| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop Maestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| X | Desktop Search | desktop.exe | "iSearch adware"
|
| X | Desktop Security 2010 | Desktop Security 2010.exe | "Desktop Security 2010 rogue security software - not recommended |
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| U | DesktopIconToy | DesktopIconToy.exe | """Desktop Icon Toy is an easy to use desktop icon enhancement tool |
| U | DesktopMaestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | detect | idetect.exe | "iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled"
|
| ? | detect | turbodetect.exe | "??"
|
| N | Detector | detector.exe | "USB port detector for LG scanners. Sits in the System Tray |
| U | DetectorApp | DetectorApp.exe | "Related to Roxio MyDVD (was Sonic) DVD authoring software"
|
| X | Deus Cleaner | DCleaner.exe | "Deus Cleaner rogue system cleaner utility - not recommended"
|
| ? | DevconDefaultDB | READREG | "Appears to be related to older Creative Soundblaster soundcards"
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| U | Device Detector | DevDetect.exe | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
| N | Device Detector 2 | DevDtct2.exe | "Installed by various Olympus products |
| X | Device Hardware | devicehnd.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device IO System | deviceio.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Management | wnsystem.exe | "Added by the AGOBOT-LH WORM!"
|
| X | Device Manager | wfxmgr.exe | "Added by the RBOT.AJU WORM!"
|
| X | Device Security | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Driver | devicesec.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| U | DeviceDiscovery | hpotdd01.exe | "Detection of new imaging |
| X | DevicePath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | DevicePath | Root.exe | "Added by the GRUEL WORM!"
|
| U | Devices | olesvr.exe | "Salfeld Child Control - parental control software"
|
| X | Devicewin | [path to trojan] | "Added by the BANKER-AEV TROJAN!"
|
| X | DHCP | smss.exe | "Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
|
| X | DHCP Server | regsvr.exe | "Added by the RBOT-PR WORM!"
|
| X | DHCP32 | services.exe | "Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
|
| Y | dhcpagnt | dhcpagnt.exe | Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
|
| X | DhcpCep | PYJJKIME.exe | "Added by the AGENT-BXQ TROJAN!"
|
| X | Diagnostic | diagnostic.exe | "Added by the ALPHA-C TROJAN!"
|
| X | Diagnostic Agent | diagent.exe | "Added by the AGOBOT-CW WORM!"
|
| X | Dialer | "rundll32.exe MSA32CHK.dll | Reg" |
| U | Dialer Control | dc.exe | "Dialer-Control. Detects and protects from premium rate adult content diallers"
|
| U | Dialer Detect | dd.exe | "DialerDetect detects stealth installed premium rate diallers |
| X | DialUp Network Application | Rnaap.exe | "Added by a variant of the SDBOT WORM!"
|
| U | Diamondback | razerhid.exe | "Razer Diamondback 3G gaming mouse driver - required if you use the additional features and programmed keys/macros"
|
| X | DIECOX | csrss.exe | "Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Diesel | Recalculate.exe | "Added by the LAZAR TROJAN!"
|
| U | DigiCell | DigiCell.exe | "MSI DigiCell - ""the most useful and powerful utility that MSI has spent much research and efforts to develop |
| N | DigiGuide | CLIENT.EXE | TV guide and reminder
|
| N | DigiGuide | client01.exe | TV guide and reminder
|
| N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
|
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| U | DIGServices | DIGServices | Created by Disney but licensed to ESPN for watching videos
|
| N | DIGServices | DIGServices.exe | Created by Disney but licensed to ESPN for watching videos
|
| X | Diomacd | fdafbfd.exe | "Added by the MULDROP.F TROJAN!"
|
| X | Dir1 | caKe | "Added by the CAKE WORM!"
|
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | Direct X Direct3D | dxd3d.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Direct X Opengl | dxopengl.exe | "Added by a variant of the RBOT-CJ WORM!"
|
| X | direct3d.exe | direct3d.exe | "Added by the CERTIF-F TROJAN!"
|
| N | DirectCD | DirectCD.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
|
| X | Director Video | btnmgern.exe | "Added by the MYTOB-KL WORM!"
|
| Y | Directory Opus Desktop Dblclk | dopusrt.exe | "Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor |
| X | directs.exe | directs.exe | "Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | DirectX | ddhelp32.exe | "Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
|
| X | directx | Directx.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | Sqlexploit.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX | DirectX.exe | "Added by the BLAXE or LOGPOLE WORMS!"
|
| X | directx | NTCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | PipeCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX 32 | directx32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | DirectX Driver | stdhost.exe | "Added by the SDBOT.GVJ BACKDOOR!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX Video Driver | dxterm5.exe | "Added by the WILAB-A TROJAN!"
|
| X | DirectX64 | DirectXset.exe | "Added by the BROWNEY.A WORM!"
|
| X | DirectX9 | direct3d.exe | "Added by the AGENT.EAK TROJAN!"
|
| X | DirectX9 | svchost32.exe | "Added by the RBOT.AQG WORM!"
|
| X | DirectX9 Diag | dx9diag.exe | "Added by the RBOT-ALT WORM!"
|
| X | DirecX | DirecX.exe | "Added by the AGOBOT-HU BACKDOOR!"
|
| X | DirLocker | dirlock.exe | "Added by the AUTORUN-AMS WORM!"
|
| ? | Disable EHCI | nousb20.exe | "??"
|
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| ? | discoveg | discoveg.exe | "??"
|
| ? | DISCover | DISCover.exe | "Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
|
| N | DiscoverDeskshop | Deskshop.exe | "Discover Deskshop - single use ""virtual"" credit card"
|
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| X | Disk Check | chkdsk32.exe | "Added by the IM TROJAN!"
|
| U | Disk Cleaner | DiskCleaner.Exe | "Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Essensial Tools | detsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | SECURITY.EXE | "Daosearch adware"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | Disk Panel Setup | npcsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| X | Diskstart | Code.exe | Adult content dialler
|
| X | Diskstart | cat.exe | MS-Connect dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| X | Dispatcher | dispatcher.exe | "Added by the DLOADR-AS TROJAN!"
|
| X | Display | backup.exe | "Added by the BRONTOK-CR WORM!"
|
| X | Display Drivers | cssrs.exe | "Added by the AGOBOT.FX WORM!"
|
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| X | Dist-FBGeneve | GDC.exe | "NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| X | Distributed File System | Dfsvc.exe | "Added by the MYFIP.A or MYFIP.K WORMS!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| U | distributed.net client | DNETC.EXE | "Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
|
| X | divx | divxenc.exe | "Added by the SPBOT.B TROJAN!"
|
| X | Divx | codll.exe | "Added by the GRAVEBOT-A TROJAN!"
|
| X | Divx4 codec | devldr32.exe | "Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file"
|
| X | DivXCodec | NEWMAIL.exe | "Added by the DELF-RQ BACKDOOR!"
|
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | DJRegFix | regedit /s c:hpdjregfix.reg | "DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
|
| ? | DJSNetCN | DJSNetCN.exe | """Symantec Licensing Detect Internet Connection"" |
| Y | DkService | DkService.exe | "From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled |
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLA | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW.EXE | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| N | dlbcserv | dlbcserv.exe | Related to Dell Photo Printers and provides additional configuration options for these devices
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| U | dlccmon.exe | dlccmon.exe | Dell Photo AIO Printer 924 device monitor
|
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| U | dlcdmon.exe | dlcdmon.exe | Dell Photo AIO Printer 944 device monitor
|
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| U | dlcgmon.exe | dlcgmon.exe | Dell Photo AIO Printer 810 device monitor
|
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| X | dlcipscl | dcpavss.exe | "Added by the MAILBOT-CB TROJAN!"
|
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| U | dlcjmon.exe | dlcjmon.exe | Dell Photo AIO Printer 964 device monitor
|
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| U | dlcqmon.exe | dlcqmon.exe | Dell Photo AIO Printer 966 device monitor
|
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| U | dlcxmon.exe | dlcxmon.exe | Dell Photo AIO Printer 926 device monitor
|
| X | DlDir1 | caKe | "Added by the CAKE WORM!"
|
| ? | DLForcerExe | DLForcerEXE.exe | "??"
|
| N | DLF_00000B00 | Vcdlf.exe | "Known to cause problems with "Out of memory" errors (see here). Otherwise |
| N | DLG | DLGCHBW.exe | Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
|
| N | DLHelperEXE | WATCH.exe | Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
|
| X | Dll Link | svchoist.exe | "Added by the AUTOSKY WORM!"
|
| X | Dll Link | svchost.exe | "Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | dll services | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | dllcache.exe | dllcache.exe | "Added by the VISPAT.A WORM!"
|
| X | DllCacherv2 | dllcachev2.exe | "Added by the LATEDA TROJAN!"
|
| X | dllcvss | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | DllExecutable | [path to file] | "Added by the VB-SP WORM!"
|
| X | DLLService32 | dllsvc32.exe | "Added by the AGOBOT.VX WORM!"
|
| Y | DLO Agent | DLOClientu.exe | "Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
|
| X | dluca | dluca.exe | "Added by the DLUCA.C TROJAN!"
|
| X | dm***.exe [* = random char] | dm***.exe [* = random char] | "Wareout - malware masquerading as a spyware and dialer remover"
|
| N | DMAScheduler | DMAScheduler.exe | "Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program |
| X | DMC | dmc.exe | Added by Trojan-Downloader.Win32.Dluca.bv TROJAN!
|
| X | Dmsvc32 | Dmsvc32.exe | "Added by the AGOBOT.ABU WORM!"
|
| U | DmwClient | dmwclient.exe | "DMW ""anti-cheating"" software for online gaming"
|
| U | DMXLauncher | DMXLauncher.exe | "Part of Dell's Media Experience |
| X | dm_service | [path to file] | "Added by the MITGLIEDER.P TROJAN!"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| X | DNS | mc-58-12-0000080.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000093.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-110-12-0000079.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000120.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000140.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS Config service | win32.exe | "Added by the RBOT-TL WORM!"
|
| X | DNS Service | dnsresolver.exe | "Added by the RBOT-PQ WORM!"
|
| X | DNS Service | dnssvc.exe | "Added by the DELBOT-Z WORM!"
|
| ? | DNS2GoClient | dns2goclient.exe | "DNS2Go is a Domain Name System that will make your computer accessible anytime |
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | DNSCacheBoost | dnsping.exe | "Added by the DNSBUST-A TROJAN!"
|
| X | dnscleaner | dnscleaner.exe | "CoolWebSearch parasite variant"
|
| ? | DNXVC | dnxvc.exe | "??"
|
| X | doc | doc.exe | "Added by the AGOBOT-BJ WORM!"
