| Y | Desktop Armor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| X | Desktop Defender 2010 | Desktop Defender 2010.exe | "Desktop Defender 2010 rogue security software - not recommended |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop Maestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | Desktop Maestro Vista Tray | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | Desktop Plant | AZARE10S.PLT | "Vritual plant from here - this version is an Azalea |
| X | Desktop Search | desktop.exe | "iSearch adware"
|
| X | Desktop Security 2010 | Desktop Security 2010.exe | "Desktop Security 2010 rogue security software - not recommended |
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THEWEA~1.EXE | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| Y | DesktopArmor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | DesktopMaestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | DesktopMaestro | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | desktopmgr | desktopmgr.exe | "Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | destroyb11 | destroyb11.exe | "Added by the DELF-KO TROJAN!"
|
| ? | detect | turbodetect.exe | "??"
|
| N | Detector | detector.exe | "USB port detector for LG scanners. Sits in the System Tray |
| U | DetectorApp | DetectorApp.exe | "Related to Roxio MyDVD (was Sonic) DVD authoring software"
|
| X | Deus Cleaner | DCleaner.exe | "Deus Cleaner rogue system cleaner utility - not recommended"
|
| ? | DevconDefaultDB | READREG | "Appears to be related to older Creative Soundblaster soundcards"
|
| X | Development Environment | devenv.exe | "Added by the DELBOT-AH WORM!"
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| U | Device Detector | DevDetect.exe | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
| N | Device Detector 2 | DevDtct2.exe | "Installed by various Olympus products |
| X | Device Hardware | devicehnd.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Manager | wfxmgr.exe | "Added by the RBOT.AJU WORM!"
|
| X | Device Security | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Driver | devicesec.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| U | DeviceDiscovery | hpotdd01.exe | "Detection of new imaging |
| X | DevicePath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | DevicePath | Root.exe | "Added by the GRUEL WORM!"
|
| U | Devices | olesvr.exe | "Salfeld Child Control - parental control software"
|
| X | Devicewin | [path to trojan] | "Added by the BANKER-AEV TROJAN!"
|
| U | devldr16 | devldr16.exe | Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
|
| U | devldr16.exe | devldr16.exe | "Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use ""Sound Play Control"" and ""Sound Recorder"". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable ""Creative SB16 Emulation"" under Creative Miscellaneous Devices"
|
| X | dfgfdgrergd | [path to trojan] | "Added by the RANKY.CK TROJAN!"
|
| X | dgtstart | dgtstart.exe | "DigitalNames.g adware"
|
| U | dguard | dguard.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| X | DHCP Server | regsvr.exe | "Added by the RBOT-PR WORM!"
|
| X | DHCP32 | services.exe | "Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
|
| X | Dialer | "rundll32.exe MSA32CHK.dll | Reg" |
| U | Dialer Control | dc.exe | "Dialer-Control. Detects and protects from premium rate adult content diallers"
|
| U | Dialer Detect | dd.exe | "DialerDetect detects stealth installed premium rate diallers |
| U | Dialgo SDK | PhoneAnswer.exe | "Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID |
| N | Dialog Helper | PDDLGHLP.EXE | "Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs"
|
| X | DialUp Network Application | Rnaap.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Diam prlaer | oqedrhg.exe | "Added by the SDBOT-DEU WORM!"
|
| U | Diamondback | razerhid.exe | "Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| X | DIECOX | csrss.exe | "Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Diesel | Recalculate.exe | "Added by the LAZAR TROJAN!"
|
| U | Digisoft AntiDialer | AntiDialer.exe | "Digisoft AntiDialer"
|
| U | DigiSrv | DigiSrv.exe | "Related to camera software from DigitalDreams"
|
| N | Digital Dashboard | devgulp.exe | For Compaq PC's. Loads Digital Dashboard options
|
| Y | Digital Patrol Update 5 | update.exe | "Digital Patrol - ""a powerful anti trojan scanner |
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| N | Digital River eBot | downlo~1.exe | "Digital River Systems EBOT for downloading software from their site. In some cases |
| X | DigitalNames | DigitalNamesStart.exe | "DigitalNames spyware variant"
|
| N | DigitalWizard | ISWizard.exe | "InstallShield's DigitalWizard - free |
| N | DigitalWizard Monitor | dwMon.exe | "InstallShield's DigitalWizard - free |
| U | DIGServices | DIGServices | Created by Disney but licensed to ESPN for watching videos
|
| N | DIGServices | DIGServices.exe | Created by Disney but licensed to ESPN for watching videos
|
| N | DIGStream | digstream.exe | "DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
|
| X | Dir1 | caKe | "Added by the CAKE WORM!"
|
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | Direct X Direct3D | dxd3d.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Direct X Opengl | dxopengl.exe | "Added by a variant of the RBOT-CJ WORM!"
|
| X | direct3d.exe | direct3d.exe | "Added by the CERTIF-F TROJAN!"
|
| N | DirectCD | DirectCD.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
|
| X | Director Video | btnmgern.exe | "Added by the MYTOB-KL WORM!"
|
| Y | Directory Opus Desktop Dblclk | dopusrt.exe | "Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor |
| X | directs.exe | directs.exe | "Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | DirectX | ddhelp32.exe | "Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
|
| X | directx | Directx.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | Sqlexploit.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX | DirectX.exe | "Added by the BLAXE or LOGPOLE WORMS!"
|
| X | directx | NTCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | PipeCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX 32 | directx32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | DirectX Driver | stdhost.exe | "Added by the SDBOT.GVJ BACKDOOR!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX Video Driver | dxterm5.exe | "Added by the WILAB-A TROJAN!"
|
| X | DirectX64 | DirectXset.exe | "Added by the BROWNEY.A WORM!"
|
| X | DirectX9 | direct3d.exe | "Added by the AGENT.EAK TROJAN!"
|
| X | DirectX9 | svchost32.exe | "Added by the RBOT.AQG WORM!"
|
| X | DirectX9 Diag | dx9diag.exe | "Added by the RBOT-ALT WORM!"
|
| X | DirecX | DirecX.exe | "Added by the AGOBOT-HU BACKDOOR!"
|
| U | Dirkey | Dirkey.exe | "Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders"
|
| X | DirLocker | dirlock.exe | "Added by the AUTORUN-AMS WORM!"
|
| X | DisableKeybaord | "Rundll32.exe Keyboard | Disable" |
| X | DisableMouse | "Rundll32.exe Mouse | Disable" |
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| ? | DISCover | DISCover.exe | "Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
|
| N | DiscoverDeskshop | Deskshop.exe | "Discover Deskshop - single use ""virtual"" credit card"
|
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| U | Disk Cleaner | DiskCleaner.Exe | "Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | [path to trojan] | "Added by the SMALL-VE TROJAN!"
|
| X | Disk Keeper | SECURITY.EXE | "Daosearch adware"
|
| X | Disk Manager | diskver.exe | "Added by the RBOT.AQT WORM!"
|
| X | Disk Master | [trojan name] | "Added by the DISTER TROJAN! - a spam relayer"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| X | DiskRetter | SysRep.exe | "DiskRetter |
| X | Diskstart | Code.exe | Adult content dialler
|
| X | Diskstart | cat.exe | MS-Connect dialler
|
| X | Diskstart | hit.exe | Adult content dialler
|
| X | Diskstart | Snt.exe | Adult content dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| U | Disk_Monitor | Disk_Monitor.exe | "Multi-media |
| X | Dispatcher | dispatcher.exe | "Added by the DLOADR-AS TROJAN!"
|
| X | dispenter | dispenter.exe | "Added by the AGENT-MKK TROJAN!"
|
| X | Display Drivers | cssrs.exe | "Added by the AGOBOT.FX WORM!"
|
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
|
| X | Distributed File System | Dfsvc.exe | "Added by the MYFIP.A or MYFIP.K WORMS!"
|
| X | Distributed File System | kernel32dll.exe | "Added by the MYFIP-C or MYFIP.K WORMS!"
|
| X | Distributed File System | blade.exe | "Added by the MYFIP.AC WORM!"
|
| X | Distributed File System | win.exe | "Added by the MYFIP.AB WORM!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| U | distributed.net client | DNETC.EXE | "Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
|
| X | DivX MediaPlayer 7.0 | Dr.DivX.exe | "Added by the ALADINZ.G TROJAN!"
|
| X | DivX Player | DivXPlayer.exe | "Added by a variant of the RBOT WORM!"
|
| X | DivX Updater | DivX.Exe | "Added by the NALDEM TROJAN or MASTAK VIRUS!"
|
| X | DIVX Video Player | DIVXPloyer.exe | Added by an unidentified WORM or TROJAN!
|
| X | Divx4 codec | devldr32.exe | "Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
|
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | DJRegFix | regedit /s c:hpdjregfix.reg | "DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
|
| X | djtopr1150.exe | djtopr1150.exe | "WebRebates adware"
|
| X | dKernel | dKernel.exe | "Added by the DECOY-A WORM!"
|
| Y | DkService | DkService.exe | "From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled |
| X | Dkware lptt01 | dkware.exe | "RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Dkware ml097e | dkware.exe | "RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLA | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW.EXE | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| N | DlaTray | Dlatray.exe | "System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
|
| N | dlbcserv | dlbcserv.exe | Related to Dell Photo Printers and provides additional configuration options for these devices
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| X | dlder | dlder.exe | "Dlder spyware. Also creates a fake ""explorer.exe"" file and can be installed via versions of Grokster |
| X | DlDir1 | caKe | "Added by the CAKE WORM!"
|
| ? | DLForcerExe | DLForcerEXE.exe | "??"
|
| N | DLHelperEXE | WATCH.exe | Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
|
| X | DLHelperEXE.exe | N/A | Downloader for Microgaming/Casino software - stealth installed
|
| X | DLINK dfe drivers for Windows NT | windfe.exe | "Added by the RANDEX.AK WORM!"
|
| U | DLink System Tray | dlnetst.exe | "Related to D-Link DGE-530T PCI card for servers and workstations"
|
| X | Dlite | dllmanager.exe | "Added by the WOOTBOT.DN WORM!"
|
| X | Dll Boot Loader on Startup (do not remove this) | [various filenames] | Added by an unidentified TROJAN!
