++ Salvation Army - Katrina & Rita - Red Cross ++
  New User? Need help? Click here to register for free! Registering removes the advertisements.

CastleCops            Microsoft MVP
image image image image image image

StartupList Index

Currently 12015 startuplist entries and growing...
Last updated on 2005-11-29 19:58:41 Eastern.
!! THESE ARE STARTUP PROGRAMS AND NOT TASK MANAGER PROCESS ITEMS !!


For more information on startup programs, including how to identify them and the information required for submitting additions to this list please refer to Content & Info. Reprinted with permission from Paul Collins who owns the copyright to the list. CastleCops also adds additional items that may not be in the original list but attempts are made to ensure the original is also updated. The full HTML list is here.

CastleCops is now hosting the official Pacs-portal forums. CastleCops has also cross-referenced startup entries with our File Hash database where appropriate. Comments or questions can be fielded here.

KEY:
  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown

  •   


    Full List

    NameStatusFilenameDescription
    WinCheckXservices.exeAdded by the W32.Sober.V WORM! Note: This worm file is found in the Windows\ConnectionStatus\Microsoft or Winnt\ConnectionStatus\Microsoft folder.
    WindowsXservices.exeAdded by the W32.Sober.X WORM! Note: This is not the legitimate Windows process services.exe (Which is always found in the System32 folder.) This worm file is found in the Windows\WinSecurity or Winnt\WinSecurity folder.
    !1_pgaccountYpgaccount.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks. You will see one instant of pgaccount.exe for every active account on your system, and this is essential for PG to work properly
    !1_ProcessGuard_StartupYprocguard.exeDiamondCS ProcessGuard security software - stops malicious worms and trojans from being executed silently in the background, as well as a variety of other attacks.
    !NoLoadUwinrecon.exeWinRecon - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
    $EnterNetUEnternet.exeConnection manager for the EnterNet ISP. You can also use RASPPOE
    $sys$cmpX$sys$xp.exeAdded by the Backdoor.Ryknos.B TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
    $sys$drvX$sys$drv.exeAdded by the Backdoor.Ryknos TROJAN! Attempts to utilize the Sony Rootkit A.K.A. SecurityRisk.First4DRM security risk to hide itself on the compromised computer.
    $WindowsRegKey%updateXIEXPLORE.EXEAdded by a W32/Rbot-EZ WORM! Note - this is not the legitimate Internet Explorer iexplorer.exe process, it should not appear in Msconfig/Startup unless you add it manually!
    %cmpmixtitle%?%cmpmixstr%Possibly related to C-Media Mixer Control panel?
    %FP%012-L2TP fts.exe?fts.exe012.Net ISP software - what does it do and is it required?
    %FP%012-L2TP FWPortal.exe?FWPortal.exe012.Net ISP software - what does it do and is it required?
    %FP%1776 Internet fts.exe?fts.exe1776 Internet ISP software - what does it do and is it required?
    %FP%1776 Internet FWPortal.exe?FWPortal.exe1776 Internet ISP software - what does it do and is it required?
    %FP%Barak013 fts.exe?fts.exe Barak013 ISP software - what does it do and is it required?
    %FP%Barak013 FWPortal.exe?FWPortal.exe Barak013 ISP software - what does it do and is it required?
    %FP%Friendly fts.exe?fts.exeFriendly ISP software - what does it do and is it required?
    (*)API MachineXwinSOCKS.exeHomepage hijacker, see here (* = any digit)
    (*)RunXwin32API.exeHomepage hijacker, see here (* = any digit)
    (default)X(random filename).exeAdded by the BLACKMAL VIRUS!
    (Default)XSystrsy.exe Added by the Trojan.Cdtray TROJAN! Note: This trojan file is found in the Internet Explorer folder.
    (default)Xllsass.exeAdded by the TROJ/PROXY-GG TROJAN!
    (Default)Xwebcam.exeAdded by the Troj/Monad-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    (Entry name)XSystem.exeAdded by the Troj/Nethief-N Trojan!
    (L4r1$$4) (4nt1) (V1ruz)XSP00Lsv32.pifAdded by the ASSIRAL.B WORM!
