| Status | Autorun name | Command | Description |
| N | UMAX VistaAccess | vsaccess.exe | VistaAccess gives you quick and easy access to scanning functions right from your desktop |
| U | UMonit | umonit.exe | Alerts when USB device is plugged in |
| Y | umxagent | umxagent.exe | Tiny Personal Firewall V4 - main engine |
| Y | umxldra | umxldra.exe | User mode executive module DLL loader - part of Tiny Personal Firewall V4 |
| Y | UMXLDRW | UMXLDRW.exe | Tiny Personal Firewall (pre V4) |
| X | un32info | un32info.Exe | Added by the CRYPTER.A TROJAN! |
| X | Undefined | winter.exe | Added by the KILLAV.LW TROJAN! |
| X | Under20 | anacon32.exe | Added by the ANACON-C WORM! |
| X | UNERI | yujixit.exe | Added by the SDBOT.BOO WORM! |
| U | UnHackMe Monitor | hackmon.exe | UnHackMe allows you to detect and remove a new generation of 'invisible' Trojan programs called "rootkits" |
| U | Uniblue Launcher | Launcher.exe | Launcher for the range of system utilities from Uniblue Systems Limited - namely PowerSuite, RegistryBooster, SpeedUpMyPC and DriverScanner. Normally located in the appropriate sub-directory of %ProgramFiles%\Uniblue |
| N | Uniblue ProcessQuickLink 2 | ProcessQuickLink2.exe | ProcessQuickLink by Uniblue Systems Ltd - gives you quick access to their Process Library entry for a currently running process via the standard Windows Task Manager (CTRL+ALT+DEL). A System Tray icon also allows you to search the library and launch the Task Manager. Run on demand |
| U | Uniblue Quick Access | qaccess.exe | Quick Access application from UniBlue Systems Ltd - "helps you account for all processes on your computer by providing an additional plug-in for the Windows task manager" |
| N | Uniblue Registry Booster | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals |
| N | Uniblue RegistryBooster 2 | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals |
| N | Uniblue RegistryBooster 2009 | RegistryBooster.exe | Old version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system." Run manually at regular intervals |
| U | Uniblue SpeedUpMyPC | SpeedUpMyPC.exe | Older version of SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" |
| Y | Uniblue SpyEraser | SpyEraser.exe | SpyEraser spyware remover from Uniblue Systems Limited - now discontinued. Provides System Tray access and also required for the real-time Live Guard feature to work to monitor and check for BHOs, toolbars, search hooks, etc |
| N | UniblueRegistryBooster | launcher.exe | Launcher for an older version of the RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will "clean, repair and optimize your system". Run manually at regular intervals |
| U | UniblueSpeedUpMyPC | Launcher.exe | Launcher for an older version of the SpeedUpMyPC from Uniblue Systems Limited - which "lets you monitor and control all your PC resources with easy, one click instructions. System settings, internet usage, disk clutter, RAM and CPU are all automatically scanned, cleaned and optimized for peak performance" |
| X | Unigray | Unigray Antivirus.exe | Unigray Antivirus rogue security software - not recommended |
| ? | UniMessenger | UNI2.exe | Possibly the UNI instant messenger for singles from Voxtel |
| X | uninstal | regsvr32 image.dll | CoolWebSearch parasite variant. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The "image.dll" file is found in %System% |
| X | Uninstall**** | upd.exe | Adult content based screen saver where **** can be any number |
| X | Uninstall_TBPS | TBuninst.exe | WebSearch Toolbar - HuntBar hijacker, toolbar installer variant |
| N | UninstallAbility | uability.exe | UninstallAbility free uninstaller |
| X | UninstallHL | PreUninstallHL.exe | LinkReplacer/FFinder adware |
