| Y | Desktop Armor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| X | Desktop Defender 2010 | Desktop Defender 2010.exe | "Desktop Defender 2010 rogue security software - not recommended |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop Maestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | Desktop Maestro Vista Tray | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | Desktop Plant | AZARE10S.PLT | "Vritual plant from here - this version is an Azalea |
| X | Desktop Search | desktop.exe | "iSearch adware"
|
| X | Desktop Security 2010 | Desktop Security 2010.exe | "Desktop Security 2010 rogue security software - not recommended |
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THEWEA~1.EXE | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| Y | DesktopArmor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | DesktopIconToy | DesktopIconToy.exe | """Desktop Icon Toy is an easy to use desktop icon enhancement tool |
| U | DesktopMaestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | DesktopMaestro | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | desktopmgr | desktopmgr.exe | "Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | DesktopX | DESKTOPX.EXE | "A program that replaces the regular Desktop and Taskbar |
| N | deskup | deskup.exe | Adds Iomega Zip drive icons to the desktop
|
| U | desp2k | desp2k.exe | "Part of the Turbo Analyzer tool from LightComm Brazil Telecom that analyzes and corrects ADSL configurations"
|
| X | destroyb11 | destroyb11.exe | "Added by the DELF-KO TROJAN!"
|
| X | Deus Cleaner | DCleaner.exe | "Deus Cleaner rogue system cleaner utility - not recommended"
|
| X | devenv | smvss.exe | "Added by the DEDLER-G TROJAN!"
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Device IO System | deviceio.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Management | wnsystem.exe | "Added by the AGOBOT-LH WORM!"
|
| X | Device Security | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Driver | devicesec.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| U | DeviceDiscovery | hpotdd01.exe | "Detection of new imaging |
| U | Devices | olesvr.exe | "Salfeld Child Control - parental control software"
|
| X | DfqwSfS | ffsqsd.exe | "Added by the SDBOT-SH WORM!"
|
| X | dgtstart | dgtstart.exe | "DigitalNames.g adware"
|
| X | DHCP | smss.exe | "Added by the WINSPY.AG TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
|
| X | DHCP Server | regsvr.exe | "Added by the RBOT-PR WORM!"
|
| X | DHCP32 | services.exe | "Added by the WINSPY.AG TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\display"
|
| X | Diagnostic | diagnostic.exe | "Added by the ALPHA-C TROJAN!"
|
| X | Diagnostic Agent | diagent.exe | "Added by the AGOBOT-CW WORM!"
|
| X | Dialer | "rundll32.exe MSA32CHK.dll | Reg" |
| U | Dialgo SDK | PhoneAnswer.exe | "Dialgo Wave Modem ActiveX - ""Telephone Answering Machine for scripting your own professional call center business scripts using a voice modem. Features Caller-ID |
| N | Dialog Box Assistant | OSDEx.exe | "Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
|
| X | DIECOX | csrss.exe | "Added by a variant of the ATM.GEN TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Diesel | Recalculate.exe | "Added by the LAZAR TROJAN!"
|
| X | DigiD | DigitalSound.exe | Adware downloader
|
| U | Digisoft AntiDialer | AntiDialer.exe | "Digisoft AntiDialer"
|
| U | DigiSrv | DigiSrv.exe | "Related to camera software from DigitalDreams"
|
| N | Digital Dashboard | devgulp.exe | For Compaq PC's. Loads Digital Dashboard options
|
| X | DigitalNames | DigitalNamesStart.exe | "DigitalNames spyware variant"
|
| N | DigitalWizard | ISWizard.exe | "InstallShield's DigitalWizard - free |
| U | DIGServices | DIGServices | Created by Disney but licensed to ESPN for watching videos
|
| N | DIGServices | DIGServices.exe | Created by Disney but licensed to ESPN for watching videos
|
| N | DIGStream | digstream.exe | "DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
|
| U | Dimension | Dimension.exe | "Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames |
| U | Dimension4 | d4.exe | "Dimension 4 - network time synchronization freeware - starts-up |
| X | Dinst | dinst.exe | "IMIServer/IEPlugin adware"
|
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| Y | Directory Opus Desktop Dblclk | dopusrt.exe | "Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor |
| X | directs.exe | directs.exe | "Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | directx | Sqlexploit.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX Driver | stdhost.exe | "Added by the SDBOT.GVJ BACKDOOR!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX64 | DirectXset.exe | "Added by the BROWNEY.A WORM!"
|
| X | DirectX9 | svchost32.exe | "Added by the RBOT.AQG WORM!"
|
| ? | Disable EHCI | nousb20.exe | "??"
|
| X | DisableKeybaord | "Rundll32.exe Keyboard | Disable" |
| X | DisableMouse | "Rundll32.exe Mouse | Disable" |
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| ? | discoveg | discoveg.exe | "??"
|
| ? | DISCover | DISCover.exe | "Related to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?"
|
| N | DiscoverDeskshop | Deskshop.exe | "Discover Deskshop - single use ""virtual"" credit card"
|
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| X | Disk Check | chkdsk32.exe | "Added by the IM TROJAN!"
|
| U | Disk Cleaner | DiskCleaner.Exe | "Hard disk management part of TuneUp Utilities from TuneUp Distribution GmbH"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Essensial Tools | detsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | [path to trojan] | "Added by the SMALL-VE TROJAN!"
|
| X | Disk Keeper | SECURITY.EXE | "Daosearch adware"
|
| X | Disk Manager | diskver.exe | "Added by the RBOT.AQT WORM!"
|
| X | Disk Master | [trojan name] | "Added by the DISTER TROJAN! - a spam relayer"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | Disk Panel Setup | npcsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DiskCheck | msdarkend.exe | Added by an unidentified WORM or TROJAN!
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| X | diskinf | diskinf.exe | "Added by the CRYPTER.A TROJAN!"
|
| ? | DISKMON.EXE | DISKMON.EXE | "??"
|
| N | Disknag | disknag.exe | Dell program that reminds you to make your backup diskettes
|
| X | DiskRetter | SysRep.exe | "DiskRetter |
| X | Diskstart | Code.exe | Adult content dialler
|
| X | Diskstart | cat.exe | MS-Connect dialler
|
| X | Diskstart | hit.exe | Adult content dialler
|
| X | Diskstart | Snt.exe | Adult content dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| U | Disk_Monitor | Disk_Monitor.exe | "Multi-media |
| X | disnisa | disnisa.exe | "Added by the DORF-AE WORM!"
|
| X | Dispatcher | dispatcher.exe | "Added by the DLOADR-AS TROJAN!"
|
| X | dispenter | dispenter.exe | "Added by the AGENT-MKK TROJAN!"
|
| U | display | The_Eye.exe | "ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
|
| X | Display | backup.exe | "Added by the BRONTOK-CR WORM!"
|
| X | Display Drivers | cssrs.exe | "Added by the AGOBOT.FX WORM!"
|
| N | Display Settings | hptasks.exe | "Allows for the adjustment of the display for LCD screen |
| U | DisplayFusion | DisplayFusion.exe | "DisplayFusion from Binary Fortress Software - ""is a fantastic application that can make your dual monitor (or triple monitor or more) life much |
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| U | Disspy | disspy.exe | "Disspy spyware detection and removal software"
|
| X | Dist-FBGeneve | GDC.exe | "NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
|
| X | Distributed File System | Dfsvc.exe | "Added by the MYFIP.A or MYFIP.K WORMS!"
|
| X | Distributed File System | kernel32dll.exe | "Added by the MYFIP-C or MYFIP.K WORMS!"
|
| X | Distributed File System | blade.exe | "Added by the MYFIP.AC WORM!"
|
| X | Distributed File System | win.exe | "Added by the MYFIP.AB WORM!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| U | distributed.net client | DNETC.EXE | "Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
|
| N | DiTask.exe | DiTask.exe | "Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free |
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| X | djdsdvqwa | vjdhdg.exe | "Added by the SDBOT-EF BACKDOOR!"
|
| N | DJRegFix | regedit /s c:hpdjregfix.reg | "DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
|
| ? | DJSNetCN | DJSNetCN.exe | """Symantec Licensing Detect Internet Connection"" |
| Y | DkService | DkService.exe | "From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled |
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| N | dlbcserv | dlbcserv.exe | Related to Dell Photo Printers and provides additional configuration options for these devices
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| X | dlcipscl | dcpavss.exe | "Added by the MAILBOT-CB TROJAN!"
|
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| X | dlhost | dlhost.exe | "Added by the EXPHOOK-A TROJAN!"
|
| X | DLINK dfe drivers for Windows NT | windfe.exe | "Added by the RANDEX.AK WORM!"
|
| U | DLink System Tray | dlnetst.exe | "Related to D-Link DGE-530T PCI card for servers and workstations"
|
| X | Dll Boot Loader on Startup (do not remove this) | [various filenames] | Added by an unidentified TROJAN!
