| Status | Autorun name | Command | Description |
| U | BO1HelperStartUp | Bo1helper.exe | ScreenScenes "Butterfly Oasis" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | BoanSystem | launcher.exe BoanSystemUp.exe | BoanSystem rogue security software - not recommended, removal instructions here. Both files are located in %ProgramFiles%\BoanSystem |
| X | Boarddata | [path] repcale.exe [path] palsp.exe | Added by a variant of the RANDON.AN WORM! Both files are often located in %System% |
| X | boat32 | boat32.exe | Added by a variant of the RBOT WORM! |
| X | boby | csrs.scr | Added by the BANCBAN-PC TROJAN! |
| X | boby | netburn.scr | Added by the BANCBAN-OX TROJAN! |
| X | boby. | Isass.scr | Added by the BANCBAN-OH TROJAN! |
| Y | BOC-412 | BOC412.exe | NSClean (now Comodo) BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.12 |
| Y | BOC-420 | BOC420.exe | NSClean (now Comodo) BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.20 |
| Y | BOC-421 | BOC421.exe | NSClean (now Comodo) BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.21 |
| Y | BOC-422 | BOC422.exe | NSClean (now Comodo) BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.22 |
| Y | BOC-423 | BOC423.exe | Comodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.23 |
| Y | BOC-424 | BOC424.exe | Comodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.24 |
| Y | BOC-425 | BOC425.exe | Comodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.25 |
| Y | BOC-426 | BOC426.exe | Comodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.26 |
| Y | BOC-427 | BOC427.exe | Comodo BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely". Version 4.27 |
| Y | BOCleanautostart | Boclean.exe | NSClean (now Comodo) BOClean anti-malware software - "Protect yourself from online identity theft. The greatest threat on the Internet today is having your personal information hijacked remotely" |
| U | BOINC Manager | boincmgr.exe | BOINC manager - "controls the use of your computer's disk, network, and processor resources" |
| U | Boingo Wireless Utility | Icon###XXX#X#.exe | Starts the Boingo Wireless utility, used to detect and login into Boingo wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start -> Programs |
| N | Bol IM | RediffMessenger.exe | Rediff Bol instant messenger |
| X | bolenja | bolenja.exe | Added by the WANTVI.BF TROJAN! |
| X | bolenjx | bolenjx.exe | Added by the ELDYCOW.O TROJAN! |
| X | boler.exe | syser.exe | Added by the RBOT-AYS WORM! |
| U | bombshel | BOMB32.EXE | Part of McAfee Nuts & Bolts. Protects your Windows system from application failure and crashes - similar to Norton Crashguard. Your choice - may cause problems |
| N | Bonus.SSR.FR10 | Bonus.ScreenshotReader.exe | Bonus version of the ABBYY Screenshot Reader utility available to registered users of ABBYY FineReader version 10. ABBYY Screenshot Reader allows you to 'Create your own "snapshots" of images and texts from opened documents, file menus, Web pages, presentations, or PDF files with just several clicks' |
| X | Bonzi Buddy | ?? | BonziBuddy adware - see here for removal instructions |
| X | BONZI Task Switcher | Taskswitch.exe | Added by the SPYBOT.DTR WORM! |
| X | boo | boo.exe | Adware downloader - detected by Kaspersky as the FAVADD.O TROJAN! |
| X | BookedSpace | RunDLL32.EXE bs2.dll,DllRun | BookedSpace parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "bs2.dll" file is located in %Windir% |
| U | Bookmark | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" |
| U | Bookmark.exe | bookmark.exe | System Tray access to Power Favorites by Desksware - which "is a bookmark manager for Windows that helps you organize and synchronize your bookmarks. It takes bookmarks from Internet Explorer, Firefox or Opera, merges them into one file, and automatically synchronizes them between computers. You can use it to detect dead links and duplicates if you have many bookmarks" |
| N | BookmarkCentral | BMLauncher.exe | Bookmark Express - "offers a more flexible way to manage Web site bookmarks, regardless of which browser you use". No longer available |
| N | BookMarkSink | syncit.exe | Bookmark synchronization utility |
| N | BookMarkSync | syncit.exe | Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
| N | BookMarkSync2It | sync2it.exe | Sync2IT BookMarkSync - "real-time automatic synchronization service that allows you to access your bookmarks, favorites and favorite files from any computer or any browser". Only installed with the users explicit permission and generally only remains running if the user decides to subscribe to the service. If it is no longer required it should be uninstalled to prevent a large number of clients 'checking in' to the server that have no chance of synchronizing |
| U | Boost XP Service | bxservice.exe | Boost XP from Systweak - WinXP tweaking utility |
| U | BoostSpeed | boostspeed.exe | System Tray access to Auslogics BoostSpeed 4 system optimization utility - which "Start programs faster. Speed up computer start time. Increase Internet speed, optimize your Internet Explorer, Firefox and E-mail programs" |
| X | boot | boot.exe | Added by the PUPPET-A TROJAN! Located in the %System% |
| U | Boot | Boot.exe | Part of Acer Empowering Technology. "Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles, or to create their own customized profiles". Located in Acer\Empowering Technology\ePower |
| X | Boot Check | bootchk.exe | Added by the DELBOT-AB WORM! |
| X | Boot Client | bootcli.exe | Added by the IRCBOT-ACF BACKDOOR! |
| X | Boot Config | bootconfig.exe | Added by the FLOOD-EV TROJAN! |