| X | UninstallQL | PreUninstallQL.exe | LinkReplacer/FFinder adware |
| U | UniPrint | SetDfltSettings.exe | Drivers for Uniprint, a printing help for Terminal Services and Citrix which recieves downloaded files from a Uniprint enabled server and prints them locally allowing for truly universal printing through Terminal Services or Citrix |
| U | UniSc | Unisc.exe | McAfee UnInstaller |
| ? | uniucu | uniucu.exe | ?? |
| X | Universal Plug & Play devices | WinUPPD.exe | Added by an unidentified WORM/TROJAN! |
| X | Universal USB Service | svchost32.exe | Added by the KELVIR.R WORM! |
| U | University of Texas Weather | University of Texas Weather.exe | Weather gadget included with the University of Texas theme for MyColors from Stardock Corporation |
| X | Unix File Support | init3.exe | Added by the RBOT-ZN WORM! |
| X | unldr16 | unldr16.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | unldr32 | unldr32.exe | Added by a variant of the CRYPTER.C TROJAN! |
| X | UNleaded Syn Manager | Edit.exe | Added by the SLINNBOT.ALD BACKDOOR! |
| U | UnlockerAssistant | UnlockerAssistant.exe | Related to Unlocker utility to unlock files when the OS reports the file is being used by an other person or program |
| X | UNrcJcrVSu.exe | UNrcJcrVSu.exe | Added by the AGENT-PPD TROJAN! |
| X | Unshare | SafeShare.exe | SafeShare peer-to-peer (P2P) file-sharing client often bundled with adware or spyware |
| X | UnSpyPC | UnSpyPC.exe | UnSpyPC rogue spyware remover - not recommended |
| Y | untray | untray.exe | Command Antivirus related |
| X | UnVirex | UnVirex.exe | UniVrex rogue security software - not recommended, removal instructions here |
| N | uoltray | exec.exe | Netzero free ISP software - not required |
| X | Up Service | up32.pif | Added by the RBOT-ARI WORM! |
| X | upascw | upascw.exe | PersonalAntiSpy rogue spyware remover - not recommended, removal instructions here |
| N | UpConfgVer | UpgConf.exe | Part of Panda Antivirus and Internet Security. Purpose unclear, but according to Panda Software not required for the AV to function |
| X | UPCTPcw | UPCTPcw.exe | Part of the PcTurboPro rogue system optimization tool - not recommended, removal instructions here |
| X | upd.exe | upd.exe | Added by the DELF-AJW BACKDOOR! |
| X | upd32.exe | upd32.exe | Added by the AGENT-PDS TROJAN! |
| X | Updade Windows | winlogom.exe | Added by the TONAX-A TROJAN! |
| X | UpData | wupdata.exe | Added by the IRCBOT-AA TROJAN! |
| X | Update | [original file path] | Added by the LYNDEGG WORM! |
| X | Update | CDUpdater.exe | "Carpe Diem" adult premium rate dialler related |
| X | Update | Sysupd.exe | Added by the SLACKBOT VIRUS! |
| X | Update | Zupdate.exe | Associated with B3d Projector foistware - see here |
| X | Update | mshtm.exe | Browser hijacker - redirecting to buldog-search.com |
| X | Update | UPDATE-28062004.exe[25 blank spaces].vbs | Added by the MIDFIN WORM! |
| X | update | winis.exe | Added by the RBOT-VD WORM! |
| X | update | r00t.exe | Added by the RBOT-ACO WORM! |
| X | UPDATE | WinUpdater5.0.vbs | Added by the GORMLEZ-A WORM! |
| X | UpDate | RAuth.exe | Added by the DLOADER-UL TROJAN! |
| X | Update | csrss.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Update | csrss.exe | Added by the MEHEERWAR TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "winupdate" subfolder |
| X | Update | lsass.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Update | svchost.exe | Added by the ADCLICK-AG TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Update | Update.exe | QuickButton adware. The file is located in %ProgramFiles%\Common Files\updat |
| X | Update | hanz.exe | Added by a variant of the RBOT-GLJ WORM! |