|
| X | Dll Link | svchoist.exe | "Added by the AUTOSKY WORM!"
|
| X | Dll Link | svchost.exe | "Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | dll services | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | DLL32 | dllhost.dll | "Added by the SUCLOVE.A WORM!"
|
| X | dllcvss | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | DLLHost | dllhst.exe | "Added by the DELBOT-AC WORM!"
|
| X | DllHost | dllhost.exe | "Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf"
|
| X | dllhostxp.exe | dllhostxp.exe | Browser hijacker and adware downloader
|
| X | DllLoader | lssas.exe | "Added by the BDOOR-JE BACKDOOR!"
|
| X | DLLService32 | dllsvc32.exe | "Added by the AGOBOT.VX WORM!"
|
| U | DLPSP | DLPSP.EXE | Dell laser printer status monitor
|
| X | dlsp2mx | dlsp2mx.exe | "Added by the MPB-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""dlsp2mx"""
|
| X | Dm Hr | lpns.exe | "Added by the IRCBOT.WORM.61673 WORM!"
|
| N | DMAScheduler | DMAScheduler.exe | "Related to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program |
| N | DMISL | DMISL.EXE | "DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
|
| N | DMISLAPP | DMISLAPP.exe | "DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information"
|
| X | Dmsvc32 | Dmsvc32.exe | "Added by the AGOBOT.ABU WORM!"
|
| X | dm[3 random letters].exe | dm[3 random letters].exe | "Added by the RUINDEM TROJAN!"
|
| X | DM_server | dmserver.exe | "Comet Cursor adware"
|
| X | dm_service | [path to file] | "Added by the MITGLIEDER.P TROJAN!"
|
| X | dnam | d140113.a.Stub.EXE | "Added by the STUB_A TROJAN!"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| X | DNS | mc-58-12-0000080.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000093.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-110-12-0000079.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000120.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | mc-58-12-0000140.exe | "Shorty adware - also detected as the AGENT.FD TROJAN!"
|
| X | DNS | [worm filename] | "Added by the BCKDR-CQG BACKDOOR!"
|
| X | DNS Config service | win32.exe | "Added by the RBOT-TL WORM!"
|
| X | Dns Resolver | dnsrslve.exe | "Added by the RBOT-WS WORM!"
|
| X | DNS Service | dnsresolver.exe | "Added by the RBOT-PQ WORM!"
|
| X | DNS Service | dnssvc.exe | "Added by the DELBOT-Z WORM!"
|
| ? | DNS2GoClient | dns2goclient.exe | "DNS2Go is a Domain Name System that will make your computer accessible anytime |
| N | DNS7reminder | Ereg.exe Ereg.ini | "Registration reminder for versions of Nuance (ScanSoft) Dragon NaturallySpeaking"
|
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | DNSCacheBoost | dnsping.exe | "Added by the DNSBUST-A TROJAN!"
|
| X | dnscleaner | dnscleaner.exe | "CoolWebSearch parasite variant"
|
| X | DNSE | DNSE.exe | "Part of rogue security tools |
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| X | Doggy Style | MsPMSPSd.exe | "Added by the SDBOT-AAP WORM!"
|
| X | DOGStart | GSDOGST.EXE | "Added by an unidentified VIRUS |
| X | DokterFix | SysRep.exe | "DokterFix |
| X | Domain Name Resolve Service | dnsresolver.exe | "Added by the KIMAN.A WORM!"
|
| X | DomPlayer Service | wakeservice.exe | "DomPlayer adware"
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| X | Dontworry | mysaym.exe | "Added by the SDBOT-RC WORM!"
|
| U | Dopus | dopus.exe | "Directory Opus - a file manager from GPSoft"
|
| N | DoroServer | DoroServer.exe | "Doro PDF Writer from The SZ Development. All what you need for creating pdf files"
|
| X | dos | dos64.exe | Adware downloader trojan
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| ? | Dosbat | ?? | "??"
|
| U | DoubleDesktop | dd.exe | """DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"""
|
| X | Dowmingzu | Dowmingzu.dll.vbs | "Added by the SOLOW-E WORM!"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | Download Plus | DownloadPlus.exe | "DownloadPlus adware"
|
| X | DownloadLegalMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | DownloadsAndMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | downs | downs.exe | "Added by the BCKDR-MNR TROJAN!"
|
| Y | DPAS | DPASNT.exe | "DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | DPASUpdate | DPASAutoUpdate.exe | "Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | Dpcstart | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| X | dpnsvr32 | dpnsvr32.exe | "Added by the AOLPASS-B TROJAN!"
|
| U | dpps2 | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| X | dps | dps.exe | "SmartestSearch parasite - poses as a foistware |
| X | DR service | [path to worm] | "Added by the RBOT-CZT WORM!"
|
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| X | DRam Monitor 23 | tskman3.exe | "Added by a variant of the RBOT WORM!"
|
| X | DRam prmaessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosesor | [random filename] | "Added by the SPYBOT.EE WORM!"
|
| X | DRam prosessor | [random filename] | "Added by the RBOT.CSG WORM!"
|
| X | DRam prosessor | plscd.exe | "Added by the RBOT.CYA WORM!"
|
| X | DRam prosessor | HWAPI.exe | "Added by a variant of the RBOT WORM! Note - this is not the McAfee HackerWatch process which has the same filename"
|
| X | DRam prosessor | WindowsUpdate.exe | "Added by the RBOT-BBZ WORM!"
|
| X | DRam prosessor | msupdate.exe | "Added by the DELF-FAW TROJAN!"
|
| X | DRam prosessor | winupl.exe | "Added by the RBOT-BCQ WORM!"
|
| X | DRan posessor | DAP.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrAntispy | DrAntispy.exe | "DrAntiSpy rogue security software - not recommended"
|
| X | DrCache | MSTDC.EXE | "Added by the BDOOR-JM BACKDOOR!"
|
| X | dreams | server.exe | "Added by a variant of the SDBOT WORM!"
|
| X | DrefIW | SysDrefIWv2.exe | "Added by the DREF-C WORM!"
|
| X | DrefIW | SysDref.exe | "Added by the DREF-D WORM!"
|
| N | DrgToDsc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| U | DriveIcons | DriveIcon.exe | "Drive Icons from Realtek - shows a specific icon for each card type for their card reader controllers"
|
| X | Driver32 | Scam32.exe | "Added by the SIRCAM WORM!"
|
| X | DriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | DriverDB | svcmdx32.exe | "Added by the BERPI TROJAN!"
|
| X | DriverLoad | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| U | DriverMagicLogon | dmschedule.exe | "Part of DriverMagic - ""the easiest way to locate device drivers"""
|
| N | DriverMax | devices.exe | "DriverMax from Innovative Solutions - ""a new tool that allows you to download the latest driver updates for your computer. No more searching for rare drivers on discs or on the web or inserting one installation CD after the other"""
|
| X | DriverModule | csrnvrt.exe | "Added by the IRCBOT.I TROJAN!"
|
| X | DriverPath | system32.exe | "Added by the PRORAT-S TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| X | Drives swap | AV1i.exe | "Anti-Virus Number-1 rogue security software - not recommended |
| N | DriveSelect | driveselect.exe | "DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
|
| X | DriveSystem | maxpaynowti1.exe | "Added by the TIBS.AZT TROJAN!"
|
| U | dRMON SmartAgent | SmartAgt.exe | "Part of the network monitoring program group for 3Com NIC cards. See here for more info"
|
| X | drmsrv32 | stmhosts.exe | "Added by the AGENT.AGWU TROJAN!"
|
| X | Drmupgds | Drmupgds.exe | "Maxfiles adware"
|
| X | DropSpam Lifestyle | dslifestyle.exe | "Dropspam adware"
|
| ? | DrvListnr | DrvListnr.exe | "Analog Devices SoundMAX soundcard related. What does it do and is it required?"
|
| U | drvlsnr | drvlsnr.exe | Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
|
| X | DrvStart | HPMedia.exe | "Added by the BANCBAN-QE TROJAN!"
|
| X | drvsys.exe | drvsys.exe | "Added by the BEAGLE.W WORM!"
|
| X | drvsyskit | hidr.exe | "Added by the BAGLE.HR WORM!"
|
| X | drvsyskit | hldrrr.exe | "Added by the BAGLE.QU TROJAN!"
|
| X | drv_st_key | hidn.exe | "Added by the BEAGLE.FF WORM!"
|
| X | DrWatson | drwatson_.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWatson | drwatson_32.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWeb Antivirus | DRWEBAV.EXE | Added by an unidentified WORM or TROJAN!