|
| X | DLL Manager | dllmngr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | dll services | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | DllCacherv2 | dllcachev2.exe | "Added by the LATEDA TROJAN!"
|
| X | dllcvss | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | DllLoader | lssas.exe | "Added by the BDOOR-JE BACKDOOR!"
|
| X | Dlload | killer.exe | "Added by the KILLAV-FK TROJAN!"
|
| X | dllreg | dllreg.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | DLLService32 | dllsvc32.exe | "Added by the AGOBOT.VX WORM!"
|
| N | dlmMgr | AdobeDownloadManager.exe | "Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted |
| X | Dm Hr | lpns.exe | "Added by the IRCBOT.WORM.61673 WORM!"
|
| X | DM mgr | dm_mgr.exe | "Added by the JITTAR TROJAN!"
|
| X | dm***.exe [* = random char] | dm***.exe [* = random char] | "Wareout - malware masquerading as a spyware and dialer remover"
|
| N | DMAScheduler | DMAScheduler.exe | "Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program |
| U | DMHotKey | DMLoader.exe | HotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
|
| N | DMILDR | dmildr.exe | "Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about |
| X | dmloader | dmloader.exe | "Added by a variant of the RBOT WORM!"
|
| U | DMXLauncher | DMXLauncher.exe | "Part of Dell's Media Experience |
| X | dm[3 random letters].exe | dm[3 random letters].exe | "Added by the RUINDEM TROJAN!"
|
| X | DM_server | dmserver.exe | "Comet Cursor adware"
|
| X | dm_service | [path to file] | "Added by the MITGLIEDER.P TROJAN!"
|
| N | Dnar | Dnar.exe | "Installed on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| X | DNHelper32 | DNHlp32.exe | Added by an unidentified WORM or TROJAN!
|
| X | DNS | [worm filename] | "Added by the BCKDR-CQG BACKDOOR!"
|
| X | DNS Config service | win32.exe | "Added by the RBOT-TL WORM!"
|
| X | Dns Resolver | dnsrslve.exe | "Added by the RBOT-WS WORM!"
|
| X | DNS Service | dnsresolver.exe | "Added by the RBOT-PQ WORM!"
|
| X | DNS Service | dnssvc.exe | "Added by the DELBOT-Z WORM!"
|
| N | DNS7reminder | Ereg.exe Ereg.ini | "Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
|
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | dnscleaner | dnscleaner.exe | "CoolWebSearch parasite variant"
|
| X | DocTor | Doctor.exe | "Added by the DOTOR.A WORM!"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| U | Document Manager | docmgr.exe | "Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
|
| X | DOGStart | GSDOGST.EXE | "Added by an unidentified VIRUS |
| X | DokterFix | SysRep.exe | "DokterFix |
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| X | DomPlayer Service | wakeservice.exe | "DomPlayer adware"
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| X | Dontworry | mysaym.exe | "Added by the SDBOT-RC WORM!"
|
| N | DoroServer | DoroServer.exe | "Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| X | down | [trojan filename] | "Added by the SMALL-QJ TROJAN!"
|
| N | Download Accelerator Manager Free Edition | dam.exe | "Download Accelerator Manager Free Edition from Tensons Corp"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| N | Download Wonder | DownloadWonder.exe | "Download Wonder from Forty Software. Download manager for resuming downloads |
| N | DownloadAccelerator | DAP.EXE | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | DownloadLegalMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadWare | dw.exe | "DownloadWare adware"
|
| X | DownloadWare Engine | Dwe.exe | "DownloadWare adware"
|
| X | dpcproxy | dpcproxy.exe | "Added by the GOLDENP-A TROJAN!"
|
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | Dpcstart | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| X | dpnsvr32 | dpnsvr32.exe | "Added by the AOLPASS-B TROJAN!"
|
| N | dptracker | dptracker.exe | "CamTrack webcam software that enhances the way people video chat"
|
| U | DpUtil | TEDTray.exe | "Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device"
|
| X | dpzProtect | n.vbe | "Added by the RUNAUTO.H WORM!"
|
| X | DR service | [path to worm] | "Added by the RBOT-CZT WORM!"
|
| X | Dr. Guard | drguard.exe | "Dr. Guard rogue security software - not recommended |
| N | Drag'n'Drop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| ? | DragDrop | DragDrop.exe | "??"
|
| N | DragnDrop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| X | DRam Monitor 23 | tskman3.exe | "Added by a variant of the RBOT WORM!"
|
| X | DRam prmaessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosesor | [random filename] | "Added by the SPYBOT.EE WORM!"
|
| X | DRam prosessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosessor | plscd.exe | "Added by the RBOT.CYA WORM!"
|
| X | DRam prosessor | HWAPI.exe | "Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
|
| X | DRam prosessor | WindowsUpdate.exe | "Added by the RBOT-BBZ WORM!"
|
| X | DRam prosessor | msupdate.exe | "Added by the DELF-FAW TROJAN!"
|
| X | DRam prosessor | winupl.exe | "Added by the RBOT-BCQ WORM!"
|
| X | DRam rar proc | winupdaterar.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DRam rare proc | updaterarwin.exe | "Added by the RBOT-GQW WORM!"
|
| X | DRan posessor | DAP.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrAntispy | DrAntispy.exe | "DrAntiSpy rogue security software - not recommended"
|
| X | DrCache | MSTDC.EXE | "Added by the BDOOR-JM BACKDOOR!"
|
| X | dreams | server.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrefIW | SysDrefIWv2.exe | "Added by the DREF-C WORM!"
|
| X | DrefIW | SysDref.exe | "Added by the DREF-D WORM!"
|
| ? | dregfix | ph_finder.exe | "??"
|
| N | DrgToDsc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| ? | dried.exe | dried.exe | "??"
|
| X | drin | [path to trojan] | "Added by the SMALL.DPB TROJAN!"
|
| X | DriveCleaner 2006 Free | UDC2006.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveCleaner Free | UDC.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveDefender | GDC.exe | "DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| U | DriveIcons | DriveIcon.exe | "Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
|
| U | DriveLED | OODLed.exe | "O&O DriveLED - hard disk monitoring and crash prevention"
|
| X | Driver | gbot.exe | "Added by the JUNTADOR.K TROJAN!"
|
| X | Driver32 | Scam32.exe | "Added by the SIRCAM WORM!"
|
| X | DriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | DriverConf | dvrconf.exe | "Added by the AGOBOT-IY WORM!"
|
| X | DriverDB | svcmdx32.exe | "Added by the BERPI TROJAN!"
|
| X | DriverLoad | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| U | DriverMagicLogon | dmschedule.exe | "Part of DriverMagic - ""the easiest way to locate device drivers"""
|
| N | DriverMax | devices.exe | "DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
|
| X | DriverModule | csrnvrt.exe | "Added by the IRCBOT.I TROJAN!"
|
| X | DriverPath | system32.exe | "Added by the PRORAT-S TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| X | Drives swap | AV1i.exe | "Anti-Virus Number-1 rogue security software - not recommended |
| N | DriveSelect | driveselect.exe | "DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
|
| X | DriveSystem | maxpaynowti1.exe | "Added by the TIBS.AZT TROJAN!"
|
| U | drkly16j | "rundll32.exe drkly16j.dll | ServiceCheck" |
| X | DRM Upgrade | drmupgd.exe | "Added by the IRCBOT.AWU BACKDOOR!"
|
| U | dRMON SmartAgent | SmartAgt.exe | "Part of the network monitoring program group for 3Com NIC cards. See here for more info"
|
| X | drmsrv32 | stmhosts.exe | "Added by the AGENT.AGWU TROJAN!"
|
| X | drmu | W95Mm.exe | Homepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
|
| X | Drmupgds | Drmupgds.exe | "Maxfiles adware"
|
| X | drocher | d.exe | Adult content dialler
|
| X | DropSpam Lifestyle | dslifestyle.exe | "Dropspam adware"
|
| X | DrProtection | DrProtection.exe | "DrProtection rogue security software - not recommended"
|
| X | drvddll.exe | drvddll.exe | "Added by the BEAGLE.AP WORM!"
|
| X | Drvddll_exe | drvddll.exe | "Added by the BEAGLE.X WORM!"
|
| U | DrvIcon | DrvIcon.exe | """Vista Drive Icon changes the drive icons shown in Windows ""My Computer"" |
| ? | DrvListnr | DrvListnr.exe | "Analog Devices SoundMAX soundcard related. What does it do and is it required?"
|
| U | drvlsnr | drvlsnr.exe | Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
|
| U | DrvMon.exe | DrvMon.exe | "Alcor drive monitor software"
|
| X | drvnetw | drvnetw.exe | "Added by the BROGGER-B TROJAN!"
|
| X | drvr32h | drvr32h.exe | "Added by an unidentified VIRUS |
| X | drvrmanager | drvrquery32.exe | "Added by the BOOHOO WORM!"
|
| X | DrvStart | HPMedia.exe | "Added by the BANCBAN-QE TROJAN!"
|
| X | drvsys.exe | drvsys.exe | "Added by the BEAGLE.W WORM!"
|
| X | drvsyskit | hidr.exe | "Added by the BAGLE.HR WORM!"
|
| X | drvsyskit | hldrrr.exe | "Added by the BAGLE.QU TROJAN!"
|
| X | drvupd | rundll32 ..drvupd.inf | "Hijacker - drvupd.inf file installs a ""searchforge.com"" hijack"
|
| X | drv_st_key | hidn.exe | "Added by the BEAGLE.FF WORM!"
|
| X | DrWatson | drwatson_.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWatson | drwatson_32.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWeb Antivirus | DRWEBAV.EXE | Added by an unidentified WORM or TROJAN!
|
| Y | Drwebscheduler | Drwebscd.exe | "DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications |
| X | DR_S | DR_S.exe | "IstBar adware"
|
| N | DSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| X | DsmSer | dsm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | svosm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | sysup.exe | "Added by the SERFLOG.B WORM!"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| X | DSService | dmrss.exe | "Added by the AGOBOT-XX WORM!"
