| X | cyberfree.exe | ****.dat [* = random char] | Unidentified adware
|
| U | CyberLat Ram Cleaner | CLRamCleaner.exe | "CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| U | CyberLat Ram Cleaner | CyberLat Ram Cleaner 1.1.exe | "CyberLat RAM Cleaner - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| N | Cyberlink PowerCinema 3.0 | PCMService.exe | "Part of Cyberlink's PowerCinema - which can be used to watch movies |
| N | CyberMedia Agent | CMAGENT.EXE | "Part of CyberMedia's Oil Change program. Not normally required. Note - if you have TextBridge |
| U | CyberPatrolNew | cphq.exe | """CyberPatrol is one of the most powerful and popular client-based |
| ? | CYNHKey | CYNHKey.exe | "??"
|
| U | CypressLinkMon | CypressLinkMon.exe | "Related to CypressViewer from Siemens that ""allows ACUSON Cypress cardiovascular system PLUS users to store |
| Y | D-Link Air USB Utility | AirCFG.exe | D-Link Air USB wireless driver and configuration utility
|
| Y | D-Link Air Utility | AirCFG.exe | D-Link Air PCI wireless driver and configuration utility
|
| N | D-Link AirPlus DWL-650+ Utility | WLANMON.exe | D-Link Air Plus Wireless PC modem connection monitor
|
| Y | D-Link AirPlus G | AirGCFG.exe | D-Link Airplus G wireless router driver and configuration utility
|
| Y | D-Link AirPlus G Wireless Utility | AirPlus.exe | "D-Link AirPlus G wireless configuration and monitoring utility"
|
| Y | D-Link AirPlus XtremeG | AirPlusCFG.exe | "D-Link AirPlus Xtreme G wireless access point driver and configuration utility"
|
| Y | D-Link D-Link DWA-125 | AirGCFG.exe | "D-Link DWA-125 Wireless 150 USB adapter driver and configuration utility"
|
| Y | D-Link D-Link RangeBooster N DWA-140 | AirNCFG.exe | "D-Link DWA-140 RangeBooster N USB adapter driver and configuration utility"
|
| Y | D-Link D-Link Wireless 108G DWA-120 | AirPlusCFG.exe | D-Link DWA-120 Wireless 108G USB adapter driver and configuration utility
|
| Y | D-Link D-Link Wireless 108G DWA-520 | AirPlusCFG.exe | D-Link DWA-520 Wireless 108G desktop adapter driver and configuration utility
|
| Y | D-Link D-Link Wireless G DWA-110 | AirGCFG.exe | D-Link DWA-110 Wireless G USB adapter driver and configuration utility
|
| Y | D-Link D-Link Wireless G DWA-510 | AirGCFG.exe | D-Link DWA-510 Wireless G desktop adapter driver and configuration utility
|
| Y | D-Link D-Link Wireless N Dual Band DWA-160 | AirNCFG.exe | "D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
|
| Y | D-Link D-Link Wireless N DWA-130 | AirNCFG.exe | "D-Link DWA-130 Wireless N USB adapter driver and configuration utility"
|
| Y | D-Link D-Link Xtreme N Dual Band DWA-160 | AirNCFG.exe | "D-Link DWA-160 Xtreme N Dual Band USB adapter driver and configuration utility"
|
| Y | D-Link RangeBooster G WDA-2320 | AirPlusCFG.exe | "D-Link WDA-2320 RangeBooster G desktop adapter driver and configuration utility"
|
| Y | D-Link RangeBooster G WUA-2340 | AirPlusCFG.exe | "D-Link WUA-2340 RangeBooster G USB adapter driver and configuration utility"
|
| Y | D-Link Wireless G WDA-1320 | AirGCFG.exe | "D-Link WDA-1320 Wireless G desktop adapter driver and configuration utility"
|
| Y | D-Link Wireless G WUA-1340 | AirGCFG.exe | "D-Link WUA-1340 Wireless G USB adapter driver and configuration utility"
|
| X | D3**.exe [* = random char] | D3**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | D3**32.exe [* = random char] | D3**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | dabrun | "rundll32.exe dabapi.dll | Rundll32" |
| N | DACONFIGEXE | daconfig.exe | 3Com NIC Diagnostics. Available via Start -> Programs
|
| N | Daemon | DAEMON32.EXE | Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
|
| N | daemon | daemon.exe | "Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| X | Daemon | daemon.exe c daemon2.exe | "Added by the SELOTIMA.A WORM!"
|
| N | DAEMON Tools | daemon.exe | "Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools Lite | daemon.exe | "Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools Lite | DTlite.exe | "Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools Pro | DTAgent.exe | "System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools Pro Agent | DTProAgent.exe | "System Tray access to an older version of DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools Pro Agent | DTAgent.exe | "System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DAEMON Tools-1033 | daemon.exe | "Older version of Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | Daily Planner | dayplan.exe | "Daily Planner - discontinued |
| X | DanBtR270414 | DanBtR270414.exe | "Added by the VB-NIB WORM!"
|
| U | Dancer | DncLE.exe | "Part of Microsoft Plus! Digital Media Edition - see here"
|
| X | Danton* | [random filename] | "Added by the DANTON TROJAN! where * = random number"
|
| X | DarKNesS LsasS | LsasS23.exe | Added by an unidentified WORM or TROJAN!
|
| ? | DashIE | N/A | "Could be related to "Dash Power Shopping" tool bar in IE?"
|
| X | data | msngs.exe | "Added by the RBOT-ADQ WORM!"
|
| N | Data LifeGuard LifeLine Lite installer | DLGLI.EXE | "Backweb installer - see here"
|
| X | Data Protection | datprot.exe | "Data Protection rogue security software - not recommended |
| N | DataCaching | FlashKsk.exe | "SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon"
|
| N | DataViz Inc Messenger | DvzIncMsgr.exe | "Installed with DataViz ""Documents to Go"" software"
|
| N | DataViz Messenger | DvzMsgr.exe | "DataViz Documents to Go - "allows you to use your Word |
| X | Date Manager | datemanager.exe | "Date Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| ? | Datechecker | N/A | "Could be related to this?"
|
| X | DateMakerIntl | DateMakerIntl.exe | Premium rate adult content dialler
|
| X | DateMngr | DATEMNGR.EXE | "Added by the SPYBOT-BR BACKDOOR!"
|
| U | DAZEL Delivery Agent | DcDaemon.exe | "Control and send documents |
| U | DC300 Monitor | cmonitor.exe | Monitor for a Acer DC300 digital camera
|
| X | DC6 | dc6_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | DC6_check | dc6_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | dc6_check | dcmon.exe | "SystemDoctor rogue security software - not recommended |
| X | DCE Manager | dcemgr.exe | "Added by the TUMAG TROJAN!"
|
| X | DCOM Server | [path to trojan] | "Added by the AGENT-CCQ BACKDOOR!"
|
| N | DDCActiveMenu | DDCActiveMenu.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | DDCM | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | DDCMan | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| X | ddivmwa | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| U | DDLAgent | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| X | DDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| ? | DDT | N/A | "??"
|
| U | DDWMon | ddwmon.exe | "Direct Disc Writer Event Monitor from TOSHIBA"
|
| X | de32gen | de32gen.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| N | DeadAIM | "rundll32.exe DeadAIM.ocm | ExportedCheckODLs" |
| X | DealHelperDown | download.exe | "DealHelper adware"
|
| X | DebugMonitor | debugmonitor.exe | "Added by the MYDOOM.BG WORM!"
|
| U | DeeEnEs | DeeEnEs.exe | "DeeEnEs - automatically updates a dynamic IP address when it changes"
|
| X | Deewoo | ncntnkwd.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| U | Default Manager | DefMgr.exe | "Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
|
| X | DefaultConfiguration | defaultconfh.exe | "Added by the AGOBOT-JC WORM!"
|
| X | Default_Page_URL | http://find.naupoint.com | "Naupoint browser hijacker"
|
| X | Default_Search_URL | http://find.naupoint.com | "Naupoint browser hijacker"
|
| X | DefendAPc | DefendAPc.exe | "DefendAPc rogue security software - not recommended |
| X | defender | defender25.exe | "DollarRevenue adware"
|
| X | defender | dfndref_7.exe | "DollarRevenue adware"
|
| X | defender | [path to trojan] | "Added by the VB-BAQ TROJAN!"
|
| X | DefensaAntiMalware | pgs.exe | "DefensaAntiMalware |
| X | Defense Center | defcnt.exe | "Defense Center rogue security software - not recommended |
| X | DefenseNetSurfage | GDC.exe | "DefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | defragm_check | defragment.exe | "CoolWebSearch parasite variant"
|
| U | Delay | delayrun.exe | On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
|
| X | DelayLoad | msprint.exe | "Added by a variant of the Win32.Agent.ryo malware - see here"
|
| U | Delayrun | delayrun.exe | On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
|
| U | Dell AIO Printer A920 | dlbkbmgr.exe | System Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
|
| U | Dell AIO Printer A940 | dlbabmgr.exe | System Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
|
| U | Dell AIO Printer A960 | dlbfbmgr.exe | System Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
|
| N | Dell Alert | DAMon.exe | ""Dell Alert" utility |
| U | Dell DataSafe Scheduler | DataSafeOnlineScheduler.exe | "Scheduler for Dell DataSafe™ Online which ""helps protect your music |
| U | Dell PanelMgr | SSMMgr.exe | "Monitors ink levels |
| U | Dell Photo AIO Printer 922 | dlbtbmgr.exe | System Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
|
| U | Dell Photo AIO Printer 942 | dlbubmgr.exe | System Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
|
| U | Dell Photo AIO Printer 962 | dlbxmon.exe | DellPhoto AIO Printer 962 Device Monitor
|
| Y | Dell Webcam Central | WebcamDell.exe | "Dell Webcam Central - webcam management software controlling aspects such as picture control |
| N | DELL Webcam Manager | DellWMgr.exe | Dell Webcam Manager - Webcam management software provided on Dell PCs
|
| N | Dell Wireless Manager UI | wltray.exe | System tray access to wireless LAN card configuration options
|
| Y | DellAutomatedPCTuneUp | PTAgnt.exe | "PC TuneUp from Dell - ""silently monitors your system |
| U | DellSupport | DSAgnt.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| U | DellSupportCenter | sprtcmd.exe /P DellSupportCenter | "Dell Support Center (provided by SupportSoft |
| ? | DellTransferAgent | TransferAgent.exe | "Found on Dell computers. What does it do and is it required?"
|
| X | delsubmit | "rundll32.exe advpack.dll | DelNodeRunDLL32 submit.exe" |
| X | DeluxeCommunications | Dxc.exe | "Deluxe Communications adware - successor to SurfSideKick"
|
| ? | demon | demon.exe | "Part of the French Wanadoo ADSL extense pack. What does it do and is it required?"
|
| X | Deneca | Virus salvado | "Added by the DELUZ VIRUS!"
|
| X | DescargaBromas | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| ? | Description of Shortcuts | *.exe | "* seems to be a sequence of alphanumerics that can be different |
| X | Desktop | "rundll32.exe msconfd.dll | Restore ControlPanel" |
| X | desktop | desktop.ini.vbs | "IE-Title malware"
|
| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| X | Desktop Defender 2010 | Desktop Defender 2010.exe | "Desktop Defender 2010 rogue security software - not recommended |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| N | Desktop Plant | AZARE10S.PLT | "Vritual plant from here - this version is an Azalea |
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| U | DesktopIconToy | DesktopIconToy.exe | """Desktop Icon Toy is an easy to use desktop icon enhancement tool |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Deus Cleaner | DCleaner.exe | "Deus Cleaner rogue system cleaner utility - not recommended"
|
| ? | DevconDefaultDB | READREG | "Appears to be related to older Creative Soundblaster soundcards"
|
| X | Development Environment | devenv.exe | "Added by the DELBOT-AH WORM!"
|
| U | DEventAgent | eventagt.exe | DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
|
| X | devenv | smvss.exe | "Added by the DEDLER-G TROJAN!"
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Device Hardware | devicehnd.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Management | wnsystem.exe | "Added by the AGOBOT-LH WORM!"
|
| X | Device Manager | wfxmgr.exe | "Added by the RBOT.AJU WORM!"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Devicewin | [path to trojan] | "Added by the BANKER-AEV TROJAN!"
|
| X | dfgfdgrergd | [path to trojan] | "Added by the RANKY.CK TROJAN!"
|
| Y | dhcpagnt | dhcpagnt.exe | Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
|
| ? | DHNUXB | DHNUXB.exe | "??"
|
| N | diagent | diagent.exe | System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
|
| X | Diagnostic | diagnostic.exe | "Added by the ALPHA-C TROJAN!"
|
| X | Diagnostic Agent | diagent.exe | "Added by the AGOBOT-CW WORM!"
|
| X | Dialer | "rundll32.exe MSA32CHK.dll | Reg" |
| U | Dialer Control | dc.exe | "Dialer-Control. Detects and protects from premium rate adult content diallers"
|
| U | Dialgo SDK | PhoneAnswer.exe | "Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID |
| X | DialNet | mxt32.exe | Adult content dialler
|
| N | Dialog Box Assistant | OSDEx.exe | "Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
|
| X | DialUp Network Application | Rnaap.exe | "Added by a variant of the SDBOT WORM!"
|
| U | Diamondback | razerhid.exe | "Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| ? | Diamondview | Diamondview.exe | "Manulife Financial Insurance program. Is it required at startup?"
|
| X | DigiD | DigitalSound.exe | Adware downloader
|
| N | DigiGuide | CLIENT.EXE | TV guide and reminder
|
| N | DigiGuide | client01.exe | TV guide and reminder
|
| U | Digisoft AntiDialer | AntiDialer.exe | "Digisoft AntiDialer"
|
| N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
|
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| N | Digital River eBot | downlo~1.exe | "Digital River Systems EBOT for downloading software from their site. In some cases |
| X | DigitalNames | DigitalNamesStart.exe | "DigitalNames spyware variant"
|
| N | DigitalWizard Monitor | dwMon.exe | "InstallShield's DigitalWizard - free |
| U | Dimension | Dimension.exe | "Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames |
| U | Dimension4 | d4.exe | "Dimension 4 - network time synchronization freeware - starts-up |
| X | Dino3 | dino3.exe | Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
|
| X | Dinst | dinst.exe | "IMIServer/IEPlugin adware"
|
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | Direct X Opengl | dxopengl.exe | "Added by a variant of the RBOT-CJ WORM!"
|
| X | Director Video | btnmgern.exe | "Added by the MYTOB-KL WORM!"
|
| X | directx | NTCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| ? | Disable EHCI | nousb20.exe | "??"
|
| X | DisableKeybaord | "Rundll32.exe Keyboard | Disable" |
| X | DisableMouse | "Rundll32.exe Mouse | Disable" |
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| U | Disk Cleaner | DiskCleaner.Exe | "Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Essensial Tools | detsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | [path to trojan] | "Added by the SMALL-VE TROJAN!"
|
| X | Disk Manager | diskver.exe | "Added by the RBOT.AQT WORM!"
|
| X | Disk Master | [trojan name] | "Added by the DISTER TROJAN! - a spam relayer"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | Disk Panel Setup | npcsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| X | diskinf | diskinf.exe | "Added by the CRYPTER.A TROJAN!"
|
| ? | DISKMON.EXE | DISKMON.EXE | "??"
|
| N | Disknag | disknag.exe | Dell program that reminds you to make your backup diskettes
|
| X | Diskstart | Snt.exe | Adult content dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| U | Disk_Monitor | Disk_Monitor.exe | "Multi-media |
| X | disnisa | disnisa.exe | "Added by the DORF-AE WORM!"
|
| X | dispenter | dispenter.exe | "Added by the AGENT-MKK TROJAN!"
|
| N | Display Settings | hptasks.exe | "Allows for the adjustment of the display for LCD screen |
| U | DisplayFusion | DisplayFusion.exe | "DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much |
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| X | Dist-FBGeneve | GDC.exe | "NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
|
| X | Distributed File System | kernel32dll.exe | "Added by the MYFIP-C or MYFIP.K WORMS!"
|
| X | Distributed File System | win.exe | "Added by the MYFIP.AB WORM!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| U | distributed.net client | DNETC.EXE | "Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
|
| ? | Divamon.exe | Divamon.exe | "Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
|
| X | divx | divxenc.exe | "Added by the SPBOT.B TROJAN!"
|
| X | DivXCodec | NEWMAIL.exe | "Added by the DELF-RQ BACKDOOR!"
|
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| ? | DJSNetCN | DJSNetCN.exe | """Symantec Licensing Detect Internet Connection"" |
| X | dKernel | dKernel.exe | "Added by the DECOY-A WORM!"