|
| Y | Drwebscheduler | Drwebscd.exe | "DrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications |
| X | DR_S | DR_S.exe | "IstBar adware"
|
| X | ds | ds.exe | "Added by the SPYMON TROJAN!"
|
| U | DS Clock | dsclock.exe | "Digital desktop clock including synchronization with atomic servers - see here"
|
| X | dS35DLL | ffqca.exe | "Added by the SDBOT-KV WORM!"
|
| X | dsa | dsa.exe | Homepage hijacker - redirecting to downseek.com
|
| X | DSAcass | [path to file] | "Added by the RANKY.M TROJAN!"
|
| X | dsadlsa14 | dsakfsak14.exe | "Added by the ONLINEG-P TROJAN!"
|
| X | DSB | DSB.exe | "EnergyPlugin adware"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| X | dsd | zz.exe | "Added by the RBOT-FOX WORM!"
|
| N | DSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| X | dsfghjgj | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | dsgb | lcsass.exe | "Added by the AGENT.TGZ BACKDOOR!"
|
| X | Dsi | dp-******.exe | Added by an unidentified adware where ****** are random characters
|
| X | Dsi | dp-him.exe | "Added by the MULTIDR-AH TROJAN!"
|
| X | Dskcompat | Dskcompat.exe | "Added by the GEMA TROJAN!"
|
| U | DSKEY | DsKey.exe | "Part of PC PhoneHome - ""secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection"". Security software from Brigadoon Security Group for tracking down lost/stolen computers"
|
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| Y | DSLagentexe | DSLagent.exe | "Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
|
| Y | dslmon | dslmon.exe | Sagem DSL modem related. Apparently needed to detect the modem
|
| U | DSLSTATEXE | dslstat.exe | System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
|
| X | DsmSer | dsm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | svosm.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsmSer | sysup.exe | "Added by the SERFLOG.B WORM!"
|
| Y | DSndUp | DSndUp.exe | "Utility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used on"
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | DSS | dssagent.exe | "Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| X | DSService | dmrss.exe | "Added by the AGOBOT-XX WORM!"
|
| ? | DSSSGENS | dssagens.exe | "??"
|
| X | dstiosys | plsitctl.exe | "Added by the MAILBOT-BX TROJAN!"
|
| X | DSystemDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT 11Mbps WLAN USB Station | DTUSBMonitor.exe | 11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT Task | DTHtml.exe | "Display Tune from Portrait Displays |
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Dulux WeatherShield WeatherDesk | weather.exe | "Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
|
| X | Dumeter Services | dumeter.exe | "Added by the SDBOT-AEQ WORM!"
|
| X | dumprep | spoolc.exe | "Detected by Kaspersky as a variant of the AGENT.CXF TROJAN!"
|
| X | DUN_SERVICES3 | dun3.exe | "Added by the SOKIRON TROJAN!"
|
| X | Duwee wong Cerbon | Cirebons.exe | "Added by the BHARAT.A WORM!"
|
| X | DVAScvssdfa | AsSDdwd.exe | "Added by the LIOTEN.IP TROJAN!"
|
| N | DVD@ccess | DVDAccess.exe | "Part of DVD Studio Pro from Apple Inc. - ""The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"""
|
| U | DVDBitSet | DVDBitSet.exe | DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
|
| N | DVDSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| N | DVDXGhost | DVDGhost.EXE | "DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free |
| X | dvsfss | fbsfsdrs.exe | "Added by the SDBOT-QA WORM!"
|
| U | DVSync | dvsync.exe | DVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PC
|
| X | Dvx | wsxsvc.exe | "Delfin Media Viewer or ""Promulgate"" adware variant"
|
| N | DW4 | DesktopWeather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW6 | DesktopWeather.exe | "Desktop Weather 6 by The Weather Channel - provides current temperature |
| N | DwlClient | support.exe | Download manager for Dell support alerts
|
| X | dwqblwrsq.exe | [random].exe | "Okcashbackmall adware"
|
| N | dwStart | FireWall.exe | "The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
|
| X | DW_Start | rwwnw64d.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| X | Dx | sys*.exe [* = random number] | "Added by the DEXTER.A WORM!"
|
| X | dxdiag diagnose | msidxdia.exe | "Added by a variant of the RBOT WORM!"
|
| X | dxdiags.exe | dxdiags.exe | "Added by the CERTIF-G TROJAN!"
|
| X | dxmsrv | dxmsrv.exe | Added by an unidentified WORM or TROJAN!
|
| X | Dxsty | Dxsty.exe | "Added by the GEMA TROJAN!"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| X | Dynamic Dns Binary | CMD16.EXE | "Added by the RBOT-XM WORM!"
|
| X | Dynamic Dns Binary | winxp34.exe | "Added by a variant of the RBOT WORM!"
|
| X | Dynamic Dns Binary | WinHelpcfn.exe | "Added by a variant of the RBOT WORM!"
|
| U | DynDNS Updater | DynDNS.exe | "Dynamic DNS IP address updater tool |
| N | DynDNS-Updater Traytool | ddutray.exe | "DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
|
| X | DynHttp Dns Binary | dynizari.exe | "Added by a variant of the RBOT WORM!"
|
| U | DynSite | DynSite.exe | "DynSite - dynamic DNS client |
| U | Dynu Basic Client | dynubas.exe | "Dynu online dynamic IP update client. Useful when using a dial up modem"
|
| ? | DZKillMe | DZSAVEME.EXE | "??"
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| X | E-nrgyPlus | E-nrgyPlus.exe | "Energyplus - tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site"
|
| U | e-Surveiller Station | estation.exe | "ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
|
| N | E6TaskPanel | TaskPanl.exe | "Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet |
| U | eabconfg.cpl | EabServr.exe | Easy Access Buttons control panel on Compaq laptops. Only required if you use the extra keys
|
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| Y | EAFRCliStart | EAFRCliStart.exe | "Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
|
| U | eanthology_install.exe | eanthology_install.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| N | Eapcisetup | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it
|
| N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
|
| N | Easy CD Creator | RoxAssist.exe | "Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize |
| U | Easy Key | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
|
| N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| X | EasyAV | EasyAV.exe | "Added by the NETSKY.S or NETSKY.T WORMS!"
|
| X | EasyDates | EasyDates.exe | Premium rate adult content dialler
|
| X | EasyDates_gb | EasyDates_gb.exe | """Edate-A"" premium rate adult content dialler"
|
| X | EasyDates_nl | EasyDates_nl.exe | Adult content dialler
|
| U | EasyKey | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used
|
| U | EasyKeyboardLogger | EasyKeyboardLogger.exe | "EasyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| U | EasyLinkAdvisor | LinksysAgent.exe | "Linksys EasyLink Advisor - ""the free application that provides and easy way to setup |
| X | EasyMessage | em2.exe | "180solutions adware"
|
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader
|
| X | easyServ | Server.exe | "Added by the EASYSERV TROJAN!"
|
| X | EasySpywareCleaner | EasySpywareCleaner.exe | "EasySpywareCleaner rogue spyware remover - not recommended |
| U | EasySync Pro | XCPCMenu.exe | """IBM® Lotus® EasySync® Pro is a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasyTuneIII | EasyTune.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneV | GUI.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| X | easywww | easywww2.exe | "Added by an unidentified VIRUS |
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | "Ebates adware"
|
| X | ebmmm | ebatesmmmv.exe | "Ebates adware"
|
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| ? | EDFcsn | discfcsn.exe | "Related to Hewlett-Packard's Discovery Agent. What does it do and is it required?"
|
| U | EDRestore | ?? | "Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
|
| X | EDxMC110 | Isass.exe | "Added by the VB-NIA WORM!"
|
| X | Edzy AntiVirus | dppsfa.exe | "Added by a variant of the RBOT WORM!"
|
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| X | efaxs lptt01 | efaxs.exe | "RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | efaxs ml097e | efaxs.exe | "RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| U | EFI Hot Folders | hffw.exe | """EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select |
| N | EgisTecLiveUpdate | EgisUpdate.exe | "Software updater for biometric and data encryption products from EgisTec Inc"
|
| X | ehSched | ehSched.exe | "Added by the SDBOT-DHF WORM!"
|
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eKerberos | eKerberos.exe | "eKerberos rogue security software - not recommended"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| X | ELNKProxy | smproxy.exe | "Surfmonkey adware"
|
| U | ELSA WINman Suite | Winmsuit.exe | "Allows you to totally customize your ELSA graphics card settings |
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| U | ELSBLaunch | ELSBLaunch.exe | "EarthLink SpamBlocker"
|
| U | eMachines eBoard | Eboard.exe | eMachines multimedia keyboard manager. Required if you use the extra keys
|
| Y | EmailScan | mcvsescn.exe | Related to McAfee AntiVirus suite - used to automatically scan incoming e-mails
|
| X | eMakeSV | EMAKESV.EXE | """Switch"" adult content dialer"
|
| X | eMakeSV | EMAKE2B.EXE | """Switch"" adult content dialer"
|
| U | EMBASSY Trust Suite Secure Update | AutoUpdate.exe | "Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| X | eMessenger | emsn.exe | "Added by the RBOT.AHO BACKDOOR!"
