| Status | Autorun name | Command | Description |
| X | USB 2.0 Driver | Winsys32.exe | Added by the AGOBOT-QM WORM! |
| X | USB 2.0 Driver | updateXP.exe | Added by the AGOBOT-QP WORM! |
| X | USB 2.0 Driver | winsystem.exe | Added by the AGOBOT-QS WORM! |
| X | USB 2.0 Driver | UpdateXPSP.exe | Added by the AGOBOT-QD WORM! |
| X | USB 2.1 Driver | winupdate1.exe | Added by a variant of the RBOT WORM! |
| U | USB 3.0 Monitor | nusb3mon.exe | Included with external USB 3.0 hard drives based upon NEC's µPD720200 controller (and maybe others in the future) such as the Western Digital My Book 3.0 range. Disabling it does not appear to cause a problem - but it may be required to achieve full USB 3.0 transfer speeds |
| X | USB controller | Svcmm32.exe | SvcMM backdoor parasite downloader |
| X | USB Device | servicelog.exe | Added by the WOOTBOT.CB WORM! |
| X | USB Device | win32usb.exe | Added by the FORBOT-BQ WORM! |
| X | USB Device Server! | usbserver.exe | Added by a variant of the IRCBOT TROJAN! |
| X | UsB driver | msjavx86.exe | Added by the AGOBOT-PQ WORM! |
| X | USB Driver4 | UpdateXP*.exe [* = random digit] | Added by a variant of the SDBOT WORM! |
| X | USB drivers | crv.exe | Added by the AUTORUN-HS WORM! |
| X | USB Drivers1 | msupdate.exe | Added by a variant of the RBOT WORM! |
| X | USB Driverz2 | msnplus1.exe | Added by the SDBOT-XQ WORM! |
| X | USB Fix 1.1 | wuservices.exe | Added by a variant of the SDBOT WORM! |
| X | USB Fixes | wuafix.exe | Added by the RBOT-ABV TROJAN! |
| X | USB Hardware Monitoring | USBhardware.exe | Added by the RBOT-NN WORM! |
| X | USB Hardware326 Monitoring | USBhardware326.exe | Added by a variant of the SPYBOT WORM! |
| X | USB Hardware32c Monitoring | USBHARDWARE32C.EXE | Added by the RBOT-UU WORM! |
| X | USB Host Service | usbsvc.exe | Added by the RBOT-GG WORM! |
| ? | USB Hub Keyboard Patch | SKBPATCH.EXE | USB HUB Update |
| X | USB MS Update | USBS.exe | Added by a variant of the RBOT WORM! |
| Y | USB SECURITY DEVICE CoInstaller | JupitCo.exe | ButterflyMedia USB Flash drive related - required for the password security feature to work |
| X | USB Updates | mservices.exe | Added by a variant of the SDBOT WORM! |
| X | USB Updates | msfirewalls.exe | Added by a variant of the RBOT WORM! |
| X | USB Updates 2 | wugfixx.exe | Added by a variant of the RBOT WORM! |
| Y | USB-TenKey | USBKPad.EXE | Multimedia USB keypad manager. Required if you use the additional keys |
| Y | USB-TenKey USBKPDrv | KPDRV4XP.EXE | Multimedia USB keypad driver. Required if you use the additional keys |
| X | usb_autorun_remover | wscript.exe usb$505$.wsf | Added by the AUTORUN.BO WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The "usb$505$.wsf" file is located in %ProgramFiles%\usb_autorun_remover |
| X | USB2.0 | usb-hi.exe | Added by the AGENT.US WORM! |
| N | USB2Check | PCLECoInst.dll | Related to Pinnacle Systems Inc. CoInstaller - you can execute the USB2.0 interface check program (Usb2Check.exe file) to check if your system is a USB2.0 enabled system |
| U | UsbBoost | TurboHddUsb.exe | LaCie USB Boost advanced driver for their range of USB hard disks which increases USB performance by up to 33%. Not required unless you use a supported external drive frequently |
| X | USBcillin | USBcillin.exe | Added by the USBCILL-A TROJAN! |
| X | USBConfigration2 | wmmndir.exe | Added by the AGOBOT-SV WORM! |
| X | UsbD | smss32.exe | Adware - detected by Kaspersky as the AGENT.CJ TROJAN! |
| X | UsbD | svhost32.exe | Added by the AGENT.IB TROJAN! |
| X | Usbd | usb_d.exe | Added by the CIDRA-A TROJAN! |
| X | UsbD | [path to trojan] | Added by the CIDRA-F TROJAN! |
| U | USBDetector | USBDetector.exe | USBDetector sets up an icon in the System Tray for a USB card which is intended to be used to eject or unplug hardware |
| U | USBDetector | UDetect.exe | USB tray icon/detection for external Belkin (and maybe other makes) under Win98 |
| X | usbdriverx.exe | usbdriverx.exe | SPYEYE.CE spyware |
| X | USBDrives | msfirewalI.exe | Added by the RBOT-ABP WORM! |
| X | usbdrv | servicetask.exe | Added by a variant of the SDBOT WORM! |
| Y | USBFW | USB FireWall.exe | USB Firewall by Net-studio.org - is "an application which protects you from malicious programs that attempt to start automatically each time you insert a USB device" |
| X | USBGuard | Y0tninam.exe | Added by the AUTORUN-BHQ WORM! |
| X | USBHWDRV | gam.exe | Added by a variant of the LOWZONE-I TROJAN! |
| X | USBHWDRV | msdc.exe | Added by a variant of the LOWZONE-I TROJAN! |
| X | USBHWDRV | sst4.exe | Added by a variant of the LOWZONE-I TROJAN! |