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| U | dlccmon.exe | dlccmon.exe | Dell Photo AIO Printer 924 device monitor
|
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| U | dlcdmon.exe | dlcdmon.exe | Dell Photo AIO Printer 944 device monitor
|
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| U | dlcgmon.exe | dlcgmon.exe | Dell Photo AIO Printer 810 device monitor
|
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| U | dlcjmon.exe | dlcjmon.exe | Dell Photo AIO Printer 964 device monitor
|
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| U | dlcqmon.exe | dlcqmon.exe | Dell Photo AIO Printer 966 device monitor
|
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| U | dlcxmon.exe | dlcxmon.exe | Dell Photo AIO Printer 926 device monitor
|
| U | dldtamon | dldtamon.exe | Dell AIO Printer V305 device monitor
|
| U | dldtmon | dldtmon.exe | Dell AIO Printer V305 device monitor
|
| U | dldtmon.exe | dldtmon.exe | Dell AIO Printer V305 device monitor
|
| X | DLHelperEXE.exe | N/A | Downloader for Microgaming/Casino software - stealth installed
|
| X | DLINK dfe drivers for Windows NT | windfe.exe | "Added by the RANDEX.AK WORM!"
|
| U | DLink System Tray | dlnetst.exe | "Related to D-Link DGE-530T PCI card for servers and workstations"
|
| X | Dlite | dllmanager.exe | "Added by the WOOTBOT.DN WORM!"
|
| X | Dll Boot Loader on Startup (do not remove this) | [various filenames] | Added by an unidentified TROJAN!
|
| X | Dll Link | svchoist.exe | "Added by the AUTOSKY WORM!"
|
| X | Dll Link | svchost.exe | "Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
|
| X | DLL Manager | dllmngr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | dll services | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | dllcvss | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| N | dlmMgr | AdobeDownloadManager.exe | "Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted |
| Y | DLO Agent | DLOClientu.exe | "Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
|
| X | Dm Hr | lpns.exe | "Added by the IRCBOT.WORM.61673 WORM!"
|
| X | dm***.exe [* = random char] | dm***.exe [* = random char] | "Wareout - malware masquerading as a spyware and dialer remover"
|
| U | DmwClient | dmwclient.exe | "DMW ""anti-cheating"" software for online gaming"
|
| U | DMXLauncher | DMXLauncher.exe | "Part of Dell's Media Experience |
| X | dm[3 random letters].exe | dm[3 random letters].exe | "Added by the RUINDEM TROJAN!"
|
| N | DNA | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
| X | dnam | d140113.a.Stub.EXE | "Added by the STUB_A TROJAN!"
|
| N | Dnar | Dnar.exe | "Installed on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| X | DNHelper32 | DNHlp32.exe | Added by an unidentified WORM or TROJAN!
|
| X | DNS | mc-58-12-0000080.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000093.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-110-12-0000079.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000120.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000140.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | [worm filename] | "Added by the BCKDR-CQG BACKDOOR!"
|
| X | DNS Config service | win32.exe | "Added by the RBOT-TL WORM!"
|
| X | Dns Resolver | dnsrslve.exe | "Added by the RBOT-WS WORM!"
|
| X | DNS Service | dnsresolver.exe | "Added by the RBOT-PQ WORM!"
|
| X | DNS Service | dnssvc.exe | "Added by the DELBOT-Z WORM!"
|
| ? | DNS2GoClient | dns2goclient.exe | "DNS2Go is a Domain Name System that will make your computer accessible anytime |
| N | DNS7reminder | Ereg.exe Ereg.ini | "Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
|
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | DNSCacheBoost | dnsping.exe | "Added by the DNSBUST-A TROJAN!"
|
| X | dnscleaner | dnscleaner.exe | "CoolWebSearch parasite variant"
|
| X | DNSE | DNSE.exe | "Part of rogue security tools |
| ? | DNXVC | dnxvc.exe | "??"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| N | DocuMagix Init | PWATCH.EXE | "PaperMaster is an application for the PC designed to automate the process of organizing |
| U | Document Manager | docmgr.exe | "Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
|
| ? | Doing | doing.exe | "??"
|
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| U | Don't Panic | dontpanicdemodp.exe | "30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| U | Don't Panic! | DP.EXE | "Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
|
| X | Dontworry | mysaym.exe | "Added by the SDBOT-RC WORM!"
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| N | DoUWantIt | duwi.exe | DoUWantIt - online shopping assistant. Start it manually
|
| X | Dowmingzu | Dowmingzu.dll.vbs | "Added by the SOLOW-E WORM!"
|
| X | down | hlp32.exe | "Added by the DLOADER.BG TROJAN!"
|
| X | down | [trojan filename] | "Added by the SMALL-QJ TROJAN!"
|
| U | Down2Home | Down2Home.exe | "Down2Home - ""monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"""
|
| N | Download Accelerator Manager Free Edition | dam.exe | "Download Accelerator Manager Free Edition from Tensons Corp"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | Download Plus | DownloadPlus.exe | "DownloadPlus adware"
|
| N | Download Wonder | DownloadWonder.exe | "Download Wonder from Forty Software. Download manager for resuming downloads |
| N | DownloadAccelerator | DAP.EXE | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | DownloadLegalMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadWare | dw.exe | "DownloadWare adware"
|
| X | DownloadWare Engine | Dwe.exe | "DownloadWare adware"
|
| X | downs | downs.exe | "Added by the BCKDR-MNR TROJAN!"
|
| X | Downxz | Downxz.bat | "Added by the MYDOOM.W WORM"
|
| Y | DpAgent | dpagent.exe | "Part of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for example"
|
| N | DPAgnt | DPAgnt.exe | "digitalPersona fingerprint scanner"
|
| Y | DPAS | DPASNT.exe | "DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | Dpcnav | dpcnav.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| N | DPConfig | DPConfig.exe | "Compuware DevPartner Studio Configuration Utility |
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| X | dpnsvr32 | dpnsvr32.exe | "Added by the AOLPASS-B TROJAN!"
|
| X | dpzProtect | n.vbe | "Added by the RUNAUTO.H WORM!"
|
| N | Drag'n'Drop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| N | DragnDrop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| X | DRam Monitor 23 | tskman3.exe | "Added by a variant of the RBOT WORM!"
|
| X | DRam prmaessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosesor | [random filename] | "Added by the SPYBOT.EE WORM!"
|
| X | DRam prosessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosessor | WindowsUpdate.exe | "Added by the RBOT-BBZ WORM!"
|
| X | DRam prosessor | winupl.exe | "Added by the RBOT-BCQ WORM!"
|
| X | DRam rar proc | winupdaterar.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DRam rare proc | updaterarwin.exe | "Added by the RBOT-GQW WORM!"
|
| X | DRan posessor | DAP.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrAntispy | DrAntispy.exe | "DrAntiSpy rogue security software - not recommended"
|
| ? | dregfix | ph_finder.exe | "??"
|
| X | drin | [path to trojan] | "Added by the SMALL.DPB TROJAN!"
|
| X | DriveCleaner 2006 Free | UDC2006.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveCleaner Free | UDC.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveDefender | GDC.exe | "DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| U | DriveIcons | DriveIcon.exe | "Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
|
| X | DriverConf | dvrconf.exe | "Added by the AGOBOT-IY WORM!"
|
| U | DriverMagicLogon | dmschedule.exe | "Part of DriverMagic - ""the easiest way to locate device drivers"""
|
| X | DriverModule | csrnvrt.exe | "Added by the IRCBOT.I TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| X | DriveSystem | maxpaynowti1.exe | "Added by the TIBS.AZT TROJAN!"
|
| U | drkly16j | "rundll32.exe drkly16j.dll | ServiceCheck" |
| U | dRMON SmartAgent | SmartAgt.exe | "Part of the network monitoring program group for 3Com NIC cards. See here for more info"
|
| X | DrProtection | DrProtection.exe | "DrProtection rogue security software - not recommended"
|
| U | DrvIcon | DrvIcon.exe | """Vista Drive Icon changes the drive icons shown in Windows ""My Computer"" |
| ? | DrvListnr | DrvListnr.exe | "Analog Devices SoundMAX soundcard related. What does it do and is it required?"
|
| U | drvlsnr | drvlsnr.exe | Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
|
| U | DrvMon.exe | DrvMon.exe | "Alcor drive monitor software"
|
| X | drvnetw | drvnetw.exe | "Added by the BROGGER-B TROJAN!"
|
| X | drvrmanager | drvrquery32.exe | "Added by the BOOHOO WORM!"
|
| X | drvupd | rundll32 ..drvupd.inf | "Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
|
| X | drv_st_key | hidn.exe | "Added by the BEAGLE.FF WORM!"
|
| X | DrWatson | drwatson_.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWatson | drwatson_32.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWeb Antivirus | DRWEBAV.EXE | Added by an unidentified WORM or TROJAN!
|
| N | DSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| Y | DSLagentexe | DSLagent.exe | "Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
|
| Y | dslmon | dslmon.exe | Sagem DSL modem related. Apparently needed to detect the modem
|
| Y | DSndUp | DSndUp.exe | "Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | DSS | dssagent.exe | "Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| ? | DSSSGENS | dssagens.exe | "??"
|
| X | DSystemDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT 11Mbps WLAN USB Station | DTUSBMonitor.exe | 11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| N | DTAgent | DTAgent.exe | "System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| X | DUN_SERVICES3 | dun3.exe | "Added by the SOKIRON TROJAN!"
|
| X | Duwee wong Cerbon | Cirebons.exe | "Added by the BHARAT.A WORM!"
|
| U | DVD Device Lock for Win95/98/Me/2k/XP | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| X | dvd98 | windvd98.exe | "Added by the CULT.P WORM!"
|
| ? | DVDAgent | DVDAgent.exe | "Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
|
| N | DVDLauncher | DVDLauncher.exe | "Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
|
| N | DVDSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| U | dvHighMem | cfgmng32.exe | "Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
|
| Y | DvpInitExe | Dvpinit.exe | "Command Antivirus related"
|
| U | DVSync | dvsync.exe | DVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
|
| U | DWHeartbeatMonitor | DWHeartbeatMonitor.exe | DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
|
| N | DwlClient | support.exe | Download manager for Dell support alerts
|
| X | dwqblwppx.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwpvl.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwrsq.exe | [random].exe | "Okcashbackmall adware"
|
| U | DWQueuedReporting | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| X | DW_Start | rwwnw64d.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| X | Dx | sys*.exe [* = random number] | "Added by the DEXTER.A WORM!"
|
| X | dxdiag diagnose | msidxdia.exe | "Added by a variant of the RBOT WORM!"
|
| X | dxdll32 | ntxdll.exe | "Added by the GAOBOT.CPX WORM!"
|
| X | DxLoad | DX3DRndr.exe | "Added by the GIBE.B WORM!"
|
| X | Dynamic DHCP | dydhcp.exe | "Added by the RINBOT.B TROJAN!"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| X | Dynamic Dns Binary | CMD16.EXE | "Added by the RBOT-XM WORM!"
|
| X | Dynamic Dns Binary | winxp34.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Dns Binary | WinHelpcfn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Link Library loader | Loader32.exe | "Added by the KOL TROJAN!"
|
| U | DynDNS Updater | DynDNS.exe | "Dynamic DNS IP address updater tool |
| N | DynDNS-Updater Traytool | ddutray.exe | "DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
|
| X | DynHttp Dns Binary | dynizari.exe | "Added by a variant of the RBOT WORM!"
|
| U | DynSite | DynSite.exe | "DynSite - dynamic DNS client |
| U | Dynu Basic Client | dynubas.exe | "Dynu online dynamic IP update client. Useful when using a dial up modem"
|
| U | E-color | IconMgr.Exe | Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| X | E-nrgyPlus | E-nrgyPlus.exe | "Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
|
| U | e-Surveiller Station | estation.exe | "ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
|
| N | E6TaskPanel | TaskPanl.exe | "Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet |
| U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
|
| X | Eac Download | download.exe | "Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
|
| U | EACLEAN | eaclean.exe | "For Compaq PC's. Easy Access button support for the keyboard"
|
| X | Eac_Cnry | canary.exe | "Added by the CANARY TROJAN!"
|
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| U | EanthologyApp | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | EanthologyApp | eanthology.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanthology_install.exe | eanthology_install.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| N | EarthLink ToolBar 5.0 | etoolbar.exe | "EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar |
| N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| X | EasyDates_nl | EasyDates_nl.exe | Adult content dialler
|
| U | EasyLinkAdvisor | LinksysAgent.exe | "Linksys EasyLink Advisor - ""the free application that provides and easy way to setup |
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySpywareCleaner | EasySpywareCleaner.exe | "EasySpywareCleaner rogue spyware remover - not recommended |
| U | EasySync Pro | XCPCMenu.exe | """IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasyTuneIII | EasyTune.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneV | GUI.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | "Ebates adware"
|
| U | eBayToolbar | eBayTBDaemon.exe | "eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
|
| N | eBot | DownloadWizard.exe | "eBot from Digital River - ""helps ensure your computer always has the latest technology |
| U | ECenter | gtb.exe | Dell E-Center/Google Toolbar related
|
| N | ECenter | EULALauncher.exe | End User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
|
| ? | EDFcsn | discfcsn.exe | "Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
|
| U | eDonkey2000 | edonkey2000.exe | "File sharing network - not recommended as the free version of this application should be avoided as it installs |
| X | educational writer | [random filename] | "Added by the RBOT-LZ WORM!"