|
| U | Emouse | Emouse.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| X | empin | e121307.Stub.exe | "Delfin Media Viewer adware related"
|
| Y | Emsisoft Anti-Malware | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
| X | emsw.exe | emsw.exe | "Attune HelpExpress - spyware. Disable and uninstall - see here"
|
| N | eMuleAutoStart | emule.exe | "eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project |
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| X | enBrowser | [name of file] | "WINBO adware"
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| ? | ENCSurf | surfboard.exe | "??"
|
| N | Energizer FileSaver | Energizer FileSaver.exe | "Energizer FileSaver - UPS back-up utility for Energizer UPS products. From their Tech Support staff this is known to have a memory leak since it's release - with no fix planned! It will grab 2-5 handles per second and crash the average system in less than 3 days - therefore not recommended"
|
| U | enginecs2 | enginecs2.exe | "Cyber Sentinel - internet filtering software"
|
| N | EnigmaPopupStop | EnigmaPopupStop.exe | "Part of Enigma SpyHunter - not recommended |
| ? | ENSApServer2_0 | APSERVER.EXE | "Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
|
| ? | ENSMIX32.EXE | ENSMIX32.EXE | "Sound card driver. Is it required?"
|
| U | EnsoniqMixer | starter.exe | "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
|
| U | Entbloess 2 | Entbloess2.exe | "Related to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Exposé |
| U | Enterprise Harmony | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| U | Enterprise Harmony '99 | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| U | EPGServiceTool | EPGClient.exe | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | EPGServiceTool | EPGCLI~1.EXE | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | EPoXUSDM | USDM.EXE | "EPoX Universal Serial Data Monitor - a diagnostics tool that shows Temps |
| N | ePrint 3.0 Service | EPRINT3.EXE | "LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF |
| N | ePrint 4.0 Service | EPRINT4.EXE | "A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF |
| N | EPS | e_srcv02.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| N | EPS | e_srcv03.exe | "According to the Epson info: ""Use this utility to automatically check for errors and also check the level of ink remaining."" This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check"
|
| X | Epsilon Squared | vmmreg32.exe | "Added by the AGENT.MVC TROJAN!"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| U | EPSON Status Monitor 3 | E_[various].EXE | "Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C40 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status |
| U | EPSON Stylus C41 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status |
| U | EPSON Stylus C42 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S08IC1.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C44 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | EPSON Stylus C45 Series | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
| U | EPSON Stylus C46 Series | E_S4I0T1.EXE | "Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status |
| U | EPSON Stylus C48 Series | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
| U | EPSON Stylus C60 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
| U | EPSON Stylus C61 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status |
| U | Epson Stylus C62 Series | E-S0BIC1.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C62 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C63 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C66 Series | E_S4I0S2.EXE | "Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | Epson Stylus C82 Series | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C82 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3100 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status |
| U | EPSON Stylus CX3200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5400 | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus D68 Series | E_FATIAAE.EXE | "Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status |
| U | EPSON Stylus D78 Series | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
| U | EPSON Stylus D88 Series | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4000 Series | E_FATIBEE.EXE | "Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4800 Series | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX5000 Series | E_FATIBVE.EXE | "Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX6000 Series | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7000F Series | E_FATIBKE.EXE | "Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 1400 Series | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 2200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status |
| U | EPSON Stylus Photo 825 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status |
| U | EPSON Stylus Photo 925 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status |
| U | EPSON Stylus Photo R1800 | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
| U | EPSON Stylus Photo R200 Series | E_S4I0H2.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_S6I2I1.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R240 Series | E_FATIAHE.EXE | "Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R260 Series | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I0F2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R320 Series | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R340 Series | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R380 Series | E_FATIBOA.EXE | "Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R800 | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX500 | E_S4I2K1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX530 Series | E_FATIAGP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX600 | E_S4I2M1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX640 Series | E_FATIAME.EXE | "Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX700 Series | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
| U | EPSON Stylus Pro 4000 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status |
| U | EPSON Stylus Pro 7600 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
| U | EPSON Stylus SX200 Series | E_FATIEFE.EXE | "Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status |
| U | EPSON SX100 Series | E_FATIEDE.EXE | "Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status |
| U | EPSON TX100 Series | E_FATIEDP.EXE | "Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this
|
| X | eraseplg | eraseplg.exe | "Added by the GENOME.AQUV TROJAN!"
|
| U | Eraser | eraser.exe | "Eraser - ""an advanced security tool for Windows which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns"". This entry starts the Scheduler with Windows and provides a System Tray icon for on-demand access. Located in %ProgramFiles%\Eraser"
|
| U | eraser | eraser.exe | "Part of Evidence Exterminator |
| U | eraser.exe | eraser.exe | "Part of Evidence Exterminator |
| Y | eRecoveryService | check.exe | "Now part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | Monitor.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | eros.exe | eros.exe | Adult content dailler
|
| X | ErrClean | SysRep.exe | "ErrClean rogue system error and cleaning utility - not recommended. There are number of variants in this family sharing the same filename and user interface - see here"
|
| X | ErreurChasseur | SysRep.exe | "ErreurChasseur |
| X | Error Safe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | Error Safe Free | uers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafe | ers.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ErrorSafeFree | UERS.exe | "ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ERS | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERScw | ERScw.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_Check | uwasers.exe | "Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended"
|
| X | erthgdr | svc.exe | "Added by the BEAGLE.BN or BEAGLE.BP WORM!"
|
| X | erthgdr2 | svc23.exe | "Added by the BAGLE.CG WORM!"
|
| ? | ERTS0749 | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| U | ESB | esb.exe | Easy Start Button - provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Scheduler | avkserv.exe | "MicroWorld eScan antivirus scheduler"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| X | EScorcher | escorcher.exe | "Part of eScorcher anti-virus software - responsible for performing virus checks and deletions. Used to collect information about the user and therefore treated as spyware - now the web-site is dead"
|
| N | ESFTP | esftp.exe | "ESftp - FTP client for transfering files between a local PC and another remote computer"
|
| U | eSnips | ClientGW.exe | "eSnips Client Gateway from eSnips"
|
| X | Esoh | Esoh123.exe | "Added by the AGOBOT.FF WORM!"
|
| X | Especial | Deneca.bat | "Added by the DELUZ VIRUS!"
|
| X | Esph | ortu.exe | "PurityScan adware"
|
| N | ESPN BottomLine | bline.exe | "ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop |
| ? | ESS Daemon | Essd.exe | "Related to an ESS based soundacard. Is it required?"
|
| ? | essapm | essapm.exe | "ESS Solo soundcard driver. Is it required?"
|
| Y | Essdc | essdc.exe | Related to an ESS Solo soundcard. Seems as though it's required
|
| ? | ESSNDSYS | ESSNDSYS.EXE | "Related to an ESS based soundacard. Is it required?"
|
| Y | ESSOLO | ESSOLO.exe | Sound card driver that re-instates itself every time it's removed
|
| Y | esspk | esspk.exe | ESS Technology modem speaker driver file. Required to get on-line with this modem
|
| U | EssSpkPhone | essspk.exe | "ESS Technologies Call waiting |
| ? | eSupInit | eSupCmd.exe | "Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
|
| X | Esutityde | osutityde.exe | "Added by the SDBOT.BQD WORM!"
|
| X | ETB Tester | etbtest.exe | "Added by the RBOT-ABR WORM!"
|
| X | ethernet | msnger.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msftp.exe | "Added by the SDBOT.BXJ WORM!"
