| U | Y!TunnelPro | YTunnelPro.exe | Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia |
| U | Y!TunnelPro | YTPro.exe | Spam, bot and ad blocker for Yahoo! Messenger from Digital Asphyxia |
| X | yahoo groups | upgrdmgr.exe | Added by a variant of the RBOT WORM! |
| ? | Yahoo HP Reminder 1.1 | yr.exe | ?? |
| X | Yahoo Instant Messengar | YahooMsgr.exe | Added by the SDBOT.GEN TROJAN! |
| X | Yahoo Messenger | Yahoomsg.exe | Added by an unidentified WORM or TROJAN! |
| X | Yahoo Messenger | YPager.exe | Added by the RBOT-QO WORM! |
| X | Yahoo Update | Yahoo.exe | Added by the YAHOO! TROJAN! |
| N | Yahoo! Pager | ypager.exe | Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs |
| X | YahooStock | Prmvr.exe | Adtomi adware |
| X | YahooStock | ystckAO32.exe | Adtomi adware |
| X | yahoo_toolbar lptt01 | yahoo_toolbar.exe | Variant of the RapidBlaster parasite (in a "yahoo_toolbar" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| X | yahoo_toolbar ml097e | yahoo_toolbar.exe | Variant of the RapidBlaster parasite (in a "yahoo_toolbar" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here |
| N | YAMAHA DS-XG Launcher | dslaunch.exe | System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups |
| N | Yankee Clipper III | YankClip.exe | Yankee Clipper III - 'A super powerful Windows clipboard extender/memory - now in its third generation. Handles Pictures, Richtext, URLS, etc - any size. Features printing, drag and drop, optional permanent storage of clippings. Familiar "Outlook" interface'. Freeware |
| N | YBrowser | ybrwicon.exe | SBC Yahoo! Browser system tray icon |
| X | yeahdude.exe | hallowelt.exe | Added by the GAOBOT.RS or GAOBOT.SA WORMS! |
| U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures® Screensaver |
| ? | YOW tuner | WatchPNM.exe | ?? |
| N | ypager | ypager.exe | Yahoo! Messenger allows you to send instant messages. Available via Start -> Programs |
| U | YPC | ypc.exe | Yahoo Parental controls - "Let you decide what type of sites and Yahoo! services your kids can access" |
| Y | YTrayMagic Lite 1 | YTRAYMAGIC.EXE | YTrayMagic from YoconSoft automatically restores your tray icons after an Explorer(the windows shell) crash. Leave to run at startup since only those icons that are in the taskbar after YTrayMagic has initialized will be restored |
| X | ywzizdon | ywzizdon.exe | Free_Scratch_Cards foistware |
| X | yyyyyyyy | [path to trojan] | Added by the MUMUBOY.B TROJAN! |
| X | yz.exe | yz.exe | Added by the VARDO TROJAN! |
| X | YZH.SYS | YZH.exe | Added by the SOPHILY VIRUS! |
| U | z-WrDialer | WrDialer.exe | WinPoet DSL dialer |
| X | ZaCker | [filename].PIF | Added by the HOLAR.A WORM! |
| X | Zacker | Zacker.exe | Added by the GEMEL WORM! |
| X | zango | zango.exe | 180Solutions/N-Case adware variant |
| Y | Zapro | Zapro.exe | Firewall program from Zonelabs - paid for version |
| U | zBrowser Launcher | iTouch.exe | For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
| U | zBrowser Launcher | Commandr.exe | For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
| ? | zcb | zcb.exe | ?? |
| X | zcproo | qssstiej.exe | Possible homepage hijacker installing a toolbar: http://tdko.com/ ,Lop.com in disguise. see this thread |
| N | zdnet | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
| N | Zebus | msdc32.exe | Runs a HTML tutorial on the Zebus web-site |
| X | Zen.A | [path to trojan] | Added by the ZOOMEN-A TROJAN! |
| X | Zenet | rundll32 CNBabe.dll, DllStartup | CommonName Toolbar spyware. To uninstall see here |
| Y | ZENRC | zenrc32.exe | The main component of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Leave well alone |
| Y | ZENRC Tray Icon | zentray.exe | Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management". Best left alone |
| Y | ZENworks Imaging Service | ZISWin.exe | Imaging Agent. Part of Novell's ZenWorks - "Complete End-to-End Directory-enabled Network Management" |
| U | ZeroAds | 0 | ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually |
| U | ZeroAds | LAS0Ads.exe | ZeroAds - culls ads, cookies and pop-ups. Required for the cookie interception to work |