|
| X | Edzy AntiVirus | dppsfa.exe | "Added by a variant of the RBOT WORM!"
|
| U | Eee Docking | Eee Docking.exe | "Intuitive shortcuts for easy access to digital content |
| N | EEventManager | EEventManager.exe | "Part of the Epson Creativity Suite supplied with their multi-function printer/scanners |
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | eFax Live Menu 3.3 | J2GDllCmd.exe | "DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications |
| N | eFax Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | eFax Tray Menu | J2GTray.exe | "System Tray access to eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.3 | J2GTray.exe | "System Tray access to version 3.3 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.5 | J2GTray.exe | "System Tray access to version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 4.0 | J2GTray.exe | "System Tray access to version 4.0 of eFax Messenger from j2 Global Communications |
| N | eFax.com Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | EFI Job Monitor | "[path] efjm.dll | run" |
| X | egikugu | napolecy.exe | "Added by the SDBOT.AOE WORM!"
|
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| U | Eicon TechnologyLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eixfi | china.bat | "Added by the WCUP.A WORM!"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | Element | Element.txt | "Added by the ELEM TROJAN!"
|
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| N | elm | Elmenv.exe | "ViaTech eLicense for securing |
| X | ELNKProxy | smproxy.exe | "Surfmonkey adware"
|
| U | ELSA WINman Suite | Winmsuit.exe | "Allows you to totally customize your ELSA graphics card settings |
| U | ELSBLaunch | ELSBLaunch.exe | "EarthLink SpamBlocker"
|
| U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| Y | EmailScan | mcvsescn.exe | Related to McAfee AntiVirus suite - used to automatically scan incoming e-mails
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| X | eMessenger | emsn.exe | "Added by the RBOT.AHO BACKDOOR!"
|
| X | empin | e121307.exe | "Delfin Media Viewer adware related"
|
| X | empin | e121307.Stub.exe | "Delfin Media Viewer adware related"
|
| ? | Empowering Technology Launcher | eAPLauncher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| ? | EmpoweringTechnology | Framework.Launcher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| Y | Emsisoft Anti-Malware | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| X | enBrowser | [name of file] | "WINBO adware"
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| N | ENCMONITOR | monitor.exe | The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
|
| N | Encoder Agent | WMENCAGT.EXE | "MS Windows Media Encoder |
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| ? | ENCSurf | surfboard.exe | "??"
|
| N | Energizer FileSaver | Energizer FileSaver.exe | "Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
|
| X | EnergyPlugIn | EnergyPlugin.exe | "EnergyPlugin adware variant"
|
| U | enginecs2 | enginecs2.exe | "Cyber Sentinel - internet filtering software"
|
| Y | EngUtil | EngUtil.exe | "Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine |
| X | Enh Win Updt | enhupdt.exe | "Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
|
| X | enhance32 | enhance32.exe | "Added by the CRYPTER.A TROJAN!"
|
| N | EnigmaPopupStop | EnigmaPopupStop.exe | "Part of Enigma SpyHunter - not recommended |
| ? | ENSApServer2_0 | APSERVER.EXE | "Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
|
| ? | ENSMIX32.EXE | ENSMIX32.EXE | "Sound card driver. Is it required?"
|
| U | EnsoniqMixer | starter.exe | "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
|
| U | Entbloess 2 | Entbloess2.exe | "Related to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Exposé |
| U | Enterprise Harmony | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| U | Enterprise Harmony '99 | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | Enterra Icon Keeper | IcnKeepr.exe | "Icon Keeper - ""tool to save and restore icon positions on the desktop"""
|
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| Y | EnvyHFCPL | EnMixCPL.exe | "VIA Envy24 PCI Audio Controller driver"
|
| U | eonemng | eOneMng.exe | "eOne Manager |
| U | EPGServiceTool | EPGClient.exe | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | ePowerManagement | ePM.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| N | ePrint 3.0 Service | EPRINT3.EXE | "LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF |
| N | ePrint 4.0 Service | EPRINT4.EXE | "A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF |
| X | Epsilon Squared | vmmreg32.exe | "Added by the AGENT.MVC TROJAN!"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| U | EPSON Status Monitor 3 | E_[various].EXE | "Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C40 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status |
| U | EPSON Stylus C41 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status |
| U | EPSON Stylus C42 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S08IC1.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C44 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | EPSON Stylus C45 Series | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
| U | EPSON Stylus C46 Series | E_S4I0T1.EXE | "Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status |
| U | EPSON Stylus C48 Series | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
| U | EPSON Stylus C60 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
| U | EPSON Stylus C61 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status |
| U | Epson Stylus C62 Series | E-S0BIC1.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C62 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C63 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C66 Series | E_S4I0S2.EXE | "Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | Epson Stylus C82 Series | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C82 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3100 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status |
| U | EPSON Stylus CX3200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5400 | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus D68 Series | E_FATIAAE.EXE | "Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status |
| U | EPSON Stylus D78 Series | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
| U | EPSON Stylus D88 Series | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4000 Series | E_FATIBEE.EXE | "Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4800 Series | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX5000 Series | E_FATIBVE.EXE | "Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX6000 Series | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7000F Series | E_FATIBKE.EXE | "Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 1400 Series | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 2200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status |
| U | EPSON Stylus Photo 825 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status |
| U | EPSON Stylus Photo 925 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status |
| U | EPSON Stylus Photo R1800 | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
| U | EPSON Stylus Photo R200 Series | E_S4I0H2.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_S6I2I1.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R240 Series | E_FATIAHE.EXE | "Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R260 Series | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I0F2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R320 Series | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R340 Series | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R380 Series | E_FATIBOA.EXE | "Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R800 | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX500 | E_S4I2K1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX530 Series | E_FATIAGP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX600 | E_S4I2M1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX640 Series | E_FATIAME.EXE | "Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX700 Series | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
| U | EPSON Stylus Pro 4000 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status |
| U | EPSON Stylus Pro 7600 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
| U | EPSON Stylus SX200 Series | E_FATIEFE.EXE | "Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status |
| U | EPSON SX100 Series | E_FATIEDE.EXE | "Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status |
| U | EPSON TX100 Series | E_FATIEDP.EXE | "Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this
|
| X | Eptr | nopdb.exe | Added by an unidentified WORM or TROJAN!
|
| ? | Equipmen | Equipmen.exe | "??"
|
| U | eRecoveryService | Monitor.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | erfgddfk | wind2ll2.exe | "Added by the BEAGLE.CQ WORM!"
|
| X | erghgjhgdr | windlhhl.exe | "Added by the BEAGLE.BG WORM!"
|
| X | erghgjhjgdr | windlhhl.exe | "Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
|
| X | ErrClean | SysRep.exe | "ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
| N | Error Nuker | ErrorNuker.exe | "ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required"
|
| X | errorhandler | errorhandler.exe | "ErrorHandler adware"
|
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| X | ERS | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | erthegdr | windll2.exe | "Added by the BEAGLE.CG WORM!"
|
| X | erthgdr | windll.exe | "Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
|
| U | ERUNT AutoBackup | AUTOBACK.EXE | "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots |
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Scheduler | avkserv.exe | "MicroWorld eScan antivirus scheduler"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| U | eSnips | ClientGW.exe | "eSnips Client Gateway from eSnips"
|
| X | Especial | Deneca.bat | "Added by the DELUZ VIRUS!"
|
| N | ESPN BottomLine | bline.exe | "ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop |
| ? | ESS Daemon | Essd.exe | "Related to an ESS based soundacard. Is it required?"
|
| ? | ESSNDSYS | ESSNDSYS.EXE | "Related to an ESS based soundacard. Is it required?"
|
| U | EssSpkPhone | essspk.exe | "ESS Technologies Call waiting |
| ? | eSupInit | eSupCmd.exe | "Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
|
| X | etbrun | elit***32.exe [* = random char] | "EliteBar adware"
|
| U | eTCertManger | eTCrtMng.exe | "eToken Certificate Manager from Aladdin Knowledge Systems |
| N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
|
| X | ethernet | airftp.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msnger.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msftp.exe | "Added by the SDBOT.BXJ WORM!"
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Driver | cmsrrs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Drivers | smrrs.exe | "Added by the RBOT-AAK WORM!"
|
| X | Ethernet Drivers | ethernet.exe | "Added by the GAOBOT.CEZ WORM!"
|
| X | Ethernet Linking | ethernet.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Etraffic | JavaRun.exe | "TopMoxie adware"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| X | eTrust Realtime Monitor | realmon.exe | "Added by the LAZAR.B TROJAN!"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | eTunnel | winfw.exe | Added by an unidentified TROJAN!
|
| ? | Event Log | eventlog.exe | "??"
|
| N | Event Planner Reminders | PLNRNote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Reminder | pmremind.exe | "Event reminder for calendar dates |
| X | EventApplicationCmd | smschk.exe | "Added by the IRCBOT-AO TROJAN!"
|
| U | EVENTLISTENER | EvLstnr.exe | Used with a Nikon digital camera to recognize when the camera is plugged in
|
| N | eventmgr | eventmgr.exe | Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
|
| X | eventwvr | eventwvr.exe | "Added by the COSIAM_G TROJAN!"
|
| U | EVGAPrecision | EVGAPrecision.exe | "EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible |
| U | Evidence Cleaner | ecleaner.exe | "Evidence Cleaner cleans up tracks left by your PC and Internet activities"
|
| N | Evidence Eliminator | ee.exe | "Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| N | evntsvc | evntsc.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| U | EvtMgr6 | Setpoint.exe | "Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| Y | ewido anti-spyware | ewido.exe | "System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
| X | Ewth | tasn.exe | "PurityScan adware"
|
| X | example | [random filename].exe | "Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
|
| N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| N | ExciteAssistantEXE | ASSISTANT.EXE | "With Excite Assistant |
| X | ExeName32 | Warm.scr | "Added by the SCOLD WORM!"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| U | Exif Launcher | Exiflaquickdcr.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| U | Exif Launcher | QuickDCF.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| ? | exmon | hpimoniter.exe | "Some kind of hp digital camera maybe or a photo smart connection probe?"
|
| X | Exn | exn.exe | "Added by the IRCBOT.RJ WORM!"
|
| X | Expatch | [random filename] | "Added by the PWSLMIR-G TROJAN!"
|
| X | expcrt | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | ExpertAntivirus | ExpertAntivirus.exe | "ExpertAntivirus rogue security software - not recommended |
| X | explore manager | explore.exe | "Added by the DONBOMB.A TROJAN!"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | config_.com | "Added by the FLOPPY-D WORM!"
|
| X | explorer | [path to trojan] | "Added by the AGENT-EU TROJAN!"
|
| X | explorer | Yinstall.exe | "PurityScan/Clickspring adware"
|
| X | Explorer | Windows Explorer.exe | "Added by the SILLYFDC-I WORM!"
|
| X | explorer | main.vbe | "Added by the SHUSH-A WORM!"
|
| X | Explorer 2238 | [path to trojan] | "Added by the AGENT-CPI TROJAN!"
|
| X | Explorer5 | config_.com | "Added by the VB.CBG WORM!"
|
| X | ExplorerRun | conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| X | exporet | winset.exe | "Added by the QQPASS-I TROJAN!"
|
| N | Extender Resource Monitor | RMSysTry.exe | "Related to Windows Media Center from Microsoft"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| X | Extra Antivirus | ExtraAV.exe | "Extra Antivirus rogue security software - not recommended |
| U | ExtraDNS | ExtraDNS.exe | "ExtraDNS - DNS configuration tool"
|
| N | ExtraFilmHemmaAgent | Agent.exe | "ExtraFilm Photo Assistant"
|
| ? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software
|
| ? | ExxtremeHelperDemon | exxdemon.exe | "Creative Exxtreme graphics card related?"
|
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| U | EZ-DUB Finder | EZ-DUB.exe | "Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
|
| N | ezagent | ezagent.exe | "EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
|
| N | EzButton | EzButton.EXE | EZbutton is a quick launcher for the Media player app that comes with certain laptops
|
| U | EZEJMNAP | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| ? | EZNORUN | EZNORUN.EXE | "Easy Internet related?"
|
| N | EzPrint | ezprint.exe | "Lexmark Fast Pics - helps users of their printers to enhance |
| Y | ezPS_Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| U | EzTune | dthtml.exe | "EzTune from Gateway. Rebranded version of Display Tune from Portrait Displays |
| X | eZulaMain | eZulaMain.exe | "eZula TopText adware"
|
| X | eZuluMain | eZuluMain.exe | Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
|
| U | E_S23 | E_SICN03.exe | "Epson printer status monitor - for checking ink levels |
| U | E_S[numbers] | [path] E_[various].EXE [path] E_S[numbers].tmp | "Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| X | f | ftkclean.exe | "FlashEnhancer adware"
|
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Manager | FSM32.EXE | "F-Secure antivirus - carry out scheduled virus scans automatically"
|
| Y | F-Secure TNB | TNBUtil.exe | "F-Secure antivirus"
|
| ? | f23mxins | f23mxins | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | f2install.exe | f2install.exe | "Added by the IEFEAT-I TROJAN!"
|
| U | F5D7050v3 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
|
| U | F5D8001 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
|
| U | F5D8011 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
|
| U | F5D8055v1 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
|
| U | F5D8071 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
|
| U | F5D9010 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
|
| U | F5D9050 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
|
| X | f73cdc8ee94e | btsendto.exe | Associated with mysearchnow.com/searchbar.html
|
| X | f94mggfhfghodftdf | [path to trojan] | "Added by the SMALL.JHZ TROJAN!"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| ? | fapmon | fapmon.exe | "Fair Access Policy monitor for DirecPC/DirecWay internet access"
|
| X | Fast Antivirus 2009 | FastAV.exe | "Fast Antivirus rogue security software - not recommended |
| X | Fast Home | svcnvt.exe | "Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines |
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | Ntut.exe | "Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
|
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | FastStart | ntnut32.exe | "Added by the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| U | FastTVSync | FastTVSync.exe | "Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps |
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | fc | runfc.exe | "Added by the CAMPURF WORM!"
|
| X | FCEngine | FCEngine.exe | "CASClient adware"
|
| X | FCMan | FCMan.exe | "FCHelp adware"
|
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | Fdr Command Module | sp2.exe | "Added by the SDBOT.WP WORM!"
|
| X | FDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| U | FG1_00 | frntgate.exe | "FrontGate MX - e-mail spam blocker"
|
| ? | fgl23DoubleScreenHooks | f23happ.exe | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| U | FieldForms Sync | SyncService.exe | "Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run |
| X | FiendlyType | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| ? | file indexing service | msfindfile.exe | "New version of MS FindFast and still a resource hog?"
|
| X | file laoder configuration | rnd32.exe | "Added by the RBOT.BQJ WORM!"
|
| X | File Mapping Services | hp-1003.exe | "Added by the RBOT.FAN WORM!"
|
| X | File Protection Monitor | filemon.exe | "Added by a variant of the RBOT WORM!"
|
| X | File-Sharing Wizard | shwizard.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | FileFreedom_Plugin | wtm.exe | "FileFreedom peer-to-peer sharing program"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | filen | filen.exe | "Added by the VBNAM-A WORM!"
|
| X | filename | filename.exe | "Added by the VB.FSY TROJAN!"
|
| X | filename process | kerneldll.exe | "Added by the AGOBOT-PO WORM!"
|
| X | filename process | explore.exe | "Added by the AGOBOT-QN WORM!"
|
| X | filename process | Rundil16.exe | "Added by the GAOBOT.ZX WORM!"
|
| X | Find | find.exe | "Added by the OPANKI WORM!"
|
| N | Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
|
| Y | Find Virus Launch Program | fvlaunch.exe | "Part of Dr. Solomon's Antivirus"
|
| X | findfast | findfast.exe | "Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
|
| X | findfast.exe | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
|
| X | FindHack | [path to worm] | "Added by the KELVIR-BA WORM!"