| X | USBHWINFO | mac.exe | Added by the LOWZONE-I TROJAN! |
| X | USBHWINFO | [path to trojan] | Added by the LOWZONE-I TROJAN! |
| X | USBHWINFO | sst6.exe | Added by the LOWZONE-I TROJAN! |
| Y | USBKBDrv | KPDrv4XP.EXE | Multimedia keyboard/keypad driver. Required if you use the additional keys |
| U | USBMMKBD | usbmmkbd.exe | USB multimedia keyboard for HP systems. Allows the use of special function keys on USB keyboards. The latest version no longer pings a server when on-line wheras the older version did but did not transmit any user information |
| U | USBMonit.exe | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives |
| ? | UsbMonitor | usbnotify.exe | Related to the TrueSuite Access Manager fingerprint recognition utility available on some Toshiba laptops - based upon TrueSuiteM by AuthenTec. What does it do and is it required? |
| X | usbn | usbn.exe | Adult content dialer - detected by Kaspersky as the SMALL.AFA TROJAN! |
| X | usbn | [path to trojan] | Added by the HOGIL-C TROJAN! |
| U | USBPhoneforSkype | USBPhoneforSkype.exe | USBPhoneForSkype uses Skype to dial out from a generic USB phone |
| U | UsbPhoneLinker | AtcomUsbDialer.exe | Dialer for Atcom USB phones |
| Y | USBPNP | USBPNP.exe | SiPix digital camera Twain USB driver |
| N | USBTA | usbtapnp.exe | System Tray access for the BeWAN Gazel 128 USB ISDN adapter |
| ? | USBToolTip | USBTip.exe | Related to Pinnacle Systems Inc. What does it do and is it required? |
| U | USCService | BcmDeviceAndTaskStatusService.exe | Part of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution" |
| X | USD Driver | ccrss.exe | Added by the SDBOT.BFH WORM! |
| X | USDR6cw | USDR6cw.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | useful-soft | svchst.exe | Added by the STARTPA-HH TROJAN! |
| X | user | user32.exe | Added by the BINGHE TROJAN! |
| X | User | .exe | Added by the PUNYA-B WORM! |
| X | user | users.exe | Added by the AUTORUN-AMK WORM! |
| X | User Debug Manager | usndebug.exe | Added by a variant of the SPYBOT WORM! See here |
| X | User Host | usnhost.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Hosting Service | usnhost.exe | Added by the IRCBOT.SN WORM! |
| X | User Input Services | CTFMON32.EXE | Added by the MANCSYN.AK TROJAN! |
| U | User Logger | UsrLog.exe | UserLogger commercial surveillance software that logs keystrokes, programs used and computer ID information. It also captures screenshots, can hide its presence on the computer and can be disguised in the Windows Task list. Uninstall this software if you did not install it yourself |
| X | user logon | [path to worm] | Added by the PAHATIA-A WORM! |
| X | user logon | user logon.exe | Added by the PAHATIA.A WORM! |
| X | User Manager | fcllls.exe | Added by the ZAGABAN-B TROJAN! |
| X | User Messages | usrmsg.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Messages Manager | usnmsgs.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Messenger Manager | usnmsgr.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Protection | usrprot.exe | User Protection rogue security software - not recommended, removal instructions here |
| X | User Servicer | usnsrvc.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Services | usersvc.exe | Added by the REVCUSS.A TROJAN! |
| X | User Services | usrsvc.exe | Added by the IRCBOT.SN WORM! |
| X | User Sharing | usrshare.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Sharing Manager | usnsharen.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Sharing Server | usnsrv.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | User Sharing Services | usnsvc.exe | Added by a variant of the KOBOT-C WORM! |
| X | User Sharing Wizard | usnshare.exe | Added by the SLENFBOT.DF WORM! |
| X | User23.exe | DIAL.exe | This is a trojan trying to disguise itself as User32.dll |
| X | User32 | [filename] | Added by the NETTRASH TROJAN! |
| X | Usercne | SVCH0ST.exe | Added by the LEGMI-AJH TROJAN! Notice the digit "0" in the filename rather than the upper case "o" |
| X | userd | systems.com | Added by the OUTLAW-A WORM! |
| N | UserFaultCheck | dumprep 0 -u | Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out |
| X | Userfile Sharing Serv | usnsrv.exe | Added by a variant of the IRCBOT TROJAN! See here |
| X | Userfile Sharing Server | usnserv.exe | Added by a variant of the IRCBOT TROJAN! |
| X | UserIMEsm | wualt.exe | Added by the AGENT-OIM TROJAN! |
| X | Userinit | lsass.exe | Added by the VIRAN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Program Files%\Common Files%\System |
| X | userinit | winlogon.exe | Added by the DLOADER-TP TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |