| Y | Desktop Armor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop Maestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | Desktop Maestro Vista Tray | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | Desktop Plant | AZARE10S.PLT | "Vritual plant from here - this version is an Azalea |
| X | Desktop Search | desktop.exe | "iSearch adware"
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THEWEA~1.EXE | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| Y | DesktopArmor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | DesktopMaestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | DesktopMaestro | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | DetectorApp | DetectorApp.exe | "Related to Roxio MyDVD (was Sonic) DVD authoring software"
|
| X | Deus Cleaner | DCleaner.exe | "Deus Cleaner rogue system cleaner utility - not recommended"
|
| ? | DevconDefaultDB | READREG | "Appears to be related to older Creative Soundblaster soundcards"
|
| U | DEventAgent | eventagt.exe | DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Device Hardware | devicehnd.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Management | wnsystem.exe | "Added by the AGOBOT-LH WORM!"
|
| X | Device Manager | wfxmgr.exe | "Added by the RBOT.AJU WORM!"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | DevicePath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | DevicePath | Root.exe | "Added by the GRUEL WORM!"
|
| X | Devicewin | [path to trojan] | "Added by the BANKER-AEV TROJAN!"
|
| X | dfgfdgrergd | [path to trojan] | "Added by the RANKY.CK TROJAN!"
|
| X | dgtstart | dgtstart.exe | "DigitalNames.g adware"
|
| U | dguard | dguard.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| Y | dhcpagnt | dhcpagnt.exe | Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
|
| X | DI2 | [path to file] | "BroadcastPC adware"
|
| N | diagent | diagent.exe | System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
|
| X | Diagnostic | diagnostic.exe | "Added by the ALPHA-C TROJAN!"
|
| X | Diagnostic Agent | diagent.exe | "Added by the AGOBOT-CW WORM!"
|
| X | Dial22 | dlm.exe | Adult content dialler
|
| X | Dial33 | dlm.exe | Adult content dialler
|
| X | Dialer | "rundll32.exe MSA32CHK.dll | Reg" |
| U | Dialer Control | dc.exe | "Dialer-Control. Detects and protects from premium rate adult content diallers"
|
| U | Dialer Detect | dd.exe | "DialerDetect detects stealth installed premium rate diallers |
| U | Dialgo SDK | PhoneAnswer.exe | "Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID |
| X | DialNet | mxt32.exe | Adult content dialler
|
| N | Dialog Box Assistant | OSDEx.exe | "Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
|
| N | Dialog Helper | PDDLGHLP.EXE | "Dialog Helper from PowerDesk Pro by Ontrack. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders. Available via Start -> Programs"
|
| X | DialUp Network Application | Rnaap.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Diam prlaer | oqedrhg.exe | "Added by the SDBOT-DEU WORM!"
|
| U | Diamondback | razerhid.exe | "Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| ? | Diamondview | Diamondview.exe | "Manulife Financial Insurance program. Is it required at startup?"
|
| X | Diesel | Recalculate.exe | "Added by the LAZAR TROJAN!"
|
| X | DigiD | DigitalSound.exe | Adware downloader
|
| U | Digisoft AntiDialer | AntiDialer.exe | "Digisoft AntiDialer"
|
| N | Digital Dashboard | devgulp.exe | For Compaq PC's. Loads Digital Dashboard options
|
| N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
|
| Y | Digital Patrol Update 5 | update.exe | "Digital Patrol - ""a powerful anti trojan scanner |
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| N | Digital River eBot | downlo~1.exe | "Digital River Systems EBOT for downloading software from their site. In some cases |
| X | DigitalNames | DigitalNamesStart.exe | "DigitalNames spyware variant"
|
| N | DigitalWizard | ISWizard.exe | "InstallShield's DigitalWizard - free |
| N | DigitalWizard Monitor | dwMon.exe | "InstallShield's DigitalWizard - free |
| N | DIGStream | digstream.exe | "DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
|
| X | Diomacd | fdafbfd.exe | "Added by the MULDROP.F TROJAN!"
|
| X | Dir1 | caKe | "Added by the CAKE WORM!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX9 Diag | dx9diag.exe | "Added by the RBOT-ALT WORM!"
|
| ? | Disable EHCI | nousb20.exe | "??"
|
| X | DisableKeybaord | "Rundll32.exe Keyboard | Disable" |
| X | DisableMouse | "Rundll32.exe Mouse | Disable" |
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| U | Disk Cleaner | DiskCleaner.Exe | "Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Essensial Tools | detsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | [path to trojan] | "Added by the SMALL-VE TROJAN!"
|
| X | Disk Manager | diskver.exe | "Added by the RBOT.AQT WORM!"
|
| X | Disk Master | [trojan name] | "Added by the DISTER TROJAN! - a spam relayer"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | Disk Panel Setup | npcsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| N | Disknag | disknag.exe | Dell program that reminds you to make your backup diskettes
|
| X | Diskstart | Code.exe | Adult content dialler
|
| X | Diskstart | cat.exe | MS-Connect dialler
|
| X | Diskstart | hit.exe | Adult content dialler
|
| X | Diskstart | Snt.exe | Adult content dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| X | disnisa | disnisa.exe | "Added by the DORF-AE WORM!"
|
| X | Dispatcher | dispatcher.exe | "Added by the DLOADR-AS TROJAN!"
|
| U | display | The_Eye.exe | "ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
|
| X | Display | backup.exe | "Added by the BRONTOK-CR WORM!"
|
| X | Display Drivers | cssrs.exe | "Added by the AGOBOT.FX WORM!"
|
| N | Display Settings | hptasks.exe | "Allows for the adjustment of the display for LCD screen |
| U | DisplayFusion | DisplayFusion.exe | "DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much |
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
|
| X | Distributed File System | blade.exe | "Added by the MYFIP.AC WORM!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| N | DiTask.exe | DiTask.exe | "Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free |
| ? | Divamon.exe | Divamon.exe | "Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?"
|
| X | DivX MediaPlayer 7.0 | Dr.DivX.exe | "Added by the ALADINZ.G TROJAN!"
|
| X | DivX Player | DivXPlayer.exe | "Added by a variant of the RBOT WORM!"
|
| X | DivX Updater | DivX.Exe | "Added by the NALDEM TROJAN or MASTAK VIRUS!"
|
| X | DIVX Video Player | DIVXPloyer.exe | Added by an unidentified WORM or TROJAN!
|
| X | DivXCodec | NEWMAIL.exe | "Added by the DELF-RQ BACKDOOR!"
|
| X | djdsdvqwa | vjdhdg.exe | "Added by the SDBOT-EF BACKDOOR!"
|
| X | Dkware lptt01 | dkware.exe | "RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Dkware ml097e | dkware.exe | "RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLA | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW.EXE | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| N | DlaTray | Dlatray.exe | "System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| X | dlcipscl | dcpavss.exe | "Added by the MAILBOT-CB TROJAN!"
|
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| X | DlDir1 | caKe | "Added by the CAKE WORM!"
|
| U | dldtamon | dldtamon.exe | Dell AIO Printer V305 device monitor
|
| N | DLHelperEXE | WATCH.exe | Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
|
| X | DLHelperEXE.exe | N/A | Downloader for Microgaming/Casino software - stealth installed
|
| U | DLink System Tray | dlnetst.exe | "Related to D-Link DGE-530T PCI card for servers and workstations"
|
| X | Dlite | dllmanager.exe | "Added by the WOOTBOT.DN WORM!"
|
| X | Dll Boot Loader on Startup (do not remove this) | [various filenames] | Added by an unidentified TROJAN!
|
| X | DLL Manager | dllmngr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | dll services | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | dllcache.exe | dllcache.exe | "Added by the VISPAT.A WORM!"
|
| X | DllCacherv2 | dllcachev2.exe | "Added by the LATEDA TROJAN!"
|
| X | dllcvss | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | DllExecutable | [path to file] | "Added by the VB-SP WORM!"
|
| X | DllLoader | lssas.exe | "Added by the BDOOR-JE BACKDOOR!"
|
| X | Dlload | killer.exe | "Added by the KILLAV-FK TROJAN!"
|
| X | DLLUPDATE32 | dllupdate32.exe | "Added by the AGOBOT.IA WORM!"
|
| N | dlmMgr | AdobeDownloadManager.exe | "Adobe Download Manager - ""can prevent you from having to start from the beginning should your download process be interrupted |
| Y | DLO Agent | DLOClientu.exe | "Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
|
| X | dluca | dluca.exe | "Added by the DLUCA.C TROJAN!"
|
| X | dm***.exe [* = random char] | dm***.exe [* = random char] | "Wareout - malware masquerading as a spyware and dialer remover"
|
| N | DMAScheduler | DMAScheduler.exe | "Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program |
| U | DMHotKey | DMLoader.exe | HotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
|
| N | DMISLAPP | DMISLAPP.exe | "DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
|
| ? | dmjay | dmjay.exe | "??"
|
| X | dmloader | dmloader.exe | "Added by a variant of the RBOT WORM!"
|
| U | DMXLauncher | DMXLauncher.exe | "Part of Dell's Media Experience |
| X | dm[3 random letters].exe | dm[3 random letters].exe | "Added by the RUINDEM TROJAN!"
|
| X | dm_service | [path to file] | "Added by the MITGLIEDER.P TROJAN!"
|
| N | DNA | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
| X | dnam | d140113.a.Stub.EXE | "Added by the STUB_A TROJAN!"
|
| N | Dnar | Dnar.exe | "Installed on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| X | DNS | [worm filename] | "Added by the BCKDR-CQG BACKDOOR!"
|
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | DNSCacheBoost | dnsping.exe | "Added by the DNSBUST-A TROJAN!"
|
| X | dnscleaner | dnscleaner.exe | "CoolWebSearch parasite variant"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| N | DocuMagix Init | PWATCH.EXE | "PaperMaster is an application for the PC designed to automate the process of organizing |
| U | Document Manager | docmgr.exe | "Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
|
| X | DOGStart | GSDOGST.EXE | "Added by an unidentified VIRUS |
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| X | DomPlayer Service | wakeservice.exe | "DomPlayer adware"
|
| U | Don't Panic | dontpanicdemodp.exe | "30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| U | Don't Panic! | DP.EXE | "Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
|
| X | Dontworry | mysaym.exe | "Added by the SDBOT-RC WORM!"
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| ? | Dosbat | ?? | "??"
|
| N | DoUWantIt | duwi.exe | DoUWantIt - online shopping assistant. Start it manually
|
| X | down | [trojan filename] | "Added by the SMALL-QJ TROJAN!"
|
| N | Download Accelerator Manager Free Edition | dam.exe | "Download Accelerator Manager Free Edition from Tensons Corp"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | Download Plus | DownloadPlus.exe | "DownloadPlus adware"
|
| N | Download Wonder | DownloadWonder.exe | "Download Wonder from Forty Software. Download manager for resuming downloads |
| N | DownloadAccelerator | DAP.EXE | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | DownloadLegalMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadWare | dw.exe | "DownloadWare adware"
|
| X | DownloadWare Engine | Dwe.exe | "DownloadWare adware"
|
| X | Downxz | Downxz.bat | "Added by the MYDOOM.W WORM"
|
| Y | DpAgent | dpagent.exe | "Part of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for example"
|
| N | DPAgnt | DPAgnt.exe | "digitalPersona fingerprint scanner"
|
| Y | DPAS | DPASNT.exe | "DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | DPASUpdate | DPASAutoUpdate.exe | "Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | Dpcnav | dpcnav.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | Dpcstart | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| N | dptracker | dptracker.exe | "CamTrack webcam software that enhances the way people video chat"
|
| U | DpUtil | TEDTray.exe | "Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device"
|
| X | DR service | [path to worm] | "Added by the RBOT-CZT WORM!"