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | "ABBYY FineReader OCR software - version 7"
|
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
|
| X | Fire Wall services | [random filename] | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Wall services | wnlmzsfhobi.exe | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Well service | [random].exe | "Added by the RBOT-FJU WORM!"
|
| ? | FireBox Control Panel | FireBox.exe | "Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
|
| X | Firefox Plugin Manager | firefoxpgm.exe | Added by the MSNPHOTO.E WORM!
|
| X | FiresWallservices | [random].exe | "Added by the RBOT-FJT WORM!"
|
| X | Firevall Administrating | rndll.exe | "Added by the PUSHBOT-B WORM!"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.D WORM!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | firewall 2008 | logoneui.exe | "Added by the SILLYFDC WORM!"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Firewall auto setup | [path to trojan] | "Added by the AGENT-GLY TROJAN!"
|
| X | Firewall config | ReadMe.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | Firewall Update System1 | WinedowsUpdater1.exe | "Added by the RBOT-ARU WORM!"
|
| X | Firewall Updater | msnupdateit.exe | "Added by the RBOT-AAQ WORM!"
|
| X | firewall_anti | firewall_anti.exe | "Added by the NETDENY-B TROJAN!"
|
| X | FireWire Service | nvscv32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireWire Services | nvcsv32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| ? | First Principle Group | fpg.exe | "Related to the E-Players Card from First Principle Group"
|
| X | FIX | WinFIX1.0.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | Fixnice | vcvw.exe | "Added by the SDBOT TROJAN!"
|
| U | FjMenu | FjMenu.exe | "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel |
| U | FJTWAIN Setup | FjtwSetup.exe | Fujitsu scanner utility
|
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop
|
| X | FKS v2.0 | msngr.exe | Added by an unidentified WORM or TROJAN!
|
| N | fkSysMon | fksysmon.exe | "fkWrae SysMon - system monitor - ""displays the current memory consumption |
| X | Flash Driver | [path to trojan] | "Added by the AGENT.CWVT TROJAN!"
|
| X | Flash Media | [path to trojan] | "Added by the IRCBOT.AUR TROJAN!"
|
| X | Flash Media | zrpk��'�'%''msn'�%'fix''.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | skxs��'�'%''msn'�%'fix''.exe | "Added by the AGENT.ZOY TROJAN!"
|
| ? | FLASH32 | #NAME? | "??"
|
| U | FlashEnc | FlashEnc.exe | "Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission |
| X | Flashget Download Manager | Flashget.exe | "Added by the RBOT-AGZ WORM!"
|
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| X | Flash_Player_Install | ying.exe | "Constructor VC2000 malware"
|
| X | FlenCPY | flencpy.exe | "FlashEnhancer adware"
|
| U | FlingRun | fling.exe | "Fling - free FTP software from NCH Software"
|
| U | FLMMEDIONMOUSE | mouse32a.exe | Mouse utility for a Medion branded Fellowes mouse
|
| X | FlnCPY | flncpy.exe | "FlashEnhancer adware"
|
| X | FLooDNeT | FLooDeR.exe | "Added by the ENDOOL TROJAN!"
|
| X | Floppy Master | [path to trojan] | "Added by the ZONIT-F TROJAN!"
|
| X | flpycntl | flpycntl.exe | "Added by the CRYPTER.C TROJAN!"
|
| Y | FltProcess | msinet.exe | "Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
|
| X | fmnwebassist | fmnwebassist.exe | Adware popup generator
|
| X | fnmwebassist | fnmwebassist.exe | "WinPL adware"
|
| X | foffice | nm.exe | "Added by the DELF-CB TROJAN!"
|
| U | FolderClone v*.*.* | folderclone.exe | "Folderclone backup and synchronization software"
|
| N | Folding@home | WINFAH.EXE | "Folding@Home is a distributed computing project which studies protein folding |
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
|
| X | Font | boot.exe | "Added by the AGENT-LZW TROJAN!"
|
| X | Font Viewer | fontviewer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | FontFix | fontfix.exe | "Added by an unidentified VIRUS |
| N | fontnav | FontNav.exe | "Font Navigator from Bitstream Inc. - a font management utility"
|
| X | FontsLoader | ldfnt32.hta | Unidentified malware
|
| X | FONTVIEW | FONTVIEW.EXE | "Added by the OPASERV.T WORM!"
|
| X | foobin lptt01 | adaware.exe | "RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | foobin ml097e | adaware.exe | "RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | FoolProof | fpwinldr.exe | "FoolProof Security PC security software from SmartStuff"
|
| X | ForceShow | "rundll32.exe QaBar.dll | ForceShowBar" |
| N | Forget Me Not | AGRemind.exe | "Calendar reminder part of Broderbund's American Greetings® CreataCard®"
|
| U | forteManager | dthtml.exe | "forteManager from LG. Rebranded version of Display Tune from Portrait Displays |
| Y | FortiClient | FortiClient.exe | "Fortinet security systems are the new generation of real time network protection systems"
|
| U | Fortis Secure Layer Config | cseinst.exe | Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
|
| N | FotoStation Easy AutoLaunch | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
|
| X | foxdh | foxdhend.exe | "Added by the MENGHUAN TROJAN!"
|
| N | Fpx | mnmsrvc.exe | Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
|
| X | Framework module library | infocard.exe | "Added by the BUZUS.AYX TROJAN!"
|
| X | Framework Windows | frmwrk32.exe | "Added by the FAKEAV-KS TROJAN!"
|
| X | France | svchost.exe | "Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| N | Free Download Manager | fdm.exe | """Free Download Manager"" - see here"
|
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| X | FreeAttention | eqsefeqe.exe | Added by an unidentified WORM or TROJAN!
|
| N | Freebie Notes | FreebieNotes.exe | "Freebie Notes by Power Soft - create electronic notes (stickers)"
|
| U | FreeMemVn2 | FreeMem.exe | "FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | FreeMP3download | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | FreePDF Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| N | FreePDF_Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| X | freinst | pgs.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| ? | FridaysInHellInstaller | FridaysInHellInstaller.exe | "??"
|
| X | FriendlyType | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | FriendlyTypeName | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| X | FriendlyTypeName | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| N | Fromine WinPopup | winpopup.exe | Instant Messenger program
|
| X | frun | derc32xz.exe | Added by an unidentified TROJAN!
|
| Y | frxmxins | frxmxins.exe | ATI 3D Studio MAX/VIZ driver
|
| X | FS Agent | fagent.exe | "Added by the VOLVER-B TROJAN!"
|
| X | FSH | svcnva.exe | Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
|
| X | fstsvc | "rundll32.exe fstsvc.dll | start" |
| X | ftk | ftkclean.exe | "FlashEnhancer adware"
|
| U | FtLnSOP_setup | FtLnSOP.exe | Fujitsu scanner utility
|
| X | FTP FOR WINDOWS | ftpwin32.exe | "Added by a variant of the RBOT WORM!"
|
| N | FTPManager | FTPDM.exe | """Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another |
| U | ftutil2 | "rundll32.exe ftutil2.dll | SetWriteCacheMode" |
| U | Fujitsu Hotkey Utility | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | Fujitsu Menu | FjMnuIco.exe | "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel |
| X | Fun | Fun.exe | "Added by the COIDUNG-A WORM!"
|
| N | FusionHdtvTray | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| U | FusionRC | FusionRC.exe | "Remote control manager for DVICO FusionHDTV"
|
| U | FusionRemote | FusionRc.exe | "Remote control manager for DVICO FusionHDTV"
|
| N | FusionTrayAgent | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| Y | FveNotify | fveNotify.exe | "Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista |
| X | FW Manager | fwcheck.exe | "Added by the DELBOT-H WORM!"
|
| X | FWDMON.EXE | fwdmon.exe | "Added by the PROXY-S TROJAN!"
|
| Y | fwenc.exe | fwenc.exe | "Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up |
| X | Fwr Command Module | fwr.exe | "Added by the SDBOT-PP WORM!"
|
| X | G00123 | [worm filename] | "Added by the BUGBROS WORM!"
|
| X | G4G | [random filename] | Detected as Trojan-Downloader.Win32.VB.fki
|
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | "System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
|
| X | gabougool | nounina.exe | "Added by the AGENT-JVX TROJAN!"
|
| N | Gadwin PrintScreen | PrintScreen.exe | "Gadwin PrintScreen - utility to capture |
| X | gah95on6 | gah95on6.exe | "ShopAtHome/SAHagent adware"
|
| U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
|
| X | Games Acceleration | svshost.exe | "EasySearch adware"
|
| X | Games Acceleration | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Games Acceleration | svshost1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | "Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| N | GameSpot | kontiki.exe | "Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
|
| X | gangsta | gangsta.exe | "Added by the RIMA.A BACKDOOR!"
|
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers
|
| X | Gate Personal Firewall | Systpl.exe | "Added by the RBOT.ADC WORM"
|
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder
|
| U | GazelDisplay | gsyno.exe | "BT Digital Access USB - Gazel ISDN installation System Tray icon"
|
| Y | GBMHome7Agent | GBMAgent.exe | "Genie Backup Manager Home 7 - backup software"
|
| Y | GBMLite7Agent | GBMAgent.exe | "Genie Backup Manager Lite 7 - backup software"
|
| Y | GBMPro7Agent | GBMAgent.exe | "Genie Backup Manager Pro 7 - backup software"
|
| Y | GBSpaceMan | SpaceMan.exe | "GreenBorder - secure your browsing activities on the internet"
|
| ? | GCC Reminder | gccrem.exe | "Associated with AcraMax Greeting Card Creator. Is it a registration reminder?"
|
| X | Gddlib | "rundll32.exe gddlib.dll | start" |
| X | gdien32 | gdien32.exe | "Added by the SINGU-P TROJAN!"
|
| N | Gearbox | confsvr.exe | "NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
|
| X | Gekio Startups | gnksvc32.exe | "Added by the AGOBOT.AFJ WORM!"
|
| X | gencroot | gencroot.exe | "Added by the SDBOT-AED WORM!"
|
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives
|
| X | General Antivirus | GenAvir.exe | "General Antivirus rogue security software - not recommended |
| X | general lptt01 | general.exe | "RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | general ml097e | general.exe | "RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Generic host proccess for windows | SVCHOSTS.EXE | "Added by the SPYBOT-GQ WORM!"
|
| X | Generic Host Process | SCHOST.EXE | "Added by the RBOT-NC WORM!"
|
| X | Generic Host Process | svchost.exe | "Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | Generic Host Process | lsassw.exe | "Added by the AGOBOT-N WORM!"
|
| X | Generic Host Process for Win Services | mscvs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Process for Win32 Service | svlhost.exe | "Added by the WOOTBOT.EX WORM!"
|
| X | Generic Host Process for Win32 Service | rpchost.exe | "Added by the IRCBOT.DCN WORM!"
|
| X | Generic Host Process for Win32 Services | ntspcv.exe | "Added by the SDBOT.S TROJAN!"
|
| X | Generic Host Process for Win32 Services | intspvc.exe | "Added by the DINFOR.D WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc.exe | "Added by the SDBOT-O WORM!"
|
| X | Generic Host Process for Win32 Services | bazzi.exe | "Added by the AHKER.E WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc32.exe | "Added by the SDBOT-P WORM!"
|
| X | Generic Host Process for Win32 Services | lspsvc.exe | "Added by the MUMU.C WORM!"
|
| X | Generic Host Process for Win32 Services | SPSVC.EXE | "Added by the SDBOT.DA WORM!"
|
| X | Generic Host Process for Win32 Services | svchost32.exe | "Added by the AGOBOT.ALH WORM!"
|
| X | Generic Host Process for Win32 Services | svñhîst.exe | "Added by the DLOADER.AK TROJAN!"
|
| X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Generic Host Process For Win32 Services | mtsc32.exe | "Added by the VB-CPL TROJAN!"
|
| X | Generic Host Process for WinXP Services | mshelp.exe | "Added by the AGENT-GQP TROJAN!"
|
| X | Generic Host Process2 System Backup | scvhost2.exe | "Added by the RBOT-BAH WORM!"
|
| X | Generic Host Process326a System Backup | scvhost326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Service | lshost.exe | "Added by the RBOT.LU WORM!"
|
| X | Generic Service Process | regsvc32.exe | "Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
|
| X | Generic Service Process | serv1ces.exe | "Added by the AGOBOT-JK WORM!"
|
| X | Generic Service Process | nvsvc.exe | "Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
|
| X | Generic Service Process | srvhost.exe | "Added by the AGOBOT-FX WORM!"
|
| X | Generic Service Process | regsvr32.exe | "Added by the AGOBOT-AGD WORM!"
|
| X | Generic Service Process | SRCHOST.EXE | "Added by the AGOBOT-DG WORM!"
|
| X | Generic Services Process | regsvc32.exe | "Added by the GAOBOT.SY WORM!"
|
| X | GenericHostXP | WinLoaderXP.exe | "Added by the BDOOR-ACX BACKDOOR!"