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Driver | cmsrrs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Drivers | smrrs.exe | "Added by the RBOT-AAK WORM!"
|
| X | Ethernet Drivers | ethernet.exe | "Added by the GAOBOT.CEZ WORM!"
|
| Y | eTrust EZ Firewall | efpeadm.exe | "eTrust EZ Firewall"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| X | eTrust Realtime Monitor | realmon.exe | "Added by the LAZAR.B TROJAN!"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | EUP Service | eupsvc.exe | "Added by the DELBOT-Q WORM!"
|
| N | Event Planner Reminders | PLNRNote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| X | EventApplicationCmd | smschk.exe | "Added by the IRCBOT-AO TROJAN!"
|
| U | EVENTLISTENER | EvLstnr.exe | Used with a Nikon digital camera to recognize when the camera is plugged in
|
| ? | EverioService | EverioService.exe | "Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
|
| U | EVGAPrecision | EVGAPrecision.exe | "EVGA Precision overclocking utility - ""allows you to fine tune your EVGA graphics card for the maximum performance possible |
| N | evntsvc | evntsc.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| U | EVOLOSTA | EVOLOSTA.EXE | "Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID |
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| U | EvtMgr6 | Setpoint.exe | "Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| U | EW Message Server | msg32.exe | Conexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
|
| N | eWare Startup | iWareStart.exe | "eWare iWare task bar. Not required"
|
| Y | ewido anti-spyware | ewido.exe | "System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
| X | Ewth | tasn.exe | "PurityScan adware"
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| N | ExciteAssistantEXE | ASSISTANT.EXE | "With Excite Assistant |
| X | ExecUser | ExecUser.exe | "Added by a variant of the RBOT WORM!"
|
| ? | Execute | delfolders.exe | "??"
|
| X | ExeName32 | Warm.scr | "Added by the SCOLD WORM!"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| ? | exgiwsl | exgiwsl.exe | "??"
|
| X | ExpertAntivirus | ExpertAntivirus.exe | "ExpertAntivirus rogue security software - not recommended |
| X | Expl0rer soft | expl0rer.pif | "Added by the RBOT-AQR WORM!"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | shellexpl.exe | "Added by the SHELDOR TROJAN!"
|
| X | Explorer | shellexp.exe | "Added by the AGENT-ZY TROJAN!"
|
| X | EXPLORER | sys.exe | "Added by the SILLYFDC-A TROJAN!"
|
| X | explorer | Yinstall.exe | "PurityScan/Clickspring adware"
|
| X | Explorer | Windows Explorer.exe | "Added by the SILLYFDC-I WORM!"
|
| X | Explorer | explorar.vbs | "Added by the DESKTO-A WORM!"
|
| X | explorer | system.exe | "Added by the AGENT-FI TROJAN!"
|
| X | Explorer | msrstart.exe | "Added by the SOPICLICK TROJAN!"
|
| X | EXPLORER MICROSOFT SYSTEM | explore.exe | "Added by a variant of the RBOT WORM!"
|
| X | Explorer soft | explorer.pif | "Added by the RBOT-APK WORM!"
|
| X | Explorer soft | explorer.com | "Added by the RBOT-ARM WORM!"
|
| X | Explorer.exe | csrss.exe | "Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
|
| X | Explorer32 | explorer6s4.exe | Added by the Downloader.Win32.Small.biq TROJAN!
|
| X | Explorer32 | efsdfgxg.exe | "Added by the CLICKER-Y TROJAN!"
|
| X | ExplorerTask | explorer.exe | "Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
|
| X | ExploreUpdSched | [random filename] | "ZenoSearch adware"
|
| X | exporet | winset.exe | "Added by the QQPASS-I TROJAN!"
|
| U | Express ClickYes | ClickYes.exe | """Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt |
| U | Exshow95 | EXSHOW95.exe | Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
|
| N | Extender Resource Monitor | RMSysTry.exe | "Related to Windows Media Center from Microsoft"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| X | Extra Antivirus | ExtraAV.exe | "Extra Antivirus rogue security software - not recommended |
| U | ExtraDNS | ExtraDNS.exe | "ExtraDNS - DNS configuration tool"
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| N | EZDesk | EZDESK.EXE | "Utility that remembers icon locations for each user and resolution. Available here"
|
| Y | ezPS_Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezPS_Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
|
| U | E_S10IC2 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | E_S23 | E_SICN03.exe | "Epson printer status monitor - for checking ink levels |
| U | E_S4I2F1 | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | E_S4I2G1 | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status |
| U | E_SOEIC1 | E_SOEIC1.exe | "Epson Status Monitor 3 - for monitoring printer status |
| U | E_S[numbers] | [path] E_[various].EXE [path] E_S[numbers].tmp | "Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure 2005 | svchost.exe | "Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| Y | F-Secure 2006 | fspex.exe | "F-Secure Anti-Virus automatic updater"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Manager | FSM32.EXE | "F-Secure antivirus - carry out scheduled virus scans automatically"
|
| Y | F-Secure Startup Wizard | FSSW.EXE | "F-Secure antivirus"
|
| Y | F-Secure TNB | TNBUtil.exe | "F-Secure antivirus"
|
| Y | F-StopW | F-StopW.exe | "F-Prot anti-virus background scanner by F-Risk Software"
|
| ? | f23mxins | f23mxins | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | f2install.exe | f2install.exe | "Added by the IEFEAT-I TROJAN!"
|
| X | f73cdc8ee94e | btsendto.exe | Associated with mysearchnow.com/searchbar.html
|
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | "Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink |
| X | FaltCheck | allps.exe | "Added by the AGENT.RAP TROJAN!"
|
| U | FamilyKeyLogger | cisvc.exe | "Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %ProgramFiles%\FamilyKeyLogger"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| X | farkrish | farkrish.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | Fash | Fash.exe | Unidentified adware
|
| X | faslkakj11 | kjgagklj11.exe | "Added by the LEGMIE-ARE TROJAN!"
|
| N | fast | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | fast | A-fast.exe | "A-fast Antivirus rogue security software - not recommended |
| X | Fast Antivirus 2009 | FastAV.exe | "Fast Antivirus rogue security software - not recommended |
| N | FAST Defrag | FAST2.EXE | "FastDefrag defragmenting software"
|
| X | Fast Home | svcnvt.exe | "Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines |
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | Ntut.exe | "Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
|
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| U | FastCache | fc.exe | "FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | fastsmell | fastsmell.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | FastStart | ntnut32.exe | "Added by the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| N | FastTrack Accelerator | SPEED UP.EXE | "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop |
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| U | FastTVSync | FastTVSync.exe | "Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps |
| N | FastUser | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| N | FastUsr | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | Fat32 Microsoft | fat32.exe | "Added by the RBOT-EL WORM!"
|
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| ? | FBI | FBISM.exe | "Compaq related but what does it do?"
|
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSearch | SearchGuardPlus.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | FBSSA | ie3sh.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | FDD SYSTEM | Fdd.exe | "Added by the MYTOB-FO WORM!"
|
| X | Fdr Command Module | sp2.exe | "Added by the SDBOT.WP WORM!"
|
| U | FD_SAP | FD.exe | Reported to be the autopassword program from the Sony Microvault thumb drive
|
| X | fegoze | SVCH0ST.EXE | "Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
| U | Fellowes Proxy | R3proxy.exe | Installed with Fellowes EasyPoint mouse software. Not necessary for normal functioning of Fellowes mice but it is necessary to use the extended features of all Fellowes mice
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| X | ff | svhost32.exe | "Added by the LINEAG-AFF TROJAN!"
|
| X | ffeqfqs | dqddss.exe | "Added by the SDBOT-SG WORM!"
|
| X | ffeqOME | vcvsav.exe | "Added by the RANKY.AB TROJAN!"
|
| X | ffis | ffisearch.exe | "iSearch adware"
|
| Y | ffprsrv | ffprsrv.exe | "File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled |
| Y | ffprsrv.exe | ffprsrv.exe | "File and Folder Privacy - is a ""system security utility you can use to password-protect or hide your files and folders with a click of mouse. The program will always prompt to enter your access password when protection is enabled and a user is trying to access a protected file or folder"". If this entry is disabled |
| Y | ffpsrv | ffpsrv.exe | "File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders |
| Y | ffpsrv.exe | ffpsrv.exe | "File & Folder Protector - ""great easy-to-use password-protected security utility lets you password-protect certain files and folders |
| ? | fgl23DoubleScreenHooks | f23happ.exe | "Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
|
| X | FHPage | shdochp.exe | "Added by the WINHOUND TROJAN!"
|
| X | FHStart | shdocsvc.exe | "Added by the WINHOUND TROJAN!"
|
| U | Fhtisxk | fhtisxk.exe | XtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
|
| U | FieldForms Sync | SyncService.exe | "Resco FieldForms. A solution for building of mobile forms that can be viewed or filled in on the run |
| X | FiendlyType | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| ? | file indexing service | msfindfile.exe | "New version of MS FindFast and still a resource hog?"
|
| X | File Mapping Services | hp-1003.exe | "Added by the RBOT.FAN WORM!"
|
| X | File System | taskmqrs.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | File System | taskmqr.exe | "Added by the RBOT.BWQ WORM!"
|
| X | File System Service | wmiprvsc.exe | "Added by the AGOBOT-HZ TROJAN!"
|
| X | File-Sharing Wizard | shwizard.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | filename process | kerneldll.exe | "Added by the AGOBOT-PO WORM!"
|
| X | filename process | explore.exe | "Added by the AGOBOT-QN WORM!"
|
| X | filename process | Rundil16.exe | "Added by the GAOBOT.ZX WORM!"
|
| X | Files Driver | sdphost.exe | "Added by the SDBOT-DKZ WORM!"