|
| X | DSystemDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT 11Mbps WLAN USB Station | DTUSBMonitor.exe | 11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| N | DU Meter | DUMETER.EXE | "Hagel Technologies internet bandwidth monitor"
|
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Dulux WeatherShield WeatherDesk | weather.exe | "Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
|
| X | Dumeter Services | dumeter.exe | "Added by the SDBOT-AEQ WORM!"
|
| X | dumprep | spoolc.exe | "Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
|
| X | dumprep | dump-k.exe | "Added by the BUZUS-U WORM!"
|
| X | dumprep | dump.exe | "Added by the CODOX-A WORM!"
|
| N | dumprep 0 -k | dumprep 0 -k | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
| N | dumprep 0 -u | dumprep 0 -u | "Used in connection with memory dumps - you can disable these by - right clicking on My Computer |
| X | DUN_SERVICES3 | dun3.exe | "Added by the SOKIRON TROJAN!"
|
| X | Duwee wong Cerbon | Cirebons.exe | "Added by the BHARAT.A WORM!"
|
| U | DVD Device Lock for Win95/98/Me/2k/XP | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| X | DVD Upgrade | dvdupgd.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| N | dvd43 | DVD43_Tray.exe | "DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
|
| N | DVDLauncher | DVDLauncher.exe | "Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
|
| N | DVDSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| N | DVDTray | DVDTray.exe | HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
|
| N | DVDUpgrade | DVDUpgrd.exe | "Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
|
| Y | dvprpt | Dvprpt.exe | "Command Antivirus related"
|
| X | dvraudio | dvraudio.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| X | dvsfss | fbsfsdrs.exe | "Added by the SDBOT-QA WORM!"
|
| N | DW4 | Weather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW4 | DesktopWeather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW6 | DesktopWeather.exe | "Desktop Weather 6 by The Weather Channel - provides current temperature |
| U | DWHeartbeatMonitor | DWHeartbeatMonitor.exe | DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
|
| N | DwlClient | support.exe | Download manager for Dell support alerts
|
| X | dwqblwppx.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwpvl.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwrsq.exe | [random].exe | "Okcashbackmall adware"
|
| U | DWQueuedReporting | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| N | dwStart | FireWall.exe | "The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
|
| U | dwtrig20 | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| X | DW_Start | rwwnw64d.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| X | Dx | sys*.exe [* = random number] | "Added by the DEXTER.A WORM!"
|
| N | DXDllRegExe | dxdllreg.exe | "Created when you select ""Yes"" to check the ""WHQL Digital signatures"" in the DirectX9 files at the first time you open it"
|
| X | DxLoad | DX3DRndr.exe | "Added by the GIBE.B WORM!"
|
| X | dxmsrv | dxmsrv.exe | Added by an unidentified WORM or TROJAN!
|
| X | DyFuCA Active Alert | actalert.exe | "Adult content dialler - see here"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| X | Dynamic Dns Binary | CMD16.EXE | "Added by the RBOT-XM WORM!"
|
| X | Dynamic Dns Binary | winxp34.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Dns Binary | WinHelpcfn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Link Library loader | Loader32.exe | "Added by the KOL TROJAN!"
|
| U | DynDNS Updater | DynDNS.exe | "Dynamic DNS IP address updater tool |
| N | DynDNS-Updater Traytool | ddutray.exe | "DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
|
| X | DynHttp Dns Binary | dynizari.exe | "Added by a variant of the RBOT WORM!"
|
| X | E-Card | ecard.exe | "Added by the YODI WORM!"
|
| U | E-color | IconMgr.Exe | Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| X | E-nrgyPlus | E-nrgyPlus.exe | "Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
|
| U | e-Surveiller Station | estation.exe | "ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
|
| U | E06DXLRD_7604703 | EDICT.EXE | "Related to Microsoft Encarta dictionary functions"
|
| N | EA Core | Core.exe | "Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches |
| U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
|
| X | Eac_Cnry | canary.exe | "Added by the CANARY TROJAN!"
|
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| Y | EAFRCliStart | EAFRCliStart.exe | "Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
|
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
|
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| N | EarthLink ToolBar 5.0 | etoolbar.exe | "EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar |
| N | Easy CD Creator | RoxAssist.exe | "Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize |
| N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| U | EasyKeyboardLogger | EasyKeyboardLogger.exe | "EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | EasyLinkAdvisor | LinksysAgent.exe | "Linksys EasyLink Advisor - ""the free application that provides and easy way to setup |
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader
|
| X | easyServ | Server.exe | "Added by the EASYSERV TROJAN!"
|
| X | EasySpywareCleaner | EasySpywareCleaner.exe | "EasySpywareCleaner rogue spyware remover - not recommended |
| U | EasySync Pro | XCPCMenu.exe | """IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | "Ebates adware"
|
| X | eBay Toolbar | EBAYTBAR.EXE | "eBay Toolbar - reportes as spyware as it "phones home""
|
| U | eBayToolbar | eBayTBDaemon.exe | "eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
|
| U | eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| N | eBot | DownloadWizard.exe | "eBot from Digital River - ""helps ensure your computer always has the latest technology |
| U | ECenter | gtb.exe | Dell E-Center/Google Toolbar related
|
| N | ECenter | EULALauncher.exe | End User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
|
| X | ecko | claro.exe | "Added by the DLOADR-AQJ TROJAN!"
|
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| N | edexter | edexter.exe | "eDexter supplements internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser"
|
| N | EDLoader | DTLoader.exe | Effective Desktop from MiniStars Software - desktop management software no longer being supported
|
| U | EDRestore | ?? | "Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
|
| X | educational writer | [random filename] | "Added by the RBOT-LZ WORM!"
|
| U | Edwizard | Edwizard.exe | "SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection |
| X | Edzy AntiVirus | dppsfa.exe | "Added by a variant of the RBOT WORM!"
|
| X | Eech | hoor.exe | "PurityScan adware"
|
| N | EEventManager | EEventManager.exe | "Part of the Epson Creativity Suite supplied with their multi-function printer/scanners |
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | eFax 4.1 | J2GTray.exe | "System Tray access to version 4.1 of eFax Messenger from j2 Global Communications |
| U | eFax 4.2 | J2GTray.exe | "System Tray access to version 4.2 of eFax Messenger from j2 Global Communications |
| U | eFax 4.3 | J2GTray.exe | "System Tray access to version 4.3 of eFax Messenger from j2 Global Communications |
| U | eFax 4.4 | J2GTray.exe | "System Tray access to version 4.4 of eFax Messenger from j2 Global Communications |
| N | eFax Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | eFax Tray Menu | J2GTray.exe | "System Tray access to eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.3 | J2GTray.exe | "System Tray access to version 3.3 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.5 | J2GTray.exe | "System Tray access to version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 4.0 | J2GTray.exe | "System Tray access to version 4.0 of eFax Messenger from j2 Global Communications |
| N | eFax.com Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | EFI Hot Folders | hffw.exe | """EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select |
| U | EFI Job Monitor | "[path] efjm.dll | run" |
| U | ehTray | ehtray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | ehTray.exe | ehTray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eKerberos | eKerberos.exe | "eKerberos rogue security software - not recommended"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| U | eLert | eLert.exe | "eLert Emergency Notification System by Kennected Software - ""is an internet based public notification system designed to get emergency and non-emergency information out to the public quickly |
| X | EliteProtector | EliteProtector.exe | "EliteProtector rogue spyware remover - not recommended |
| ? | ElkCtrl | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| X | ELNKProxy | smproxy.exe | "Surfmonkey adware"
|
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| U | EMBASSY Trust Suite Secure Update | AutoUpdate.exe | "Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| X | eMessenger | emsn.exe | "Added by the RBOT.AHO BACKDOOR!"
|
| U | EMMeter | EMMeter.exe | """Express Meter lets you track and manage software usage so you can avoid purchasing and supporting applications that aren't being used |
| X | emoc0re | emo.exe | "Added by the AGOBOT-AGE WORM!"
|
| ? | Empowering Technology Launcher | eAPLauncher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| ? | EmpoweringTechnology | Framework.Launcher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| X | emre1 | emre1.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| Y | Emsisoft Anti-Malware | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
| N | eMuleAutoStart | emule.exe | "eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project |
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| X | enBrowser | [name of file] | "WINBO adware"
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| N | ENCMONITOR | monitor.exe | The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
|
| N | Encoder Agent | WMENCAGT.EXE | "MS Windows Media Encoder |
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| ? | ENCSurf | surfboard.exe | "??"
|
| N | Energizer FileSaver | Energizer FileSaver.exe | "Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
|
| X | EnergyPlugIn | EnergyPlugin.exe | "EnergyPlugin adware variant"
|
| ? | ENSApServer2_0 | APSERVER.EXE | "Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
|
| U | EnsoniqMixer | starter.exe | "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
|
| U | Enterprise Harmony | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| U | Enterprise Harmony '99 | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | Enterra Icon Keeper | IcnKeepr.exe | "Icon Keeper - ""tool to save and restore icon positions on the desktop"""
|
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| U | EPGServiceTool | EPGClient.exe | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | EPGServiceTool | EPGCLI~1.EXE | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | ePowerManagement | ePM.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| U | ePower_DMC | ePower_DMC.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| N | ePrint 3.0 Service | EPRINT3.EXE | "LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF |
| N | ePrint 4.0 Service | EPRINT4.EXE | "A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF |
| U | ePrompter | ePrompter.exe | "ePrompter - E-mail notification software"
|
| N | EPS | e_srcv02.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| N | EPS | e_srcv03.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| X | Epsilon Squared | vmmreg32.exe | "Added by the AGENT.MVC TROJAN!"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| U | EPSON Status Monitor 3 | E_[various].EXE | "Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C40 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status |
| U | EPSON Stylus C41 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status |
| U | EPSON Stylus C42 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S08IC1.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C44 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | EPSON Stylus C45 Series | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
| U | EPSON Stylus C46 Series | E_S4I0T1.EXE | "Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status |
| U | EPSON Stylus C48 Series | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
| U | EPSON Stylus C60 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
| U | EPSON Stylus C61 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status |
| U | Epson Stylus C62 Series | E-S0BIC1.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C62 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C63 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C66 Series | E_S4I0S2.EXE | "Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | Epson Stylus C82 Series | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C82 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus D68 Series | E_FATIAAE.EXE | "Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status |
| U | EPSON Stylus D78 Series | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
| U | EPSON Stylus D88 Series | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4000 Series | E_FATIBEE.EXE | "Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4800 Series | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX5000 Series | E_FATIBVE.EXE | "Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX6000 Series | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7000F Series | E_FATIBKE.EXE | "Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 1400 Series | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R1800 | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
| U | EPSON Stylus Photo R200 Series | E_S4I0H2.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_S6I2I1.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R240 Series | E_FATIAHE.EXE | "Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R260 Series | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I0F2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R320 Series | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R340 Series | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R380 Series | E_FATIBOA.EXE | "Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R800 | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX500 | E_S4I2K1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX530 Series | E_FATIAGP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX600 | E_S4I2M1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX640 Series | E_FATIAME.EXE | "Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX700 Series | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
| U | EPSON Stylus Pro 4000 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status |
| U | EPSON Stylus Pro 7600 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
| U | EPSON Stylus SX200 Series | E_FATIEFE.EXE | "Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status |
| U | EPSON SX100 Series | E_FATIEDE.EXE | "Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status |
| U | EPSON TX100 Series | E_FATIEDP.EXE | "Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this
|
| X | Eptr | nopdb.exe | Added by an unidentified WORM or TROJAN!