|
| Y | Genie USB Monitor | USBmonitor.exe | Port monitor for an external USB hard drive. Required to enable access to the drive
|
| X | Genius Mose Driver | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | genserv path | sdqdqg.exe | "Added by the SDBOT-RF WORM!"
|
| X | Geography TX 1.0 NT | CompuSpeed.vbs | "Added by the NEWLEY-A WORM!"
|
| X | Gerenciamento de arquivos do Windows | Winmod32.exe | "Added by the DLOADER-WG TROJAN!"
|
| X | german.exe | winsystems.exe | "Added by the BAGLEDl-AE TROJAN!"
|
| X | german.exe | wintems.exe | "Added by the BAGLE-AS TROJAN!"
|
| X | Gestionnaire de disques universel | sysoobe.exe | "Added by the TOADER-A TROJAN!"
|
| X | Get-Torrent Service | wakeservice.exe | Get-Torrent bittorrent client - Installs LOP adware
|
| Y | Getca | InfoMyCa.exe | "Monitor for a Belkin USB Wireless adapter"
|
| X | GetitAll | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | GetRight - Tray Icon | getright.exe | "Entry added with older versions of the GetRight download manager from Headlight Software |
| X | GetTheMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | Getting started with MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | getwin | winB_.exe | "Added by the BANKER-HS TROJAN!"
|
| X | gfxtray | "rundll32 ctccw32.dll | findwnd" |
| X | Ghost Antivirus | GhostAV.exe | "Ghost Antivirus rogue security software - not recommended |
| X | Ghost Relay | [random filename] | "Added by the DNSCHANG.EK TROJAN!"
|
| U | Giganews Accelerator | GiganewsAccelerator.exe | "Giganews Accelerator from Giganews |
| Y | Gilat SOM Enumerator | dllhost.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| X | gimmygames | [path to trojan] | "Added by the DLOADR-LN TROJAN!"
|
| X | GinaDll | ntgina.dll | "Added by the ANIG.A WORM!"
|
| ? | GisdnLog | gisdnlog.exe | "BT Digital Access USB"
|
| X | GLF Network Lan Monitor | NPFMNTOR.exe | "Added by the RBOT-AGY WORM!"
|
| X | Global Startup | WinDash.EXE | "Detected by Kaspersky as the VB.Q WORM!"
|
| X | GlobalSCAPE | [random filename] | "Added by the RBOT-AYM WORM!"
|
| ? | gluon | gluon.exe | "In a gluon/bin sub-directory"
|
| U | Gnetmous | gnetmous.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| U | GNETMOUSE | gnetmouse.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| X | GNP Generic Host Process | svchost.exe | "Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| ? | gnub | gnub.exe | "??"
|
| X | Go And Start | svdll32.exe | "Added by the RBOT.AI BACKDOOR!"
|
| X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
|
| U | GoBack | GBMenu.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Polling Service | GBPoll.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Tray Icon | GBTray.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | GoldenAntiSpy | pgs.exe | "GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
|
| U | Goldensoft_MndlSvr | MndlSvr.exe | "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive |
| X | Google Earth | [random filename] | "Added by the RBOT-AXK TROJAN!"
|
| U | Google IME Autoupdater | GooglePinyinDaemon.exe | "Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone |
| X | google Intrenet Explorer | google.pif | "Added by the RBOT-ARA WORM!"
|
| N | GoogleDCClient | GoogleDCC.exe | "Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser |
| U | GoogleToolbarNotifier | GoogleToolbarNotifier.exe | "Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
|
| X | gotnewupdate000.exe | gotnewupdate000.exe | "Added by the FAKEAV-BGA TROJAN!"
|
| U | GoTrusted | GoTrusted Secure Tunnel.exe | """GoTrusted is the fast |
| X | govurarope | "Rundll32.exe retasevo.dll | s" |
| X | GPLv3 | [random name].dll | "Vundo adware"
|
| X | gpmce | window.exe | "Added by the VB.CK WORM!"
|
| X | Graphic Loader | ntvdm32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Update | openglx.exe | "Added by the IRCBOT.AMU WORM!"
|
| X | Graphics adapter service | windll.exe | "Added by the ATNAS.A WORM!"
|
| U | Gravis Xperience Driver Support | Grxp4exe.exe | "Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
|
| X | GreatDefender | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDefender.exe | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Greetings Workshop | GWREMIND.EXE | You really want to be reminded about somebody's birthday at the expense of resources?
|
| X | Gremlin | intrenat.exe | "Added by the DOOMJUICE WORM!"
|
| X | grgtgvgb.exe | [random].exe | "Added by the AGENT-EBF TROJAN!"
|
| X | grinders | grinders.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| U | GrooveMonitor | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GrooveMonitor Utility | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| N | GrpConv | grpconv.exe | "Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
|
| N | Gsiconexe | Gsicon.exe | "ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
|
| ? | GsiFinal | "rundll32 gspndll.dll | postInstall final" |
| ? | GSISETUP | [path] GsiInst.exe INSTALL [path] V205Res 13 | "BT Voyager ADSL modem related - what does it do and is it required?"
|
| N | GSOrganizer | GSOrganizer.exe | "GoldenSection Organizer (now WinOrganizer - personal information manager)"
|
| X | GuardCenter | GuardCenter.exe | "GuardCenter rogue security software - not recommended"
|
| Y | GuardGui Application | GuardGui.exe | "System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
|
| U | Guardian | CMGrdian.exe | "McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security |
| U | Guardian PC Security Tools | Pfft.exe | "Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
|
| X | guarnset | guarnset.exe | "Adlogix adware"
|
| U | GuruNet | GuruNet.exe | "GuruNet lets you click on any word on your screen to get the relevant information you want"
|
| X | GustavVED | [filename].exe | "Added by the OPASERV.H WORM!"
|
| X | gvagfxj | rundll32 ...gvagfxj.dll | "Unidentified adware |
| Y | gw port controller | PORTCT95.EXE | "From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties |
| N | GWInkMonitor | GWInkMonitor.exe | "Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink |
| X | gwiz | ntsystem.exe | "Added by the NITWIZ.A TROJAN!"
|
| U | H/PC Connection Agent | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| X | hachimitsu-lemon | hachimitsu-lemon.exe | "Added by the HACHILEM TROJAN!"
|
| X | hagent | avp.exe | "Added by the ""Herman Agent"" remote access TROJAN!"
|
| U | HalifaxHowardCluster | skinkers.exe | """Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
|
| U | HaMFrontPanel | hampanel.exe | "Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget |
| U | Handy Backup 3.9 | hbagent.exe | "Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
|
| X | HanUpdate | hanz.exe | "Added by the RBOT-GLJ WORM!"
|
| N | Hard Disk Sentinel | HDSentinel.exe | "Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find |
| X | Hard drive Controller | hdcontroller.exe | "Added by the KIMAN.B WORM!"
|
| X | Hardware Monitor Service | mshms.exe | "Added by the WOLLF-A TROJAN!"
|
| U | Hardware Sensors Monitor | hmonitor.exe | Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
|
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| U | Harmony 98 - CasioOrg | CasAgnt.exe | "Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | HATAPE | [path to trojan] | "Added by the BANKER-QF TROJAN!"
|
| U | HawkEye IV Control Panel | HAWK_32.EXE | "Control Panel application for the old Number Nine graphics cards to change resolution |
| U | Hawking HWU54G Utility | HWU54G.exe | "Wireless management utility for the HWU54G Mini Wireless-G USB Adapter from Hawking Technologies |
| U | Hawking Wireless Utility | HWU8DD.exe | "Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies |
| X | Hbinst | Hbinst.exe | "Hotbar adware"
|
| N | HC Reminder | hc.exe | "For Compaq PC's. Help Compiler |
| X | hcen | hcen.exe | "Added by the SMALL.LR TROJAN!"
|
| U | hcenter | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | hcenter | hcenter.exe | "Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| X | hclean32.exe | hclean32.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| U | Hcontrol | hcontrol.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| U | HControlUser | HControlUser.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| N | HD Audio Control Panel | RtHDVCpl.exe | "Realtek HD Audio Manager |
| X | HDAudio Driver 1.0 | [random filename].exe | "Added by the TEADOOR-D TROJAN!"
|
| X | HDAudio Driver 2.0 | [random filename].exe | "Added by the TEADOOR-E TROJAN!"
|
| U | HDDControlGuard | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| U | HDDControlGuard.exe | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| X | hdlfoe df98ndf | svchots.exe | "Added by a variant of the RBOT WORM!"
|
| X | hdlpscom | [8 random letters].exe | "Added by the RBOT-FUL WORM!"
|
| X | he3bbcff | "rundll32.exe he3bbcff.dll | EnableRunDLL32" |
| X | he3e3fc4 | "rundll32.exe he3e3fc4.dll | EnableRunDLL32" |
| X | Hekio Startups | Hnksvc32.exe | "Added by the AGOBOT-QE WORM!"
|
| X | HelloInt | hello3.exe | "Added by the CASAL.A TROJAN!"
|
| X | helloworld | nb32ext2.exe | "Added by the MYDOOM.BV WORM!"
|
| X | helloworld | nb32ext3.exe | "Added by the MYTOB.JT WORM!"
|
| X | helloworld3 | nb32ext4.exe | "Added by the RITDOOR.A WORM!"
|
| X | Help | Wizardnil.exe | "Added by the BANCOS-BCZ TROJAN!"
|
| X | Help Temp Files | netreg.exe | "Added by the FORBOT-EM WORM!"
|
| U | HelpCenter | sprtcmd.exe /P HelpCenter | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| U | HelpCenter4.1 | sprtcmd.exe /P HelpCenter4.1 | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| X | HELPER | greece_nm.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | Netherlands.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | new_zealand.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | sweden.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | canada.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | france.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | helper.dll | rundll32.exe [path] helper.dll | "CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | helpmanager | spoler.exe | "Added by the RANDEX.J WORM!"
|
| X | hen | [filename].exe | "Added by the TARNO.G TROJAN!"
|
| X | hErcUnes | softhost.exe | "Added by the GARROCH WORM!"
|
| U | Hermes Messenger | DGDRHE~1.EXE | "A LAN messenger alternative to WinPopUp - Digital Dreams Software"
|
| X | Hewlett Packard Manager | hpmanager.exe | "Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
|
| N | Hewlett Packard Recorder | Remind32.exe | HP multifunction registration
|
| X | hfdtubvnx | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | Hhjg5jfd93dftdf | winlogan.exe | "Added by the ERTFOR.A TROJAN!"
|
| X | hhtnsn | rnxntup.exe | "Added by a variant of the ORCU.B TROJAN!"
|
| ? | HiberMonitor | HCount.exe | "??"
|
| U | Hibernation | hib32.exe | "Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate |
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | hiden | hiden.exe | "Added by the AGENT-IW TROJAN!"
|
| X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | "Added by the BOOHOO WORM!"
|
| X | HideStyle | Ante Browse Trust.exe | "IE toolbar taking you to Lop.com. If the exe is running |
| U | Hidetools Spy Monitor | wmispe.exe | "HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
| X | Hidup_Susah | Pembantu.exe | "Added by the SILLYFDC.BDM WORM!"
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| N | High Definition Audio Property Page Shortcut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| Y | HighPoint ATA RAID Management Software | raidman.exe | "HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
|
| X | Highspeeddownloader | SetupClickHere.EXE | "Homepage hijacker |
| U | HijackThis startup scan | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| U | Hitman Pro SurfRight Helper | srhelper.exe | "Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
|
| X | HKEYok | runlli32.exe | "Added by the QQPASS-U TROJAN!"
|
| X | HKLMRun | windowsupdate.exe | "Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
|
| X | HKLM\Run | svhost.exe | "Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
|
| X | HLcleanup | hlsetup2.exe | "LinkReplacer/FFinder adware"
|
| U | Hmonitor | Hmonitor.exe | Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
|
| X | hohohhaha | ournik.com | "Added by the IRCFLOOD.AL BACKDOOR!"
|
| X | Home Antivirus 2010 | HomeAntivirus2010.exe | "Home Antivirus 2010 rogue security software - not recommended |
| X | HomeAntivirus 2009 | HomeAntivirus2009.exe | "HomeAntivirus 2009 rogue security software - not recommended |
| ? | HomeCentre WakeUp | LGWAKEUP.EXE | "Associated with the no longer supported Xerox HomeCentre printer/scanner"
|
| X | Homeland Network | HomelandNetwork.exe | Homeland Network Notifier - pops ads
|
| X | homepage.monitor.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| U | HondaHelper | HondaHelper.exe | "Part of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod® in you car"
|
| ? | Honor | honor.exe | "??"
|
| U | HornetMonitor | MntrHrnt.exe | "Hornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network"
|
| Y | HorngTech4D | bally4d.exe | HorngTech 4D mouse driver
|
| X | Host | N/A | "Added by the POPDIS or STARTPAGE.F TROJANS!"
|
| X | Host Process for Windows Tasks | taskhost.exe | "Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| U | HostManager | AOLHostManager.exe | "Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched |
| N | HostManager | AOLSoftware.exe | "Quoted from AOL Beta Team |
| X | Hostname Manager Server | host32srv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Hostren.exe | Hostren.exe | "Added by PWS.BANKER.F |
| U | HostsFileMgr | winHostsEdit.exe | "AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
|
| U | HostsMan | hm.exe | """HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost |
| U | Hot Corners | Hotc.exe | "Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
|
| X | HOT FIX | filename.exe | "Added by the SDBOT-DKM WORM!"
|
| X | HOT FIX | QOching.exe | "Added by the WOOTBOT.VH WORM!"
|
| X | HOT FIX | windsys2.exe | "Added by the AGOBOT.AOI BACKDOOR!"
|
| X | Hot Inside | Hottest Story Ever.exe | "Added by the BHARAT.A WORM!"
|
| U | Hot Key Kbd 2690 Daemon | SK2690DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| U | Hot Key Kbd 9910 Daemon | SK9910DM.exe | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| X | HotAction_hr | hotaction_hr.exe | "Added by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""HotAction_hr"""
|
| X | Hotbar | Hbinst.exe | "Hotbar adware"
|
| X | Hotbar | HbOEAddOn.exe | "Hotbar adware"
|
| X | HotbarOE | OEAddOn.exe | "Hotbar adware"
|
| X | hotefix | msnmanegers.exe | "Added by the IRCBRUTE.AS TROJAN!"
|
| X | hotfix | msnnmaneger.exe | "Added by the WOOTBOT.AF WORM!"
|
| U | HOTFOON2 | hotfoon4.exe | "Related to Hotfoon - a developer and provider of Internet Telephony technology based on LTP (Lightweight Telephony Protocol)"
|
| N | HotSync Manager | hotsync.exe | Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
|
| X | HP | mon.exe | "Added by the SILLYFDC WORM!"