    (no name)Xpathex.exeAdded by the TROJ/MKMOOSE-A WORM!
    (Original file name)Xsvchost.scrAdded by Troj/Bancban-CX and Troj/Bancban-DA TROJANS!
    (Original filename)Xxphost.scrAdded by the Troj/Bancban-HM TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    (Original Trojan filename)XInstall.exeAdded by the Troj/Bancban-FS TROJAN! Note: This trojan file is found in the Windows or Winnt folder.
    (random 12 digit number)Xactxprxy.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavicap32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbrowser8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xavifile5.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcdmodem4.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xacctres8.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xautodisc.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcabview1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xatitvo32.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadvpack1.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbatmeter.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbidispl2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xasferror.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcatsrvps.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xaudiosrv.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xadmparse.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xbootvid2.exe Adsrv.com/IeDriver adware variant
    (random 12 digit number)Xcmpbk321.exe Adsrv.com/IeDriver adware variant
    (Random characters)Xsecurewinload32x.exeAdded by the Troj/OptixP-N TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. The file system32dir2a.exe will also be found in the same folder and should be deleted.
    (random name)X(random filename)Added by the Troj/StartPa-GL Trojan! Found in the WINDOWS or Winnt directory.
    (Random number)Xexplorer.exeAdded by the Troj/Keylog-AN TROJAN! Note: This trojan file is found in the Windows\service or Winnt\service folder, be sure to check the link for this one, It copies it's self under 9 additional file names, all in the Windows\service or Winnt\service folder.
    (random)Xlsass.scrAdded by Troj/Bancban-CW Trojan!
    (random)Xsvchost.scrAdded by Troj/Bancban-CY Trojan!
    (Random)Xsvshost.exeAdded by the W32/Kelvir-AX WORM! Note: This worm\trojan file is found in the System\(random folder name) (95/98/ME) or System32\(random folder name) (NT/2000/XP) folder.
    (Randomly chosen existing folder name)X_cfg.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_login.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_start.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_config.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_autorun.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_loader.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_env.exeAdded by the W32/Antinny-L WORM!
    (Randomly chosen existing folder name)X_setup.exeAdded by the W32/Antinny-L WORM!
    (Registry Value Name)Xroses.exeAdded by the W32/Rbot-AFT Worm!
    (Unknown)Xcharmapnt.exeAdded by the Troj/Bancos-DR TROJAN!
    (User name) configX(Path to Trojan exe)Added by the Troj/Mosuck-H TROJAN!
    (various file names)Xmediaplayer32.exeAdded by a variant of the WIN32.RBOT WORM!
    (various file names)Xbling.exeAdded by the W32/RBOT-NI WORM!
    (various names)Xwin32snd.exeAdded by the W32/RBOT-DQ WORM!
    (various names)Xsvchostss.exeAdded by a variant of the WIN32.RBOT WORM!
    (various names)XPasswdMon.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    (various names)Xrunload32.exeTROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
    *JanisRuckenbrodIIXjanis.comAdded by the POPS VIRUS!
    *Microsoft UpdateXwucxt.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwuytc.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXctxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXwstcl.exeAdded by the W32.HLLW.STMU TROJAN!
    *Microsoft UpdateXcxma.exeAdded by the W32.HLLW.STMU TROJAN!
    *microsoft updateXcxma.exeAdded by the W32.HLLW.STMU TROJAN
    *MS SetupX[random file name]Virtumondo adware, also known as the VUNDO TROJAN!
    *Security CenterXsecctr.exeAdded by the SDBOT.BRO WORM!
    *StateMgrYstatemgr.exeWindows ME default for System Restore. Do NOT disable!
    *windows updateXwurauclt.exeAdded by the W32/RBOT-SY WORM!
    *windows updateXwsctl.exeAdded by the SPYBOT.PR WORM!
    *windows updateXwscxt.exeAdded by the RBOT.AOS WORM!
    *windows updateXwkmst.exeAdded by the SDBOT.AVD WORM!
    *windows updateXwuaucrlt.exeAdded by the SPYBOT.HUR WORM!
