Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
U Evoluent Mouse Manager EvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
X EvtHtm evthtm.exe"Added by the DLUCA-EJ TROJAN!"
U EvtMgr6 Setpoint.exe"Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice
U EW Message Server msg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
N eWare Startup iWareStart.exe"eWare iWare task bar. Not required"
Y ewido ewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
Y ewido anti-spyware ewido.exe"System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
X ewrgetuj geurge.exe"Added by the AUTOINF-AK WORM!"
X Ewth tasn.exe"PurityScan adware"
X ewupdater ewupdater.exe"EasyWebSearch adware updater"
X example [random filename].exe"Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
N Excite Platform Exlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
? Excite Private Messenger Pipe x8impipe.exe"??"
N ExciteAssistantEXE ASSISTANT.EXE"With Excite Assistant
X exdl.exe exdl.exe"BargainBuddy adware"
X exe lptt01 exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X exe ml097e exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X execfg4 execfg4.exe"Added by the ELECTRON WORM!"
X ExecUser ExecUser.exe"Added by a variant of the RBOT WORM!"
? Execute delfolders.exe"??"
X ExeName32 Warm.scr"Added by the SCOLD WORM!"
X ExFilter "Rundll32.exe [path] cdnspie.dll ExecFilter"
? exgiwsl exgiwsl.exe"??"
U Exif Launcher Exiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U Exif Launcher QuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U ExitKiller Ekiller.exe"Exit Killer - automatically closes pop-up windows in your browser"
? exmon hpimoniter.exe"Some kind of hp digital camera maybe or a photo smart connection probe?"
X Exn exn.exe"Added by the IRCBOT.RJ WORM!"
X exo.exe exo.exe"Added by the AGOBOT.ALD WORM!"
X exp1orer.exe exp1orer.exe"Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename
X Expatch [random filename]"Added by the PWSLMIR-G TROJAN!"
X expcrt [random filename]"Added by a variant of the SLAPER TROJAN!"
X ExpertAntivirus ExpertAntivirus.exe"ExpertAntivirus rogue security software - not recommended
X EXPL0RE.EXE EXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
X Expl0rer soft expl0rer.pif"Added by the RBOT-AQR WORM!"
X expler Updadv.exe"Added by the QQPASS-N TROJAN!"
X Explkw expup.exeKeywords hijacker
X explord.exe explord.exe"Added by the DLOADR-AYW TROJAN!"
X explore explore.exe"Added by any number of VIRUSES
X Explore Explorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Explore explore.exeAdult content dialler
X Explore PLORE.EXE"Added by the FORBOT-P WORM!"
X explore manager explore.exe"Added by the DONBOMB.A TROJAN!"
X explore.exe Explore.exe"Added by the GRAYBIRD.G TROJAN!"
X exploreff.exe exploreff.exe"Added by the FINFANSE TROJAN!"
X explorep.exe explorep.exe"Added by the LINEAG-I TROJAN!"
U explorer explorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
X explorer wscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
X Explorer shellexpl.exe"Added by the SHELDOR TROJAN!"
X explorer expl32.exe"Added by the RATSOU TROJAN!"
X Explorer [path to worm]"Added by the AUTEX WORM!"
X Explorer shellexp.exe"Added by the AGENT-ZY TROJAN!"
X EXPLORER EXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
X EXPLORER sys.exe"Added by the SILLYFDC-A TROJAN!"
X Explorer config_.com"Added by the FLOPPY-D WORM!"
X Explorer drv.exe"Added by the SMALL-FD TROJAN!"
X explorer [path to trojan]"Added by the AGENT-EU TROJAN!"
X explorer explorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
X EXPLORER EXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
X explorer explorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
X explorer Yinstall.exe"PurityScan/Clickspring adware"
X Explorer Windows Explorer.exe"Added by the SILLYFDC-I WORM!"
X Explorer explorar.vbs"Added by the DESKTO-A WORM!"
X Explorer TXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
X explorer system.exe"Added by the AGENT-FI TROJAN!"
X Explorer msrstart.exe"Added by the SOPICLICK TROJAN!"
X explorer main.vbe"Added by the SHUSH-A WORM!"
X Explorer 2238 [path to trojan]"Added by the AGENT-CPI TROJAN!"
X Explorer Loader explr32.exe"Added by the AGOBOT.N WORM!"
X Explorer Loader explorerl.exe"Added by the SDBOT-ADI WORM!"
X Explorer lptt01 explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
X EXPLORER MICROSOFT SYSTEM explore.exe"Added by a variant of the RBOT WORM!"
