![]() |
Added by the TDISERV.A WORM! |
_tdicli_.exe |
![]() |
Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC" |
winadm.exe |
![]() |
Added by the SOBER.V WORM! |
services.exe |
![]() |
Added by the SOBER.AA WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "PoolData" subfolder of the Windows or Winnt folder |
services.exe |
![]() |
Added by the SOBER.X WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a "WinSecurity" subfolder of the Windows or Winnt folder |
services.exe |
![]() |
Added by the DLOADER-XX TROJAN! |
winexec.exe |
![]() |
Added by the SOBER.O WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Connection WizardStatus subfolder of the Windows or Winnt folder |
services.exe |
![]() |
Added by the SOBER.K TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentwin32 subfolder of the Winnt or Windows folder |
smss.exe |
![]() |
Disconnects and redials an ISP modem to an adult content site |
_x-Finder.exe |
![]() |
Zenosearch adware, where ** are random characters |
mrdsregp.exe |
![]() |
Google Gmail Notifier. Alerts you when you have new Gmail messages |
gnotify.exe |
![]() |
Scheduler for CyberLink PowerBackup - archiving/backup utility |
PBKScheduler.exe |
![]() |
BrowserAid/BrowserPal foistware |
rundll32.exe [path] stlb2.dll, DllRunMain |
![]() |
ZenoSearch adware |
dwdsregt.exe |
![]() |
BrowserAid/BrowserPal foistware |
rundll32.exe stlbdist.dll, DllRunMain |
![]() |
BrowserAid/BrowserPal foistware |
rundll32.exe stlbupdt.DLL, DllRunMain |
![]() |
ZenoSearch adware |
omdsregk.exe |
![]() |
Added by the SMALL-AQ TROJAN! |
[path to svchost.exe] |
![]() |
Added by FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in an "Inetsrv" subfolder |
services.exe |
![]() |
Added by the SMALL-EP TROJAN! |
[path to trojan] |
![]() |
Zeno Think-Adz adware |
thinksnet.exe |
![]() |
ZenoSearch adware |
dwdsregt.exe |
![]() |
BrowserAid/BrowserPal foistware |
rundll32.exe E6F1873B.DLL, D9EBC318C |
![]() |
æTorrent - BitTorrent client for Windows sporting a very small footprint. It was designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients |
utorrent.exe |

Main Page 