    *windows updateXwaurclt.exeAdded by a variant of the WIN32.RBOT WORM!
    *WinLogonX[trojan path] ren time:[random number]Added by the VUNDO TROJAN!
    *winstatsXwinstats.exeAdded by the Trojan.Gargafx TROJAN! Note: This trojan file (winstats.exe) is found in the Windows or Winnt folder.
    *wuauclt.exeXw****.exe (* = random char)Added by a variant of the W32/RBOT-UG WORM! - NOTE: * in the file name represents a random char; variants spotted: wxmct.exe, wtmsv.exe, wxmst.exe, wmsvc.exe and so on...
    *wuauclt.exeXwmsvc.exeAdded by the W32/RBOT-UG WORM!
    ,main drive LoaderXwininfo.exeSuspected malware as it appears in 3 different registry locations - see here
    .mscdrXlassa.exeAdded by the WEBUS.C TROJAN!
    .mscdrXlsvchost.exeAdded by the WEBUS.D TROJAN!
    .mscdsrXlsvchost.exeAdded by the Troj/Bdoor-CR Trojan!
    .mscsblXsvhost.exeAdded by the BACKDOOR-CMQ TROJAN!
    .msfupdateXmsveup.exeAdded by the W32.ALLOCUP.A WORM!
    .mssecureXmssecure.exeAdded by the DDOS_BOXED.X TROJAN!
    .mssecureXmssecure.exeAdded by the Troj/Borobot-B Trojan!
    .NET config?sysmon32.exe??
    .nortonXrchost.exeAdded by a variant of the BOXED-A TROJAN!
    .ProgXservices.exeAdded by the NEVEG.B or NEVEG.C WORMS! Note - this is not the valid Windows Service Controller (services.exe ) process
    .ProgXwinlogon.exeAdded by NEVEG.A WORM! Note - this is not the valid Windows Logon winlogon.exe process
    .svchostXCSRSS.EXEAdded by the WEBUS.F TROJAN! - NOTE - this file is placed in the Winnt\System or Windows\System folder, and should NOT be confused with the legitimate Windows Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    .TEXTCONVXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process, which provides text window support, shutdown, and hard-error handling
    .WMAudioXcsrss.exeAdded by the WEBUS TROJAN! Note - this is not the valid Client Server Runtime Subsystem csrss.exe process" which provides text window support, shutdown, and hard-error handling
    .WMAudioXlsass.exeAdded by a Webus.B trojan infection. Note - this is not the legitimate Lsass.exe system file, which should normally NOT figure in Msconfig/Startup
    /l:engNN/ARelated to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appear on every startup
    000Upit.exeAdded by the PrivateEye SPYWARE! **Note - If you did not intentionally install this remove it.
    000hpdllhosXhpdllhost.exe LZIO.com adware downloader
    000StTHKU000StTHK.exeToshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output), etc...)
    0050726-007-i32-1X0050726-007-i32-1.exeAdded by the Troj/Bancban-EC TROJAN!
    00DSKSVR00Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00DSKSVR01Ndesksaver.exeRelated to Advanced_Desktop_Shield
    00THotkeyU00THotKey.exeFor Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev.
    0190 WarnerUWARN0190.EXEAnti-dialer program (Germany)
    0900 WarnerUWARN0900.EXEAnti-dialer program (Germany)
    0utlook ExpressX*****.exe (where * = random char)Added by the W32/RBOT-CC WORM!
    1X1.exeAdded by the ESTEEMS TROJAN!
    1Xsvchost.scrAdded by PWSteal.Bancos.X Trojan.
    1Xlsass.scrAdded by the PWSteal.Bancos.V TROJAN!
    11Xfaxcomdos.exeAdded by the Tuimer TROJAN!
    1111swapmgr.exeX1111swapmgr.exeAdded by the BDOOR-IC TROJAN!
    123456Xrundll32.exe shell32.dll, Control_RunDLL ...123456.cplAdded by the KITRO.C (or DANDI.A) VIRUS! 123456 can be any random 3 to 6 digit number
    12Ghosts Popup-KillerU12popup.exe12Ghosts Popup-Killer
    17779Proj2002?N/A??