X Explorer ml097e explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
X Explorer soft explorer.pif"Added by the RBOT-APK WORM!"
X Explorer soft explorer.com"Added by the RBOT-ARM WORM!"
X Explorer Updater IEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X explorer.exe explorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X explorer.exe explorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
X Explorer.exe csrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
X Explorer32 Expl32.exe"Added by the HACKTACK.B TROJAN!"
X Explorer32 explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
X Explorer32 efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
X Explorer5 config_.com"Added by the VB.CBG WORM!"
X Explorer6.1.EXE Explorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
X explorerf.exe explorerf.exe"Added by the AGENT-GDZ TROJAN!"
X ExplorerRun conime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
X ExplorerTask explorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
X ExploreUpdSched [random filename]"ZenoSearch adware"
X exporet winset.exe"Added by the QQPASS-I TROJAN!"
U Express ClickYes ClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt
U Exshow95 EXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
N Extender Resource Monitor RMSysTry.exe"Related to Windows Media Center from Microsoft"
X External Dependencies External.exe"Added by the MYTOB.EC WORM!"
X Extra Antivirus ExtraAV.exe"Extra Antivirus rogue security software - not recommended
U ExtraDNS ExtraDNS.exe"ExtraDNS - DNS configuration tool"
N ExtraFilmHemmaAgent Agent.exe"ExtraFilm Photo Assistant"
? Extranet AutoDial AutoExt.exeNortel Networks Contivity Extranet Switching Software
? ExxtremeHelperDemon exxdemon.exe"Creative Exxtreme graphics card related?"
N Eye Tide Launcher oneeyetideone.exeNascar wallpaper
X EYORE Notepad.scr"Added by the GIMLET-A WORM!"
Y EZ Firewall ca.exe"eTrust EZ Armor Internet Security"
U EZ-DUB Finder EZ-DUB.exe"Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
N ezagent ezagent.exe"EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
N EzButton EzButton.EXEEZbutton is a quick launcher for the Media player app that comes with certain laptops
N EZDesk EZDESK.EXE"Utility that remembers icon locations for each user and resolution. Available here"
U EZEJMNAP EzEjMnAp.Exe"EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
N EZEJTRAY EZEJTRAY.EXE"System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once
N ezHelper ezHelper.exe"Part of the ezPeer+ ezHelper music sharing program."
X eZmmod mmod.exe"eZula TopText adware"
? EZNORUN EZNORUN.EXE"Easy Internet related?"
N EzPrint ezprint.exe"Lexmark Fast Pics - helps users of their printers to enhance
Y ezPS_Px ezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezPS_Px ezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezShieldProtector for Px ezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezShieldProtector for Px ezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
U EZSMART App ezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
U EzTune dthtml.exe"EzTune from Gateway. Rebranded version of Display Tune from Portrait Displays
X ezula eZmmod.exe"eZula TopText adware"
X eZulaMain eZulaMain.exe"eZula TopText adware"
X eZuluMain eZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
X eZWO wo.exe"eZula TopText adware"
U E_S10IC2 E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status
U E_S23 E_SICN03.exe"Epson printer status monitor - for checking ink levels
U E_S4I2F1 E_S4I2F1.EXE"Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status
U E_S4I2G1 E_S4I2G1.EXE"Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status
U E_SOEIC1 E_SOEIC1.exe"Epson Status Monitor 3 - for monitoring printer status
U E_S[numbers] [path] E_[various].EXE [path] E_S[numbers].tmp"Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status
X f ftkclean.exe"FlashEnhancer adware"
U F-PROT Antivirus Tray application FProtTray.exe"System Tray access to F-PROT Antivirus"
X F-Secure 2005 svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Y F-Secure 2006 fspex.exe"F-Secure Anti-Virus automatic updater"
X F-Secure Gatekeeper [malware name].exe"Added by the NUWAR.AXQ WORM!"
U F-Secure Management Agent FSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
Y F-Secure Manager FSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
Y F-Secure Startup Wizard FSSW.EXE"F-Secure antivirus"
Y F-Secure TNB TNBUtil.exe"F-Secure antivirus"
Y F-StopW F-StopW.exe"F-Prot anti-virus background scanner by F-Risk Software"
U f1Tray.exe F1TRAY.EXE"System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
? f23mxins f23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
X f2install.exe f2install.exe"Added by the IEFEAT-I TROJAN!"