|
| X | EQArticle | EQArticle.exe | "EQArticle adware"
|
| X | eraseplg | eraseplg.exe | "Added by the GENOME.AQUV TROJAN!"
|
| U | Eraser | eraser.exe | "Eraser - ""an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns"". This entry starts the Scheduler with Windows and provides a System Tray icon for on-demand access. Located in %ProgramFiles%\Eraser"
|
| U | eraser | eraser.exe | "Part of Evidence Exterminator |
| U | eraser.exe | eraser.exe | "Part of Evidence Exterminator |
| Y | eRecoveryService | check.exe | "Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | Monitor.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| N | Ereg | reg32.exe | "EReg is a software registration tool incorporated on products such as those by Broderbund |
| X | erfgddfk | wind2ll2.exe | "Added by the BEAGLE.CQ WORM!"
|
| X | erghgjhgdr | windlhhl.exe | "Added by the BEAGLE.BG WORM!"
|
| X | erghgjhjgdr | windlhhl.exe | "Added by the BEAGLE.BG or BEAGLE.BH or BEAGLE.BI or BEAGLE.BJ WORMS!"
|
| ? | erm | erm.exe | "??"
|
| X | Eroca | Eroca.exe | "Insider.i adware"
|
| X | eros.exe | eros.exe | Adult content dailler
|
| X | ErrClean | SysRep.exe | "ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
| X | ErreurChasseur | SysRep.exe | "ErreurChasseur |
| N | Error Nuker | ErrorNuker.exe | "ErrorNuker registry cleaner - only required if you want the application to run a scan at startup. The program can be launched manually if required"
|
| X | Error Safe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | Error Safe Free | uers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorFix | ErrorFix.exe | "ErorrFix rogue system error and cleaning utility - not recommended |
| X | ErrorGuard | ErrorGuard.exe | "ErrorGuard rogue spyware remover - not recommended |
| X | errorhandler | errorhandler.exe | "ErrorHandler adware"
|
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| X | ErrorRepairTool | ErrorRepairTool.exe | "ErrorRepairTool rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafeFree | UERS.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorWiz | ErrorWiz.exe | "ErrorWiz rogue system error and cleaning utility - not recommended |
| X | ERS | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERScw | ERScw.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_Check | uwasers.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| X | erthegdr | windll2.exe | "Added by the BEAGLE.CG WORM!"
|
| X | erthgdr | windll.exe | "Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
|
| X | erthgdr | svc.exe | "Added by the BEAGLE.BN or BEAGLE.BP WORM!"
|
| X | erthgdr2 | svc23.exe | "Added by the BAGLE.CG WORM!"
|
| ? | ERTS0749 | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| X | ertyuop | rttrwq.exe | "Added by the AUTORUN-APA WORM!"
|
| U | ERUNT AutoBackup | AUTOBACK.EXE | "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots |
| X | erwghjjrjt | ucbcg.exe | "Added by the SMALL.CUL TROJAN!"
|
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Scheduler | avkserv.exe | "MicroWorld eScan antivirus scheduler"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| X | EScorcher | escorcher.exe | "Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
|
| X | Esph | ortu.exe | "PurityScan adware"
|
| X | ETB Tester | etbtest.exe | "Added by the RBOT-ABR WORM!"
|
| X | etbrun | elit***32.exe [* = random char] | "EliteBar adware"
|
| U | eTCertManger | eTCrtMng.exe | "eToken Certificate Manager from Aladdin Knowledge Systems |
| U | ETDWare | ETDCtrl.exe | Elantech smart-pad touchpad driver for the Asus Eee PC range
|
| X | eth0 driver | exec.exe | "Added by the SPYBOT-Z WORM!"
|
| N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
|
| X | ethernet | airftp.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msnger.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msftp.exe | "Added by the SDBOT.BXJ WORM!"
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Driver | cmsrrs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Drivers | smrrs.exe | "Added by the RBOT-AAK WORM!"
|
| X | Ethernet Drivers | ethernet.exe | "Added by the GAOBOT.CEZ WORM!"
|
| X | Ethernet Linking | ethernet.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Etraffic | JavaRun.exe | "TopMoxie adware"
|
| Y | eTrust EZ Firewall | efpeadm.exe | "eTrust EZ Firewall"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| X | eTrust Realtime Monitor | realmon.exe | "Added by the LAZAR.B TROJAN!"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| U | Eudora | Eudora.exe | "Eudora from Qualcomm allows you to receive and send Internet e-mails"
|
| X | EUP Service | eupsvc.exe | "Added by the DELBOT-Q WORM!"
|
| U | EuroGlot | EuroGlot.exe | "Euroglot - ""multilanguage translating system |
| N | Event Planner Reminders | PLNRNote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Reminder | pmremind.exe | "Event reminder for calendar dates |
| U | EVENTLISTENER | EvLstnr.exe | Used with a Nikon digital camera to recognize when the camera is plugged in
|
| N | eventmgr | eventmgr.exe | Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
|
| X | eventwvr | eventwvr.exe | "Added by the COSIAM_G TROJAN!"
|
| ? | EverioService | EverioService.exe | "Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
|
| U | EVGAPrecision | EVGAPrecision.exe | "EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible |
| U | Evidence Cleaner | ecleaner.exe | "Evidence Cleaner cleans up tracks left by your PC and Internet activities"
|
| N | Evidence Eliminator | ee.exe | "Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| U | EvtMgr6 | Setpoint.exe | "Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| U | EW Message Server | msg32.exe | Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
|
| N | eWare Startup | iWareStart.exe | "eWare iWare task bar. Not required"
|
| Y | ewido anti-spyware | ewido.exe | "System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
| X | ewrgetuj | geurge.exe | "Added by the AUTOINF-AK WORM!"
|
| X | ewupdater | ewupdater.exe | "EasyWebSearch adware updater"
|
| X | example | [random filename].exe | "Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
|
| N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| X | ExecUser | ExecUser.exe | "Added by a variant of the RBOT WORM!"
|
| ? | Execute | delfolders.exe | "??"
|
| X | ExeName32 | Warm.scr | "Added by the SCOLD WORM!"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| U | Exif Launcher | Exiflaquickdcr.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| U | Exif Launcher | QuickDCF.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| U | ExitKiller | Ekiller.exe | "Exit Killer - automatically closes pop-up windows in your browser"
|
| ? | exmon | hpimoniter.exe | "Some kind of hp digital camera maybe or a photo smart connection probe?"
|
| X | exp1orer.exe | exp1orer.exe | "Added by the DLOAD-FG TROJAN! Notice the digit ""1"" used in both the startup entry and filename |
| X | Expatch | [random filename] | "Added by the PWSLMIR-G TROJAN!"
|
| X | expcrt | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | ExpertAntivirus | ExpertAntivirus.exe | "ExpertAntivirus rogue security software - not recommended |
| X | EXPL0RE.EXE | EXPL0RE.EXE | "Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
|
| X | Expl0rer soft | expl0rer.pif | "Added by the RBOT-AQR WORM!"
|
| X | expler | Updadv.exe | "Added by the QQPASS-N TROJAN!"
|
| X | explord.exe | explord.exe | "Added by the DLOADR-AYW TROJAN!"
|
| X | explore | explore.exe | "Added by any number of VIRUSES |
| X | Explore | Explorer.exe | "Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Explore | explore.exe | Adult content dialler
|
| X | Explore | PLORE.EXE | "Added by the FORBOT-P WORM!"
|
| X | explore manager | explore.exe | "Added by the DONBOMB.A TROJAN!"
|
| X | explore.exe | Explore.exe | "Added by the GRAYBIRD.G TROJAN!"
|
| X | exploreff.exe | exploreff.exe | "Added by the FINFANSE TROJAN!"
|
| X | explorep.exe | explorep.exe | "Added by the LINEAG-I TROJAN!"
|
| U | explorer | explorer.exe | "Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | shellexpl.exe | "Added by the SHELDOR TROJAN!"
|
| X | explorer | expl32.exe | "Added by the RATSOU TROJAN!"
|
| X | Explorer | [path to worm] | "Added by the AUTEX WORM!"
|
| X | Explorer | shellexp.exe | "Added by the AGENT-ZY TROJAN!"
|
| X | EXPLORER | EXPL0RER.EXE | "Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
|
| X | EXPLORER | sys.exe | "Added by the SILLYFDC-A TROJAN!"
|
| X | Explorer | config_.com | "Added by the FLOPPY-D WORM!"
|
| X | Explorer | drv.exe | "Added by the SMALL-FD TROJAN!"
|
| X | explorer | [path to trojan] | "Added by the AGENT-EU TROJAN!"
|
| X | explorer | explorer.exe | "Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
|
| X | EXPLORER | EXPLORER.exe | "Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
|
| X | explorer | explorer.exe | "Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
|
| X | explorer | Yinstall.exe | "PurityScan/Clickspring adware"
|
| X | Explorer | Windows Explorer.exe | "Added by the SILLYFDC-I WORM!"