| X | Update | WinUpdate.exe | Added by the SDBOT-CV BACKDOOR! |
| X | Update | Update.exe | Added by the MDROP-BUV TROJAN! The file is located in %Windir% |
| X | Update | systems.exe | Added by the SURUBAT.A WORM! |
| X | Update Checker | winlog.exe | Added by the IRCBOT-TJ TROJAN! |
| X | Update Checker | scvhost.exe | Added by the AGENT-DSF TROJAN! |
| X | update driver | SNDVOL32.EXE | Added by the SPYBOT-CU BACKDOOR! |
| X | Update Explorer | iexploreupd.exe | Added by a variant of the RBOT WORM! |
| X | Update for Windows | [various filenames] | Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe, common.pif, common.scr, Sexo.exe, Sexo.jpg.pif, ini_file__.pif, load_me__.tmp, msfile.pif, system_load_.pif or zipped.rar.pif |
| ? | Update for Works | MSWkstz.exe | Maybe related to later versions of MS Works? |
| N | Update Grokster | WiseUpdt.exe | Automatically updates the Grokster file sharing software. Beware of adware and spyware when using this type of program, for instance, Grokster contains CyDoor |
| X | Update Install | Schost.exe | Added by the GAOBOT.AO WORM! |
| ? | Update local | SetCPQLC.exe | Running on a Compaq desktop. Any ideas? |
| N | Update Manager | UpdateManager.exe | Searches for updates for the Rogers Yahoo! Browser - which "is designed to maximize your enjoyment with the Rogers Yahoo! Hi-Speed Internet service by providing you with a browsing tool that allows easy access to all the popular Yahoo! areas such as News, Finance, and many others." Can be run manually |
| X | update mon sys | updaterar.exe | Added by a variant of the RBOT WORM! |
| X | update run dos | logon.exe | Added by a variant of the SDBOT WORM! |
| X | Update Run MSword | LOGON.EXE | Added by the RBOT.TY WORM! |
| Y | Update Scheduler | UPSCHD.EXE | Automatic update scheduler for older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus |
| Y | Update Service | Update.exe | Loaded by Handybits programs such as EasyCrypto. Re-instates itself every time the program is run so best to leave it enabled. Prevent it dialling out via a firewall |
| X | update service | svxhost.exe | Added by the RBOT-MG WORM! |
| X | Update Service | winu32.exe | Added by the RBOT-MG WORM! |
| X | update service | winx.exe | Added by a variant of the RBOT WORM! |
| X | Update Srv | svchost.exe | Added by the DELF.OB TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winservxv |
| ? | Update TUT | WiseUpdt.exe | ?? |
| X | Update ver 1.0 | Swap.exe | Added by the SWAP-C WORM! |
| X | Update Windows | EXPLORE.EXE | Added by a variant of the SDBOT WORM! |
| X | Update.exe | ravseuper.exe | Added by the QQPASS-P TROJAN! |
| N | UPDATE~1 | updatemgr.exe | Once a month, your EarthLink 5.0 Update Manager contacts EarthLink's servers to check for software updates. If an update is available for your EarthLink software, Update Manager will inform you and, with your permission, download and install the update. Can go to http://www.earthlink.net and download the updates manually |
| X | Update32 | configs.exe | Hijacker, also detected as the QURL-2 TROJAN! |
| X | UpdateCheck | winstall.exe | Added by the SPYBOT-CY WORM! |
| N | UpdateChecker | UpdateChecker.exe | (1) Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. (2) Part of the ASUS Update Windows based BIOS update utility included with some ASUS motherboards. Checks the current BIOS revision |
| N | UpdateChecker Application | UpdateChecker.exe | Part of the ASUS Update Windows based BIOS update utility included with some ASUS motherboards. Checks the current BIOS revision. Note that with the version tested (7.16.02 Beta) if this entry was allowed to run at startup, ASUS Update would not run properly and casued system errors |