|
| U | HP AutoIndexer | hppautoindexer.exe | "Installed by HP multi-function printer driver software |
| X | hp center | BACKWEB-*****.exe | "See here - ""messaging service that automatically sends you support information |
| N | hp center UI | ShadowBar.exe | "User Interface for HP Center - see here"
|
| N | HP Component Manager | hpcmpmgr.exe | "Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
|
| U | HP Digital Imaging Monitor | hpqtra08.exe | "System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera |
| U | HP Display Settings | hpdisply.exe | "Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
|
| U | HP Gaming Keyboard | razerhid.exe | HP VoodooDNA Gaming Keyboard (powered by Razer) driver - required if you use the additional features and programmed keys/macros
|
| N | HP Image Zone Fast Start | hpqthb08.exe | "Improves the startup time of HP Image Zone. If you disable it |
| N | HP Info Express | ?? | "On HP PCs |
| U | HP Instant Support | matcli.exe | ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| N | HP Internet Center | SURFBRD.EXE | Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
|
| ? | HP Network Registry Agent | hpnra.exe | "??"
|
| X | HP Photo Manager | HPPhotoManager.exe | "Added by the SDBOT.AXU WORM!"
|
| N | HP Precision Scan | hpmdlbwx.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| N | HP Presentation Ready | PresRdy.exe | HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
|
| U | hp psc 2000 Series | hpobnz08.exe | System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
|
| U | HP RecordNow | ?? | "From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."""
|
| U | HP ScanPatch | HPScanFix.exe | "Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used |
| N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| U | HP SchedIndexer | hppschedindexer.exe | "Installed by HP multi-function printer driver software |
| ? | hp Silent Service | HpSrvUI.exe | "HP related"
|
| N | HP Simple Trax | Hpcron.exe | Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
|
| U | HP TV Now | HpTvNow.exe | Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
|
| X | HP Update Assistant | HPAware.exe | Added by the MRO TROJAN!
|
| ? | HP Visualize Init | HpVisIni.exe | "HP Visualize software related. What does it do and is it required?"
|
| N | HP-Aio Flight | Remind32.exe | HP multifunction registration
|
| ? | HPAiODevice(hp officejet g series) | hpoavn07.exe | "HP Printer related |
| N | HPAIO_PrintFolderMgr | hpoopm07.exe | "Directly from HP: "This process has one purpose - detects if the device moves to a different port |
| U | HPDAgent | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| U | HPGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | hpgs2wnd | hpgs2wnd.exe | "Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
|
| U | Hpha1mon | Hpha1mon.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 2.0 to 2.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | Hpha2mon | Hpha2mon.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.1 to 3.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | Hpha3mon | Hpha3mon.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 3.3.138 to 3.4.13 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | HPHmon03 | hphmon03.exe | Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. Known to cause 100% CPU load in some cases. Only needed if you use this feature
|
| U | HPHmon04 | hphmon04.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 4.0 to 4.2 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | hphmon05 | hphmon05.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 5.0 to 5.3 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | HPHmon06 | hphmon06.exe | "Supports the memory card reader on some HP Photosmart and AIO (all-in-one) printers - displaying a System Tray icon for the drive and allowing you to transfer files directly via the SAVE button. This verison is applicable for version 6.0 drivers - see here. Known to cause 100% CPU load in some cases. Only needed if you use this feature"
|
| U | HPLaptopGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| Y | HPLJ Config | SetConfig.exe | Connects system to networked HP printer.
|
| U | HPLogiFinder | hp_finder.exe | HP LogiFinder helps detect and allows the use of the centre button for the Logitech mouse. Can be disabled if not used
|
| X | HPNT | hpdll.exe | "Malware downloader - detected by Kaspersky as the VB.KU TROJAN!"
|
| N | hpoddt01.exe | N/A | "Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software |
| X | HpPrinter | hpserver.exe | "Added by the CMJSPY-W TROJAN!"
|
| ? | hpqcmon | hpqcmon.exe | "From HP and related to digital imaging"
|
| ? | hpqSRMon | hpqSRMon.exe | "Related to HP Digital Imaging products. What does it do and is it required?"
|
| U | HPSCANMonitor | hpsjvxd.exe | HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
|
| ? | hpScannerFirstBoot | scannerfb.exe | "HP scanner related"
|
| X | hpsysconf1 | [random filename] | "Added by a variant of the VIVIA.A TROJAN!"
|
| N | HPU | ProvenTactics.exe | "Proven Internet Marketing software"
|
| U | hpWirelessAssistant | HP Wireless Assistant.exe | The HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
|
| U | hpWirelessAssistant | HPWAMain.exe | Wireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
|
| X | HP_runner | front.exe | "Added by the SILLYFDC WORM!"
|
| X | Hrn_qtv | hrnsvc32.exe | "Added by the SDBOT-AET WORM!"
|
| U | HSON | HSON.exe | Toshiba HotStart button support for instant-on entertainment on their laptops
|
| U | HSTrans | hstrans.exe | "Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
|
| ? | HsuGuiControl | HsuGuiControl.exe | "Part of the Starband Internet satellite client. What does it do and is it required?"
|
| U | Hti | npdor.exe | "Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
|
| X | HTTP Tunneling Server | mstunnel.exe | "Added by the RBOT.EDL WORM!"
|
| X | http://www.lienvandekelder.be | LienVandeKelder.exe | "Added by the MYTOB-AZ WORM!"
|
| X | http://www.lienvandekelder.be | Lien Van de Kelder.exe | "Added by the MYTOB-AP WORM and variants!"
|
| X | http://www.lienvandekelder.be | Lien Vande Kelder.exe | "Added by the MYTOB-AQ WORM!"
|
| X | http://www.lienvandekelder.be | Lien vd Kelder.exe | "Added by the MYTOB-M WORM!"
|
| X | http://www.lienvandekelder.be | Lien.exe | "Added by the MYTOB-CZ WORM!"
|
| X | http://www.lienvandekelder.be | Lientjeuh.exe | "Added by the MYTOB-P WORM!"
|
| X | http://www.lienvandekelder.be | LienVdK.exe | "Added by the MYTOB-U WORM!"
|
| X | http://www.lienvandekelder.be | Van de Kelder Lien.exe | "Added by the MYTOB-BF WORM!"
|
| X | http://www.lienvandekelder.be | We Love Lien Van de Kelder.exe | "Added by the MYTOB-CV WORM!"
|
| X | http://www.lienvandekelder.com | Lien Van de Kelder.exe | "Added by the MYTOB-EQ WORM!"
|
| X | http://www.lienvandekelder.com/ | LienVandeKelder.exe | "Added by the MYTOB-EO WORM!"
|
| X | httpd | c_pan.exe | Added by a variant of the DELF-A TROJAN!
|
| X | httpd | deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
| U | HughesNet Tools | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| X | Hvewsveqmg | ANACON.EXE | "Added by the NACO.A WORM!"
|
| X | HWINFO* | HWINFO* | "Added by the PUROL WORM! where * is a random character"
|
| Y | HWinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
|
| X | hxadsec | [path to trojan] | "Added by the ADCLICK-AP TROJAN!"
|
| U | HydarVisionDesktopManager | desk95.exe | "ATI's HydraVision desktop management software |
| U | HydraVisionDesktopManager | desk98.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionDesktopManager | HydraDM.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes |
| U | HydraVisionViewport | viewport.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionViewPort | HydraMD.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates |
| X | Hyper Start | instantmsgrs.exe | "Added by the RBOT-NH WORM!"
|
| X | I am not Ranky. I am eTunnel! | msyervice.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | winsys.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | disney.exe | Added by an unidentified WORM or TROJAN!
|
| X | I just want to say I love Milko and I need a drink | svchost.exe | "Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
|
| X | I/O Controllers | svcnet.exe | "Added by the TIBIK-B TROJAN!"
|
| U | i8kfangui | i8kfangui.exe | Graphical interface for fan speed control
|
| U | IAAnotif | Iaanotif.exe | "Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes |
| X | Iamnacho On Irc.MusIrc.com Is a Homosexual! | XBox64.exe | "Added by the RANDEX.Y WORM!"
|
| ? | IaNvSrv | IaNvSrv.exe | "Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
|
| X | ibin | [path to trojan] | "Added by the PERDA-C TROJAN!"
|
| Y | IBM Client Security | certtool.exe | "Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk) |
| N | IBM Client Security Software | csecwiz.exe | "Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once |
| Y | IBM Password Manager | pwmgr.exe | "Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information |
| N | IBM RecordNow! | RecordNow.exe | "IBM customized version of the RecordNow! CD-writing utility from Sonic Solutions"
|
| U | IBM ThinkPad EasyEject Support Application | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad EasyEject Tray Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad Tray Utility | TP98TRAY.EXE | "System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility |
| U | IBM ThinkPad Utility | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
|
| U | IBM TrackPoint Accessibility Features | tp4ex.exe | "Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound"" |
| ? | IBM Warranty Notification | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| ? | Ibmmon.exe | Ibmmon.exe | "??"
|
| U | IBMUltraBayHotSwapCPLLoader | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
|
| ? | IBMUltraBayHotSwapSound | IBMBAYSN.EXE | "Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
|
| U | IBWin Background process | IBackground.exe | "IBackup for Windows"
|
| U | IBWin Monitor | IBMonitor.exe | "IBackup for Windows"
|
| U | iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| X | icccomp | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| X | ICcontrol | iccontrol.exe | "ICcontrol premium rate adult content dialer"
|
| X | icdd7ee6 | "rundll32.exe icdd7ee6.dll | EnableRunDLL32" |
| X | icddefff | "rundll32.exe icddefff.dll | EnableRunDLL32" |
| N | ICH Synth | eusexe.exe | "Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
|
| U | iClean | iClean.exe | "IEClean - ""advanced |
| X | ICManagement | msic32.exe | "Added by the MSIC BACKDOOR!"
|
| N | iCn | NAG.EXE | "iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy |
| N | Icon Animation | HDE.EXE | Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
|
| N | Icon Hearit 95 | hearit95.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| N | Icon Hearit 98 | hearit98.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| X | Icon lptt01 | icon.exe | "RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Icon ml097e | icon.exe | "RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | iconcache | icon.bat | "Related to the Vista Customization Pack"
|
| Y | ICONCLNT | iconclnt.exe | "APC PowerChute® Personal Edition tray icon"
|
| U | ICONDESK | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons
|
| N | Iconfig.exe | Iconfig.exe | Icon for LS-120 "Superdisk"
|
| X | iConfigLoader | DIIhost.exe | "Added by the GAOBOT.AO WORM!"
|
| N | Iconoid | Iconoid.exe | "Iconoid is a desktop icon manager"
|
| N | Iconsaver | Iconsaver.exe | "IconSaver is a desktop icon manager"
|
| X | ICQ | ICQNET.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | ICQ Agent | icq6.exe | "Added by the AGENT-FZJ TROJAN!"
|
| X | ICQ Center | [path to worm] | "Added by the RANDIN WORM!"
|
| X | ICQ Hacking Pro | ICQpro.exe | "Added by a variant of the NETSPY TROJAN!"
|
| X | icq lite | winlog.exe | "Added by the IRCBOT-TJ TROJAN!"
|
| X | ICQ Lite Messenger | ICQLITE.EXE | "Added by an unidentified VIRUS |
| X | ICQ Messenger 2002 | ICQ2002.exe | "Added by the SDBOT-ABL WORM!"
|
| X | ICQ Net | winlogon.exe | "Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
|
| U | ICQMonitor | ICQMonitor.exe | "ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself"
|
| X | ICQMsn | [path to trojan] | "Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
|
| X | ICQNet | winlogon.exe | "Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | icrosof Avps32 Control | av32.pif | "Added by the RBOT-AVC WORM!"
|
| X | icrosoft Visual InterDevc | zvslmqb.exe | "Added by the RBOT-AYP WORM!"
|
| X | icrosoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AER WORM!"
|
| X | icrosoftf Avpx Control | avpx.exe | "Added by the RBOT-AYN WORM!"
|
| U | ICSDCLT | "rundll32.exe Icsdclt.dll | ICSClient" |
| N | ID Commander | IDCom.exe | Caller ID utility for identifying incoming telephone numbers
|
| X | idecntl | idecntl.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| X | idlesam | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| N | IDMan | IDMan.exe | "Internet Download Manager - download files faster |
| X | idmlssp | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| N | IDW Logging Tool | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
|
| X | IE configure | explorer.exe | "Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
|
| X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | "Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| U | IE New Window Maximizer | iemaximizer.exe | "IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows"
|
| X | IE Runtime | wini.exe | "Added by the PICRATE.B WORM!"
|
| X | IE Runtimes | winis.exe | "Added by the RBOT-ADZ TROJAN!"
|
| X | IE**.exe [* = random char] | IE**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IE**32.exe [* = random char] | IE**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IE-Security | iescan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE-Security | wdscan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE6 | porn.pif | "Added by the RBOT-ATF WORM!"
|
| X | IE6 | winsnt.exe | "Added by the RBOT-GOV WORM!"
|
| X | IEAgent update check | iewatch.exe | "Added by the BOMKA TROJAN!"
|
| U | IECleanAux | Ieboot6.exe | "IEClean by Kevin McAleavy - cookie manager |
| X | IEengine | IEeng.exe | "STARTPAG.AI hijacker"
|
| X | IEFeatures | Internetfeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | Iehelper | syslaunch.exe | Outwar adware downloader
|
| X | iel2cde8 | "rundll32.exe iel2cde8.dll | EnableRunDLL32" |
| X | ielcaabe | "rundll32.exe ielcaabe.dll | EnableRunDLL32" |
| X | ieupdate | MCP****.exe [**** = random char] | "Added by the ASOXY TROJAN!"
|
| X | ieupdate | [random filename] | "Added by the AGENT-C BACKDOOR!"
|
| X | IEWinserv | winserv.exe | "Added by the BANKER-MY TROJAN!"
|
| X | iExplore Ini | ie4uini.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | IEXPLORE.EXE | [path to trojan] | "Added by the BANCOS-CJ TROJAN!"
|
| X | IExplorer32 Java Scripting | IExplore32b.exe | "Added by the RBOT.ABO WORM!"
|
| X | IExplorer32c Java Scripting | IExplore32cb.exe | "Added by the RBOT.ABN WORM!"
|
| X | IExplorer6 Java Scripting | IExplore326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorer7 Java Scripting | IExplore327.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorerService | WinSock.exe | "Added by the AGENT.KIU TROJAN!"
|
| X | ifperx | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| N | igndlm.exe | DLM.exe | "IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin |
| X | Iinl | iptl.exe | "PurityScan adware"
|
| X | IISADMINS | systems.exe | "Added by the AGOBOT.U WORM!"