|
| X | Explorer | explorar.vbs | "Added by the DESKTO-A WORM!"
|
| X | Explorer | TXP1atform.exe | "Added by the FUJACKS.CA VIRUS!"
|
| X | explorer | system.exe | "Added by the AGENT-FI TROJAN!"
|
| X | Explorer | msrstart.exe | "Added by the SOPICLICK TROJAN!"
|
| X | explorer | main.vbe | "Added by the SHUSH-A WORM!"
|
| X | Explorer 2238 | [path to trojan] | "Added by the AGENT-CPI TROJAN!"
|
| X | Explorer Loader | explr32.exe | "Added by the AGOBOT.N WORM!"
|
| X | Explorer Loader | explorerl.exe | "Added by the SDBOT-ADI WORM!"
|
| X | Explorer lptt01 | explorer.exe | "RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
|
| X | EXPLORER MICROSOFT SYSTEM | explore.exe | "Added by a variant of the RBOT WORM!"
|
| X | Explorer ml097e | explorer.exe | "RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
|
| X | Explorer soft | explorer.pif | "Added by the RBOT-APK WORM!"
|
| X | Explorer soft | explorer.com | "Added by the RBOT-ARM WORM!"
|
| X | Explorer Updater | IEXPLORE.exe | "Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | explorer.exe | explorer.exe | "Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | explorer.exe | explorer.exe | "Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
|
| X | Explorer.exe | csrss.exe | "Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
|
| X | Explorer32 | Expl32.exe | "Added by the HACKTACK.B TROJAN!"
|
| X | Explorer32 | explorer6s4.exe | Added by the Downloader.Win32.Small.biq TROJAN!
|
| X | Explorer32 | efsdfgxg.exe | "Added by the CLICKER-Y TROJAN!"
|
| X | Explorer5 | config_.com | "Added by the VB.CBG WORM!"
|
| X | Explorer6.1.EXE | Explorer.exe | Added by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
|
| X | explorerf.exe | explorerf.exe | "Added by the AGENT-GDZ TROJAN!"
|
| X | ExplorerRun | conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
|
| X | ExplorerTask | explorer.exe | "Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| X | exporet | winset.exe | "Added by the QQPASS-I TROJAN!"
|
| U | Express ClickYes | ClickYes.exe | """Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt |
| N | Extender Resource Monitor | RMSysTry.exe | "Related to Windows Media Center from Microsoft"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| X | Extra Antivirus | ExtraAV.exe | "Extra Antivirus rogue security software - not recommended |
| U | ExtraDNS | ExtraDNS.exe | "ExtraDNS - DNS configuration tool"
|
| N | ExtraFilmHemmaAgent | Agent.exe | "ExtraFilm Photo Assistant"
|
| ? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software
|
| ? | ExxtremeHelperDemon | exxdemon.exe | "Creative Exxtreme graphics card related?"
|
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| Y | EZ Firewall | ca.exe | "eTrust EZ Armor Internet Security"
|
| U | EZ-DUB Finder | EZ-DUB.exe | "Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
|
| N | EZEJTRAY | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | ezHelper | ezHelper.exe | "Part of the ezPeer+ ezHelper music sharing program."
|
| ? | EZNORUN | EZNORUN.EXE | "Easy Internet related?"
|
| N | EzPrint | ezprint.exe | "Lexmark Fast Pics - helps users of their printers to enhance |
| Y | ezShieldProtector for Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
|
| U | E_S[numbers] | [path] E_[various].EXE [path] E_S[numbers].tmp | "Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure 2005 | svchost.exe | "Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| Y | F-Secure 2006 | fspex.exe | "F-Secure Anti-Virus automatic updater"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Manager | FSM32.EXE | "F-Secure antivirus - carry out scheduled virus scans automatically"
|
| Y | F-Secure Startup Wizard | FSSW.EXE | "F-Secure antivirus"
|
| Y | F-Secure TNB | TNBUtil.exe | "F-Secure antivirus"
|
| U | f1Tray.exe | F1TRAY.EXE | "System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
|
| X | f94mggfhfghodftdf | [path to trojan] | "Added by the SMALL.JHZ TROJAN!"
|
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | "Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink |
| U | FamilyKeyLogger | cisvc.exe | "Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| X | farkrish | farkrish.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | farmmext | farmmext.exe | "VX2.Transponder parasite updater/installer related"
|
| X | Fast Antivirus 2009 | FastAV.exe | "Fast Antivirus rogue security software - not recommended |
| N | FAST Defrag | FAST2.EXE | "FastDefrag defragmenting software"
|
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | Ntut.exe | "Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
|
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | FastStart | ntnut32.exe | "Added by the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| N | FastTrack Accelerator | SPEED UP.EXE | "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop |
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| N | FastUser | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| N | FastUsr | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | Fat32 Microsoft | fat32.exe | "Added by the RBOT-EL WORM!"
|
| U | Fatpipe Dialer | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | fatrecov | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
|
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| U | FBDirect | FBDirect.exe | "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan |
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSearch | SearchGuardPlus.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | fc | runfc.exe | "Added by the CAMPURF WORM!"
|
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | Fdr Command Module | sp2.exe | "Added by the SDBOT.WP WORM!"
|
| X | FDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | feedreader.exe | feedreader.exe | """Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"""
|
| X | feelalright | mirc.exe | "Added by the IRCFLOOD-M WORM!"
|
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
|
| U | Fellowes Proxy | R3proxy.exe | Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| U | FerrariWallPaper | FerrariWP.exe | Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| X | ff | [path to worm] | "Added by the RBOT-XL WORM!"
|
| X | ffis | ffisearch.exe | "iSearch adware"
|
| Y | ffprsrv | ffprsrv.exe | "File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled |
| Y | ffprsrv.exe | ffprsrv.exe | "File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled |
| Y | ffpsrv | ffpsrv.exe | "File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders |
| Y | ffpsrv.exe | ffpsrv.exe | "File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders |
| U | FG1_00 | frntgate.exe | "FrontGate MX - e-mail spam blocker"
|
| ? | fgl23DoubleScreenHooks | f23happ.exe | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | FHStart | shdocsvc.exe | "Added by the WINHOUND TROJAN!"
|
| X | Fhzepgyi | HELLRAIDER.EXE | "Added by the MINDCTRL.A BACKDOOR!"
|
| U | FieldForms Sync | SyncService.exe | "Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run |
| X | FiendlyType | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| ? | file indexing service | msfindfile.exe | "New version of MS FindFast and still a resource hog?"
|
| X | file laoder configuration | rnd32.exe | "Added by the RBOT.BQJ WORM!"
|
| X | File Mapping Services | hp-1003.exe | "Added by the RBOT.FAN WORM!"
|
| X | File Protection Monitor | filemon.exe | "Added by a variant of the RBOT WORM!"
|
| X | File System | taskmqrs.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | File System | taskmqr.exe | "Added by the RBOT.BWQ WORM!"
|
| X | File System Service | wmiprvsc.exe | "Added by the AGOBOT-HZ TROJAN!"
|
| X | File-Sharing Wizard | shwizard.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | File1 | Dia Claro.htm | "Added by the DLOADER-OR TROJAN!"
|
| X | FileFreedom_Plugin | wtm.exe | "FileFreedom peer-to-peer sharing program"
|
| N | filehippo.com | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | FileHippo.com Update Checker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | filename process | kerneldll.exe | "Added by the AGOBOT-PO WORM!"
|
| X | filename process | explore.exe | "Added by the AGOBOT-QN WORM!"
|
| X | filename process | Rundil16.exe | "Added by the GAOBOT.ZX WORM!"
|
| X | Files Driver | sdphost.exe | "Added by the SDBOT-DKZ WORM!"
|
| X | Files Driver | sfdhost.exe | "Added by the AGOBOT-AJC BACKDOOR!"
|
| X | FileSoft | Wscript.exe UpdataFiles.vbs | "Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
|
| U | FilmLoop | FilmLoopService.exe | "Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
|
| U | FilterGate | filtergate.exe | "Filtergate internet filtering software - filters sounds |
| U | Filterguard | Filtrgrd.exe | "An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian |
| X | FilterProgram | GDC.exe | "FilterProgram rogue privacy tool - not recommended |
| Y | Find Virus Launch Program | fvlaunch.exe | "Part of Dr. Solomon's Antivirus"
|
| X | FindHack | [path to worm] | "Added by the KELVIR-BA WORM!"
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | "ABBYY FineReader OCR software - version 7"
|
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
|
| X | Fire Wall services | [random filename] | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Wall services | wnlmzsfhobi.exe | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Well service | [random].exe | "Added by the RBOT-FJU WORM!"
|
| ? | FireBox Control Panel | FireBox.exe | "Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
|
| X | FireExplore Update | FireExplore.exe | "Added by a variant of the RBOT WORM!"
|
| X | FireFox | firefox.exe | "Added by the RBOT-ATP WORM! Note - this is not the popular FireFox web browser and is located in %System%"
|
| X | Firefox Plugin Manager | firefoxpgm.exe | Added by the MSNPHOTO.E WORM!
|
| U | Firefox Preloader | FirefoxPreloader.exe | "Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
|
| X | FireFox Service Drivers | ssmss.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireFox Startup Drivers | wuaclt.exe | "Added by the RBOT.BYX WORM!"
|
| X | firefox.exe | firefox.exe | "Added by the BANKER-EBO TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
|
| Y | FirePod | FIREPOD.EXE | "Driver for the PreSonus FP10 (formerly FirePod) Firewire recording system"
|
| X | FiresWallservices | [random].exe | "Added by the RBOT-FJT WORM!"
|
| X | Firevall Administrating | rndll.exe | "Added by the PUSHBOT-B WORM!"
|
| X | firewal | firewal.exe | "Added by the BANCBAN-QY TROJAN!"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.D WORM!"
|
| X | Firewall | SP2 UPDATE.exe | "Added by the ELITPER.E WORM!"
|
| X | Firewall | Firewall.bat | "Added by the YPSAN.G WORM!"
|
| X | firewall | fw_304.exe | "Added by the BDOOR-JQ BACKDOOR!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | firewall | spoolsv.exe | "Added by the DIZAN.F VIRUS!"
