Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 10/8/7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 30th November, 2017
52420 listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

1860 results found for P

Startup Item or Name Status Command or Data Description Tested
POLIXp.exeDetected by Dr.Web as Trojan.DownLoader9.14264 and by Malwarebytes as Trojan.Agent.ENo
pXp.exeDetected by Sophos as Troj/Agent-UNo
UpdateXP.O.exeDetected by Malwarebytes as Spyware.Agent.E. The file is located in %UserStartup%\chaaaNo
RunmeAtStartupXp07.exeDetected by Dr.Web as Trojan.DownLoader7.21479 and by Malwarebytes as Trojan.DownloaderNo
courtsXp1.exeDetected by Malwarebytes as Trojan.Agent.CRE. The file is located in %AppData% - see hereNo
p2Xp2.exeDetected by Dr.Web as Trojan.DownLoader8.24379. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\p2No
RunmeAtStartupXp24.exeDetected by Malwarebytes as Trojan.Downloader.Bullit. The file is located in %Temp%No
P2kAutostartNP2kAutostart.exeSystem Tray access to, and connection detector for the P2kCommander filemanager application for Motorola phonesNo
P2P Networking#XP2P Networking#.exeAdded by a variant of Adware.P2PNetworking - where # represents a digit. The file is located in %System%\P2P NetworkingNo
P2P NetworkingXP2P Networking.exeDetected by Symantec as Adware.P2PNetworkingNo
Microsoft® Windows® Operating SystemNp2phost.exeSigns a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that "identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer." Available via Start → Control PanelYes
CollaborationHostNp2phost.exeSigns a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that "identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer." Available via Start → Control PanelYes
Microsoft People Near MeNp2phost.exeSigns a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that "identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer." Available via Start → Control PanelYes
p2pnetworkXp2pnetwork.exeDetected by Trend Micro as WORM_ALCAN.ANo
p2p networkingXp2pnetworking.exeDetected by Sophos as W32/Rbot-ECP and by Malwarebytes as Backdoor.BotNo
p2pnetworkingXp2pnetworking.exeDetected by Sophos as W32/Rbot-AFLNo
XpXp2pnetworking.exeDetected by Trend Micro as WORM_SDBOT.XANo
MSPluginSrvcXp3.exeDetected by Sophos as W32/Rbot-WV and by Malwarebytes as Backdoor.BotNo
P3p4chkXP3p4chk.exeDetected by Symantec as Trojan.GemaNo
P4mx4Xp4mx4.exeDetected by Trend Micro as TROJ_CRYPTER.ANo
MSNPluginSrvcsXp6.exeDetected by Sophos as W32/Rbot-VJNo
Pointsec TrayYp95tray.exeSystem Tray access to Pointsec (now Check Point) Full Disk Encryption - which provides "automatic encryption of laptop and desktop hard drives protects critical information and prevents corporate data breaches"No
FilmFanatic Browser Plugin LoaderUpabrmon.exeFilmFanatic toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FilmFanatic\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itNo
FilmFanatic Browser Plugin Loader 64Upabrmon64.exeFilmFanatic toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FilmFanatic\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itNo
Winsock2 driverXPAC.EXEDetected by Sophos as W32/Spybot-ET and by Malwarebytes as Backdoor.BotNo
PacheXPache.exeDetected by Malwarebytes as Trojan.Autoit. The file is located in %CommonAppData%\Adobe\GamersNo
pachuborhepaXpachuborhepa.exeDetected by McAfee as RDN/Generic Dropper!vc and by Malwarebytes as Trojan.Agent.USNo
PaciSoftXpacis.exePacerD Media/Pacimedia.com adware installerNo
package.exeXpackage.exeDetected by Sophos as W32/Dabber-A and by Malwarebytes as Worm.Dabber. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
PadCryptXpackage.exeDetected by Symantec as Ransom.PadCrypt and by Malwarebytes as Ransom.PadCryptNo
sasserfixXpackage.exeDetected by Sophos as W32/Dabber-A and by Malwarebytes as Worm.DabberNo
winbar.pifXpacke.pifDetected by Sophos as W32/Rbot-AVINo
sassfixXpacker.exeDetected by Bitdefender as Win32.Worm.Dabber.ANo
PackersScreenServerUPackersScreenServer.exeScreensaver for the Green Bay Packers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
PackersScreenServerSvcUPackersScreenServer.exeScreensaver for the Green Bay Packers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
rauUPackerV2.exeDetected by Malwarebytes as PUP.Optional.Linkury. The file is located in %Temp%\Rau. If bundled with another installer or not installed by choice then remove itNo
Network Packet MonitorXpacket.exeDetected by McAfee as Generic.dx!tnc and by Malwarebytes as Trojan.AgentNo
AdobeMsnXPackwin.exeDetected by McAfee as RDN/PWS-Banker!db and by Malwarebytes as Trojan.Banker.ADBNo
SlipStreamYpacore.exePhreego Express Web Accelerator customized core module for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pixNo
SteamXPACsteam.exeDetected by Sophos as Mal/Agent-SFNo
padailyXpadaily.exeDetected by Malwarebytes as Adware.KorAd. The file is located in %ProgramFiles%\padaily - see hereNo
PadTouchNPadExe.exe"The Toshiba Touch and Launch Utility extends the built-in touchpad functionality to provide application launching features"No
Google ChromeXpadlock.exeDetected by Malwarebytes as Trojan.LockScreen - see hereNo
Pag Windows MonitorXpag.exeDetected by Sophos as Troj/Agent-EOTNo
PaganiseXPaganise.exeDetected by Dr.Web as Trojan.DownLoader9.50609 and by Malwarebytes as Malware.Trace.E. Note - this entry loads from the Windows Startup folderNo
pagefile.sysXpagefile.sysDetected by Dr.Web as Trojan.DownLoader11.36748 and by Malwarebytes as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PAgentXPAgent.exeScans your hard drive for the popular P2P file-sharing applications BearShare, Grokster, Kazaa, Limewire and Morpheus. After searching the entire local file system for any files with those names it connects to the DownloadWare servers and tells it what, if anything, is foundNo
PagooNPagoo.exeOlder version of Pagoo by RingCentral - which "is a VoIP, cloud-based virtual PBX system that enables you to stay connected anytime, anywhere." This version intercepted telephone calls like an answering machine and played the voice message on your PC and was only required when you were on-line via a dial-up modemNo
Phreego Express Web AcceleratorYpagui.exePhreego Express Web Accelerator customized user interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pixNo
Paid InvoiceXPaid.exeDetected by Malwarebytes as Backdoor.Agent.E. The file is located in %UserTemp%No
Paid SlipXPaid.exeDetected by Malwarebytes as Backdoor.Agent.E. The file is located in %AppData%No
WindowsXpaint.exeDetected by McAfee as Generic BackDoor!ff3 and by Malwarebytes as Trojan.Agent.WNLNo
HKCUXPaint.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%\microsoftNo
PoliciesXPaint.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\microsoftNo
PaintXPaint.exeDetected by Trend Micro as WORM_VRENAME.A and by Malwarebytes as Worm.AutoRun. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%No
SkypeXpaint.exeDetected by McAfee as Generic BackDoor!ff3 and by Malwarebytes as Trojan.Agent.WNLNo
Paint.exeXPaint.exeDetected by Malwarebytes as Worm.AutoRun. The file is located in %AppData%No
Paint.exeXPaint.exeDetected by Symantec as W32.Tapin. The file is located in %UserProfile%No
UpdateXpaint.exeDetected by McAfee as Generic BackDoor!ff3 and by Malwarebytes as Trojan.Agent.WNLNo
HKLMXPaint.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%\microsoftNo
loadXpaint.exeDetected by McAfee as Generic BackDoor!ff3 and by Malwarebytes as Trojan.Agent.WNL. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "paint.exe" (which is located in %AppData%\windowsys) and also adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" entry pointing to the same fileNo
taskmgr.exeXpaint.exeAdded by a variant of the AGENT.AH TROJAN!No
PaintingRoom evidence monitorXpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...No
PaintingRoom smile monitorXpaintingroom.exePaintingroom.com smiley software - not recommended as the site tries to drop a trojan on you...No
taskmgr.exeXpaintms.exeAdded by a variant of the AGENT.AH TROJAN!No
linefolderXpaintname.scrDetected by Malwarebytes as Backdoor.DarkComet. The file is located in %AppData%\linefolderNo
ShellXpalladium.exeDetected by Kaspersky as Trojan.Win32.FakeAV.afyz and by Malwarebytes as Rogue.Palladium. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "palladium.exe" which is located in %AppData%No
Palm DesktopNPalm.exe"Palm Desktop desktop companion software for all Palm devices. It allows users to view, sort, find, edit, back up, and add anything to Palm OS handhelds"No
Personal Anti MalwareXPAM.exeUnregistered version of Personal Anti Malware rogue security software - not recommended, removal instructions hereNo
FilmFanatic EPM SupportUpamedint.exeFilmFanatic toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FilmFanatic\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itYes
pamela.exeUpamela.exePamela is a plug-in or add-on that adds features to Skype peer to peer voice serviceNo
Panda Software IntrenetXpanda.pifDetected by Sophos as W32/Rbot-ATZNo
PandaAVEngineXPandaAVEngine.exeDetected by Symantec as W32.Netsky.R@mmNo
System handlerXPandawas.exeDetected by Trend Micro as WORM_BHARAT.ANo
Panda Security URL FilteringYPanda_URL_Filtering.exeURL checking feature of Panda Cloud Antivirus by Panda SecurityNo
PandoNPando.exePando by Pando Networks - "is free, secure software that makes sending, receiving, and publishing files up to 1GB in size a breeze." No longer availableNo
KN_PanelAppUPanelApp.exeKnowledgePanel online survey softwareNo
[various names]Xpanel_its.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
PanteraXpantera.exeDetected by Trend Micro as WORM_SDBOT.AYNNo
Configuration LoaderXpany.exeDetected by Trend Micro as WORM_RBOT.L and by Malwarebytes as Backdoor.BotNo
PapeleraXpapeleraxp2.exeDetected by Malwarebytes as Trojan.Qhost. The file is located in %Recycled%No
PapeleraXpapeleraxpn.exeDetected by Malwarebytes as Trojan.Qhost. The file is located in %Recycled%No
PapeleraXpapeleraxpt.exeDetected by Malwarebytes as Trojan.Qhost. The file is located in %Recycled%No
PowerDOCSAPIHostUpapihost.exeHummingbird PowerDOCS - "delivers powerful enterprise document management functionality via a tightly integrated Microsoft WinNT/98/2K environment"No
paqezgulhapaXpaqezgulhapa.exeDetected by McAfee as RDN/Generic.tfr!ed and by Malwarebytes as Trojan.Agent.USNo
Paraben's Password ManagerUParaben.exeParaben's Password Manager by Paraben Corporation - personal password management program for online accounts, ATM numbers, PIN numbers, bank accounts, password protected documents, etcNo
ParadoxXParadox.exeDetected by Dr.Web as Trojan.Siggen4.25429 and by Malwarebytes as Trojan.BackdoorNo
MetoSystemXparalise1.exeDetected by McAfee as RDN/Ransom!de and by Malwarebytes as Trojan.Agent.RNSNo
Parallels Tools?ParallelsToolsCenter.exePart of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels WorkstationNo
ParentalControlUParentalControl.ExeCrawler Parental Control - "Get perfect control of websites your children browse, software they use, and folders they access. Regulate the time when they can use your computer and connect to the Internet. Hide content on your computer that you don't want them to see"No
ParetoLogic Anti-SpywareYPareto_AS.exe"ParetoLogic Anti-Spyware delivers Active Protection in the form of real-time blocking"No
[various names]XParisM.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
macroXparivac.exeDetected by Dr.Web as Trojan.DownLoader8.19816 and by Malwarebytes as Trojan.Agent.PVNo
parsazqacvolXparsazqacvol.exeDetected by McAfee as RDN/Generic Downloader.x!kp and by Malwarebytes as Trojan.Agent.USNo
VAIO RecoveryUPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhereNo
PartSealUPartSeal.exeSystem backup for Sony Vaio PCs. Adds a recovery mechanism for users over and above any System Restore features - allowing users to revert a drive back to the state it was when bought form the factory by hitting F10. The user obviously loses any data stored if not backed-up elsewhereNo
Winsock32 driverXparty.exeDetected by McAfee as MultiDropper-DCNo
party.taskXparty.exeDetected by McAfee as MultiDropper-DCNo
P Antispyware 09Xpas.exeP Antispyware 09 rogue security software - not recommended, removal instructions hereNo
PersonalAntiSpy FreeXpas.exePersonalAntiSpy rogue spyware remover - not recommended, removal instructions hereNo
Pas Windows MonitorXpas.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %System%No
Palo Alto Software Update Manager 8.0NPAS8_UD.exeUpdate manager for small business planning software from Palo Alto Software - such as Business Plan Pro, Marketing Plan Pro and Email Center ProNo
cmonitorXpasmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
SalestartXPASmon.exePart of rogue security tools, including ErrorSafe and PcTurboProNo
pas_checkXpasmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
was_checkXPASmon.exePart of the ErrorSafe rogue system error and cleaning utility - not recommendedNo
FilmFanatic Search Scope MonitorUpasrchmn.exeFilmFanatic toolbar - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FilmFanatic\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itNo
Windows System ConfigurationXPASSCFG16.EXEDetected by Sophos as Troj/Domwis-ENo
Windows DLL LoaderXPASSCFG16.EXEDetected by Sophos as Troj/Domwis-ENo
NETVISIONPasse-partoutXPasse-partout.exeDetected by Sophos as Dial/DialCar-MNo
PassLockerYPassLocker.exe"PassLocker is a complete password manager helping you to manage and safely store your passwords"No
Panda Antispam Server ServiceUPasSrv.exeAntiSpam of an older version of the Panda Security range of internet security products. Runs as a service on Windows XPNo
[various names]XPasswdMon.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Password DepotYPasswordDepot.exePassword Depot by AceBIT Gmbh - is a "powerful and very user-friendly password manager which helps to organize all of your passwords - but also, for instance, information from your credit cards or software licenses"No
pwdirUPasswordDirector.exePassword Director by LastBist Software - "provides a safe and secure way to keep all your passwords and sensitive records (such as system logins, credit card information, PINs, private phone numbers and other sensitive records) in the single well-protected password database"No
Steganos Password Manager 14UPasswordManager.exeLoads version 14 of the Steganos Password Manager in windowed mode at startup (which is configured via Settings? → General Settings → "Start automatically on log on")Yes
Steganos Privacy Suite 14UPasswordManager.exeLoads version 14 of the Steganos Password Manager in windowed mode at startup (which is configured via Settings? → General Settings → "Start automatically on log on"). This entry is for the version included with Steganos Privacy SuiteYes
SSS14_PasswordManagerUPasswordManager.exeLoads version 14 of the Steganos Password Manager in windowed mode at startup (which is configured via Settings? → General Settings → "Start automatically on log on"). This entry is for the version included with Steganos Privacy SuiteYes
PasswordManagerUPasswordManager.exeLoads version 14 of the Steganos Password Manager in windowed mode at startup (which is configured via Settings? → General Settings → "Start automatically on log on")Yes
SPM14_PasswordManagerUPasswordManager.exeLoads version 14 of the Steganos Password Manager in windowed mode at startup (which is configured via Settings? → General Settings → "Start automatically on log on")Yes
PasswordManagerUpassword_manager.exeLenovo ThinkVantage Password Manager "allows users to save passwords for Web sites and Windows applications, and subsequently auto-fills those passwords when the user visits those Web sites or logs on to the application"No
PastaLeadsApplicationUPastaLeadsApplication.exeDetected by Malwarebytes as PUP.Optional.PastaLeads. The file is located in %ProgramFiles%\pastaleads. If bundled with another installer or not installed by choice then remove itNo
PastaQuotesUPastaLeadsWinApp.exeDetected by Malwarebytes as PUP.Optional.PastaQuotes. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\pastaleads - see here. If bundled with another installer or not installed by choice then remove itNo
PowerArchiver TrayNPASTARTER.EXESystem Tray access to PowerArchiver from ConeXware, Inc - file compression support toolNo
paswonmyrytrXpaswonmyrytr.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
PaSystemXpasystem.exeTargetsaver adware variantNo
PASystemTrayYPASystemTray.exePart of the Panda Security range of enterprise/business internet security productsNo
MicroUpdateXPatch 2.11.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
GoogleAppsXPatch.exeDetected by Malwarebytes as Trojan.Agent.Gen. The file is located in %AppData%\MicrosoftNo
Telechips,MassUpatch.exeRemovable disk driver for the Muro MP3 playerNo
Win PatchXpatch.exeDetected by Sophos as W32/Sdbot-GLNo
DC-STARTXpatch1.exeDetected by Malwarebytes as Backdoor.Agent.DCGen. The file is located in %AppData% - see hereNo
AV ClientXpatch31345.exeDetected by Symantec as W32.Mydoom.AD@mmNo
AV IndustryXpatch31345.exeDetected by Symantec as W32.Mydoom.AD@mmNo
gameXpatcher.scrDetected by Sophos as Troj/PSW-EDNo
PathNvidiaTV?patchnvidiaTVout.exeRelated to a Gigabyte NVIDIA based video card - typical file location is %ProgramFiles%\Gigabyte\NvidiaNo
patchsetup70700.exeXpatchsetup70700.exeDetected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%\[32 hex characters]No
PatchUp_PlusXPatchUpInit.exePatchUp_Plus rogue security software - not recommended, removal instructions hereNo
patgeasukumpXpatgeasukump.exeDetected by Dr.Web as Trojan.DownLoader11.6956 and by Malwarebytes as Trojan.Agent.USNo
[blank]Xpathex.exeDetected by Sophos as Troj/Mkmoose-A. Note - has a blank entry under the Startup Item/Name fieldNo
pathnameXpathname.exeDetected by Symantec as Backdoor.IrcContactNo
SDHT14Xpatrent3.exeDetected by McAfee as RDN/PWS-Banker!db and by Malwarebytes as Backdoor.Agent.DRNo
ManagerXpatrick_schwazy.exeDetected by McAfee as RDN/Generic Downloader.x!jb and by Malwarebytes as Trojan.KBayi.FLANo
HKC UPDATE MANAGERXpatrick_schwazy.exeDetected by McAfee as RDN/Generic Downloader.x!iz and by Malwarebytes as Trojan.Downloader.ENo
Podcast Update ManagerXpatrick_schwazy.exeDetected by McAfee as RDN/Ransom!dw and by Malwarebytes as Trojan.KBayi.FLANo
PersonalAVXpav.exePersonal Antivirus rogue security software - not recommended. Detected by Trend Micro as TROJ_FAKEAV.FT and by Malwarebytes as Rogue.PersonalAntiVirus. The file is located in %ProgramFiles%\PersonalAVNo
Paladin AntivirusXpav.exePaladin Antivirus rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PaladinAntivirusNo
PAVXpav.exePersonal Antivirus rogue security software - not recommended. Detected by Malwarebytes as Rogue.PersonalAntiVirus. The file is located in %ProgramFiles%\PAVNo
PAV.EXEYPAV.EXEPER Antivirus - no longer available. The file is located in %ProgramFiles%\Persystems\PeravNo
Panda CleanerYpavdr.exePart of an older version of the Panda Security range of internet security products. Possibly the ActiveScan on-line scanner?No
PAVFIRESYPavFires.exeFirewall included with older versions of the Panda Security range of internet security products. Runs as a service on Windows XPNo
PAVFNSVRYPavFnSvr.exePart of an older version of the Panda Security range of internet security products. Runs as a service on Windows XPNo
Pavkre9xYpavkre9x.exePart of an older version of the Panda Security range of internet security productsNo
PER Email ProtectionYpavmail.exeE-mail scanner part of PER Antivirus - no longer availableNo
PavProtYPavProt.exePart of an older version of the Panda Security range of internet security productsNo
Pavprot9YPavprot9.exePart of an older version of the Panda Security range of internet security productsNo
PavProcYPavPrS9x.exePart of the Panda Security range of internet security productsNo
Panda SchedulerUpavsched.exeScheduler for older versions of the Panda Security range of internet security products. Required if you have scans scheduled on a regular basisNo
PandaSchedulerUpavsched.exeScheduler for older versions of the Panda Security range of internet security products. Required if you have scans scheduled on a regular basisNo
Microsoft Update MachineXpaxrxo.exeDetected by Intel Security/McAfee as W32/Pushbot.a and by Malwarebytes as Backdoor.Bot. The file is located in %System%No
System InitializationXpayload.datDetected by Symantec as Backdoor.RoxyNo
Microsoft WordXPayment Slip.exeDetected by Malwarebytes as Backdoor.Agent.V. The file is located in %AppData%No
updateXpayment-main.exeDetected by Sophos as Troj/Mdrop-FBP and by Malwarebytes as Trojan.Agent.PMNo
PayTimeXpaytime.exeDetected by Sophos as Troj/StartPa-YRNo
PoliciesXPb Hack.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\installNo
UEBCQ7L6PUXpb70njK.exe.lnkDetected by McAfee as RDN/Generic BackDoor!tm and by Malwarebytes as Backdoor.Agent.DCENo
ShellXpb7ZmiJ.exe,explorer.exeDetected by McAfee as RDN/Generic Dropper!tn and by Malwarebytes as Backdoor.Messa.E. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "explorer.exe" (which is a legitimate file located in %Windir% and shouldn't be deleted) and "pb7ZmiJ.exe" (which is located in %AppData%\9DKFTWfE)No
pbagentUpbagent.exeProbot keystroke logger/monitoring program - remove unless you installed it yourself!No
pguFnnXPBcyLZ.exeDetected by McAfee as RDN/Generic.dx!crz and by Malwarebytes as Backdoor.Messa.ENo
FirewallXPBHax.exeDetected by Malwarebytes as Trojan.Injector.MSIL. The file is located in %CommonAppData%\Microsoft\Windows\Start Menu\PointBlank (10/8/7/Vista) or %AllUsersProfile%\Start Menu\PointBlank (XP)No
{1290A33C-85F5-4164-A1BE-7DD299D4986A}UPBKScheduler.exePart of the PowerBackup archiving/backup utility from CyberLink. The entry is present if you have any backup jobs scheduledYes
PowerBackupUPBKScheduler.exePart of the PowerBackup archiving/backup utility from CyberLink. The entry is present if you have any backup jobs scheduledYes
PBKSchedulerUPBKScheduler.exePart of the PowerBackup archiving/backup utility from CyberLink. The entry is present if you have any backup jobs scheduledYes
PASMonitorXpbm.exePersonalAntiSpy rogue spyware remover - not recommended, removal instructions hereNo
PbAdminACADUPbMngr5.exeBluebeam PDF software printer support. Prints AutoCAD ".dwg" to PDFNo
run_pbnextYPBNext.exePBNext is virtual phone system which offers the same functionality as expensive PBX hardwareNo
PC Health PlanXPC Health Plan.exePC Health Plan rogue security software - not recommended, removal instructions hereNo
PC JUNKCLEANERXPC JUNKCLEANER.exeDetected by Malwarebytes as Rogue.TechSupportScam. The file is located in %ProgramFiles%\A POKEMONGO Company\PC Cleaner Pro. Removal instructions hereNo
PC MagnumUPC Magnum.exePC Magnum privacy/cleaner utility from PC Pitstop LLC. Detected by Malwarebytes as PUP.Optional.PCMagnum. The file is located in %ProgramFiles%\PCPitstop\PC Magnum. If bundled with another installer or not installed by choice then remove itNo
(Default)Xpc update.exeDetected by Malwarebytes as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %UserStartup%No
pc update.exeXpc update.exeDetected by Malwarebytes as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PC-AntispyXPC-Antispy.exePC-Antispy rogue spyware remover - not recommended, removal instructions hereNo
PC-AntispywareXPC-Antispyware.exePC-AntiSpyware rogue spyware remover - not recommendedNo
PC-CleanerXPC-Cleaner.exePC-Cleaner rogue security software - not recommendedNo
Pc.exeXPc.exeDetected by Dr.Web as Trojan.DownLoader9.21591 and by Malwarebytes as Backdoor.Bot. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
Service DriversXPC.EXEDetected by Sophos as W32/Sdbot-WKNo
PCXPC.exeDetected by Sophos as Troj/MSIL-BSWNo
PC2011XPC2011.exePC Security 2011 rogue security software - not recommended, removal instructions hereNo
PC2SafeXPC2SafeLaunch.exePC-Safe rogue security software - not recommended, removal instructions hereNo
MSNSysRestoreXpc32.exeAdded by a variant of the MASTAK VIRUS!No
SmartalecUpcaccel.exeSmartalec PC Accelerator - system optimization utilityNo
SmartPCXLUpcaccel.exeSmartalec PC Accelerator - system optimization utilityNo
PCAccelerateProUPCAcceleratePro.exe"PC Accelerate Pro is a powerful application that makes cleaning up your computer a simple process." Detected by Malwarebytes as PUP.Optional.PCAcceleratePro. The file is located in %ProgramFiles%\PCAcceleratePro. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PCAntiMalwareXpcam.exePCAntiMalware rogue security software - not recommended, removal instructions hereNo
pcAnywhere AgentUpcamgt.exePart of pcAnywhere by Symantec - "is the world's leading remote access software solution. It lets you manage computers efficiently, resolve helpdesk issues quickly, and connect to remote devices simply and securely." This process listens for incoming PC Anywhere connections if your PC is configured as a PC Anywhere host. Now discontinuedNo
PCBGYPCBODYGUARD.EXEPC Bodyguard from Calluna Technology - protects system files and settings from being deleted, modified, etc. No longer availableNo
PCBODYGUARDYPCBODYGUARD.EXEPC Bodyguard from Calluna Technology - protects system files and settings from being deleted, modified, etc. No longer availableNo
PcBoostUPcBoost.exePCBoost from PGWARE, LLC increases computer performance by allocating higher portions of CPU power to active applications and gamesNo
PC BoosterUpcbooster.exePC Booster from inKline Global - "easy-to-use computer system optimizer that gives your system the extra speed and stability you want while ensuring that your computer is kept clean and in tip-top condition"No
UpdateFlow.ComcastNpcBrowser.exePart of the Comcast broadband support package by Motive, which helps users troubleshoot and configure the service. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
ATT-SSTNpcBrowser.exePart of the AT&T Self Support Tool broadband support package by Motive, which helps users troubleshoot and configure the service. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
PcCareMainXPcCare.exeDetected by Malwarebytes as Rogue.PcCare. The file is located in %ProgramFiles%\PcCareNo
pc-care3Xpccare3up.exePcCare rogue security software - not recommended, removal instructions hereNo
PCCarePro Anti-MalwareUPCCarePro.AntiMalware.exePC Care Pro Anti-Malware. Detected by Malwarebytes as PUP.Optional.PCCarePro. The file is located in %ProgramFiles%\PC Care Software\PC Care Anti-Malware. If bundled with another installer or not installed by choice then remove itNo
PCCClient.exeYPCCClient.exePart of Trend Micro web-security products - PC-cillin 2002-2003 and Virus Buster 2001-2003No
pccenterstart.exeXpccenterstart.exeDetected by Malwarebytes as Rogue.PCCenter. The file is located in %ProgramFiles%\pccenterNo
pccenter mainXpccenteru.exeDetected by Malwarebytes as Rogue.PCCenter. The file is located in %ProgramFiles%\pccenterNo
pccguide.exeYpccguide.exePart of Trend Micro web-security products - including Internet Security 2005-2007, PC-cillin 2002-2004, Virus Buster 2001-2007 and AntivirusNo
PC-CheckupNPCCheckUp.exeIncluded with an older version of SpeedItup. PC optimizer that requires you to purchase the software in order to fix what it findsNo
PCCIOMON.exeYPCCIOMON.exePart of Trend Micro web-security products - PC-cillin 2000, 2002-2003 and Virus Buster 2001-2004. This is the virus scannerNo
PC CleanerUPCCLauncher.exePC Cleaner optimization utility by PC HelpSoft. Detected by Malwarebytes as PUP.Optional.PCCleaner. The file is located in %ProgramFiles%\PC Cleaner. If bundled with another installer or not installed by choice then remove itNo
TweakBit\PCCleaner\Start PCCleaner ?n logonUPCCleaner.exeTweakbit PCCleaner - which will "clean out invalid keys, repair broken shortcuts and defragment the registry to make it more compact and organized." Detected by Malwarebytes as PUP.Optional.TweakBit. The file is located in %ProgramFiles%\TweakBit\PCCleaner. If bundled with another installer or not installed by choice then remove itNo
PCCPReminderUPCCleanPlus.exePC Clean Plus by Jawego Partners LLC - "is the best registry cleaner and optimizer to improve your PC's performance by removing all registry errors." Detected by Malwarebytes as PUP.Optional.PCCleanPlus. The file is located in %ProgramFiles%\PC Clean Plus. If bundled with another installer or not installed by choice then remove itNo
PCClearPlusXPCClearPlus.exeDetected by Malwarebytes as Rogue.PCClearPlus. The file is located in %ProgramFiles%\PCClearPlus - removal instructions hereNo
PCClear_PlusXPCclear_Plus.exePCclear Plus rogue security software - not recommended, see here and hereNo
PCClient.exeYPCClient.exePart of Trend Micro web-security products - PC-cillin 2004, Virus Buster 2004 and AntivirusNo
OfficeScanNT MonitorYpccntmon.exePart of an older version of the Trend Micro OfficeScan business anti-malware suiteNo
Sony Ericsson PC CompanionNPCCompanion.exeSony PC Companion mobile device management utilityNo
Sony PC CompanionNPCCompanion.exeSony PC Companion mobile device management utility - replace PC SuiteNo
PccPfwYPccPfw.exePart of Trend Micro web-security products - PC-cillin 2002-2003 and Virus Buster 2002-2004. This is the firewallNo
PcCtlComYPCCTLCOM.EXEPart of Trend Micro web-security products - Internet Security 2005-2006 and Virus Buster 2005-2006No
PC Clean Maestro StartupNpccum.exePC Clean Maestro by CompuClever - "removes unwanted files and it eliminates confidential information so your PC is clean and safe". Detected by Malwarebytes as PUP.Optional.CompuClever. The file is located in %ProgramFiles%\CompuClever\PC Clean Maestro. If bundled with another installer or not installed by choice then remove itNo
OfficeScan95Ypccwin97.exePart of an older version of the Trend Micro OfficeScan business anti-malware suiteNo
PC DefenderXpcdef.exePC Defender rogue security software - not recommendedNo
sysavXpcdefender.exeWinPC Defender rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.WinPCDefender. The file is located in %AppData%No
PC Doc Pro - 3.1Upcdocpro.exePC Doc Pro (now Win Doc Pro) - system health check and fix utilityNo
NERCLKXpcEamB.exeDetected by McAfee as Generic BackDoor and by Malwarebytes as Backdoor.Agent.ENo
Ms System ConfigXpcedit.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
PCEssenceMainXPCEssence.exePC-Essence rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PCEssence. The file is located in %ProgramFiles%\PCEssenceNo
PcEyeUpceye.exePCEye 2000 - parental control utilityNo
ReceiverUPcfaxRcv.exeIncorporated on multifunction digital copiers (such as the MX-6240N), "Sharp's innovative PC fax driver enables users to send fax documents right from their desktop"No
PCFixUPCFix.exePCFix optimizer/cleaner by CK Technologies. Detected by Malwarebytes as PUP.Optional.PCFixCleaner. The file is located in %ProgramFiles%\PCFix. If bundled with another installer or not installed by choice then remove itNo
PCFix BoosterUPCFixBooster.exePC Fix Booster is "an Awarder Registry cleaner which help to clear your PC from old software fragments which are still living on your computer's registry. This cause errors and conflicts on your PC." Detected by Malwarebytes as PUP.Optional.PCFixBooster. The file is located in %ProgramFiles%\PCFixBooster. If bundled with another installer or not installed by choice then remove itNo
PCFixSpeedUPCFixTray.exePC Fix Speed system optimization tool from Crawler, LLC - "is an essential application that should be a part of every computer. PC Fix Speed especially helps computers that are unusually slow, freeze up often or show error messages, by cleaning the system registry and improving overall performance." Detected by Malwarebytes as PUP.Optional.PCFixSpeed. The file is located in %ProgramFiles%\PCFixSpeed. If bundled with another installer or not installed by choice then remove itNo
PCFixUPCFixV7.exePCFix optimizer/cleaner by CK Technologies. Detected by Malwarebytes as PUP.Optional.PCFixCleaner. The file is located in %ProgramFiles%\PCFix. If bundled with another installer or not installed by choice then remove itNo
PCFixUPCFixV8.exePCFix optimizer/cleaner by CK Technologies. Detected by Malwarebytes as PUP.Optional.PCFixCleaner. The file is located in %ProgramFiles%\PCFix. If bundled with another installer or not installed by choice then remove itNo
PCFixUPCFixV9.exePCFix optimizer/cleaner by CK Technologies. Detected by Malwarebytes as PUP.Optional.PCFixCleaner. The file is located in %ProgramFiles%\PCFix. If bundled with another installer or not installed by choice then remove itNo
PCFixBoosterUPCFixV9.exePC Fix Booster is "an Awarder Registry cleaner which help to clear your PC from old software fragments which are still living on your computer's registry. This cause errors and conflicts on your PC." Detected by Malwarebytes as PUP.Optional.PCFixBooster. The file is located in %ProgramFiles%\PCFixBooster. If bundled with another installer or not installed by choice then remove itNo
System CheckerXPCGuard.exeDetected by Symantec as W32.BakainNo
pcguarderstart.exeXpcguarderstart.exePCGuarder rogue security software - not recommended, removal instructions hereNo
PCHbuttonNPCHbutton.exeUsed by HP Instant SupportNo
Acme.PCHButtonNpchbutton.exeUsed by HP Instant SupportNo
PCHDPlayerXPCHDPlayer.exeDetected by Kaspersky as Porn-Tool.Win32.StripDance.c. The file is located in %ProgramFiles%\pchdNo