|
| X | Dr. Guard | drguard.exe | "Dr. Guard rogue security software - not recommended |
| N | Drag'n'Drop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| ? | DragDrop | DragDrop.exe | "??"
|
| N | DragnDrop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| X | DRam Monitor 23 | tskman3.exe | "Added by a variant of the RBOT WORM!"
|
| X | DRam prmaessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosesor | [random filename] | "Added by the SPYBOT.EE WORM!"
|
| X | DRam prosessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosessor | plscd.exe | "Added by the RBOT.CYA WORM!"
|
| X | DRam prosessor | HWAPI.exe | "Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
|
| X | DRam prosessor | WindowsUpdate.exe | "Added by the RBOT-BBZ WORM!"
|
| X | DRam prosessor | msupdate.exe | "Added by the DELF-FAW TROJAN!"
|
| X | DRam prosessor | winupl.exe | "Added by the RBOT-BCQ WORM!"
|
| X | DRam rar proc | winupdaterar.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DRam rare proc | updaterarwin.exe | "Added by the RBOT-GQW WORM!"
|
| X | DRan posessor | DAP.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrAntispy | DrAntispy.exe | "DrAntiSpy rogue security software - not recommended"
|
| X | DrCache | MSTDC.EXE | "Added by the BDOOR-JM BACKDOOR!"
|
| X | dreams | server.exe | "Added by a variant of the SDBOT WORM!"
|
| X | drin | [path to trojan] | "Added by the SMALL.DPB TROJAN!"
|
| X | DriveCleaner 2006 Free | UDC2006.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveCleaner Free | UDC.exe | "DriveCleaner rogue security software - not recommended |
| X | Driver32 | Scam32.exe | "Added by the SIRCAM WORM!"
|
| X | DriverLoad | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| U | DriverMagicLogon | dmschedule.exe | "Part of DriverMagic - ""the easiest way to locate device drivers"""
|
| N | DriverMax | devices.exe | "DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
|
| X | DriverPath | system32.exe | "Added by the PRORAT-S TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| X | Drives swap | AV1i.exe | "Anti-Virus Number-1 rogue security software - not recommended |
| X | DriveSystem | maxpaynowti1.exe | "Added by the TIBS.AZT TROJAN!"
|
| X | DRM Upgrade | drmupgd.exe | "Added by the IRCBOT.AWU BACKDOOR!"
|
| U | dRMON SmartAgent | SmartAgt.exe | "Part of the network monitoring program group for 3Com NIC cards. See here for more info"
|
| X | DropSpam Lifestyle | dslifestyle.exe | "Dropspam adware"
|
| X | drvrmanager | drvrquery32.exe | "Added by the BOOHOO WORM!"
|
| X | DrvStart | HPMedia.exe | "Added by the BANCBAN-QE TROJAN!"
|
| X | DrWatson | drwatson_.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWatson | drwatson_32.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWeb Antivirus | DRWEBAV.EXE | Added by an unidentified WORM or TROJAN!
|
| X | dS35DLL | ffqca.exe | "Added by the SDBOT-KV WORM!"
|
| X | dsa | dsa.exe | Homepage hijacker - redirecting to downseek.com
|
| X | DSAcass | [path to file] | "Added by the RANKY.M TROJAN!"
|
| X | dsadlsa14 | dsakfsak14.exe | "Added by the ONLINEG-P TROJAN!"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | dsfghjgj | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | dsgb | lcsass.exe | "Added by the AGENT.TGZ BACKDOOR!"
|
| X | Dskcompat | Dskcompat.exe | "Added by the GEMA TROJAN!"
|
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| Y | DSLagentexe | DSLagent.exe | "Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
|
| U | DSLSTATEXE | dslstat.exe | System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DSS | dssagent.exe | "Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| ? | DSSSGENS | dssagens.exe | "??"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT 11Mbps WLAN USB Station | DTUSBMonitor.exe | 11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT Task | DTHtml.exe | "Display Tune from Portrait Displays |
| N | DTAgent | DTAgent.exe | "System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Dulux WeatherShield WeatherDesk | weather.exe | "Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
|
| X | DVAScvssdfa | AsSDdwd.exe | "Added by the LIOTEN.IP TROJAN!"
|
| U | DVD Device Lock for Win95/98/Me/2k/XP | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| X | DVD Upgrade | dvdupgd.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| N | dvd43 | DVD43_Tray.exe | "DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
|
| N | DVD@ccess | DVDAccess.exe | "Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
|
| ? | DVDAgent | DVDAgent.exe | "Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
|
| X | Dvdcompat | Dvdcompat.exe | "Added by the GEMA TROJAN!"
|
| N | DVDLauncher | DVDLauncher.exe | "Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
|
| N | DVDTray | DVDTray.exe | HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
|
| N | DVDUpgrade | DVDUpgrd.exe | "Microsoft program to upgrade your DVD decoder program - see Q306331. Available via Start -> Programs"
|
| Y | dvpapi9x | DVPAPI9X.exe | Command AntiVirus for Windows 95/98/Me
|
| X | dvraudio | dvraudio.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| N | DW4 | Weather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW4 | DesktopWeather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW6 | DesktopWeather.exe | "Desktop Weather 6 by The Weather Channel - provides current temperature |
| U | DWHeartbeatMonitor | DWHeartbeatMonitor.exe | DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
|
| X | dwqblwppx.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwpvl.exe | [random].exe | "Okcashbackmall adware"
|
| X | dwqblwrsq.exe | [random].exe | "Okcashbackmall adware"
|
| N | dwStart | FireWall.exe | "The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
|
| X | DW_Start | rwwnw64d.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| X | Dx | sys*.exe [* = random number] | "Added by the DEXTER.A WORM!"
|
| X | Dx8compat | Dx8compat.exe | "Added by the GEMA TROJAN!"