|
| X | DocTor | Doctor.exe | "Added by the DOTOR.A WORM!"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| N | DocuMagix Init | PWATCH.EXE | "PaperMaster is an application for the PC designed to automate the process of organizing |
| U | Document Manager | docmgr.exe | "Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
|
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| X | DomPlayer Service | wakeservice.exe | "DomPlayer adware"
|
| U | Don't Panic | dontpanicdemodp.exe | "30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| U | Don't Panic! | DP.EXE | "Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| X | Dot1XCfg | Dot1XCfg.exe | "Added by the AGOBOT.EA TROJAN!"
|
| N | Download Accelerator Manager Free Edition | dam.exe | "Download Accelerator Manager Free Edition from Tensons Corp"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| N | DownloadAccelerator | DAP.EXE | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | DownloadLegalMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| Y | Dpcnav | dpcnav.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| N | DPConfig | DPConfig.exe | "Compuware DevPartner Studio Configuration Utility |
| X | dpcproxy | dpcproxy.exe | "Added by the GOLDENP-A TROJAN!"
|
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | Dpcstart | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| N | dptracker | dptracker.exe | "CamTrack webcam software that enhances the way people video chat"
|
| X | dpzProtect | n.vbe | "Added by the RUNAUTO.H WORM!"
|
| X | DR service | [path to worm] | "Added by the RBOT-CZT WORM!"
|
| N | Drag'n'Drop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| N | DragnDrop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| X | DRam prosessor | plscd.exe | "Added by the RBOT.CYA WORM!"
|
| X | DRam rar proc | winupdaterar.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DRam rare proc | updaterarwin.exe | "Added by the RBOT-GQW WORM!"
|
| X | DrCache | MSTDC.EXE | "Added by the BDOOR-JM BACKDOOR!"
|
| N | DrgToDsc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| X | DriveCleaner 2006 Free | UDC2006.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveCleaner Free | UDC.exe | "DriveCleaner rogue security software - not recommended |
| X | DriveDefender | GDC.exe | "DriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| U | DriveIcons | DriveIcon.exe | "Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
|
| X | Driver32 | Scam32.exe | "Added by the SIRCAM WORM!"
|
| X | DriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | DriverConf | dvrconf.exe | "Added by the AGOBOT-IY WORM!"
|
| X | DriverDB | svcmdx32.exe | "Added by the BERPI TROJAN!"
|
| X | DriverLoad | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| U | DriverMagicLogon | dmschedule.exe | "Part of DriverMagic - ""the easiest way to locate device drivers"""
|
| N | DriverMax | devices.exe | "DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
|
| X | DriverModule | csrnvrt.exe | "Added by the IRCBOT.I TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| N | DriveSelect | driveselect.exe | "DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
|
| X | drocher | d.exe | Adult content dialler
|
| X | DrProtection | DrProtection.exe | "DrProtection rogue security software - not recommended"
|
| U | DrvIcon | DrvIcon.exe | """Vista Drive Icon changes the drive icons shown in Windows ""My Computer"" |
| Y | Drwebscheduler | Drwebscd.exe | "DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications |
| U | DS Clock | dsclock.exe | "Digital desktop clock including synchronization with atomic servers - see here"
|
| X | dS35DLL | ffqca.exe | "Added by the SDBOT-KV WORM!"
|
| X | DSAcass | [path to file] | "Added by the RANKY.M TROJAN!"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | dsgb | lcsass.exe | "Added by the AGENT.TGZ BACKDOOR!"
|
| X | Dskcompat | Dskcompat.exe | "Added by the GEMA TROJAN!"
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | DSService | dmrss.exe | "Added by the AGOBOT-XX WORM!"
|
| X | dstiosys | plsitctl.exe | "Added by the MAILBOT-BX TROJAN!"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| X | duck | duck.exe | "Added by the AGOBOT-AVG WORM!"
|
| X | Dumeter Services | dumeter.exe | "Added by the SDBOT-AEQ WORM!"
|
| X | dumprep | spoolc.exe | "Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
|
| X | DUN_SERVICES3 | dun3.exe | "Added by the SOKIRON TROJAN!"
|
| X | Duweculey | yujixit.exe | "Added by the SDBOT.BRP WORM!"
|
| X | Duwee wong Cerbon | Cirebons.exe | "Added by the BHARAT.A WORM!"
|
| X | DVAScvssdfa | AsSDdwd.exe | "Added by the LIOTEN.IP TROJAN!"
|
| U | DVD Device Lock for Win95/98/Me/2k/XP | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| N | DVD@ccess | DVDAccess.exe | "Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
|
| ? | DVDCheck | DVDCheck.exe | "Related to an Intervideo program. What does it do and is it required in startup?"
|
| X | Dvdcompat | Dvdcompat.exe | "Added by the GEMA TROJAN!"
|
| N | DVDLauncher | DVDLauncher.exe | "Part of Cyberlink's Power Cinema - allows you to play DVDs upon insertion"
|
| U | dvHighMem | cfgmng32.exe | "Related to PureSight PC - designed to offer maximum flexibility and choice as families manage their internet use"
|
| U | DVSync | dvsync.exe | DVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
|
| X | Dvx | wsxsvc.exe | "Delfin Media Viewer or ""Promulgate"" adware variant"
|
| N | DwlClient | support.exe | Download manager for Dell support alerts
|
| X | Dx8compat | Dx8compat.exe | "Added by the GEMA TROJAN!"
|
| N | DXM6Patch_981116 | p_981116.exe | "Win32 cabinet self extractor. More info here"
|
| X | DyFuCA | optimize.exe | "Adult content dialler - see here"
|
| X | DyFuCA Active Alert | actalert.exe | "Adult content dialler - see here"
|
| X | Dynamic DHCP | dydhcp.exe | "Added by the RINBOT.B TROJAN!"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| X | Dynamic Dns Binary | CMD16.EXE | "Added by the RBOT-XM WORM!"
|
| X | Dynamic Dns Binary | winxp34.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Dns Binary | WinHelpcfn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Link Library loader | Loader32.exe | "Added by the KOL TROJAN!"
|
| U | Dynu Basic Client | dynubas.exe | "Dynu online dynamic IP update client. Useful when using a dial up modem"
|
| X | E-Card | ecard.exe | "Added by the YODI WORM!"
|
| U | E-color | IconMgr.Exe | Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| U | E06DXLRD_7604703 | EDICT.EXE | "Related to Microsoft Encarta dictionary functions"
|
| N | EA Core | Core.exe | "Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches |
| U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
|
| X | Eac Download | download.exe | "Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here"
|
| U | EACLEAN | eaclean.exe | "For Compaq PC's. Easy Access button support for the keyboard"
|
| X | Eac_Cnry | canary.exe | "Added by the CANARY TROJAN!"
|
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| Y | EAFRCliStart | EAFRCliStart.exe | "Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
|
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| N | Eapcisetup | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it
|
| N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
|
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| N | Easy CD Creator | RoxAssist.exe | "Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize |
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader
|
| X | EasySpywareCleaner | EasySpywareCleaner.exe | "EasySpywareCleaner rogue spyware remover - not recommended |
| U | EasySync Pro | XCPCMenu.exe | """IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| U | EC21 | EZQ.EXE | "Related to EC21 ""the world's largest B2B marketplace to facilitate online trades between exporters and importers from all around the world"""
|
| U | ECenter | gtb.exe | Dell E-Center/Google Toolbar related
|
| N | ECenter | EULALauncher.exe | End User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
|
| X | ecko | claro.exe | "Added by the DLOADR-AQJ TROJAN!"
|
| ? | ecpe | ECPE.EXE | "??"
|
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| ? | EDFcsn | discfcsn.exe | "Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
|
| X | educational writer | [random filename] | "Added by the RBOT-LZ WORM!"
|
| X | EDxMC110 | Isass.exe | "Added by the VB-NIA WORM!"
|
| X | Eech | hoor.exe | "PurityScan adware"
|
| U | Eee Docking | Eee Docking.exe | "Intuitive shortcuts for easy access to digital content |
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | eFax 4.1 | J2GDllCmd.exe | "DLL Command Utility for version 4.1 of eFax Messenger from j2 Global Communications |
| U | eFax 4.2 | J2GDllCmd.exe | "DLL Command Utility for version 4.2 of eFax Messenger from j2 Global Communications |
| U | eFax 4.3 | J2GDllCmd.exe | "DLL Command Utility for version 4.3 of eFax Messenger from j2 Global Communications |
| U | eFax 4.4 | J2GDllCmd.exe | "DLL Command Utility for version 4.4 of eFax Messenger from j2 Global Communications |
| U | eFax DllCmd | J2GDllCmd.exe | "DLL Command Utility for eFax Messenger from j2 Global Communications |
| U | eFax DllCmd 3.5 | J2GDllCmd.exe | "DLL Command Utility for version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax DllCmd 4.0 | J2GDllCmd.exe | "DLL Command Utility for version 4.0 of eFax Messenger from j2 Global Communications |
| U | eFax Live Menu 3.3 | J2GDllCmd.exe | "DLL Command Utility for version 3.3 of eFax Messenger from j2 Global Communications |
| N | eFax.com Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| X | egikugu | napolecy.exe | "Added by the SDBOT.AOE WORM!"
|
| N | EgisTecLiveUpdate | EgisUpdate.exe | "Software updater for biometric and data encryption products from EgisTec Inc"
|
| X | ehSched | ehSched.exe | "Added by the SDBOT-DHF WORM!"
|
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| U | Eicon TechnologyLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eixfi | china.bat | "Added by the WCUP.A WORM!"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| U | Elbycheck | ElbyCheck.exe | "From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it"
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| X | EliteProtector | EliteProtector.exe | "EliteProtector rogue spyware remover - not recommended |
| ? | ElkCtrl | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| U | ELSBLaunch | ELSBLaunch.exe | "EarthLink SpamBlocker"
|
| U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| Y | EmailScan | mcvsescn.exe | Related to McAfee AntiVirus suite - used to automatically scan incoming e-mails
|
| U | EMBASSY Trust Suite Secure Update | AutoUpdate.exe | "Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| X | emoc0re | emo.exe | "Added by the AGOBOT-AGE WORM!"
|
| ? | Empowering Technology Launcher | eAPLauncher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| ? | EmpoweringTechnology | Framework.Launcher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| U | EM_EXEC | EM_EXEC.EXE | "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| N | ENCMONITOR | monitor.exe | The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
|
| N | Encoder Agent | WMENCAGT.EXE | "MS Windows Media Encoder |
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| ? | ENCSurf | surfboard.exe | "??"