|
| X | firewall | firewall.exe | "Added by the SURO-A TROJAN!"
|
| X | firewall 2008 | logoneui.exe | "Added by the SILLYFDC WORM!"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Firewall auto setup | [path to trojan] | "Added by the AGENT-GLY TROJAN!"
|
| X | Firewall config | ReadMe.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Policy | MidiDef32.exe | "Added by the PIEBOT-A TROJAN!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | Firewall Update System1 | WinedowsUpdater1.exe | "Added by the RBOT-ARU WORM!"
|
| X | Firewall Updater | msnupdateit.exe | "Added by the RBOT-AAQ WORM!"
|
| X | Firewall.exe | Firewall.exe | "Added by the AGENT.AGL BACKDOOR! Located in %System%"
|
| Y | FireWall.exe | FireWall.exe | "Ashampoo® Firewall PRO and Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG. Located in an Ashampoo related sub-directory of %ProgramFiles%"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| Y | FirewallGUI | FirewallGUI.exe | "System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
|
| U | FirewallStartup | Firewallstartup.exe | "Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean |
| X | FirewallSvr | FirewallSvr.exe | "Added by the NETSKY.X or NETSKY.Y WORMS!"
|
| X | firewall_anti | firewall_anti.exe | "Added by the NETDENY-B TROJAN!"
|
| X | FireWire Driver | samx.exe | "Added by the SDBOT.AE WORM!"
|
| X | FireWire Service | nvscv32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireWire Services | nvcsv32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| ? | First Principle Group | fpg.exe | "Related to the E-Players Card from First Principle Group"
|
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop
|
| X | FKS v2.0 | msngr.exe | Added by an unidentified WORM or TROJAN!
|
| X | Flash Driver | [path to trojan] | "Added by the AGENT.CWVT TROJAN!"
|
| X | Flash Media | [path to trojan] | "Added by the IRCBOT.AUR TROJAN!"
|
| X | Flash Media | services.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Flash Media | zrpk��'�'%''msn'�%'fix''.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Player2 | [path to worm] | "Added by the IRCBOT.PD WORM!"
|
| X | Flashget Download Manager | Flashget.exe | "Added by the RBOT-AGZ WORM!"
|
| X | FlashGuard | FlashGuard.exe | "Added by the AUTOIT.AL WORM!"
|
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| X | Flash_Player_Install | ying.exe | "Constructor VC2000 malware"
|
| U | FlingRun | fling.exe | "Fling - free FTP software from NCH Software"
|
| U | FLMBROWSERMOUSE | mouse32A.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | FLooDNeT | FLooDeR.exe | "Added by the ENDOOL TROJAN!"
|
| X | Floppy Master | [path to trojan] | "Added by the ZONIT-F TROJAN!"
|
| Y | FltProcess | msinet.exe | "Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
|
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
|
| U | FMStart | Fmstart.exe | "GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks |
| X | Folder Service | wssdtu.exe | "Added by the MANIFEST TROJAN!"
|
| U | Folder View | folderview.exe | "Folder View enhances the Windows file Explorer by making all folders you need available in a single click"
|
| U | FolderClone v*.*.* | folderclone.exe | "Folderclone backup and synchronization software"
|
| X | FolderRaper | [path to worm] | "Added by the VB.GOZ WORM!"
|
| U | FolderShare | FolderShare.exe | """FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
|
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
|
| X | Font Viewer | fontviewer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | FontsLoader | ldfnt32.hta | Unidentified malware
|
| U | FooBar 1.0 | FooBar.exe | "FooBar - ""combines fifteen high-quality productivity tools in a single toolbar that floats on your desktop or runs in the Windows task bar"""
|
| X | foobin lptt01 | adaware.exe | "RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | foobin ml097e | adaware.exe | "RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | FoolProof | fpwinldr.exe | "FoolProof Security PC security software from SmartStuff"
|
| Y | FoolProofSweep | ?? | "Part of FoolProof Security PC security software from SmartStuff"
|
| N | Forbes | ForbesAlerts.exe | Forbes Business News Alerts - displays business news headlines in a little window on the screen
|
| X | ForceShow | "rundll32.exe QaBar.dll | ForceShowBar" |
| N | Forget Me Not | AGRemind.exe | "Calendar reminder part of Broderbund's American Greetings® CreataCard®"
|
| U | forteManager | dthtml.exe | "forteManager from LG. Rebranded version of Display Tune from Portrait Displays |
| Y | FortiClient | FortiClient.exe | "Fortinet security systems are the new generation of real time network protection systems"
|
| U | Fortis Secure Layer Config | cseinst.exe | Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
|
| U | FourthDay | FourthDay.exe | "The Fourth Day - ""astronomical clock and almanac for your system tray"""
|
| X | foxrxjh | foxrxjh.exe | "Added by the GWGHOST-T TROJAN!"
|
| X | foxwudy9912 | service.exe | "Added by the BANCOS-BT TROJAN!"
|
| Y | FP Loader | loadfp.exe | "FoolProof Security - PC security software from SmartStuff"
|
| N | Fpx | mnmsrvc.exe | Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
|
| X | fqor | stub_113_4_0_4_0.exe | "TargetSaver adware"
|
| X | FrameWork 2.5 | FrameWork.exe | "Added by the RBOT-FMW WORM! Note - can terminate AV related processes"
|
| X | Framework module library | infocard.exe | "Added by the BUZUS.AYX TROJAN!"
|
| X | Framework Windows | frmwrk32.exe | "Added by the FAKEAV-KS TROJAN!"
|
| X | France | svchost.exe | "Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| N | Fraps | FRAPS.EXE | "Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting |
| N | Free Download Manager | fdm.exe | """Free Download Manager"" - see here"
|
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| N | Free DVD Direct | FreeDVDDirect.exe | "Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
|
| U | Free Key Logger | freekeylogger.exe | "Free Key Logger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | Free Ram Optimizer | fro.exe | "Free Ram Optimizer monitors your memory |
| X | free-save | [path to risk] | "Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
|
| X | FreeAttention | eqsefeqe.exe | Added by an unidentified WORM or TROJAN!
|
| N | Freebie Notes | FreebieNotes.exe | "Freebie Notes by Power Soft - create electronic notes (stickers)"
|
| N | FreeCall | FreeCall.exe | "FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| Y | Freedom | Freedom.exe | "Freedom Internet Security & Privacy - anti-virus |
| U | FreeMem Pro | FMEMPRO.EXE | "FreeMem Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| U | FreeMemVn2 | FreeMem.exe | "FreeMem - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | FreeMP3download | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | FreePDF Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| N | FreePDF_Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| U | FreeRAM XP | FreeRAM XP Pro *.exe | "FreeRAM XP Pro - memory optimizer where * represents the version. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| U | FreeRAM XP | FreeRAM XP Pro.exe | "FreeRAM XP Pro - memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | freestyle | lockx.exe | "Added by the RBOT-ATH WORM!"
|
| U | freesurfer | fs20.exe | "EMS Free Surfer mk II - pop-up stopper"
|
| X | freexstyle | lockbar.exe | "Added by the LOXBOT.D WORM!"
|
| X | freexstyle | lockbr.exe | "Added by the LOXBOT.C WORM!"
|
| X | freinst | pgs.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| U | Fresh Desktop | freshdesktop.exe | "Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
|
| N | freshclam | freshclam.exe | "Auto update agent of the open source Clamwin virus scanner"
|
| ? | frguk | shdrkmck.exe | "??"
|
| ? | FridaysInHellInstaller | FridaysInHellInstaller.exe | "??"
|
| X | FriendlyType | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | FriendlyTypeName | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| X | FriendlyTypeName | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
|
| U | FRISK FP-Scheduler | F-Sched.exe | "Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| U | FRITZ!webProtect | FwebProt.exe | Firewall included in FRITZ! ISP DSL software
|
| N | Fromine WinPopup | winpopup.exe | Instant Messenger program
|
| X | froody | timoty.exe | Added by an unidentified malware
|
| X | Frsk | frsk.exe | Unidentified adware downloader trojan
|
| X | frun | derc32xz.exe | Added by an unidentified TROJAN!
|
| Y | FRW_EXE | FRW.EXE | "ConSeal Signal9 firewall - now McAfee Personal firewall"
|
| Y | frxmxins | frxmxins.exe | ATI 3D Studio MAX/VIZ driver
|
| ? | FSDPSRV | FSDPSRV.exe | "??"
|
| X | fsdsft | [path to backdoor] | "Added by the RANKY.S BACKDOOR!"
|
| Y | fspr | FolderShield.exe | "Folder Shield - hide personal files and folders"
|
| N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
|
| U | fsserv | fserv.exe | "Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
|
| X | fstsvc | "rundll32.exe fstsvc.dll | start" |
| U | FSWebServer | fsws.exe | "Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
|
| X | FTP FOR WINDOWS | ftpwin32.exe | "Added by a variant of the RBOT WORM!"
|
| X | FTPGraber | FTPGraber.exe | "Added by the DLOADER-DT TROJAN!"
|
| N | FTPManager | FTPDM.exe | """Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another |
| ? | FtpServer.exe | FtpServer.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| U | ftutil2 | "rundll32.exe ftutil2.dll | SetWriteCacheMode" |
| X | FU | FUvirus.exe | "Added by the VB-EJC TROJAN!"
|
| X | Fucker | fucker.vbs | "Added by the CATCHER-A WORM!"
|
| U | Fujitsu Hotkey Utility | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| X | fukerservice | fukerz.exe | "Added by a variant of the RBOT WORM!"
|
| X | FUKLBAR | bar.exe | "PurityScan adware"
|
| N | FullAudio | WMPImporter.exe | Used to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
|
| N | FusionHdtvTray | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| U | FusionRC | FusionRC.exe | "Remote control manager for DVICO FusionHDTV"
|
| U | FusionRemote | FusionRc.exe | "Remote control manager for DVICO FusionHDTV"
|
| N | FusionTrayAgent | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| X | FW Manager | fwcheck.exe | "Added by the DELBOT-H WORM!"
|
| X | Fwr Command Module | fwr.exe | "Added by the SDBOT-PP WORM!"