    180adsolutionX180adsolution.exe 180Solutions/N-Case adware variant
    180axX180ax.exe 180Solutions/N-Case adware variant
    180ClientStubInstallXstubinstaller****.exe (* = digit) 180Solutions adware related
    180ClientStubInstallX******.exe (* = random digit/character) 180Solutions adware related
    180ClientStubInstallX******.tmp (* = random digit/character) 180Solutions adware related
    1:Nhpdrv.exeHP utility for monitoring when and how many recoveries have been done
    1A:MacVisionTrayMonitorNTrayMonitor.exeComes with the MacVision program for monitoring tray icons (Note : program is by Stardock)
    1A:Stardock MCPYmcpserver.exeMaster Control Program for Stardock apps, in development. People should leave it running if they're using any of the Stardock applications
    1A:Stardock TrayMonitorYTrayServer.exeFor monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX
    1CmailS?NETMAIL.EXE??
    1on1X1on1.exeAdult content dialler
    1Srv32USpyAgent4.exeSpyTech SpyAgent monitoring software. "Spy software that allows you to monitor EVERYTHING users do on your PC."
    1Win32CfgUSpyBuddy.exeSpyBuddy monitoring software
    1Win32CfgUKeyloggerpro.exeKeyloggerPro - monitoring software
    1WinCfg32X"\WebMailSpy.exeAdded by WebMailSpy SPYWARE!
    2020DownloaderXmssvr.exe2020Search Toolbar related. Reported to be auto-installed
    252Xwinmgr.exeAdded by the Troj/LegMir-AT TROJAN!
    27Xslsorve.exeAdded by the SLSORVE-A TROJAN!
    27Xcsrss32.exeAdded by the TROJ/SLSORVE-D TROJAN!
    27Xmsm32.exeAdded by the TROJ/SLSORVE-E TROJAN!
    2kadirasY2kadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    2thousandbuckX(path to file)Added by the RANKY.L TROJAN!
    2wSysTrayU2portalmon.exe2Wire Homeportal user interface
    32-bit Thunking serviceXthunk32.exeAdded by the W32.Derdero.A WORM!
    357AA41A-B7A8-4632-A27D-5B980B25CF43X[path to svchost.exe]Added by the SMALL-AQ TROJAN!
    357AA41A-B7A8-4632-A27D-5B980B25CF43Xservices.exeAdded by FakeMessage/AdRotator adware - NOTE - this file is placed in a Winnt\System32\Inetserv or Windows\System32\Inetsrv folder, and should NOT be confused with the legitimate Windows services.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
    3c1807pdY3cmlink.exe 3cpipe-3c1807pd3Com WinModem driver. See here for more WinModem information
    3capplnkY3capplnk.exeUS Robotics Modem driver
    3cdminicN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3CM LinkY3cmcnkw.exeRequired for a US Robotics WinModem as it provides the link to Windows - won't work without it.
    3CmlinkY3CmlinkW.exeFor a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinModem information
    3ComDMIAgentN3CDMINIC.EXE3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards
    3D TextN3D Text.scrAdded by the JERMY.A VIRUS!
    3Deep Control PanelU3DeepCTL.EXEFrom LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games
    3Dfx AccXGFXACC.EXEAdded by the GIBE VIRUS!
    3dfx Task ManagerN3dfxMan.exeSystem Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs
    3dfx ToolsY3dfxCmn.dllUpdates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards
    3dfxv2ps.dllY3dfxv2ps.dllUpdates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards
    3Dlabs Taskbar Display Manager?3DLman.exe3DLabs graphics driver related. System Tray access to display settings?
    3DLabsHelperDemonU3dldemon.exeDirectly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled
    3DMouse.EXEY3DMouse.EXEDritek System Inc. 3D Mouse driver
    3d_soundX3d_sound.exeAdded by the Troj/Riados-A TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder.
    3qdctl.exeU3qdctl.exeProvided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ
    3ware 3DMY3dm.exeMonitors status of the disk array on 3ware IDE RAID controllers
    4wd!!!XNatal!.pifAdded by the OPASERV.AI VIRUS!