|
| U | enginecs2 | enginecs2.exe | "Cyber Sentinel - internet filtering software"
|
| X | enhance32 | enhance32.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | Enterra Icon Keeper | IcnKeepr.exe | "Icon Keeper - ""tool to save and restore icon positions on the desktop"""
|
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| Y | EnvyHFCPL | EnMixCPL.exe | "VIA Envy24 PCI Audio Controller driver"
|
| U | EPGServiceTool | EPGClient.exe | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | EPGServiceTool | EPGCLI~1.EXE | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | ePower_DMC | ePower_DMC.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| N | ePrint 3.0 Service | EPRINT3.EXE | "LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF |
| N | ePrint 4.0 Service | EPRINT4.EXE | "A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF |
| N | EPS | e_srcv02.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| N | EPS | e_srcv03.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C40 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status |
| U | EPSON Stylus C41 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status |
| U | EPSON Stylus C42 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S08IC1.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C44 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | EPSON Stylus C45 Series | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
| U | EPSON Stylus C46 Series | E_S4I0T1.EXE | "Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status |
| U | EPSON Stylus C48 Series | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
| U | EPSON Stylus C60 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
| U | EPSON Stylus C61 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status |
| U | Epson Stylus C62 Series | E-S0BIC1.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C62 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C63 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C66 Series | E_S4I0S2.EXE | "Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | Epson Stylus C82 Series | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C82 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3100 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status |
| U | EPSON Stylus CX3200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5400 | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 2200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status |
| U | EPSON Stylus Photo 825 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status |
| U | EPSON Stylus Photo 925 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Pro 4000 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status |
| U | EPSON Stylus Pro 7600 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| X | EQAdvice | EQAdvice.exe | "NewAds1 adware"
|
| X | EQArticle | EQArticle.exe | "EQArticle adware"
|
| Y | eRecoveryService | check.exe | "Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | Monitor.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | Eroca | Eroca.exe | "Insider.i adware"
|
| X | ErrClean | SysRep.exe | "ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
| X | ErreurChasseur | SysRep.exe | "ErreurChasseur |
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| X | ERScw | ERScw.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_Check | uwasers.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| X | erthgdr | svc.exe | "Added by the BEAGLE.BN or BEAGLE.BP WORM!"
|
| X | erthgdr2 | svc23.exe | "Added by the BAGLE.CG WORM!"
|
| U | ERUNT AutoBackup | AUTOBACK.EXE | "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots |
| X | erwghjjrjt | ucbcg.exe | "Added by the SMALL.CUL TROJAN!"
|
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Scheduler | avkserv.exe | "MicroWorld eScan antivirus scheduler"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| X | EScorcher | escorcher.exe | "Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
|
| U | eSnips | ClientGW.exe | "eSnips Client Gateway from eSnips"
|
| X | Especial | Deneca.bat | "Added by the DELUZ VIRUS!"
|
| Y | Essdc | essdc.exe | Related to an ESS Solo soundcard. Seems as though it's required
|
| ? | eSupInit | eSupCmd.exe | "Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
|
| X | etbrun | elit***32.exe [* = random char] | "EliteBar adware"
|
| U | eTCertManger | eTCrtMng.exe | "eToken Certificate Manager from Aladdin Knowledge Systems |
| U | ETDWare | ETDCtrl.exe | Elantech smart-pad touchpad driver for the Asus Eee PC range
|
| X | eth0 driver | exec.exe | "Added by the SPYBOT-Z WORM!"
|
| N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Driver | cmsrrs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Etraffic | JavaRun.exe | "TopMoxie adware"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | EUP Service | eupsvc.exe | "Added by the DELBOT-Q WORM!"
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| X | EventApplicationCmd | smschk.exe | "Added by the IRCBOT-AO TROJAN!"
|
| ? | EverioService | EverioService.exe | "Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
|
| U | EVGAPrecision | EVGAPrecision.exe | "EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible |
| U | Evidence Cleaner | ecleaner.exe | "Evidence Cleaner cleans up tracks left by your PC and Internet activities"
|
| N | Evidence Eliminator | ee.exe | "Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| N | evntsvc | evntsc.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| N | ExciteAssistantEXE | ASSISTANT.EXE | "With Excite Assistant |
| X | execfg4 | execfg4.exe | "Added by the ELECTRON WORM!"
|
| X | ExecUser | ExecUser.exe | "Added by a variant of the RBOT WORM!"
|
| ? | Execute | delfolders.exe | "??"
|
| X | ExeName32 | Warm.scr | "Added by the SCOLD WORM!"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| U | Exif Launcher | Exiflaquickdcr.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| U | Exif Launcher | QuickDCF.exe | USB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
|
| X | Expatch | [random filename] | "Added by the PWSLMIR-G TROJAN!"
|
| X | expcrt | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | config_.com | "Added by the FLOPPY-D WORM!"
|
| X | EXPLORER MICROSOFT SYSTEM | explore.exe | "Added by a variant of the RBOT WORM!"
|
| X | Explorer soft | explorer.com | "Added by the RBOT-ARM WORM!"
|
| X | Explorer.exe | csrss.exe | "Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
|
| X | Explorer5 | config_.com | "Added by the VB.CBG WORM!"
|
| X | ExplorerRun | conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| U | Express ClickYes | ClickYes.exe | """Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt |
| N | Extender Resource Monitor | RMSysTry.exe | "Related to Windows Media Center from Microsoft"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| Y | EZ Firewall | ca.exe | "eTrust EZ Armor Internet Security"
|
| Y | ezShieldProtector for Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| U | E_S10IC2 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | E_S23 | E_SICN03.exe | "Epson printer status monitor - for checking ink levels |
| U | E_SOEIC1 | E_SOEIC1.exe | "Epson Status Monitor 3 - for monitoring printer status |
| X | f | ftkclean.exe | "FlashEnhancer adware"
|
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure 2005 | svchost.exe | "Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| Y | F-Secure 2006 | fspex.exe | "F-Secure Anti-Virus automatic updater"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Manager | FSM32.EXE | "F-Secure antivirus - carry out scheduled virus scans automatically"
|
| Y | F-Secure Startup Wizard | FSSW.EXE | "F-Secure antivirus"
|
| Y | F-Secure TNB | TNBUtil.exe | "F-Secure antivirus"
|
| U | F5D7050v3 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D7050 Wireless G USB Adapter"
|
| U | F5D8001 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8001 N1 Wireless Desktop Card"
|
| U | F5D8011 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8011 N1 Wireless Notebook Card"
|
| U | F5D8055v1 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8055 Wireless N+ USB Adapter"
|
| U | F5D8071 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D8071 N1 Wireless ExpressCard"
|
| U | F5D9010 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
|
| U | F5D9050 | Belkinwcui.exe | "Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
|
| X | f73cdc8ee94e | btsendto.exe | Associated with mysearchnow.com/searchbar.html
|
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | "Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink |
| X | FaltCheck | allps.exe | "Added by the AGENT.RAP TROJAN!"
|
| U | FamilyKeyLogger | cisvc.exe | "Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| X | Fast Home | svcnvt.exe | "Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines |
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| U | FastCache | fc.exe | "FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| N | FastTrack Accelerator | SPEED UP.EXE | "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop |
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| U | FastTVSync | FastTVSync.exe | "Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps |
| X | Fat32 Microsoft | fat32.exe | "Added by the RBOT-EL WORM!"
|
| U | FatPipe | DHCP | Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | fatrecov | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
|
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| U | FBDirect | FBDirect.exe | "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan |
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSearch | SearchGuardPlus.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | fc | runfc.exe | "Added by the CAMPURF WORM!"
|
| X | FCEngine | FCEngine.exe | "CASClient adware"
|
| X | FCHelp | FCHelp.exe | "Added by either FCHelp adware or a variant of it"
|
| X | FCMan | FCMan.exe | "FCHelp adware"
|
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | Fdr Command Module | sp2.exe | "Added by the SDBOT.WP WORM!"
|
| X | FeCPY | fecpy.exe | "FlashEnhancer adware"
|
| X | feelalright | mirc.exe | "Added by the IRCFLOOD-M WORM!"
|
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
|
| X | fegoze | SVCH0ST.EXE | "Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| X | ffeqOME | vcvsav.exe | "Added by the RANKY.AB TROJAN!"
|
| X | ffis | ffisearch.exe | "iSearch adware"
|
| ? | fgl23DoubleScreenHooks | f23happ.exe | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | FHPage | shdochp.exe | "Added by the WINHOUND TROJAN!"
|
| X | FHStart | shdocsvc.exe | "Added by the WINHOUND TROJAN!"
|
| U | FieldForms Sync | SyncService.exe | "Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run |
| X | FiendlyType | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| X | FILE | abcdefg.exe | "Added by the KELVIR.DD WORM!"
|
| ? | file indexing service | msfindfile.exe | "New version of MS FindFast and still a resource hog?"
|
| X | file laoder configuration | rnd32.exe | "Added by the RBOT.BQJ WORM!"
|
| X | File Mapping Services | hp-1003.exe | "Added by the RBOT.FAN WORM!"
|
| X | File Protection Monitor | filemon.exe | "Added by a variant of the RBOT WORM!"
|
| X | File System Service | wmiprvsc.exe | "Added by the AGOBOT-HZ TROJAN!"
|
| X | File1 | Dia Claro.htm | "Added by the DLOADER-OR TROJAN!"
|
| N | filehippo.com | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | FileHippo.com Update Checker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | filename process | kerneldll.exe | "Added by the AGOBOT-PO WORM!"
|
| X | filename process | explore.exe | "Added by the AGOBOT-QN WORM!"
|
| X | filename process | Rundil16.exe | "Added by the GAOBOT.ZX WORM!"
|
| X | FileSoft | Wscript.exe UpdataFiles.vbs | "Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
|
| U | FilmLoop | FilmLoopService.exe | "Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
|
| X | FilterProgram | GDC.exe | "FilterProgram rogue privacy tool - not recommended |
| Y | Find Virus Launch Program | fvlaunch.exe | "Part of Dr. Solomon's Antivirus"
|
| X | FindHack | [path to worm] | "Added by the KELVIR-BA WORM!"