|
| X | Files Driver | sfdhost.exe | "Added by the AGOBOT-AJC BACKDOOR!"
|
| X | FileSoft | Wscript.exe UpdataFiles.vbs | "Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
|
| U | FilmLoop | FilmLoopService.exe | "Related to FilmLoop - a photocasting network. Share your pictures with your family and friends"
|
| N | Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
|
| Y | Find Virus Launch Program | fvlaunch.exe | "Part of Dr. Solomon's Antivirus"
|
| X | findfast | findfast.exe | "Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
|
| X | findfast.exe | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| N | FineReader7NewsReaderPro | AbbyyNewsReader.exe | "ABBYY FineReader OCR software - version 7"
|
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
|
| X | Fire Wall services | [random filename] | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Wall services | wnlmzsfhobi.exe | "Added by the IRCBOT-QY WORM!"
|
| X | Fire Well service | [random].exe | "Added by the RBOT-FJU WORM!"
|
| X | FireFox Service Drivers | ssmss.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireFox Startup Drivers | wuaclt.exe | "Added by the RBOT.BYX WORM!"
|
| X | FiresWallservices | [random].exe | "Added by the RBOT-FJT WORM!"
|
| X | Firevall Administrating | rndll.exe | "Added by the PUSHBOT-B WORM!"
|
| X | Firewall | SP2 UPDATE.exe | "Added by the ELITPER.E WORM!"
|
| X | firewall | spoolsv.exe | "Added by the DIZAN.F VIRUS!"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Firewall auto setup | [path to trojan] | "Added by the AGENT-GLY TROJAN!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | Firewall Update System1 | WinedowsUpdater1.exe | "Added by the RBOT-ARU WORM!"
|
| X | Firewall Updater | msnupdateit.exe | "Added by the RBOT-AAQ WORM!"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| U | FirewallStartup | Firewallstartup.exe | "Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean |
| X | FirewallSvr | FirewallSvr.exe | "Added by the NETSKY.X or NETSKY.Y WORMS!"
|
| X | FireWire Driver | samx.exe | "Added by the SDBOT.AE WORM!"
|
| X | FireWire Service | nvscv32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | FireWire Services | nvcsv32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| ? | First Principle Group | fpg.exe | "Related to the E-Players Card from First Principle Group"
|
| X | FIX | WinFIX1.0.vbs | "Added by the GORMLEZ-A WORM!"
|
| Y | Fix-it | mxtask.exe | "Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard |
| X | fjdslssdfd | mat2.exe | "Added by the SLAPEW.C TROJAN!"
|
| U | FJTWAIN Setup | FjtwSetup.exe | Fujitsu scanner utility
|
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop
|
| X | FKS v2.0 | msngr.exe | Added by an unidentified WORM or TROJAN!
|
| N | fkSysMon | fksysmon.exe | "fkWrae SysMon - system monitor - ""displays the current memory consumption |
| X | Flash Driver | [path to trojan] | "Added by the AGENT.CWVT TROJAN!"
|
| X | Flash Media | %%%%%.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | %%%.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | [path to trojan] | "Added by the IRCBOT.AUR TROJAN!"
|
| X | Flash Media | ^ ^^^ %% % ^% ^%%^ %^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^^% ^ %%% %^%%%^%%^%^% % ^^%% % %^^^^ ^%%^%% .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^^^^^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | ^^^^^^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Flash Media | services.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Flash Media | zrpk��'�'%''msn'�%'fix''.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | % ^% ^^^ %^% %% ^ ^ %%% ^% %^ % %^^.exe | "Added by a variant of the IRCBOT BACKDOOR! Note the space at the beginning of the filename"
|
| X | Flash Media | ^%%^%%%^% %^ ^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %^^%^^% %^^^^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | ^%^^^%% ^ ^ %^^^^^ %^ ^%^^ ^%^^^^^ %^ ^^^%^%%.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %^% ^ %^%% ^ % ^%%^^ %^^%^%^ ^%% %^.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | %%%%%%^^ ^ .exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Flash Media | skxs��'�'%''msn'�%'fix''.exe | "Added by the AGENT.ZOY TROJAN!"
|
| X | Flash Media | ^ %%^%^%.exe | "Added by the FLUSH.A TROJAN! Note the space at the beginning of the filename"
|
| X | Flash Media | %% % ^^ % %% ^%^^ ^^^ % ^%% ^ ^.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note the space at the beginning of the filename"
|
| X | Flash Media | ^ ^ % ^ % % ^ ^ ^%% ^% %%^^.exe | "Added by the IRCBOT.BAW BACKDOOR!"
|
| X | Flash Player2 | [path to worm] | "Added by the IRCBOT.PD WORM!"
|
| ? | FLASH32 | #NAME? | "??"
|
| X | Flash32 | FLASH32.COM | "Added by the STARTER-F TROJAN!"
|
| U | FlashEnc | FlashEnc.exe | "Supplied with EasyDisk USB pen devices. The utility manages the encryption and compressed folders options. It will create these folders if running on the USB key without permission |
| N | Flashget | FlashGet.exe | "FlashGet download manager"
|
| X | Flashget Download Manager | Flashget.exe | "Added by the RBOT-AGZ WORM!"
|
| X | FlashGuard | FlashGuard.exe | "Added by the AUTOIT.AL WORM!"
|
| U | FlashMute | FlashMute.exe | """FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively |
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| X | Flashy Bot | Flashy.exe | "Added by the GLUPZY.A WORM!"
|
| X | Flash_Player_Install | ying.exe | "Constructor VC2000 malware"
|
| U | FLMBROWSERMOUSE | mouse32A.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMLABTECMOUSE | mouse32A.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMMEDIONMOUSE | mouse32a.exe | Mouse utility for a Medion branded Fellowes mouse
|
| U | FLMOFFICE4DMOUSE | moffice.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMOFFICE4DMOUSE | mouse32a.exe | Mouse utility for a Micro Innovations brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | Floppy Master | [path to trojan] | "Added by the ZONIT-F TROJAN!"
|
| X | flps | flps.vbs | "Added by the BYRON WORM!"
|
| ? | FLSVCI | FLSVCI.exe | "??"
|
| Y | FltProcess | msinet.exe | "Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
|
| X | FlyswatDesktop | flydesk.exe | Advertising spyware
|
| X | fmnwebassist | fmnwebassist.exe | Adware popup generator
|
| U | FMStart | Fmstart.exe | "GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks |
| X | FMSZ | fmsz.exe | "Added by the FMSZ TROJAN!"
|
| X | fnmwebassist | fnmwebassist.exe | "WinPL adware"
|
| ? | Focus | Focus.exe | "ISDN configuration wizard?"
|
| X | Folder Service | wssdtu.exe | "Added by the MANIFEST TROJAN!"
|
| U | FolderShare | FolderShare.exe | """FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
|
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
|
| X | FontsLoader | ldfnt32.hta | Unidentified malware
|
| Y | FoolProofSweep | ?? | "Part of FoolProof Security PC security software from SmartStuff"
|
| N | Forbes | ForbesAlerts.exe | Forbes Business News Alerts - displays business news headlines in a little window on the screen
|
| X | ForceShow | "rundll32.exe QaBar.dll | ForceShowBar" |
| U | Fortis Secure Layer Config | cseinst.exe | Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
|
| X | fotos | fotos.exe | "Added by the BANKER-FP TROJAN!"
|
| N | FotoStation Easy AutoLaunch | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
|
| X | foxwudy9912 | service.exe | "Added by the BANCOS-BT TROJAN!"
|
| N | fpassist | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| N | Fpx | mnmsrvc.exe | Remote Desktop Sharing service part of Microsoft's Netmeeting allowing users to share items on their screens across remote locations
|
| X | fqor | stub_113_4_0_4_0.exe | "TargetSaver adware"
|
| X | Framework Windows | frmwrk32.exe | "Added by the FAKEAV-KS TROJAN!"
|
| X | France | svchost.exe | "Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| N | Fraps | FRAPS.EXE | "Fraps® by Beepa Pty Ltd - is ""a universal Windows application that can be used with games using DirectX or OpenGL graphic technology"". It can show how many Frames Per Second (FPS) you are getting |
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| X | free-save | [path to risk] | "Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
|
| X | FreeAttention | eqsefeqe.exe | Added by an unidentified WORM or TROJAN!
|
| N | Freebie Notes | FreebieNotes.exe | "Freebie Notes by Power Soft - create electronic notes (stickers)"
|
| X | FreeMP3download | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | FreePDF Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| N | FreePDF_Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| X | freestyle | lockx.exe | "Added by the RBOT-ATH WORM!"
|
| U | freesurfer | fs20.exe | "EMS Free Surfer mk II - pop-up stopper"
|
| X | freexstyle | lockbar.exe | "Added by the LOXBOT.D WORM!"
