| Status | Autorun name | Command | Description |
| U | Acronis Scheduler2 Service | schedhlp.exe | Part of Acronis True Image - backup software. Co-operates with the "schedul2.exe" service to perform backup/restore tasks correctly. Required if you want to use True Image to do some real backup/restore tasks - not if you only want to explore/mount images |
| U | Acronis True Image | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | Acronis True Image Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| N | Acronis TrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| N | Acronis*True*Image Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| U | AcronisTimounterMonitor | TimounterMonitor.exe | Part of Acronis True Image backup software. Monitor for the backup archive explorer for moving and viewing files within an archive |
| N | AcronisTrueImage Monitor | TrueImageMonitor.exe | Part of Acronis True Image - backup software. Can be disabled without affecting TrueImage |
| X | Acroread | AcroRD32.exe | Added by the DLOADR-BDK TROJAN! Note - this is not the popular Adobe Reader |
| X | Acroread | GoogleUpdate.exe | Added by the AGENT-JGI TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %Temp% |
| X | Acroread | AdobeUpdater.exe | Added by the DWNLDR-IYR TROJAN! Note - this is not the legitimate Adobe "AdobeUpdater.exe" file which is normally located in %ProgramFiles%\Common Files\Adobe\Updater5. This one is located in %Temp%. |
| U | Acrotray | Acrotray.exe | Installed with the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) |
| U | AcroTray - Adobe Acrobat Distiller helper application. | Acrotray.exe | Installed with the Adobe Acrobat PDF creation/editing utility. Used when PDF files are created from non Adobe applications through the "Watched Folders" feature of Acrobat Distiller (which is the main engine for turning PostScript files into PDF files) |
| U | ACS_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for ACS users |
| U | Act! Preloader | Act8.exe | Sage Software's ACT! "enables individuals and small business customers to instantly access key contact and customer information, manage and prioritize activities, and track all contact-related communications so you can grow productive business relationships" |
| N | Action Manager 32 | am32.exe | Associated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs |
| ? | ActionAgent | actionagent.exe | "A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required? |
| ? | Activate Scanner | ACTIVATE.EXE | Part of older versions of the range of internet security products from Quick Heal - including Total Security, Internet Security and AntiVirus. Also included by vendors who use the Quick Heal engine such as Omniquad and iQon. What does it do and is it required? |
| N | Activation | Activation.exe | Part of MS Money 2002 |
| U | Activboard | MMKeybd.exe | Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys |
| U | ACTIVBOARD | ABoard.exe | Packard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys |
| Y | ActivClient Agent | acsagent.exe | Part of ActivIdentity ActivClient - security software from ActivIdentity Corporation which "enables organizations to secure workstations with smart cards and smart USB tokens while enforcing strong authentication for desktop access and network login" |
| X | Active Bit Station | abs.exe | Added by the MYTOB.BZ WORM! |
| U | Active CallerID | CallerID.exe | Active Caller ID from SoftRM - "is a powerful full-featured Caller ID detection software that will turn your PC into an advanced Caller ID device. It uses your MODEM and Caller ID service provided by your local phone company in order to identify who's calling" |
| N | Active CPU | acpu.exe | Active CPU - "easy to use tool for Windows 95/98/ME/NT/2000 that enables you to watch a graphical representation of your CPU's activity" |
| U | Active Desktop Calendar | ADC.EXE | XemiComputers Active Desktop Calendar |
| U | Active Email Monitor | aem25.exe | Active Email Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email |
| X | Active Security | asecurity.exe | Active Security rogue security software - not recommended, removal instructions here |
| U | Active shield | Activeshield.exe | Active Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses" |