|
| U | IJNetworkScanUtility | CNMNSUT.EXE | Network utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
|
| U | iKeyWorks | IKEYMAIN.EXE | "A4Tech wireless keyboard driver and utility"
|
| U | IKL | rundll32.exe [path] IKL.dll | "IKL surveillance software. Uninstall this software unless you put it there yourself"
|
| ? | ILO_Office_Manager | IntEdReg.exe /OFFMAN | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| N | iM Start Center | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
|
| X | Image | "rundll32 [path] [trojan filename] | Install" |
| X | Image Remote Players | sysvn.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| N | Image Transfer | SonyTray.exe | Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
|
| U | ImageDrive-{hex numbers} | ImageDrive.exe | "Nero ImageDrive from Ahead - virtual CD/DVD drive software"
|
| X | ImagePath | taskbarmngr.exe | "Added by the SDBOT-XB WORM!"
|
| U | ImageTune | dthtml.exe | "ImageTune from Hyundai ImageQuest. Rebranded version of Display Tune from Portrait Displays |
| N | iMarkup Client | iUtil.exe | "Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
|
| U | Imatio | imation.exe | "Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive"
|
| X | IME | conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
|
| U | ImgIcon | ImgIcon.exe | "Displays Iomega icons in Explorer/My Computer |
| X | ImMsn | timed.exe | "Added by the WEBDOR.AK TROJAN!"
|
| U | Imonitor | Plguni.exe | "Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection |
| X | imonitor | [path to trojan] | "Added by the IMONI-A TROJAN!"
|
| U | IMONTRAY | imontray.exe | "System tray monitoring of fans |
| U | ImScInst | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | ImScInst.exe | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | IMVU | IMVUClient.exe | "IMVU chat client that allows you to create ""your own avatars who chat in animated 3D scenes"""
|
| X | imwinsrvc | acpmonsrv.exe | "Added by the SLAPER.E TROJAN!"
|
| X | imxecs | vbrun70sp4.exe | "Added by the AGOBOT.ALA WORM!"
|
| X | im_autorn | im_1.exe | "Added by the IMAV.A WORM!"
|
| X | im_autorn | im_2.exe | "Added by the BAGLEDL-BO TROJAN!"
|
| Y | InCD | incd.exe | "Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3) |
| N | IncMail | IncMail.exe | """IncrediMail is an advanced |
| X | incognito | incognito.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| N | InControl Desktop Manager | DMHKEY.EXE | For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
|
| X | Incredible Keylogger | AdvKeylog.exe | "IncredibleKeylogger spyware"
|
| N | Incredimail | incredimail.exe | ""IncrediMail is an advanced |
| N | Incredimail | IncMail.exe | """IncrediMail is an advanced |
| X | Index Service | dllhost32.exe | "Added by the AGOBOT.CH WORM!"
|
| U | Index Washer | WashIdx.exe | "Window Washer from Webroot Software. Useful utility that deletes safe to remove files |
| ? | Indexer | Indexer.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| X | Indexindicator | Indexindicator.exe | "Added by the LAZAR TROJAN!"
|
| N | IndexSearch | IndexSearch.exe | "Part of Nuance (ScanSoft) PaperPort - ""scan |
| U | IndexTray | IndexTray.exe | "Part of
| U | IndicatorUty | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMIndexStoreSvr.exe | "Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
|
| X | ine | svchosts.exe | "Added by the RBOT.BNL WORM!"
|
| X | INET | inetsync.exe | "Meplex adware"
|
| X | Inet DataBase | Inetdbs.exe | "Added by the QEDS WORM!"
|
| X | Inet Delivery | inetdl.exe | "Inet Delivery adware"
|
| X | Inet Delivery | inetdl_2.exe | "Inet Delivery adware"
|
| X | Inetapi | Netapi.exe | "Added by the NETDEVIL.14 TROJAN!"
|
| X | InetChk | ms[random value].exe | "Added by the AGENT-IRL TROJAN!"
|
| U | inetcntrl | inetcntrl.exe | Bsafe Online - internet filter
|
| ? | InetConf | inetconf.exe | "??"
|
| U | Inetd | INETD32.EXE | "Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
|
| U | inetinfo.exe | inetinfo.exe | "Executable used by MS Internet Information Server (IIS). If it's running |
| X | inetinfomon manager | inetinfomon.exe | "Added by the DONBOMB.A TROJAN!"
|
| X | inetmgr | inetmgr.exe | "Actual Names (AdvSearch) Internet Keywords parasite"
|
| X | InetMSN | msnet.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | InetServices | wsock32.exe | "Added by the WOCK32-A TROJAN!"
|
| X | infamous.exe | wmplayer.exe | Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
|
| X | InfeStop | InfeStopRemover.exe | "InfeStop rogue spyware remover - not recommended |
| X | info | smss.exe | "Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
|
| X | INFO DATA | apc.exe | "Added by the RANDON.B WORM!"
|
| U | Info Select | is.exe | "Info Select from Micro Logic - personal information manager"
|
| X | Info32x | Info32x.exe | "Added by the GEMA TROJAN!"
|
| X | InfoData | "rundll32.exe ********.dll | realset [* = random char]" |
| U | InfoPenMSN | InfoPenIM.exe | "InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
|
| ? | Infoplay.exe | Infoplay.exe | "Written by New Media Properties |
| X | Information Update | iu.exe | "Detected by Kaspersky as the CENTIM.CH TROJAN!"
|
| U | Infra-red Monitor | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices
|
| X | infus | infus.exe | Adult content dialler
|
| U | Infuzer | Infuzer.exe | "Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them |
| X | infwin | infwin.exe | "VX2.Transponder parasite updater/installer related"
|
| X | Init | [path to trojan] | "Added by the DROPPER.EAT TROJAN!"
|
| X | Init32 | Init32.exe | "Added by the WINEX.A TROJAN!"
|
| X | Initial Page | install.exe | EasySearch browser hijack installer
|
| Y | Initialize8x8 | 8x8_init.exe | Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
|
| X | inixs | minix32.exe | "Added by the AGENT.CKQX TROJAN!"
|
| X | injob | injobs.exe | "Added by the BINJO TROJAN!"
|
| N | Ink Monitor | InkMonitor.exe | Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
|
| N | InkWatch | InkWatch.exe | Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
|
| X | Inom | snmoo.exe | "Added by the RBOT-DPM WORM!"
|
| Y | InoRPC | InoRpc.exe | "Associated with eTrust Antivirus/InoculateIT"
|
| Y | InoRT | InoRT9x.exe | "Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage"
|
| U | InoTask | InoTask.exe | "Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
|
| X | iNotice | iservice.exe | Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
|
| ? | insCOA5 | insCOA5.exe | "??"
|
| X | Insider | Insider.exe | "Added by the AGENT.KMC TROJAN!"
|
| U | InstaAlert | InstaAlert.exe | """Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
|
| X | Instafinder | instafinder.exe | "TopSearch.D adware"
|
| X | InstaFinderK | InstaFinderK inst.exe | "InstaFinder adware"
|
| X | Install | Install.exe | "Added by the BANCBAN-HG TROJAN!"
|
| X | Install part II | updates.exe | "Added by the RELFEERWORM!"
|
| ? | Install Pending Files | sifxinst.exe | "Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
|
| x | install32 | install32.exe | "Added by the NUCLEAR.DG BACKDOOR!"
|
| N | InstallAurealDemos | InstallAurealDemos.js | Used to initialize the Aureal A3D demos InstallShield wizard
|
| U | InstallBuddy | Ibtna.exe | "InstallBuddy - automatically translates and installs your desktop documents |
| X | InstallCleaner | InstallCleaner.exe | "Added by the ANYHOMB.F TROJAN!"
|
| X | Installed shell32.dll | Office.exe... | "Added by the LOVGATE.AO WORM!"
|
| X | Installed shell32.dll | Office.exe | "Added by the LOVGATE.E WORM!"
|
| X | Installer | dial.exe | "Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
|
| ? | InstallNAIProduct | SETUP.EXE | "Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
|
| X | InstallProgram | [path to trojan] | "Added by the AGENT-HHU TROJAN!"
|
| X | InstallProvider | newsoftware2007install.exe | "Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
|
| X | Installs SP2 | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
|
| X | Installs SP4 | [path] repcale.exe [path] p0rd.exe | "Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
|
| U | Installstub | installstub.exe | "Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
|
| X | Instance 001 | [path to worm] | "Added by the ALASROU-A WORM!"
|
| X | Instant Access | "rundll32.exe EGDHTML_1023.dll | InstantAccess" |
| X | Instant Access | "rundll32.exe eg_auth_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMLIB_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMSERVICE_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe p2esocks_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | mwsrvacc.exe | "InstantAccess premium rate adult content dialer"
|
| X | Instant Access | linewsrv.exe | "InstantAccess premium rate adult content dialer variant"
|
| X | Instant Buzz Daemon | IBDaemon.exe | "Instant Buzz adware"
|
| X | Instant Messenger Service | imservice.exe | "Detected by Kaspersky as the HEUR TROJAN!"
|
| X | instant messengers | instantmsgtr.exe | "Added by the AGOBOT-PC BACKDOOR!"
|
| N | Instant Update Center | reminder.exe | "Event reminder for calendar dates |
| U | Instant Wireless Configuration Utility | WUSB11cfg.exe | "Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| U | Instant Wireless Configuration Utility | WPC11Cfg.exe | "Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| N | InstantAccess | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
|
| U | InstantDrive | InstantDrive.exe | "Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
|
| X | InstantPleasure | instantpleasure.exe | Adult content dialler
|
| X | InstantPleasureXXX | instantpleasurexxx.exe | Adult content dialler
|
| N | InstantTray | PCLETray.exe | "Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
|
| X | instit | instit.bat | "Added by the OPASERV.H WORM!"
|
| X | instit | INSTIT.BAT | "Added by the OPASERV.K WORM!"
|
| ? | InstUtlR.exe | InstUtlR.exe | "??"
|
| X | InSysSecure | InSysSecure.exe | "InSysSecure rogue security software - not recommended |
| X | intdctrr | idctup20.exe | "SafeSurfing adware variant"
|
| X | Intec Service Drivers | msmsgrs.exe | "Added by the SDBOT-ADN WORM!"
|
| X | Intec Service Drivers | [path to worm] | "Added by the RBOT-GLU WORM!"
|
| X | Intec Service Drivers | wing32.exe | "Added by the RBOT.HAZ WORM!"
|
| X | Intec Service Drivers | msmsgredss.exe | "Added by the SDBOT-AGL WORM!"
|
| X | Intec Services Driverrs | winrvc.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Intec Services Drivers | msupdate22e.exe | "Added by the RBOT-CGC WORM!"
|
| U | IntegardTray | IntegardTray.exe | "System Tray access to Integardparental control software from Race River Corp"
|
| U | Intel Active Monitor | imontray.exe | "System tray monitoring of fans |
| X | Intel Audio Studio V2.0 | fmideploy.exe | Detected by VBA32 as the BIFROSE.ADR TROJAN!
|
| X | Intel Driver | csrs.exe | "Added by a variant of the SDBOT WORM!"
|
| U | Intel File Transfer | xfr.exe | Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
|
| X | Intel Management Services v32 | mstime32.exe | "Added by the AUTORUN-AYG WORM!"
|
| U | Intel PDS | pds.exe | Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
|
| X | Intel Physical Routine 1.2A | stnetlib.exe | "Added by the BACKDR-AS BACKDOOR!"
|
| U | Intel Product Number Utility | IntelProcNumUtility.exe | "Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
|
| N | Intel PROSet Tray Icon | promon.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
|
| X | Intel Service Drivers | msconfig16.exe | "Added by the MSCONFIG16 TROJAN!"
|
| X | Intel system tool | hookdump.exe | "Added by the SPYRE-H TROJAN!"
|
| X | Intel system tool | winnook.exe | "Added by the SPYRE-C TROJAN!"
|
| X | Intel system tool | svehost.exe | "Added by the AGENT-EBT TROJAN!"
|
| X | Intel system works | iis.exe | "Added by the RBOT.QGA WORM!"
|
| U | Intel(R) Common User Interface | igfxtray.exe | "System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
| X | intel32.exe | intel32.exe | "Added by the SmitFraud alias SPYJACK-B TROJAN!"
|
| U | IntelAPMClient | amclient.exe | "LANDesk® Management Suite software component"
|
| N | IntelAudioStudio | IntelAudioStudio.exe | """Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience"". Audio utility supplied with some Intel motherboards"
|
| X | InteliSys | smss.exe | "Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | intell32.exe | intell32.exe | "Added by the SmitFraud alias Desktophijack.C TROJAN!"
|
| X | intell321.exe | intell321.exe | "Added by the SPYJACK-B TROJAN!"
|
| X | Intelli Mouse Pro Version 2.0B | ncsjapi32.exe | "Added by the BUZUS-O WORM!"
|
| X | Intelliflag_be.exe | Intelliflag_be.exe | "Intelliflag spyware"
|
| U | IntelliPoint | point32.exe | "Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice |
| U | IntelliPoint | ipoint.exe | "Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice |
| U | Intellitype | type32.exe | "Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys |
| U | IntelMEM | IntelMEM.exe | "Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore |
| X | Intelprc | Aas3lovu.exe | "Added by the SILLYFDC-CG WORM!"
|
| U | IntelProcNumUtility | cpunumber.exe | "Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
|
| Y | IntelWireless | ifrmewrk.exe | Associated with the Intel PRO/Set Wireless software
|
| U | IntelZeroConfig | ZCfgSvc.exe | "Zero Config MFC Application |
| ? | Intense Registry Service | IntEdReg.exe /CHECK | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| X | InterceptedSystem | [path to worm] | "Added by the ANACON-B WORM!"
|
| Y | InterCheck Monitor | Icmon.exe | "Part of Sophos ant-virus sofware"
|
| Y | InterCheckMonitor | ICMON.EXE | "Part of Sophos anti-virus sofware"
|
| X | Interdll | Interdll.exe | "Added by the DELF family of TROJANS!"
|
| X | Internal | [trojan filename] | "Added by the SMOTHER and TRANSLAT TROJANS!"
|
| X | Internal | regedit.exe /s c[month number] | "Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir% |
| X | Internal Memory File | sysintmemory.exe | "Added by the RBOT-GKT WORM!"
|
| X | InternalSystray | Kazza.exe | "Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable |
| X | internat | internat.exe | "Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
|
| X | Internat | systray.exe | "Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
|
| X | Internat | msgsrv32.exe | "Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
|
| X | Internat | [trojan filename] | "Added by the CMJSPY-Y TROJAN!"
|
| X | Internat Conf | bootconf.exe | "Homepage hijacker |
| N | internat.exe | internat.exe | "Microsoft language selection icon in system tray |
| X | Internat.exe | internat.exe | "Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a ""?"" icon wheras this version resides in %windir% and has a ZIP icon"
|
| X | internct | WinSocks5.exe | "Added by the GRAYBIRD.F TROJAN!"