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| X | Fire Wall services | [random filename] | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Wall services | wnlmzsfhobi.exe | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Well service | [random].exe | "Added by the RBOT-FJU WORM!"
|
| ? | FireBox Control Panel | FireBox.exe | "Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
|
| X | FireFox Service Drivers | ssmss.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireFox Startup Drivers | wuaclt.exe | "Added by the RBOT.BYX WORM!"
|
| X | FiresWallservices | [random].exe | "Added by the RBOT-FJT WORM!"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.A or ELIPTER.B WORMS! Note the space at the beginning of the filename"
|
| X | Firewall | wmlaunch .exe | "Added by the ELIPTER.D WORM!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall config | ReadMe.exe | "Added by the SILLYFDC.BBT WORM!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Policy | MidiDef32.exe | "Added by the PIEBOT-A TROJAN!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| X | FireWire Service | nvscv32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireWire Services | nvcsv32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| ? | First Principle Group | fpg.exe | "Related to the E-Players Card from First Principle Group"
|
| Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
|
| X | Fixnice | vcvw.exe | "Added by the SDBOT TROJAN!"
|
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop
|
| X | FlaCPY | flacpy.exe | "FlashEnhancer adware"
|
| X | Flash Media | services.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Flash32 | FLASH32.COM | "Added by the STARTER-F TROJAN!"
|
| U | FlashEnc | FlashEnc.exe | "Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission |
| X | FlenCPY | flencpy.exe | "FlashEnhancer adware"
|
| U | Flexicd | Flexicd.exe | "CD player - part of the Win95 Power Toys"
|
| U | FLMLABTECMOUSE | mouse32A.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMOFFICE4DMOUSE | moffice.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMOFFICE4DMOUSE | mouse32a.exe | Mouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | FlnCPY | flncpy.exe | "FlashEnhancer adware"
|
| X | flpycntl | flpycntl.exe | "Added by the CRYPTER.C TROJAN!"
|
| ? | FLSVCI | FLSVCI.exe | "??"
|
| Y | FltProcess | msinet.exe | "Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
|
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
|
| ? | Focus | Focus.exe | "ISDN configuration wizard?"
|
| X | foffice | nm.exe | "Added by the DELF-CB TROJAN!"
|
| X | Folder Service | wssdtu.exe | "Added by the MANIFEST TROJAN!"
|
| U | FolderClone v*.*.* | folderclone.exe | "Folderclone backup and synchronization software"
|
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
|
| X | ForceShow | "rundll32.exe QaBar.dll | ForceShowBar" |
| Y | FortiClient | FortiClient.exe | "Fortinet security systems are the new generation of real time network protection systems"
|
| U | Fortis Secure Layer Config | cseinst.exe | Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
|
| N | FotoStation Easy AutoLaunch | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
|
| X | FoWilCo | fowilco.exe | "Added by the WOOTBOT.CR WORM!"
|
| X | foxwudy9912 | service.exe | "Added by the BANCOS-BT TROJAN!"
|
| N | Fpx | mnmsrvc.exe | Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
|
| X | Framework module library | infocard.exe | "Added by the BUZUS.AYX TROJAN!"
|
| X | France | svchost.exe | "Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| N | Free DVD Direct | FreeDVDDirect.exe | "Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
|
| N | FreeCall | FreeCall.exe | "FreeCall - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| X | FreeMP3download | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | freestyle | lockx.exe | "Added by the RBOT-ATH WORM!"
|
| X | freexstyle | lockbar.exe | "Added by the LOXBOT.D WORM!"
|
| X | freexstyle | lockbr.exe | "Added by the LOXBOT.C WORM!"
|
| N | freshclam | freshclam.exe | "Auto update agent of the open source Clamwin virus scanner"
|
| ? | frguk | shdrkmck.exe | "??"
|
| X | FriendlyTypeName | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
|
| U | FRISK FP-Scheduler | F-Sched.exe | "Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| U | FRITZ!webProtect | FwebProt.exe | Firewall included in FRITZ! ISP DSL software
|
| X | frun | derc32xz.exe | Added by an unidentified TROJAN!
|
| N | FSCBoss | FSCBoss.exe | Free Store Club shop online software
|
| X | fsdsft | [path to backdoor] | "Added by the RANKY.S BACKDOOR!"
|
| X | FSH | svcnva.exe | Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
|
| N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
|
| X | fstsvc | "rundll32.exe fstsvc.dll | start" |
| X | ftk | ftkclean.exe | "FlashEnhancer adware"
|
| X | FtkCPY | ftkcpy.exe | "FlashEnhancer adware"
|
| U | Ftpqueue | Ftpsched.exe | "Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
|
| X | FuckD3w4 | FuckD3w4.exe | "Added by the BRONTOK-DI WORM!"
|
| X | Fucker | fucker.vbs | "Added by the CATCHER-A WORM!"
|
| U | Fujitsu Hotkey Utility | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | Fujitsu Menu | FjMnuIco.exe | "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel |
| X | fukerservice | fukerz.exe | "Added by a variant of the RBOT WORM!"
|
| U | FusionRC | FusionRC.exe | "Remote control manager for DVICO FusionHDTV"
|
| U | FusionRemote | FusionRc.exe | "Remote control manager for DVICO FusionHDTV"
|
| X | FW Manager | fwcheck.exe | "Added by the DELBOT-H WORM!"
|
| Y | fwenc.exe | fwenc.exe | "Check Point SecuRemote VPN client - ""dynamic and fixed IP addressing for all ISP services - dial-up |
| X | Fwr Command Module | fwr.exe | "Added by the SDBOT-PP WORM!"
|
| N | fwrastrc | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP
|
| U | fwservice | fwservice | "eAcceleration Stop-Sign security software related. Previously not recommended |
| ? | g3dctl | g3dctl.exe | "??"
|
| X | ga6pcw | ga6pcw.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| X | gac | gac.exe | "Part of VirusVakt |
| ? | GACService | GACService.exe | "Related to a Gemplus product. What does it do and is it required?"
|
| X | gadcom | gadcom.exe | "Added by the AGENT-HIC TROJAN!"
|
| N | Gadwin PrintScreen | PrintScreen.exe | "Gadwin PrintScreen - utility to capture |
| X | GAELICUM.EXE | GAELICUM.EXE | "Added by the PENTA-A TROJAN!"
|
| X | game | patcher.scr | "Added by the PSW-ED TROJAN!"
|
| N | Game Device | JOYUPDRV.EXE | Genius game controller profile activator
|
| X | Games Acceleration | svshost.exe | "EasySearch adware"
|
| X | Games Acceleration | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Games Acceleration | svshost1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| N | GameTracker | GTLite.exe | "GameTracker - ""Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"""
|
| X | gamma | svchost.exe | "Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
|
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers
|
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder
|
| Y | GBSpaceMan | SpaceMan.exe | "GreenBorder - secure your browsing activities on the internet"
|
| X | gCac | gcac.exe | "Added by the TACTSLAY.U TROJAN!"
|
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
|
| Y | gcasServ | gcasServ.exe | "Giant Antipsyware - now superseded by Microsoft's Windows Defender"
|
| X | gcasServ | realsched.exe | "Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
|
| ? | GCC Reminder | gccrem.exe | "Associated with AcraMax Greeting Card Creator. Is it a registration reminder?"
|
| N | GCS | GrabClipSave.exe | "GrabClipSave screen capture tool"
|
| X | gcw | gcw.exe | "Part of BestsellerAntivirus |
| X | GDAX | [path to backdoor] | "Added by the RANKY.K TROJAN!"
|
| X | gdcw | GDCW.exe | "Part of ContentEraser |
| N | Gearbox | confsvr.exe | "NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
|
| N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
|
| X | GEDZAC | GEDZAC.exe | "Added by the GEMEL WORM!"
|
| X | Gekio Startups | gnksvc32.exe | "Added by the AGOBOT.AFJ WORM!"
|
| X | gencroot | gencroot.exe | "Added by the SDBOT-AED WORM!"
|
| X | Generic host proccess for windows | SVCHOSTS.EXE | "Added by the SPYBOT-GQ WORM!"
|
| X | Generic Host Process | SCHOST.EXE | "Added by the RBOT-NC WORM!"
|
| X | Generic Host Process | svchost.exe | "Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | Generic Host Process | lsassw.exe | "Added by the AGOBOT-N WORM!"
|
| X | Generic Host Process for Win Services | mscvs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Process for Win32 Service | svlhost.exe | "Added by the WOOTBOT.EX WORM!"
|
| X | Generic Host Process for Win32 Service | rpchost.exe | "Added by the IRCBOT.DCN WORM!"
|
| X | Generic Host Process for Win32 Services | ntspcv.exe | "Added by the SDBOT.S TROJAN!"
|
| X | Generic Host Process for Win32 Services | intspvc.exe | "Added by the DINFOR.D WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc.exe | "Added by the SDBOT-O WORM!"
|
| X | Generic Host Process for Win32 Services | bazzi.exe | "Added by the AHKER.E WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc32.exe | "Added by the SDBOT-P WORM!"
|
| X | Generic Host Process for Win32 Services | lspsvc.exe | "Added by the MUMU.C WORM!"
|
| X | Generic Host Process for Win32 Services | SPSVC.EXE | "Added by the SDBOT.DA WORM!"
|
| X | Generic Host Process for Win32 Services | svchost32.exe | "Added by the AGOBOT.ALH WORM!"
|
| X | Generic Host Process for Win32 Services | svñhîst.exe | "Added by the DLOADER.AK TROJAN!"
|
| X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Generic Host Process For Win32 Services | mtsc32.exe | "Added by the VB-CPL TROJAN!"
|
| X | Generic Host Process for WinXP Services | mshelp.exe | "Added by the AGENT-GQP TROJAN!"
|
| X | Generic Host Process2 System Backup | scvhost2.exe | "Added by the RBOT-BAH WORM!"
|
| X | Generic Host Process326a System Backup | scvhost326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Service | lshost.exe | "Added by the RBOT.LU WORM!"
|
| X | Generic Service Process | regsvc32.exe | "Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
|
| X | Generic Service Process | serv1ces.exe | "Added by the AGOBOT-JK WORM!"
|
| X | Generic Service Process | nvsvc.exe | "Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
|
| X | Generic Service Process | srvhost.exe | "Added by the AGOBOT-FX WORM!"
|
| X | Generic Service Process | regsvr32.exe | "Added by the AGOBOT-AGD WORM!"
|
| X | Generic Service Process | SRCHOST.EXE | "Added by the AGOBOT-DG WORM!"
|
| X | Generic Services Process | regsvc32.exe | "Added by the GAOBOT.SY WORM!"
|
| X | GenericHostXP | WinLoaderXP.exe | "Added by the BDOOR-ACX BACKDOOR!"
|
| X | Geography TX 1.0 NT | CompuSpeed.vbs | "Added by the NEWLEY-A WORM!"
|
| X | Gerenciamento de arquivos do Windows | Winmod32.exe | "Added by the DLOADER-WG TROJAN!"