|
| N | fwrastrc | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP
|
| U | fwservice | fwservice | "eAcceleration Stop-Sign security software related. Previously not recommended |
| X | FX | ieloader.exe | Added by the SMALL.RR TROJAN!
|
| X | Fxoekm | miyhart.exe | "Added by the SDBOT-CZQ WORM!"
|
| U | fxredir | fxredir.exe | Canon MultiPASS fax redirector
|
| X | f~a | ra32.exe | "Added by the CAY TROJAN!"
|
| X | G00123 | [worm filename] | "Added by the BUGBROS WORM!"
|
| X | G4G | [random filename] | Detected as Trojan-Downloader.Win32.VB.fki
|
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | "System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
|
| ? | GACService | GACService.exe | "Related to a Gemplus product. What does it do and is it required?"
|
| N | Gadwin PrintScreen | PrintScreen.exe | "Gadwin PrintScreen - utility to capture |
| U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
|
| X | game | patcher.scr | "Added by the PSW-ED TROJAN!"
|
| N | Game Device | JOYUPDRV.EXE | Genius game controller profile activator
|
| N | GameDrive | GDTask.exe | "GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
|
| X | Games Acceleration | svshost.exe | "EasySearch adware"
|
| X | Games Acceleration | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Games Acceleration | svshost1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | "Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| N | GameTracker | GTLite.exe | "GameTracker - ""Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"""
|
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers
|
| X | gaSrv | gaSrv.exe | "Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
|
| X | gaSrve | gaSrve.exe | "Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
|
| X | Gate Personal Firewall | Systpl.exe | "Added by the RBOT.ADC WORM"
|
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder
|
| X | Gator | gator.exe | "Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | Gator eWallet | gator.exe | "Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| Y | GBMPro7Agent | GBMAgent.exe | "Genie Backup Manager Pro 7 - backup software"
|
| U | GBTray | GBTray.exe | "System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
|
| Y | gcasServ | gcasServ.exe | "Giant Antipsyware - now superseded by Microsoft's Windows Defender"
|
| X | gcasServ | realsched.exe | "Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
|
| ? | GCC Reminder | gccrem.exe | "Associated with AcraMax Greeting Card Creator. Is it a registration reminder?"
|
| N | GCS | GrabClipSave.exe | "GrabClipSave screen capture tool"
|
| X | GDAX | [path to backdoor] | "Added by the RANKY.K TROJAN!"
|
| X | Gddlib | "rundll32.exe gddlib.dll | start" |
| Y | GDFirewallTray | GDFirewallTray.exe | "System Tray access to the firewall part of G Data range of internet security products"
|
| U | GDMgr.exe | gdmgr.exe | "GuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer"
|
| N | GDrive | GDriver.exe | Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager
|
| N | Gearbox | confsvr.exe | "NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
|
| N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
|
| X | Gekio Startups | gnksvc32.exe | "Added by the AGOBOT.AFJ WORM!"
|
| N | GemStRmW | GemStRmW.exe | "For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card |
| X | gencroot | gencroot.exe | "Added by the SDBOT-AED WORM!"
|
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives
|
| X | General Antivirus | GenAvir.exe | "General Antivirus rogue security software - not recommended |
| X | general lptt01 | general.exe | "RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | general ml097e | general.exe | "RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Generic host proccess for windows | SVCHOSTS.EXE | "Added by the SPYBOT-GQ WORM!"
|
| X | Generic Host Process | SCHOST.EXE | "Added by the RBOT-NC WORM!"
|
| X | Generic Host Process | svchost.exe | "Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | Generic Host Process | lsassw.exe | "Added by the AGOBOT-N WORM!"
|
| X | Generic Host Process for Win Services | mscvs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Process for Win32 Service | svlhost.exe | "Added by the WOOTBOT.EX WORM!"
|
| X | Generic Host Process for Win32 Service | rpchost.exe | "Added by the IRCBOT.DCN WORM!"
|
| X | Generic Host Process for Win32 Services | ntspcv.exe | "Added by the SDBOT.S TROJAN!"
|
| X | Generic Host Process for Win32 Services | intspvc.exe | "Added by the DINFOR.D WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc.exe | "Added by the SDBOT-O WORM!"
|
| X | Generic Host Process for Win32 Services | bazzi.exe | "Added by the AHKER.E WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc32.exe | "Added by the SDBOT-P WORM!"
|
| X | Generic Host Process for Win32 Services | lspsvc.exe | "Added by the MUMU.C WORM!"
|
| X | Generic Host Process for Win32 Services | SPSVC.EXE | "Added by the SDBOT.DA WORM!"
|
| X | Generic Host Process for Win32 Services | svchost32.exe | "Added by the AGOBOT.ALH WORM!"
|
| X | Generic Host Process for Win32 Services | svñhîst.exe | "Added by the DLOADER.AK TROJAN!"
|
| X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Generic Host Process For Win32 Services | mtsc32.exe | "Added by the VB-CPL TROJAN!"
|
| X | Generic Host Process for WinXP Services | mshelp.exe | "Added by the AGENT-GQP TROJAN!"
|
| X | Generic Host Process2 System Backup | scvhost2.exe | "Added by the RBOT-BAH WORM!"
|
| X | Generic Host Process326a System Backup | scvhost326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Service | lshost.exe | "Added by the RBOT.LU WORM!"
|
| X | Generic Service Process | regsvc32.exe | "Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
|
| X | Generic Service Process | serv1ces.exe | "Added by the AGOBOT-JK WORM!"
|
| X | Generic Service Process | nvsvc.exe | "Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
|
| X | Generic Service Process | srvhost.exe | "Added by the AGOBOT-FX WORM!"
|
| X | Generic Service Process | regsvr32.exe | "Added by the AGOBOT-AGD WORM!"
|
| X | Generic Service Process | SRCHOST.EXE | "Added by the AGOBOT-DG WORM!"
|
| X | Generic Services Process | regsvc32.exe | "Added by the GAOBOT.SY WORM!"
|
| X | GenericHostXP | WinLoaderXP.exe | "Added by the BDOOR-ACX BACKDOOR!"
|
| Y | Genie USB Monitor | USBmonitor.exe | Port monitor for an external USB hard drive. Required to enable access to the drive
|
| X | Genius Mose Driver | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | genserv path | sdqdqg.exe | "Added by the SDBOT-RF WORM!"
|
| X | Geography TX 1.0 NT | CompuSpeed.vbs | "Added by the NEWLEY-A WORM!"
|
| X | Gerenciamento de arquivos do Windows | Winmod32.exe | "Added by the DLOADER-WG TROJAN!"
|
| X | german.exe | winsystems.exe | "Added by the BAGLEDl-AE TROJAN!"
|
| X | german.exe | wintems.exe | "Added by the BAGLE-AS TROJAN!"
|
| X | Gestionnaire de disques universel | sysoobe.exe | "Added by the TOADER-A TROJAN!"
|
| X | Get-Torrent Service | wakeservice.exe | Get-Torrent bittorrent client - Installs LOP adware
|
| X | GetitAll | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | GetRight | GetRight.exe | "GetRight from Headlight Software - shareware download manager for resuming downloads and choosing multiple download locations. The Pro version adds uploading and other features. Earlier 4.x versions included ads |
| U | GetRight - Tray Icon | getright.exe | "Entry added with older versions of the GetRight download manager from Headlight Software |
| X | GetTheMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | Getting started with MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | gfxtray | "rundll32 ctccw32.dll | findwnd" |
| X | Ghost Antivirus | GhostAV.exe | "Ghost Antivirus rogue security software - not recommended |
| X | Ghost Relay | [random filename] | "Added by the DNSCHANG.EK TROJAN!"
|
| U | GhostSecuritySuite | gss.exe | "Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
|
| N | GhostStartService | GhostStartService.exe | "Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
|
| N | GhostStartTrayApp | GhostStartTrayApp.exe | "System Tray access to Norton Ghost - added from the 2003 version"
|
| Y | GhostSurfDelSatellite | DeleteSatellite.exe | "Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning |
| U | Giganews Accelerator | GiganewsAccelerator.exe | "Giganews Accelerator from Giganews |
| Y | Gilat SOM Enumerator | dllhost.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| X | gimmygames | [path to trojan] | "Added by the DLOADR-LN TROJAN!"
|
| X | GLF Network Lan Monitor | NPFMNTOR.exe | "Added by the RBOT-AGY WORM!"
|
| X | Global Startup | WinDash.EXE | "Detected by Kaspersky as the VB.Q WORM!"
|
| X | GlobalFlagACER | ACER.exe | "Added by the VB.BL WORM!"
|
| X | GlobalSCAPE | [random filename] | "Added by the RBOT-AYM WORM!"
|
| X | GNP Generic Host Process | svchost.exe | "Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| X | go | cvir.exe | "Added by the SILOV-A WORM!"
|
| X | Go And Start | svdll32.exe | "Added by the RBOT.AI BACKDOOR!"
|
| X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
|
| U | GoBack | GBTray.exe | "System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Polling Service | GBPoll.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Tray Icon | GBTray.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | goidr | goidr.exe | "Goidr adware"
|
| U | Goldensoft_MndlSvr | MndlSvr.exe | "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive |
| X | Golum | services.exe | "Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process |
| X | golumm | services.exe | "Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
|
| X | good | badvir.exe | "Added by the SILOV-B WORM!"
|
| U | Google Desktop Search | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| X | Google Earth | [random filename] | "Added by the RBOT-AXK TROJAN!"
|
| N | Google Earth Viewer | GOOGLEMAPS.EXE | "Google Earth ""combines satellite imagery |
| U | Google IME Autoupdater | GooglePinyinDaemon.exe | "Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone |
| X | google Intrenet Explorer | google.pif | "Added by the RBOT-ARA WORM!"
|
| U | Google Quick Search Box | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| X | Google service | Googlesetup.exe | "Added by the IRCBOT-RJ WORM!"
|
| X | Google Service FR | GO0GLEFREE.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | google toolbar | ggtb32.exe | "Added by the AGOBOT-RR WORM!"