    5-1-61-96Xmembers-area.exeAdult content dialler
    5-2-46-112X5-2-46-112.exeAdult content pop-up dialler. Removal instructions here
    55278Xgrepclient1.exeAdded by the Troj/Lineage-S Trojan!
    5p4mX(Path to Trojan)Added by the Troj/Litebot-C TROJAN!
    666XSka.exeAdded by the Troj/Pipes TROJAN!
    678Xlsas32.exeAdded by the Troj/Slsorve-C TROJAN!
    98D0CE0C16B1Xrundll32.exe D0CE0C16B1,D0CE0C16B1 BrowserAid/Startium parasite related
    9xadirasY9xadiras.exe Allied_Telesyn AT series router/modem related - apparently required
    9xHtProtectXAVprotect9x.exeAdded by the W32.NETSKY.M WORM!
    ;RundllX(random filename)Added by the PWSLEGMIR.E VIRUS!
    XRegsrv32.comAdded by the SOUTHGHOST VIRUS!
    XApp.exeAdded by the WAXPOW VIRUS! where <filename> is the executed filename
    Xwincpu.exeAdded by an unidentified VIRUS!
    Xelf.exeElf is a hacker program, tied to a trojan server
    ?ekio StartupsX?nksvc32.exeAdded by the W32/AGOBOT-OV WORM!
    @Xregedit -s ..win.dllAdded by the SEEKER.K VIRUS!
    @Hoc ToolbarNAtHoc.exeOne-click activated browsing toolbar used by various web-sites. See here for more info
    @lohaNreminder.exeRegistration reminder for @loha@home E-mail utility
    @tour_wwX@tour_ww[1].exeAdult content dialler
    aXa.exeCommercials file that registers itself in the system registry and redirects IE to a certain commercial website
    aXjesse.exeAdded by the W32/Melo-A WORM! Note: This worm file is found in the system32\drivers\etc folder.
    A New Windows UpdaterXw32NTupdt.exeAdded by W32.Mytob.BM WORM!
    a-squaredUa2guard.exe a-Squared antitrojan - can be run on demand, but necessary in Startup, if you prefer the a˛ 'Background Guard' real time protection feature
    a-winpoet-serviceYwinpppoverethernet.exeWinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking
    A1000 Settings UtilityUcpqa1000.exeCompaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features
    A4ProxyUA4Proxy.exeAnonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites
    A70F6A1D-0195-42a2-934C-D8AC0F7C08EBXrundll32.exe E6F1873B.DLL,D9EBC318C BrowserAid/Startium parasite related
    AAACLEAN?AAACLEAN.INF??
    AAAKeyboard?????
    AAATraySaverNTraySaver.exeSystem Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray
    AAKUaak.exeAdvanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere"
    AaouXamee.exe PurityScan/Clickspring adware
    AappXadprot AdBlaster adware
    aauclient?ACNUpdater.exeAppears to be related to software from Accenture.com - what does it do and is it required?
    ab EazyScheduler?ezsched.exe??
    ABBYY Community AgentNCAGENT.EXEInstalled with the Optical Character Recognition (OCR) software that comes bundled with a Compaq A3000 all-in-one printer/scanner. Its function appears to be to link you to the internet in an attempt to buy the 5.0 version of the software
    ABCXkeylogger.exeMonitors keystrokes so you can check if someone has typed anything while your away from your PC. Reported as spyware by SpyCop in their FAQ
    abcdefghXabcdefgh.exeMalware - detected by Panda antivirus as the DOWNLOADER.EPJ TROJAN!
    ABITEQNabiteq.exeMonitoring utility for ABIT Motherboards. Displays system voltages, temperatures and fan speeds.