|
| X | gescw | gescw.exe | "Part of BeschermingsTool |
| X | Get-Torrent Service | wakeservice.exe | Get-Torrent bittorrent client - Installs LOP adware
|
| Y | Getca | InfoMyCa.exe | "Monitor for a Belkin USB Wireless adapter"
|
| X | GetitAll | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetPack18 | GetPack18.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack19 | GetPack19.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack20 | GetPack20.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack21 | GetPack21.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack22 | GetPack22.exe | "Internet Speed Monitor adware related"
|
| X | GetPack23 | GetPack23.exe | "Internet Speed Monitor adware related"
|
| X | GetPack24 | GetPack24.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack25 | GetPack25.exe | "Internet Speed Monitor adware related"
|
| U | GetRight - Tray Icon | getright.exe | "Entry added with older versions of the GetRight download manager from Headlight Software |
| X | GetTheMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | Getting started with MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | gfxtray | "rundll32 ctccw32.dll | findwnd" |
| U | GhostSecuritySuite | gss.exe | "Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
|
| N | GhostStartService | GhostStartService.exe | "Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
|
| X | GigaByte | Cheatle.exe | "Added by the SHODI.B VIRUS!"
|
| U | Giganews Accelerator | GiganewsAccelerator.exe | "Giganews Accelerator from Giganews |
| Y | GilatFTC | ftc.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| X | GlobalFlagACER | ACER.exe | "Added by the VB.BL WORM!"
|
| X | GlobalSCAPE | [random filename] | "Added by the RBOT-AYM WORM!"
|
| X | Glock Suite 1.1 | glock32.exe | "Added by the TINY.GV TROJAN!"
|
| X | GLSetIT32 | msiexec16.exe | "Added by the OPTIX PRO TROJAN!"
|
| X | GLSetT32 | smsiexec.exe | "Added by the OPTIX-D TROJAN!"
|
| X | Gmsvc32 | gmsvc32.exe | "Added by the AGOBOT.ABN WORM!"
|
| X | GNP Generic Host Process | svchost.exe | "Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| X | go | cvir.exe | "Added by the SILOV-A WORM!"
|
| U | GoBack | GBMenu.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack | GBTray.exe | "System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Polling Service | GBPoll.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Tray Icon | GBTray.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | Golum | services.exe | "Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process |
| X | golumm | services.exe | "Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
|
| U | Google Desktop Search | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| U | Google Quick Search Box | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| X | Google service | Googlesetup.exe | "Added by the IRCBOT-RJ WORM!"
|
| X | Google Service FR | GO0GLEFREE.EXE | "Added by a variant of the SPYBOT WORM!"
|
| N | GoogleDCClient | GoogleDCC.exe | "Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser |
| U | GoogleQuickSearchBox | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| U | GoToMyPC | g2svc.exe | "ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
|
| U | GoTrusted | GoTrusted Secure Tunnel.exe | """GoTrusted is the fast |
| X | gpmce | window.exe | "Added by the VB.CK WORM!"
|
| X | Graphic Driver | smss32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Loader | ntvdm32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Update | openglx.exe | "Added by the IRCBOT.AMU WORM!"
|
| X | Graphics | _default.pif | "Added by the AUTOSKY WORM!"
|
| X | Graphics adapter service | windll.exe | "Added by the ATNAS.A WORM!"
|
| U | Gravis Xperience Driver Support | Grxp4exe.exe | "Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
|
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | gremier | wscript.exe gpremier.vbs | "Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
|
| Y | Groove Virtual Office | Groove.exe | """Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings |
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| N | GrpConv | grpconv.exe | "Microsoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base article"
|
| ? | Gscbc | Gscbc.exe | "??"
|
| N | Gsiconexe | Gsicon.exe | "ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
|
| X | gssomatic | gssomatic.exe | "Searchcentrix hijacker"
|
| X | GT15J4R49V | cpuserv.exe | Identified as a variant of the Trojan.Win32.Radi.gu malware
|
| U | GTVRec | GTVRec.exe | "Part of Got All Media - control your TV tuner and other utilities from your PC"
|
| N | Gtwatch | gtwatch.exe | Associated with a Mustec scanner and not required
|
| X | gtydf | iisca.exe | "Added by the CLAGGER-BB TROJAN!"
|
| X | gtydf | iscca.exe | "Added by the DWNLDR-GTK TROJAN!"
|
| X | GuardCenter | GuardCenter.exe | "GuardCenter rogue security software - not recommended"
|
| Y | GuardGui Application | GuardGui.exe | "System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
|
| U | Guardian | CMGrdian.exe | "McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security |
| U | Guardian PC Security Tools | Pfft.exe | "Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
|
| X | GuardPcs.exe | GuardPcs.exe | "GuardPcs rogue security software - not recommended |
| Y | gw port controller | PORTCT95.EXE | "From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties |
| U | H/PC Connection Agent | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| Y | H2O | cledx.exe | "Related to copyright protection products by SyncroSoft"
|
| U | H2OWIBU | CXWibu.exe | "Related to CodeMeter from WIBU-SYSTEMS AG. Software protection hardware"
|
| X | h4te Service Drivers | h4te.exe | "Added by a variant of the RBOT WORM!"
|
| X | hachimitsu-lemon | hachimitsu-lemon.exe | "Added by the HACHILEM TROJAN!"
|
| X | HackMuFpt | HackMuFpt.exe | "Added by the SCLOG-AG TROJAN!"
|
| U | HalifaxHowardCluster | skinkers.exe | """Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
|
| Y | Hamachi | hamachi.exe | "LogMeIn Hamachi remote control and VPN software"
|
| U | Handy Backup 3.9 | hbagent.exe | "Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
|
| X | Hard drive Controller | hdcontroller.exe | "Added by the KIMAN.B WORM!"
|
| U | Hardware Doctor | Hwdoctor.exe | "Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds |
| X | Hardware Monitor Service | mshms.exe | "Added by the WOLLF-A TROJAN!"
|
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| U | Harmony 98 - CasioOrg | CasAgnt.exe | "Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | HataDuzelticisi | SysRep.exe | "HataDuzelticisi |
| U | HawkEye IV Control Panel | HAWK_32.EXE | "Control Panel application for the old Number Nine graphics cards to change resolution |
| N | HC Reminder | hc.exe | "For Compaq PC's. Help Compiler |
| N | HCDetect | HCDetect.exe | "MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification |
| X | hcen | hcen.exe | "Added by the SMALL.LR TROJAN!"
|
| U | hcenter | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | hcenter | hcenter.exe | "Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| X | hclean32.exe | hclean32.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| U | Hcontrol | hcontrol.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| U | HControlUser | HControlUser.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| N | hcsystray | hc_tray.exe | "Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
|
| N | HD Audio Control Panel | RtHDVCpl.exe | "Realtek HD Audio Manager |
| N | HDAShCut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | HDAudDeck | HDAudioCPL.exe | "Vista control panel for VIA Vinyl HD Audio Codecs from VIA Technologies |
| U | HDAudDeck | HDeck.exe | "XP control panel for VIA Vinyl HD Audio Codecs from VIA Technologies |
| U | HDDControlGuard | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| U | HDDControlGuard.exe | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| X | hdlfoe df98ndf | svchots.exe | "Added by a variant of the RBOT WORM!"
|
| X | hdlpscom | [8 random letters].exe | "Added by the RBOT-FUL WORM!"
|
| X | he3bbcff | "rundll32.exe he3bbcff.dll | EnableRunDLL32" |
| X | he3e3fc4 | "rundll32.exe he3e3fc4.dll | EnableRunDLL32" |
| X | Hekio Startups | Hnksvc32.exe | "Added by the AGOBOT-QE WORM!"
|
| X | HELLBOT3 | coolbot.exe | "Added by the MYTOB.AB WORM!"
|
| X | hellfire | svchost.exe | "Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | help | help.scr | "Added by the BANCOS-BBU TROJAN!"
|
| U | HelpCenter | sprtcmd.exe /P HelpCenter | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| U | HelpCenter4.1 | sprtcmd.exe /P HelpCenter4.1 | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| X | helpctl.exe | helpctl.exe | "Added by the GASLIDE TROJAN!"
|
| X | Helper | eschlp.exe | "Added by the BLASTER.T WORM!"
|
| X | HELPER | greece_nm.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | canada.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | france.exe | "AsdPlug premium rate adult content dialer variant"
|
| Y | HEProtect | HSockPE.exe | "Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
|
| ? | HerculesCamService | CamService.exe | "Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
|
| X | hErcUnes | softhost.exe | "Added by the GARROCH WORM!"
|
| X | Hewlett Packard Manager | hpmanager.exe | "Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
|
| N | Hewlett Packard Recorder | Remind32.exe | HP multifunction registration
|
| X | HF Security | hfsecure.exe | "Added by the AGOBOT-TI WORM!"
|
| ? | HiberMonitor | HCount.exe | "??"
|
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| N | High Definition Audio Property Page Shortcut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| X | Highspeeddownloader | SetupClickHere.EXE | "Homepage hijacker |
| U | HijackThis | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| U | HijackThis startup scan | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| X | HistoriaLout. | GDC.exe | "HistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| U | hkcmd | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | HKCU | server.exe | "Added by the AGENT-NLT TROJAN!"
|
| X | HLcleanup | hlsetup2.exe | "LinkReplacer/FFinder adware"
|
| X | HLL Data Parameter | hllcxpa.exe | "Added by the RBOT.AFG WORM!"
|
| X | HMI PowerSystem | hmisvc32.exe | "Added by the RANDEX.CZZ WORM!"
|
| X | HML PowerSource | hmlsvc32.exe | "Added by the SDBOT-XL WORM!"
|
| X | HMV PowerSource | hmusvc32.exe | "Added by the SDBOT-YW WORM!"
|
| X | hohohhaha | ournik.com | "Added by the IRCFLOOD.AL BACKDOOR!"
|
| X | HOI Services | holsvc32.exe | "Added by the AGOBOT-SF WORM!"
|
| X | Hollaback | slvhosts.exe | "Added by the SDBOT.BMO WORM!"
|
| N | Home Theater SchSvr | SchSvr.exe | "WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| ? | HomeCentre WakeUp | LGWAKEUP.EXE | "Associated with the no longer supported Xerox HomeCentre printer/scanner"
|
| Y | HorngTech4D | bally4d.exe | HorngTech 4D mouse driver
|
| X | Host Process | mame.exe | "Added by the RBOT-APO WORM!"
|
| X | Host Process | svchost.exe | "Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
|
| X | Host Process for Windows Tasks | taskhost.exe | "Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
|
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
|
| X | HostSrv | sachostx.exe... | "Added by the LOOKSKY.E WORM!"
|
| X | HostSVC syse | HostSVC.exe | "Added by the RBOT-ANZ WORM!"