| U | ZeroSpyware | ZeroSpyware.exe | FBM Software ZeroSpyware 2004 spyware detector and remover |
| X | zervpack2 | update2.exe | Added by the SDBOT.WD WORM! |
| ? | ZGNUBI | ZGNUBI.exe | ?? |
| X | ZIBMACC | rundll.exe ZIBMACC.INF | ZIBMACC.INF is an IBM file that is only loaded and installed under a recovery operation. The file is a support file for IBM access to the system if needed. You may delete this file. This is as from IBM Technical Support (USA - 800-887-7435) |
| U | ZingSpooler | ZingSpooler.exe | Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums |
| N | Zinio DLM | ZDLM.EXE | Zinio - used to read magazines in digital rather than paper format |
| X | Zip Driver Loader | ZipLoader32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
| X | Zip Driver Loader | msload32.exe | Added by the OBLIVION TROJAN! This executable is one of the most common but there are more |
| U | ZipDisk Icons | IMGICON.EXE | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
| N | ZipGenius Clean | zg.exe | ZipGenius file compression utility |
| X | ziphelp | ziphelp.exe | CoolWebSearch parasite related |
| N | ZipMagic | zm32.exe | Zip utility by Ontrack. Preloading ZipMagic allows you to access files within a zip archive without unzipping them first |
| Y | zlclient | zlclient.exe | Firewall program from Zonelabs. Pro version inlcudes other online security options |
| U | ZLH | ZLH.EXE | System Tray icon for Norman Antivirus |
| X | Zonavirus | 0 | Added by the KITRO.D (or ARGEN.A) WORM! |
| X | Zone Alarm | vsmon.exe | Added by the RBOT.BO WORM! If this was the ZoneAlarm firewall the name column would be TrueVector |
| Y | Zone Labs Client | zlclient.exe | Firewall program from Zonelabs. Pro version inlcudes other online security options |
| X | Zone Labs Client Ex | svchost.exe | Added by the NETSKY.F WORM! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| X | Zone system | szchost.exe | Added by the MULTIDR-AC TROJAN! |
| Y | ZoneAlarm | zonealarm.exe | Firewall program from Zonelabs - free version |
| X | zonealarm | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! The only exception is if you have an older version of the ZoneAlarm firewall running |
| X | Zonealarm | Removeme.exe | Added by the FORBOT-BG WORM! |
| Y | ZoneAlarm Plus | zaplus.exe | Firewall program from Zonelabs - paid for version |
| Y | ZoneAlarm Pro | Zapro.exe | Firewall program from Zonelabs - paid for version |
| U | Zoom | zoom.exe | Zoom - speeds up Windows startup and manages startup applications |
| ? | ZoomingHook | ZoomingHook.exe | Related to the Toshiba Zooming Utility for Tablet PC. What does it do and is it required? |
| Y | ZPOINT32 | ZPOINT32.exe | USB graphics/writing tablet driver |
| X | zSearch | Zstb.exe | TotalVelocity zSearch parasite |
| U | zSPGuard | Spguard.exe | "StartPage Guard (SPG) protects your PC from cyberscam, by detecting and preventing any unauthorized changes to your internet browser's Start and Search pages. It is also capable of removing automatically most of known 'invaders'." |
| X | ZtgServerSwitch | server.vbs | ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware |
| X | Zupdate | Zupdate.exe | B3d Projector foistware - periodically trys to access the internet. (1) Uninstall it via Start -> Settings -> Control Panel -> Add/Remove Programs. (2) Remove the BDEsecureinstall.exe if still present in C:\Windows\System. (3) Disable and ideally delete it from the registry. (4) Remove the "BDE" directory and all its contents |
| X | zzb | zzb.exe | IAGold adware downloader |
| X | zzb | zzb.exe | IAGold adware downloader |
| X | zzgshp | gshp.vbs | Homepage hi-jacker that re-defines your IE or Netscape start page |
| X | zztp | svchost.exe | Added by the TANNICK.B TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! |
| ? | zzz-hpi-boot | hpi-boot.exe | Associated with HP Photosmart printers |
| ? | zzzCamlnSuitelll | setup.exe 46*** | ?? |
| ? | zzzhpsetup | setup.exe | ?? |
| X | [default] | DrWatson32.exe | Added by the DREMN TROJAN! |