    Absolute ShieldUdseraser.exeAbsolute Shield/Evidence Eliminator - iternet history eraser
    Absolute StartUp monitorUASMon.exeAbsolute Startup - startup monitor from F-Group Software
    ABsrXabsr.exeAdded by the AUTOUPDER VIRUS!
    absrXmwsvm.exeSeekSeek search hijacker related - as seen here
    abtuXmp3serch.exeLoads the executable for Lop.com. mp3serch.exe is the final version whilst lopsearch.exe is the beta version
    abtuXlopsearch.exeLoads the executable for LOP adware - mp3serch.exe is the final version whilst lopsearch.exe is the beta version
    AbyssWebServerUabyssws.exeAbyss web server
    AcBtnMgr_XxxYAcBtnMgr_Xxx.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    accUacc.exeAdvanced Call Center - "full-featured yet easy-to-use answering machine software for your voice modem"
    ACCDEFRAGINFOX(path to file)Added by the W32/Darby-O WORM!
    AccelerateUaccelerate.exeWebroot Accelerate - allows you to optimize Windows network registry settings in order to boost surfing speeds. Leave this enabled if you find it improves your connection
    Access Ramp MonitorNarmon32.exeMonitors your progress on the internet; hang-ups, connection speeds, internet congestion and traffic flow. It prevents some games from running also. To disable the Access Ramp Monitor (1) Open Windows Explorer (2) Open the Program Files folder (3) Open the MindSpring folder (4) Open the AccessRamp folder (5) Double-click on the ARMCfg32.exe file (6) Uncheck Enable Dialup Monitor and click OK (7) Restart the computer and try again
    Access WebControlX[path to file]Added by the TROJ/PPDOOR-M TROJAN!
    AccessManagerUAccessMgr.exePart of SmartPipes SecureSite software - "SecureSite enables rapid turnup and enhanced administration of VPNs. It automates and simplifies tasks for VPN design and policy management, access control management, and key management"
    AccessMedia P2P LoaderXamp2pl.exeMy AccessMedia toolbar related, stealth installed!
    AccessoriesPlusUclockplus.exe"Clock Plus", part of Accessories_Plus allows you to select from dozens of alternatives for the Windows clock.
    AccessRamp Monitor01NARMon32a.exeFrom a visitor "Just wanted to provide you with some info on Access Ramp software installed with Verizon DSL accounts in those areas that use the Winpoet PPPoE software. The Access Ramp TSRs are installed as part of IP Insight software (can't remember the software maker). You can decline to install IP Insight during Winpoet setup, or go into Add/Remove programs uninstall IP Insight by hand if it's already installed. It really doesn't do a darn thing for you. It was intended to help DSL techs monitor QoS, but the backend part was never implemented (at least as of earlier this year). This will not affect the user's ability or inability to access their DSL service."
    AccessRampLAN01NARUpld32.exeVersion of the above for LAN connections - a history uploader. The key in turning it off is a file named ARUCfg32.exe. This file (ARUCfg32.exe) does not show up in the startup process. If you have this file, you can execute it and remove all the monitoring activities it does. Removing all the checks in all the boxes (both tabs) still calls ARUpld32.exe to start when you start the dial up. You can block it from sending info if you have Zone Alarm installed. Renaming the extension of ARUCfg32.exe to ARUCfg32.exe1 works. The ARUpld32.exe is not loaded when launching the dial up client. Written by IP Insight and also included with Earthlink Total Access 2003
    AcctMgrUAcctMgr.exeNorton™ Password Manager - part of Norton SystemWorks 2004 - stores passwords and other personal information, and retrieves the data needed for email logins, shopping orders, banking, and other online activities—all from the safety of your own PC
    AccuWeather.com® DesktopN??Desktop weather from AccuWeather.com
    accwizz.exeXaccwizz.exeAdded by the W32.Ruland.A WORM!
    accwizzz.exeXaccwizzz.exeAdded by the W32.Ruland.A WORM!
    Acecad.WtxploadYWtxpload.exe Acecaddriver for an AceCad USB Graphics Tablet
    AceGain LiveUpdateNLiveUpdate.exe AceGain_LiveUpdate . "AceGain LiveUpdate provides a fully managed and customizable LiveUpdate platform that seamlessly integrates with a game. As soon as an update is made available, AceGain manages the alert, download and installation as well as version control and user network preferences."
    AcerGotoUAcerGoto.exeAcer Computer "Goto Drive" Cold Swap Driver - a swappable second disk drive provides convenient backup of large files, or easy importation of data from user's previous computer.
    AcerNotebookManagerUalmxptray.exeSystem Tray access on some Acer Notebooks to give faster access to system settings
    AcerPowerkeyUPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn F3
    AceuX[random file name] PurityScan/Clickspring adware
    AceUtilsNau.exeRelated to Ace Utilities from Acelogix_Software Note: this is NOT to be confused with the au.exe used by the BEAGLE.B worm!
    AClntUsrUAClntUsr.exeAltiris AClient Service Windows Tray Icon
    Acme.PCHButtonNpchbutton.exeUsed by HP Instant Support
    ACMonitor_XxxYACMonitor_Xxx.exeAssociated with the Lexmark Xxx (where "xx" is the model) all-in-one printer/scanner/copier. Required for correct operation
    acocashXfastdown.exe, fastfown.exeAdult content dialler
    Acombo3dmouseUAcombo3d.exeMouse driver - required if you use non-standard Windows driver features
    AcontiXaconti.exeAdult content dialler
    acousticUacoustic.exeControl panel program for Philips Acoustic Edge soundcard. Not required unless changed settings aren't retained
    acpartNagpart11.exeProgram for finding trucks on-line
    Acrobat AssistantUACROTRAY.EXEUsed to create PDF files with Acrobat Distiller. For Win9x/Me systems you can run this file manually beforehand. For WinXP systems this file must run at startup. Hence the "U" recommendation
    Acronis Scheduler2 ServiceUschedhlp.exePart of Acronis True Image - backup software. Co-operates with the "schedul2.exe" servuce to perform backup/restore tasks correctly. Required if you want to use TrueImage to do some real backup/restore tasks - not if you only want to explore/mount images
    Acronis True Image MonitorNTrueImageMonitor.exePart of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
    Acronis TrueImage MonitorNTrueImageMonitor.exePart of Acronis True Image - backup software. Can be disabled without affecting TrueImage
    AcronisTrueImage MonitorNTrueImageMonitor.exePart of Acronis_True_Image - backup software. Can be disabled without affecting TrueImage
    Action Manager 32Nam32.exeAssociated with a Plustech scanner. Small utility that runs in the background for doing fax/copy/etc. Available via Start -> Programs
    ActionAgent?actionagent.exe"A COM server that runs on the client as part of the Dell OpenManage Client Instrumentation 6.x package; provides a simple method for a remote administrator to perform actions on the instrumented client". Is it required?
    ActivationNActivation.exePart of Microsoft Money
    ActivboardUMMKeybd.exePackard Bell ActiveBoard keyboard - multimedia keyboard manager. Required if you use the additional keys and want to see the status of the Num Lock, Caps Lock, Scroll Lock keys
    Active Bit StationXabs.exeAdded by the W32.MYTOB.BZ WORM!
    Active Email MonitorUaem25.exe Active_Email_Monitor checks multiple accounts for email, serves as a SPAM filter and can also protect you from harmful items that can be sent via email.
    Active shieldUActiveshield.exe Active_Shield is "an heuristic screen that actively protects your computer from trojans, spyware, adware, trackware, dialers, keyloggers, and even some special kinds of viruses["
    ActiveDesktopXsystray32.exeAdded by the DABOOM VIRUS!
    ACTIVEDSXACTIVEDS.EXEAdded by the OPASERV.T VIRUS!
    ActiveEyesNActiveEyes.exeActiveEyes from TFI Technology
    ActiveMenuUActiveMenu.exeWild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
    ActivePlusUactiveplus.exeInteractive Agents Plugin for Messenger Plus! (MSN Messenger add-on)
    ActiveShieldYMCVSSHLD.EXEMcAfee VirusScan On-line. See also McAgentExe entry.
    ActiveSpeedUAS.exeAscentive ActiveSpeed Internet Optimizer
    ActiveX StreamerXmsgfix.exeAdded by the SDBOT.NQ WORM!
    ActiveXUpdateXsvcss.exeAdded by a variant of the DEDLER.C TROJAN!
    ActivityUactik.exe ActivityKey Keystroke logger/monitoring program - remove unless you installed it yourself!