|
| X | freexstyle | lockbr.exe | "Added by the LOXBOT.C WORM!"
|
| X | freinst | pgs.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| U | Fresh Desktop | freshdesktop.exe | "Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
|
| N | freshclam | freshclam.exe | "Auto update agent of the open source Clamwin virus scanner"
|
| ? | frguk | shdrkmck.exe | "??"
|
| ? | FridaysInHellInstaller | FridaysInHellInstaller.exe | "??"
|
| X | FriendlyType | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | FriendlyTypeName | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
|
| U | FRISK FP-Scheduler | F-Sched.exe | "Scheduler for F-Prot anitvirus software. Leave enabled unless you scan manually on a regular basis"
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| X | Frsk | frsk.exe | Unidentified adware downloader trojan
|
| Y | frxmxins | frxmxins.exe | ATI 3D Studio MAX/VIZ driver
|
| X | FS Agent | fagent.exe | "Added by the VOLVER-B TROJAN!"
|
| X | FS6519 | FS6519.dll.vbs | "Added by the SOLOW.B WORM!"
|
| Y | fsaa | fsaa.exe | "F-Secure antivirus Authentication Agent - creates and stores private keys used by a client to access servers"
|
| N | FSCBoss | FSCBoss.exe | Free Store Club shop online software
|
| ? | FSDPSRV | FSDPSRV.exe | "??"
|
| X | fsdsft | [path to backdoor] | "Added by the RANKY.S BACKDOOR!"
|
| X | FSH | svcnva.exe | Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.KA TROJAN!
|
| U | fsp | fsp.exe | "Folder Shield - hide entire directories and thus prevent access by anyone else to your personal files and documents"
|
| Y | fspr | FolderShield.exe | "Folder Shield - hide personal files and folders"
|
| N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
|
| U | fsserv | fserv.exe | "Farsighter Server - monitors a remote computer invisibly by streaming video to a viewer on your computer. You will know exactly what is happening on the remote computer as you see it in real-time"
|
| U | fssui | fsui.exe | "System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety |
| U | fssui | fssui.exe | "System Tray access to and notifications from Windows Live OneCare Family Safety - part of the Live OneCare range and now superseded by Windows Live Family Safety which is part of Windows Live Essentials. Allows you to decide how your kids experience the Internet by limiting searches |
| X | fstsvc | "rundll32.exe fstsvc.dll | start" |
| U | fsui | fsui.exe | "System Tray access to and notifications from Windows Live Family Safety - optionally installed as part of Windows Live Essentials. ""With Family Safety |
| X | FSW | FSW.exe | "FreeScratchAndWin parasite"
|
| U | FSWebServer | fsws.exe | "Easy File Sharing Web Server is a Windows program that allows you to host a secure peer-to-peer and web-based file sharing system without any additional software or services"
|
| U | FtLnSOP_setup | FtLnSOP.exe | Fujitsu scanner utility
|
| U | FTMSFLT(USB) | FTMSFLTU.EXE | Fujitsu's Touch Panel Message Notifier
|
| X | FTP FOR WINDOWS | ftpwin32.exe | "Added by a variant of the RBOT WORM!"
|
| U | Ftpqueue | Ftpsched.exe | "Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
|
| ? | FtpServer.exe | FtpServer.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| X | FU | FUvirus.exe | "Added by the VB-EJC TROJAN!"
|
| X | Fucker | fucker.vbs | "Added by the CATCHER-A WORM!"
|
| U | Fujitsu Hotkey Utility | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | Fujitsu Menu | FjMnuIco.exe | "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel |
| X | fukerservice | fukerz.exe | "Added by a variant of the RBOT WORM!"
|
| N | FusionHdtvTray | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| U | FusionRC | FusionRC.exe | "Remote control manager for DVICO FusionHDTV"
|
| U | FusionRemote | FusionRc.exe | "Remote control manager for DVICO FusionHDTV"
|
| N | FusionTrayAgent | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| N | fwrastrc | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP
|
| U | fwservice | fwservice | "eAcceleration Stop-Sign security software related. Previously not recommended |
| X | fzg | svhost32.exe | "Added by the DLOADER.BDK TROJAN!"
|
| X | G0mez | G0mez.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | G3 | GSMedia3.exe | "Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
|
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | "System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
|
| ? | GACService | GACService.exe | "Related to a Gemplus product. What does it do and is it required?"
|
| X | gadkgak12 | fsafsakx12.exe | "Added by the ONLINEG-N TROJAN!"
|
| N | Gadwin PrintScreen | PrintScreen.exe | "Gadwin PrintScreen - utility to capture |
| X | game | shit.exe | Added by the Netclap Gold backdoor TROJAN!
|
| X | game | patcher.scr | "Added by the PSW-ED TROJAN!"
|
| X | Game House | GameHouse.exe | "Added by the DELF-DRA WORM!"
|
| N | GameDrive | GDTask.exe | "GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
|
| X | Games Acceleration | svshost.exe | "EasySearch adware"
|
| X | Games Acceleration | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Games Acceleration | svshost1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | "Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| N | GameSpot | kontiki.exe | "Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
|
| X | gamma | svchost.exe | "Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
|
| U | GammaHotKeys | setgamma.exe | "Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop"
|
| X | gangsta | gangsta.exe | "Added by the RIMA.A BACKDOOR!"
|
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers
|
| X | gaSrv | gaSrv.exe | "Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
|
| X | gaSrve | gaSrve.exe | "Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader"
|
| X | Gate Personal Firewall | Systpl.exe | "Added by the RBOT.ADC WORM"
|
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder
|
| X | Gay_Sexy_** | Gay_Sexy_**.exe | Premium rate adult content dialler (where * is a random char)
|
| U | GazelDisplay | gsyno.exe | "BT Digital Access USB - Gazel ISDN installation System Tray icon"
|
| Y | GBSpaceMan | SpaceMan.exe | "GreenBorder - secure your browsing activities on the internet"
|
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
|
| Y | gcasServ | gcasServ.exe | "Giant Antipsyware - now superseded by Microsoft's Windows Defender"
|
| X | gcasServ | realsched.exe | "Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
|
| N | GCS | GrabClipSave.exe | "GrabClipSave screen capture tool"
|
| X | gdagdgajs | bbsbw.exe | "Added by the SDBOT-QX WORM!"
|
| N | Gearbox | confsvr.exe | "NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here"
|
| N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player
|
| X | Gekio Startups | gnksvc32.exe | "Added by the AGOBOT.AFJ WORM!"
|
| N | GemStRmW | GemStRmW.exe | "For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card |
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives
|
| X | General Antivirus | GenAvir.exe | "General Antivirus rogue security software - not recommended |
| X | Generic host proccess for windows | SVCHOSTS.EXE | "Added by the SPYBOT-GQ WORM!"
|
| X | Generic Host Process | SCHOST.EXE | "Added by the RBOT-NC WORM!"
|
| X | Generic Host Process | svchost.exe | "Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | Generic Host Process | lsassw.exe | "Added by the AGOBOT-N WORM!"
|
| X | Generic Host Process for Win Services | mscvs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Process for Win32 Service | svlhost.exe | "Added by the WOOTBOT.EX WORM!"
|
| X | Generic Host Process for Win32 Service | rpchost.exe | "Added by the IRCBOT.DCN WORM!"
|
| X | Generic Host Process for Win32 Services | ntspcv.exe | "Added by the SDBOT.S TROJAN!"
|
| X | Generic Host Process for Win32 Services | intspvc.exe | "Added by the DINFOR.D WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc.exe | "Added by the SDBOT-O WORM!"
|
| X | Generic Host Process for Win32 Services | bazzi.exe | "Added by the AHKER.E WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc32.exe | "Added by the SDBOT-P WORM!"
|
| X | Generic Host Process for Win32 Services | lspsvc.exe | "Added by the MUMU.C WORM!"
|
| X | Generic Host Process for Win32 Services | SPSVC.EXE | "Added by the SDBOT.DA WORM!"
|
| X | Generic Host Process for Win32 Services | svchost32.exe | "Added by the AGOBOT.ALH WORM!"
|
| X | Generic Host Process for Win32 Services | svñhîst.exe | "Added by the DLOADER.AK TROJAN!"
|
| X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Generic Host Process For Win32 Services | mtsc32.exe | "Added by the VB-CPL TROJAN!"
|
| X | Generic Host Process for WinXP Services | mshelp.exe | "Added by the AGENT-GQP TROJAN!"
|
| X | Generic Host Process2 System Backup | scvhost2.exe | "Added by the RBOT-BAH WORM!"
|
| X | Generic Host Process326a System Backup | scvhost326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Service | lshost.exe | "Added by the RBOT.LU WORM!"
|
| X | Generic Service Process | regsvc32.exe | "Added by the GAOBOT.UJ or GAOBOT.UL WORMS!"