[random]XPcHeallth.exeDetected by Malwarebytes as Backdoor.LuminosityLink.E. The file is located in %AllUsersStartup%No
PcHeallth.exeXPcHeallth.exeDetected by Malwarebytes as Backdoor.LuminosityLink.E. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows startsNo
X-PowerPCHealthXPCHealth.comDetected by Dr.Web as Trojan.MulDrop2.51293No
PcHealthXPcHealth.exeDetected by Malwarebytes as Trojan.Crypt.Trace. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\PcHealthNo
pchealthXpchealth.exeDetected by Malwarebytes as Trojan.MSIL.SEO. The file is located in %UserTemp%No
MicrosoftPCHealthXPCHealth.exeDetected by McAfee as RDN/Tufik.worm!d and by Malwarebytes as Backdoor.AgentNo
PC HealthFixUPCHealthFix.exePC Health Fix - "an effortless and automatic way to keep your computer clean, optimized and junk-free, which, in turn, helps you get the best performance possible." Detected by Malwarebytes as PUP.Optional.HealthFix. The file is located in %CommonAppData%\PC HealthFix. If bundled with another installer or not installed by choice then remove itNo
PC Health KitXPCHKLauncher.exePC Health Kit rogue security software - not recommended, removal instructions hereNo
PC Health KitXPCHKSchedule.exePC Health Kit rogue security software - not recommended, removal instructions hereNo
PCHealthNpchschd.exeThis is a "scheduler" and does not turn off PC Health on WinME. For more information refer hereNo
Windows ExpressXpci32b.exeDetected by Symantec as Trojan Horse. The file is located in %System%No
PCIMODEM?pcimodem.exeAssociated with Lucent based Aztech MDP7800-U PCI modems. Is it required?No
NVIDA Server ProxyXpcjUb.exeDetected by Dr.Web as BackDoor.Comet.1750 and by Malwarebytes as Backdoor.Agent.DCENo
PCKeeper AntivirusUPCKAV.exePCKeeper Antivirus by Essentware S.A. (formerly Kromtech Alliance and ZeoBIT) - "is an easy way to keep yourself safe from online threats. With automated protection and regular updating you won't bother about your online security." Detected by Malwarebytes as PUP.Optional.PCKeeper. The file is located in %ProgramFiles%\Essentware\PCKAV. If bundled with another installer or not installed by choice then remove itNo
PCKeeper2UPCKeeper.exePCKeeper Live by Kromtech Alliance (now Essentware S.A., was ZeoBIT) - "a new way to care for your PC. Its unique technology allows real certified technical specialists to spot problems on your PC and fix them." Detected by Malwarebytes as PUP.Optional.PCKeeper. The file is located in %ProgramFiles%\Kromtech\PCKeeper. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PCKeeperLiveUPCKeeper.exePCKeeper Live by Essentware S.A. (formerly Kromtech Alliance and ZeoBIT) - "a new way to care for your PC. Its unique technology allows real certified technical specialists to spot problems on your PC and fix them." Detected by Malwarebytes as PUP.Optional.PCKeeper. The file is located in %ProgramFiles%\Kromtech\PCKeeper. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
Pinnacle PCTV SchedulerUPCLEScheduler.exeScheduler for Pinnacle PCTV solutions for watching and recording terrestrial and satellite TV on a desktop/laptop from Pinnacle Systems (which became Avid Technology and then Corel). The Pinnacle PCTV product line was sold to Hauppauge DigitalNo
InstantTrayNPCLETray.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manuallyNo
PCLGXPCLiveGuard.exeDetected by Malwarebytes as Rogue.PCLiveGuard. The file is located in %CommonAppData%\[random] - see examples here and hereNo
PClKXPClK.exeDetected by Sophos as Troj/LegMir-BLNo
PCLockXPCLockUpdate.exeDetected by Sophos as Troj/Mdrop-CYTNo
PCStartNPcm25.exePCMonitor by Strategic Business Solutions, Inc. "allows you to control the use of your computer and monitor the activities of other users." It makes screen dumps and key logging and it can hang-up your system because the screen dump page gets VERY big. No longer availableNo
PCMAgentNPCMAgent.exePreloads parts of CyberLink PowerCinema digital home entertainment software to speed up the launch of the main program. Only required on slower/older systems and if disabled it loads when required via an instance of svchost.exe. Also included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and othersYes
CyberLink PowerCinemaNPCMAgent.exePreloads parts of the HP re-branded version of the CyberLink PowerCinema digital home entertainment software to speed up the launch of the main program. Only required on slower/older systems and if disabled it loads when required via an instance of svchost.exe. Found on the HP TouchSmart series of tablets and all-in-one desktopsYes
PC Malware CleanerUPCMalwareCleaner.exePC Malware Cleaner anti-malware. Detected by Malwarebytes as PUP.Optional.Plumbytes. The file is located in %ProgramFiles%\PC Malware Cleaner. If bundled with another installer or not installed by choice then remove itNo
PC MaticRTUPCMaticRT.exePart of an older version of the PC Matic utility suite from PC Pitstop, LLCNo
PCM DefenderXpcmdefenderp.exeDetected by Malwarebytes as Rogue.PCMDefender. The file is located in %AppData%\PCM DefenderNo
PCMedicXPCMedic.exePCMedic rogue security software - not recommended, removal instructions hereNo
PCMedicXPCMedicLaunch.exePCMedic rogue security software - not recommended, removal instructions hereNo
PCMMRealtimeXpcmm.exePC MightyMax rogue security software - not recommended, see hereNo
PCMM2007RTXpcmm2007.exePC MightyMax 2007 rogue security software - not recommended, see hereNo
PCMMediaSharing?PCMMediaSharing.exePart of Acer HomeMedia Connect, which is part of Acer Arcade Live. What does it do and is it required?No
pcmn891.exeUpcmn891.exeFreeKeyLogger surveillance software. Uninstall this software unless you put it there yourselfNo
PCMaster AntispywareXpcmp.exePCMaster Antispyware rogue security software - not recommended, removal instructions hereNo
PCMServiceNPCMService.exePart of Cyberlink's PowerCinema - which can be used to watch movies, play music and even watch TV in a central location. Commonly, PC manufacturers will base their own multimedia player/organizer on PowerCinema (such as Dell's Media Experience and Acer's Arcade Deluxe). Disabling this entry will not prevent PowerCinema working and doing so can prevent problems such as the screensaver not starting or a laptop not entering standby/hibernation/sleep-modeYes
Cyberlink PowerCinema 3.0NPCMService.exePart of Cyberlink's PowerCinema - which can be used to watch movies, play music and even watch TV in a central location. Commonly, PC manufacturers will base their own multimedia player/organizer on PowerCinema (such as Dell's Media Experience and Acer's Arcade Deluxe). Disabling this entry will not prevent PowerCinema working and doing so can prevent problems such as the screensaver not starting or a laptop not entering standby/hibernation/sleep-modeYes
pcn.exeXpcn.exeDetected by Dr.Web as Trojan.DownLoader10.49964. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
SoundXPCNT_Trend.exeDetected by Malwarebytes as Trojan.Agent.AI. The file is located in %System%\driversNo
PCPTMReminderUpcoptimizer.exeDetected by Malwarebytes as PUP.Optional.Jawego. The file is located in %ProgramFiles%\{GUID}. If bundled with another installer or not installed by choice then remove itNo
ProtectXPCoptimizer2010.exePCoptimizer 2010 rogue security software - not recommended, removal instructions hereNo
PC_Clean_OptimizerXPCOUpdate.exeDetected by Malwarebytes as Rogue.PCCleanerOptimizer. The file is located in %ProgramFiles%\PCONo
PCPrivacyCleanerXpcpc.exePCPrivacyCleaner rogue privacy tool - not recommendedNo
Total Protect 2009Xpcpc_starter.exeTotal Protect 2009 rogue security software - not recommended, removal instructions hereNo
PCPerfUpcperf.exePC Accelerator 2007 from DefendGate Inc. "Powerful all-in-one PC performance and Internet acceleration solution designed to help increase your system and online performance and security"No
RDReminderUPCPerformer.exePC Performer optimization utility by PerformerSoft. Detected by Malwarebytes as PUP.Optional.PCPerformer. The file is located in %ProgramFiles%\PC Performer. If bundled with another installer or not installed by choice then remove itNo
PC Pitstop EraseUPCPitstopErase.exeScheduler for an earlier release of Erase from PC Pitstop LLC - which "protects your privacy by removing personal information stored on your computer. Safely and easily removes traces of your computing and Internet activities." Now superseded by PC Magnum (which is detected by Malwarebytes as PUP.Optional.PCMagnum)Yes
PC Pitstop Erase SchedulerUPCPitstopErase.exeScheduler for an earlier release of Erase from PC Pitstop LLC - which "protects your privacy by removing personal information stored on your computer. Safely and easily removes traces of your computing and Internet activities." Now superseded by PC Magnum (which is detected by Malwarebytes as PUP.Optional.PCMagnum)Yes
PCPitstopEraseUPCPitstopErase.exeScheduler for an earlier release of Erase from PC Pitstop LLC - which "protects your privacy by removing personal information stored on your computer. Safely and easily removes traces of your computing and Internet activities." Now superseded by PC Magnum (which is detected by Malwarebytes as PUP.Optional.PCMagnum)Yes
PCPitStopEraserUPCPitStopErase.exeScheduler for an earlier release of Erase from PC Pitstop LLC - which "protects your privacy by removing personal information stored on your computer. Safely and easily removes traces of your computing and Internet activities." Now superseded by PC Magnum (which is detected by Malwarebytes as PUP.Optional.PCMagnum)No
PCPlus SecurityXpcplusupsc.exePCPlus rogue security software - not recommended, removal instructions hereNo
PC Pitstop Optimize SchedulerUPCPOptimize.exeScheduler for an older version of the Optimize system optimization utility from PC Pitstop LLCNo
PCPOptimizeUPCPOptimize.exeScheduler for an older version of the Optimize system optimization utility from PC Pitstop LLCNo
PCPowerSpeedUPCPowerTray.exePCPowerSpeed optimization utility. Detected by Malwarebytes as PUP.Optional.PCPowerSpeed. The file is located in %ProgramFiles%\PCPowerSpeed. If bundled with another installer or not installed by choice then remove itNo
pcprivacyXpcprivacy.exePCPrivacy rogue security software - not recommended, removal instructions hereNo
PC Privacy2XPcPrivacy2Up.exePCPrivacy rogue security software - not recommended, removal instructions hereNo
PCPrivacyDockUPCPrivacyDock.exePC Privacy Dock by Tweaklogy Technologies - "a system cleaner that makes cleaning your computer a safe and simple process." Detected by Malwarebytes as PUP.Optional.PCPrivacyDock. The file is located in %ProgramFiles%\PC Privacy Dock. If bundled with another installer or not installed by choice then remove itNo
PCprotectar.exeXPCprotectar.exePCprotectar rogue security software - not recommended. A member of the AntiAID familyNo
PC Protection CenterXPcProtection.exePC Protection Center 2008 rogue security software - not recommended, removal instructions hereNo
PCPUReminderUPCPurifier.exeOptimize and improve your PC's performance with PC Purifier. Get rid of all registry errors to make your PC run faster and smoother. Detected by Malwarebytes as PUP.Optional.PCPurifier. The file is located in %ProgramFiles%\PCPurifier or %ProgramFiles%\PC Purifier or %ProgramFiles%\PC-Purifier. If bundled with another installer or not installed by choice then remove itNo
PCRecSAUPCRecSA.exePart of the IBM/XPoint Rapid Restore backup utility. If you choose, you can use it to create a "clean" backup of your hard drive. The process involves the software partitioning your hard drive, making a compressed image of the working drive which will then allow you to revert to that should you need toNo
pcsXpcs.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
pcspeedupXpcs.exePC Speed Up rogue security software - not recommended, removal instructions hereNo
PC ScanAndSweepNPCScanAndSweep.exeAscentive PC Scan & Sweep junk file remover - not recommended, see here and hereNo
PC ScoutXpcscout.exePC Scout rogue security software - not recommended, removal instructions hereNo
PCSpeed ServiceXpcsdup.exePCSpeed rogue security software - not recommended, removal instructions hereNo
PCSecureMainXPCSecure.exePC Secure rogue security software - not recommended, removal instructions hereNo
PcSecureNetXPcSecureNet.exePcSecureNet rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
BGDDS9N8RWXPCSetups.exe.lnkDetected by McAfee as RDN/Generic Dropper!uv and by Malwarebytes as Trojan.Agent.IMNNo
CyberArmorHelperYpcshelp.exePart of the CyberArmor enterprise class personal firewallNo
PC Smart CleanupXPCSmart.batDetected by Malwarebytes as Rogue.PCSmartCleanup. The file is located in %ProgramFiles%\PC Smart Cleanup, removal instructions hereNo
PC Speedup Pro_LogonUpcsp.exe"PC Speedup Pro is the world's most liked and preferred PC protection utility! The most efficient and simple-to-use tool for the users to quickly optimize and get a clean and faster PC." Detected by Malwarebytes as PUP.Optional.PCSpeedupPro. The file is located in %ProgramFiles%\PC Speedup Pro. If bundled with another installer or not installed by choice then remove itNo
PC Speedup-Pro_LogonUpcsp.exe"PC Speedup Pro is the world's most liked and preferred PC protection utility! The most efficient and simple-to-use tool for the users to quickly optimize and get a clean and faster PC." Detected by Malwarebytes as PUP.Optional.PCSpeedupPro. The file is located in %ProgramFiles%\PC Speedup-Pro. If bundled with another installer or not installed by choice then remove itNo
PCScan AntispywareXpcsp.exePCScan Antispyware rogue security software - not recommended, removal instructions hereNo
PC SpeedScan ProNPCSpeedScan.exeAscentive PC SpeedScan Pro registry optimizer - not recommended, see here and hereNo
PC-SpiderXpcspiup.exePC Spider rogue security software - not recommended, removal instructions hereNo
PcsProtectorXPcsProtector.exePcsProtector rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
PcsSecureXPcsSecure.exePcsSecure rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
Client Access PC5250 Sound?pcssnd.exePart of IBM's iSeries (nee As/400) Client Access - communications suite that allows desktop, browser and wireless access to iSeries servers. "The Client Access Express PC5250 emulator provides desktop users with a graphical user interface for existing iSeries applications". What does it do and is it required?No
Nokia Launch ApplicationXPCSuite.exeDetected by Sophos as W32/AutoRun-BHX and by Malwarebytes as Worm.Prolaco.Gen. Note - this is not legitimate Nokia or SAMSUNG file of the same name which is normally located in a %ProgramFiles%\Nokia or %ProgramFiles%\Samsung sub-directory. This one is located in %System%No
S60 PC Suite TrayNPCSuite.exeSystem Tray access to SAMSUNG PC Studio (by Nokia) - with which "you can use easily to manage personal data and multimedia file by connecting a Samsung Electronics Mobile hone(GSM/GPRS/UMTS) to your PC". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
PC SuiteNPCSuite.exeSystem Tray access to Nokia PC Suite - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
PC Suite TrayNPCSuite.exeSystem Tray access to Nokia PC Suite - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
PCSuiteNPCSuite.exeSystem Tray access to Nokia PC Suite and SAMSUNG PC Studio (by Nokia) - free PC software product that allows you to connect your mobile device to a PC and access mobile content as if the device and the PC were one. This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
Samsung PC Studio 7NPCSuite.exeSystem Tray access to SAMSUNG PC Studio (by Nokia) - with which "you can use easily to manage personal data and multimedia file by connecting a Samsung Electronics Mobile hone(GSM/GPRS/UMTS) to your PC". This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menuYes
PCSpeedUpUPCSUNotifier.exePC Speed Up optimization utility by Optimal Software s.r.o. Detected by Malwarebytes as PUP.Optional.PCSpeedUp. The file is located in %ProgramFiles%\PC Speed Up. If bundled with another installer or not installed by choice then remove itNo
PcsvXpcsvc.exeDelfin PromulGate adware. The most common filename is "pcsvc.exe"No
NokiaPCSyncTrayNPCSync.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
PCSyncNPCSync.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
PcSyncXPcSync.exeDetected by Sophos as W32/Rbot-XJ. Note - do not confuse with the legitimate Nokia application which is normally located in %ProgramFiles%\Nokia\Nokia PC Suite. This one is located in %System%No
PCSync.exeNPCSync.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
Nokia PC SyncNPcSync2.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
Nokia.PCSyncNPcSync2.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
PC SyncNPCSync2.exeSystem Tray access to PC Sync for both Nokia and Samsung - which allow you to synchronise contacts, calendar/to-do items, notes, and e-mails between your mobile device and your PC Personal Information Manager (PIM). Available via the main Nokia PC Suite or SAMSUNG PC Studio interfacesYes
PcSyncNPcSync2.exeSystem Tray access to Nokia PC Sync - which "allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a Nokia mobile phone and your PC Personal Information Manager (PIM)." Available via the main Nokia PC Suite interfaceYes
PCSync2NPCSync2.exeSystem Tray access to PC Sync for both Nokia and Samsung - which allow you to synchronise contacts, calendar/to-do items, notes, and e-mails between your mobile device and your PC Personal Information Manager (PIM). Available via the main Nokia PC Suite or SAMSUNG PC Studio interfacesYes
Samsung.PCSyncNPCSync2.exeSystem Tray access to SAMSUNG PC Sync - which allows you to synchronise contacts, calendar/to-do items, notes, and e-mails between a SAMSUNG mobile phone and your PC Personal Information Manager (PIM). Available via the main SAMSUNG PC Studio interfaceYes
PC Tools AntiVirus ClientYPCTAV.exeSystem Tray access to PC Tools AntiVirus from PC Tools by Symantec (now discontinued) - which "provides world-leading protection against viruses, worms and Trojans with rapid updates and IntelliGuard™ technology"Yes
PCTAVYPCTAV.exeSystem Tray access to PC Tools AntiVirus from PC Tools by Symantec (now discontinued) - which "provides world-leading protection against viruses, worms and Trojans with rapid updates and IntelliGuard™ technology"Yes
PCTAVAppYPCTAV.exeSystem Tray access to PC Tools AntiVirus from PC Tools by Symantec (now discontinued) - which "provides world-leading protection against viruses, worms and Trojans with rapid updates and IntelliGuard™ technology"Yes
pctdf.exeXpctdf.exePCTotalDefender rogue spyware remover variantNo
PCTechHotlineUPCTechHotline.exePC Tech Hotline Assistant - "Whether it's emergency computer assistance, virus concerns, peripheral and software configurations or other technical issues, round the clock help is just a call away." Detected by Malwarebytes as PUP.Optional.PCTechHotline. The file is located in %ProgramFiles%\PCTechHotline. If bundled with another installer or not installed by choice then remove itNo
PcThrustUPcThrust.exePCThrust from SwiftDog - "increases computer performance by allocating higher portions of CPU power to active applications and games"No
PCTurboProXpctp.exePcTurboPro rogue system optimization tool - not recommended, removal instructions hereNo
CountrySelectionNpctptt.exeCountry selection for a PCtel HSP56 based modem. Often found in OEM (Dell,Compaq, HP, etc) systems for their modems included on the motherboard or as a separate card. Once you've set the modem up to the chosen country it's not requiredNo
0pagXPCtray.exeDetected by Malwarebytes as Spyware.Password. The file is located in %LocalAppData%\MicrosoftNo
Windstream_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Windstream users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
TTNET_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Türk Telekom users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
tcnz_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Telecom New Zealand (now Spark New Zealand) users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
Spark_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Spark New Zealand (was Telecom New Zealand) users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
Comcast_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Comcast users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
Telstra_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for Telstra users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
ATT_McciTrayAppUpcTrayApp.exeSystem tray access to the Motive broadband configuration and repair utility - for AT&T users. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
pctspkUpctspk.exeUsed for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functionsNo
PCTVOICEUpctspk.exeUsed for modems based upon PC-TEL chipsets. Normally used for some Voice and Speakerphone functions and also for some Power management options. If you remove it you may not be able to use any of those functionsNo
ISTrayYpctsTray.exeSystem Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools by Symantec (now discontinued)Yes
pctsTrayYpctsTray.exeSystem Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools by Symantec (now discontinued)Yes
pctsTray.exeYpctsTray.exeSystem Tray access to both PC Tools Internet Security suite and Spyware Doctor antispyware from PC Tools by Symantec (now discontinued)Yes
MRCUPCTuneUp.exePC Tune-Up by Large Software - "registry repair defrag software which quickly and easily brings your slow running computer back to life by removing the items that can cause crashes, slow speeds, freezing, and impact the overall health of your computer." Detected by Malwarebytes as PUP.Optional.PCTuneUp. The file is located in %ProgramFiles%\PC Tune-Up. If bundled with another installer or not installed by choice then remove itNo
pctutoXpctuto.exeDetected by Malwarebytes as PUP.Optional.Tuto4PC. The file is located in %ProgramFiles%\Agence-Exclusive. If bundled with another installer or not installed by choice then remove itNo
PCTutoXpctuto.exeDetected by Intel Security/McAfee as Adware-Tuto4PC and by Malwarebytes as Adware.EoRezoNo
PCTVOICEUpctvoice.exeThe program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it, it comes back. It's better to leave itNo
pcuagentXpcuagent.exeDetected by Dr.Web as Trojan.DownLoader10.20624 and by Malwarebytes as Adware.KorAdNo
pc-upXpcup.exeDetected by Dr.Web as Trojan.DownLoader8.32000No
PCVaccineXPCVaccineLaunch.exePCVaccine rogue security software - not recommended, removal instructions hereNo
PCWatchUpcwatch.exePCWatch surveillance software. Uninstall this software if you did not install it yourselfNo
WPMN1JWI05XPCWire.exe.lnkDetected by McAfee as RDN/Generic.dx!ddb and by Malwarebytes as Backdoor.Agent.IMNNo
Xtrem parental controlUpcx.exeParentXtreme - surveillance software. Uninstall this software unless you put it there yourselfNo
ShellXPCyrNJb.exe,explorer.exeDetected by McAfee as RDN/Generic BackDoor!wu and by Malwarebytes as Backdoor.Agent.DCE. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "explorer.exe" (which is a legitimate file located in %Windir% and shouldn't be deleted) and "PCyrNJb.exe" (which is located in %AppData%\B4b6loG5)No
PC Live GuardXPC[random].exePC Live Guard rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PCLiveGuard. The file is located in %CommonAppData%\[random]No
PC Antispyware 2010XPC_Antispyware2010.exePC Antispyware 2010 rogue security software - not recommended, removal instructions hereNo
PC Security 2009XPC_Security2009.exePC Security 2009 rogue security software - not recommended, removal instructions hereNo
PC_GIZMOSUPC_[version].exe.exeDetected by Malwarebytes as PUP.Optional.PCGizmos. The file is located in %AppData%\PC-Gizmos. If bundled with another installer or not installed by choice then remove itNo
Popup DefenderUPD.exePopup Defender - pop-up killerNo
Windows ServiceXpd14.exeAdware - detected by DiamondCS TDS-3 anti-trojan as the DELF.DG TROJAN!No
Windows ServiceXpd7.exeDetected by Trend Micro as TROJ_SMALL.VZNo
Pd71PanUPd71Pan.ExeAudiotrak Prodigy 7.1 sound card control panelNo
PdaNet DesktopUPdaNetPC.exePdaNet from June Fabrics Technology Inc. Allows you to use iPhone, Android, Blackberry, Windows Mobile or PocketPC smartphones as wireless modem for your PCNo
PDASCANXpdascan.exeDetected by Sophos as W32/Agobot-QYNo
MICROSOFT Windows updateXpdate.exeDetected by Trend Micro as WORM_RBOT.BZT and by Malwarebytes as Trojan.MWF.GenNo
Dialog HelperNPDDLGHLP.EXEDialog Helper for an older version of the PowerDesk Pro file management utility by Avanquest. Previously by V Communications, Inc (now part of Avanquest) who acquired it from Kroll OnTrackNo
PDDMUpddm.exePatchlink Update - "core product of the leading patch and vulnerability management software solution for medium and large enterprise network security"No
Personal Defender 2009Xpdefendr.exePersonal Defender 2009 rogue security software - not recommended, removal instructions hereNo
PDEngineUPDEngine.exePerfectDisk from Raxco - disk defragmenter. Only required if you schedule disk defragmenting at re-bootNo
AdobeReaderUXPDEngines.exeDetected by McAfee as RDN/Generic Downloader.x and by Malwarebytes as Backdoor.Agent.ADBENo
Matrox PowerdeskNPDesk.exe"Matrox PowerDesk software provides extra multi-display desktop management controls"No
PowerDeskNPDExplo.exeOlder version of the PowerDesk Pro file management utility by Avanquest. Previously by V Communications, Inc (now part of Avanquest) who acquired it from Kroll OnTrackNo
PowerDesk [version]NPDExplo.exeOlder version of the PowerDesk Pro file management utility by Avanquest. Previously by V Communications, Inc (now part of Avanquest) who acquired it from Kroll OnTrackNo
PDF FoxitReader.exeXPDF FoxitReader.exeDetected by McAfee as W32/Worm-FFX!5AC005CEBD74 and by Malwarebytes as Trojan.Ransom.GAR. Note - this is not the legitimate Foxit Reader and the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PDF Reader Launcher.exeXPDF Reader Launcher.exeDetected by McAfee as RDN/Ransom!cd and by Malwarebytes as Ransom.FileLocker. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
adobe2Xpdf.exeDetected by Malwarebytes as Trojan.Agent.PFD. The file is located in %AppData%\adobe2No
adobea1Xpdf.exeDetected by Malwarebytes as Backdoor.NetWiredRC. The file is located in %AppData%\adobea1No
ShellXpdf.exeDetected by Malwarebytes as Trojan.Agent.AI. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "pdf.exe" (which is located in %Temp%)No
UpdateXpdf.exeDetected by Malwarebytes as Trojan.Agent.UPD. The file is located in %AppData%\pdfNo
PDFPrintNpdf24.exePDF24 Creator - free PDF converter utilityNo
PDFCreatorClientNPDFClient.exeJaws PDF Creator by Jaws PDF Technologies - "is an affordable and reliable means of creating high quality PDF files from virtually any document, in any application"No
PDFHookUpdfcreate5hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFHookUpdfcreate6hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
Nuance PDF ProductsUpdfcreate7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
pdfcreate7hook.exeUpdfcreate7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFCreHookUpdfcreate7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
Nuance PDF ProductsUpdfcreate8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
pdfcreate8hook.exeUpdfcreate8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFCreHookUpdfcreate8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
StartnameXPDFF2.exeDetected by Malwarebytes as Backdoor.Agent.DCE. The file is located in %ProgramFiles% - see hereNo
Proof Defender 2009Xpdfndr.exeProof Defender 2009 rogue security software - not recommended, removal instructions hereNo
Perfect Defender 2009Xpdfndr.exePerfect Defender 2009 rogue security software - not recommended, removal instructions hereNo
PDFHookUpdfpro5hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFHookUpdfpro6hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFHookUpdfpro7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PdfPro7Hook.exeUpdfpro7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFProHookUpdfpro7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
Nuance PDF ProductsUpdfpro7hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PdfPro8Hook.exeUpdfpro8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFProHookUpdfpro8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
Nuance PDF ProductsUpdfpro8hook.exePrevents the "Trial Version www.Nuance.com" watermark appearing in PDF documents created by the PDF creating/editing utilities from Nuance (was ScanSoft) when the product has been installed but not activated properly. See here for more informationNo
PDFSaverNPDFSaver.exePDF-Xchange range of PDF document creation utilities from Tracker Software ProductsNo
PDF-XChange CaptureNpdfSaver.exePDF-Xchange range of PDF document creation utilities from Tracker Software ProductsNo
pdfSaver3NpdfSaver3.exePDF-XChange by Tracker Software Products - create Adobe compatible PDF files from virtually any Windows software such as MS Word, Excel, AutoCAD, MS Publisher, etcNo
PDF CompleteNpdfsty.exe"PDF Complete is a high-quality PDF document creation tool that operates much like the Acrobat® PDF Writer solution. Almost any document can be converted to a pdf file by simply printing the document to the PDF Complete printer"No
PDF_Reader.exeXPDF_Reader.exeDetected by Dr.Web as Trojan.DownLoader11.32974 and by Malwarebytes as Trojan.Agent.PRDGen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
pdibmNpdibm.exePart of the IBM customized version of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which provides secure area of hard disk where files and folders are encrypted. This entry loads the associated IBM wizard to create the initial secure area once the program has been installed and will no longer be loaded (but remains as a startup entry) once it is completedYes
PDIBM ApplicationNpdibm.exePart of the IBM customized version of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which provides secure area of hard disk where files and folders are encrypted. This entry loads the associated IBM wizard to create the initial secure area once the program has been installed and will no longer be loaded (but remains as a startup entry) once it is completedYes
PDIBM.exeNpdibm.exePart of the IBM customized version of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which provides secure area of hard disk where files and folders are encrypted. This entry loads the associated IBM wizard to create the initial secure area once the program has been installed and will no longer be loaded (but remains as a startup entry) once it is completedYes
PDirectNPDirect.exeIBM/Lenovo ThinkPad Presentation Director - display configuration utility for your ThinkPad computer that enables you to create, manage, and use presentation and display schemesNo
Password Door LoaderUPDMonitor.exePassword Door - password protection softwareNo
pdnolXpdnol.exeDetected by Malwarebytes as Worm.SFDC. The file is located in %UserProfile% - see hereNo
PDNotesNPDNotes.exePost-it® Digital Notes from 3M - "simple to use software that lets you make and organize lists, plan projects step by step, sort your notes by category, personalize messages with photos, even set alarms to remind you of appointments or key dates". Not required unless you use the alarm featureYes
Post-it® Digital NotesNPDNotes.exePost-it® Digital Notes from 3M - "simple to use software that lets you make and organize lists, plan projects step by step, sort your notes by category, personalize messages with photos, even set alarms to remind you of appointments or key dates". Not required unless you use the alarm featureNo
Post-it(R) Digital NotesNPDNotes.exePost-it® Digital Notes from 3M - "simple to use software that lets you make and organize lists, plan projects step by step, sort your notes by category, personalize messages with photos, even set alarms to remind you of appointments or key dates". Not required unless you use the alarm featureYes
pdoubrhgfjkxeiqndtsXpdoubrhgfjkxeiqndts.exeDetected by McAfee as Ransom!hm and by Malwarebytes as Trojan.Dropper.injNo
pdoubrhgfjkxeiqndtsXpdoubrhgfjkxeiqndts.exeDetected by Sophos as Troj/Ransom-MD and by Malwarebytes as Trojan.Agent.USNo
Windows TMXpdpatbcyj.exeDetected by Trend Micro as WORM_RBOT.FEF. The file is located in %System%No
Intel PDSUpds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabledNo
Microsoft DirectXXPDSched.exeDetected by Trend Micro as WORM_SDBOT.CNNo
pdserviceUpdservice.exePart of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which "securely and transparently protects sensitive files on notebooks and desktop computers, regardless of their location (local hard disk, removable media, network file servers), all the time without forcing the user to think about security." As well as providing System Tray access to the main program GUI, this entry also mounts the secured virtual drive(s) when the system boots if you have configured them this way and set the "Automatic Login at Startup" option. This entry isn't required if you mount them manuallyYes
PDService.exeUpdservice.exePart of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which "securely and transparently protects sensitive files on notebooks and desktop computers, regardless of their location (local hard disk, removable media, network file servers), all the time without forcing the user to think about security." As well as providing System Tray access to the main program GUI, this entry also mounts the secured virtual drive(s) when the system boots if you have configured them this way and set the "Automatic Login at Startup" option. This entry isn't required if you mount them manuallyYes
PrivateDiskUpdservice.exePart of SafeGuard PrivateDisk from Sophos (formerly by Utimaco) - which "securely and transparently protects sensitive files on notebooks and desktop computers, regardless of their location (local hard disk, removable media, network file servers), all the time without forcing the user to think about security." As well as providing System Tray access to the main program GUI, this entry also mounts the secured virtual drive(s) when the system boots if you have configured them this way and set the "Automatic Login at Startup" option. This entry isn't required if you mount them manuallyYes
PDTrayUPDTRAY.EXESystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some modelsYes
PDTRAY.EXEUPDTRAY.EXESystem Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options. Scheme selection and settings are also available via Fn+F7 key combination on some modelsYes
ZPdtWzdVitaKey MC3000?PdtWzd.exePart of the Acer Bio-Protection fingerprint recognition feature included with their implementation of the MyWinLocker encryption software from EgisTec Inc - see hereNo
PDUiP6000DMonUPDUiP6000DMon.exeMemory Card Utility for the Canon PIXMA iP6000D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDUiP6000DTskbrUPDUiP6000DTskbr.exeMemory Card Utility for the Canon PIXMA iP6000D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDUiP6210DMonUPDUiP6210DMon.exeMemory Card Utility for the Canon PIXMA iP6210D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDUiP6220DMonUPDUiP6220DMon.exeMemory Card Utility for the Canon PIXMA iP6220D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDUiP6600DMonUPDUiP6600DMon.exeMemory Card Utility for the Canon PIXMA iP6600D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDUiP6700DMonUPDUiP6700DMon.exeMemory Card Utility for the Canon PIXMA iP6600D photo printer - which allows "your computer to access the memory card reader feature of your printer"No
PDVD10ServUPDVD10Serv.exeRemote Control background application for version 10 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
PowerDVD RC ServiceUPDVD10Serv.exeRemote Control background application for version 10 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
RemoteControl10UPDVD10Serv.exeRemote Control background application for version 10 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
RemoteControl11UPDVD11Serv.exeRemote Control background application for version 11 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneNo
PDVD8ServUPDVD8Serv.exeRemote Control background application for version 8 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one. Also rebranded as ASUSDVD 8 for ASUSTek based systemsYes
PowerDVDUPDVD8Serv.exeRemote Control background application for version 8 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one. Also rebranded as ASUSDVD 8 for ASUSTek based systemsYes
RemoteControl8UPDVD8Serv.exeRemote Control background application for version 8 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one. Also rebranded as ASUSDVD 8 for ASUSTek based systemsYes
PDVD9ServUPDVD9Serv.exeRemote Control background application for version 9 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
PowerDVD RC ServiceUPDVD9Serv.exeRemote Control background application for version 9 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
RemoteControl9UPDVD9Serv.exeRemote Control background application for version 9 of Cyberlink's PowerDVD. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
PDVDDXSrvUPDVDDXSrv.exeRemote Control background application for Cyberlink's PowerDVD DX - a Dell specific version of their standard PowerDVD product. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneNo
PDVDLaunchPolicyNPDVDLaunchPolicy.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PDVDLaunchPolicy ApplicationNPDVDLaunchPolicy.exeRuns version 10 of CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD10NPDVDLaunchPolicy.exeRuns version 10 of CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD12NPDVDLaunchPolicy.exeRuns version 12 of CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PDVDServUPDVDServ.exeRemote Control background application for Cyberlink's PowerDVD from version 5 thru 7. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
PowerDVDUPDVDServ.exeRemote Control background application for Cyberlink's PowerDVD from version 5 thru 7. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
RemoteControlUPDVDServ.exeRemote Control background application for Cyberlink's PowerDVD from version 5 thru 7. Enables you to use a remote control with your Blu-ray or DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use oneYes
RealtekXpdxhEecK.exeDetected by McAfee as RDN/Generic BackDoor!zs and by Malwarebytes as Backdoor.Agent.DCENo
Window upadateXpe2.exeAdded by a variant of Backdoor:Win32/RbotNo
peabyboftafvXpeabyboftafv.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile%No
peacewme4Xpeacewme4.exeDetected by Malwarebytes as Worm.AutoRun.Gen. The file is located in %Recycled%\{SID}No
PeachtreePrefetcherNPeachtreePrefetcher.exeInstalled with different versions of Peachtree (now Sage 50c) accounting software by Sage - loads several files Peachtree needs to run reducing the time the program needs to startNo
PeachtreePrefetcher.exeNPeachtreePrefetcher.exeInstalled with different versions of Peachtree (now Sage 50c) accounting software by Sage - loads several files Peachtree needs to run reducing the time the program needs to startNo
peadunuzvomyXpeadunuzvomy.exeDetected by McAfee as RDN/Downloader.a!ms and by Malwarebytes as Trojan.Agent.USNo
pebldwtygxtqqxumbvpXpebldwtygxtqqxumbvp.exeDetected by Trend Micro as TROJ_INJECTO.ARY and by Malwarebytes as Trojan.VBKryptNo
SIUYTXPEBTVVU.exeDetected by McAfee as RDN/Generic PWS.y!wz and by Malwarebytes as Backdoor.Agent.DCENo
PECarlinXPECarlin.exePECarlin adwareNo
PeerBlockUpeerblock.exe"PeerBlock lets you control who your computer 'talks to' on the Internet. By selecting appropriate lists of 'known bad' computers, you can block communication with advertising or spyware oriented servers, computers monitoring your p2p activities, computers which have been 'hacked', even entire countries!"Yes
Peer ManagerXpeere32.exeDetected by Sophos as W32/Sdbot-JXNo
PeerGuardianUPeerGuardian.exe"PeerGuardian is a privacy oriented firewall application. It blocks connections to and from hosts specified in huge blocklists (thousands or millions of IP ranges). Its origin seeds in targeting aggressive IPs while you use P2P"No
PeerGuardianUPeerGuardian_1.99b_pr13-6.exe"PeerGuardian is a privacy oriented firewall application. It blocks connections to and from hosts specified in huge blocklists (thousands or millions of IP ranges). Its origin seeds in targeting aggressive IPs while you use P2P"No
PeerGuardianUPeerGuardian_1.99b_pr14.exe"PeerGuardian is a privacy oriented firewall application. It blocks connections to and from hosts specified in huge blocklists (thousands or millions of IP ranges). Its origin seeds in targeting aggressive IPs while you use P2P"No
pefmonXpefmon.exeDetected by Malwarebytes as Trojan.FakeJava. The file is located in %AppData%No
pegfoffofcotXpegfoffofcot.exeDetected by McAfee as RDN/Downloader.a!to and by Malwarebytes as Trojan.Agent.USNo
PeiheXinXPeiheXin.exeDetected by Dr.Web as Trojan.Click2.58276 and by Malwarebytes as Trojan.AgentNo
Mouse Suite 98 DaemonNpelmiced.exeMouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated gamesNo
Hidup_SusahXPembantu.exeDetected by Symantec as W32.SillyFDC.BDM and by Malwarebytes as Worm.SFDCNo
pemuaxulcipeXpemuaxulcipe.exeDetected by McAfee as RDN/Ransom!ej and by Malwarebytes as Trojan.Agent.USNo
pendonXpendon.exeDetected by Malwarebytes as Adware.Kraddare. The file is located in %ProgramFiles%\pendonNo
Pro PCL Status MonitorUPENGSS.EXEXerox printer/fax/copier status monitor (PCL = printer control language)No
SlutXPenis.exeDetected by Malwarebytes as Trojan.Agent.E. The file is located in %AppData%\SubDir - see hereNo
LoadXPenisholes.exeDetected by Malwarebytes as Backdoor.Messa.E. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "Penisholes.exe" (which is located in %AppData%, see here)No
PennyBeeUPennyBeeW.exeDetected by Malwarebytes as PUP.Optional.Linkury. The file is located in %LocalAppData%\PennyBee. If bundled with another installer or not installed by choice then remove itNo
PenOfficeNPenOffice.exePenOffice collaboration and handwriting recognition software from Phatware® CorporationNo
Pent@VALUE 3.2UPent@VALUE.exePent@VALUE Digital Satellite Internet PC ReceiverNo
Pen DriverXPenTest.exeDetected by Malwarebytes as Backdoor.Androm. The file is located in %MyDocuments%\ServicesNo
PenWesUpenwes.exe"PenWes is free software that protects you when you're surfing the Web. More specifically, PenWes blocks websites that present a danger to Internet users. These either download malicious software or broadcast fraudulent adverts or sales websites that never deliver your purchases"No
pepipbapipeXpepipbapipe.exeDetected by McAfee as RDN/Generic Dropper!uy and by Malwarebytes as Trojan.Agent.USNo
pepylboxwundXpepylboxwund.exeDetected by McAfee as RDN/Generic BackDoor!rm and by Malwarebytes as Trojan.Agent.USNo
PeqBL100XPEQBL100.exeDetected by Symantec as W32.Envid.D@mmNo
pequiwacxaspXpequiwacxasp.exeDetected by McAfee as RDN/Generic.tfr!eb and by Malwarebytes as Trojan.Agent.USNo
WINDOWS SYSTEMXper.exeDetected by McAfee as W32/Zotob.worm.c and by Malwarebytes as Backdoor.AgentNo
Personal AntivirusXPerAvir.exePersonal Antivirus rogue security software - not recommended, removal instructions hereNo
perelsiXperelsi.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData% - see hereNo
msgmsgsXperemption.exeDetected by Sophos as W32/Sdbot-KUNo
PerfectSpeedUPerfectSpeed.exeSystem Tray access to the PerfectSpeed optimization utility from Raxco Software, Inc - which includes defrag, registry cleaning and privacy protection. Note - if you disable by right-clicking on the tray icon, it will run at start-up and then exitYes
PerfectSpeed ModuleUPerfectSpeed.exeSystem Tray access to the PerfectSpeed optimization utility from Raxco Software, Inc - which includes defrag, registry cleaning and privacy protection. Note - if you disable by right-clicking on the tray icon, it will run at start-up and then exit. This entry is taken from 7/Vista MSConfig and Windows Defender for an earlier releaseYes
PerfectSpeed.exeUPerfectSpeed.exeSystem Tray access to the PerfectSpeed optimization utility from Raxco Software, Inc - which includes defrag, registry cleaning and privacy protection. Note - if you disable by right-clicking on the tray icon, it will run at start-up and then exitYes
CheckWinPerfXperfinfo.exeAdded by a variant of the IRCBOT BACKDOOR!No
perfmonUperfmon.vbsMindStorm AnalyzerPro from Secure Associates. "A security management tool for customers easy to manage report and analyze security events across heterogeneous security devices"No
CheckWinPerfXperfmon32.exeAdded by a variant of the IRCBOT BACKDOOR!No
loadXPerfWatson.exeDetected by Malwarebytes as Backdoor.Agent.PDL. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "PerfWatson.exe" (which is located in %AppData%\Microsoft\Blend\14.0\FeedCache)No
© Windows Live Messenger Music Status Plugin ModuleXPerfWatsonPackage.exeDetected by McAfee as Generic Dropper and by Malwarebytes as Trojan.AgentNo
regehostXperf_ssp.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %System%No
Run POPFile in backgroundUperl.exePOPFile - E-mail spam blockerNo
PersFwYPersFw.exePart of the now discontinued Tiny/Kerio Personal Firewall. Runs as a service on an NT based OS (such as Windows 10/8/7/Vista/XP)No
Tiny Personal Firewall EngineYpersfw.exePart of the now discontinued Tiny Personal Firewall. Runs as a service on an NT based OS (such as Windows 10/8/7/Vista/XP)No
personalguardXpersonalguard.exePersonal Guard 2009 rogue security software - not recommended, removal instructions hereNo
Personal Internet Security 2011XPersonalIS2011.exePersonal Internet Security 2011 rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalInternetSecurity. The file is located in %CommonAppData%\[random]No
PMTXpersonalmoneytree.exePersonal Money Tree adwareNo
personalprotectorXpersonalprotector.exePersonal Protector rogue security software - not recommended, removal instructions hereNo
PersSecurityXpersonalsecurity.exePersonal Security rogue security software - not recommended, removal instructions hereNo
Personal Security SentinelXPersonalSS.exePersonal Security Sentinel rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalSecuritySentinel. The file is located in %CommonAppData%\[random]No
PerSonoCallYPerSonoCall.exePlantronics PerSonoCall software - which provides the link between wireless headsets and compatible softphone applications, allowing users to answer and end calls remotely while away from their desks via the headset call control button. Now superseded by their Sopkes softwareNo
PerSonoSuiteYPerSonoSuite.exePlantronics PerSono Suite software - which provides the link between wireless headsets and compatible softphone applications, allowing users to answer and end calls remotely while away from their desks via the headset call control button. Now superseded by their Sopkes softwareNo
ServiceXPervice.exeDetected by Dr.Web as Trojan.DownLoader4.32554 and by Malwarebytes as Trojan.AgentNo
Pest-PatrolXPest-Patrol.exePest-Patrol rogue security software - not recommended, removal instructions hereNo
Pest-Patrol 2.1.0XPest-Patrol.exePest-Patrol rogue security software - not recommended, removal instructions hereNo
PestCaptureXPestCapture.exePestCapture rogue security software - not recommended, removal instructions hereNo
Pest-CaptureXPestCapture.exePestCapture rogue security software - not recommended, removal instructions hereNo
PestPatrolCLUPestPatrolCL.exeRuns the command line scanner for PestPatrol at boot time - part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
pestsweeperXpestsweeper.exePestSweeper rogue security software - not recommended, removal instructions hereNo
PestTrapXPestTrap.exePestTrap rogue spyware remover - not recommended, removal instructions here. Detected by Microsoft as Rogue:Win32/SpySheriffNo
PestWiperXPestWiper.exePestWiper rogue security software - not recommended. Detected by Microsoft as Rogue:Win32/SpySheriffNo
MSPetServXPET32.EXEDetected by Sophos as W32/IRCBot-VENo
peteupdateXpete.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%No
UpdateserviceXpetray.exeDetected by Malwarebytes as Trojan.Banker. The file is located in %Root% - see hereNo
MSN MessengerXpetrescue.exeDetected by Sophos as Troj/Agent-ABXH and by Malwarebytes as Trojan.BankerNo
Microsoft FixUpXpevblbvr.exeDetected by Trend Micro as WORM_RBOT.DWKNo
Kodak Picture Easy *.* Batch TransferNPezDownload.exePart of "Kodak Picture Easy" software for digital cameras. Includes the display of an icon in the System Tray to quickly transfer photos to a PC. *.* represents the versionNo
pezorxyvatteXpezorxyvatte.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfileNo
STROMKERNHILFEXpfde22.exeDetected by McAfee as Generic.grp!mq and by Malwarebytes as Backdoor.Agent.DCNo
Guardian PC Security ToolsUPfft.exeBoomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security SuiteNo
pFGhxpSbYyLWrXpFGhxpSbYyLWr.exeDetected by Sophos as Troj/Agent-TEZ and by Malwarebytes as Rogue.Agent.SANo
PrivatefirewallYPFGUI.exePrivatefirewall by Privacyware - "a proactive, multi-layered defense solution for Windows desktops and servers"No
MDM Rock 4Xpfhtksleq.exeDetected by Kaspersky as Backdoor.Win32.SdBot.chg. The file is located in %System%No
PFM3.0UPFM30.exeManagement software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device, transfer photos from a PC by drag and drop and on this wireless model, you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this oneYes
PFM30UPFM30.exeManagement software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device, transfer photos from a PC by drag and drop and on this wireless model, you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this oneYes
Philips PhotoFrame ManagerUPFM30.exeManagement software for the Philips 8FF3WMI/27 digital PhotoFrame. Used to configure the device, transfer photos from a PC by drag and drop and on this wireless model, you can also use it to download RSS feeds to and display Internet photos on the device. Only required if you use the wireless features - otherwise it can be started when you manually connect the device. May also be included with other models but currently only available for this oneYes
PDF Filler Pilot printing agentUpfpagent.exeVirtual printer for PDF Filler Pilot by Two Pilots - which "is a PDF filler that allows you to fill out PDF forms and other electronic forms (DOC, XLS, TXT...) and import and export data from/to an external database"No
PDF Filler Pilot (demo) printing agentUpfpagentd.exeVirtual printer for PDF Filler Pilot by Two Pilots - which "is a PDF filler that allows you to fill out PDF forms and other electronic forms (DOC, XLS, TXT...) and import and export data from/to an external database." Demo versionNo
PerfectPrintNpfppop70.exePrint engine used by Corel WordPerfect 7 and Presentations 7No
PDFFillerPilotAgentDUPfpprxyTSD.exePDF Filler Pilot by Two Pilots - "is a PDF filler that allows you to fill out PDF forms and other electronic forms (DOC, XLS, TXT...) and import and export data from/to an external database"No
ScanSnap Manager?PfuSsMon.exeIncluded with the software for the ScanSnap range of scanners from Fujitsu - which "take the complication out of document imaging with one-button ease of use. Perfect for home and small business environments, the ScanSnap family of scanners bring duplex multi-sheet scanning to everyone, combining performance and affordability in a compact size"No
PfuSsSct.exe?PfuSsSct.exeIncluded with the software for the ScanSnap range of scanners from Fujitsu - which "take the complication out of document imaging with one-button ease of use. Perfect for home and small business environments, the ScanSnap family of scanners bring duplex multi-sheet scanning to everyone, combining performance and affordability in a compact size"No
PC Tools Privacy GuardianUpg.exePrivacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
Privacy GuardianUpg.exePrivacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
pgUpg.exePrivacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
PeerGuardianUpg2.exe"PeerGuardian is a privacy oriented firewall application. It blocks connections to and from hosts specified in huge blocklists (thousands or millions of IP ranges). Its origin seeds in targeting aggressive IPs while you use P2P"No
Pg6r2VPXPg6r2VP.exeDetected by McAfee as RDN/Generic FakeAlert!ej and by Malwarebytes as Backdoor.Messa.ENo
!1_pgaccountYpgaccount.exeDiamondCS ProcessGuard "is a powerful new type of security system that secures Windows at the lowest (kernel) level, allowing it to provide the maximum possible security" stopping malware from being executed silently in the background, as well as a variety of other attacks. You will see one instance of pgaccount.exe for every active account on your system, and this is essential for PG to work properlyNo
FantasyFootballBoss Browser Plugin LoaderUpgbrmon.exeFantasyFootballBoss toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FantasyFootballBoss\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itYes
FantasyFootballBoss Browser Plugin Loader 64Upgbrmon64.exeFantasyFootballBoss toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FantasyFootballBoss\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itNo
PghistYPgHist.exePart of Privacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". This startup entry runs only on the next reboot if the "Cache, History and Address Bar" option is selected under "Browsers" when the users selects "Clean Your Computer" and is only created when Privacy Guardian is installed on XP. Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
PgHist.exeYPgHist.exePart of Privacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". This startup entry runs only on the next reboot if the "Cache, History and Address Bar" option is selected under "Browsers" when the users selects "Clean Your Computer" and is only created when Privacy Guardian is installed on XP. Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
Privacy GuardianYPgIndex.exePart of Privacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". This startup entry runs only on the next reboot if the "Cache, History and Address Bar" option is selected under "Browsers" when the users selects "Clean Your Computer" and is only created when Privacy Guardian is installed on XP. Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
PrivacyGuardianIndexYPgIndex.exePart of Privacy Guardian from PC Tools by Symantec (now discontinued) - which "is a safe and easy-to-use privacy protection tool that securely deletes online Internet tracks and program activity records that are stored in your browser and other hidden files on your computer". This startup entry runs only on the next reboot if the "Cache, History and Address Bar" option is selected under "Browsers" when the users selects "Clean Your Computer" and is only created when Privacy Guardian is installed on XP. Also included in PC Tools Desktop Maestro (which incorporates Privacy Guardian)Yes
statloadsXpgjd83sa.exeDetected by Sophos as W32/Sdbot-UKNo
FantasyFootballBoss EPM SupportUpgmedint.exeFantasyFootballBoss toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FantasyFootballBoss\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itYes
PromulGateXPgMonitr.exeDelfin PromulGate adwareNo
Defender Copy AutoConfig TrackingXpgplfkeyu.exeDetected by Dr.Web as BackDoor.IRC.Bot.2596 and by Malwarebytes as Trojan.Downloader.RNDNo
PGPSDKSVCYpgpsdkserv.exePGPsdkServ.exe is the new SDK service which is responsible for performing all PGP key management and cryptographic functions. This functionality was moved into a service to allow multiple modules simultaneous read/write access to the keyrings, among other things. As you can imagine, it is necessary for PGPsdkServ to be running in order to perform practically any PGP functionalityNo
PGPSERVICEUpgpservice.exePGPservice.exe has two main purposes: (1) it handles a large part of the PGPnet functionality (along with the PGPnet driver) and (2) it allows efficient access to the PGP preferences database. The individual PGP modules normally access the preferences through PGPservice, but they are capable of a "fall-back" mode where they can handle such access on their own. Thus, if you are not running PGPnet, you may not immediately notice much of a difference if you disable PGPservice. If you are running PGPnet, you will notice a big differenceNo
PGPtrayNpgptray.exePGP 7.x. Provides icon tray shortcuts to PGP programs from Network Associates. Available via Start → ProgramsNo
PGQLXpgql.exeDetected by Sophos as Troj/Bckdr-PQNNo
VirtualPCGuardXpgs.exeVirtualPCGuard rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
AntivirusschermXpgs.exeAntivirusscherm, Dutch rogue security software - not recommended. A member of the AVSystemCare familyNo
freinstXpgs.exePart of the AVSystemCare rogue security software and other members of this family. See here for more examplesNo
AntiWorm2008Xpgs.exeAntiWorm2008 rogue security software - not recommended. A member of the AVSystemCare familyNo
overinstallXpgs.exePart of the AVSystemCare rogue security software and other members of this family. See here for examplesNo
BedreigingsMonitoorXpgs.exeBedreigingsMonitoor rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusDifesaXpgs.exeVirusDifesa, Italian rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusEffaceurXpgs.exeVirusEffaceur, French rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusForsvarXpgs.exeVirusForsvar, Danish rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusGardeXpgs.exeVirusGarde, French rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusGuardPlusXpgs.exeVirusGuardPlus rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
WinSecureAvXpgs.exeWinSecureAv rogue security software - not recommended, removal instructions here. A member of the AVSystemCare family. Detected by Malwarebytes as Rogue.WinSecureAvNo
PCAntiVirusProXpgs.exePCAntiVirusPro rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
ProtectionCompleteXpgs.exeProtectionComplete rogue security software - not recommended. A member of the AVSystemCare familyNo
ProtectionConueXpgs.exeProtectionConue rogue security software - not recommended. A member of the AVSystemCare familyNo
AntiSpionageXpgs.exeAntiSpionage, German rogue security software - not recommended. A member of the AVSystemCare familyNo
AntiSpionageProXpgs.exeAntiSpionagePro, German rogue security software - not recommended. A member of the AVSystemCare familyNo
BortMedVirusXpgs.exeBortMedVirus rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusSchlachtXpgs.exeVirusSchlacht, German rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusSeigyoXpgs.exeVirusSeigyo rogue security software - not recommended. A member of the AVSystemCare familyNo
VirusVaktXpgs.exeVirusVakt, Swedish rogue security software - not recommended. A member of the AVSystemCare familyNo
AntiSpyControlXpgs.exeAntiSpyControl rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
ProtezionefiDataXpgs.exeProtezionefiData rogue security software - not recommended. A member of the AVSystemCare familyNo
BestsellerAntivirusXpgs.exeBestsellerAntivirus rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
atf.exeXpgs.exePart of members of the AVSystemCare family of rogue security software suites. See here for examplesNo
AntiSpywareControlXpgs.exeAntiSpywareControl rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
AntiSpywareSuiteXpgs.exeAntiSpywareSuite rogue security software - not recommended. A member of the AVSystemCare familyNo
MegaVirusKitXpgs.exeMegaVirusKit rogue security software - not recommended. A member of the AVSystemCare familyNo
AntiVer2008Xpgs.exeAntiVer2008, French rogue security software - not recommended. A member of the AVSystemCare familyNo
SichererAntivirusXpgs.exeSichererAntivirus, German rogue security software - not recommended. A member of the AVSystemCare familyNo
SichererSchutzXpgs.exeSichererSchutz, German rogue security software - not recommended. A member of the AVSystemCare familyNo
DefensaAntiMalwareXpgs.exeDefensaAntiMalware, Spanish rogue security software - not recommended. A member of the AVSystemCare familyNo
SpyGuardProXpgs.exeSpyGuardPro rogue security software - not recommended. A member of the AVSystemCare family. Detected by Malwarebytes as Rogue.SpyGuardNo
NeuerSchildXpgs.exeNeuerSchild, German rogue security software - not recommended. A member of the AVSystemCare familyNo
MenaceSecureXpgs.exeMenaceSecure rogue security software - not recommended. A member of the AVSystemCare familyNo
PCSecureSystemXpgs.exePCSecureSystem rogue security software - not recommended. A member of the AVSystemCare familyNo
TrojansFilterXpgs.exeTrojansFilter rogue security software - not recommended. A member of the AVSystemCare familyNo
TrojansFiltreXpgs.exeTrojansFiltre, French rogue security software - not recommended. A member of the AVSystemCare familyNo
BastioneAntivirusXpgs.exeBastioneAntivirus, Italian rogue security software - not recommended. A member of the AVSystemCare familyNo
PCTotalDefenderXpgs.exePCTotalDefender rogue security software - not recommended. A member of the AVSystemCare familyNo
AVSeguroXpgs.exeAVSeguro, Spanish rogue security software - not recommended. A member of the AVSystemCare familyNo
GoldenAntiSpyXpgs.exeGoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare familyNo
TrustedAntivirusXpgs.exeTrustedAntivirus rogue security software - not recommended. A member of the AVSystemCare family. Detected by Malwarebytes as Rogue.TrustedAntiVirusNo
PCViruslessXpgs.exePCVirusless, French rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
SolelunaAntiVirusXpgs.exeSolelunaAntiVirus rogue security software - not recommended. A member of the AVSystemCare familyNo
WinSpyControlXpgs.exeWinSpyControl rogue security software - not recommended. A member of the AVSystemCare family. Detected by Malwarebytes as Rogue.WinSpyControlNo
AVSystemCareXpgs.exeAVSystemCare rogue security software - not recommended. There are number of variants in this family sharing the same filename and user interface - see here. Detected by Malwarebytes as Rogue.AVSystemcareNo
VeiligheidAgentXpgs.exeVeiligheidAgent, Dutch rogue security software - not recommended. A member of the AVSystemCare familyNo
AntivirusFiableXpgs.exeAntivirusFiable, French rogue security software - not recommended. A member of the AVSystemCare familyNo
AntivirusForAllXpgs.exeAntivirusForAll rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
WegVonVirenXpgs.exeWegVonViren, Swedish rogue security software - not recommended. A member of the AVSystemCare familyNo
NoWayVirusXpgs.exeNoWayVirus rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
AntivirusOrdiXpgs.exeAntivirusOrdi, French rogue security software - not recommended. A member of the AVSystemCare familyNo
AntivirusPCPakkeXpgs.exeAntivirusPCPakke, Danish rogue security software - not recommended. A member of the AVSystemCare familyNo
AntivirusPCSuiteXpgs.exeAntivirusPCSuite rogue security software - not recommended, removal instructions here. A member of the AVSystemCare familyNo
AntiviruspertuttiXpgs.exeAntiviruspertutti rogue security software - not recommended. A member of the AVSystemCare familyNo
FantasyFootballBoss Search Scope MonitorUpgsrchmn.exeFantasyFootballBoss toolbar (now retired) - powered by the Ask Partner Network toolbars by IAC Applications (was Mindspark). Detected by Malwarebytes as PUP.Optional.MindSpark. The file is located in %ProgramFiles%\FantasyFootballBoss\bar\*.bin - where * represents a number or letter. If bundled with another installer or not installed by choice then remove itYes
pgtaffXpgtaff.exeAdRotator adware variantNo
PiracyGuardXpguard_nbvpeqv.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %CommonAppData%\PiracyGuardNo
Lenovo MotionUPG_Tray.exeSystem Tray access to and/or notifications for Lenovo Motion Control on selected models in their range of desktops and laptops. Rebranded version of Hand Gesture Control by PointGrab LTD - which "is a unique software-only solution that enables full control over tablets and smartphones through simple hand gestures. Using a standard 2D integrated camera available on mobile devices, PointGrab's solution accurately detects and tracks human hand movements from a close range and up to 5m"No
PGUPG_Tray.exeSystem Tray access to and/or notifications for Lenovo Motion Control on selected models in their range of desktops and laptops. Rebranded version of Hand Gesture Control by PointGrab LTD - which "is a unique software-only solution that enables full control over tablets and smartphones through simple hand gestures. Using a standard 2D integrated camera available on mobile devices, PointGrab's solution accurately detects and tracks human hand movements from a close range and up to 5m"No
Winux Piriax ServiceXPH32.EXEDetected by Symantec as W32.Randex.GNo
PHOTOfunSTUDIONPhAutoRun.exePanasonic PHOTOfunSTUDIO photo/video management and editing software for their LUMIX range of digital cameras - "smartly sorts your photos and videos into practical folders that are created automatically as you upload them from your camera to a computer. The folders and their icons interface are linked with your LUMIX"No
PHOTOfunSTUDIO -viewer-NPhAutoRun.exePanasonic PHOTOfunSTUDIO photo/video management and editing software for their LUMIX range of digital cameras - "smartly sorts your photos and videos into practical folders that are created automatically as you upload them from your camera to a computer. The folders and their icons interface are linked with your LUMIX"No
DRam prmaessorXpHELLd.exeDetected by Malwarebytes as Backdoor.IRCBot. The file is located in %System%No
Hyper FilesXphfhost.exeDetected by Sophos as Troj/Agent-JQONo
PhiBtnYPhiBtn.exeSnapshot and Launch button application from Philips belonging to Philips SPC 900NC CameraNo
Philips Intelligent AgentUPhilips Intelligent Agent.exePhilips Intelligent Agent searches automatically the correct update for your recordable drive in only three simple stepsNo
PhilipsRemoteUPhilipsRemote.exeRemote control support for MusicMatch Jukebox on Philips audio players such as the AZ2555 Sound Machine - see hereNo
PeresXPhisyco.scrDetected by McAfee as PWS-Banker.dldr!s and by Malwarebytes as Trojan.BankerNo
GamecomSoundUPhoebus_x64.exeSupport for the ASUS ROG Xonar Phoebus soundcardNo
PhoneCompanionNPhone Companion.exeLenovo PhoneCompanion is "used to sync your phone's pictures, videos, messages (SMS) and contacts. You can also use the application to send SMSes and also make phone calls as well"No
Dialgo SDKUPhoneAnswer.exeDialgo Wave Modem ActiveX SDK - telephone answering machine for scripting your own professional call center business scripts using a voice modem. "Features Caller ID Extraction, Digit Monitor and Playback, Wave File Playback and Recording on Phone Line. With this application you can save your Wave File in more than 20 Audio Formats"No
PhoneFree version 6.2UPHONEF??.EXEAn Internet telephony application. Complicated registration and ad banners tailored to your profile - see hereNo
PhoneToolsXphoneTools.exeDetected by Malwarebytes as Adware.Weiduan.TskLnk. The file is located in %ProgramFiles%\PhoneToolsNo
syshost.exeXphost.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %Root%No
Client AgentXphotes.exeDetected by Sophos as Troj/PPdoor-PNo
photo sex #.exeXphoto sex #.exeDetected by Malwarebytes as Trojan.Agent.E - where # represents one or more digits. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
POURXphoto.exeDetected by McAfee as RDN/Autorun.bfr!d and by Malwarebytes as Worm.AutoRun.ENo
StartupXPhoto.exeDetected by Malwarebytes as Trojan.Agent.STU. The file is located in %CommonAppData%\Microsoft\Windows\Start Menu\Programs (10/8/7/Vista) or %AllUsersProfile%\Start Menu\Programs (XP)No
RunXPhoto.exeDetected by Malwarebytes as Backdoor.Agent.TRJE. The file is located in %AppData%No
PhotoXPhoto.exeDetected by Sophos as W32/SillyFDC-KH and by Malwarebytes as Worm.SFDC.GenNo
OnceXPhoto.exeDetected by Malwarebytes as Backdoor.Agent.TRJE. The file is located in %AppData%No
DrsktopXPhoto49.exeDetected by Dr.Web as Win32.HLLW.Autoruner2.14589 and by Malwarebytes as Backdoor.Agent.ENo
winsys32XPhotobucket Energi3.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData% - see hereNo
PhotoCAL StartupNPhotoCAL.exePhotoCAL wizard driven monitor calibration software from ColorVision for beginners and photo enthusiastsNo
PhotoJoyNPhotoJoy.exePhotoJoy by IncrediMail Ltd - utility to turn photos into PhotoToys, 3D Screensavers and Wallpaper CollagesNo
Auto Run Software for Photo FrameUPhotoManager.exeManagement software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the deviceYes
PhotoManagerUPhotoManager.exeManagement software for Philips digital PhotoFrame range. Used to edit photos and transfer them directly from a PC via a USB cable. Start manually when you connect the deviceYes
Photos Widget (HTC Home)NPhotos.exePhotos Widget from HTC Home - which is "a free set of widgets for Windows like on HTC Smartphones." The default installation includes the QuickShare ad-supported browser enhancement which can in turn install the Delta toolbarYes
Photos.exeXPhotos.exeDetected by Malwarebytes as Backdoor.Messa. The file is located in %AppData%No
PhotoScape#.exeXPhotoScape#.exeDetected by Malwarebytes as Password.Stealer.E - where # represents 4 or more digits. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PhotoScapeXPhotoScape.exeDetected by Malwarebytes as Backdoor.Agent.E. The file is located in %AppData%No
PhotoshopElementsSyncAgentUPhotoshopElementsSyncAgent.exePart of Adobe Photoshop Elements. "When you sign in with your Adobe ID, you can back up your albums and catalogs to Photoshop.com servers. Backing up and synchronizing your albums and catalogs are essential for protecting your photos and media files"No
PhotoShopXphotoshoxp.exeDetected by Malwarebytes as Backdoor.Messa. The file is located in %AppData%No
I&F Viewer toolbarUphototoolkitmem.exePart of Photo Toolkit from VicMan Software, Inc - which "is powerful multifunctional software offering a complete set of image editing tools. It contains anything a digital camera owner might need to correct or enhance their photos"No
new_bAppXphotoview.exeDetected by Symantec as Trojan.Scarimson and by Malwarebytes as Trojan.Agent.MSIL.GenericNo
photo_idXphoto_id.exeDetected by Sophos as Troj/Agent-LTF and by Malwarebytes as Backdoor.BotNo
VMGOATPOSTREBOOTANXphphelp.exeDetected by McAfee as RDN/Generic PWS.y!bb3 and by Malwarebytes as Backdoor.Agent.GTONo
phpserviceXphpservice5.exeDetected by Malwarebytes as Trojan.Dropper.E. The file is located in %AppData%No
VCXD SettingsXphqg.EXEDetected by Trend Micro as WORM_RBOT.BRFNo
WEB DRIVERS FOR WIN32Xphqgh.exeDetected by Trend Micro as WORM_SDBOT.BPENo
VID INTERNET WEB DRIVERS FOR WIN32Xphqghu.exeDetected by Trend Micro as WORM_RBOT.BUDNo
VIEW POINT DRIVERS FOR WIN32Xphqghu.exeAdded by a variant of WORM_RBOT.BUD. The file is located in %System%No
phqghu.exeXphqghu.exeDetected by McAfee as W32/Autorun.worm.bx and by Malwarebytes as Backdoor.AgentNo
KYM Control SettingsXphqghum.exeDetected by Trend Micro as WORM_RBOT.BQDNo
Microsoft Update SERVICEXphqghum.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %System%No
VIEW POINT DRIVERSXphqghum.exeDetected by Trend Micro as WORM_RBOT.BRXNo
Optional Web Drivers For WIN32Xphqghume.exeAdded by a variant of Backdoor:Win32/RbotNo
LOCAL INTERNET WEB DRIVERS FOR WIN32Xphqghume.exeDetected by Trend Micro as WORM_RBOT.BTLNo
Microsoft UpdateXphqghumea.exeDetected by Trend Micro as WORM_SDBOT.AFO and by Malwarebytes as Backdoor.BotNo
PhraseExpressNphrase.exe"PhraseExpress organizes your frequently used text snippets in customizable categories for quick access"No
PhraseExpressUphraseexpress.exePhraseExpress® by Bartels Media GmbH - "organizes your frequently used text snippets in customizable categories for quick access"No
PhysicsUpdaterXPhysicsUpdater.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.DCENo
PI MonitorUPI Monitor.exePart of older versions of the ArcSoft PhotoImpression photo management software that monitors for new images being added to watched foldersNo
pi.exeXpi.exeDetected by Malwarebytes as Trojan.Agent. Note - the file is located in %AllUsersStartup% and/or %UserStartup% and its presence there ensures it runs when Windows startsNo
Pianists?Pianists.exeKeyboard Pianist - installed with versions of the Tildes Birojs language tools - which supports Latvian, English, German, Russian, French, Lithuanian and EstonianNo
pibmyrpimqaqXpibmyrpimqaq.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes as Spyware.PasswordNo
pic.bmpXpic.bmpDetected by McAfee as RDN/Generic PWS.y and by Malwarebytes as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
(Default)Xpic.exeDetected by Malwarebytes as Backdoor.Agent.Gen. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot and the name field in MSConfig may be blank. The file is located in %AppData%No
whateverXpic.exeDetected by McAfee as RDN/Generic.bfr!hp and by Malwarebytes as Backdoor.Agent.XNo
PicabooNPicabooMain.exePicaboo - "Easily create stunning photo books and cards with your digital photos"No
Picasa Media DetectorNPicasaMediaDetector.exeMedia detector for an older version of the Picasa photo editing, organizing and sharing utility - before Google acquired itNo
LifeScape Media DetectorNPicasaMediaDetector.exeMedia detector for an older version of the Picasa photo editing, organizing and sharing utility - before Google acquired itNo
picoconXpicocon.exeDetected by Malwarebytes as Trojan.Clicker.Gen. The file is located in %UserProfile%\My MyPersonalStuffNo
piconUPIconStartup.exeIntel Management & Security Status (IMSS) tool system tray icon. Part of Intel Active Management Technology - bundled with many computers and used in network environments. Not required for standalone computersNo
IMSSUPIconStartup.exeIntel Management & Security Status (IMSS) tool system tray icon. Part of Intel Active Management Technology - bundled with many computers and used in network environments. Not required for standalone computersNo
Configuration L0aderXpicorulez.exeDetected by Sophos as W32/Sdbot-INNo
PicoZipUPicoZipTray.exeSystem tray access to PicoZip - "an award winning file compression utility for Microsoft Windows users. Its intuitive user interface is extremely easy to use, while its wide ranging support for most file compression formats and comprehensive feature set makes PicoZip the only archive utility you will ever need"No
PicPick StartNpicpick.exe"PicPick - "an all-in-one program that provides a full-featured screen capture tool, an intuitive image editor, a color picker, a color palette, a pixel-ruler, a protractor, a crosshair and even a whiteboard"No
PICPRTRNPICPRTR.EXEProgram for viewing and measuring a variety of 3D CAD data formatsNo
Pics.exeXPics.exeDetected by Malwarebytes as Trojan.Banker.Gen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see hereNo
picsvrXpicsvr.exeDelfin PromulGate adwareNo
PictureMoverNPictureMover.exeSnapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your cameraYes
PictureMover ApplicationNPictureMover.exeSnapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your cameraYes
Snapfish PictureMoverNPictureMover.exeSnapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your cameraNo
JPEGXPICTURES.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %MyDocuments%No
UPD32WIN.EXEXPicture_391.exeDetected by McAfee as RDN/Generic.bfr!fj and by Malwarebytes as Backdoor.Agent.ENo
PictureMoverNPICTUR~1.EXESnapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your cameraYes
PictureMover ApplicationNPICTUR~1.EXESnapfish PictureMover free application to get photos directly from your camera to Snapfish (and your computer), without the pain of uploading. "Snapfish by HP is the number one online photo service, with more than 70 million members in over 20 countries and 2 billion unique photos stored online". Run manually before connecting your cameraYes
picviewXpicview.exeDetected by Sophos as Troj/DwnLdr-FPHNo
PIC SYSTEMXpicx.exeDetected by Trend Micro as WORM_MYTOB.LLNo
Personal IDUpid.exeTranslation: Personal ID by coolspot AG - "is a personal identification number, which is permanently in a computer chip. This chip is on a USB stick, making it virtually compatible with all current PC's. After registering with the staff ID system is allocated and linked your record with this chip you a personal chip. Thus, staff ID to your ID card for the Internet"No
windowsXPIDcheck.exeDetected by Malwarebytes as Backdoor.PWin.Gen. The file is located in %AppData%No
winnt DNS identXpidchk32.exeDetected by Sophos as W32/Rbot-ACY and by Malwarebytes as Trojan.Agent.ENo
Windows UpdateXpidgin.exeDetected by Malwarebytes as Ransom.Stampado.Generic. The file is located in %AppData%No
PidginNpidgin.exePidgin IM client - "a multi-protocol Instant Messaging client that allows you to use all of your IM accounts at once"No
pidleXpidle.exeDetected by Sophos as Troj/Matcash-A and by Malwarebytes as Trojan.AgentNo
Microsoft© PID LexXPIDLex.exeDetected by Symantec as Backdoor.NiovadoorNo
Process Session ManagerXpidserv.exeDetected by Sophos as W32/Rbot-YNo
PiDunHKUPIDUNHK.EXEPart of the Prodigy Internet software - part of the dialer/DUN. Presumably needed for users of that service otherwise you may not be able to connect, although you may try creating your own shortcut and see what happensNo
Symantec PIF AlertEngUPIFSvc.exeSymantec LiveUpdate Notice ServiceNo
PigeonXpigeon.exeDetected by Malwarebytes as Trojan.Agent.PG. The file is located in %LocalAppData%\Microsoft\shahramNo
pigglettXpigglett.exeAdded by a variant of the SMALL.EP TROJAN!No
piiserviceOEUpiiserviceOE.exeSpam Inspector (nee Postal Inspector) from The Giant Company (before they were acquired by Microsoft) or iHateSpam from Sunbelt Software (before they were acquired by GFI Software) - spam filter add-ons for OENo
pijewiwejowoXpijewiwejowo.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
pijorlepehorXpijorlepehor.exeDetected by McAfee as RDN/Spybot.bfr!g and by Malwarebytes as Trojan.Agent.USNo
pikaXpika.exeDetected by Sophos as Troj/Swisyn-AINo
pikachuXpikachu.exeDetected by Dr.Web as Trojan.MulDrop3.2712 and by Malwarebytes as Trojan.AgentNo
gpmceXpikirrr.exeDetected by McAfee as RDN/Autorun.worm!cwNo
pilifXpilif.exeDetected by Symantec as W32.Fili.A@mmNo
VistENXpill.exeDetected by Dr.Web as Trojan.Inject1.30318 and by Malwarebytes as Trojan.Agent.ENo
Windows his LayerXpilotGame.exeDetected by Trend Micro as WORM_RBOT.GLXNo
Pim.exeXPim.exeDetected by Malwarebytes as Spyware.Agent.E. The file is located in %AppData%\Pim\FolderNo
Pim.exeXPim.exeDetected by Malwarebytes as Spyware.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
HKCUXping.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%No
pingXping.exeDetected by Sophos as Troj/Scar-AK. Note - do not confuse with the Microsoft utility of the same name as described hereNo
PoliciesXping.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%No
[3-4 random letters]Xping.exeDetected by Symantec as Adware.PurityScan - also see the archived version of Andrew Clover's page. Note - do not confuse with the Microsoft utility of the same name as described hereNo
HKLMXping.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%No
PingTimeout InstitutionXpingchek.exeDetected by Sophos as W32/Sdbot-VYNo
PingerNpinger.exePinger is the resident program for Toshiba updates. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notificationNo
ToshibaPingerNpinger.exePinger is the resident program for Toshiba Upgrades. Periodically checks to see if there are any software/driver upgrades for your particular computer model. If it finds any, it posts a notificationNo
firefoxXpingits.exeDetected by McAfee as Generic Downloader.il and by Malwarebytes as Trojan.BankerNo
processXpingkil.exeDetected by McAfee as Generic Downloader.il and by Malwarebytes as Trojan.BankerNo
PPPOEOXpingppac.exeDetected by Symantec as W32.Spybot.KHCNo
PinGuideXPinGuide.exeDetected by Microsoft as Adware:Win32/PinGuideNo
pingwab.exeXpingwab.exeDetected by McAfee as Generic Downloader.il and by Malwarebytes as Trojan.BankerNo
pingweb.exeXpingweb.exeDetected by McAfee as Generic Downloader.il and by Malwarebytes as Trojan.BankerNo
kissXpingy.exeDetected by Dr.Web as Trojan.DownLoader7.26272No
Pink CalendarUPinkCal.exePink Calendar & Day PlannerNo
MartiniXpinmart.exeAdded by a variant of W32/Sdbot.wormNo
PI NotifyNPINotify.exeProperty Intellect from Wild Rabbit Software Ltd - "is widely used in the residential lettings markets to help landlords, investors and managing agents deal with the day-to-day aspects of looking after property"No
PINotifyNPINotify.exeProperty Intellect from Wild Rabbit Software Ltd - "is widely used in the residential lettings markets to help landlords, investors and managing agents deal with the day-to-day aspects of looking after property"No
pinuohibsukpXpinuohibsukp.exeDetected by McAfee as RDN/Generic Dropper!vb and by Malwarebytes as Trojan.Agent.USNo
PioletNpiolet.exePiolet - peer-to-peer file sharing clientNo
CMKFIJXPiowlR.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
pipamyvaczoqXpipamyvaczoq.exeDetected by McAfee as Generic.tfr!cq and by Malwarebytes as Trojan.Agent.USNo
PIPE SYSTEMXpipe.exeDetected by Sophos as W32/Mytob-FFNo
directxXPipeCmd.exeDetected by Symantec as Backdoor.Sdbot.DNo
PIPUPIPInstaller_HIP_.exeDetected by Malwarebytes as PUP.Optional.Spigot. The file is located in %UserTemp%\ns[random].tmp. If bundled with another installer or not installed by choice then remove itNo
pipzonesippiXpipzonesippi.exeDetected by McAfee as RDN/Generic.dx!d2u and by Malwarebytes as Trojan.Agent.USNo
piqxyhibragpXpiqxyhibragp.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
000Upit.exePrivateEye surveillance software. Uninstall this software unless you put it there yourselfNo
Pittsburgh Penguins WeatherUPittsburgh Penguins Weather.exeWeather gadget included with the Pittsburgh Penguins theme for MyColors from Stardock CorporationNo
pivywytiqomzXpivywytiqomz.exeDetected by McAfee as Generic.grp and by Malwarebytes as Trojan.Agent.USNo
Pixel32XPixel32.exeDetected by Symantec as Trojan.GemaNo
Pixelpwr32XPixelpwr32.exeDetected by Symantec as Trojan.GemaNo
PixelsvrXPixelsvr.exeDetected by Symantec as Trojan.GemaNo
ewtsxqibXpixxevuh.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %LocalAppData%No
[various names]Xpizda.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
xxxXpi_server.exeDetected by Dr.Web as Trojan.DownLoader9.26692 and by Malwarebytes as Backdoor.Agent.XENo
PJAOQxanYhXPJAOQxanYh.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.ENo
pjedkfpnXpjedkfpn.datDetected by Malwarebytes as Trojan.Ransom.Gend. The file is located in %CommonAppData%No
pjpcslvmXpjpcslvm.exeDetected by Malwarebytes as Trojan.Banker. The file is located in %UserProfile%\pjpcslvmNo
pjsieqXpjsieq.exeDetected by Malwarebytes as Trojan.FakeAlert. The file is located in %UserProfile% - see hereNo
pjWebCam.exeUpjWebCam.exeWebcam automation software that saves regular photos from webcam and can also act as HTTP serverNo
Microsoft Update 2.5XPK1.exeDetected by McAfee as RDN/Generic Downloader.x and by Malwarebytes as Backdoor.BotNo
Microsoft Update 2.5XPK2.exeDetected by Sophos as Troj/Agent-ABLE and by Malwarebytes as Backdoor.BotNo
Perfect KeyboardUpk32.exePerfect Keyboard by Macro Toolworks - "allows users to create macros running in all Windows applications and fire them by keyboard shortcuts, hotkeys and auto-complete feature from within any application"No
Perfect Keyboard LITEUpk32.exePerfect Keyboard by Macro Toolworks - "allows users to create macros running in all Windows applications and fire them by keyboard shortcuts, hotkeys and auto-complete feature from within any application"No
Perfect Keyboard PROUpk32.exePerfect Keyboard by Macro Toolworks - "allows users to create macros running in all Windows applications and fire them by keyboard shortcuts, hotkeys and auto-complete feature from within any application"No
PKASTINGXpkast.exeDetected by McAfee as RDN/PWS-Banker!dk and by Malwarebytes as Trojan.Banker.ENo
PrintKey-ProUPKey_Pro.exePrintKey-Pro by WareCentral.com - "is a screen capture program that can capture the screen or any part of it with the press of the Print Screen key (or any other key you configure)"No
ADDITIONAL ServicesXpkgadd.exeAdded by a variant of W32.IRCBot. The file is located in %System%No
WV3E3W0UXE4W1H6JOEOJOSEIHJTGBGXpkgfurotmvn.exeDetected by McAfee as PWS-Zbot.gen.jt and by Malwarebytes as Trojan.SpyEyesNo
PK GuardXpkguard32.exeDetected by Symantec as W32.GuapimNo
Pagekeeper JobsUpkjobs.exePageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etcNo
Pagekeeper LiteUpkjobs.exePageKeeper Jobs is a separate PageKeeper program that handles the analysis of new documents and keeps track of the location and content of current documents in PageKeeper. Pagekeeper comes bundled with scanners such has HP, Microtek, etcNo
Phrozen Mon_KPXpkllagent.exeDetected by Malwarebytes as Keylogger.PKL. The file is located in %AppData%\PhrozenSoft\PKLLNo
microsoftXpkNdaBh.exeDetected by Malwarebytes as Trojan.Autoit. The file is located in %UserTemp%\microsoftNo
PKR PalNpkrpal.exePKR Pal utility from PKR - "helps keep your software updated so in future there will be no lengthy waits for new versions to install. Based on your selected options it will also let you know when your favourite tournaments are starting!"No
pkrpalNpkrpal.exePKR Pal utility from PKR - "helps keep your software updated so in future there will be no lengthy waits for new versions to install. Based on your selected options it will also let you know when your favourite tournaments are starting!"No
PK ServicesXpksvc.exeDetected by Sophos as W32/Forbot-BWNo
places.exeXplaces.exeDetected by Malwarebytes as Trojan.Agent.PL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PlantronicsBatteryStatus.exeUPlantronicsBatteryStatus.exePlantronics Battery Status Meter - battery charge level monitor for all the Plantronics wireless USB devices which sits in the System Tray. Part of the Plantronics Sopkes software which "enables remote call control with Plantronics headsets and the latest generation of UC and IP softphones. This means that users can answer and end calls remotely while away from their desks"No
PlantronicsURE.exeYPlantronicsURE.exePlantronics Unified Runtime Engine - required component for the Plantronics Sopkes software which "enables remote call control with Plantronics headsets and the latest generation of UC and IP softphones. This means that users can answer and end calls remotely while away from their desks"No
Platinum Hide IPUPlatinumHideIP.exePlatinum Hide IP - "keep your real IP address hidden, surf anonymously, secure all the protocols on your PC, provide full encryption of your activity while working in Internet, and much more"Yes
PosServiceNPLauncher.exePowerOffer - Italian service offering the latest deals on a number of different categories. Has a clearly defined privacy statementNo
Photo Loader residentNPlauto.exeWatcher for Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your picturesNo
Photo Loader supervisoryNPlauto.exeWatcher for Casio's Photo Loader software. Hook up your camera to the USB port, and it pops up and asks you if you want to load your picturesNo
PlaxoUpdateUPlaxoHelper_en.exePart of Plaxo contact management software which can "keep your address book updated, clean,and always available"No
PlaxoSysTrayUPlaxoSysTray.exeSystem Tray access to Plaxo contact management software which can "keep your address book updated, clean,and always available"No
PlayboyXplayavi.exeDetected by Symantec as Infostealer.GamanlockNo
NewmanXplayavi.exeDetected by Sophos as Troj/Lineage-ATNo
PnP DriverXplayboy.exeDetected by Sophos as W32/Forbot-FRNo
Windows Media CenterXPlayer Studio 3.2.exeDetected by McAfee as Generic Dropper and by Malwarebytes as Trojan.KBayi.FLA. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer. This one is located in %AppData%No
ttXplayer.exeDetected by Malwarebytes as Trojan.Agent.TGen. The file is located in %CommonAppData%No
PoliciesXPlayer.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.PGenNo
AdobeFlashUpdateManagerXPlayer.exeDetected by Dr.Web as Trojan.AVKill.31063 and by Malwarebytes as Trojan.Agent.AINo
winapXplayer.exeDetected by Dr.Web as Trojan.Click2.53629 and by Malwarebytes as Trojan.AgentNo
Flash PlayerXPlayer.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.FLPNo
MediaXPlayer.exeDetected by McAfee as RDN/Generic.bfr!fi and by Malwarebytes as Backdoor.Agent.DCENo
player32.exeXplayer32.exeDetected by Malwarebytes as Backdoor.Agent.WUGen. The file is located in %CommonAppData%\samsungNo
wimplayerXplayer32.exeDetected by McAfee as Generic.dx and by Malwarebytes as Trojan.Banker.WMPNo
wimplayerXplayer32.exeDetected by Malwarebytes as Trojan.Banker.A. The file is located in %CommonAppData%\MessengerPlusNo
Windows Media CenterXPlayers install maeker Inc.exeDetected by Dr.Web as Trojan.DownLoader10.46183 and by Malwarebytes as Trojan.KBayi.FLANo
Windows Media CenterXplayers install maker 5.1.exeDetected by Malwarebytes as Trojan.MSIL. The file is located in %Windir%No
PlayGemUPlayGem.exeDetected by Malwarebytes as PUP.Optional.PlayGem. The file is located in %ProgramFiles%\PlayGem. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
Play Now RadioUplaynowradio.exePlayNowRadio radio music streamer by Montiera Technologies LTD. Detected by Malwarebytes as PUP.Optional.PlayNowRadio. The file is located in %AppData%\playnowradio\playnowradio\[version]. If bundled with another installer or not installed by choice then remove itNo
playnowradioUplaynowradio.exePlayNowRadio radio music streamer by Montiera Technologies LTD. Detected by Malwarebytes as PUP.Optional.Montiera. The file is located in %AppData%\playnowradio\playnowradio\[version]. If bundled with another installer or not installed by choice then remove itNo
Playthru PlayerUPlaythruPlayer.exeDetected by Malwarebytes as PUP.Optional.PlayThruPlayer. The file is located in %ProgramFiles%\PlaythruPlayer. If bundled with another installer or not installed by choice then remove itNo
PlayVolcanoSAXPlayVolcanoSA.exeDetected by Malwarebytes as Adware.HotBar.CP. The file is located in %LocalAppData%\PlayVolcanoSA\bin\[version]No
Prolific_PLUtilUPLBkMon.exeProlific USB Flash Disk UtilityNo
TSE_PLUtilUPLBkMon.exeProlific USB 2.0 Flash Drive UtilityNo
Supports RAS ConnectionsXplcexmq.exeDetected by Sophos as Troj/Inject-AID and by Malwarebytes as Backdoor.IRCBotNo
winscplXpldmcx.exeDetected by Malwarebytes as Trojan.Downloader. The file is located in %System%No
UPS Online PLD Reminder UtilityNPLDReminder.exeOlder version of the UPS WorldShip utility used to create and manage your UPS shipmentsNo
UPS WorldShip PLD Reminder UtilityNPldReminder.exeOlder version of the UPS WorldShip utility used to create and manage your UPS shipmentsNo
PLEAPCPUCPLUpleapu.exeCPU Control Panel for the Powerleap CPU upgradeNo
msngerXpleasecrypt.exeDetected by McAfee as RDN/Generic.dx!cxx and by Malwarebytes as Backdoor.Messa.ENo
Plex Media ServerUPlex Media Server.exePlex Media Server by Plex - "is smart software that makes playing Movies, TV Shows and other media on your computer simple. It's been designed from the ground up to work automatically in your home network with a variety of devices - like an LG 2011 Netcast TV, Plex Client for Mac OS X, or numerous Mobile Devices like your iPhone, iPad or Android device"No
PlexToolsUPlexTool.exePlexTools utility for Plextor optical drives enhance the possibility to directly control specific functions of the drive and can be used for tasks such as Digital Audio Extraction (aka ripping of Audio CDs). Now superseded by PlexUTILITIESNo
PlexTools ProfessionalUPlexTool.exePlexTools utility for Plextor optical drives enhance the possibility to directly control specific functions of the drive and can be used for tasks such as Digital Audio Extraction (aka ripping of Audio CDs). Now superseded by PlexUTILITIESNo
loadXpleyere.exeDetected by Malwarebytes as Trojan.Agent.ADB. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "pleyere.exe" (which is located in %AppData%\Adobe)No
PLFSetI?PLFSetI.exeAppears to be related to the webcam on some Acer laptops and users disabling it don't notice anything unusual. Can anyone confirm What it does and if it's required?No
PLFSetL?PLFSetL.exeSonix chipset driver on some Acer and other laptops - possibly webcam related. Can anyone confirm What it does and if it's required?No
McAfee QuickClean ImonitorUPlguni.exePart of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection, Internet Security and AntiVirus Plus products primarily as a file cleaner/shredder and no longer supports program removalNo
PlguniUPlguni.exePart of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection, Internet Security and AntiVirus Plus products primarily as a file cleaner/shredder and no longer supports program removalNo
ImonitorUPlguni.exePart of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection, Internet Security and AntiVirus Plus products primarily as a file cleaner/shredder and no longer supports program removalNo
StartKeyXpligde.exeDetected by Symantec as Backdoor.Bifrose.E and by Malwarebytes as Backdoor.BotNo
PasteListerNplister.exePasteLister by Progency Software - clipboard extenderNo
plite731Xplite731.exePoplite A adwareNo
plmg.exeUplmg.exeParagon Last Minute Bidder - auction assistant softwareNo
PLNRNoteNPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event PlannerNo
Event Planner RemindersNPLNRNote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event PlannerNo
Event Planner Reminders Tray IconNPLNRnote.exePart of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event PlannerNo
PlookXplook.exeAffiliateTarget.com alias PLook adwareNo
ExploreXPLORE.EXEDetected by Sophos as W32/Forbot-PNo
PlotXPlot.exeDetected by Malwarebytes as Trojan.Agent.BH. The file is located in %UserTemp% - see hereNo
Windows Virus ControlXplou.exeDetected by Sophos as W32/Sdbot-ACZNo
DRam prosessorXplscd.exeDetected by Trend Micro as WORM_RBOT.CYA and by Malwarebytes as Backdoor.BotNo
Microsoft Visual StudioXplscdksxg.exeDetected by Sophos as W32/Rbot-AWVNo
icrosoft VisualXplscx.exeDetected by Sophos as W32/Rbot-AYONo
dstiosysXplsitctl.exeDetected by Sophos as Troj/Mailbot-BXNo
PLsS7.exeXPLsS7.exeDetected by Malwarebytes as Ransom.Crypren. The file is located in %System%No
PLsS7.exeXPLsS7.exeDetected by Malwarebytes as Ransom.Crypren. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Pluck TrayUPluckTray.exeRSS (XML TAGS) reader programNo
PluckSvrNPluckUpdater.exePluck Toolbar updaterNo
PlugginXPluggin.exeDetected by McAfee as RDN/Generic Dropper and by Malwarebytes as Backdoor.Agent.ENo
plugin ttXplugin tt.exeDetected by McAfee as RDN/Generic.tfr!du and by Malwarebytes as Trojan.Agent.MNRNo
Firefox PluginsXplugin-container.exeDetected by Sophos as Mal/MSIL-CXNo
Adobe Flash PlayerXplugin-container.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.IMNGenNo
plugin-container.exeXplugin-container.exeDetected by McAfee as RDN/Generic.hra and by Malwarebytes as Trojan.Agent.CMA. Note - the file is located in %AllUsersStartup% and its presence here ensures it runs when Windows startsNo
Adobe Updater Startup UtilityXplugin-container.exeDetected by McAfee as RDN/Generic BackDoor!zy and by Malwarebytes as Backdoor.Agent.ADBGenNo
Browser Software UpdaterXplugin-container.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Trojan.AgentNo
No Credit CardXplugin-[random].exeAdult content pop-up dialerNo
AVGXplugin.exeDetected by McAfee as RDN/Generic.bfr!fj and by Malwarebytes as Backdoor.Agent.ENo
MicrosoftXPlugin.exeDetected by Malwarebytes as Trojan.Agent.MSGen. The file is located in %System%\MicrosoftNo
WindowsXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.CSR. The file is located in %Root%\MicrosoftNo
mofenitorXplugin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\plugin - see hereNo
Win32XPlugin.eXeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Root%\directory\CyberGate\MicrosoftNo
Win32XPlugin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.PLG. The file is located in %System%\MicrosoftNo
HKCUXPlugin.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%No
Win32XPlugin.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Windir%\Cursors\CursoresNo
Win32XPlugin.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Windir%\Microsoft - see hereNo
Windows UpdatesXplugin.exeDetected by Malwarebytes as Trojan.Agent.WU. The file is located in %UserTemp%No
PoliciesXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\MicrosoftNo
PoliciesXplugin.exeDetected by McAfee as RDN/Generic.bfr!fj and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\ctfmonNo
PoliciesXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\Cursors\CursoresNo
PoliciesXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\installNo
Windows Live MessengerXplugin.exeDetected by Malwarebytes as Trojan.Agent.ADB. The file is located in %AppData%\MicrosoftNo
Java UpdaterXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Windir%\installNo
souregndXplugin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\plugin - see hereNo
Adobe ReaderXplugin.exeDetected by Malwarebytes as Backdoor.Agent.DCE. The file is located in %AppData% - see hereNo
Adobe ReaderXplugin.exeDetected by Malwarebytes as Trojan.Agent.MPL. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\Microsoft - see hereNo
Adobe ReaderXplugin.exeDetected by Malwarebytes as Trojan.Agent.MPL. Note - this entry loads from the HKCU\Run and HKCU\Policies\Explorer\Run keys and the file is located in %AppData%\Microsoft - see hereNo
Adobe ReaderXplugin.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %Temp%No
Windows WordXplugin.exeDetected by Dr.Web as Trojan.MulDrop2.39589 and by Malwarebytes as Backdoor.Agent.DCGenNo
SkypeXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.PLG. The file is located in %System%\MicrosoftNo
SkypeXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Windir%\installNo
SystemXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.CSR. The file is located in %Root%\MicrosoftNo
UPTADEXPlugin.exeDetected by McAfee as RDN/Generic Dropper!sp and by Malwarebytes as Backdoor.Agent.UPDNo
Dlls do WindowsXPlugin.exeDetected by Malwarebytes as Backdoor.Agent.CSR. The file is located in %Root%\MicrosoftNo
pluginXplugin.exeDetected by McAfee as RDN/Generic BackDoor!yt and by Malwarebytes as Backdoor.Agent.DCENo
MOVIDARXplugin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %System%\WindowsNo
Smiley DistrictXplugin.exeSmiley District adwareNo
AdobeXplugin.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
HKLMXPlugin.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%No
AppleUtilityXplugin.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCENo
CLSIDXplugin.exeFirstEnter - Switch dialer and hijacker variant, see hereNo
ShellXplugin.exe,explorer.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Hijack.ShellA.Gen. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "explorer.exe" (which is a legitimate file located in %Windir% and shouldn't be deleted) and "plugin.exe" (which is located in %AppData%)No
ShellXplugin.exeexplorer.exeDetected by Malwarebytes as Hijack.ShellA.Gen. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "plugin.exeexplorer.exe" (which should be located in %AppData% but does not exist as there should have been a "," between "ee" - see here)No
Windows Plugin OneXplugin01.exeDetected by McAfee as PWS-Banker!hcqNo
 Windows Plugin TwoXplugin02.exeDetected by McAfee as PWS-Banker!hcq and by Malwarebytes as Trojan.Banker. Note the space at the beginning of the "Startup Item" fieldNo
Windows Plugin ThreeXplugin03.exeDetected by McAfee as PWS-Banker!hcq and by Malwarebytes as Trojan.BankerNo
WinXPXplugin1.exeAdded by the Downloader-JW TROJAN!No
WinXPHomeXplugin2.exeDetected by Trend Micro as VBS_INOR.TNo
Plugin Live 64Xplugin64.exeDetected by McAfee as PWS-Banker!hcq and by Malwarebytes as Spyware.BankerNo
XURNMSXPluginIntro.exeDetected by McAfee as RDN/Generic Dropper!sp and by Malwarebytes as Backdoor.Agent.PLGenNo
SGOFRVXPluginIntro.exeDetected by McAfee as RDN/Generic Dropper!sn and by Malwarebytes as Backdoor.Agent.PLGenNo
RGGTXplugins.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %Windir%No
PoliciesXplugins.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%No
Adobe ReaderXplugins.exeDetected by Malwarebytes as Trojan.Agent.ADB. The file is located in %AppData%No
Adobe ReaderXplugins.exeDetected by Malwarebytes as Trojan.Agent.ADB. The file is located in %UserTemp%No
tyXplugins.exeDetected by Malwarebytes as Worm.Rebhip. The file is located in %Windir%No
tyrtXplugins.exeDetected by Malwarebytes as Worm.Rebhip. The file is located in %Windir%No
TRTHYXplugins.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %Windir%No
PluginSegXPluginSeg.exeDetected by Malwarebytes as Ransom.Banker.NCU. The file is located in %AppData%No
PluginSegXPluginSeg.exeDetected by Malwarebytes as Ransom.Banker.NCU. The file is located in %AppData%\CB300No
PlugIntroXPlugIntro.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes as Backdoor.Agent.ENo
pluginXXpluginX.exeDetected by Sophos as Troj/Dloadr-KNNo
plugin_containerXplugin_container.exeDetected by Malwarebytes as Backdoor.Bot.MSIL. Note - do not confuse with the legitimate Mozilla Firefox file "plugin-container.exe" (which is normally located in %ProgramFiles%\Mozilla Firefox). This file is located in %AppData%No
WebToolbar Plugin UpdaterXPlugin_helper.exeDetected by Malwarebytes as Trojan.Backdoor. The file is located in %AppData%\AdobeNo
plugsysXplugsys.exeDetected by Sophos as Troj/Agent-OVXNo
plugtXplugt.exeDetected by Malwarebytes as Trojan.Agent.E. The file is located in %Temp%\plugtNo
MicrosoftXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Root%\directory\Microsoft\MicrosoftNo
MicrosoftXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Temp%\Microsoft\MicrosoftNo
svchostXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Bot.ENo
win32XPluguin.exeDetected by Kaspersky as Trojan.Win32.Llac.acbv and by Malwarebytes as Backdoor.Agent.MPG. The file is located in %System%\MicrosoftNo
AvgntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\ExplorerNo
AvgntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\MicrosoftNo
AvgntXPluguin.exeDetected by Kaspersky as Trojan.Win32.Llac.xqx and by Malwarebytes as Backdoor.Agent. The file is located in %Root%\directory\Microsoft\Pluguin\MicrosoftNo
PoliciesXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\ExplorerNo
AvgntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Root%\Microsoft - see hereNo
PoliciesXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %ProgramFiles%\MicrosoftNo
AvgntXPluguin.exeDetected by McAfee as Generic.bfr and by Malwarebytes as Backdoor.Agent. The file is located in %System%\MicrosoftNo
PoliciesXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Root%\directory\Microsoft\MicrosoftNo
AvgntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %System%\MikrosoftNo
PoliciesXPluguin.exeDetected by Kaspersky as Trojan.Win32.Llac.xqx and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Root%\directory\Microsoft\Pluguin\MicrosoftNo
AvgntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %Windir%\Microsoft - see hereNo
PoliciesXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Root%\MicrosoftNo
AvgntXPluguin.exeDetected by McAfee as RDN/Generic.dx!bbs and by Malwarebytes as Backdoor.Agent. The file is located in %Windir%\WindowsNo
PoliciesXPluguin.exeDetected by Kaspersky as Trojan.Win32.Llac.acbv and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\MicrosoftNo
PoliciesXPluguin.exeDetected by McAfee as Generic.bfr and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\MicrosoftNo
PoliciesXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\MikrosoftNo
PoliciesXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Temp%\Microsoft\MicrosoftNo
PoliciesXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\Microsoft - see hereNo
PoliciesXPluguin.exeDetected by McAfee as RDN/Generic.dx!bbs and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\WindowsNo
Java UpdaterXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.MPGNo
Adobe ReaderXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.MPGNo
WIM32XPluguin.exeDetected by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Root%\directory\Microsoft\Pluguin\MicrosoftNo
AvirntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\ExplorerNo
AvirntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %ProgramFiles%\MicrosoftNo
AvirntXPluguin.exeDetected by Kaspersky as Trojan.Win32.Llac.xqx and by Malwarebytes as Backdoor.Agent. The file is located in %Root%\directory\Microsoft\Pluguin\MicrosoftNo
AvirntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Root%\Microsoft - see hereNo
AvirntXPluguin.exeDetected by McAfee as Generic.bfr and by Malwarebytes as Backdoor.Agent. The file is located in %System%\MicrosoftNo
AvirntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %System%\MikrosoftNo
AvirntXPluguin.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %Windir%\Microsoft - see hereNo
AvirntXPluguin.exeDetected by McAfee as RDN/Generic.dx!bbs and by Malwarebytes as Backdoor.Agent. The file is located in %Windir%\WindowsNo
cftmonXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.AgentNo
PluguinXPluguin.exeDetected by Malwarebytes as Backdoor.Agent.MPG. The file is located in %Root%\directory\Microsoft\MicrosoftNo
Skype UpdaterXPluguin.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.MPGNo
Microsoft Update 2.5XPluguinFaceBook#.exeDetected by Malwarebytes as Backdoor.Bot - where # represents a digit. The file is located in %Root%\ProgramData - see examples here and hereNo
WinInitXPluguinFaceBook.exeDetected by Malwarebytes as Trojan.Banker. The file is located in %Root%\ProgramDataNo
Plumbytes Anti-MalwareUplumbytes.exePlumbytes Anti-Malware. Detected by Malwarebytes as PUP.Optional.Plumbytes. The file is located in %ProgramFiles%\Plumbytes Software\Plumbytes Anti-Malware. If bundled with another installer or not installed by choice then remove itNo
Plus Internet?PlusInternetChecker.exePart of the Polish "Plus Internet" ISP service from Polkomtel. What does it do and is it required?No
btbb_McciTrayAppUPlusnetHelpNotifier.exeSystem tray access to the now discontinued Plusnet Assist package by Motive, which helps users troubleshoot and configure the service. Motive, Inc. were acquired by Alcatel-Lucent, who were subsequently acquired by NokiaNo
PlusServiceNPlusService.exeMessenger Plus! add-in for Windows Live Messenger from Yuna SoftwareNo
PlusTabXPlusTab.exeDetected by Trend Micro as TROJ_ADLOAD.SMNNo
plusupXplusup.exeDetected by Malwarebytes as Backdoor.Agent.DCGen. The file is located in %ProgramFiles%\plusup - see hereNo
PLXSTARTUPLXSTART.EXESets the spindown timeout and access speeds at startup and displays the "Plextor Manager 2000" splash screen for a Plextor CD-RW.No
PLXTASKNPLXTASK.EXETaskbar utility for a "control panel" for a Plextor CD-RW. Has MVP 2000 (audio CD player), DiscDupe 2000 (self-explanatory CD copying program) and AudioCapture 2000 (rips audio CDs into MP3 or WAV files)No
PowermarksUpm.exePowermarks from Kaylon Technologies - bookmark manager and personal search engineNo
Pm32infoXpm32info.exeDetected by Trend Micro as TROJ_CRYPTER.ANo
VeriFaceManagerYPManage.exeLenovo VeriFace™ face-recognition software that "controls access to your notebook by using your face as your logon password and recording the faces of others who try to log on or leave you a message"No
VeriFacePassManagerYPManage.exeLenovo VeriFace™ face-recognition software that "controls access to your notebook by using your face as your logon password and recording the faces of others who try to log on or leave you a message"No
Pando Media BoosterUPMB.exePando Media Booster from Pando Networks, Inc - "is a tiny (2MB) UI-less client that enables you to cost effectively stream full-screen HD video by leveraging your viewer's collective spare bandwidth"No
PMBVolumeWatcherUPMBVolumeWatcher.exePart of the Picture Motion Browser (PMB) software from Sony that comes with their Cyber-shot™ range of digital cameras. "An easy-to-use PC package that lets you find and organise your favourite images in moments. Email photos to a friend or upload and share them online in just a few clicks"No
Program Management Console StartupUpmc.exePart of the Program Management Console for products from CompuClever. Detected by Malwarebytes as PUP.Optional.CompuClever. The file is located in %LocalAppData%\CompuClever\Program Management Console. If bundled with another installer or not installed by choice then remove itNo
PMCS?PMC.Service.Main.exeRelated to MediaCenterService from Pinnacle Systems. What does it do and is it required?No
PMCLoader?PMCLoader.exePart of Pinnacle TVCenter Pro for watching and recording TV on a desktop/laptop from Pinnacle Systems. What does it do and is it required?No
pmcqtXpmcqt.exeDetected by Sophos as Troj/Dluca-VNo
pmH57hItrkQp.exeXpmH57hItrkQp.exeDetected by Malwarebytes as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PMHandler?PMHandler.exeRelated to IBM/Lenovo Thinkpad notebooks - possibly related to power management features? What does it do and is it required?No
EgisTec In-Product ServiceNPmmUpdate.exeSoftware updater for Biometrics Solutions and Data Security products from EgisTec IncYes
EgisTecPMMUpdateNPmmUpdate.exeSoftware updater for Biometrics Solutions and Data Security products from EgisTec IncYes
PmmUpdateNPmmUpdate.exeSoftware updater for Biometrics Solutions and Data Security products from EgisTec IncYes
pMNKUWCMUCXpMNKUWCMUC.exeDetected by Sophos as Mal/FakeAV-OPNo
PDF Maker Pilot printing agentUpmpagent.exeVirtual printer for PDF Maker Pilot by Two Pilots - which "is specially designed for making PDF documents and fillable PDF forms that can be filled out using free Adobe Reader"No
PDF Maker Pilot (demo) printing agentUpmpagentd.exeVirtual printer for PDF Maker Pilot by Two Pilots - which "is specially designed for making PDF documents and fillable PDF forms that can be filled out using free Adobe Reader." Demo versionNo
PMPro32Xpmpro32.exeSpyArsenal Print Monitor Pro spywareNo
PmProxy?PmProxy.exeAssociated with Analog Devices SoundMAX audio chipset - often built-in to motherboards. What does it do and is it required?No
pmrXpmr.exePowerStrip foistware. Note - this is not the same as the video tweaking utility of the same name hereNo
Event ReminderNPMremind.exeEvent reminder for calendar dates, etc from Broderbund PrintMaster. Disable using the program's own option (if available) or a startup manager as it will re-instate if disabled via MSConfigNo
PremierOpinionXpmropn.exePremierOpinion adware. Detected by Malwarebytes as Adware.PremierOpinion. The file is located in %ProgramFiles%\PremierOpinionNo
noneXpmsngr.exeDetected by ThreatTrack Security as Trojan-Downloader.Zlob.Media-Codec (fs) and by Malwarebytes as Trojan.Zlob. This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machineNo
pmsngr.exeXpmsngr.exeDetected by ThreatTrack Security as Trojan-Downloader.Zlob.Media-Codec (fs) and by Malwarebytes as Trojan.Zlob. This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machineNo
PMSpeed?PMSpeed.EXERelated to Presto! PageManager from NewSoft Technology Corporation - which "allows you see your entire file organization structure - from the overall picture to the smallest detail. You can create, write, and open PDF files without file conversion or other application"No
Disk Defragmentation LoaderXpmsvcr.exeDetected by Microsoft as Worm:Win32/Slenfbot.JGNo
PMTSHOOTNpmtshoot.exePmtshoot is a MS tool used to identify which device driver is preventing your PC from going into a suspended or standby modeNo
PlayMovieNPMVService.exePreloads movie related parts of CyberLink's PowerCinema digital home entertainment software to speed up the launch of that feature. Only required on slower/older systems and included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and othersYes
PMVServiceNPMVService.exePreloads movie related parts of CyberLink's PowerCinema digital home entertainment software to speed up the launch of that feature. Only required on slower/older systems and included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and othersYes
CyberLink PlayMovieNPMVService.exePreloads movie related parts of CyberLink's PowerCinema digital home entertainment software to speed up the launch of that feature. Only required on slower/older systemsYes
Scan Detector?Pmxdetect.exeAssociated with Visioneer PrimaScan scanners. Is it required?No
PMXInitUpmxinit.exeRestores user display preferences Kyro2 based graphics cards. Not required unless you change the default settings - such as gammaNo
pmyhouseXpmyhouse.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%No
jubvXpnafnog.exeDetected by Malwarebytes as Trojan.Agent.MSP. The file is located in %AppData%\Microsoft\PnafnogNo
trfhhiXpnafnog.exeDetected by Malwarebytes as Trojan.Agent.MSP. The file is located in %AppData%\Microsoft\PnafnogNo
hcxzuXpnafnog.exeDetected by Malwarebytes as Trojan.Downloader. The file is located in %AppData%\Microsoft\PnafnogNo
PNAgentNPNAgent.exePhatNoise Music Manager - manages WMA, MP3, WAV, etc music files & PhatNoise Media Manager - access, organize, transfer, and playback digital music and movie filesNo
Program Neighborhood AgentUpnagent.exeCitrix Program Neighborhood AgentNo
Microsoft PnDXpnd.exeDetected by Dr.Web as Trojan.DownLoader7.18330 and by Malwarebytes as Trojan.AgentNo
PalNetawareXpnetaware.exePalTalk adware (as included in Morpheus) - see hereNo
PalNetawareXPNETAW~1.EXEPalTalk adware (as included in Morpheus) - see hereNo
Vekio StartupsXPnksvc32.exeDetected by Trend Micro as WORM_AGOBOT.AJGNo
MSPRO32Xpnp.exeDetected by Trend Micro as WORM_ZOTOB.ONo
runUPNPCHK.EXEAztech Labs Sound 3 PnP driver. Note - this entry loads via "run" section of WIN.INI on operating systems prior to Windows NT and the file is located in %Windir%No
Smart Start UPNPnPDetect.exePart of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos"No
pnpdevicemonXpnpdevicemon.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%\PnPDeviceMonitor - see hereNo
PNP FIXXpnpfix.exeDetected by Trend Micro as WORM_RBOT.CBKNo
Windows PNP ServerXpnpsrv.exeDetected by Sophos as W32/Rbot-AKMNo
PNSetupUPNSetup.exePopNot - pop-up killerNo
wacultXPNsItbtSXt.exeDetected by Dr.Web as Trojan.DownLoader4.21422 and by Malwarebytes as Backdoor.Messa.GenNo
PNtask ServicesXpntask.exeDetected by Symantec as Backdoor.Lala.CNo
NexusServerUPNXSERVR.exeRelated to ProCoder from Grass Valley (was Canopus) - which "combines speed and flexibility into a streamlined video conversion tool. Widely acknowledged as the leading software transcoder, it features extensive input/output options, advanced filtering, batch processing, and an easy-to-use interface"No
StartnameXPO#35211410.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.STRNo
PktAnythingUPocketCompanion.exePocketAnything lets you save anything on your computer to your mobile, with one clickNo
Gaviri PocketSearchNPocketSearch.exeGaviri PocketSearch by Gaviri Technologies "is the search engine for all your mobile and desktop needs. Finding files, email, pictures, songs and other documents on any of the many devices, laptop or desktop you use is plug & play." No longer supportedNo
W32.Formalin.BetaXPocong.exeDetected by Symantec as W32.SillyFDC. The file is located in %System%No
POEngineNPOEngine.exe"PokerOffice is much more than just a poker odds calculator and poker software. It is the most sophisticated poker software tool on the market for Online Poker"No
PoetXPoet.exeDetected by Symantec as W32.Doep.ANo
pofbewarpeacXpofbewarpeac.exeDetected by Malwarebytes as Trojan.Intel.BRV. The file is located in %UserProfile% - see hereNo
pofemxoffofpXpofemxoffofp.exeDetected by Trend Micro as TROJ_CUTWAIL.YYS and by Malwarebytes as Trojan.Agent.USNo
HKCUXpograma.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%\winrarNo
PoliciesXpograma.exeDetected by Malwarebytes as Backdoor.Agent.PGen. The file is located in %System%\winrarNo
HKLMXpograma.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %System%\winrarNo
eEjerikXpohapereq.exeDetected by Trend Micro as WORM_SDBOT.BFFNo
Microsoft Security Monitor ProcessXpoint.exeDetected by Trend Micro as BKDR_IRCBOT.AVP and by Malwarebytes as Trojan.Downloader. The file is located in %Windir%No
Microsoft IntelliPointUpoint32.exeMicrosoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
point32Upoint32.exeMicrosoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
POINTERUpoint32.exeMicrosoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedNo
IntelliPointUpoint32.exeMicrosoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
pointbag_shop_svXpointbag_hidden.exePointbag browser modifierNo
pointmaniaXpointmania.exePointMania adware. File located in %Program Files%\pointmaniaNo
PointmaruXPointmaru.exeDetected by Kaspersky as Trojan-Downloader.Win32.Agent.bldk. The file is located in %ProgramFiles%\PointmaruNo
AltnetPointsManagerXpoints manager.exeTopSearch adwareNo
points managerXpoints manager.exeTopSearch adwareNo
demoXpoisonn.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %System%No
PoivYNPoivY.exePoivY - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
System service**Xpokapoka**.exeDetected by Symantec as Trojan.Elitebar - where ** represents the numbers 61 to 79No
Microsoft Windows DLL Services ConfigurationXpoker.exeDetected by Sophos as W32/Sdbot-ZY and by Malwarebytes as Trojan.MWF.GenNo
Microsoft Windows DLL Services ConfigurationXpoker3.exeDetected by Sophos as W32/Sdbot-AAH and by Malwarebytes as Trojan.MWF.GenNo
icrosoft Windows DLL Services ConfigurationXpoker3.exeDetected by Sophos as W32/Sdbot-AERNo
ShellXPokerStarsCardsViewer.exe,explorer.exeDetected by McAfee as RDN/Generic.bfr!hy and by Malwarebytes as Backdoor.Agent.PS. Note - this entry adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry. The value data points to "explorer.exe" (which is a legitimate file located in %Windir% and shouldn't be deleted) and "PokerStarsCardsViewer.exe" (which is located in %AppData%\PokerStarsCardsViewer)No
Pokilsde.vbeXPokilsde.vbeDetected by Malwarebytes as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
poklakefrybcXpoklakefrybc.exeDetected by McAfee as RDN/Generic BackDoor!sh and by Malwarebytes as Trojan.Agent.USNo
HKCUXPolicies.exeDetected by Kaspersky as Trojan.Win32.Llac.ehs and by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %Windir%\PoliciesNo
PoliciesXPolicies.exeDetected by McAfee as Generic.dx!bd3g and by Malwarebytes as Backdoor.Agent. The file is located in %AppData%No
PoliciesXPolicies.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes as Backdoor.Agent. The file is located in %AppData%\PoliciesNo
PoliciesXPolicies.exeDetected by Kaspersky as Trojan.Win32.Llac.ehs and by Malwarebytes as Backdoor.Agent.PGen. The file is located in %Windir%\PoliciesNo
runXPolicies.exeDetected by McAfee as Generic Downloader.x. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "run" value data to include the file "Policies.exe" (which is located in %AppData%\Policies)No
HKLMXPolicies.exeDetected by Kaspersky as Trojan.Win32.Llac.ehs and by Malwarebytes as Backdoor.HMCPol.Gen. The file is located in %Windir%\PoliciesNo
loadXPolicies.exeDetected by McAfee as Generic Downloader.x. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "Policies.exe" (which is located in %AppData%\Policies)No
Polaris Office SyncUPOLinkLauncher.exeSync utility for Polaris Office - "a drag-and-drop computer application that allows you to manage your documents efficiently. You can now easily access the documents from your computer on the website and mobile app"No
Steganos VPN Local ProxyUpolipo.exePart of the 2012 version of Steganos Internet Anonym VPN from Steganos Software GmbH - which, as a VPN client, provides Wi-Fi hotspot protection, anonymous web surfing, security from hackers and snoops and access to region blocked websites when travellingNo
PollonXpollone.exeDetected by Trend Micro as WORM_SPYBOT.FWNo
POlNTERXPOlNT32.EXEDetected by Sophos as Troj/XDEM-A. Note - this is not the valid Microsoft IntelliPoint mouse utility. Both the Name and Command entries have a lower case "L" in them rather than an upper case "i"No
polo.exeXpolo.exeDetected by Sophos as Troj/Agent-PENo
Win32 USB2 DriverXpomedsrv.exeDetected by Trend Micro as WORM_WOOTBOT.ZA and by Malwarebytes as Backdoor.BotNo
Spool32Xpool32.exeDetected by Sophos as Troj/Assasin-FNo
CoinXpooler.exeDetected by McAfee as RDN/Generic.dx!cxs and by Malwarebytes as Trojan.Agent.MNRNo
lemechiXpoolers.exeDetected by Malwarebytes as Trojan.Crypt. The file is located in %AppData%\Microsoft\Windows\Start Menu\Programs (10/8/7/Vista) or %UserProfile%\Start Menu\Programs\poolers.exe (XP) - see hereNo
Windows Pool SetupXpoolmc.exeDetected by Microsoft as Worm:Win32/Slenfbot.IVNo
Windows Pool ManagerXpoolsc.exeDetected by Trend Micro as WORM_OBOT.CH. The file is located in %System%No
poolsvXpoolsv.exeDetected by Kaspersky as Trojan-Downloader.Win32.VB.bhs. The file is located in %Windir%No
AARCXpoony.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %MyDocuments%\SYSNo
poony.exeXpoony.exeDetected by Malwarebytes as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PopXPop#.exeDetected by Malwarebytes as Backdoor.Bot.PP - where # represents a digit. The file is located in a sub-folder of %AppData%\Pop_AdsNo
Pop#.exeXPop#.exeDetected by Malwarebytes as Backdoor.Bot.PP - where # represents a digit. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Pop-Up ZeroUPop-Up Zero.exePop-Up Zero pop-up stopperNo
pop06apXpop06ap2.exeMediaMotor adwareNo
NOD32POP3YPop3scan.exePOP3 E-mail part of Eset's NOD32 antivirusNo
Pop3trap.exeYPop3trap.exePart of Trend Micro web-security products - PC-cillin 2000, 2002-2003 and Virus Buster 2001-2003. This is the E-mail scannerNo
PopComUPopCom.exeDetected by Malwarebytes as PUP.Optional.Installmatic. The file is located in %ProgramFiles%\PopCom. If bundled with another installer or not installed by choice then remove itNo
ControlPanelXpopcorn.exe internat.dll,LoadKeyboardProfileDetected by Sophos as Troj/Bizves-BNo
ControlPanelXpopcorn320.exe rundll.dll,LoadMouseProfileAdded by a variant of the DLOADER-RA TROJAN!No
ControlPanelXpopcorn64.exe rundll.dll,LoadMouseProfileDetected by Sophos as Troj/Dloader-OINo
ControlPanelXpopcorn72.exe rundll.dll,LoadMouseProfileDetected by Sophos as Troj/Dloader-RANo
PopcornewUpopcornew.exeDetected by Malwarebytes as PUP.Optional.Popcornew. The file is located in %ProgramFiles%\Popcornew\Popcornew. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PopDealsUPopDeals.exeDetected by Malwarebytes as PUP.Optional.PopDeals. The file is located in %ProgramFiles%\PopDeals. If bundled with another installer or not installed by choice then remove itNo
PopeSvrXPopeSvr.exeDetected by Sophos as Troj/LegMir-AJ and by Malwarebytes as Trojan.GamesThiefNo
Popup Ad FilterUPopFilter.exePopup Ad Filter - pop-up killerNo
Super Popup BlockerUpopkill.exeSaga Super Popup Blocker - pop-up stopperNo
plinkXPopLink.exeDetected by McAfee as Generic.tfr!bf and by Malwarebytes as Adware.KorAdNo
POP ManagerXpopmgr.exeDetected by Sophos as Troj/Bckdr-PYVNo
PoPMinerXPoPMiner.exeDetected by McAfee as RDN/Generic Downloader.x and by Malwarebytes as Trojan.Agent.MNRNo
PopNotUPopNot.exePopNot - pop-up killerNo
PopOopsUPopOops.exePopOops - pop-up killerNo
PopopenUpopopen.exePopOpen makes your windows spring open with animation effectsNo
POP PeeperUPOPPeeper.exePOP Peeper from Mortal Universe Software Entertainment "is an email notifier that runs in your Windows task bar and alerts you when you have new email on your POP3, IMAP, etc"No
PoproxyYPOPROXY.EXEProxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning itNo
Norton eMail ProtectYPOPROXY.EXEProxy E-mail protection from Norton Anti-Virus (prior to 2002). If you have it installed, leave it enabled to automatically check for suspect attachments in E-mails that may contain viruses. It downloads the E-mail into poproxy, which serves as a proxy server on the local machine, before scanning itNo
iPopXpopsi.exeDetected by McAfee as Generic Downloader.x!gmz and by Malwarebytes as Adware.KorAdNo
POPXPopSrv***.exePeopleonPage foistware, bundled with Grokster where *** are random digitsNo
POPXPopSrv146.exeAproposMedia/POP adware - also known as the PeopleOnPage browser enhancement. Detected by Microsoft as Trojan:Win32/AproposMedia. Also see the archived version of Andrew Clover's page. The file is located in %ProgramFiles%\POPNo
lgbrz32XPopStop32.exeDetected by Trend Micro as WORM_SPYBOT.HFTNo
PopSubtractUPopSub.exePopSubtract by InterMute - pop-up stopper. Trend Micro acquired InterMute in 2005 and this has now been discontinuedNo
pool managerXpopsvr.exeDetected by Sophos as Troj/Agent-SNo
PopTrayUPopTray.exePopTray - POP3 mail notifierNo
PopularXPopular.exeDetected by McAfee as RDN/Generic.bfr!ex and by Malwarebytes as Backdoor.Agent.GenNo
PopupEliminatorUPopup Eliminator.exePopupEliminator pop-up blocker from SurfSecret - no longer availableNo
PopUp DestroyUPopup-Destroy.exeFrench pop-up killer from VSoftNo
PopupXPopup.exeDetected by Malwarebytes as Rogue.TechSupportScam. The file is located in %ProgramFiles%\Pandaje Technical Services\Junk CleanerNo
PopupUPopup.exePop-up blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea SoftwareNo
Pop-Up-BlockerUpopup.exePop-up blocker part of the Tweak-XP optimization utility for Windows XP from Totalidea SoftwareNo
PopupAgentUPopupAgent.exeSpytech PopupAgent "kills and stops ad popups from annoying you and wasting your browsing time on the web"No
PopupBlockUPopupBlock.exePopupBlock pop-up blocker by planetscott.caNo
Popup Blocker SystemXPopUpBlocker.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
System Mechanic Popup BlockerUPopupBlocker.exePopup blocker part of an older version of iolo's System Mechanic or System Mechanic Professional utility suitesNo
Blocker System611 MonitoringXPopUpBlocker611.exeDetected by Trend Micro as WORM_RBOT.BLJNo
Popup Blocker System326a MonitoringXPopUpBlocker6a.exeDetected by Trend Micro as WORM_RBOT.AUHNo
Popup Blocker System8 MonitoringXPopUpBlocker8.exeAdded by a variant of W32/Sdbot.worm. The file is located in %System%No
PopUp Buster+Upopupbuster.exePopUp Buster - free Pop-up blockerNo
MasterBoot SwitchXpopupkill.exeDetected by Trend Micro as WORM_SDBOT.AYONo
Ultimate Popup KillerUPopupkiller.exeUltimate Popup Killer - pop-up killerNo
PopUpKillerUPopUpKiller.exePopUpKiller - pop-up killerNo
Ashampoo PopUpBlockerUPopUpKiller.exeAshampoo® Popup Blocker - part of a number or their products, including Magical Security and WinOptimizer Platinum 3No
Asmw Soft Popups BurnerUpopups burner.exePopup blocker, part of Asmw Soft PC OptimizerNo
Pop-Up_ScannerUPopupscn.exePanicware popup blockerNo
Pop-Up SmasherUPopupSmasher.exePop-Up Smasher - pop-up killerNo
System Mechanic Popup StopperUPopupstopper.exePopup stopper part of an older version of iolo's System Mechanic or System Mechanic Professional utility suitesNo
PopUpStopperProfessionalUPopUpStopperProfessional.exePanicware's Pop-Up Stopper - paid for versionNo
PopupVanishUPopupVanish.exePop-up blockerNo
PopUpWasherUPopUpWasher.exeWebroot PopUpWasher pop-up killer - now discontinuedNo
POPUPWATCHXPopUpWatch.exeBPS Spyware Remover rogue spyware remover - not recommended, removal instructions hereNo
Lenovo EE Boot OptimizerUPopWnd.exePart of Lenovo EE Boot Optimizer which speeds up the boot time for ThinkPad/IdeaPad notebooks and ThinkCentre/IdeaCentre desktops running Windows 7No
[various names]Xporka_.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
IE6Xporn.pifDetected by Sophos as W32/Rbot-ATFNo
TrojanShield ProtectorUPort.exeTrojanShield anti-hacker/anti-trojan softwareNo
Pure Networks Port MagicNPortAOL.exePure Networks Port Magic (as available with versions AOL® software) automatically configures most in-home Internet gateways, improving access and performance for applications such as instant messaging, online gaming, and streaming music and videoNo
portcrds.exeUportcrds.exeDetected by Malwarebytes as PUP.Optional.Chad. The file is located in %ProgramFiles%\WinPcaC. If bundled with another installer or not installed by choice then remove itNo
GW Port ControllerYPORTCT95.EXEFrom a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties, the file is known as "Smart Thru Fax Drive Spy" and is supplied by SamsungNo
postsosXpost.exeDetected by Sophos as W32/Taterf-Z and by Malwarebytes as Spyware.OnlineGamesNo
winsXPostalSecreto.exeDetected by Microsoft as Trojan:Win32/Sisron and by Malwarebytes as Trojan.Agent. The file is located in %Windir%No
wuaclt.exeXpostal_tarjeta.batDetected by McAfee as Generic.dx!balw and by Malwarebytes as Worm.AutoRun.ENo
LastwordXPosta_Update.exeDetected by ESET as Win32/LastwordNo
PostTipXPostTip.exeDetected by McAfee as Generic Downloader.xNo
jiungasXpot.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%\settingNo
poueuploadXpoueupload.exeDetected by Malwarebytes as Trojan.Injector.AI. The file is located in %AppData%No
GtermxXPouitnx.exeDetected by McAfee as RDN/Generic PWS.y!wa and by Malwarebytes as Trojan.KeyLogger.GenNo
POW!Upow.exePop-up killerNo
HKCUXpower excell.exeDetected by McAfee as RDN/Generic.bfr!hy and by Malwarebytes as Backdoor.HMCPol.GenNo
PoliciesXpower excell.exeDetected by McAfee as RDN/Generic.bfr!hy and by Malwarebytes as Backdoor.Agent.PGenNo
HKLMXpower excell.exeDetected by McAfee as RDN/Generic.bfr!hy and by Malwarebytes as Backdoor.HMCPol.GenNo
Power-Antivirus-2009XPower-Antivirus-2009.exePower Antivirus 2009 rogue security software - not recommended, removal instructions hereNo
winsXpower12.exeDetected by Dr.Web as Trojan.DownLoader11.19985 and by Malwarebytes as Trojan.Downloader.ENo
Power2Go ExpressNPower2GoExpress.exePower2GoExpress is the simple mode of the Power2GO all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconYes
Power2GoExpressNPower2GoExpress.exePower2GoExpress is the simple mode of the Power2GO all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconYes
Power2Go Desktop Burning GadgetNPower2GoExpress10.exePower2GoExpress is the simple mode of the Pwoer2Go all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconYes
Power2GoExpress10NPower2GoExpress10.exePower2GoExpress is the simple mode of the Pwoer2Go all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconYes
Power2GoExpress8NPower2GoExpress8.exePower2GoExpress is the simple mode of the Pwoer2Go all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconNo
Power2GoExpress9NPower2GoExpress9.exePower2GoExpress is the simple mode of the Pwoer2Go all-media disc burning software from Cyberlink. In this mode you can drag files to a series of desktop icons and right-click on the appropriate icon to burn a disc or simply erase a disc via the System Tray iconNo
PowerBarNPowerbar.exePart of Cyberlink's PowerDVD software. Not sure what exactly it does, but not required in startupNo
Microsoft CorporationXpowercfg.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData%\Microsoft\ProtectNo
[various names]Xpowerdll.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
PowerDVDNPowerDVD.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD12AgentNPowerDVD12Agent.exeRuns version 12 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVD12DMREngineNPowerDVD12DMREngine.exeRuns version 12 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVD13AgentNPowerDVD13Agent.exeRuns version 13 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVD14AgentNPowerDVD14Agent.exeRuns version 14 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVD 15NPowerDVD15Agent.exeRuns version 15 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD15AgentNPowerDVD15Agent.exeRuns version 15 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
CyberLink PowerDVD 15NPowerDVD15Agent.exeRuns version 15 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD16AgentNPowerDVD16Agent.exeRuns version 16 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVD17AgentNPowerDVD17Agent.exeRuns version 17 of CyberLink's PowerDVD Blu-ray, 3D & HD media player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyNo
PowerDVDNPowerDVD8.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD8NPowerDVD8.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVDNPowerDVD9.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
PowerDVD9NPowerDVD9.exeRuns CyberLink's PowerDVD Blu-ray and DVD player at startup. If enabled, PowerDVD will automatically play a disc when inserted. Launch manuallyYes
Power DVD PlayerXPowerDVDPlayer.exe hmwDetected by Sophos as Troj/Zbot-OB. The file is located in %ProgramFiles%\Power DVD PlayerNo
PowerForPhoneUPowerForPhone.exe"ASUS Power 4 Phone is a telephone terminal emulation utility which can use hotkeys to handle a phone call from Skype or Modem in your notebook system." For more information you can find a user's manual hereNo
PowerGramoNPowerGramo.exe"PowerGramo Skype recorder is a perfect Skype recording solution. With it you can easily record skype calls of any kind"No
PowerKeyUPowerKey.exePart of Acer Launch Manager - programmable keys on such laptops as the TravelMate 610No
AcerPowerkeyUPowerkey.exePowerKey utility for Acer TravelMate notebook PCs. Allows the user to quickly switch between different power schemes by pressing Fn+F3No
PowerMenuUPowerMenu.exePowerMenu which adds Always On Top, Transparency and Minimize To Tray optionsNo
poweroffXpoweroffuc.exeDetected by Malwarebytes as Adware.KorAd. The file is located in %ProgramFiles%\poweroffNo
SkyXpoweroftelepo.exeDetected by Malwarebytes as Trojan.MSIL.Agent. The file is located in %UserTemp%No
PowerPointViewXPowerPointView.exeDetected by McAfee as RDN/PWS-Banker and by Malwarebytes as Trojan.BankerNo
PowerProUpowerpro.exePart of the power professional program that loads the floating menu bar. Can be accessed from Start → Programs, but I'd leave it alone if you use this programNo
PowerProfXPowerProf.exeAdded by the LOREX.B TROJAN!No
setosimage?PowerRecover.exePart of PowerRecover protection and recovery software from CyberLink. What does it do and is it required?No
PowerReg Scheduler V3NPowerReg Scheduler V3.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst othersYes
PowerReg Scheduler V3.exeNPowerReg Scheduler V3.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst othersYes
PowerReg Scheduler.exeNPowerReg Scheduler.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst othersNo
PowerReg SchedulerV2.exeNPowerReg SchedulerV2.exePowerREGISTER from Leadertech. Registration reminder as used by Iomega, Hasbro & Microprose - amongst othersNo
POWERR~1.EXE?POWERR~1.exePower monitoring? The file is located in %UserStartup%No
PowerS?PowerS.exeProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?No
Power ScanXpowerscan.exeFoistware by Integrated Search Technologies - the people behind ISTBar adwareNo
powersearchXpowersearch.exeDetected by Malwarebytes as Adware.KorAd. The file is located in %AppData%\powersearch - see hereNo
Matrox PowerSpaceUPowerSpace.exeMatrox PowerSpace virtual desktop management software - "enables users to customize their Windows desktop workspace and alleviates the need to minimize and maximize windows when working with multiple applications simultaneously"No
Uniblue PowerSuiteUPowerSuite.exeOlder version of the PowerSuite system optimization suite from Uniblue Systems Limited - which incorporated RegistryBooster, SpeedUpMyPC and DriverScannerNo
Powersuite MonitorUpowersuite_monitor.exeOlder version of the PowerSuite system optimization suite from Uniblue Systems Limited - which incorporated RegistryBooster, SpeedUpMyPC and DriverScannerNo
powertimeXpowertime_uc.exeDetected by Malwarebytes as Trojan.Backdoor. The file is located in %ProgramFiles%\powertimeNo
PowerPcXpowerup.exePowerPc rogue security software - not recommended, removal instructions hereNo
powervaccinestart.exeXpowervaccinestart.exePowerVaccine rogue security software - not recommended, removal instructions hereNo
PowerPanelYPOWPANEL.EXEPower management utility on notebooks/laptops - automatically switches modes when running on batteryNo
ChromeUpdateXpowrper.exeDetected by Dr.Web as Trojan.DownLoader6.41884 and by Malwarebytes as Backdoor.AgentNo
Win32.PozarevacXPozarevac.exeDetected by Sophos as Troj/Delf-FBNNo
ppXpp12.exeDetected by Sophos as Troj/DwnLdr-HXV and by Malwarebytes as Worm.KoobFaceNo
ppXpp2.exeDetected by McAfee as W32/Koobface.worm.gen.eNo
PPActiveDetectionYPPActiveDetection.exeReal-time protection for eTrust PestPatrol Anti-Spyware - which became CA Anti-Spyware and is now included in CA AntiVirus PlusYes
eTrust PestPatrolYPPActiveDetection.exeReal-time protection for eTrust PestPatrol Anti-Spyware - which became CA Anti-Spyware and is now included in CA AntiVirus PlusYes
eTrust PestPatrol Active ProtectionUPPActiveDetection.exeReal-time protection for eTrust PestPatrol Anti-Spyware - which became CA Anti-Spyware and is now included in CA AntiVirus PlusNo
eTrustPPAPYPPActiveDetection.exeReal-time protection for eTrust PestPatrol Anti-Spyware - which became CA Anti-Spyware and is now included in CA AntiVirus PlusYes
PPAPNPPAP.exePart of PPLive from SynaCast - "the largest online video interactive entertainment media platform worldwide with the highest number of users and widest coverage serving Chinese communities"No
PPass.exeUPPass.exeDetected by Malwarebytes as PUP.Optional.PPass. Note - this entry loads from the Windows Startup folder and the file is located in %LocalAppData%\PPass. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
ppbeuserUppbeuser.exeCyberPower PowerPanel Business Edition - user interface for controlling and monitoring CyberPower UPS systemsNo
PPC-softwareUPPC-software.exeDetected by Malwarebytes as PUP.Optional.ProCleaningSoftware. The file is located in %ProgramFiles%\PPC-software. If bundled with another installer or not installed by choice then remove itNo
ppcXppcagent.exeDetected by Malwarebytes as Adware.KorAd. The file is located in %AppData%\PangPangClean - see hereNo
PPClean RunOnce insertion?ppclean.exeRelated to the installation of Yahoo! Anti-Spy for ToolbarNo
Bart StationUPPCOLink.exeDialer for PeoplePC ISPNo
PestPatrol Control CenterYPPControl.exePestPatrol Control Terminal - core program with System Tray access that launches PestPatrol features such as PPMemCheck and CookiePatrol. Part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
PPControlYPPControl.exePestPatrol Control Terminal - core program with System Tray access that launches PestPatrol features such as PPMemCheck and CookiePatrol. Part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
jaoyXPPCoP.exeDetected by Malwarebytes as Trojan.MSIL. The file is located in %AppData%No
PPCRunonceUPPCRunOnce.exeRelated to PeoplePC ISP software - may display advertising, see hereNo
ppcupXppcup.exeDetected by Dr.Web as Trojan.DownLoader10.20624 and by Malwarebytes as Adware.KorAdNo
PCLEPCIUppe.exePCI Performance Enhancer tool for PCI cards included with some Pinnacle Systems products - "helps to increase the PCI Busmaster performance of all Pinnacle PCI boards"No
PP GammaUppgamma.exeProfile Prism software that allows monitor calibration and can generate ICC profiles for digital camerasNo
PPHIDPADUpphidpad.exePenPower Chinese handwriting recognition softwareNo
Protector Plus InstaUpdateYPPInupdt.exeProland Protector Plus anti-virus software - instant updatesNo
PP2000 InstaupdateYPPInupdt.exeProland Protector Plus anti-virus software - instant updatesNo
agentXppl.exeDetected by Sophos as W32/Dref-U and by Malwarebytes as Email.WormNo
PPLiveNPPLive.exePPLive from SynaCast - "the largest online video interactive entertainment media platform worldwide with the highest number of users and widest coverage serving Chinese communities"No
ppmateNppmate.exePPMate - free tool for streaming online TV via P2P (peer-to-peer)No
PPMemCheckYPPMemCheck.exeReal-time spyware installation blocker - part of the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusYes
Windows Audio ControlXppnsvc.exeDetected by Sophos as Troj/DwnLdr-HAMNo
PowerPanel Personal Edition User InteractionUpppeuser.exeCyberPower PowerPanel Personal Edition - user interface for controlling and monitoring CyberPower UPS systemsNo
SoftickPPPUPPPGate.exeSoftick PPP is a Microsoft Windows driver that allows to establish PPP session between Palm powered devices and Microsoft Windows desktop computerNo
System_MessagesUpprsen.exeTerminatorX - "offers an easy and effective method of stopping users running predetermined file sharing programs like KaZaA, messenger programs, chat rooms and the like"No
ppr_killXppr_kill.exeDetected by Dr.Web as Trojan.Siggen6.16526 and by Malwarebytes as Trojan.Agent.PRNo
apphideUpps.exeDetected by Malwarebytes as PUP.Optional.AppHide. The file is located in %ProgramFiles%\baidu. If bundled with another installer or not installed by choice then remove itNo
PPS AcceleratorNppsap.exePPStream from PPStream, Inc - peer-to-peer (P2P) television service. As PPStream is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsNo
PPScheduler?PPScheduler.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". What does it do and is it required?No
Perfect Process shieldYppshield.exePerfect Process by VelociWare - "the easiest way of protecting and defending against Spyware in your network"No
bin32hpuXppstub.exePrecisionPop adwareNo
PPSYSUppsys.exePC Police commercial keystroke logger. Uninstall this software if you did not install it yourselfNo
apphideUppt.exeDetected by Malwarebytes as PUP.Optional.ChinAd. The file is located in %ProgramFiles%\ppt. If bundled with another installer or not installed by choice then remove itNo
Protector Plus Taskbar ControlYPPTbc.EXEProland Protector Plus anti-virus software - system tray accessNo
PP2000 Taskbar ControlYPPTbc.exeProland Protector Plus anti-virus software - system tray accessNo
PaperPortNpptd40nt.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". This is the virtual printer driver which enables the "Print to the PaperPort Desktop" feature of the PaperPort DesktopYes
PaperPort Print to Desktop for NTNpptd40nt.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". This is the virtual printer driver which enables the "Print to the PaperPort Desktop" feature of the PaperPort DesktopYes
PaperPort PTDNpptd40nt.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". This is the virtual printer driver which enables the "Print to the PaperPort Desktop" feature of the PaperPort DesktopYes
pptd40ntNpptd40nt.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". This is the virtual printer driver which enables the "Print to the PaperPort Desktop" feature of the PaperPort DesktopYes
PPUpdateUppupdater.exeAutomatic updates for the original anti-malware program by PestPatrol, Inc. Acquired by CA where it became eTrust PestPatrol Anti-Spyware and then CA Anti-Spyware - which is now included in CA AntiVirus PlusNo
PP2000 Real Time ScanYPPVstop.exeProland Protector Plus anti-virus software - real time scannerNo
PPWebCapNPPWebCap.exeAllows you to capture the visible portion of a webpage direct to Scansoft PaperPort (now by Nuance)No
W4TEEYTMPVDHS4M769HDJCV9HXPPX.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.DCGenNo
pq5kk4ujjj.exeXpq5kk4ujjj.exeDetected by Sophos as Troj/Tibia-N and by Malwarebytes as Trojan.Delf. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
pqhelperXpqhelper.exeSearchcentrix hijackerNo
PowerQuest Startup UtilityNPQINIT.EXEFrom a visitor - "This seems to be installed when you install Power Quest Partition Magic. I think that it implements the changes when you use the magic mover app. If you don't have any mappings set up, it does nothing (except waste bytes and cycles). I disabled it using msconfig.exe with no problems"No
12CFG515-K641-55SF-N66PXpqlmq.exeDetected by Microsoft as Trojan:Win32/Lethic.C and by Malwarebytes as Worm.AutoRun.GenNo
Google Update HelperXpqtsu.exeDetected by Malwarebytes as Backdoor.Agent.E. The file is located in %LocalAppData%\Google Update HelperNo
PqwickUPQwick.exeDetected by Malwarebytes as PUP.Optional.PQwick. The file is located in %ProgramFiles%\PQwick[version]. If bundled with another installer or not installed by choice then remove itNo
startXPR 2.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Backdoor.Agent.ENo
NETWORK SERVICEXpr.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Messa.E.No
Microsoft Svchost local servicesXpr1nc.exeDetected by Sophos as W32/Rbot-GWW and by Malwarebytes as Backdoor.IRCBotNo
PraetorianNpraetorian.exeRelated to updates for the Yandex Russian search engineNo
PrcgdXPrcgd.exeDetected by Sophos as W32/Autorun-BCJNo
[various names]XPrcIdle.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
[various names]Xprcmon.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Task ManagerXprcview.exeDetected by Sophos as W32/Agobot-RT. Note - this is not the legitimate PrcView process viewer (also bundled with versions of Symantec's Norton Utilities)No
PrcViewNPrcView.exePrcView from Computer Technology, Inc - "is a process viewer utility that displays detailed information about processes running under Windows. Freeware and also bundled with versions of Symantec's Norton Utilities (either as a standalone product or as part of Norton SystemWorks)Yes
PrdMgr.exeXPrdMgr.exeDetected by Trend Micro as WORM_SPYBOT.DAVNo
prdtectXprdtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
ReproPRDUPrdUsb.exeThrustmaster game controller driver, necessary for certain functions to workNo
PreAnnotate?PreAnntt.exeGenius Wizard Pen Tablet driver related. Is it required?No
Precision Time Clock CheckerXPrecisionTime.exePrecisionTime - clock synchronizing software. Contains GAIN adware by Claria CorporationNo
PrecisionTimeXPrecisionTime.exePrecisionTime - clock synchronizing software. Contains GAIN adware by Claria CorporationNo
MicrosoftXprefcgnet.vbsDetected by Dr.Web as Trojan.Siggen3.37225 and by Malwarebytes as Trojan.Agent.MSGenNo
Microsoft_IscXprefcgnet.vbsDetected by Dr.Web as Trojan.Siggen3.37225 and by Malwarebytes as Backdoor.AgentNo
[various names]XPreliminary.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Keyboard Preload CheckYPreload.exeMulti-function keyboard driverNo
PreloadYPreload.exeMulti-function keyboard driverNo
Norton AV Preload?Premend.exePart of an older version of Norton Antivirus. Is it required?No
premiumad.exeXpremiumad.exeDetected by Dr.Web as Trojan.DownLoad3.16130 and by Malwarebytes as Adware.KorAdNo
MagicKeyboardUPreMKBD.exeProgrammable key manager for Samsung laptops. Required if you use the additional keysNo
4StoryPrePatchUPrePatch.exePrePatch downloader for the 4Story MMORPG from Zemi InteractiveNo
GBTUpdNprerun.exeGIGABYTE Update Manager - used to manage all installed Gigabyte programs on a user's PC and check for and update any new versions of the software if availableNo
PreRunUprerun.exePart of GIGABYTE APP Center - which "gives you easy access to a wealth of GIGABYTE apps that help you get the most from your GIGABYTE motherboard. Using a simple, unified user interface, GIGABYTE APP Center allows you to easily launch all GIGABYTE apps installed on your system, check related updates online, and download the latest apps, drivers, and BIOS"No
Windows UDP Control CenterXPresends0.exeDetected by Sophos as Mal/VBPit-A and by Malwarebytes as Backdoor.BotNo
statusXpresentDetected by Sophos as W32/AHKHeap-ANo
Presentation64XPresentation64.exeDetected by McAfee as RDN/Generic Downloader.x and by Malwarebytes as Trojan.Downloader.PRSNo
HP Presentation ReadyNPresRdy.exeHP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"No
Startup NameXpress.exeDetected by McAfee as RDN/Generic Dropper and by Malwarebytes as Backdoor.Agent.ENo
Prestigioms.exeXPrestigioms.exeDetected by McAfee as RDN/Generic PWS.y!b2m and by Malwarebytes as Trojan.Agent.VRNo
PrestoNotesNPrestoNotes.exe"PrestoNotes is a freeware tool for Windows that lets you write little memos and stick them on your screen"No
Presto TuneUpXPrestoTuneUp.exePresto TuneUp rogue optimization utility - not recommended, removal instructions hereNo
UninstallHLXPreUninstallHL.exeDetected by SUPERAntiSpyware as Trojan.PreUninstallHL/32.ProcessNo
UninstallQLXPreUninstallQL.exeDetected by SUPERAntiSpyware as Trojan.Logger.ProcessNo
Preview AdServiceXPrevAdServ.exePreview AdService adware - removal instructions hereNo
Panda Preventium+ ServiceYPREVSRV.EXEPart of an older version of the Panda Security range of internet security products. Runs as a service on Windows XPNo
PrevXXprevx.exeDetected by Sophos as W32/IRCBot-TF. Note - file is located in the %System% and is not the PrevX (now Webroot) behaviour-based anti-malware softwareNo
Paypal ReceiptXPRG.exeDetected by Dr.Web as Trojan.Siggen6.19984 and by Malwarebytes as Backdoor.Agent.ENo
[various names]Xprgsys0984.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
prgtectXprgtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
Le Petit Robert HyperappelUprhyper.exeAllows you to select a word or phrase within a document, application, web-page, etc and search for it within an older version of the "Le Petit Robert" French dictionary from Le Robert. See here for more informationNo
Pribi.exeXPribi.exeFastFind.B adwareNo
\Pribi.exeXPribi.exeFastFind adware variantNo
pricefountainw.exeUpricefountainw.exe"PriceFountain is a dynamic online tool that automatically offers you relevant deals according to your online searches in real time". Detected by Malwarebytes as PUP.Optional.PriceFountain. The file is located in %LocalAppData%\PriceFountain. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
Price-HorseUpricehorse.exePrice-Horse - "Enjoy hassle-free and more budget-friendly online shopping using the Price-Horse tool. Save more cash and time as it brings you all the best deals, coupons, discounts, and item prices." Detected by Malwarebytes as PUP.Optional.PriceHorse. The file is located in %LocalAppData%\pricehorse\pricehorse\[version]. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PriceLessInstallerUPriceLessInstaller.exeDetected by Malwarebytes as PUP.Optional.PriceLess. Note - this entry loads from the Windows Startup folder and the file is located in %CommonAppData%\{GUID}. If bundled with another installer or not installed by choice then remove itNo
PriceMeterWUpricemeterw.exe"PriceMeter helps you save money (and time!) by bringing the lowest prices and the best deals directly to you while you're browsing and shopping online!" Detected by Malwarebytes as PUP.Optional.PriceMeter. The file is located in %LocalAppData%\PriceMeter. If bundled with another installer or not installed by choice then remove itNo
PricePeepUpdaterUPricePeepUpdater.exeUpdater for PricePeep - which "automatically searches across thousands of online stores to find the most up-to-date information and prices". Detected by Malwarebytes as PUP.Optional.PricePeep. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\PricePeep. If bundled with another installer or not installed by choice then remove itNo
pridlXpridl.exeDetected by Malwarebytes as Trojan.Downloader. The file is located in %AppData%\pridlNo
primead.exeXprimead.exeDetected by Dr.Web as Trojan.DownLoader7.16410 and by Malwarebytes as Trojan.KoradNo
Prime_UpdaterUPrime_Updater.exeDetected by Malwarebytes as PUP.Optional.PrimeUpdater. The file is located in %ProgramFiles%\Prime_Updater. If bundled with another installer or not installed by choice then remove itNo
Microsoft Security Monitor ProcessXprinc.exeDetected by Kaspersky as Net-Worm.Win32.Kolabc.adv and by Malwarebytes as Trojan.Downloader. The file is located in %Windir%No
PrintDispYPrintDisp.exeVirtual printer installed with ALL2PDF PDF Creator and Document Converter file conversion utilities from ActMask Co.,Ltd. Also licensed by a number of 3rd parties. As other applications potentially depend upon this leave it enabledYes
printerXprinter.exeDetected by Sophos as Troj/Agent-HNVNo
WinXPServiceXprinter.exeDetected by Sophos as Troj/Mdrop-BYD and by Malwarebytes as Backdoor.BotNo
TernateXprinter.sysDetected by Dr.Web as Trojan.MulDrop4.55547 and by Malwarebytes as Trojan.Agent.ENo
PrinterProDesktopUPrinterProDesktop.exePrinter Pro Desktop by Readdle Inc. "allows users to print to any printer connected to your Mac/PC using Printer Pro app. We also advise to use Printer Pro Desktop in case the network printer is not compatible with Printer Pro application installed on the iPad/iPhone/iPod Touch"No
Printkey2000NPrintkey2000.exeScreen grabber that intercepts the pressing of the Print Screen (Prn Scrn) key. Start manually when requiredNo
Print this now!Nprintnow.exeUtility that allows "Print Screen" or "Alt+Print Screen" screenshots to be sent directly to a printer. Note - this entry loads from HKLM\Run and the file is located in %Root%\PrintNow or %ProgramFiles%\PrintNow. Maybe related to PrintNow from PC Magazine (no longer available)No
PrintNowNPrintNow.exeVCS PrintNow from Vanguard Appraisals, Inc. - "When you have an error message, this handy utility allows you to email, or print the screen." Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\Vanguard Appraisals\PrintNowNo
PrintNowNprintnow.exeUtility that allows "Print Screen" or "Alt+Print Screen" screenshots to be sent directly to a printer. Note - this entry loads from the Windows Startup folder and the file is located in %Root%\PrintNow or %ProgramFiles%\PrintNow. Maybe related to PrintNow from PC Magazine (no longer available)No
printnow.exeNprintnow.exeUtility that allows "Print Screen" or "Alt+Print Screen" screenshots to be sent directly to a printer. Note - the file is located in %AllUsersStartup% and its presence there ensures it runs when Windows starts. Maybe related to PrintNow from PC Magazine (no longer available)No
CompaqPrinTrayNprintray.exeCompaq printer icon in the System Tray for quick access. Not required - uncheck via the printer's configuration optionsNo
LexmarkPrinTrayNprintray.exeLexmark printer icon in the System Tray for quick access. Not required - uncheck via the printer's configuration optionsNo
PrinTrayNPrintray.exePrinter icon in the System Tray for quick access. Not required - uncheck via the printer's configuration optionsNo
WinSysQQXprints.exeDetected by McAfee as RDN/BackDoor-AWQ.b and by Malwarebytes as Trojan.Agent.WSNo
Gadwin PrintScreenNPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current windowNo
Gadwin PrintScreen 2.6NPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current windowNo
Gadwin PrintScreen 3.1NPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current windowNo
Gadwin PrintScreen 3.5NPrintScreen.exeGadwin PrintScreen - utility to capture, print or save the current windowNo
Gadwin PrintScreen ProNPrintScreenPro.exeGadwin PrintScreen - utility to capture, print or save the current windowNo
PrintUtilNPrintUtil.exeHP Print Utility - a troubleshooting utility for HP printers and all-in-onesNo
winXPrintWindows.exeDetected by McAfee as RDN/FakeAV-M.bfr and by Malwarebytes as Trojan.Agent.PWNo
PRISMSTAUPRISMSTA.EXESystem Tray access to wireless settings for cards based upon PRISM chipsets by Connexant (previously by Intersil) - including products from D-Link, Cisco Linksys and GemtekNo
PRISMSTA.EXEUPRISMSTA.EXESystem Tray access to wireless settings for cards based upon PRISM chipsets by Connexant (previously by Intersil) - including products from D-Link, Cisco Linksys and GemtekNo
PRISMSVRUPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB AdapterNo
PRISMSVR.EXEUPRISMSVR.EXEConfiguration and settings utility for PRISM chipset based wireless modems such as the 2Wire Wireless Gateway (2701HG) and Siemens Gigaset USB AdapterNo
ControlPanelXpriva.exe internat.dll,LoadMouseCarpetProfileDetected by Sophos as Troj/Clicker-AZNo
Privacy ProtectorXPrivacy Protector.exePrivacyProtector rogue privacy tool - not recommended, removal instructions hereNo
Privacy WatcherXPrivacy Watcher.exePrivacy Watcher rogue privacy program - not recommended, removal instructions hereNo
Privacy ProtectionXprivacy.exePrivacy Protection rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrvacyProtectNo
PrivacyAlphaXPrivacyAlpha.exePrivacyAlpha rogue security software - not recommended, removal instructions hereNo
privacyboanXprivacyboan.exeDetected by Malwarebytes as Rogue.PrivacyBoan. The file is located in %ProgramFiles%\privacyboanNo
PrivacyBohoXPrivacyBoho.exePrivacyBoho rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.K.PrivacyBohoNo
privacycareXprivacycare.exePrivacyCare rogue security software - not recommended, removal instructions hereNo
PrivacyClearXPrivacyClear.exePrivacyClear rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyClearNo
PrivacyCodeXPrivacyCode.exePrivacyCode rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyCodeNo
PrivacyControlXPrivacyControl.exePrivacyControl rogue privacy program - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyControlNo
PrivacyCutXPrivacyCut.exePrivacyCut rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyCutNo
PrivacyDr2016UPrivacyDr2016.exeDetected by Malwarebytes as PUP.Optional.PrivacyDr. The file is located in %ProgramFiles%\Privacy Dr 2016. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
Privacy Eraser ProNPrivacyEraser.exePrivacy Eraser Pro - protects your Internet privacy by cleaning up all Internet history tracks and past computer activitiesNo
PrivacyGateXPrivacyGate.exePrivacyGate rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyGate. The file is located in %ProgramFiles%\PrivacyGateNo
Privacy GuarantorXPrivacyGuarantor.exePrivacy Guarantor rogue privacy program - not recommended, removal instructions hereNo
ProtectXPrivacyGuard2010.exePrivacyGuard 2010 rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyGuard2010No
PrivacyGuardXprivacyguarduc.exePrivacyGuard rogue security software - not recommended, removal instructions hereNo
privacygXprivacyg_up.exePrivacyG rogue privacy program - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.K.PrivacyGNo
PrivacyHiddenXPrivacyHidden.exePrivacyHidden rogue security software - not recommended, removal instructions hereNo
PrivacyiXPrivacyi.exePrivacy.I rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyiNo
piconUPrivacyIconClient.exePart of Intel Active Management Technology - bundled with many computers and used in network environments. Displays the Intel Management & Security Status (IMSS) tool system tray icon. Not required for standalone computersNo
PrivacyInfoXPrivacyInfo.exePrivacy Info rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyInfoNo
PrivacyKeyXPrivacyKey.exePrivacyKey rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyKeyNo
PrivacyKeyboardUPrivacyKeyboard.exePrivacyKeyboard is a product "that can provide every computer with strong protection against ALL types of keylogging programs and keylogging hardware devices, both known and unknown, currently in use or presently being developed worldwide"No
PrivacyKingdomXPrivacyKingdom.exePrivacyKingdom rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.K.PrivacyKingdomNo
privacylockSXprivacylockU.exeDetected by Malwarebytes as Rogue.PrivacyLock. The file is located in %ProgramFiles%\privacylockNo
PrivacyManagerXPrivacyManager.exePrivacyManager rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PrivacyManagerNo
com.codeode.privacymantraUprivacymantra.exe"Privacy Mantra keeps your computer clean from online and offline tracks"No
privacynSXprivacynU.exeDetected by McAfee as Generic FakeAlertNo
PrivacyPlusUPrivacyPlus.exeDetected by Malwarebytes as PUP.Optional.PrivacyPlus. The file is located in %ProgramFiles%\Privacy Plus. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PrivacyPlusXPrivacyPlusC.exeDetected by Malwarebytes as Rogue.PrivacyPlus.K. The file is located in %ProgramFiles%\PrivacyPlusNo
PrivacyReviverUPrivacyReviver.exePrivacy Reviver from ReviverSoft - "will scan your PC and identify any personal information or activities that are at the risk of being exposed to hackers and scammers. Privacy Reviver can safely remove all these traces and keep your information private and secured in minutes." Detected by Malwarebytes as PUP.Optional.ReviverSoft. The file is located in %ProgramFiles%\Privacy Reviver. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PrivacyRightXPrivacyRight.exePrivacyRight rogue security software - not recommended, removal instructions hereNo
PrivacyViewXPrivacyView.exePrivacyView rogue security software - not recommended, removal instructions hereNo
Private Facebook Stealer v 1.5.2 By Anonymous.vbsXPrivate Facebook Stealer v 1.5.2 By Anonymous.vbsDetected by Dr.Web as Trojan.MulDrop5.39207 and by Malwarebytes as Trojan.Agent.VBS. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Windows ServiceXprivate-zone.exeAdded by an unidentified WORM or TROJAN! The file is located in %System%No
PrinterXprivate.exeDetected by Malwarebytes as Backdoor.BotNo
ControlPanelXprivate.exe internat.dll,LoadMouseCarpetProfileDetected by Trend Micro as TROJ_DLOADER.BGQNo
Complete SecurityYPrivateSurfNT.exeDefender Pro Private Surf - now incorporated Defender Pro 15-in-1 and 5-in-1No
NameCleanXPrivChkUpdate.exeDetected by Dr.Web as Trojan.DownLoader9.32447No
PrivitizeVPNUPrivitizeVPN.exe"Privitize is a VPN - virtual private network - that makes sure that all your internet connections go through our super fast servers located world wide - now your privacy is protected all the time while browsing the internet, accessing Facebook, sending emails or chatting with friends." Note - the default installation includes ZoomEX adware and changes the homepage and search provider to SearchTab (maybe different ones in other versions)No
PrivoxyUprivoxy.exePrivoxy - "non-caching web proxy with advanced filtering capabilities for enhancing privacy, modifying web page data and HTTP headers, controlling access, and removing ads and other obnoxious Internet junk"No
PrivacyProtectorUprivprot.exePrivacy Protector part of an older version of the Advanced System Optimizer utility suite by Systweak SoftwareNo
privsoftXprivsoft.exeDetected by Malwarebytes as Trojan.TrickBot. The file is located in %ProgramFiles%\privsoftNo
PrizeSurferXprizesurfer.exePrizeSurfer parasiteNo
PrjBetaXprjbeta.exeDetected by Dr.Web as Trojan.Siggen6.19943 and by Malwarebytes as Backdoor.Agent.ENo
prjtectXprjtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prktectXprktect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prltectXprltect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
Parallels Tools?prl_cc.exePart of Parallel Tools utility suite for guest operating systems included with virtualization software from Parallels - such as Parallels WorkstationNo
PermissionResearchXprmrsr.exeMarketscore.RelevantKnowledge adwareNo
prmtXprmt.exeNetRatings Premeter spywareNo
PremeterXprmt.exeNetRatings Premeter spywareNo
prmtectXprmtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prnetXprnet.tmpDetected by Microsoft as TrojanDownloader:Win32/Pacoheir.A and by Malwarebytes as Trojan.AgentNo
SysPrntXprnsrv.vbsDetected by Sophos as W32/VBLame-HNo
PrnStatusMXNPrnStatusMX.exeStatus monitor for the HP Color LaserJet CP1210 printer series - for monitoring printer status, checking ink levels, etcNo
PrnSys ExecutableUPrnSys.exePrint screen utility bundled with some HP printer software - not required, but your choice if you like that featureNo
pro2.exeXpro2.exeDetected by McAfee as Generic.bfr!dyNo
ProAntispyXProAntispy.exeProAntispy rogue spyware remover - not recommended, removal instructions hereNo
ProAntiVirusXProAntiVirus.exeDetected by Sophos as W32/Rbot-FTPNo
Pro Antispyware 2009Xproas2009.exePro AntiSpyware 2009 rogue spyware remover - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.ProAntiSpyware. The file is located in %CommonAppData%\Solt Lake Software\Pro Antispyware 2009No
Probe2UProbe2.exePC Probe II system monitoring utility included with some ASUS motherboards which monitors, detects and alerts you if there are any problems with fan rotation, CPU temperature, system voltages and others. Only required if you overclock the system or live in a hot climateYes
Probe2.exeUProbe2.exePC Probe II system monitoring utility included with some ASUS motherboards which monitors, detects and alerts you if there are any problems with fan rotation, CPU temperature, system voltages and others. Only required if you overclock the system or live in a hot climateYes
Launch PC Probe IIUProbe2.exePC Probe II system monitoring utility included with some ASUS motherboards which monitors, detects and alerts you if there are any problems with fan rotation, CPU temperature, system voltages and others. Only required if you overclock the system or live in a hot climateYes
Microsoft© Windows© Operating SystemXProccessor.exeDetected by Malwarebytes as Trojan.Agent.MSWGen. The file is located in %UserTemp%No
SysctrlsXprocdll.exeDetected by Trend Micro as BKDR_WEEDBOTZ.14 and by Malwarebytes as Backdoor.BotNo
SystemReg?PROCES.EXEThe file is located in %Windir%No
Default KeyXprocess.exeDetected by Malwarebytes as Trojan.Injector. The file is located in %LocalAppData%\processNo
proccessXProcess.exeDetected by Malwarebytes as Trojan.PWS.Zbot. The file is located in %AppData%\ProcessNo
processXprocess.exeDetected by Microsoft as TrojanSpy:Win32/Bancos.VI!dll2 and by Malwarebytes as Password.StealerNo
process.exeXprocess.exeDetected by Symantec as Infostealer.Bancos.PNo
Microsoft Process ManagerXprocess32.exeDetected by Intel Security/McAfee as W32/Checkout. The file is located in %System%No
process32Xprocess32.exeDetected by Microsoft as TrojanSpy:Win32/Bancos.VI!dll2 and by Malwarebytes as Trojan.BankerNo
Process ExplorerXProcessEX.exeDetected by Malwarebytes as Trojan.Agent.DE. Note - this is not the legitimate Process Explorer from Windows Sysinternals which has the filename "processexp.exe". The file is located in %UserTemp%No
Process Lasso core engineUprocessgovernor.exeCore Engine (responsible for applying the process rules) for Process Lasso from Bitsum Technologies - "a unique new technology that will improve your PC's responsiveness and stability during periods of high CPU load" which "intelligently adjusts the priorities of running programs so that badly behaved processes won't negatively impact the responsiveness of your PC"Yes
ProcessGovernorUprocessgovernor.exeCore Engine (responsible for applying the process rules) for Process Lasso from Bitsum Technologies - "a unique new technology that will improve your PC's responsiveness and stability during periods of high CPU load" which "intelligently adjusts the priorities of running programs so that badly behaved processes won't negatively impact the responsiveness of your PC"Yes
Process HackerUProcessHacker.exe"Process Hacker is a free and open source process viewer. This multi-purpose tool will assist you with debugging, malware detection and system monitoring. It includes powerful process termination, memory viewing/editing and other unique and specialized features"No
Process Hacker 2UProcessHacker.exe"Process Hacker is a free and open source process viewer. This multi-purpose tool will assist you with debugging, malware detection and system monitoring. It includes powerful process termination, memory viewing/editing and other unique and specialized features"No
SystemXprocessina_inddowss.exeDetected by Malwarebytes as Trojan.Agent.E. The file is located in %Windir%No
AviraXProcessKernel.exeDetected by McAfee as RDN/Generic.dx!czw and by Malwarebytes as Backdoor.Agent.PKNo
Process Lasso management consoleNprocesslasso.exeSystem Tray access to the Management Console (GUI) for Process Lasso from Bitsum Technologies - "a unique new technology that will improve your PC's responsiveness and stability during periods of high CPU load" which "intelligently adjusts the priorities of running programs so that badly behaved processes won't negatively impact the responsiveness of your PC"Yes
processlassoNprocesslasso.exeSystem Tray access to the Management Console (GUI) for Process Lasso from Bitsum Technologies - "a unique new technology that will improve your PC's responsiveness and stability during periods of high CPU load" which "intelligently adjusts the priorities of running programs so that badly behaved processes won't negatively impact the responsiveness of your PC"Yes
ProcessLassoManagementConsoleNprocesslasso.exeSystem Tray access to the Management Console (GUI) for Process Lasso from Bitsum Technologies - "a unique new technology that will improve your PC's responsiveness and stability during periods of high CPU load" which "intelligently adjusts the priorities of running programs so that badly behaved processes won't negatively impact the responsiveness of your PC"Yes
ShellXProcessMgr.exeDetected by Dr.Web as Trojan.Siggen6.19914 and by Malwarebytes as Hijack.Shell. Note - this entry modifies the legitimate HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" value data to load the file "ProcessMgr.exe" (which is located in %ProgramFiles%\AtmEngine) rather than the default "explorer.exe" (which is located in %Windir% and shouldn't be deleted)No
NetWireXProcessname.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData%No
processpowerXProcessPower.exeDetected by Dr.Web as Trojan.DownLoader10.7600 and by Malwarebytes as Trojan.Agent.ENo
Uniblue ProcessQuickLink 2NProcessQuickLink2.exeProcessQuickLink by Uniblue Systems Ltd - gives you quick access to their Process Library entry for a currently running process via the standard Windows Task Manager (CTRL+ALT+DEL). A System Tray icon also allows you to search the library and launch the Task Manager. No longer availableYes
ProcessQuickLink2NProcessQuickLink2.exeProcessQuickLink by Uniblue Systems Ltd - gives you quick access to their Process Library entry for a currently running process via the standard Windows Task Manager (CTRL+ALT+DEL). A System Tray icon also allows you to search the library and launch the Task Manager. No longer availableYes
ProcessSupervisorGUIUProcessSupervisor.exeGraphical user interface (GUI) for Process Lasso from Bitsum Technologies - "a state-of-the-art, highly optimized, automated Windows process (program) management tool. Through managing the programs running on your computer, Process Lasso increases system responsiveness"No
ProcessSysWeatherAlertUProcessSysWeatherAlert.exeDetected by Malwarebytes as PUP.Optional.SysWeatherAlert. The file is located in %CommonAppData%\ProcessSysWeatherAlert. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
ProcessTamerUProcessTamerTray.exeMouser's Software Process Tamer "is a tiny (140k) and super efficient utility for Microsoft Windows XP/2K/NT that runs in your system tray and constantly monitors the cpu usage of other processes"No
!1_ProcessGuard_StartupYprocguard.exeDiamondCS ProcessGuard "is a powerful new type of security system that secures Windows at the lowest (kernel) level, allowing it to provide the maximum possible security" stopping malware from being executed silently in the background, as well as a variety of other attacksNo
WinSvcXprocin.exeDetected by Dr.Web as Trojan.DownLoader4.58498No
procmonXprocmon.exeDetected by Symantec as Backdoor.Bionet.40aNo
Windows Generic ProcXprocmsg.exeDetected by Symantec as W32.Allim.BNo
procto2.exeXprocto2.exeDetected by Malwarebytes as Trojan.Agent.AP. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see hereNo
ProdikeysAutorunNProdload.exeCreative Prodikeys software - 'an interactive music entertainment device which not only functions as a full-featured, ergonomic "QWERTY" keyboard but also comes equipped with 37 touch-sensitive music keys and accessible music controls for endless entertainment at your desktop. Coupled with the Sound Blaster audio card, you can explore a wide array of realistic instrument sounds and have non-stop fun making music right at your desktop'No
DSL Connection ManagerNProDsl.exeSystem Tray access to the connection manager for Intel ADSL modems - such as the ProDSL 3200 and ProDSL 2100. Allows you to monitor a number of parameters for you DSL connection and modemNo
ProDslNProDsl.exeSystem Tray access to the connection manager for Intel ADSL modems - such as the ProDSL 3200 and ProDSL 2100. Allows you to monitor a number of parameters for you DSL connection and modemNo
Instant AccessXprodsrvs.exeDialer.InstantAccess premium rate adult content dialer variant. Detected by Malwarebytes as Adware.EGDAccess. The file is located in %System%No
JPEGXproductimage.exeDetected by McAfee as Generic BackDoor and by Malwarebytes as Backdoor.Agent.DCNo
ShellXProductkeyupdate.exeDetected by Malwarebytes as Rogue.WindowsActivation. Note - this entry modifies the legitimate HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" value data to point to the file "Productkeyupdate.exe" (which is located in %ProgramFiles%\Productkeyupdate) and also adds an illegal HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" entry pointing to the same file. Removal instructions here and more information hereNo
Products Detail.exeXProducts Detail.exeDetected by Malwarebytes as Backdoor.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ProductUpdaterNProductUpdater.exeProduct updater for media products from Freemake including Video Converter, Video Downloader and Audio ConverterYes
ProductUpdaterUProductUpdater.exeDetected by Malwarebytes as PUP.Optional.ProductUpdater. The file is located in %LocalAppData%\VDI\Shared\Product Updater. If bundled with another installer or not installed by choice then remove itNo
produpdUprodupd.exeDetected by Malwarebytes as PUP.Optional.Clicker. Note - this entry loads from HKCU\Run and the file is located in %AppData%\VDI\Shared\Product Updater. If bundled with another installer or not installed by choice then remove itNo
produpdUprodupd.exeDetected by Malwarebytes as PUP.Optional.Clicker. Note - this entry loads from the Windows Startup folder and the file is located in %AppData%\VDI\Shared\Product Updater. If bundled with another installer or not installed by choice then remove itNo
profaimbotXProfaimbot.exeDetected by Malwarebytes as Trojan.Backdoor. The file is located in %Windir%No
ProfessionalCleaningSoftwareUProfessionalCleaningSoftware.exePro PC Cleaner optimization and cleaning utility by Rainmaker Software Group LLC. Detected by Malwarebytes as PUP.Optional.ProCleaningSoftware. The file is located in %ProgramFiles%\Professional Cleaning Software\ProfessionalCleaningSoftware.exe. If bundled with another installer or not installed by choice then remove itNo
Microsoft Profile ManagerXprofile.exeAdded by a variant of the IRCBOT BACKDOOR!No
ProfileXProfile.vbsDetected by McAfee as VBS/WhiteHo@MMNo
ProfilerNProfiler.exeSaitek SST (Saitek Smart Technology) Profile Launcher - allows System Tray access to the "Profile Editor" (to edit and load profiles) and "Control Panel" for their range of game controllers. Run manually via Start → All Programs → Saitek SST Software → Launch Profile LauncherYes
Configuration SoftwareNProfiler.exeSaitek SST (Saitek Smart Technology) Profile Launcher - allows System Tray access to the "Profile Editor" (to edit and load profiles) and "Control Panel" for their range of game controllers. Run manually via Start → All Programs → Saitek SST Software → Launch Profile LauncherYes
ProfileReminderUProfileReminder.exeEye-One Match (or i1Match) monitor calibration software for use with professional imaging tools such as the X-Rite (was GretagMacbeth) Eye-One Display LT and iDisplay 2 or the Pantone Eye-One Display 2No
Saitek SD6 SoftwareNProfilerU.exeSaitek SST (Saitek Smart Technology) Profile Launcher - allows System Tray access to the "Profiler" and "Control Panel" for their range of game controllers. Run manually via Start → Programs → Saitek SD6 Programming Software → ProfilerYes
ProfilerNProfilerU.exeSaitek SST (Saitek Smart Technology) Profile Launcher - allows System Tray access to the "Profiler" and "Control Panel" for their range of game controllers. Run manually via Start → Programs → Saitek SD6 Programming Software → ProfilerNo
ProfilerUNProfilerU.exeSaitek SST (Saitek Smart Technology) Profile Launcher - allows System Tray access to the "Profiler" and "Control Panel" for their range of game controllers. Run manually via Start → Programs → Saitek SD6 Programming Software → ProfilerYes
ProfileWatcherXprofilewatcher.exeMySpace ProfileWatcher profile monitoring software from zpsearch.com. Parasite/adware - see here and hereNo
Windows Media CenterXProfonix install makers.exeDetected by McAfee as RDN/Generic.bfr!fl and by Malwarebytes as Trojan.KBayi.FLANo
gdsXprog.exeDetected by McAfee as RDN/Generic.bfr!d and by Malwarebytes as Trojan.Agent.ZBNo
CS5YFRYIG0TV65APDE8=Xprogman.exeDetected by McAfee as RDN/Generic BackDoor!zf and by Malwarebytes as Trojan.Agent.MCNo
[various names]Xprogmen.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Program FileXProgmon.exeDetected by Symantec as Backdoor.Peeper and by Malwarebytes as Trojan.DownloaderNo
Windows.exeXProgram FilesWindows.exeDetected by Malwarebytes as Trojan.Agent.WDE. The file is located in %Root%No
UpdateXprogram.exeDetected by Malwarebytes as Spyware.KeyBase.Generic. The file is located in %UserProfile%\Desktop\rogramNo
ProgramXProgram.exeDetected by Dr.Web as Trojan.AVKill.28729 and by Malwarebytes as Trojan.Agent.GenNo
ctfmom.exeXPrograma.exeDetected by Dr.Web as Trojan.MulDrop5.230 and by Malwarebytes as Backdoor.Agent.ENo
ProgramControlXProgramControl.exeDetected by Sophos as Troj/Dloadr-BAGNo
ProgramsKaspersky.vbsXProgramsKaspersky.vbsDetected by Dr.Web as Trojan.DownLoader11.27744 and by Malwarebytes as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Protocol Host OperatorXprohost.exeDetected by Malwarebytes as Backdoor.Agent.Gen. The file is located in %System% - see hereNo
Project1.exeXProject1.exeDetected by Dr.Web as Trojan.DownLoader4.11208. Note - this entry loads from the Windows Startup folder and the file is located in %Temp%\Project1No
Project1.exeXProject1.exeDetected by Dr.Web as Trojan.Siggen3.13222 and by Malwarebytes as Trojan.Agent.gen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ctfmonXProject1.exeDetected by Dr.Web as Trojan.DownLoader4.11208 and by Malwarebytes as Trojan.Agent.GenNo
ShellXProject1.exeDetected by Dr.Web as Trojan.Siggen6.16512 and by Malwarebytes as Hijack.Shell. Note - this entry modifies the legitimate HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" value data to open the file "Project1.exe" (which is located in %ProgramFiles%\W1\Win1) instead of the default "explorer.exe" (which is located in %Windir% and shouldn't be deleted)No
Project1XProject1.exeDetected by Dr.Web as Trojan.Siggen3.13222 and by Malwarebytes as Trojan.Agent.PJTGenNo
Project2.exeXProject2.exeDetected by Malwarebytes as Trojan.Banker.Gen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts - see hereNo
Project7.exeXProject7.exeDetected by Malwarebytes as Trojan.Banker.Gen. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ProjectWhoisNProjectWhois.exeProject Whois by Domain Tools, LLC - "gives users one-click access to see the owners of each site they visit (in IE or Firefox currently) on demand, as well as allowing discrete Whois lookups anytime"No
ProjectXpXProjectXp.exeDetected by Dr.Web as Trojan.Belanit.4 and by Malwarebytes as Trojan.AgentNo
projselectorNprojselector.exeRoxio Project Selector - can be started manuallyNo
PROMon.exeNPROMon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic featuresNo
PromptCastUPromptCast.exePromptCast by NOP World for Surveys.com. Automatically downloads short films and movie trailers in the background for reviewing in surveys. A valid Surveys.com account is requiredNo
PRONoMgr.exeNPRONoMgr.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic featuresNo
PRONoMgrWiredUPRONoMgr.exeIntel's Pro 100 Ethernet card managerNo
msprojectXproobjecttwo.exeDetected by McAfee as Generic Dropper!dhuNo
opesysXpropagador.exeDetected by Sophos as W32/Autorun-BPNNo
ProPCCleanerUProPCCleaner.exePro PC Cleaner optimization and cleaning utility by Rainmaker Software Group LLC. Detected by Malwarebytes as PUP.Optional.ProPCCleaner. The file is located in %ProgramFiles%\Pro PC Cleaner. If bundled with another installer or not installed by choice then remove itNo
PROPCCleanerSoftUPROPCCleanerSoft.exePro PC Cleaner optimization and cleaning utility by Rainmaker Software Group LLC. Detected by Malwarebytes as PUP.Optional.ProPCCleaner. The file is located in %ProgramFiles%\PRO PC Cleaner Soft. If bundled with another installer or not installed by choice then remove itNo
PROPCCleanerSoftwareUPROPCCleanerSoftware.exePro PC Cleaner - "Designed to result in a Cleaner and Faster PC!" Detected by Malwarebytes as PUP.Optional.ProPCCleaner. The file is located in %ProgramFiles%\PRO PC Cleaner Software. If bundled with another installer or not installed by choice then remove itNo
Propel AcceleratorUPropelAC.exePropel Internet AcceleratorNo
ProPort StartupUProPort.exeProport is a port monitor/protector. Monitors an infinite amount of ports for trojans and nukes. Some additional features are auto connection-kill, and IP resolvingNo
ProPrivacyXProPrivacy.exeProPrivacy rogue security software - not recommended, removal instructions hereNo
TroughXPROset.exeDetected by Dr.Web as Trojan.Siggen.47533 and by Malwarebytes as Backdoor.Agent.ENo
ProSiteFinderXprositefinder.exeProSiteFinder adwareNo
ServicesXprosys32.exeAdded by an unidentified WORM or TROJAN!No
ProSystemXProsystem.exeDetected by Sophos as W32/Mdrop-BPZNo
ProtectXProtect.exeDetected by Dr.Web as Trojan.Siggen3.3200No
Protect.exeXProtect.exeDetected by McAfee as Downloader.gen.aNo
Windows DefenderXprotect.exeDetected by Malwarebytes as Trojan.Agent.Gen. The file is located in %AppData%No
SvchEDXProtect.exeDetected by Dr.Web as Trojan.Siggen3.3200No
run32.dllXProtect.exeDetected by Dr.Web as Trojan.MulDrop3.27289 and by Malwarebytes as Trojan.Agent.STNo
run32.exeXProtect.exeDetected by Dr.Web as Trojan.Inject.45984 and by Malwarebytes as Backdoor.AgentNo
protectXprotect.scrDetected by Sophos as Troj/Dloader-TQNo
ProtectBoanXProtectBoan.exeProtect Boan rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.K.ProtectBoan. The file is located in %ProgramFiles%\ProtectBoanNo
mbamsXprotectbytes.batDetected by Dr.Web as Trojan.DownLoader9.17017 and by Malwarebytes as Trojan.Agent.MNRNo
ProtectCodeXProtectCode.exeProtectCode rogue security software - not recommended, removal instructions hereNo
ProtectDefenderXProtectDefender.exeProtectDefender rogue security software - not recommended, removal instructions hereNo
PELockXProtected.exeDetected by Malwarebytes as Trojan.Passwords. The file is located in %AppData%No
ProtectFileUpdaterYProtectFileUd.exeProtectFile by SafeNet - "provides data security with fully automated file encryption of unstructured data contained in network drives and file servers. When an organization knows their confidential data is protected from both external and internal threats, they can focus on growth, gain knowledge through secured collaboration, and enjoy an increase in productivity"No
Protector GBXprotectgb.exeDetected by Trend Micro as TROJ_BANKER.EIENo
protectinfoXprotectinfo.exeProtectInfo rogue security software - not recommended, removal instructions hereNo
ProtectionXProtection.exeDetected by Sophos as W32/Febelneck-ANo
ProtectKeepXProtectKeep.exeProtect Keep rogue security software - not recommended, removal instructions hereNo
ProtectMineXProtectMine.exeProtectMine rogue security software - not recommended, removal instructions hereNo
ProtectOnXProtectOn.exeProtectOn rogue security software - not recommended, removal instructions hereNo
protectonerXprotectonerun.exeProtectOne rogue security software - not recommended, removal instructions hereNo
InspectorXProtector-****.exeOne of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-ablu.exeWindows Virtual Security rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-edxh.exeWindows AntiHazard Helper rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-elww.exeWindows Safety Series rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-fbfv.exeWindows Efficiency Accelerator rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-fnov.exeWindows Secure Web Patch rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-foju.exeWindows Premium Defender rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-frb.exeWindows Risk Minimizer rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-fvog.exeWindows Active Guard rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-hrnn.exeWindows PC Aid rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-jasu.exeWindows Interactive Security rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-jgxf.exeWindows Security Renewal rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-kcdt.exeWindows Foolproof Protector rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-kuh.exeWindows Smart Partner rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-lutu.exeWindows Anti-Malware Patch rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-oaaw.exeWindows Maintenance Guard rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-ogpl.exeWindows Efficiency Reservoir rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-pnnn.exeWindows Antivirus Care rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-qbbn.exeWindows Interactive Safety rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-qdva.exeWindows Advanced User Patch rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-quet.exeWindows Safety Checkpoint rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-rchh.exeWindows Abnormality Checker rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-rpqu.exeWindows Antivirus Machine rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-tdxa.exeWindows Warding System rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-tpnv.exeWindows Guard Solutions rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-uft.exeWindows Tools Patch rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-uxgh.exeWindows Custom Management rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-vthu.exeWindows Expert Series rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-wnxo.exeWindows Custom Safety rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-wqic.exeWindows Guard Tools rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-wxqn.exeWindows Antivirus Rampart rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-xghp.exeWindows Safety Module rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-xhk.exeWindows Functionality Checker rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-xjxh.exeWindows Secure Workstation rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-xtbb.exeWindows Guardian Angel rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-yhrm.exeWindows Secure Surfer rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
InspectorXProtector-yrox.exeWindows Trouble Taker rogue security software - not recommended, removal instructions here. One of the Tritax family of rogue security software - detected by Malwarebytes as Trojan.FakeAlert. The file is located in %AppData%No
SpyCatcher Protector?Protector.exePart of the SpyCatcher spyware remover from Tenebril Inc - which "is the only antispyware that uses multiple layers of technology including advanced behavioral detection to stay ahead of spyware attacks." Main program?No
SafetyCenterXprotector.exeSafety Center rogue security software - not recommended, removal instructions hereNo
ProtectPcs.exeXProtectPcs.exeProtectPcs rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
ProtectPCXprotectpcuc.exeProtectPC rogue security software - not recommended, removal instructions hereNo
wscriptXProtectProcess.exeDetected by Malwarebytes as Misused.Legit. The file is located in %UserTemp%\PprotecNo
ProtectShieldXProtectShield.exeProtectShield rogue security software - not recommended, removal instructions hereNo
ProtectSoldierXProtectSoldier.exeProtectSoldier rogue security software - not recommended, removal instructions hereNo
ProtectTopXProtectTop.exeProtectTop rogue security software - not recommended, removal instructions hereNo
protestasx.exeXprotestasx.exeDetected by Malwarebytes as Trojan.SpyEyes. The file is located in %Root%No
protestasx.exeXprotestasx.exeDetected by Sophos as Troj/Dloadr-DDK and by Malwarebytes as Trojan.SpyEyes. The file is located in %Root%\protestasx.exeNo
ProtectionsXProtEX32.exeUltimate SecuritySuite, Ultimate Defender or UltimateFixer rogue security software - not recommended. Detected by Malwarebytes as Rogue.UltimateFixerNo
GuardSoftwareXproto-opxk.exeWindows Virtual Protector rogue security software - not recommended, removal instructions hereNo
DLDXprotoc-34123.vbsDetected by Malwarebytes as Trojan.Downloader.DLD. The file is located in %UserTemp% - see hereNo
AVGXProtocole.exeDetected by McAfee as RDN/Generic.dx!czc and by Malwarebytes as Backdoor.XTRatNo
loadXprotocolhost.exeDetected by Malwarebytes as Trojan.Agent. Note - this entry modifies the legitimate HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" value data to include the file "protocolhost.exe" (which is located in %AppData%\Microsoft\Blend\14.0\FeedCache)No
ProtoWallUProtoWall.exeProtowall IP blocker - "a lightweight program that runs in the background, taking up little CPU and memory, while blocking thousands of bad IP addresses"No
provXprov.exeAdded by a variant of the IRCBOT BACKDOOR!No
WINDOWSXprova.exeDetected by Malwarebytes as Backdoor.Agent.DC. The file is located in %MyDocuments%\provaNo
StartnameXprova.exeDetected by Malwarebytes as Trojan.Inject. The file is located in %ProgramFiles%No
LIDKESXprovalist.exeDetected by Malwarebytes as Trojan.Banker.E. The file is located in %Root% - see hereNo
sqlpdroXprovidd.exeDetected by Sophos as Troj/Agent-LXF and by Malwarebytes as Trojan.AgentNo
Microsoft UpdateXprowind32.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %System%No
The ProxomitronNProxomitron.exe"Proxomitron: a free, highly flexible, user-configurable, small but very powerful, local HTTP web-filtering proxy"No
ProxomitronNProxomitron.exe"Proxomitron: a free, highly flexible, user-configurable, small but very powerful, local HTTP web-filtering proxy"No
NOME DA ENTRADAUProxy.exeDetected by Malwarebytes as PUP.Proxy. The file is located in %Temp%. If bundled with another installer or not installed by choice then remove itNo
Microsoft Windows DLL Services ConfigurationXproxy.exeDetected by Sophos as W32/Sdbot-ZL and by Malwarebytes as Trojan.MWF.GenNo
ProxyXProxy.exeDetected by Malwarebytes as Trojan.Agent.DE. The file is located in %AppData%No
msconfig.exeXproxy.exeAdded by a variant of the AGENT.AH TROJAN!No
LocalProxyUproxy4free.exe"ProxyTools is a package of Perl network utilities designed mainly to assist those whose Internet access is censored, unreliable, or otherwise damaged. Uncensored access is provided to any outside service required (Usenet News, Web browsing, IRC, Socks etc.). Setup requires installation of Perl and some modules"No
ProxyCapYProxyCap.exe"ProxyCap enables you to tunnel Internet applications through HTTP, SOCKS v4, and SOCKS v5 Proxy Servers"No
pumcfgpYproxycfg.exePart of iShield® by Guardware - which "is a unique software solution that enables you to protect your family from Internet based pornography and manage their Internet usage"No
ProxyFirewallUProxyFirewall.exeProxy Firewall by Unique Internet Services, LLC - "is an automatic proxy selector that will simply and easily manage proxy connections for you" and also acts "as a standard firewall for out-bound connections"No
PSwitchUProxySwitcher.exeProxy Switcher by V-Tech LLC - IP address cloaker which "can be used to avoid all sorts of limitations imposed by various sites. Be that a download site that limits amount of downloads. Or video site works only in a particular country - more often than not it gets defeated by the anonymous browsing features Proxy Switcher provides"No
ProxyWayUproxyway.exeProxyWay anonymous proxy surfing softwareNo
proxzy[numbers]Xproxzy[numbers].exeDetected by Intel Security/McAfee as W32/Mabezat and by Malwarebytes as Worm.AutoRun. The file is located in %Recycled%\{SID} - see examples here and hereNo
MediaPathXProyecto1.exeDetected by Trend Micro as WORM_GRUEL.DNo
Rundll32.exeXProyecto1.exeDetected by Trend Micro as WORM_GRUEL.DNo
DevicePathXProyecto1.exeDetected by Trend Micro as WORM_GRUEL.DNo
GerenteXProyecto105.exeDetected by Dr.Web as Trojan.DownLoader3.2114 and by Malwarebytes as Trojan.Agent.GRNo
PRPCMonitorUPRPCUI.exeIntel® SpeedStep™ interface. This automatically detects whether a mobile PC is using battery or AC power. When using battery power, SpeedStep scales the processor clock frequency and voltage to reduce the power it needs by 40%No
Data Restore ServiceXprq8.exeDetected by Symantec as W32.Kelvir.AINo
prqtectXprqtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prrtectXprrtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prstectXprstect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
LnchSysIPXprsyncp.exeDetected by Malwarebytes as Adware.Korad. The file is located in %ProgramFiles%\SysIntProNo
Printscreen 95NPRT95MIN.EXEPrintscreen 95 - utility to capture, print or save the current window. Note - this entry loads from the Windows Startup folder and the file is located in %Root%\PRT9540. No longer availableNo
prtcctXprtcct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
Clotusorgreg0?prtStart.exe [path] Orgprt.exeIBM Lotus SmartSuite related. The file is located in %Root%\LOTUS\ORGREG. What does it do and is it required?No
PrtUprtsvc.exeDetected by Malwarebytes as PUP.Optional.DeskBar. The file is located in %LocalAppData%\TECHP-Browser. If bundled with another installer or not installed by choice then remove itNo
prttectXprttect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
PrU Async ServiceXpruas.exeDetected by Sophos as W32/IRCBot-UGNo
prunnetXprunnet.exeDetected by Sophos as Troj/Dloadr-BHN and by Malwarebytes as Trojan.AgentNo
prutcctXprutcct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutdctXprutdct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutgctXprutgct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
pruthctXpruthct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutictXprutict.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutlctXprutlct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutpctXprutpct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
prutsctXprutsct.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
HKLMPRVXPRV.exeDetected by McAfee as RDN/Generic.bfr!fd and by Malwarebytes as Backdoor.Agent.HKPGenNo
HKCUPRVXPRV.exeDetected by McAfee as RDN/Generic.bfr!fd and by Malwarebytes as Backdoor.Agent.HKPGenNo
Windows ServiceXprvdi.exeMalware - detected by Kaspersky as the SMALL.RD TROJAN!No
taskmgrXprvrk.vbsDetected by Malwarebytes as Malware.Trace. The file is located in %Windir%No
prvtectXprvtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
HKLMPRVXXPRVx.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.HKPGenNo
HKCUPRVXXPRVx.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes as Backdoor.Agent.HKPGenNo
prxtectXprxtect.exePrutect malware from e2Give - attempts to shut down or tamper with a number of anti spyware applications, like Ad-Aware and SpyBot S&D. Note - has been seen using alternative file names like prttect.exe, prmtect.exe and so forth!No
PrzyspieszKomputerNprzyspieszkomputer.exePrzyŚpieszKomputer - Polish optimization utility which "scans your computer to identify the settings, processes and files that slow down your computer work before taking a number of impressive tricks and tools to accelerate the operation of your computer"No
przy[numbers]Xprzy[numbers].exeDetected by Malwarebytes as Worm.AutoRun. The file is located in %Recycled%\{SID}No
Java RuntimeXps.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %AppData%\AdobeNo
ps1Xps1.exePacerD Media/Pacimedia.com adwareNo
PS2Ups2.exeMultimedia Keyboard companion on HP computers. If this is prevented from starting, then some keyboard functionality will be lostNo
WireLessKeyboardUPS2USBKbdDrv.exeWireless keyboard driverNo
WireLessKeyboard UPS2USBKbdDrv.exeWireless keyboard driver. Note that there is a space at the end of the "Startup Item" fieldNo
psaload32Xpsaload32.exeDetected by Sophos as W32/Rbot-ADLNo
Audio CodecXPSBTRF4NX6.exeDetected by Sophos as W32/Ainslot-AG and by Malwarebytes as Trojan.FakeAVNo
PrivacyScannerXpscan.exePrivacy Champion, a stealth installed 'Privacy Scanner'. It purportedly scans your PC for links to adult content websites, and then offers to "clean" them. Produces loads of False Positives as goad to purchaseNo
PSCastorXPSCastor.exeDetected by Total Defense as Clicker PSCastor. The file is located in %ProgramFiles%\PSCastorNo
PSCMainXpscmain2.exeDetected by ThreatTrack Security as Trojan.Win32.Obfuscated.ev. The file is located in %System%No
PopUpStopperCompanionUPSComp.exePopupStopper Companion popup blockerNo
PSIWin2.3 Connection Server NPsconsv.exeAllows connectivity between a PC and a Psion device. Access can be gained from the Desktop or Start → Programs. Note the space at the end of the "Startup Item" fieldNo
Print Screen DeluxeNpsdeluxe.exePrint Screen Deluxe by American Systems - provides a fast and easy way to capture, print and save your screen with one simple keystrokeNo
PSDiagnosticMUPSDiagnosticM.exeDiagnostic utility for the Linksys WPS54G Wireless-G PrintServerNo
userinitXpsdokqc.exeDetected by McAfee as Generic BackDoor!1vr and by Malwarebytes as Trojan.AgentNo
PinnacleDriverCheckYPSDrvCheck.exePart of Pinnacle Instant CD/DVD burning and authoring software and InstantCopy burning software from Pinnacle Systems. Verifies drive settings, once loaded it doesn't use any resources so you can leave it enabledNo
PSDrvCheckYPSDrvCheck.exePart of Pinnacle Instant CD/DVD burning and authoring software and InstantCopy burning software from Pinnacle Systems. Verifies drive settings, once loaded it doesn't use any resources so you can leave it enabledNo
PractiSearchUPSearch.exePractiSearch web search softwareNo
Provan SecurityXpsecure.exeDetected by Trend Micro as WORM_RBOT.BRVNo
PersonalSecXpsecurity.exePersonal Security rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalSecurityNo
PersonSecurityXpsecurity.exePersonal Security rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalSecurity. The file is located in %ProgramFiles%\PersSecurityNo
PersSecurityXpsecurity.exePersonal Security rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalSecurityNo
PsecurityXpsecurity.exePersonal Security rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.PersonalSecurity. The file is located in %ProgramFiles%\PSecurityNo
Service.comXpService.comDetected by Dr.Web as Trojan.MulDrop4.53993 and by Malwarebytes as Trojan.Agent.CMNo
Peeramid?PService.exeThe file is located in %ProgramFiles%\KOptimizerNo
Xecuter.batXpsexec.batDetected by Symantec as BAT.Boohoo.WormNo
PopUpStopperFreeEditionUPSFree.exePop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup groupNo
PSFreeUPSFree.exePop-Up Stopper Free from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup groupNo
pSGEStateYpSGEState.exeSafeGuard Easy from Sophos (formerly by Utimaco) - "provides total company-wide protection for sensitive information on laptops and workstations. Boot protection, pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"No
P.S.GuardXPSGuard.exePSGuard rogue security software - not recommendedNo
PSGuardXPSGuard.exePSGuard rogue security software - not recommendedNo
PSGuard spyware removerXPSGuard.exePSGuard rogue security software - not recommendedNo
PS Hot Launch VVLUPSHotLaunchVVL.exePS Hot Launch by PS Soft Lab "is meant to quickly run different applications, open documents, go to the right folders and web pages, send mail to a specified address, etc."No
pshowerXpshwr.exeAdded by a variant of Spyware.SafeSurfingNo
PSIMSVCYPSIMSVC.exePart of an older version of the Panda Security range of internet security products. Runs as a service on Windows XPNo
(Default)Xpsiphon.exeDetected by Malwarebytes as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