| X | Boot K | bootk.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Boot Manager | Njgal.exe | Added by the KILO TROJAN! |
| X | Boot Manager | bootmng.exe | Added by a variant of the SPYBOT WORM! |
| X | Boot Server | bootserver.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Boot Service | bootservice.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Boot Service | bootsv.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Boot Verify | bootvfy.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | boot_reg | [path to file] | Added by the BANCBAN-CA TROJAN! |
| X | boot_reg | svchot.exe | Added by the BANCBAN-BQ TROJAN! |
| X | BootCfg | Install.log.vbs | Added by the YPSAN.D WORM! |
| X | BootClean | smartdrv.exe | Added by the LURKA-A VIRUS! |
| X | BootCTRL | bootctrl.exe | Added by an unidentified WORM or TROJAN! |
| X | BootLoader | BootLoader.exe.vbs | Added by the WATERWORKS WORM! |
| X | bootpd.exe | bootpd.exe | Added by the AGENT-DT TROJAN! |
| ? | Boots Insert Detect | InsDetect.exe | Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? |
| X | BootsCfg | wscript.exe [path] Date.POP.vbs | Added by the KUULLIO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe [path] All Users.vbs | Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe [path] All Users.vbe | Added by the SPILTRON WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | BootsCfg | wscript.exe Install.log.vbs | Added by the YPSAN.E WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "Install.log.vbs" file is located in %System% |
| X | bootsec | NAVSSE.exe | Added by the FORBOT-CY WORM! |
| U | BootSkin | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page |
| U | BootSkin Randomizer | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page |
| U | BootSkin Startup Jobs | BootSkin.exe | Part of BootSkin XP by Stardock - which allows the user to change their Windows XP boot (loading) screens. This entry is required if the user chooses to select a random boot screen at startup and doesn't remain in memory. No longer supported but still available from the BootSkin downloads page |
| U | BootStatus | BOOTST~1.EXE | Visual Basic program that pops up a small window on startup telling you how many times the machine has been booted that day. Once you exit it, it has no more effect on resources |
| U | BootWarn | BootWarn.exe | Used to warn the end-user that they must reboot their PC when using older versions of Norton AntiVirus in those cases where a reboot did not happen after installation or a significant software update via LiveUpdate. See the AnswersThatWork entry for a more detailed description |
| X | boowudo | fafegoubu.exe | Added by the LINEAG-FX TROJAN! |
| X | boqamah | dytevevi.exe | Added by the SDBOT-UH WORM! |
| X | BortMedVirus | pgs.exe | BortMedVirus rogue security software - not recommended. A member of the AVSystemCare family |
| U | borzoi | blg.exe | Borzoi surveillance software. Uninstall this software unless you put it there yourself |
| N | Bose Wave/PC Monitor | wavepcmonitor.exe | System Tray access for this system (more info on the system here). Available via Start -> Programs |
| X | BossIdea | winlogin.exe | Added by the LINEAGE-I TROJAN! |
| ? | Boston | Boston.exe | Part of the Boston Acoustics USB speaker systems. What does it do and is it required? |
| X | Bot Loader | svchostt.exe | Added by the GAOBOT.ALV WORM! |
| X | Bouncer RunStartup | bouncer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | Bouncer RunStartup | LiveUpdate.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | boy lovers of bsd | ilikeboys.exe | Added by the MYTOB.LY WORM! |
| U | bpcpost.exe | bpcpost.exe | MS TV Viewer Post Setup Program. Part of MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it |
| X | BPCV2 | BPCV2.exe | BroadcastPC adware |
| X | BPCv2 re | bpc2 re inst.exe | BroadcastPC adware variant |
| U | BPK | bpk.exe | Blazing Tools Perfect Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! |
| X | BPSANTISPY | SpyWatch.exe | BPS Spyware Remover rogue spyware remover - not recommended, removal instructions here |
| N | BPServer | G6FTPSrv.exe | BulletProof FTP Server |
| U | BQTray.exe | BQTray.exe | System Tray access to BurnQuick CD burning software. Only required if you use the queueing facility, hence the U recommendation. Create your own desktop shortcut to start manually |
| X | Brasil | Brasil.exe | Added by the OPASERV.E WORM! |
| X | Brasil | BRASIL.PIF | Added by the OPASERV.E WORM! |
| X | BrasilOld | [worm filename] | Added by the OPASERV.P WORM! |
| X | brastk | brastk.exe | Added by the DORF-BV TROJAN! |
| X | Brave-Sentry | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here |
| X | BraveSentry | BraveSentry.exe | BraveSentry rogue security software - not recommended, removal instructions here |
| X | braviax | braviax.exe | Added by the FAKEALER.LE TROJAN! |
| X | Brct | trdb.exe | Detected by Kaspersky as the PURITYSCAN.Y TROJAN! |
| X | Break.exe Espanha | Break.exe | Added by an unidentified TROJAN! See here |
| U | Break_Reminder | BREAK REMINDER.exe | Break Reminder - Remind yourself to take breaks to prevent computer related injuries. See here |
| Y | Bredbandsbolaget | servicecenter.exe | Related to the Brebband Swedish Broadband provider |
| X | Breg | bcre.exe | BroadcastPC adware variant |
| X | Breg | bptre.exe | BroadcastPC adware variant |
| X | Breg | breg.exe | BroadcastPC adware |
| X | Bridge | rundll32.exe [path] Bridge.dll,Load | WinFavorites adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "Bridge.dll" file is located in %System% |