|
| X | dxdiag diagnose | msidxdia.exe | "Added by a variant of the RBOT WORM!"
|
| X | dxdiags.exe | dxdiags.exe | "Added by the CERTIF-G TROJAN!"
|
| X | DxDialog | dxdlg32.exe | "Added by the VB-CXT TROJAN!"
|
| X | DxLoad | DX3DRndr.exe | "Added by the GIBE.B WORM!"
|
| N | DXM6Patch_981116 | p_981116.exe | "Win32 cabinet self extractor. More info here"
|
| X | Dxupdate.exe | Dxupdate.exe | "Added by the MAFEG WORM!"
|
| X | DyFuCA | optimize.exe | "Adult content dialler - see here"
|
| X | DyFuCA Active Alert | actalert.exe | "Adult content dialler - see here"
|
| X | Dynamic DHCP | dydhcp.exe | "Added by the RINBOT.B TROJAN!"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| X | Dynamic Dns Binary | CMD16.EXE | "Added by the RBOT-XM WORM!"
|
| X | Dynamic Dns Binary | winxp34.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Dns Binary | WinHelpcfn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Link Library loader | Loader32.exe | "Added by the KOL TROJAN!"
|
| U | DynDNS Updater | DynDNS.exe | "Dynamic DNS IP address updater tool |
| N | DynDNS-Updater Traytool | ddutray.exe | "DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
|
| X | DynHttp Dns Binary | dynizari.exe | "Added by a variant of the RBOT WORM!"
|
| U | Dynu Basic Client | dynubas.exe | "Dynu online dynamic IP update client. Useful when using a dial up modem"
|
| ? | DZKillMe | DZSAVEME.EXE | "??"
|
| X | E-Card | ecard.exe | "Added by the YODI WORM!"
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| U | e-Surveiller Station | estation.exe | "ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
|
| N | E6TaskPanel | TaskPanl.exe | "Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet |
| N | EA Core | Core.exe | "Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches |
| U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
|
| X | Eac Download | download.exe | "Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
|
| U | EACLEAN | eaclean.exe | "For Compaq PC's. Easy Access button support for the keyboard"
|
| X | Eac_Cnry | canary.exe | "Added by the CANARY TROJAN!"
|
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| Y | EAFRCliStart | EAFRCliStart.exe | "Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
|
| U | EanthologyApp | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | EanthologyApp | eanthology.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanthology_install.exe | eanthology_install.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| N | Eapcisetup | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it
|
| N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
|
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| N | EarthLink ToolBar 5.0 | etoolbar.exe | "EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar |
| N | Easy CD Creator | RoxAssist.exe | "Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize |
| U | Easy Key | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
|
| N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| X | EasyAV | EasyAV.exe | "Added by the NETSKY.S or NETSKY.T WORMS!"
|
| X | EasyDates | EasyDates.exe | Premium rate adult content dialler
|
| X | EasyDates_gb | EasyDates_gb.exe | """Edate-A"" premium rate adult content dialler"
|
| X | EasyDates_nl | EasyDates_nl.exe | Adult content dialler
|
| U | EasyKey | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
|
| U | EasyKeyboardLogger | EasyKeyboardLogger.exe | "EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | EasyLinkAdvisor | LinksysAgent.exe | "Linksys EasyLink Advisor - ""the free application that provides and easy way to setup |
| X | EasyMessage | em2.exe | "180solutions adware"
|
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader
|
| X | easyServ | Server.exe | "Added by the EASYSERV TROJAN!"
|
| X | EasySpywareCleaner | EasySpywareCleaner.exe | "EasySpywareCleaner rogue spyware remover - not recommended |
| U | EasySync Pro | XCPCMenu.exe | """IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasyTuneIII | EasyTune.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneV | GUI.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| X | easywww | easywww2.exe | "Added by an unidentified VIRUS |
| U | eAudio | eAudio.exe | "Part of Acer Empowering Technology. Acer eAudio Management provides centralized control over notebook audio and specialized audio modes for movies |
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | "Ebates adware"
|
| X | eBay Toolbar | EBAYTBAR.EXE | "eBay Toolbar - reportes as spyware as it "phones home""
|
| U | eBayToolbar | eBayTBDaemon.exe | "eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
|
| X | ebmmm | ebatesmmmv.exe | "Ebates adware"
|
| U | eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| N | eBot | DownloadWizard.exe | "eBot from Digital River - ""helps ensure your computer always has the latest technology |
| N | ECenter | EULALauncher.exe | End User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
|
| X | ecko | claro.exe | "Added by the DLOADR-AQJ TROJAN!"
|
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| X | editpad | editpad.exe | "Added by the CONSPER-B TROJAN!"
|
| N | EDLoader | DTLoader.exe | Effective Desktop from MiniStars Software - desktop management software no longer being supported
|
| X | educational writer | [random filename] | "Added by the RBOT-LZ WORM!"
|
| U | Edwizard | Edwizard.exe | "SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection |
| X | EDxMC110 | Isass.exe | "Added by the VB-NIA WORM!"
|
| X | Edzy AntiVirus | dppsfa.exe | "Added by a variant of the RBOT WORM!"
