| Status | Autorun name | Command | Description |
| X | userinit | smss.exe | Added by the DLOADR-B TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | userinit | choo_003956f4 | Added by the PEED.16896 TROJAN! |
| X | userinit | ntos.exe | Added by the AGENT-ECU TROJAN! |
| X | Userinit | cologsver.exe | Added by the DROPPER.DJO TROJAN! |
| X | Userinit | rundll32.exe winsys16_070813.dll | Added by the AUTORUN-C WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "winsys16_070813.dll" file is found in %System% |
| X | userinit | appconf32.exe | Added by the SAVNUT TROJAN! |
| X | UserInit StartUp | rpcxuisu.exe | Added by a variant of the SDBOT WORM! |
| X | userinit.exe | userinit.exe | Added by the HAXDOOR-DP TROJAN! |
| X | userint32 | userint32.exe | Added by an unidentified TROJAN via an Instant Message that says, "This was cool, check it out here." Also contains Aurora popups |
| X | USERINTERFACE REPORT3R | M0USE.exe | Added by the MYTOB.HS WORM! |
| X | Userinterface Reporter | fuuuucktttttt.exe | Added by the MYTOB-DK WORM! |
| X | Userinterface Reporter | srv32.exe | ISTBar adware |
| U | UserSwitch | FastUserSwitching.exe | Allows for fast user switching between user accounts without logging off via a hotkey on some Dell machines (and maybe others?) |
| X | UserSystem | [filename] | CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN! |
| X | userun32 | userun32.exe | Added by the LYDRA-B TROJAN! |
| X | ushli | sscbltqu.exe | Obtained from an MP3 search list site. Also generates random processes on reboot |
| U | USIUDF_Eject_Monitor | USISrv.exe | Added by Ulead DVD Moviefactory. This program monitors your DVD or CD drives and alerts when you eject the media or have no media present |
| X | usnsvc.exe | usnsvc.exe | Added by the SPYBOT.AMD WORM! |
| X | UsrClassEx | UsrClassEx.exe | Added by the AGENT-KPU TROJAN! |
| X | usrgtway.exe | syswrun4x.exe | Added by the MITGLIEDER.E TROJAN! |
| X | UsrManagementConf | umcss.exe | Added by the IRCBOT-W TROJAN! |
| N | USRobotics 802.11g Wireless Network Utility | USRWLANG.exe | USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck "Use Windows to configure my wireless settings" for the program to work properly. Has Site Survey capabilities, and reports link quality and signal strength. Not required for proper operation of the device as the features given are accessible in the network connection properties |
| N | Usrobotics Online Registration | ?? | Pop-up reminding customers to register their products online at US Robotics |
| Y | USRpdA | USRmlnkA.exe | Modem driver files from US Robotics |
| U | UsrPrmpt | UsrPrmpt.exe | Used in conjunction with Security Center on XP from SP2 onwards to warn user's that older versions of Symantec's security products including Norton Internet Security, Norton AntiVirus and the now discontinued Norton Personal Firewall are disabled |
| X | Usrr | rncr.exe | PurityScan adware |
| X | Usrr | rpen.exe | PurityScan adware |
| ? | USRSTA | USRSTA.exe | Wireless Card controller. What does it do and is it required? |
| ? | USRSTA.EXE | USRSTA.EXE | Wireless Card controller. What does it do and is it required? |
| X | Ussi | rwsa.exe | PurityScan adware |
| X | Ussi | wnscpit.exe | PurityScan adware |
| N | USSShReg | USSSHREG.EXE | Registration reminder for Ulead SmartSaver Pro - compacts large graphics for web designers |
| U | UStorag | ustorage.exe | U-Storage is application software running under Microsoft Windows, it provides functions and utility to manage STF flash drive (USB drive) for security, partition, boot-ability and recovery. See note |
| N | Ustorage | Ustorage.exe | Maintenance tool (enable security functions) for a USB drive from Pretec |
| X | utasvc | rundll32.exe utasvc.dll,start | Added by the AKBOT-AB WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "utasvc.dll" file is found in %System% |
| X | UtilisateurSur | SysRep.exe | UtilisateurSur, French rogue system error and cleaning utility - not recommended. A member of the ErrClean family |
| U | Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter | WLANUTL.exe | SAGEM wireless LAN configuration utility |
| X | UtilitiesAndSoftware | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| ? | Utility Ping | UTILIT~1.EXE | ?? |
| U | Utility Tray | sistray.exe | System Tray access to display settings for Silicon Integrated Systems (SiS) based graphics chipsets. Located in %System% |
| N | UtilityPro | UtilityPro.exe | IE search toolbars as supplied by people such as Yellow Internet and SearchBoss and written by Rawhide Search Solutions |
| Y | UTILsInst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
| N | Utopia Angel | Angel.exe | "Utopia Angel is a powerful program which is a set of professional formatters, calculators, optimizers and other tools, working cooperatively, all specifically designed to assist and maximize the Utopian player's productivity." For the text-based massively multiplayer online game Utopia |
| N | uTorrent | uTorrent.exe | µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent, Inc. Designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients. For more information about the protocol see here. As µTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads |
| N | uTorrent.exe | uTorrent.exe | µTorrent - file sharing client for Windows sporting a very small footprint from BitTorrent, Inc. Designed to use as little cpu, memory and space as possible while offering all the functionality expected from advanced clients. For more information about the protocol see here. As µTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloads |
| X | uvnx | uvcx.exe | Added by the DLOADR-AWF TROJAN! |
| X | uvnx | uvnx.exe | Added by the AGENT-EOH TROJAN! |
| N | UVS10 Preload | uvPL.exe | Part of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this |
| N | UVS11 Preload | uvPL.exe | Part of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this |
| N | UVS12 Preload | uvPL.exe | Part of older versions of the Ulead (now Corel) VideoStudio video editing and DVD authoring software. Unless you use VideoStudio daily and find this speeds up the time it takes to open files associated with the program you shouldn't need this |
| X | uwa6pcw | uwa6pcw.exe | Part of the WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions here |
| X | uwa7pcw | uwa7pcw.exe | Part of the WinAntiVirus Pro 2007 rogue security software - not recommended, removal instructions here |
| X | uwanah | uwanah.exe | Added by the SDBOT-VL WORM! |
| X | uwas6cw | uwas6cw.exe | Part of the WinAntiSpyware 2006 rogue spyware remover - not recommended, removal instructions here |
| X | uwas7cw | uwas7cw.exe | Part of the WinAntiSpyware 2007 rogue spyware remover - not recommended |
| X | Uwezig | humom.exe | Added by the MULTIDR-CR TROJAN! |
| X | uwuxusif | jijikete.exe | Added by the SDBOT.AXW WORM! |
| X | uwyrl | uwyrl.exe | Added by the PHEL.A TROJAN! |
| X | uwyw.exe | yujixit.exe | Added by the SDBOT.BGB WORM! |
| X | uz | uz.exe | Added by the AGENT-GGH WORM! |
| U | V.92 Modem On Hold | Ltmoh.exe | Modem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet |
| U | V0220Mon.exe | V0220Mon.exe | Creative Live! Cam Console Auto Launcher |
| U | V0230Mon.exe | V0230Mon.exe | Creative Live! Cam Console Auto Launcher |
| Y | V0250Mon.exe | V0250Mon.exe | Part of Creative Webcam Launcher |
| Y | V128IID | Rundll32.exe v128iitw.dll, STB_InitTweak | Loads drivers for some STB graphics cards such as the STB nVIDIA TNT 16MB. Required if you don't want to experience lock-ups or error messages |
| ? | V128IITV | ?? | Loads drivers for some STB graphics cards. May be related to such a card with a TV out option? |
| X | V3smx4pnp | rundll32.exe [path] V3smx4pnp.dll | Added by the SMAXIN TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "V3smx4pnp.dll" file is found in C:\Documents and Settings\Administrator\Microsoft |
| ? | V66SHELL | V66SHELL.EXE | It looks to be part of the display driver set for ASUS V3800, V6600 and V6800 display adapters. Probably a system tray quick access control? |
| U | va10key | va10key.exe | Only required if you use the 10 kay bay unit with a Sony Vaio laptop |
| X | VaccineDataMain | VaccineData.exe | VaccineData rogue security software - not recommended, removal instructions here |
| X | VaccineLabMain | VaccineLab.exe | VaccineLab rogue security software - not recommended, removal instructions here |
| X | VaccineLabMain | VaccineLabPlus.exe | VaccineLabPlus rogue security software - not recommended, removal instructions here |
| X | VaccineTreeMain | VaccineTree.exe | VaccineTree rogue security software - not recommended, removal instructions here |
| X | VaCtrls | v7 | Downloader, detected as a variant of the ALPHABET TROJAN! |
| Y | Vade Retro Outlook Express | Vaderetro_oe.exe | Vade Retro anti-spam software for Outlook Express from GOTO software products |
| X | vadseinst | [path to trojan] | Added by the RANCK-CM TROJAN! |
| X | Vaganza-XPloit-[User Name]" | [user name].exe | Added by the GAVGENT.A WORM! |
| Y | VAGCtrl | VAGCTRL.EXE | Vexira Antivirus - virus scanner from Central Command |
| X | Vagiconline | vadaSq.exe | Added by the SDBOT-TD WORM! |
| Y | VAGuard | VAGNT.exe | Vexira Antivirus - virus scanner from Central Command |
| U | VAIO Action Setup (Server) | VAServ.exe | Sony Vaio utility that auto-launches selected applications when you plug in a digital video camera, digital still camera, etc. via iLink (FireWire) or USB |
| U | VAIO Recovery | PartSeal.exe | System backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhere |
| U | VAIO Update 2 | VAIOUpdt.exe | Related to Sony Vaio Update service |
| U | VAIOCameraUtility | VCUServe.exe | Sony VAIO Camera Utility for the built-in webcam on their VAIO range of laptops. Required if you want to use the utility but not if you use the webcam in other programs |
| X | ValidData | [path to trojan] | Added by the RANKY.H TROJAN! |
| X | valuename | svchosts.exe | Added by a variant of the SDBOT WORM! |
| X | ValueS0ft | [random filename] | Added by a variant of the SPYBOT WORM! See here |
| X | ValueX | [random filename] | Added by the IRCBOT.EE TROJAN! |
| X | ValuSet | MaJde.exe | Added by the SDBOT-OU WORM! |
| X | Vanyzim | axepis.exe | Added by the SDBOT.AXJ WORM! |
| X | VasddwDg | zxXZwd.exe | Added by the SDBOT-SN WORM! |
| X | VB_run | comctl_32.exe | Dubious downloader from densmail.com |
| X | vb6 | vb6.exe | Added by the MUGLY.D WORM! |
| X | vbcdtm | [random filename] | Added by a variant of the SLAPER TROJAN! |
| X | vbe | [random name].vbe | Added by the UISGON-A WORM! |
| X | vbe | win.vbe | Added by the LOSESLP-A WORM! |
| X | VBouncer | VirtualBouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | VbouncerDL | VbouncerInner****.exe [* = random char] | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | VbouncerDL | VBouncerInner.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| Y | VBoxTray | VBoxTray.exe | Part of the VirtualBox virtual machine software from Oracle. Required for the guest services to work properly |