|
| N | Google Updater | GOOGLE~1.EXE | "Downloads and installs updates for Google applications (Google Earth |
| N | Google Updater | GoogleUpdater.exe | "Downloads and installs updates for Google applications (Google Earth |
| U | GoogleQuickSearchBox | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| U | GoogleToolbarNotifier | GoogleToolbarNotifier.exe | "Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
|
| X | GoogleUpdater3 | GoogleMapper.exe | "Added by the ROUTROBOT WORM!"
|
| U | GoTrusted | GoTrusted Secure Tunnel.exe | """GoTrusted is the fast |
| X | gouday.exe | readme.exe | "Added by the BEAGLE.C WORM!"
|
| X | govurarope | "Rundll32.exe retasevo.dll | s" |
| X | GP Updater | gpupdater.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | GPLv3 | [random name].dll | "Vundo adware"
|
| X | gqgqqger | gqgeqegl.exe | "Added by the SDBOT-CLJ WORM!"
|
| N | GRA | gra.exe | "Looks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up |
| ? | gramdate | 2Stop.exe | "??"
|
| X | Graphic Driver | smss32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Loader | ntvdm32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Update | openglx.exe | "Added by the IRCBOT.AMU WORM!"
|
| X | Graphics | _default.pif | "Added by the AUTOSKY WORM!"
|
| X | Graphics adapter service | windll.exe | "Added by the ATNAS.A WORM!"
|
| U | Gravis Appawareloader | dbserver.exe | "Looks like it's associated with Gravis game controllers and the Keyset Manager |
| U | Gravis Xperience Driver Support | Grxp4exe.exe | "Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
|
| ? | GrdSys32 | GrdSys32.exe | "X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
|
| X | GreasyPalmUpdate | GreasyPalmUpdate.exe | "SearchFast adware"
|
| X | GreatDefender | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDefender.exe | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Greetings Workshop | GWREMIND.EXE | You really want to be reminded about somebody's birthday at the expense of resources?
|
| X | gremier | wscript.exe gpremier.vbs | "Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
|
| X | Gremlin | intrenat.exe | "Added by the DOOMJUICE WORM!"
|
| X | grgtgvgb.exe | [random].exe | "Added by the AGENT-EBF TROJAN!"
|
| X | grinders | grinders.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| N | Grokster | Grokster.exe | "Grokster Peer-To-Peer File Sharing program"
|
| Y | Groove Virtual Office | Groove.exe | """Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings |
| U | GrooveMonitor | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GrooveMonitor Utility | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| N | GrpConv | grpconv.exe | "Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
|
| ? | GsiFinal | "rundll32 gspndll.dll | postInstall final" |
| ? | GSISETUP | [path] GsiInst.exe INSTALL [path] V205Res 13 | "BT Voyager ADSL modem related - what does it do and is it required?"
|
| N | GSOrganizer | GSOrganizer.exe | "GoldenSection Organizer (now WinOrganizer - personal information manager)"
|
| Y | gStart | gStart.exe | gStart GPS software from Garmin
|
| X | GStartup | GMT.exe | "Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | GT15J4R49V | cpuserv.exe | Identified as a variant of the Trojan.Win32.Radi.gu malware
|
| U | GTVRec | GTVRec.exe | "Part of Got All Media - control your TV tuner and other utilities from your PC"
|
| X | gtydf | ggrrgg.exe | "Added by the DLOADR-AZK TROJAN!"
|
| U | Guard | Guard.exe | "Related to Phoenix Technologies Core Managed Environment (cME) Integration and Certification program"
|
| X | Guard Pro | VH339.exe | "Guard Pro rogue security software - not recommended |
| X | GuardCenter | GuardCenter.exe | "GuardCenter rogue security software - not recommended"
|
| Y | GuardGui Application | GuardGui.exe | "System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
|
| U | Guardian | CMGrdian.exe | "McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security |
| U | Guardian PC Security Tools | Pfft.exe | "Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
|
| X | GuardPcs.exe | GuardPcs.exe | "GuardPcs rogue security software - not recommended |
| X | GuardWWW | GuardWWW.exe | "GuardWWW rogue security software - not recommended |
| X | guarnset | guarnset.exe | "Adlogix adware"
|
| X | GURL | gurl.exe | "GURLWatcher spyware"
|
| U | GuruNet | GuruNet.exe | "GuruNet lets you click on any word on your screen to get the relevant information you want"
|
| X | gvagfxj | rundll32 ...gvagfxj.dll | "Unidentified adware |
| Y | gw port controller | PORTCT95.EXE | "From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties |
| N | GWInkMonitor | GWInkMonitor.exe | "Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink |
| X | gwiz | arpl.exe | "Detected by F-Prot as W32/Downloader-Sml-based"
|
| X | G_Server.exe | G_Server.exe | "Added by the FEUTEL-C TROJAN!"
|
| X | G_Server1.2.exe | G_Server1.2.exe | "Added by the GRAYBIRD-Z TROJAN!"
|
| X | h4te Service Drivers | h4te.exe | "Added by a variant of the RBOT WORM!"
|
| U | Habu | razerhid.exe | "Microsoft Habu (by Razer) gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| U | HalifaxHowardCluster | skinkers.exe | """Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
|
| U | HaMFrontPanel | hampanel.exe | "Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget |
| N | Hard Disk Sentinel | HDSentinel.exe | "Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find |
| X | Hard drive Controller | hdcontroller.exe | "Added by the KIMAN.B WORM!"
|
| X | HardDriveGuard | SysRep.exe | "HardDriveGuard rogue system error and cleaning utility - not recommended |
| U | Hardware Doctor | Hwdoctor.exe | "Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds |
| X | Hardware Monitor Service | mshms.exe | "Added by the WOLLF-A TROJAN!"
|
| X | Hardware Profile | hxdef.exe | "Added by the LOVGATE.AB WORM!"
|
| X | Hardware Profile | hxdef.exe... | "Added by the LOVGATE.Z WORM!"
|
| U | Hardware Sensors Monitor | hmonitor.exe | Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
|
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| U | Hare | hare.exe | "Hare - improve and optimize performance of desktop/laptop PCs"
|
| U | Harmony 98 - CasioOrg | CasAgnt.exe | "Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | HataDuzelticisi | SysRep.exe | "HataDuzelticisi |
| X | HATAPE | [path to trojan] | "Added by the BANKER-QF TROJAN!"
|
| U | HawkEye IV Control Panel | HAWK_32.EXE | "Control Panel application for the old Number Nine graphics cards to change resolution |
| U | Hawking Wireless Utility | HWU8DD.exe | "Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies |
| N | HC Reminder | hc.exe | "For Compaq PC's. Help Compiler |
| U | hcenter | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | hcenter | hcenter.exe | "Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | Hcontrol | hcontrol.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| U | HControlUser | HControlUser.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| N | hcsystray | hc_tray.exe | "Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
|
| N | HD Audio Control Panel | RtHDVCpl.exe | "Realtek HD Audio Manager |
| X | HDAudio Driver 1.0 | [random filename].exe | "Added by the TEADOOR-D TROJAN!"
|
| X | HDAudio Driver 2.0 | [random filename].exe | "Added by the TEADOOR-E TROJAN!"
|
| U | HDDControlGuard | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| U | HDDControlGuard.exe | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| X | hdlpscom | [8 random letters].exe | "Added by the RBOT-FUL WORM!"
|
| X | HDriveSweeper | HDriveSweeper.exe | "HDriveSweeper rogue privacy program - not recommended |
| N | HDtray | HDtray.exe | Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
|
| X | he3bbcff | "rundll32.exe he3bbcff.dll | EnableRunDLL32" |
| X | he3e3fc4 | "rundll32.exe he3e3fc4.dll | EnableRunDLL32" |
| X | Hekio Startups | Hnksvc32.exe | "Added by the AGOBOT-QE WORM!"
|
| X | hellfire | svchost.exe | "Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | helloserv | helloserv.exe | "Added by the ZHELATI.BHA WORM!"
|
| X | helloworld | nb32ext2.exe | "Added by the MYDOOM.BV WORM!"
|
| X | helloworld | nb32ext3.exe | "Added by the MYTOB.JT WORM!"
|
| X | helloworld3 | nb32ext4.exe | "Added by the RITDOOR.A WORM!"
|
| X | help | help.scr | "Added by the BANCOS-BBU TROJAN!"
|
| X | Help | Wizardnil.exe | "Added by the BANCOS-BCZ TROJAN!"
|
| X | Help Temp Files | netreg.exe | "Added by the FORBOT-EM WORM!"
|
| U | HelpCenter | sprtcmd.exe /P HelpCenter | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| U | HelpCenter4.1 | sprtcmd.exe /P HelpCenter4.1 | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| X | Helper | eschlp.exe | "Added by the BLASTER.T WORM!"
|
| X | HELPER | greece_nm.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | Netherlands.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | new_zealand.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | sweden.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | canada.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | france.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | temp532.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | helper.dll | rundll32.exe [path] helper.dll | "CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | helpmanager | spoler.exe | "Added by the RANDEX.J WORM!"
|
| Y | HEProtect | HSockPE.exe | "Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
|
| ? | HerculesCamService | CamService.exe | "Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
|
| X | hErcUnes | softhost.exe | "Added by the GARROCH WORM!"
|
| X | herjek | herjek.exe | "Added by the NUWAR.APJ WORM!"
|
| U | Hermes Messenger | DGDRHE~1.EXE | "A LAN messenger alternative to WinPopUp - Digital Dreams Software"
|
| X | Hewlett Packard Manager | hpmanager.exe | "Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
|
| N | Hewlett Packard Recorder | Remind32.exe | HP multifunction registration
|
| X | HF Security | hfsecure.exe | "Added by the AGOBOT-TI WORM!"
|
| Y | hffsrv | hffsrv.exe | "Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders |
| Y | hffsrv.exe | hffsrv.exe | "Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders |
| N | HGTXPEI | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
|
| X | hhtnsn | rnxntup.exe | "Added by a variant of the ORCU.B TROJAN!"
|
| ? | HiberMonitor | HCount.exe | "??"
|
| U | Hibernation | hib32.exe | "Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate |
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | "Added by the BOOHOO WORM!"
|
| X | HideStyle | Ante Browse Trust.exe | "IE toolbar taking you to Lop.com. If the exe is running |
| U | Hidetools Spy Monitor | wmispe.exe | "HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252