|
| N | EEventManager | EEventManager.exe | "Part of the Epson Creativity Suite supplied with their multi-function printer/scanners |
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | eFax 4.1 | J2GDllCmd.exe | "DLL Command Utility for version 4.1 of eFax Messenger from j2 Global Communications |
| U | eFax 4.1 | J2GTray.exe | "System Tray access to version 4.1 of eFax Messenger from j2 Global Communications |
| U | eFax 4.2 | J2GDllCmd.exe | "DLL Command Utility for version 4.2 of eFax Messenger from j2 Global Communications |
| U | eFax 4.2 | J2GTray.exe | "System Tray access to version 4.2 of eFax Messenger from j2 Global Communications |
| U | eFax 4.3 | J2GDllCmd.exe | "DLL Command Utility for version 4.3 of eFax Messenger from j2 Global Communications |
| U | eFax 4.3 | J2GTray.exe | "System Tray access to version 4.3 of eFax Messenger from j2 Global Communications |
| U | eFax 4.4 | J2GDllCmd.exe | "DLL Command Utility for version 4.4 of eFax Messenger from j2 Global Communications |
| U | eFax 4.4 | J2GTray.exe | "System Tray access to version 4.4 of eFax Messenger from j2 Global Communications |
| U | eFax DllCmd | J2GDllCmd.exe | "DLL Command Utility for eFax Messenger from j2 Global Communications |
| U | eFax DllCmd 3.5 | J2GDllCmd.exe | "DLL Command Utility for version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax DllCmd 4.0 | J2GDllCmd.exe | "DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications |
| U | eFax Live Menu 3.3 | J2GDllCmd.exe | "DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications |
| N | eFax Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | eFax Tray Menu | J2GTray.exe | "System Tray access to eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.3 | J2GTray.exe | "System Tray access to version 3.3 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.5 | J2GTray.exe | "System Tray access to version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 4.0 | J2GTray.exe | "System Tray access to version 4.0 of eFax Messenger from j2 Global Communications |
| N | eFax.com Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| X | efaxs lptt01 | efaxs.exe | "RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | efaxs ml097e | efaxs.exe | "RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| U | EFI Job Monitor | "[path] efjm.dll | run" |
| U | Efpap.exe | Efpap.exe | "Easy File & Folder Protector. Deny access to certain files and folders |
| X | egikugu | napolecy.exe | "Added by the SDBOT.AOE WORM!"
|
| N | EgisTecLiveUpdate | EgisUpdate.exe | "Software updater for biometric and data encryption products from EgisTec Inc"
|
| U | ehTray | ehtray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | ehTray.exe | ehTray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| U | Eicon TechnologyLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eixfi | china.bat | "Added by the WCUP.A WORM!"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| X | elitemedia | elitemediapop.exe | "Added by the LOWZONE-BB TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware"
|
| U | ELSA WINman Suite | Winmsuit.exe | "Allows you to totally customize your ELSA graphics card settings |
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| U | ELSBLaunch | ELSBLaunch.exe | "EarthLink SpamBlocker"
|
| N | EMA.exe | EMA.EXE | Time management system which helps you to manage your time and appointments
|
| U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| Y | EmailScan | mcvsescn.exe | Related to McAfee AntiVirus suite - used to automatically scan incoming e-mails
|
| X | eMakeSV | EMAKESV.EXE | """Switch"" adult content dialer"
|
| X | eMakeSV | EMAKE2B.EXE | """Switch"" adult content dialer"
|
| U | EMBASSY Trust Suite Secure Update | AutoUpdate.exe | "Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| ? | Empowering Technology Launcher | eAPLauncher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| ? | EmpoweringTechnology | Framework.Launcher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| Y | Emsisoft Anti-Malware | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
| N | eMuleAutoStart | emule.exe | "eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project |
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| X | enBrowser | [name of file] | "WINBO adware"
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| N | Encoder Agent | WMENCAGT.EXE | "MS Windows Media Encoder |
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| ? | ENCSurf | surfboard.exe | "??"
|
| N | Energizer FileSaver | Energizer FileSaver.exe | "Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
|
| X | enhance32 | enhance32.exe | "Added by the CRYPTER.A TROJAN!"
|
| N | EnigmaPopupStop | EnigmaPopupStop.exe | "Part of Enigma SpyHunter - not recommended |
| ? | ENSApServer2_0 | APSERVER.EXE | "Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
|
| U | EnsoniqMixer | starter.exe | "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
|
| U | Enterprise Harmony | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| U | Enterprise Harmony '99 | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | Enterra Icon Keeper | IcnKeepr.exe | "Icon Keeper - ""tool to save and restore icon positions on the desktop"""
|
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| U | EOUApp | EOUWiz.exe | Intel ProSET Wireless related - provides additional configuration options for these devices
|
| U | ePowerManagement | ePM.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| X | Epsilon Squared | vmmreg32.exe | "Added by the AGENT.MVC TROJAN!"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| U | EPSON Status Monitor 3 | E_[various].EXE | "Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus D68 Series | E_FATIAAE.EXE | "Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status |
| U | EPSON Stylus D78 Series | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
| U | EPSON Stylus D88 Series | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4000 Series | E_FATIBEE.EXE | "Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4800 Series | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX5000 Series | E_FATIBVE.EXE | "Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX6000 Series | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7000F Series | E_FATIBKE.EXE | "Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 1400 Series | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R1800 | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R240 Series | E_FATIAHE.EXE | "Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R260 Series | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R320 Series | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R340 Series | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R380 Series | E_FATIBOA.EXE | "Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R800 | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX530 Series | E_FATIAGP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX640 Series | E_FATIAME.EXE | "Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX700 Series | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
| U | EPSON Stylus SX200 Series | E_FATIEFE.EXE | "Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status |
| U | EPSON SX100 Series | E_FATIEDE.EXE | "Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status |
| U | EPSON TX100 Series | E_FATIEDP.EXE | "Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this
|
| X | EQAdvice | EQAdvice.exe | "NewAds1 adware"
|
| X | EQArticle | EQArticle.exe | "EQArticle adware"
|
| X | eraseplg | eraseplg.exe | "Added by the GENOME.AQUV TROJAN!"
|
| U | Eraser | eraser.exe | "Eraser - ""an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns"". This entry starts the Scheduler with Windows and provides a System Tray icon for on-demand access. Located in %ProgramFiles%\Eraser"
|
| U | eraser | eraser.exe | "Part of Evidence Exterminator |
| U | eraser.exe | eraser.exe | "Part of Evidence Exterminator |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | Eroca | Eroca.exe | "Insider.i adware"
|
| X | ErrClean | SysRep.exe | "ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
| X | ErreurChasseur | SysRep.exe | "ErreurChasseur |
| X | Error Safe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | Error Safe Free | uers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorGuard | ErrorGuard.exe | "ErrorGuard rogue spyware remover - not recommended |
| X | errorhandler | errorhandler.exe | "ErrorHandler adware"
|
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| X | ErrorRepairTool | ErrorRepairTool.exe | "ErrorRepairTool rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafeFree | UERS.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ERS | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_Check | uwasers.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| U | ERUNT AutoBackup | AUTOBACK.EXE | "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots |
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Scheduler | avkserv.exe | "MicroWorld eScan antivirus scheduler"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| X | Especial | Deneca.bat | "Added by the DELUZ VIRUS!"
|
| ? | ESS Daemon | Essd.exe | "Related to an ESS based soundacard. Is it required?"
|
| ? | essapm | essapm.exe | "ESS Solo soundcard driver. Is it required?"
|
| X | etbrun | elit***32.exe [* = random char] | "EliteBar adware"
|
| U | eTCertManger | eTCrtMng.exe | "eToken Certificate Manager from Aladdin Knowledge Systems |
| U | ETDWare | ETDCtrl.exe | Elantech smart-pad touchpad driver for the Asus Eee PC range
|
| N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
|
| X | ethernet | airftp.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Etraffic | JavaRun.exe | "TopMoxie adware"
|
| Y | eTrust EZ Firewall | efpeadm.exe | "eTrust EZ Firewall"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| X | eTrust Realtime Monitor | realmon.exe | "Added by the LAZAR.B TROJAN!"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| U | Eudora | Eudora.exe | "Eudora from Qualcomm allows you to receive and send Internet e-mails"
|
| N | Event Planner Reminders | PLNRNote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| X | EventApplicationCmd | smschk.exe | "Added by the IRCBOT-AO TROJAN!"
|
| U | EVGAPrecision | EVGAPrecision.exe | "EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible |
| U | Evidence Cleaner | ecleaner.exe | "Evidence Cleaner cleans up tracks left by your PC and Internet activities"
|
| N | Evidence Eliminator | ee.exe | "Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| U | EVOLOSTA | EVOLOSTA.EXE | "Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID |
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| U | EW Message Server | msg32.exe | Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
|
| N | eWare Startup | iWareStart.exe | "eWare iWare task bar. Not required"
|
| Y | ewido anti-spyware | ewido.exe | "System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
| X | Ewth | tasn.exe | "PurityScan adware"
|
| X | ewupdater | ewupdater.exe | "EasyWebSearch adware updater"
|
| X | example | [random filename].exe | "Added by the NUCLEAR BACKDOOR! Note - this trojan file is located in %Windir%\NR"
|
| N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| N | ExciteAssistantEXE | ASSISTANT.EXE | "With Excite Assistant |
| X | ExeName32 | Warm.scr | "Added by the SCOLD WORM!"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| U | Exif Launcher | Exiflaquickdcr.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| U | Exif Launcher | QuickDCF.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| X | Expatch | [random filename] | "Added by the PWSLMIR-G TROJAN!"
|
| X | expcrt | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | ExpertAntivirus | ExpertAntivirus.exe | "ExpertAntivirus rogue security software - not recommended |
| X | expler | Updadv.exe | "Added by the QQPASS-N TROJAN!"
|
| X | explore manager | explore.exe | "Added by the DONBOMB.A TROJAN!"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | [path to worm] | "Added by the AUTEX WORM!"
|
| X | explorer | [path to trojan] | "Added by the AGENT-EU TROJAN!"
|
| X | explorer | Yinstall.exe | "PurityScan/Clickspring adware"
|
| X | Explorer | explorar.vbs | "Added by the DESKTO-A WORM!"
|
| X | Explorer | TXP1atform.exe | "Added by the FUJACKS.CA VIRUS!"
|
| X | Explorer | msrstart.exe | "Added by the SOPICLICK TROJAN!"
|
| X | explorer | main.vbe | "Added by the SHUSH-A WORM!"
|
| X | Explorer 2238 | [path to trojan] | "Added by the AGENT-CPI TROJAN!"
|
| X | Explorer Loader | explr32.exe | "Added by the AGOBOT.N WORM!"
|
| X | Explorer Loader | explorerl.exe | "Added by the SDBOT-ADI WORM!"
|
| X | Explorer Updater | IEXPLORE.exe | "Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | ExplorerTask | explorer.exe | "Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| X | Extra Antivirus | ExtraAV.exe | "Extra Antivirus rogue security software - not recommended |
| U | ExtraDNS | ExtraDNS.exe | "ExtraDNS - DNS configuration tool"
|
| N | ExtraFilmHemmaAgent | Agent.exe | "ExtraFilm Photo Assistant"
|
| ? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software
|
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| Y | EZ Firewall | ca.exe | "eTrust EZ Armor Internet Security"
|
| N | ezagent | ezagent.exe | "EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
|
| U | EZEJMNAP | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | EZEJTRAY | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
|
| X | ezula | eZmmod.exe | "eZula TopText adware"
|
| X | eZulaMain | eZulaMain.exe | "eZula TopText adware"
|
| X | eZuluMain | eZuluMain.exe | Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
|
| U | E_S[numbers] | [path] E_[various].EXE [path] E_S[numbers].tmp | "Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| X | f | ftkclean.exe | "FlashEnhancer adware"
|
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Manager | FSM32.EXE | "F-Secure antivirus - carry out scheduled virus scans automatically"
|
| Y | F-Secure Startup Wizard | FSSW.EXE | "F-Secure antivirus"
|
| U | f1Tray.exe | F1TRAY.EXE | "System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
|
| X | f2install.exe | f2install.exe | "Added by the IEFEAT-I TROJAN!"
|
| X | f94mggfhfghodftdf | [path to trojan] | "Added by the SMALL.JHZ TROJAN!"
|
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | "Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink |
| X | FaltCheck | allps.exe | "Added by the AGENT.RAP TROJAN!"
|
| U | FamilyKeyLogger | cisvc.exe | "Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| ? | fapmon | fapmon.exe | "Fair Access Policy monitor for DirecPC/DirecWay internet access"
|
| X | farkrish | farkrish.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | farmmext | farmmext.exe | "VX2.Transponder parasite updater/installer related"
|
| X | Fash | Fash.exe | Unidentified adware
|
| X | faslkakj11 | kjgagklj11.exe | "Added by the LEGMIE-ARE TROJAN!"
|
| N | fast | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | fast | A-fast.exe | "A-fast Antivirus rogue security software - not recommended |
| X | Fast Antivirus 2009 | FastAV.exe | "Fast Antivirus rogue security software - not recommended |
| N | FAST Defrag | FAST2.EXE | "FastDefrag defragmenting software"
|
| X | Fast Home | svcnvt.exe | "Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines |
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | Ntut.exe | "Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
|
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| U | FastCache | fc.exe | "FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | fastsmell | fastsmell.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | FastStart | ntnut32.exe | "Added by the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| N | FastTrack Accelerator | SPEED UP.EXE | "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop |
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| U | FastTVSync | FastTVSync.exe | "Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps |
| N | FastUser | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| N | FastUsr | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | faT | faT.exe | "Added by the BANKER-DFP TROJAN!"
|
| X | fat.exe | fat.exe | "Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended |
| X | Fat32 Microsoft | fat32.exe | "Added by the RBOT-EL WORM!"
|
| U | FatPipe | DHCP | Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | Fatpipe Dialer | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | fatrecov | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
|
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSearch | SearchGuardPlus.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSSA | ie3sh.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FCMan | FCMan.exe | "FCHelp adware"
|
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | fddddHOME | dxxatp.exe | "Added by the RANKY.AA TROJAN!"
|
| X | Fdr Command Module | sp2.exe | "Added by the SDBOT.WP WORM!"
|
| U | FD_SAP | FD.exe | Reported to be the autopassword program from the Sony Microvault thumb drive
|
| U | feedreader.exe | feedreader.exe | """Feedreader is a freeware Windows application that reads and displays Internet newsfeeds aka ATOM and RSS feeds based on XML"""
|
| X | feelalright | mirc.exe | "Added by the IRCFLOOD-M WORM!"
|
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| U | FerrariWallPaper | FerrariWP.exe | Calendar that replaces the default desktop background image. It comes with every Acer Ferrari 3000 laptop. Also downloadable for members of www.ferrari.com
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| X | ff | [path to worm] | "Added by the RBOT-XL WORM!"
|
| X | ffeqOME | vcvsav.exe | "Added by the RANKY.AB TROJAN!"
|
| X | ffis | ffisearch.exe | "iSearch adware"
|
| U | FG1_00 | frntgate.exe | "FrontGate MX - e-mail spam blocker"
|
| ? | fgl23DoubleScreenHooks | f23happ.exe | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | FHPage | shdochp.exe | "Added by the WINHOUND TROJAN!"
|
| X | FHStart | shdocsvc.exe | "Added by the WINHOUND TROJAN!"
|
| X | Fhzepgyi | HELLRAIDER.EXE | "Added by the MINDCTRL.A BACKDOOR!"
|
| X | FILE | abcdefg.exe | "Added by the KELVIR.DD WORM!"
|
| X | file laoder configuration | rnd32.exe | "Added by the RBOT.BQJ WORM!"
|
| X | File Mapping Services | hp-1003.exe | "Added by the RBOT.FAN WORM!"
|
| X | File System | taskmqrs.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | File System | taskmqr.exe | "Added by the RBOT.BWQ WORM!"
|
| X | File-Sharing Wizard | shwizard.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | File1 | Dia Claro.htm | "Added by the DLOADER-OR TROJAN!"
|
| N | filehippo.com | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | FileHippo.com Update Checker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | filename | filename.exe | "Added by the VB.FSY TROJAN!"
|
| X | filename process | kerneldll.exe | "Added by the AGOBOT-PO WORM!"
|
| X | filename process | explore.exe | "Added by the AGOBOT-QN WORM!"
|
| X | filename process | Rundil16.exe | "Added by the GAOBOT.ZX WORM!"
|
| X | FileSoft | Wscript.exe UpdataFiles.vbs | "Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
|
| U | FilterGate | filtergate.exe | "Filtergate internet filtering software - filters sounds |
| U | Filterguard | Filtrgrd.exe | "An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian |
| X | FilterProgram | GDC.exe | "FilterProgram rogue privacy tool - not recommended |
| N | Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
|
| Y | Find Virus Launch Program | fvlaunch.exe | "Part of Dr. Solomon's Antivirus"
|
| X | findfast | findfast.exe | "Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
|
| X | findfast.exe | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
|
| X | FindHack | [path to worm] | "Added by the KELVIR-BA WORM!"
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | "ABBYY FineReader OCR software - version 7"
|
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
|
| X | Fire Wall services | [random filename] | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Wall services | wnlmzsfhobi.exe | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Well service | [random].exe | "Added by the RBOT-FJU WORM!"
|
| ? | FireBox Control Panel | FireBox.exe | "Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
|
| X | FireExplore Update | FireExplore.exe | "Added by a variant of the RBOT WORM!"
|
| X | Firefox Plugin Manager | firefoxpgm.exe | Added by the MSNPHOTO.E WORM!
|
| U | Firefox Preloader | FirefoxPreloader.exe | "Firefox Preloader - ""a utility that is designed to load parts of Mozilla Firefox into memory before it is used to improve the its startup time"". Even on fast machines Firefox can take a while to load"
|
| X | FireFox Startup Drivers | wuaclt.exe | "Added by the RBOT.BYX WORM!"
|
| X | FiresWallservices | [random].exe | "Added by the RBOT-FJT WORM!"
|
| X | Firevall Administrating | rndll.exe | "Added by the PUSHBOT-B WORM!"
|
| X | firewal | firewal.exe | "Added by the BANCBAN-QY TROJAN!"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.D WORM!"
|
| X | Firewall | SP2 UPDATE.exe | "Added by the ELITPER.E WORM!"
|
| X | Firewall | Firewall.bat | "Added by the YPSAN.G WORM!"
|
| X | firewall | fw_304.exe | "Added by the BDOOR-JQ BACKDOOR!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | firewall | spoolsv.exe | "Added by the DIZAN.F VIRUS!"
|
| X | firewall | firewall.exe | "Added by the SURO-A TROJAN!"
|
| X | firewall 2008 | logoneui.exe | "Added by the SILLYFDC WORM!"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Firewall auto setup | [path to trojan] | "Added by the AGENT-GLY TROJAN!"
|
| X | Firewall config | ReadMe.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Policy | MidiDef32.exe | "Added by the PIEBOT-A TROJAN!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | Firewall Update System1 | WinedowsUpdater1.exe | "Added by the RBOT-ARU WORM!"
|
| X | Firewall Updater | msnupdateit.exe | "Added by the RBOT-AAQ WORM!"
|
| X | Firewall.exe | Firewall.exe | "Added by the AGENT.AGL BACKDOOR! Located in %System%"
|
| Y | FireWall.exe | FireWall.exe | "Ashampoo® Firewall PRO and Ashampoo® Firewall FREE from Ashampoo GmbH & Co. KG. Located in an Ashampoo related sub-directory of %ProgramFiles%"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| Y | FirewallGUI | FirewallGUI.exe | "System Tray access to PC Tools Firewall Plus from PC Tools - which ""is a powerful personal firewall for Windows that protects your computer from intruders and controls the network traffic in and out of your PC"""
|
| U | FirewallStartup | Firewallstartup.exe | "Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean |
| X | FirewallSvr | FirewallSvr.exe | "Added by the NETSKY.X or NETSKY.Y WORMS!"
|
| X | firewall_anti | firewall_anti.exe | "Added by the NETDENY-B TROJAN!"
|
| X | FireWire Driver | samx.exe | "Added by the SDBOT.AE WORM!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| Y | Fix-it | mxtask.exe | "Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard |
| Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
|
| X | fjdslssdfd | mat2.exe | "Added by the SLAPEW.C TROJAN!"
|
| U | FJTWAIN Setup | FjtwSetup.exe | Fujitsu scanner utility
|
| X | FlaCPY | flacpy.exe | "FlashEnhancer adware"
|
| X | Flash Driver | [path to trojan] | "Added by the AGENT.CWVT TROJAN!"
|
| X | Flash Media | %%%%%.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | %%%.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | [path to trojan] | "Added by the IRCBOT.AUR TROJAN!"
|
| X | Flash Media | ^ ^^^ %% % ^% ^%%^ %^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^^^^^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | ^^^^^^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | services.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Flash Media | zrpk��'�'%''msn'�%'fix''.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | % ^% ^^^ %^% %% ^ ^ %%% ^% %^ % %^^.exe | "Added by a variant of the IRCBOT BACKDOOR! Note the space at the beginning of the filename"
|
| X | Flash Media | ^%%^%%%^% %^ ^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %^^%^^% %^^^^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^%^^^%% ^ ^ %^^^^^ %^ ^%^^ ^%^^^^^ %^ ^^^%^%%.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %^% ^ %^%% ^ % ^%%^^ %^^%^%^ ^%% %^.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %%%%%%^^ ^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | skxs��'�'%''msn'�%'fix''.exe | "Added by the AGENT.ZOY TROJAN!"
|
| X | Flash Media | ^ %%^%^%.exe | "Added by the FLUSH.A TROJAN! Note the space at the beginning of the filename"
|
| X | Flash Media | %% % ^^ % %% ^%^^ ^^^ % ^%% ^ ^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note the space at the beginning of the filename"
|
| X | Flash Media | ^ ^ % ^ % % ^ ^ ^%% ^% %%^^.exe | "Added by the IRCBOT.BAW BACKDOOR!"
|
| X | Flash Player2 | [path to worm] | "Added by the IRCBOT.PD WORM!"
|
| ? | FLASH32 | #NAME? | "??"
|
| X | Flash32 | FLASH32.COM | "Added by the STARTER-F TROJAN!"
|
| U | FlashEnc | FlashEnc.exe | "Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission |
| N | Flashget | FlashGet.exe | "FlashGet download manager"
|
| X | Flashget Download Manager | Flashget.exe | "Added by the RBOT-AGZ WORM!"
|
| X | FlashGuard | FlashGuard.exe | "Added by the AUTOIT.AL WORM!"
|
| U | FlashMute | FlashMute.exe | """FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively |
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| X | Flashy Bot | Flashy.exe | "Added by the GLUPZY.A WORM!"
|
| X | Flash_Player_Install | ying.exe | "Constructor VC2000 malware"
|
| U | FLMBROWSERMOUSE | mouse32A.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMK08KB | KbdAp32A.exe | Keyboard utility for a Medion brand (and possibly others) keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | FLMLABTECMOUSE | mouse32A.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMMEDIONMOUSE | mouse32a.exe | Mouse utility for a Medion branded Fellowes mouse
|
| U | FLMOFFICE4DMOUSE | mouse32a.exe | Mouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | Floppy Master | [path to trojan] | "Added by the ZONIT-F TROJAN!"
|
| X | FlyswatDesktop | flydesk.exe | Advertising spyware
|
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
|
| X | fmnwebassist | fmnwebassist.exe | Adware popup generator
|
| U | FMStart | Fmstart.exe | "GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks |
| X | fnmwebassist | fnmwebassist.exe | "WinPL adware"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252