U F5D7050v3 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
U F5D8001 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
U F5D8011 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
U F5D8055v1 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
U F5D8071 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
U F5D9010 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
U F5D9050 Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
X f607 f607.exe"Added by the URAT.B TROJAN!"
X f73cdc8ee94e btsendto.exeAssociated with mysearchnow.com/searchbar.html
X f94mggfhfghodftdf [path to trojan]"Added by the SMALL.JHZ TROJAN!"
U Fabrik Ultimate Backup Status fabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink
X FaltCheck allps.exe"Added by the AGENT.RAP TROJAN!"
U FamilyKeyLogger cisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
X Fantasia injector wincfg.exe"Added by the AGOBOT.US WORM!"
? fapmon fapmon.exe"Fair Access Policy monitor for DirecPC/DirecWay internet access"
X farkrish farkrish.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X farmmext farmmext.exe"VX2.Transponder parasite updater/installer related"
X Fash Fash.exeUnidentified adware
X faslkakj11 kjgagklj11.exe"Added by the LEGMIE-ARE TROJAN!"
N fast fast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
X fast A-fast.exe"A-fast Antivirus rogue security software - not recommended
X Fast Antivirus 2009 FastAV.exe"Fast Antivirus rogue security software - not recommended
N FAST Defrag FAST2.EXE"FastDefrag defragmenting software"
X Fast Home svcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines
X Fast Search svcnv.exe"Homepage
X Fast start Ntut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
X Fast start svcnt.exe"Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
U FastCache fc.exe"FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
X FastDownloads "rundll32.exe MSA64CHK.dllDllMostrar"
X fastsmell fastsmell.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X FastStart ntnut32.exe"Added by the STARTPAGE.L TROJAN!"
X FastStart svcnut.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
X FastStart svcnut32.exe"Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
N FastTrack Accelerator SPEED UP.EXE"FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop
X FASTTRACKNETVISION NETVISION.exe"DialCar-Z premium rate dialer"
U FastTVSync FastTVSync.exe"Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps
N FastUser fast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
N FastUsr fast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
X faT faT.exe"Added by the BANKER-DFP TROJAN!"
X fat.exe fat.exe"Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended
X Fat32 Microsoft fat32.exe"Added by the RBOT-EL WORM!"
U FatPipe DHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
U Fatpipe Dialer fpdialer.exeDailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
U fatrecov fatrecov.exeSCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
U FavoriteSync FavoriteSync.exe"FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
U FaxCenterServer fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
U FaxCenterServer4_in_1 fm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark
U FaxCtrl.exe ASMediaProxyServer.exe"Part of Avaya's Contact Center Express - ""a multi-channel
N FaxTalk CallControl 6.0 FTClCtrl.EXEThis allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
U FBDirect FBDirect.exe"Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan
? FBI FBISM.exe"Compaq related but what does it do?"
X FBSearch FastBrowserSearchProtection.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
X FBSearch SearchGuardPlus.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
X FBSSA ie3sh.exe"Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo
X fc runfc.exe"Added by the CAMPURF WORM!"
X FCEngine FCEngine.exe"CASClient adware"
X FCHelp FCHelp.exe"Added by either FCHelp adware or a variant of it"
X FCMan FCMan.exe"FCHelp adware"
X Fdaemon security fsecur.exe"Added by the SDBOT.KXO WORM!"
X FDD SYSTEM Fdd.exe"Added by the MYTOB-FO WORM!"
X fddddHOME dxxatp.exe"Added by the RANKY.AA TROJAN!"
X Fdr Command Module sp2.exe"Added by the SDBOT.WP WORM!"
X FDriver windrv.exe"Added by the DELF.WG TROJAN!"
U FD_SAP FD.exeReported to be the autopassword program from the Sony Microvault thumb drive
X FeCPY fecpy.exe"FlashEnhancer adware"
U feedreader.exe feedreader.exe"""Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"""
X feelalright mirc.exe"Added by the IRCFLOOD-M WORM!"
U FEELitDeviceManager feelitdm.exeAssociated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
X fegoze SVCH0ST.EXE"Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
U Fellowes Proxy R3proxy.exeInstalled with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
X Fen Startups fensvc32.exe"Added by the RANDEX.CCF WORM!"
X Fenio Startups fnesvc32.exe"Added by the AGOBOT-OS BACKDOOR!"
U FerrariWallPaper FerrariWP.exeCalendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
X FestPlattenCleaner SysRep.exe"FestPlattenCleaner
X FestplattenReiniger GDC.exe"FestplattenReiniger
X ff [path to worm]"Added by the RBOT-XL WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list