    ActivSurfNbackweb*****.exePackard Bell ActivSurf - automatically detects an internet connection and downloads any available updates
    ActMakerUActMak25.exeThe ActMaker mouse and keyboard toolkit can record the daily operation of your computer and reduce your workload. You don't need to do any coding, nor are you required to know a lot about the computer.
    ACUUACU.exe Atheros wireless Client Utility For HP Compaq
    ACU_QSBUACU.exe Atheros wireless Client Utility For HP Compaq
    Ad BlockerUblocker.exeAd Blocker - blocks popups, and also removes banners, image ads and flash ads
    Ad Blocker ProUAd Blocker Pro.exe"Ad Away" popup and banner remover
    Ad MuncherUAdMunch.exeAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    Ad Online Guide?adonlineguide.exe??
    Ad-awareNAd-aware.exeAd-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
    Ad-AwareXAd-Aware.exeAdded by the W32/Rbot-ADJ Worm!
    Ad-Aware-6XWINDOWSUPDATER.EXEAdded by an unidentified WORM or TROJAN!
    Ad-MuncherUADMUNCH.EXEAd Muncher removes adverts, pop-ups and general annoyances in your browser, file-sharing and messenger programs. Causes conflicts with Outlook, game sites and web-building applications
    Ad-watchUAd-watch.exePart of Lavasoft Ad-aware Plus - realtime spyware-monitor watching your memory and registry for spyware that tries to install or change your system
    AD2KClientUAD2KClient.exeExecutable for Active Disk from Iomega disk - allows software applications to be run directly from an Iomega Zip® disk. Required if you wish the applications to launch on insertion of a disk
    Adaptec DirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    AdaptecDirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
    AdAwareXwini.exeAdded by the W32/RBOT-XN WORM!
    Adaware BootupNad-aware.exeAd-aware from Lavasoft. Checks your PC for "Spyware" which reports back your internet activities to "base". Available via Start -> Programs
    Adaware lptt01 or Adaware ml097eXadaware.exeVariant of the RapidBlaster parasite (in a "Adaware" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here. Note - this is not the valid Lavasoft Adaware
    Add**.exe (* = random char)XAdd**.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log
    Add**32.exe (* = random char)XAdd**32.exe (* = random char) CoolWebSearch/HomeSearch adware component - for examples, see this log.
    AddClassX(Path to Trojan)Added by the Troj/SecDl-A TROJAN!
    AdDeleteUAdDelete.exeBanner advertisment blocker
    AdDestroyerXAdDestroyer.exeLike VirtualBouncer, malware from Spyware Labs. It is distributed by the same bundling and drive-by download techniques as the malware it claims to remove/prevent, so definitely qualifies as unsolicited commercial software in itself. It also has an update feature that can download and execute arbitrary code
    ADG?ADG.exe SoundBlaster Audigy related?
    ADGJdetNADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
    AdirasYAdiras.exeADSL USB modem related
    ADM Library LoaderXadmlib32.exeAdded by a variant of the SDBOT WORM!
    Admanager ControllerXAdManCtl.exeWindUpdates ADW_WINAD.M adware
    Admilli ServiceXAdmilliServ.exeWindUpdates AdmilliServ adware
    AdministratorXsvchost.scrAdded by the Backdoor.Novacal TROJAN! Note: This trojan file is found in the Windows\Fonts or Winnt\Fonts folder.
    AdminSoftXsysfile.vbsAdded by the VBS/STARGRUB-A WORM!
    AdobeXAdobe.exeAdded by an unidentified VIRUS!
    AdobeXsysconfig.exeAdded by an unidentified WORM or TROJAN!
    AdobeXsysbat32.exeAdded by the TROJ_LOWZONES.T TROJAN!
    adobeXgam.exeAdded by an unidentified WORM or TROJAN!
    AdobeXzteam.exeAdded by an unidentified TROJAN!
    Adobe Acrobat Distiller ApplicationXacrotray.exeAdded by the W32.RANDEX.DFJ WORM!
    Adobe Acrobat Reader CFGX[random file name]Added by a variant of the