|
| X | internet | smss.exe | "Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
|
| X | Internet | Internet.exe | "Added by the PWS-CS TROJAN!"
|
| X | Internet | recruit.exe | "Added by the RBOT-AJG WORM!"
|
| X | internet | [trojan filename].exe | "Added by the MIFENG-D TROJAN!"
|
| X | Internet | winlogom.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Internet | nteusodp.exe | "Added by the RBOT-GFJ WORM!"
|
| X | internet | winsas32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | internet | lsass.exe | "Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | Internet | alm7tas.exe | "Added by a variant of the RBOT WORM!"
|
| X | Internet | wins.exe | "Added by the RBOT.AAYF WORM!"
|
| U | Internet Answering Machine | IAMNET~1.EXE | "From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| U | Internet Answering Machine | IAM.exe | "From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| X | Internet Antivirus | IAvir.exe | "Internet Antivirus rogue security software - not recommended |
| X | Internet Antivirus Pro | IAPro.exe | "Internet Antivirus Pro rogue security software - not recommended |
| X | Internet Application Driver | expIorer.exe | "Added by the IRCBOT-WK TROJAN!"
|
| U | Internet Call Director | ICD.EXE | "TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
|
| U | Internet Call Manager | ICM.EXE | "Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
|
| X | Internet Config | svchosts.exe | "Added by the SDBOT TROJAN!"
|
| X | Internet Connection Wizard | stisvsq.exe | "EasySearch adware"
|
| X | Internet Connection Wizard | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Internet Connection Wizard | stisvsq1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Internet Content Publisher | ICP.EXE | "Added by the RBOT-UD WORM!"
|
| U | Internet Disk Cleaner | CLEARH~1.EXE | """Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
|
| U | Internet Download Accelerator | ida.exe | "Internet Download Accelerator download manager"
|
| X | Internet download manager service | idman.exe | "Added by the RBOT-BMS WORM!"
|
| X | Internet Exploere Services | urlmon32.dll.exe | "Added by the EVIAN.C WORM!"
|
| X | Internet Explore Microsoft | lEXPLORE.EXE | "Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
|
| X | Internet Explorer | iexplorer.exe | "Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Internet Explorer | IEXPLORE.EXE | "Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Internet Explorer | IExplorer.exe | "Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Internet Explorer | http.exe | "Added as part of a new potential CWS infection |
| X | Internet Explorer | iexpiore.exe | "Added by the RBOT-AZC WORM!"
|
| X | Internet Explorer | IEPLORE32.EXE | "Added by the AGOBOT-CU WORM!"
|
| X | Internet Explorer | twain.exe | "Added by the AGENT.BEA TROJAN!"
|
| X | Internet Explorer Agent | iexplorer.exe | "Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Internet Explorer Auto-Update | updt32v5.exe | "Added by the SPYBOT-AB BACKDOOR!"
|
| X | Internet Explorer Configuration | IEXPLORE.EXE | "Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Internet Explorer Security | iexplore.pif | "Added by the RBOT-ALQ WORM!"
|
| X | Internet Explorer Sys32 | isys32.exe | "Added by the IRCBOT-ADA WORM!"
|
| X | Internet Explorer Updater | lexbac.exe | "Added by the DOWNLOAD TROJAN!"
|
| X | Internet Explorer Updater | iexplorer.exe | "Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Internet Explorer6 | IEexplore.exe | "Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Internet Explorer6.0 | IEXPLORE.EXE | "Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Internet Firewall Layer | tsqla.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | Internet History Eraser | HERASER.exe | "Internet History Eraser - deletes your browsing tracks"
|
| X | Internet Loader1 | MSInstall61.exe | "Added by the KWBOT.B WORM!"
|
| X | Internet Mail and News | msqdevl.exe | "EasySearch adware"
|
| X | Internet Mail and News | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Internet Mail and News | msqdevl1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Internet Optimizer | optimize.exe | "Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants"
|
| X | Internet Protocol Configuration Loader | ipcl32.exe | "Added by the SDBOT TROJAN!"
|
| X | Internet Security 2010 | IS2010.exe | "Internet Security 2010 rogue security software - not recommended |
| X | Internet Security Service | msq32.exe | "Added by the RBOT-GFP WORM!"
|
| X | Internet Security Service | msq23.exe | "Added by the RBOT-GQL WORM!"
|
| X | Internet Security Service | msql23.exe | "Added by the RBOT-GML WORM!"
|
| X | Internet Security Service | mysqlwin32.exe | "Added by the RBOT.UX TROJAN!"
|
| X | Internet Security Service | expllorer.exe | "Added by the REFROSO.AFF TROJAN!"
|
| X | Internet Send | More log.exe | Unidentfied adware
|
| X | Internet Server | inetsrv.exe | "Added by the STARTPA-EM TROJAN!"
|
| X | Internet Service | intersvc.exe | "Added by the SPYBOT-DE WORM!"
|
| X | internet service | syscfg32.exe | "Added by the RBOT-QS WORM!"
|
| X | internet service | ssvhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | internet service | svho0st98.exe | "Added by the RBOT.EAT WORM!"
|
| X | Internet Services | systemdev.exe | "Added by the SDBOT-PW WORM!"
|
| X | Internet Services | internet.exe | "Added by the MYTOB.BT WORM!"
|
| X | Internet Services | interserv.exe | "Added by the RBOT.BNT WORM!"
|
| X | Internet Services | Netsvc.exe | "Added by the MYTOB.MN WORM!"
|
| X | INTERNET SERVISES | winz32.exe | "Added by the KWBOT.Z WORM!"
|
| Y | Internet Sharing Server | iss_srvr.exe | "Intel AnyPoint internet sharing software. Now discontinued"
|
| X | Internet Suspention | story.exe | "Added by the WOOTBOT.HV WORM!"
|
| N | Internet Sweeper | Sweeper.exe | "Internet Sweeper - removes unnecessart left over files after browsing the internet"
|
| U | Internet Timer | ITIMER.exe | "Shareware dial-up connection call cost calculator from Ratsoft"
|
| X | Internet Washer Pro | iw.exe | "Internet Washer manages temporary browser files |
| X | Internet.exe | Internet.exe | "Added by the MAGICCALL VIRUS!"
|
| X | internet.exe | yinyin3345.vbs | "Added by the YINI MACRO!"
|
| X | Internet2 Optimizer | wkfix.exe | "Added by a variant of the RBOT WORM!"
|
| N | InternetCalls | InternetCalls.exe | "InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| X | InternetExplorer2 | windows.exe | "Added by the SDBOT-CZP WORM!"
|
| X | InternetExplorer32 | iexplore32.exe | "Added by the RBOT-GRA WORM!"
|
| X | InternetGetConnectedState | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetGetConnectedStateEx | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetShield | INTERN~1.EXE | "InternetShield rogue security software - not recommended |
| X | InternetShield | InternetShield.exe | "InternetShield rogue security software - not recommended |
| U | InternetSpy | InternetSpy.exe | "Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
|
| X | InternetWasherPro | iw.exe | "Internet Washer manages temporary browser files |
| X | Internet_Explorer | microsoft.exe | "Added by the BANKER-EUQ TROJAN!"
|
| X | Internet_Explorer.exe | Internet_Explorer.exe | "Added by the BANKER-END TROJAN!"
|
| X | INTERNET_SERVISES | winz32.exe | "Added by the SDBOT.Q TROJAN!"
|
| U | InternodeUsage | mum.exe | Australian ISP's free monthly download meter
|
| X | Internt | Internt.exe | "Added by the PEEPER or CARUFAX.A TROJANS!"
|
| X | Inters Configuration Loader | RCL0ADERS.exe | "Added by the SDBOT-KX WORM!"
|
| X | Intersoft Msngr | intersoftmsngr.exe | "Added by the AGOBOT-NW WORM!"
|
| N | InterTrust Quick Start | it_cpq~1.exe | "InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
|
| X | InterU | WINDRV.EXE | "Added by the IRCINTER.A TROJAN!"
|
| N | Intervideo Win Cinema Manager | WinCinemaMgr.exe | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo Win Cinema Manager | WINCIN~1.EXE | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinCinema Manager | WinCinemaMgr.exe | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinCinema Manager | WINCIN~1.EXE | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinScheduler | WinScheduler.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| N | Intervideo WinScheduler | SchSvr.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| N | InterVoip | InterVoip.exe | "InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| U | InterWARN | interwarn.exe | "InterWARN by Storm Alert Inc. Provides customized |
| X | Intespention | IEXPLORE.exe | "Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Intmgr | Intmgr.exe | "Added by the GEMA TROJAN!"
|
| X | intranet | SYS32CFG.EXE | "Added by the SPYBOT-DW WORM!"
|
| X | Intranet | intranet.exe | "Added by the CHIMOZ.AC TROJAN!"
|
| X | Intranet | schost.exe | "Added by the RBOT.SV BACKDOOR!"
|
| X | Intranet Explorer | [random filename] | "Added by the POEBOT.DK BACKDOOR!"
|
| X | Intrenat | Intrenat.exe | "Added by the LEMIR.E TROJAN!"
|
| N | Introducing Media Manager | SPLASHA.EXE | "MS Media Manager tour. Not required"
|
| N | Introduction-Registration | ?? | "For Compaq PC's. Should only run first time |
| X | IntruderAlert | ia99.exe | "Intruder Alert '99 from Bonzi - spyware"
|
| X | IntSys1 | [path to trojan] | "Added by the BANLOA-ASE TROJAN!"
|
| Y | Intuit SyncManager | IntuitSyncManager.exe | "Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync |
| U | Inventory Scan | LDISCN32.EXE | "LANDesk® Management Suite software component"
|
| N | iobi | iobiClient.exe | "iobi Home - a mail/voice service by Verizon"
|
| Y | iolo AntiVirus | ioloAV.exe | "iolo AntiVirus"
|
| Y | iolo Personal Firewall | ioloFW.exe | "iolo Personal Firewall"
|
| U | Iolo Task Agent | Task_Agent.exe | "Iolo System Mechanic Task Agent. Scheduled maintenance"
|
| U | Iomega Disk Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| U | Iomega Drive Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| U | Iomega ImIconXP | imiconxp.exe | "Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system |
| ? | Iomega QuickSync | Quicksync.exe | "??"
|
| N | Iomega Startup Options | IMGSTART.EXE | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| N | IomegaWare | COMMANDER.EXE | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| U | Iomon98.exe | Iomon98.exe | PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
|
| U | IP Changer 2.0 | IPChanger.exe | "IP Changer 2.0 from Plustech Inc - network configuration management tool"
|
| X | IP**.exe [* = random char] | IP**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IP**32.exe [* = random char] | IP**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| N | iPalm | mon.exe | "Installed with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded"
|
| X | IPC Connection | ipcconn.exe | "Added by the RBOT-AEG WORM!"
|
| X | IPC Spool Manager | wnmgre.exe | "Added by the SDBOT-ZC WORM!"
|
| X | IPC Spool Manager | winspec.exe | "Added by the SDBOT-BLU WORM!"
|
| X | IPConfig | svcxnv32.exe | "Added by the HACARMY.E TROJAN!"
|
| X | IPConfig | svcxnw32.exe | "Added by a variant of the HACARMY.E TROJAN!"
|
| X | IPConfig | ipconfigs.exe | "Added by the HACARMY.C BACKDOOR!"
|
| X | IpCtrl | ipcon32.exe | "Added by an unidentified VIRUS |
| ? | IPHSend | IPHSend.exe | "AOL related. What does it do and is it required?"
|
| N | IPInSightLAN 01 | IPClient.exe | "IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth |
| N | IPInSightMonitor 01 | IPMon32.exe | "IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth |
| Y | IPinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
|
| ? | iPlusAgent2 | iAgent2.exe | "Related to iriver portable media products. What does it do and is it required?"
|
| X | ipmon.exe | ipmon.exe | "Added by the RECERV or R3C.B TROJANS!"
|
| X | IpNetwork | ipnetwork.exe | Maxifiles adware
|
| X | Ipnuker | Ipnuker.vbs | "Added by the INKER.B WORM!"
|
| X | Ipod Help | [9 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| U | iPodManager | iPodManager.exe | "Apple iPod® management software for the iPod® player - updates |
| U | ipoint | ipoint.exe | "Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice |
| ? | iPrint LPT Redirector | nipplpte.exe | "Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
|
| N | iPrint Tray | iprntctl.exe | "Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
|
| X | iprun | iPY.exe | "iProtectYou spyware"
|
| X | IPSEC Configuration | wsupdate.exe | "Added by the AGOBOT-IQ WORM!"
|
| Y | IPSecMon | IPSecMon.exe | "Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
|
| X | IPTable Configuration | Winipcfgs.exe | "Added by a variant of the RBOT WORM!"
|
| X | IPv6 STUN Service | netstun.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IpWins | ipwins.exe | "IPWins adware"
|
| X | ipyjy | woniz.exe | "Added by the SDBOT.BQD WORM!"
|
| X | iqmanager.exe | iqmanager.exe | "IQ-Manager ransomware copyright scanner - not recommended |
| X | irassync | irasyncd.exe | "IRASSync adware"
|
| X | irc session | sessionmgr.exe | "Added by the SDBOT-ACE WORM!"
|
| N | iRis Active Monitor | winmon32.exe | "Iris Antivirus - discontinued |
| N | iRiS AntiVirus Active Monitor | WIMMUN32.exe | "Iris Antivirus - discontinued |
| U | IRIS_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
|
| U | IRIS_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
|
| U | IrMon | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices
|
| ? | IRPMonitor | itcnmon.exe | "??"
|
| X | irssyncd | irssyncd.exe | "SafeSurfing adware variant"
|
| X | Irwftp | [path to trojan] | "Added by the BANCOS-AP TROJAN!"
|
| X | irwftp | ftpmon.exe | "Added by the BANCBAN-BO TROJAN!"
|
| X | isamini.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| X | isamonitor.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| X | IsassRenascimento | Issas.exe | "Added by the BANKER.GAX TROJAN!"
|
| N | ISDN Monitor | Linksts.exe | "Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards |
| U | ISDNwatch | IWatch.exe | "FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
|
| X | iSecurity applet | "rundll32.exe iSecurity.cpl | SecurityMonitor" |
| X | ISPSERVICE | wintmp.exe | "Added by the IRCBOT.GP BACKDOOR!"
|
| U | iSpyNOW | ispynow.exe | "iSpyNOW - remote monitoring and surveillance software"
|
| N | IsReminder | ISPopup.exe | "Related to GuardWare iShield - this is the registration reminder for the trial version |
| X | ISS | inet.exe | "Meplex adware"
|
| X | issEnc32Svr | issEnc32.exe | "Added by a variant of the RBOT WORM!"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
|