|
| U | Hot Corners | Hotc.exe | "Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
|
| X | HOT FIX | Gothic.exe | "Added by the SDBOT.FIR WORM!"
|
| X | HOT FIX | E0chis.exe | "Added by the HUPIGON.JTY TROJAN!"
|
| X | HOT FIX | QOching.exe | "Added by the WOOTBOT.VH WORM!"
|
| X | HotAction_hr | hotaction_hr.exe | "Added by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""HotAction_hr"""
|
| X | hotdlll | remote.cmd | "Added by the BANKER-EHG TROJAN!"
|
| U | HotKeysCmds | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | HotKeysCmds | [path to worm] | "Added by the PAHATIA-A WORM!"
|
| N | HotSync Manager | hotsync.exe | Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
|
| X | Hot_Tarts_mc | Hot_Tarts_mc.exe | "HotTarts adult content dialer"
|
| N | HP CD Writer | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| N | HP CD-DVD | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| N | HP CD-Writer | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| X | hp center | BACKWEB-*****.exe | "See here - ""messaging service that automatically sends you support information |
| N | hp center UI | ShadowBar.exe | "User Interface for HP Center - see here"
|
| N | HP Component Manager | hpcmpmgr.exe | "Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
|
| X | HP Desktop | ccappms.exe | "Added by the SDBOT-TG WORM!"
|
| U | HP Health Check Schedule | HPHC_Scheduler.exe | HP Health Check Scheduler from Hewlett-Packard
|
| ? | HP IDScheduler | HPIDSCHD.exe | "HP Instant Delivery Scheduler"
|
| U | HP Instant Support | matcli.exe | ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| N | HP Internet Center | SURFBRD.EXE | Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
|
| N | HP JetDiscovery | HPJETDSC.EXE | HP JetAdmin software which monitors printing jobs on a network environment
|
| U | HP Laser Jet Director | hppdirector.exe | "System Tray icon that opens various functions such as copy |
| ? | HP OfficeJet Series xxx Startup | HPOSTR03.EXE | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| ? | HP OfficeJet Series xxx Startup | HPOstr05.exe | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| N | HP Precision Scan | hpmdlbwx.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| U | hp psc 2000 Series | hpobnz08.exe | System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
|
| U | HP RecordNow | ?? | "From HP ""Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used."""
|
| U | HP ScanPatch | HPScanFix.exe | "Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used |
| N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| U | HP SchedIndexer | hppschedindexer.exe | "Installed by HP multi-function printer driver software |
| X | HP Service Drivers | hdsys.exe | "Added by the SDBOT-ZE WORM!"
|
| ? | hp Silent Service | HpSrvUI.exe | "HP related"
|
| N | HP Simple Trax | Hpcron.exe | Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
|
| N | HP software update | HPWuSchd2.exe | HP software updates. If a shortcut doesn't exist create your own and run it manually
|
| N | HP software update | HPWuSchd.exe | "HP software updates. If a shortcut doesn't exist |
| N | hpaiodevice | hpodev07.exe | "Direct from HP - "Device Objects Server - detects all device events and handles all ongoing communication on the device. Loads in the Startup group (except when "portable" is chosen during installation)". Related to various HP all-in-one printer/scanner/copier devices. They print and copy fine with those files disabled |
| ? | HPAiODevice(hp officejet g series) | hpoavn07.exe | "HP Printer related |
| N | HPAiODevice(hp psc 900 series) -1 | hpobrt07.exe | "Installed with a Hewlett Packard 900 series colour printer |
| X | hpcmd | cmd.exe | "Added by the ADCLICK-DS TROJAN!"
|
| N | hpcmpmgr | hpcmpmgr.exe | "Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
|
| N | hpfsched | hpfsched.exe | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
|
| U | HPGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| X | HPl Services | hmlsvc32.exe | "Added by the AGOBOT-SI WORM and variants!"
|
| U | hplampc | hplampc.exe | HP Scanner Lamp Utility - fixes an issue with the scanner lamp not going off
|
| U | HPLaptopGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| Y | HPLJ Config | SetConfig.exe | Connects system to networked HP printer.
|
| ? | hpqcmon | hpqcmon.exe | "From HP and related to digital imaging"
|
| U | HPSCANMonitor | hpsjvxd.exe | HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
|
| ? | hpScannerFirstBoot | scannerfb.exe | "HP scanner related"
|
| X | hpsysconf1 | [random filename] | "Added by a variant of the VIVIA.A TROJAN!"
|
| X | hptools | microsoft.exe | "Added by a variant of the SDBOT WORM!"
|
| N | HPU | ProvenTactics.exe | "Proven Internet Marketing software"
|
| X | HQI Services | hqisvc32.exe | "Added by the AGOBOT-RO WORM!"
|
| X | HQI Services | hqlsvc32.exe | "Added by the AGOBOT-RP WORM!"
|
| U | HREF.OCX | regsvr32.exe ....HREF.OCX | "HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
|
| X | Hrn_qtv | hrnsvc32.exe | "Added by the SDBOT-AET WORM!"
|
| X | Hservice | msservice.exe | "Added by the AUTORUN-KL WORM!"
|
| X | hsim | isearch.exe | Unidentified malware
|
| ? | HsuGuiControl | HsuGuiControl.exe | "Part of the Starband Internet satellite client. What does it do and is it required?"
|
| U | HTpatch | htpatch.exe | HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
|
| X | HtProtect | AVprotect.exe | "Added by the NETSKY.L WORM!"
|
| X | http://www.lienvandekelder.com | Lien Van de Kelder.exe | "Added by the MYTOB-EQ WORM!"
|
| X | http://www.lienvandekelder.com/ | LienVandeKelder.exe | "Added by the MYTOB-EO WORM!"
|
| X | httpd | c_pan.exe | Added by a variant of the DELF-A TROJAN!
|
| U | HughesNet Tools | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| X | Hvewsveqmg | ANACON.EXE | "Added by the NACO.A WORM!"
|
| X | Hwp | system_wc.exe | "Eziin adware"
|
| X | hxadsec | [path to trojan] | "Added by the ADCLICK-AP TROJAN!"
|
| X | I am not Ranky. I am eTunnel! | msyervice.exe | Added by an unidentified WORM or TROJAN!
|
| X | I just want to say I love Milko and I need a drink | svchost.exe | "Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
|
| X | I/O Controllers | svcnet.exe | "Added by the TIBIK-B TROJAN!"
|
| X | Iamnacho On Irc.MusIrc.com Is a Homosexual! | XBox64.exe | "Added by the RANDEX.Y WORM!"
|
| Y | IBM Client Security | certtool.exe | "Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk) |
| N | IBM Client Security Software | csecwiz.exe | "Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once |
| N | IBM RecordNow! | RecordNow.exe | "IBM customized version of the RecordNow! CD-writing utility from Sonic Solutions"
|
| U | IBM ThinkPad EasyEject Support Application | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad EasyEject Tray Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| U | IBM TrackPoint Accessibility Features | tp4ex.exe | "Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound"" |
| ? | IBM Warranty Notification | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| U | Ibmpmsvc | ibmpmsvc.exe | "Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn |
| ? | IBMPRC | ibmprc.exe | IBM application - what does it do and is it required?
|
| U | IBMUltraBayHotSwapCPLLoader | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
|
| U | IBWin Background process | IBackground.exe | "IBackup for Windows"
|
| Y | IcaBar | icabar.exe | Related to Citrix MetaFrame
|
| U | iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| X | icasServ | icasServ.exe | "Browser hijacker |
| X | icccomp | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| X | ICcontrol | iccontrol.exe | "ICcontrol premium rate adult content dialer"
|
| X | icdd7ee6 | "rundll32.exe icdd7ee6.dll | EnableRunDLL32" |
| X | icddefff | "rundll32.exe icddefff.dll | EnableRunDLL32" |
| Y | ICF | mfp.exe | "McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content |
| N | ICH Synth | eusexe.exe | "Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
|
| X | icifati | yujixit.exe | "Added by the SDBOT.ZZH WORM!"
|
| U | iClean | iClean.exe | "IEClean - ""advanced |
| U | ICM | ICM.EXE | "Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
|
| X | ICManagement | msic32.exe | "Added by the MSIC BACKDOOR!"
|
| N | iCn | NAG.EXE | "iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy |
| U | ICO | ICO.EXE | "Found on some Sony Vaio |
| N | Icon Animation | HDE.EXE | Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
|
| N | Icon Hearit 95 | hearit95.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| N | Icon Hearit 98 | hearit98.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| X | Icon lptt01 | icon.exe | "RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Icon ml097e | icon.exe | "RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | iconcache | icon.bat | "Related to the Vista Customization Pack"
|
| Y | ICONCLNT | iconclnt.exe | "APC PowerChute® Personal Edition tray icon"
|
| U | ICONDESK | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons
|
| N | Iconfig.exe | Iconfig.exe | Icon for LS-120 "Superdisk"
|
| X | iConfigLoader | DIIhost.exe | "Added by the GAOBOT.AO WORM!"
|
| N | Iconoid | Iconoid.exe | "Iconoid is a desktop icon manager"
|
| N | Iconsaver | Iconsaver.exe | "IconSaver is a desktop icon manager"
|
| X | ICQ | ICQNET.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | ICQ Agent | icq6.exe | "Added by the AGENT-FZJ TROJAN!"
|
| X | ICQ Center | [path to worm] | "Added by the RANDIN WORM!"
|
| X | ICQ Chat Service | icqjdhs.exe | "Added by a variant of the RBOT WORM!"
|
| X | ICQ Hacking Pro | ICQpro.exe | "Added by a variant of the NETSPY TROJAN!"
|
| N | ICQ Lite | ICQLite.exe | "ICQ Lite - compact version of the popular messaging program"
|
| X | icq lite | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | icq lite | winlog.exe | "Added by the IRCBOT-TJ TROJAN!"
|
| X | ICQ Lite Messenger | ICQLITE.EXE | "Added by an unidentified VIRUS |
| X | ICQ Messenger 2002 | ICQ2002.exe | "Added by the SDBOT-ABL WORM!"
|
| X | ICQ Net | winlogon.exe | "Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
|
| N | ICQ Plus | vplus.exe | "ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
|
| X | IcqBeta | webcamupdate.exe | Added by an unidentified TROJAN!
|
| U | ICQMonitor | ICQMonitor.exe | "ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself"
|
| X | ICQMsn | [path to trojan] | "Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
|
| X | ICQNet | winlogon.exe | "Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | icrosof Avps32 Control | av32.pif | "Added by the RBOT-AVC WORM!"
|
| X | icrosoft Visual | plscx.exe | "Added by the RBOT-AYO WORM!"