| Y | Active Virus Shield | avp.exe | System Tray access to and notifications for AOL's Active Virus Shield (by Kaspersky) - found in %ProgramFiles%\AOL\Active Virus Shield. Runs together with a related service - Active Virus Shield (AVP) - which runs a separate instance of the same file |
| X | ActiveDesktop | systray32.exe | Added by the DABOOM WORM! |
| X | ACTIVEDS | ACTIVEDS.EXE | Added by the OPASERV.T WORM! |
| N | ActiveEyes | ActiveEyes.exe | ActiveEyes from TFI Technology is a small utility that you can use to liven up your desktop. It follows your mouse around and can tell you how far your cursor has travelled or point out where the cursor is. It's small, it's free and comes with a range of options and animations. Not needed - if unavailable via Start -> Programs, create your own shortcut |
| U | ActiveKeys.AAB635BD7D054a37A576 | akeys.exe | "Active Keys is a powerful yet easy-to-use tool for creating and managing keyboard shortcuts for any system action" |
| U | ActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| U | ActivePlus | activeplus.exe | Interactive Agents Plugin for Messenger Plus! (MSN Messenger add-on) |
| X | ActiveScan Antivirus | ActiveScan.exe | Added by the RBOT-FKQ WORM! |
| X | ActiveScript32 | nod.exe | Added by the SOHANA-AJ WORM! |
| Y | ActiveShield | mcvsshld.exe | ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed, including scanning E-mails via the McAfee VirusScan E-mail Scan Module (McVSEscn.exe) |
| N | ActiveSpeed | AS.exe | Ascentive ActiveSpeed internet optimizer - not recommended, see here and here |
| X | ActiveSync | wcescom32.exe | Added by the MANCSYN-E TROJAN! |
| N | ActiveWords | AWMonitor.exe | ActiveWords from ActiveWord Systems, Inc. Like macro programs, ActiveWords sits in the background and watches as you type. When it recognizes that you've typed an ActiveWord, it takes the associated action, such as replacing your keystrokes with the text you've defined |
| X | ActiveX File Registration Service | filereg.exe | Added by the RBOT-DVD WORM! |
| X | ActiveX Streamer | msgfix.exe | Added by the SDBOT.NQ WORM! |
| X | ActiveXUpdate | svcss.exe | Added by a variant of the DEDLER.C TROJAN! |
| U | Activity | actik.exe | ActivityKey keystroke logger/monitoring program - remove unless you installed it yourself! |
| N | ActivSurf | backweb*****.exe | Packard Bell ActivSurf - automatically detects an internet connection and downloads any available updates |
| U | ActMaker | ActMak25.exe | "ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer" |
| U | ActMaker | ActMaker25.exe | "ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer" |
| U | ACTray | ACTray.exe | System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" |
| U | Actual Window Manager | ActualWindowManagerCenter.exe | Actual Window Manager from Actual Tools - "an innovative desktop organization application which introduces unconventional window controls and also automatic general window operations making your work more productive, convenient and enjoyable" |
| U | Actual Window Minimizer | ActualWindowMinimizerCenter.exe | Actual Window Minimizer - "allows minimizing any window to task tray notification area or to the edge of the screen" |
| X | ACTX1 | v1201.exe | Added by the VB.IS TROJAN! |
| U | ACU | ACU.exe | Atheros wireless Client Utility |
| U | ACU_QSB | ACU.exe | Atheros wireless Client Utility |
| U | ACWLIcon | ACWLIcon.exe | Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically." This is the System Tray icon giving notifications of and access to the Wireless Connection Status |
| U | Ad Arrest | adarrest.exe | Ad Arrest IE popup killer from GameFools |
| U | Ad Blocker | blocker.exe | Ad Blocker - blocks popups, and also removes banners, image ads and flash ads |
| U | Ad Blocker Pro | Ad Blocker Pro.exe | Ad Away popup and banner remover |
| U | Ad Muncher | AdMunch.exe | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
| ? | Ad Online Guide | adonlineguide.exe | ?? |
| U | Ad-Aware | Ad-Aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool |
| X | Ad-Aware | Ad-Aware.exe | Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware anti-malware tool and is located in %System% |
| Y | Ad-Aware Personal Firewall | GDFirewallTray.exe | Part of the firewall included with Lavasoft's Ad-Aware Total Security internet security product (which is based upon TotalSecurity from G Data Software AG). Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it running |
| Y | Ad-Aware Total Security | AVKTray.exe | System Tray access to and notifications for Lavasoft's Ad-Aware Total Security internet security product (which is based upon TotalSecurity from G Data Software AG). If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates |
| X | Ad-Eliminator | ad-eliminator.exe | Ad-Eliminator rogue spyware remover - not recommended, see here |
| U | Ad-Muncher | ADMUNCH.EXE | Ad Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications |
| U | Ad-Protect | ad-protect.exe | Ad-Protect spyware and spam monitoring tool |
| U | Ad-watch | Ad-watch.exe | Part of older versions of the Plus and Pro versions of Ad-Aware from Lavasoft - realtime monitor watching your memory and registry for malware that tries to install or change your system |
| U | Ad-Watch | AAWTray.exe | System Tray access to older versions of the Lavasoft Ad-Aware anti-malware tool |
| U | AD2KClient | AD2KClient.exe | Active Disk from Iomega - allows software applications to be run directly from compatible removable media such as Zip®, Rev, FireWire, USB and Mini flash. Required if you wish the applications to launch on insertion of a disk |
| N | Adaptec DirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
| N | AdaptecDirectCD | Directcd.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later |
| X | AdAware | wini.exe | Added by the RBOT-XN WORM! |
| U | Adaware Bootup | Ad-aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool |
| X | Adaware lptt01 | adaware.exe | RapidBlaster variant (in a "adaware" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Lavasoft Ad-Aware |
| X | Adaware ml097e | adaware.exe | RapidBlaster variant (in a "adaware" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the valid Lavasoft Ad-Aware |
| U | AdBin | AdBin.exe | AdBin - "Free and easy solution to managing your Window's hosts file. A fun way to block ads" |
| X | adcareup | adcareup.exe | AdCare rogue security software - not recommended, removal instructions here |
| X | Add**.exe [* = random char] | Add**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Add**32.exe [* = random char] | Add**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | AddClass | AddClass.exe | CoolWebSearch Addclass parasite variant |
| X | AddClass | [Installation_Path] | Added by the STARTPAGE.F hijacker |
| X | AddClass | [path to trojan] | Added by the SECDL-A TROJAN! |
| U | AdDelete | AdDelete.exe | Banner advertisment blocker |
| X | AdDestroyer | AdDestroyer.exe | Virtual Bouncer - malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the parasites it claims to remove, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code. Warning - choose "custom" uninstall as "automatic" may remove other programs - see here |
| X | Additional Guard | WI[random characters].exe | Additional Guard rogue security software - not recommended, removal instructions here |
| X | ADDITIONAL Services | pkgadd.exe | Added by a variant of the IRCBOT TROJAN! |
| X | addons | addon.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here |
| X | AddrPlus3 | [path] stup.exe [path] Adplus.dll Rundll32 | TCent adware |
| ? | ADG | ADG.exe | SoundBlaster Audigy related? |
| N | ADGJdet | ADGJDet.exe | Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection |
| Y | adi CleanUp | CleanUp.exe | Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards to clean-up the files no longer required once the installation is complete. Other programs/drivers may use the same filename for the same purpose. In this case, the file is located in %System% and is listed under the HKLM\RunOnce registry key |
| Y | adi DSndUp | DSndUp.exe | Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on |
| X | aDir | adirss.exe | Added by the SPAMSRV-E TROJAN! |
| Y | Adiras | Adiras.exe | ADSL USB modem related |
| X | adirka | adirka.exe | Added by the TIBS-QT TROJAN! |
| X | AdKiller | AD Defender.exe | Part of the Advanced Spyware Remover rogue spyware remover - not recommended, see here |
| X | adlhidp | psncc32.exe | Added by the SLAPER.AI TROJAN! |
| X | ADM Library Loader | admlib32.exe | Added by a variant of the SDBOT TROJAN! |
| X | Admanager Controller | AdManCtl.exe | Adware, probably a Windupdates variant |