MalwareScaner.exeXpsirAnRTR.exeDetected by Dr.Web as Trojan.Inject1.43790 and by Malwarebytes as Trojan.Agent.MWNo
Secunia PSI TrayNpsi_tray.exe"Secunia Personal Software Inspector (PSI) is a free computer security solution that identifies vulnerabilities in non-Microsoft (third-party) programs which can leave your PC open to attacks. Simply put, it scans software on your system and identifies programs in need of security updates to safeguard your PC against cybercriminals. It then supplies your computer with the necessary software security updates to keep it safe"No
Secunia PSI TrayUpsi_tray.exeSystem Tray access to and notifications for Secunia PSI (which is now Flexera Software Personal Software Inspector) - which "scans software on your system and identifies programs in need of security updates to safeguard your PC against cybercriminals. It then supplies your computer with the necessary software security updates to keep it safe"Yes
PSListerXPSLister.exePurityScan C adwareNo
PsMFCardUPsMFCard.exeComponent of the Toshiba Controls. Provides power-saving functions for the PCMCIA slots. Through the Power Save Mode Properties dialogue, the user can select from 3 PCMCIA power options - On, Auto1 and Auto2. Disabling this item has no adverse effects, except disabling the ability to reduce power consumption by powering-down the PCMCIA slots when not in useNo
Microsoft Update MachineXpsmszw.exeDetected by Trend Micro as WORM_KOLABC.CC and by Malwarebytes as Backdoor.Bot. The file is located in %System%No
Post-it Software NotesNpsn.exePost-it® Software Notes from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Post-it® Software NotesNpsn.exePost-it® Software Notes from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Post-it Software NotesNpsn2.exeVersion 2 of Post-it® Software Notes from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Post-it® Software NotesNpsn2.exeVersion 2 of Post-it® Software Notes from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Post-it® Software Notes LiteNPsn2Lite.exeVersion 2 of Post-it® Software Notes Lite from 3M - now replaced by the more advanced Post-it® Digital NotesNo
adlhidpXpsncc32.exeDetected by Kaspersky as Trojan-Proxy.Win32.Slaper.ai. The file is located in %System%No
Post-it® Software Notes LiteNPsnLite.exePost-it® Software Notes Lite from 3M - now replaced by the more advanced Post-it® Digital NotesYes
Post-it(R) Software Notes LiteNPsnLite.exePost-it® Software Notes Lite from 3M - now replaced by the more advanced Post-it® Digital NotesYes
PsnLiteNPsnLite.exePost-it® Software Notes Lite from 3M - now replaced by the more advanced Post-it® Digital NotesNo
PsnLite.exeNPsnLite.exePost-it® Software Notes Lite from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Logiciel notes Post-it®Npsnotes.exeLogicel Post-it® (developed by 3M) - now replaced by the more advanced Post-it® Digital NotesNo
Post-it® Software NotesNPsnotes.exePost-it® Software Notes from 3M - now replaced by the more advanced Post-it® Digital NotesNo
Pharos NotifyYpsnotify.exePharos SignUp Vx - "PC reservation and management application that addresses the PC scheduling needs of public libraries and higher education labs and libraries"No
© Windows Live Messenger Music Status Plugin ModuleXpsnsong.exeDetected by McAfee as Generic.bfr!ev and by Malwarebytes as Trojan.AgentNo
PSof1XPSof1.exePacerD Media/Pacimedia.com adware installerNo
PSoft1Xpsoft1.exePacerD Media/Pacimedia.com adware installerNo
SpeechExec Startup?PSP.SpeechExec.StartupApp.exeRelated to Philips SpeechExec dictation software. What does it do and is it required?No
PsPCCardYPsPCCard.EXEBackground Power Saving task found on Toshiba laptops and which handles turning Power Saving ON and OFF on any inserted PC Card (PCMCIA card). Only ever disable if you do not use any power saving or hibernation settings (ie: they are all OFF)No
PspContrUpspcontr.exeDriver/controller for the Philips SpeechMike 6174. As the Philips FreeSpeech application is no longer supported it can be disabled but the Mike can still be used for certain functions using this driverNo
System Monitor ControlXpspluginwkr.exeDetected by Malwarebytes as Trojan.Agent. The file is located in %UserTemp%No
PspUsbCf?PspUsbCf.exeThe file is located in %System%. What does it do and is it required?No
PSPVideo9NpspVideo9.exe"PSP Video 9 is a free PSP video converter that converts video files, YouTube videos, movies and DVD's so you can play them on your PSP"No
Microsoft Driver SetupXpsreg.exeDetected by Sophos as W32/VBMato-C and by Malwarebytes as Worm.PalevoNo
PsSoundUPsSound.exeOn a Toshiba laptop. Operates your sound in one of 4 modes, off, on , on only with powerr, same as #3 but longer delayNo
AutoShutdown?pssvc.exeUtility to fix vCard Export in MS Outlook 2000 - although why are these together?No
Microsoft PSTCP32 DataXpstcp32.exeAdded by a variant of Backdoor:Win32/Rbot. The file is located in %System%No
pstfgrXpstfgr.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes as Trojan.Agent.LCXNo
PowerStripNPSTRIP.EXEPowerStrip by EnTech - "provides advanced, multi-monitor, programmable hardware support to a wide range of graphics cards - from the venerable Matrox Millennium I to AMD Radeon graphics. It is the only program of its type to support multiple graphics cards from multiple chipset vendors, simultaneously, under every Windows operating system from Windows 95 to the x64-bit edition of Windows 7"No
PSUNMainYPSUNMain.exeSystem Tray access to, and notifications for Panda Cloud Antivirus by Panda SecurityNo
tjy02jgg86vh74s9ml00lu3b1v77i0jyduXpsuqndrb.exeDetected by Malwarebytes as Trojan.VBAgent. The file is located in %System%No
psvx.exeXpsvx.exeDetected by Sophos as W32/AutoRun-CT and by Malwarebytes as Worm.AutoRun. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Pocket Sheet SyncUPSXLTRAY.EXECasio Pocket Sheet synchronization softwareNo
psyBNC-2.1.4 Client ServerXpsyBNC215.exeAdded by a variant of Backdoor:Win32/Rbot. The file is located in %System%No
psybnc server 3.1Xpsybnc321.exeDetected by Kaspersky as Backdoor.Win32.Rbot.eni. The file is located in %Windir%No
ISPSERVICEXpsycho.exeDetected by Sophos as Troj/IRCFlood-O and by Malwarebytes as Backdoor.BotNo
Protection SystemXpsystem.exeProtection System rogue security software - not recommended, removal instructions here. Detected by Malwarebytes as Rogue.ProtectionSystemNo
PowertweakUPT2.EXE"Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured". This entry is added if 'Use predefined settings' is enabled in the programs optionsNo
Windows UpdateXPt5y8.exeDetected by Malwarebytes as Trojan.MSIL. The file is located in %UserStartup%No
Pt5y8.exeXPt5y8.exeDetected by Malwarebytes as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
DellAutomatedPCTuneUpYPTAgnt.exePC TuneUp from Dell - "silently monitors your system, automatically running needed maintenance during idle time to keep you at peak performance"No
Parallel TaskingXptask.exeDetected by Sophos as Troj/Small-CJNo
ptaskXptask.exePart of the AVSystemCare rogue security software and other members of this family. See here for examplesNo
PTBSyncUPTBSync.exePTBSync from ElmüSoft - a tool to synchronize your PC time with an an atomic clock via the internetNo
PowertweakUPTCTRL.EXE"Powertweak is designed to configure your system in the best way. A processor, the core of the system, or a chipset (a set of components that manage the data flows between the different parts of the system) can be configured". This entry is added if 'Configure system at logon' is enabled in the programs optionsNo
PTFBUPTFB.exeOlder, freeware version of the PTFB PRO (Push the Freakin' Button) utility from Technology Lighthouse - which "sits quietly in the system tray until a task comes up that it can help you with. It then springs to life taking care of repetitive tasks, eliminating workflow interruptions, restoring program preferences, responding to prompts and popups and so on"Yes
Push The Freakin' ButtonUPTFB.exeOlder, freeware version of the PTFB PRO (Push the Freakin' Button) utility from Technology Lighthouse - which "sits quietly in the system tray until a task comes up that it can help you with. It then springs to life taking care of repetitive tasks, eliminating workflow interruptions, restoring program preferences, responding to prompts and popups and so on"Yes
TLH_PTFBProUPTFBStart.exeLoads the main executable (PTFBPro.exe) for the PTFB PRO (Push the Freakin' Button) utility from Technology Lighthouse and exits. PTFB "sits quietly in the system tray until a task comes up that it can help you with. It then springs to life taking care of repetitive tasks, eliminating workflow interruptions, restoring program preferences, responding to prompts and popups and so on"Yes
PTFB Pro Launch AppUPTFBStart.exeLoads the main executable (PTFBPro.exe) for the PTFB PRO (Push the Freakin' Button) utility from Technology Lighthouse and exits. PTFB "sits quietly in the system tray until a task comes up that it can help you with. It then springs to life taking care of repetitive tasks, eliminating workflow interruptions, restoring program preferences, responding to prompts and popups and so on"Yes
PTFBStartUPTFBStart.exeLoads the main executable (PTFBPro.exe) for the PTFB PRO (Push the Freakin' Button) utility from Technology Lighthouse and exits. PTFB "sits quietly in the system tray until a task comes up that it can help you with. It then springs to life taking care of repetitive tasks, eliminating workflow interruptions, restoring program preferences, responding to prompts and popups and so on"Yes
PTHOSTTRUPTHOSTTR.EXESystem Tray access to HP ProtectTools Security Manager - which "can be configured to prevent unauthorized access using Smart Cards, TPM Embedded security chips, USB tokens and other security technologies. HP ProtectTools Security Manager is completely customizable, which gives business customers the flexibility to choose the level of security that best meets their needs"No
PTIM.exeUPTIM.exePart of the WebEx Productivity Tools which make it very easy for users to "start, schedule, and join WebEx sessions right from your favorite applications."No
d3y9Xptkelmrt.exeDetected by Malwarebytes as Trojan.Backdoor.VB. The file is located in %System%No
run=Xptlseq.cplPhoenixNet BIOS adware. See hereNo
Personal FirwallXptmedsrv.exeDetected by Trend Micro as WORM_SDBOT.XYNo
ptmsgfrm.exeUptmsgfrm.exePart of the WebEx Productivity Tools which make it very easy for users to "start, schedule, and join WebEx sessions right from your favorite applications."No
Karen's Once-A-Day IIUPTOAD.exe"Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!" Scheduler that lets you specify progams, web pages and files that be run or opened automatically, the first timeNo
PTOneClickUptoneclk.exePart of the WebEx Productivity Tools which make it very easy for users to "start, schedule, and join WebEx sessions right from your favorite applications."No
KernelFaultCheckXptool32.exeDetected by Sophos as Troj/LegMir-BNNo
PornoTopXptop.exeDetected by Sophos as Troj/Delf-AES and by Malwarebytes as Trojan.Agent.PRNNo
PTRUN32Uptr32w.exeParentTools surveillance software. Uninstall this software unless you put it there yourselfNo
ReplicatorUPTReplicator.exeReplicator from Karen's powertools. "Automatically backup files, directories, even entire drives!"No
ptrun32Uptrun32.exeParentTools surveillance software. Uninstall this software unless you put it there yourselfNo
Logiciel de transfert d'images KODAKNpts.exeLooks for Kodak camera connection and media insertionNo
Kodak Picture Transfer SoftwareNpts.exeLooks for Kodak camera connection and media insertionNo
PTS SoftwareUPTS.exeDetected by Malwarebytes as PUP.Optional.Protominer. The file is located in %AppData%\PTS. If bundled with another installer or not installed by choice then remove itNo
PlatinumYPtSessionAgent.exeUser session agent for Trend Micro security products, including Maximum Security, Internet Security and Antivirus+ SecurityYes
Platinum user session agentYPtSessionAgent.exeUser session agent for Trend Micro security products, including Maximum Security, Internet Security and Antivirus+ SecurityYes
Trend Micro PlatinumYPtSessionAgent.exeUser session agent for Trend Micro security products, including Maximum Security, Internet Security and Antivirus+ SecurityYes
ptshellXptshell.exeDetected by McAfee as PWS-Mmorpg.genNo
PTSNOOPNPtsnoop.exeThe descriptions we've come across - all valid as far as we can see:- (1) Program installed with some modems that monitors the COM ports for the modem driver. Not required from what we've read - may need a registry edit to get rid of it. (2) Backdoor trojan virus that copies itself as PTSNOOP.EXE -see here for more info. (3) Apparently the people who put it out claim it's a driver for a Voice modems (don't know who they are though - Ed) Note: If using AOL and you disable this you may lose your connection or lock up. (4) Can also be an older Logitech scanner program. Remove from the Win.ini tab under Load='path'PTSNOOP and the System.ini tab under drivers='path'ptrtkr.drb. Can cause parallel port conflicts big time dragging system resources way down when a conflict exists. (5) Allows audio monitoring of modem phone dialling tones and can be useful if you have connection problems. (6) Karen Kenworthy's Snooper - "logs the start and stop time of all programs run under Windows"No
PTSShellXPTSShell.exeDetected by Trend Micro as WORM_WINKO.AONo
Win32loadXptssvc.exeDetected by Sophos as Troj/FakeAV-MK and by Malwarebytes as Trojan.FakeAlertNo
PowerTools Tray IconUpttray.exePowerTools - add-on for AOLNo
pttrunUpttrun.exeTransmeta Crusoe processor related. Reduces application launch times and makes the computer "more responsive"No
PtUDFAppNPtUDFApp.exeSony abCD program, included on the CD Xtreme install CD, used to format CD-RWs for packet writing (similar to DirectCD). Available via Start → Programs. Note that you must add a /T switch to the command line to get it to load to the taskbarNo
PrayerUPTW.EXEIslamic Adhan program (call fpr daily prayers)No
PUAC v2.0.7UPuac.exe"Peter's Ultimate Alarm Clock"No
PubelleUPubelle.exePubelle - French popup blocker by Guillaume RyderYes
_Xpukk.exeDetected by McAfee as RDN/Autorun.worm!db and by Malwarebytes as Trojan.Agent.WMGenNo
pukredalepukXpukredalepuk.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile%No
Push ClientNpull.exeAT&T push client, part of the AT&T Connect Participant Application (was Interwise) - which "is the essential interface to host and fully participate in an AT&T Connect web conference"No
DesktopProfXpulpit.exeDetected by Dr.Web as Dialer.Plsex.21 and by Malwarebytes as Dialer.UlubioneNo
WIN31Xpunisher.exeDetected by McAfee as RDN/Generic PWS.y!tr and by Malwarebytes as Backdoor.Agent.PNNo
PopUpNoNoUpunn.exe"Pop-Up No-No! pop-up blockerNo
Adobe Update ManagerXpunto.exeDetected by Symantec as Trojan.RatopakNo
Punto SwitcherUpunto.exePunto Switcher - Russian keyboard utility which statistically analyses the keys that were pressed. If the distribution of two-symbol pairs appears untypical for the current input language, Punto Switcher switches input languages, emulates Backspace key presses to erase the phrase, and types it again using the correct keyboard layoutNo
puoiwXpuoiw.exeDetected by Malwarebytes as Trojan.FakeAlert. The file is located in %UserProfile% - see hereNo
Microsoft Update 2.2XPuOPGQhAu.exeDetected by Malwarebytes as Backdoor.Bot. The file is located in %LocalAppData%No
Microoft TimingXpupdate.exeDetected by Trend Micro as WORM_RBOT.AKMNo
mspwrUpupstman.exePart of the PowerUp Deluxe (Me/98) tweaking utility from Ashampoo®No
mspwrUpupxpman.exeSystem Tray access to the PowerUp XP (XP/2K/NT) tweaking utility from Ashampoo®No
PwrupTweakMeUPUPXPTWK.EXEBoot-up options for the PowerUp XP (XP/2K/NT) tweaking utility from Ashampoo®No
Puqtbfbwgjqglxsp.exeXPuqtbfbwgjqglxsp.exeDetected by Malwarebytes as Trojan.IRCBrute. The file is located in %AppData%No
purchase order.exeXpurchase order.exeDetected by McAfee as Generic PWS.y!dvk and by Malwarebytes as Spyware.Password. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
(Default)XPurchase.exeDetected by Malwarebytes as Trojan.Keylogger.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
MagerethXPurchase.exeDetected by Malwarebytes as Trojan.Agent.E. The file is located in %UserStartup%No
AswfASDEXPurchase.exeDetected by Malwarebytes as Trojan.Agent.E. The file is located in %UserStartup%No
Purchase.exeXPurchase.exeDetected by Malwarebytes as Trojan.Agent.E. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
fileXPurchaseOrder.exeDetected by Malwarebytes as Trojan.Agent.AI. The file is located in %UserProfile%\DesktopNo
rVFvkXpurchase_order.exeDetected by Malwarebytes as Trojan.Autoit. The file is located in %UserTemp%\rVFvkNo
chromeXpure.exeDetected by Malwarebytes as Backdoor.Agent. The file is located in %AppData%No
purecoaixXpurecoaix.exeDetected by Malwarebytes as Trojan.Downloader. The file is located in %AppData%\purecoaixNo
PureLeadsUPureLeadsTray.exeSystem Tray access to, and notifications for PureLeads - which "Supports direct address bar type in of brands and keywords to navigate the web with fewer web address errors and typos. Presents coupon and savings offers to you when you browse to your favorite Brand sites." Detected by Malwarebytes as PUP.Optional.PureLeads. The file is located in %ProgramFiles%\PureLeads - see here. If bundled with another installer or not installed by choice then remove itNo
PureLeads Notification IconUPureLeadsTray.exeSystem Tray access to, and notifications for PureLeads - which "Supports direct address bar type in of brands and keywords to navigate the web with fewer web address errors and typos. Presents coupon and savings offers to you when you browse to your favorite Brand sites." Detected by Malwarebytes as PUP.Optional.PureLeads. The file is located in %ProgramFiles%\PureLeads - see here. If bundled with another installer or not installed by choice then remove itNo
PureLeads TrayUPureLeadsTray.exeSystem Tray access to, and notifications for PureLeads - which "Supports direct address bar type in of brands and keywords to navigate the web with fewer web address errors and typos. Presents coupon and savings offers to you when you browse to your favorite Brand sites." Detected by Malwarebytes as PUP.Optional.PureLeads. The file is located in %ProgramFiles%\PureLeads - see here. If bundled with another installer or not installed by choice then remove itNo
PureLeadsTrayUPureLeadsTray.exeSystem Tray access to, and notifications for PureLeads - which "Supports direct address bar type in of brands and keywords to navigate the web with fewer web address errors and typos. Presents coupon and savings offers to you when you browse to your favorite Brand sites." Detected by Malwarebytes as PUP.Optional.PureLeads. The file is located in %ProgramFiles%\PureLeads - see here. If bundled with another installer or not installed by choice then remove itNo
PureTextUPureText.exePureText by Steve Miller. "Have you ever copied some text from a web page or a document and then wanted to paste it as simple text into another application without getting all the formatting from the original source? PureText makes this simple by adding a new Windows hot-key (default is WINDOWS+V) that allows you to paste text to any application without formatting"No
PurgatoryXPurga.exeDetected by Sophos as W32/Purgory-BNo
PurgativeUPURGATIVE100.EXEAIM (AOL Instant Messenger) Ad Remover Using Active Memory Edits instead of a patch/crackNo
PurgeIEUPURGEIE.EXEPurgeIE from Assistance & Resources for Computing, Inc. - Internet Explorer browsing history cleanerNo
SureshotpopupkillerUpusak.exeStop-the-Pop-Up popup blockerNo
PUSH6599.EXENPUSH6599.EXEScan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning softwareNo
pussitidsXpussitids1.exeDetected by Malwarebytes as Trojan.Agent.PD. The file is located in %MyDocuments%\WindowsNo
PutAS!XPutA!!.comDetected by Trend Micro as WORM_OPASERV.ZNo
PutA!!XPutA!!.exeDetected by Trend Micro as WORM_OPASERV.LNo
putkb_.exeXputkb_.exeDetected by Dr.Web as Win32.HLLW.Autoruner2.17331 and by Malwarebytes as Worm.AutoRun.ENo
putmuzqihyxtXputmuzqihyxt.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
Terminal Services ControlXputty-patcher.exeDetected by Dr.Web as Trojan.DownLoader11.35147 and by Malwarebytes as Trojan.Agent.TSCNo
puush daemonXpuush.daemon.exeDetected by Symantec as Backdoor.Weecnaw and by Malwarebytes as Trojan.Agent.PUSDNo
puushNpuush.exepuush is a quick and simple way to share screenshots and files. Use keyboard shortcuts or drag-drop gestures to quickly capture any portion of your screen or upload any file. These files are near-instantly puush'd, leaving behind a short URL in your clipboard, perfect for sharing. Paste these easily into your Twitter, IRC or IM clients. Share them with the world or make them private, for your eyes only"No
PwrUpManagerUPuXpMan2.exeSystem Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility - which includes (amongst others) one-click tuning, multiple desktops, taskbar control center and an autostart managerYes
mspwrUPuXpMan2.exeSystem Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility - which includes (amongst others) one-click tuning, multiple desktops, taskbar control center and an autostart managerYes
PuXpMan2UPuXpMan2.exeSystem Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility - which includes (amongst others) one-click tuning, multiple desktops, taskbar control center and an autostart managerYes
PwrupTweakMeUPUXPTWKS.EXEBoot-up options for the PowerUp XP (XP/2K/NT) tweaking utility from Ashampoo®No
PV92TRAYUPV92Tray.exePCtel HSP V.92 modem configuration utilityNo
pvchost.exeXpvchost.exeDetected by Dr.Web as Trojan.Disabler.84 and by Malwarebytes as Trojan.Agent. The file location variesNo
kok15dls15w856+45456Xpvcnrxse.exeDetected by Malwarebytes as Trojan.Backdoor.VB. The file is located in %System%No
PVModuleXpvmodule.exeAdperform.com/Adoptim.com adware - located in %ProgramFiles%\PrintView and detected by Avira AntiVir antivirus as the AGENT.ALB TROJAN! NOTE - the 'real' PrintView installs in C:\CBR folderNo
Windows ConfigXpvphost.exeAdded by a variant of Trojan-Proxy.Win32.Slaper. The file is located in %System%No
PVRNPVR.exePocket Voice Recorder - freeware sound recorder that records from microphone and any other input line available with your sound cardNo
wintorXpvrss.exeDetected by Malwarebytes as Trojan.Agent.SBFGen. The file is located in %AppData%\SubFolder\SubFolderNo
PVUnInst1UPVUnInst1.exePrivacy View - privacy software that ensures that all your private computer files, photos, documents, and websites remain secure from prying eyesNo
AntivirusXpwa.exePower Antivirus rogue security software - not recommended. Detected by Microsoft as Win32/FakeSecSenNo
PasswordAgentUPwAgent.exe"Password Agent is an easy-to-navigate password management program that allows you to store all your passwords, secret notes and data snippets in a single, secure database"No
DocuMagix InitNPWATCH.EXEPaperMaster is an application for the PC designed to automate the process of organizing, archiving, and retrieving digital versions of files. Start manually if neededNo
PwdBank?PwdBank.exeRelated to the TrueSuite Access Manager fingerprint recognition utility available on some Toshiba, Lenovo and maybe other laptops - based upon TrueSuite by AuthenTec (since acquired by Apple). What does it do and is it required?No
Bench Communicator WatcherUpwdg.exeDetected by Malwarebytes as PUP.Optional.Bench. The file is located in %ProgramFiles%\Bench\Proxy. If bundled with another installer or not installed by choice then remove itNo
Microsoft WindowsXpwjbvphi.exeDetected by Sophos as W32/Rbot-GQK and by Malwarebytes as Backdoor.IRCBotNo
PwmConsole.exeYPwmConsole.exe"Trend Micro DirectPass manages website passwords and login IDs in one secure location, so you only need to remember one password." Now superseded by Trend Micro Password ManagerNo
pwmgrYpwmgr.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks - IBM® Client Security Password Manager "enables you to manage your sensitive and easy-to-forget login information, such as user IDs, passwords, and other personal information, with IBM Client Security. The IBM Client Security Password Manager stores all information through the IBM Security Chip so that your UVM user authentication policy controls access to your secure applications and Web sites." Can also be used with or without the Fingerprint Reader on select modelsYes
IBM Password ManagerYpwmgr.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks - IBM® Client Security Password Manager "enables you to manage your sensitive and easy-to-forget login information, such as user IDs, passwords, and other personal information, with IBM Client Security. The IBM Client Security Password Manager stores all information through the IBM Security Chip so that your UVM user authentication policy controls access to your secure applications and Web sites." Can also be used with or without the Fingerprint Reader on select modelsYes
IBM_PWMGRYpwmgr.exePart of Client Security Software (CSS) for IBM\Lenovo notebooks - IBM® Client Security Password Manager "enables you to manage your sensitive and easy-to-forget login information, such as user IDs, passwords, and other personal information, with IBM Client Security. The IBM Client Security Password Manager stores all information through the IBM Security Chip so that your UVM user authentication policy controls access to your secure applications and Web sites." Can also be used with or without the Fingerprint Reader on select modelsYes
Power MixerUpwmixer.exePower Mixer by Actual Solution - "is an advanced Windows audio mixer, a complete replacement for the standard Windows volume control. This application lets you easily change the sound volume just by rotating the mouse wheel or by using keyboard hot keys"No
updatehXpwned.exeDetected by Dr.Web as Trojan.DownLoader11.26016 and by Malwarebytes as Trojan.Agent.ENo
Pwr32crtlXpwr32crtl.exeDetected by Trend Micro as TROJ_CRYPTER.ANo
Pwr32ctrXpwr32ctr.exeDetected by Trend Micro as TROJ_CRYPTER.ANo
Pwr32ctrlXPwr32ctrl.exeDetected by Symantec as Trojan.GemaNo
Pwr32mgtXPwr32mgt.exeDetected by Symantec as Trojan.GemaNo
PowerChuteXPwrchute.exeDetected by Sophos as Troj/Lazar-A. Note - this is not the legitimate APC PowerChute software User Interface Module which has the same filename and is normally located in %ProgramFiles%\Pwrchute. This one is located in %ProgramFiles%\APC_PowerNo
PowerChuteYPwrchute.exeAPC PowerChute software which controls their range of uninterruptible power supplies (UPS) - to provide unattended shutdown of servers and workstations in the event of an extended power outage and status logging. This is the User Interface Module for an older version - see here and hereNo
PWRESETUpwreset.exeRelated to the Avaya IP SoftphoneNo
PWRISOVM.EXENPWRISOVM.EXEPowerISO - a powerful CD/DVD image file processing toolNo
PwroffXPwroff.exeDetected by Symantec as Trojan.GemaNo
PwrsaveUPwrsave.exeToshiba Power Saver utility - which "manages the power consumption of various devices on Toshiba notebook computers. Its primary purpose is to extend the amount of time that your machine can run from its battery or batteries"No
LidPolicyUpwrschem.exeHP utility for configuring supported notebook models to enter Standby mode when the lid is closed only when running on batteryNo
mspwrUpwrupst.exePart of the PowerUp XP (XP/2K/NT) tweaking utility from Ashampoo®No
atitoolXpwrwin.exeDetected by Symantec as W32.Yazz and by Malwarebytes as Trojan.AgentNo
PwSaveUPwSave.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3+ - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors the energy savings made via the EPU and when the Energy Saving option of AI Gear 3+ is selected it displays the current status and provides access to the calculatorYes
PwSave.exeUPwSave.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3+ - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors the energy savings made via the EPU and when the Energy Saving option of AI Gear 3+ is selected it displays the current status and provides access to the calculatorYes
ASUS Energy SavingUPwSave.exePart of the AI Suite system management utility included with some ASUS motherboards. This entry is part of AI Gear 3+ - "a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features. This easy-to-use utility provides four system performance profiles that adjusts the processor frequency and vCore voltage for different computing needs." Monitors the energy savings made via the EPU and when the Energy Saving option of AI Gear 3+ is selected it displays the current status and provides access to the calculatorYes
PWS TrayUPwsTray.exeMicrosoft's Personal Web Server, an application which allows PCs to behave as web servers (allows you to test your .asp pages on your own PC without having to load them onto the internet). Available via Start → ProgramsNo
Password Tracker DeluxeUPwTrkr.exe"Password Tracker Deluxe stores passwords and usernames neatly and securely (encrypted) on your computer"No
uaafvxXPwTuuGhrj.exeDetected by Malwarebytes as Trojan.MSIL. The file is located in %Windir%No
AntivirusXpwx.exePower Antivirus rogue security software - not recommended. Detected by Microsoft as Win32/FakeSecSenNo
pxador.exeXpxador.exeDetected by McAfee as RDN/PWS-Banker!cy and by Malwarebytes as Trojan.Banker.E. The file is located in %Root%\Arquivos de programas\Microsoft Office\Office\bots\msgNo
pxador.exeXpxador.exeDetected by Dr.Web as Trojan.Starter.2241 and by Malwarebytes as Trojan.Banker.E. The file is located in %Windir%\msapps\msinfo\aprouchNo
pxador.exeXpxador.exeDetected by McAfee as Generic Downloader.c and by Malwarebytes as Trojan.Banker.E. The file is located in %Windir%\wdfmgrNo
PrevxOneYPXConsole.exePrevX (now Webroot) behaviour-based anti-malware protectionNo
PYJJIMEXPYJJKIME.exeDetected by Sophos as Troj/Agent-BXQNo
DhcpCepXPYJJKIME.exeDetected by Sophos as Troj/Agent-BXQNo
pymydoncatbiXpymydoncatbi.exeDetected by Malwarebytes as Trojan.Agent.US. The file is located in %UserProfile%No
ROCCAT Pyra MouseUPyraMonitor.EXEROCCAT Pyra gaming mouse driver - required if you use the additional features and programmed keys/macrosNo
PyroAntiSpyXPyroAntiSpy.exePyroAntiSpy Russian rogue spyware remover - not recommended, removal instructions hereNo
pyrobatchftpUpyrobatchftp.exe"PyroBatchFTP lets you transfer files to/from FTP/SFTP servers in an automatic and unattended way through a simple to learn batch/script language"Yes
pyrobatchftp.exeUpyrobatchftp.exe"PyroBatchFTP lets you transfer files to/from FTP/SFTP servers in an automatic and unattended way through a simple to learn batch/script language"Yes
PyroTransUpyrobatchftp.exe"PyroBatchFTP lets you transfer files to/from FTP/SFTP servers in an automatic and unattended way through a simple to learn batch/script language"Yes
AnskyaXPYSKY.NET.exeDetected by Sophos as Troj/Dloader-MWNo
SearchAYUpythonw.exe ml.py --APPNAME='SearchAY'Detected by Malwarebytes as PUP.Optional.StartPage. The files are located in %AppData%\SearchAY\python and %AppData%\SearchAY respectively. If bundled with another installer or not installed by choice then remove itNo
setupskUpythonw.exe ml.py --APPNAME='setupsk'Detected by Malwarebytes as PUP.Optional.StartPage. The files are located in %AppData%\setupsk\python and %AppData%\setupsk respectively. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
setupsk_updUpythonw.exe ml.py --APPNAME='setupsk_upd'Detected by Malwarebytes as PUP.Optional.StartPage. The files are located in %AppData%\setupsk\python and %AppData%\setupsk respectively. If bundled with another installer or not installed by choice then remove it, removal instructions hereNo
PrepareYourVAIO?PYVAlert.exe"Prepare your VAIO" utility for Sony Vaio computers. What does it do and is it required?No
Windows LoL LayerXpyvnpt.exeDetected by Sophos as W32/Rbot-GKV and by Malwarebytes as Backdoor.BotNo
DXM6Patch_981116Np_981116.exeWin32 cabinet self extractor. More info hereNo
p_981116Np_981116.exeWin32 cabinet self extractor. More info hereNo
P_gunxefgtfXP_gunxefgtf.exeDetected by McAfee as W32/Worm-FSE!Gamarue and by Malwarebytes as Backdoor.Agent.ENo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a list of tasks/processes taken from the Task Manager (CTRL+SHIFT+ESC) "Processes" tab. This displays some startup programs AND other background tasks and "Services". These pages are concerned with startup programs from the common startup locations shown above ONLY. Please do not submit entries collected from this method as they will not be used. For a list of tasks/processes you should try the list at PC Pitstop, the Process Library from Uniblue or one of the many others now available.

Therefore, before ending a task/process via CTRL+SHIFT+ESC just because it has an "X" recommendation, please check whether it's in the registry or common startup locations first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+SHIFT+ESC. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 25K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entries listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program.

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the Windows 8/7/Vista/XP/2K/NT operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2017 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home