|
| X | icrosoft Visual InterDevc | zvslmqb.exe | "Added by the RBOT-AYP WORM!"
|
| X | icrosoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AER WORM!"
|
| X | icrosoftf Avpx Control | avpx.exe | "Added by the RBOT-AYN WORM!"
|
| U | ICSDCLT | "rundll32.exe Icsdclt.dll | ICSClient" |
| N | ICServer | Icserver.exe | Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
|
| Y | ICSMGR | ICSMGR.EXE | Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
|
| X | ICU-Sucker | Service32.exe | "Added by the ILLNOTIFIER.D TROJAN!"
|
| N | IC_KEY_3 | spvic.exe | "Instant Chess related"
|
| N | ID Commander | IDCom.exe | Caller ID utility for identifying incoming telephone numbers
|
| X | idecntl | idecntl.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| X | IE configure | explorer.exe | "Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
|
| U | IE Doctor | IEDoctor.exe | "IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily |
| X | IE**.exe [* = random char] | IE**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IE**32.exe [* = random char] | IE**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IE-Security | iescan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE-Security | wdscan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IEACCESS | temp532.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | IEACCESS | surfya.exe | "
| X | IEAgent update check | iewatch.exe | "Added by the BOMKA TROJAN!"
|
| X | IECache | IECache.exe | "Detected by Bitdefender as the DELF.OFC TROJAN! See here"
|
| N | iecheck | iecheck.exe | "Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2"
|
| X | IECheck | MSDTCs.exe | "Added by the TIRBOT-D WORM!"
|
| X | IECheck | xpssl.exe | "Added by the TIRBOT-E WORM!"
|
| X | IECheck | mssvp.exe | "Added by the TIRBOT-G WORM!"
|
| U | IECleanAux | Ieboot6.exe | "IEClean by Kevin McAleavy - cookie manager |
| X | Iehelper | syslaunch.exe | Outwar adware downloader
|
| X | iel2cde8 | "rundll32.exe iel2cde8.dll | EnableRunDLL32" |
| X | ielcaabe | "rundll32.exe ielcaabe.dll | EnableRunDLL32" |
| X | Iesearch.exe | Iesearch.exe | "LookNSearch adware"
|
| X | IEService.exe | IEService.exe | "FastFind adware variant"
|
| X | ieupdate | MCP****.exe [**** = random char] | "Added by the ASOXY TROJAN!"
|
| X | ieupdate | mcpdll32.exe | Adware downloader trojan
|
| X | Iexplore Services | iexplore.exe | "Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
|
| X | IEXPLORER | msiecfg.exe | "Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
|
| X | IExplorer32 Java Scripting | IExplore32b.exe | "Added by the RBOT.ABO WORM!"
|
| X | IExplorer32c Java Scripting | IExplore32cb.exe | "Added by the RBOT.ABN WORM!"
|
| X | IExplorer6 Java Scripting | IExplore326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorer7 Java Scripting | IExplore327.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorerService | WinSock.exe | "Added by the AGENT.KIU TROJAN!"
|
| X | igamatu | atecaca.exe | "Added by the IRCBOT.R WORM!"
|
| U | igfxhkcmd | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | igfxtras | svchots.exe | "Added by the AUTORUN-AIW WORM!"
|
| X | IGuardPc.exe | IGuardPc.exe | "IGuardPc rogue security software - not recommended |
| ? | iHP-100 | iHPDetect.exe | "Drive Letter Searcher |
| X | iilc | IILC.EXE | Homepage hijacker
|
| X | iiuyvyu | uzcx.exe | "Added by the AGENT-EOF TROJAN!"
|
| U | IJNetworkScanUtility | CNMNSUT.EXE | Network utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
|
| Y | IKE Service 95 | IKEService.exe | "Associated with PGP. The PGP Tray can be disabled |
| ? | ILO_Office_Manager | IntEdReg.exe /OFFMAN | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| U | iLyric | iLyric.exe | "iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button"
|
| N | iM Start Center | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
|
| N | iMarkup Client | iUtil.exe | "Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
|
| X | imchat | imchat.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | IMClass | Svhosl.exe | Added by an unidentified WORM or TROJAN!
|
| X | imcssl | xmliwvug.exe | "Added by the SLAPER.U TROJAN!"
|
| X | IME | conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
|
| U | ImgIcon | ImgIcon.exe | "Displays Iomega icons in Explorer/My Computer |
| X | IMJPMIG6.1 | HelpCat.exe | "Added by the BESVERIT WORM!"
|
| ? | immcheck.exe | immcheck.exe | "Related to I-FORCE driver for force feedback steering wheel?"
|
| X | IMprocess | IM-svr.EXE | "IMNames adware"
|
| U | ImScInst | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | ImScInst.exe | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | IMVU | IMVUClient.exe | "IMVU chat client that allows you to create ""your own avatars who chat in animated 3D scenes"""
|
| X | imwinsrvc | acpmonsrv.exe | "Added by the SLAPER.E TROJAN!"
|
| X | imxecs | vbrun70sp4.exe | "Added by the AGOBOT.ALA WORM!"
|
| Y | InCD | incd.exe | "Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3) |
| N | IncMail | IncMail.exe | """IncrediMail is an advanced |
| X | incognito | incognito.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| N | InControl Desktop Manager | DMHKEY.EXE | For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
|
| X | Incredible Keylogger | AdvKeylog.exe | "IncredibleKeylogger spyware"
|
| N | Incredimail | incredimail.exe | ""IncrediMail is an advanced |
| N | Incredimail | IncMail.exe | """IncrediMail is an advanced |
| X | Index Service | dllhost32.exe | "Added by the AGOBOT.CH WORM!"
|
| X | Indexindicator | Indexindicator.exe | "Added by the LAZAR TROJAN!"
|
| N | IndexSearch | IndexSearch.exe | "Part of Nuance (ScanSoft) PaperPort - ""scan |
| U | IndicatorUty | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMIndexStoreSvr.exe | "Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
|
| X | ine | svchosts.exe | "Added by the RBOT.BNL WORM!"
|
| X | INET | inetsync.exe | "Meplex adware"
|
| X | InetChk | ms[random value].exe | "Added by the AGENT-IRL TROJAN!"
|
| U | inetcntrl | inetcntrl.exe | Bsafe Online - internet filter
|
| ? | InetConf | inetconf.exe | "??"
|
| X | InetServices | wsock32.exe | "Added by the WOCK32-A TROJAN!"
|
| X | INFO DATA | apc.exe | "Added by the RANDON.B WORM!"
|
| U | Info Select | is.exe | "Info Select from Micro Logic - personal information manager"
|
| N | InkWatch | InkWatch.exe | Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
|
| Y | InoRPC | InoRpc.exe | "Associated with eTrust Antivirus/InoculateIT"
|
| X | iNotice | iservice.exe | Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
|
| ? | insCOA5 | insCOA5.exe | "??"
|
| X | InstallCleaner | InstallCleaner.exe | "Added by the ANYHOMB.F TROJAN!"
|
| X | Installed shell32.dll | Office.exe... | "Added by the LOVGATE.AO WORM!"
|
| X | Installed shell32.dll | Office.exe | "Added by the LOVGATE.E WORM!"
|
| ? | InstallNAIProduct | SETUP.EXE | "Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
|
| X | Installs SP2 | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
|
| X | Installs SP4 | [path] repcale.exe [path] p0rd.exe | "Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
|
| X | Instance 001 | [path to worm] | "Added by the ALASROU-A WORM!"
|
| X | Instant Access | "rundll32.exe EGDHTML_1023.dll | InstantAccess" |
| X | Instant Access | "rundll32.exe eg_auth_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMLIB_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMSERVICE_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe p2esocks_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | mwsrvacc.exe | "InstantAccess premium rate adult content dialer"
|
| X | Instant Access | linewsrv.exe | "InstantAccess premium rate adult content dialer variant"
|
| X | Instant Messenger Service | imservice.exe | "Detected by Kaspersky as the HEUR TROJAN!"
|
| N | Instant Update Center | reminder.exe | "Event reminder for calendar dates |
| U | Instant Wireless Configuration Utility | WUSB11cfg.exe | "Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| U | Instant Wireless Configuration Utility | WPC11Cfg.exe | "Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| N | InstantAccess | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
|
| N | InstantTray | PCLETray.exe | "Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
|
| X | InSysSecure | InSysSecure.exe | "InSysSecure rogue security software - not recommended |
| X | intdctrr | idctup20.exe | "SafeSurfing adware variant"
|
| X | Intec Service Drivers | msmsgrs.exe | "Added by the SDBOT-ADN WORM!"
|
| X | Intec Service Drivers | [path to worm] | "Added by the RBOT-GLU WORM!"
|
| X | Intec Service Drivers | wing32.exe | "Added by the RBOT.HAZ WORM!"
|
| X | Intec Service Drivers | msmsgredss.exe | "Added by the SDBOT-AGL WORM!"
|
| X | Intec Services Driverrs | winrvc.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Intec Services Drivers | msupdate22e.exe | "Added by the RBOT-CGC WORM!"
|
| U | Intel Active Monitor | imontray.exe | "System tray monitoring of fans |
| X | Intel Driver | csrs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Intel Management Services v32 | mstime32.exe | "Added by the AUTORUN-AYG WORM!"
|
| X | Intel Physical Routine 1.2A | stnetlib.exe | "Added by the BACKDR-AS BACKDOOR!"
|
| U | Intel Product Number Utility | IntelProcNumUtility.exe | "Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
|
| N | Intel PROSet Tray Icon | promon.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
|
| X | Intel Service Drivers | msconfig16.exe | "Added by the MSCONFIG16 TROJAN!"
|
| U | Intel(R) Common User Interface | igfxtray.exe | "System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
| U | IntelAPMClient | amclient.exe | "LANDesk® Management Suite software component"
|
| X | Intelli Mouse Pro Version 2.0B | ncsjapi32.exe | "Added by the BUZUS-O WORM!"
|
| X | Intelprc | Aas3lovu.exe | "Added by the SILLYFDC-CG WORM!"
|
| U | IntelProcNumUtility | cpunumber.exe | "Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
|
| U | IntelZeroConfig | ZCfgSvc.exe | "Zero Config MFC Application |
| ? | Intense Registry Service | IntEdReg.exe /CHECK | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| X | InterceptedSystem | [path to worm] | "Added by the ANACON-B WORM!"
|
| Y | InterCheck Monitor | Icmon.exe | "Part of Sophos ant-virus sofware"
|
| Y | InterCheckMonitor | ICMON.EXE | "Part of Sophos anti-virus sofware"
|
| X | Internal | regedit.exe /s c[month number] | "Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir% |
| X | Internat Conf | bootconf.exe | "Homepage hijacker |
| X | internct | WinSocks5.exe | "Added by the GRAYBIRD.F TROJAN!"