| X | [Ephemeral 2.x] by TreeHugger, | [path to worm] | Added by the LEMOOR.A WORM! where "x" represents 3 or 4 |
| X | [executed file name] | App.exe | Added by the WAXPOW WORM! |
| X | [executed file name] | Regsrv32.com | Added by the SOUTHGHOST WORM! |
| X | [random 12 digit number] | avifile5.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | bootvid4.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | browser8.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | atitvo32.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | autodisc.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | cabview1.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | advpack1.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | batmeter.exe | Adsrv.com/IeDriver adware variant |
| X | [random 12 digit number] | bidispl2.exe | Adsrv.com/IeDriver adware variant |
| X | [random name] | Svchosts.exe | Added by the SDBOT.N TROJAN! |
| X | [random name] | wincpu.exe | Added by an unidentified VIRUS, WORM or TROJAN! |
| N | [System Mechanic Professional Update [Incinerator.dll] | REREG: [path] Incinerator.dll | System_Mechanic's "Incinerator" feature securely deletes files and folders from your PC so they can never be recovered again |
| X | [various names] | elf.exe | Elf is a hacker program, tied to a trojan server |
| X | [various names] | crsrs.exe | Added by the FORBOT-AK WORM! |
| X | [various names] | Windows32.exe | Added by any of a number of WORM or TROJAN variants |
| X | [various names] | bling.exe | Added by the RBOT-NI WORM! |
| X | [various names] | mediaplayer32.exe | Added by a variant of the RBOT WORM! |
| X | [various names] | winlogon32.exe | Added by an unidentified WORM or TROJAN! |
| X | [various names] | svchostss.exe | Added by a variant of the RBOT WORM! |
| X | [various names] | win32snd.exe | Added by the RBOT-DQ WORM! |
| X | [various names] | shch.exe | Premium rate adult content dialler |
| X | [various names] | PasswdMon.exe | TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here |
| X | [various names] | runload32.exe | TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here |
| X | [] | spolsvr2.exe | Added by the EVILSOCK.10 TROJAN! |
| X | [] | iexpl0res.exe | Added by an unidentified WORM or TROJAN! |
| X | [] | winbas12.exe | Adware, probably CoolWebSearch parasite related - recognized by Kaspersky antivirus as TrojanDownloader.Win32.VB.du |
| X | \IEService.exe | IEService.exe | FastFind parasite variant |
| X | \Pribi.exe | Pribi.exe | FastFind parasite variant |
| X | ^`d}qZxu | ~`d}qzxu3zYF | Added by the GAOBOT.GEN!POLY WORM! |
| U | _AntiSpyware | MssCli.exe | McAfee AntiSpyware |
| X | _Hazafibb | [path to file] | Added by the ZAFI.B WORM! |
| X | _svchost.con | svchost.com | Added by the ERKEZ.C WORM! |
| U | _winadm | winadm.exe | Parents Friend - "Log any activity and protect programs with a password. Further more you can lock the pc any hour in the week you want with the main password. You can also give users allowed programs in their program-lists and you can limit the maximal daily hours and maximal weekly hours user spend on the PC" |
| X | _winsystem.sys | smss.exe | Added by the SOBER.K WORM! Note - this is not the legitimate Smss.exe system file should normally NOT figure in Msconfig/Startup! |
| X | _x-Finder | _x-Finder.exe | Disconnects and redials an ISP modem to an adult content site |
| U | {0228e555-4f9c-4e35-a3ec-b109a192b4c2} | gnotify.exe | Google Gmail_notifier. Alerts you when you have new Gmail messages |
| X | {12EE7A5E-0674-42f9-A76B-000000004D00} | rundll32.exe [path] stlb2.dll, DllRunMain | BrowserAid/Startium parasite |
| X | {2CF0B992-5EEB-4143-99C0-5297EF71F444} | rundll32.exe stlbdist.dll, DllRunMain | BrowserAid/Startium parasite |
| X | {2CF0B992-5EEB-4143-99C2-5297EF71F44B} | rundll32.exe stlbupdt.DLL, DllRunMain | BrowserAid/Startium parasite |
| X | {357AA41A-B7A8-4632-A27D-5B980B25CF43} | [path to svchost.exe] | Added by the SMALL-AQ TROJAN! |
| X | ®Windows Update | svchosts.exe | Added by the FRUCTA TROJAN! |