|
| X | Internet | recruit.exe | "Added by the RBOT-AJG WORM!"
|
| U | Internet Answering Machine | IAMNET~1.EXE | "From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| U | Internet Answering Machine | IAM.exe | "From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| X | Internet Application Driver | expIorer.exe | "Added by the IRCBOT-WK TROJAN!"
|
| U | Internet Call Director | ICD.EXE | "TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
|
| U | Internet Call Manager | ICM.EXE | "Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
|
| X | Internet Config | svchosts.exe | "Added by the SDBOT TROJAN!"
|
| X | Internet Connection Wizard | stisvsq.exe | "EasySearch adware"
|
| X | Internet Connection Wizard | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Internet Connection Wizard | stisvsq1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Internet Content Publisher | ICP.EXE | "Added by the RBOT-UD WORM!"
|
| U | Internet Disk Cleaner | CLEARH~1.EXE | """Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
|
| U | Internet Download Accelerator | ida.exe | "Internet Download Accelerator download manager"
|
| X | Internet download manager service | idman.exe | "Added by the RBOT-BMS WORM!"
|
| X | Internet Exploere Services | urlmon32.dll.exe | "Added by the EVIAN.C WORM!"
|
| X | Internet Explore Microsoft | lEXPLORE.EXE | "Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
|
| X | Internet Explorer Configuration | IEXPLORE.EXE | "Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Internet Explorer Security | iexplore.pif | "Added by the RBOT-ALQ WORM!"
|
| X | Internet Explorer Updater | lexbac.exe | "Added by the DOWNLOAD TROJAN!"
|
| X | Internet Protocol Configuration Loader | ipcl32.exe | "Added by the SDBOT TROJAN!"
|
| X | Internet Security 2010 | IS2010.exe | "Internet Security 2010 rogue security software - not recommended |
| X | Internet Security Service | msq32.exe | "Added by the RBOT-GFP WORM!"
|
| X | Internet Security Service | msq23.exe | "Added by the RBOT-GQL WORM!"
|
| X | Internet Security Service | msql23.exe | "Added by the RBOT-GML WORM!"
|
| X | Internet Security Service | mysqlwin32.exe | "Added by the RBOT.UX TROJAN!"
|
| X | Internet Security Service | expllorer.exe | "Added by the REFROSO.AFF TROJAN!"
|
| X | Internet Service | intersvc.exe | "Added by the SPYBOT-DE WORM!"
|
| X | internet service | syscfg32.exe | "Added by the RBOT-QS WORM!"
|
| X | internet service | ssvhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | internet service | svho0st98.exe | "Added by the RBOT.EAT WORM!"
|
| X | Internet Services | systemdev.exe | "Added by the SDBOT-PW WORM!"
|
| X | Internet Services | internet.exe | "Added by the MYTOB.BT WORM!"
|
| X | Internet Services | interserv.exe | "Added by the RBOT.BNT WORM!"
|
| X | Internet Services | Netsvc.exe | "Added by the MYTOB.MN WORM!"
|
| N | InternetCalls | InternetCalls.exe | "InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| X | InternetGetConnectedState | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetGetConnectedStateEx | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | Internet_Explorer | microsoft.exe | "Added by the BANKER-EUQ TROJAN!"
|
| X | Inters Configuration Loader | RCL0ADERS.exe | "Added by the SDBOT-KX WORM!"
|
| N | InterTrust Quick Start | it_cpq~1.exe | "InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
|
| N | Intervideo Win Cinema Manager | WinCinemaMgr.exe | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo Win Cinema Manager | WINCIN~1.EXE | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinCinema Manager | WinCinemaMgr.exe | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinCinema Manager | WINCIN~1.EXE | "WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs"
|
| N | Intervideo WinScheduler | WinScheduler.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| N | Intervideo WinScheduler | SchSvr.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| X | intranet | SYS32CFG.EXE | "Added by the SPYBOT-DW WORM!"
|
| X | Intranet | schost.exe | "Added by the RBOT.SV BACKDOOR!"
|
| N | Introducing Media Manager | SPLASHA.EXE | "MS Media Manager tour. Not required"
|
| N | Introduction-Registration | ?? | "For Compaq PC's. Should only run first time |
| Y | Intuit SyncManager | IntuitSyncManager.exe | "Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync |
| U | Inventory Scan | LDISCN32.EXE | "LANDesk® Management Suite software component"
|
| N | iobi | iobiClient.exe | "iobi Home - a mail/voice service by Verizon"
|
| U | Iomega Automatic Backup | ibackup.exe | "Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
|
| U | Iomega Automatic Backup 1.0.1 | ibackup.exe | "Iomega Automatic Backup - automatic backups for use with Iomega portable HDD"
|
| N | Iomega Backup Scheduler | dtiom98.exe | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| U | Iomega Disk Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| U | Iomega Drive Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| U | Iomega ImIconXP | imiconxp.exe | "Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system |
| ? | Iomega QuickSync | Quicksync.exe | "??"
|
| N | Iomega Watch | IOWATCH.EXE | Used by Iomega drives. Available via Start -> Programs
|
| N | IomegaWare | COMMANDER.EXE | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| X | ioroxxo microsoft sux | system32.exe | "Added by a variant of the RBOT WORM!"
|
| U | IP Changer 2.0 | IPChanger.exe | "IP Changer 2.0 from Plustech Inc - network configuration management tool"
|
| X | IP Packet Redirect Service | ipredirect.exe | "Added by the FORBOT.SM WORM!"
|
| X | IP Stack | ipstack.exe | "Added by the AGOBOT.CW WORM!"
|
| X | IP**.exe [* = random char] | IP**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IP**32.exe [* = random char] | IP**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | IPC Connection | ipcconn.exe | "Added by the RBOT-AEG WORM!"
|
| X | IPC Spool Manager | wnmgre.exe | "Added by the SDBOT-ZC WORM!"
|
| X | IPC Spool Manager | winspec.exe | "Added by the SDBOT-BLU WORM!"
|
| X | ipcfg.exe | ipcfg.exe | "Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!"
|
| X | IPConfig | svcxnv32.exe | "Added by the HACARMY.E TROJAN!"
|
| X | IPConfig | svcxnw32.exe | "Added by a variant of the HACARMY.E TROJAN!"
|
| X | IPConfig | ipconfigs.exe | "Added by the HACARMY.C BACKDOOR!"
|
| X | IpCtrl | ipcon32.exe | "Added by an unidentified VIRUS |
| N | IPInSightLAN 01 | IPClient.exe | "IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth |
| X | IPLog Security | iplogsec.exe | "Added by the IRCBOT.GP BACKDOOR!"
|
| X | iPod USB Service | iPODService.exe | "Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service |
| ? | iPodWatcher | iPodWatcher.exe | "Associated with Apple's iPod® player. Detects when the iPod® is connected?"
|
| X | IPOT Service Drivers | compaq.exe | "Added by a variant of the FUROOTKIT TROJAN!"
|
| X | IPOT USB Service DRIVER | hpsebc087.exe | "Added by the SDBOT-WA WORM!"
|
| X | IPOT USB Service DRV32 | hpsebc08.exe | "Added by the SDBOT-WH WORM!"
|
| N | IPPDetect | IPP4Detect.exe | "Part of Presto! Mr.Photo - ""an ideal program for creating |
| ? | iPrint LPT Redirector | nipplpte.exe | "Related to Novell iPrint - ""a printing solution that enables you to send documents to printers located throughout the Net."" Is it required?"
|
| N | iPrint Tray | iprntctl.exe | "Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net"
|
| U | iProtectYou | ip.exe | "iProtectYou - internet filtering/parental control and network monitoring software"
|
| X | IPSEC Configuration | wsupdate.exe | "Added by the AGOBOT-IQ WORM!"
|
| X | iPSec7 | ipsec7.exe | "Added by the AGENT.AHVR TROJAN!"
|
| U | ipsecdialer | IPSECD~1.EXE | "Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
|
| U | ipsecdialer | ipsecdialer.exe | "Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
|
| Y | IPSecMon | IPSecMon.exe | "Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet"
|
| X | IPTable Configuration | Winipcfgs.exe | "Added by a variant of the RBOT WORM!"
|
| X | IPv6 Helper Driver | csass.exe | "Added by the AGOBOT.TC WORM!"
|
| X | IPv6 STUN Service | netstun.exe | "Added by a variant of the SDBOT WORM!"
|
| X | irassync | irasyncd.exe | "IRASSync adware"
|
| X | irc session | sessionmgr.exe | "Added by the SDBOT-ACE WORM!"
|
| N | iRis Active Monitor | winmon32.exe | "Iris Antivirus - discontinued |
| N | iRiS AntiVirus Active Monitor | WIMMUN32.exe | "Iris Antivirus - discontinued |
| U | IRIS_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX-3160 Series multifunction laser printer
|
| U | IRIS_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 6110MFP multifunction laser printer
|
| U | iRiver AutoDB | MLService.exe | "Associated with the iRiver Music Manager"
|
| ? | IRPMonitor | itcnmon.exe | "??"
|
| X | irssyncd | irssyncd.exe | "SafeSurfing adware variant"
|
| N | IS CfgWiz | cfgwiz.exe | Norton Internet Security configuration wizard
|
| X | IsassRenascimento | Issas.exe | "Added by the BANKER.GAX TROJAN!"
|
| X | iscch | iscch.exe | "Added by the LCPRANK-A WORM!"
|
| N | isdbdc | isdbdc.exe | For Compaq PC's. May install properties in dial-up networking when you register with an ISP
|
| U | ISDNwatch | IWatch.exe | "FRITZ!X ISDNWatch - ""dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"""
|
| X | iSecurity applet | "rundll32.exe iSecurity.cpl | SecurityMonitor" |
| X | ISMPack5 | ISMPack5.exe | "Internet Speed Monitor C adware related - see example here"
|
| X | ISMPack6 | ISMPack6.exe | "Internet Speed Monitor C adware related - see example here"
|
| X | ISMPack7 | ISMPack7.exe | "Internet Speed Monitor C adware"
|
| X | ISMPack8 | ISMPack8.exe | "Internet Speed Monitor C adware related - see example here"
|
| Y | ISP.COM High Speed | slipgui.exe | "User interface for Slipstream - internet acceleration through compression/decompression techniques |
| X | ISPSERVICE | psycho.exe | "Added by the IRCFLOOD-O TROJAN!"
|
| X | ISPSERVICE | wintmp.exe | "Added by the IRCBOT.GP BACKDOOR!"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
|