|
| X | Generic Service Process | serv1ces.exe | "Added by the AGOBOT-JK WORM!"
|
| X | Generic Service Process | nvsvc.exe | "Added by the AGOBOT.BY WORM! Note - this is not the valid NVIDIA Driver Helper Service and is located in %System%"
|
| X | Generic Service Process | srvhost.exe | "Added by the AGOBOT-FX WORM!"
|
| X | Generic Service Process | regsvr32.exe | "Added by the AGOBOT-AGD WORM!"
|
| X | Generic Service Process | SRCHOST.EXE | "Added by the AGOBOT-DG WORM!"
|
| X | Generic Services Process | regsvc32.exe | "Added by the GAOBOT.SY WORM!"
|
| X | GenericHostXP | WinLoaderXP.exe | "Added by the BDOOR-ACX BACKDOOR!"
|
| Y | Genie USB Monitor | USBmonitor.exe | Port monitor for an external USB hard drive. Required to enable access to the drive
|
| X | Genius Mose Driver | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | genserv path | sdqdqg.exe | "Added by the SDBOT-RF WORM!"
|
| X | Geography TX 1.0 NT | CompuSpeed.vbs | "Added by the NEWLEY-A WORM!"
|
| X | Gerenciamento de arquivos do Windows | Winmod32.exe | "Added by the DLOADER-WG TROJAN!"
|
| X | german.exe | winsystems.exe | "Added by the BAGLEDl-AE TROJAN!"
|
| X | german.exe | wintems.exe | "Added by the BAGLE-AS TROJAN!"
|
| X | gescw | gescw.exe | "Part of BeschermingsTool |
| X | Gestionnaire de disques universel | sysoobe.exe | "Added by the TOADER-A TROJAN!"
|
| N | Get Smile | getsmile.exe | Puts smilie faces in your E-mail. Run manually when required
|
| X | Get-Torrent Service | wakeservice.exe | Get-Torrent bittorrent client - Installs LOP adware
|
| X | GetitAll | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetTheMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | Getting started with MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | Ghost Antivirus | GhostAV.exe | "Ghost Antivirus rogue security software - not recommended |
| X | Ghost Relay | [random filename] | "Added by the DNSCHANG.EK TROJAN!"
|
| U | GhostSecuritySuite | gss.exe | "Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
|
| N | GhostStartService | GhostStartService.exe | "Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
|
| N | GhostStartTrayApp | GhostStartTrayApp.exe | "System Tray access to Norton Ghost - added from the 2003 version"
|
| Y | GhostSurfDelSatellite | DeleteSatellite.exe | "Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning |
| U | Giganews Accelerator | GiganewsAccelerator.exe | "Giganews Accelerator from Giganews |
| Y | Gilat SOM Enumerator | dllhost.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| X | gimmygames | [path to trojan] | "Added by the DLOADR-LN TROJAN!"
|
| X | gimmysmileys | gimmysmileys.exe | "GimmySmileys adware"
|
| ? | GisdnLog | gisdnlog.exe | "BT Digital Access USB"
|
| U | Glass2k | Glass2k.exe | ""Glass2k is a small little program that allows Win2K/XP users to make any window transparent""
|
| X | Global Startup | WinDash.EXE | "Detected by Kaspersky as the VB.Q WORM!"
|
| X | GlobalSCAPE | [random filename] | "Added by the RBOT-AYM WORM!"
|
| X | Glock Suite 1.1 | glock32.exe | "Added by the TINY.GV TROJAN!"
|
| X | GLSetIT32 | msiexec16.exe | "Added by the OPTIX PRO TROJAN!"
|
| X | GLSetIT32 | isass.exe | "Added by a variant of the OPTIX PRO TROJAN!"
|
| X | GLSetT32 | smsiexec.exe | "Added by the OPTIX-D TROJAN!"
|
| X | GMedia2 | GSM2.exe | "Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
|
| X | GMedia2 | GSMedia3.exe | "Malware downloader - detected by Kaspersky as the VB.UX TROJAN!"
|
| Y | Gmouse | Gmouse.exe | Amouse mouse driver - required if you use non-standard Windows driver features
|
| X | Gmsvc32 | gmsvc32.exe | "Added by the AGOBOT.ABN WORM!"
|
| U | Gnetmous | gnetmous.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| U | GNETMOUSE | gnetmouse.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| X | GNP Generic Host Process | svchost.exe | "Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| X | Go And Start | svdll32.exe | "Added by the RBOT.AI BACKDOOR!"
|
| X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
|
| U | GoBack Polling Service | GBPoll.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | GoldenAntiSpy | pgs.exe | "GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
|
| U | Goldensoft_MndlSvr | MndlSvr.exe | "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive |
| X | Golum | services.exe | "Added by the GOLUM.A TROJAN! Note - this is not the legitimate services.exe process |
| X | golumm | services.exe | "Added by the DLOADER-ET TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""golumm"" subfolder"
|
| U | Google Desktop | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| U | Google Desktop Search | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| N | Google Earth Viewer | GOOGLEMAPS.EXE | "Google Earth ""combines satellite imagery |
| U | Google Quick Search Box | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| X | Google service | Googlesetup.exe | "Added by the IRCBOT-RJ WORM!"
|
| X | Google Service FR | GO0GLEFREE.EXE | "Added by a variant of the SPYBOT WORM!"
|
| U | GoogleDesktop | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| U | GoogleQuickSearchBox | GoogleQuickSearchBox.exe | "Part of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the ""Start"" button and Quick Launch toolbar and ""lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"""
|
| U | GoToMyPC | g2svc.exe | "ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
|
| U | GoTrusted | GoTrusted Secure Tunnel.exe | """GoTrusted is the fast |
| X | GotSmiley | GotSmiley.exe | "GotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | govurarope | "Rundll32.exe retasevo.dll | s" |
| ? | gramdate | 2Stop.exe | "??"
|
| X | Graphic Driver | smss32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphics | _default.pif | "Added by the AUTOSKY WORM!"
|
| X | Graphics adapter service | windll.exe | "Added by the ATNAS.A WORM!"
|
| U | Gravis Appawareloader | dbserver.exe | "Looks like it's associated with Gravis game controllers and the Keyset Manager |
| U | Gravis Xperience Driver Support | Grxp4exe.exe | "Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
|
| ? | GrdSys32 | GrdSys32.exe | "X-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?"
|
| X | GreasyPalmUpdate | GreasyPalmUpdate.exe | "SearchFast adware"
|
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Greetings Workshop | GWREMIND.EXE | You really want to be reminded about somebody's birthday at the expense of resources?
|
| X | gremier | wscript.exe gpremier.vbs | "Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
|
| X | grinders | grinders.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| N | Grokster | Grokster.exe | "Grokster Peer-To-Peer File Sharing program"
|
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| X | GsAds | gms2.exe | "PacerD_Media/Pacimedia.com adware"
|
| ? | Gscbc | Gscbc.exe | "??"
|
| X | gshp | zzgshp.vbs | Homepage hi-jacker
|
| N | Gsiconexe | Gsicon.exe | "ADSL modem monitor from Eicon Networks (as used by BT for its Broadband internet service for example). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilities"
|
| ? | GsiFinal | "rundll32 gspndll.dll | postInstall final" |
| ? | GSISETUP | [path] GsiInst.exe INSTALL [path] V205Res 13 | "BT Voyager ADSL modem related - what does it do and is it required?"
|
| N | GSOrganizer | GSOrganizer.exe | "GoldenSection Organizer (now WinOrganizer - personal information manager)"
|
| X | gssomatic | gssomatic.exe | "Searchcentrix hijacker"
|
| Y | gStart | gStart.exe | gStart GPS software from Garmin
|
| X | GStartup | GMT.exe | "Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | gsv | gsv.exe | Added by the ROBAL 1.0 backdoor TROJAN!
|
| X | GT15J4R49V | cpuserv.exe | Identified as a variant of the Trojan.Win32.Radi.gu malware
|
| X | gtydf | iisca.exe | "Added by the CLAGGER-BB TROJAN!"
|
| X | gtydf | iscca.exe | "Added by the DWNLDR-GTK TROJAN!"
|
| U | Guardian PC Security Tools | Pfft.exe | "Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
|
| X | GuardPcs.exe | GuardPcs.exe | "GuardPcs rogue security software - not recommended |
| X | guarnset | guarnset.exe | "Adlogix adware"
|
| X | GustavVED | [filename].exe | "Added by the OPASERV.H WORM!"
|
| X | gwiz | ntsystem.exe | "Added by the NITWIZ.A TROJAN!"
|
| N | GWMDMMSG | GWMDMMSG.exe | Used with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctly
|
| X | G_Host | gHost.exe | "Added by the AUTOIT-BP WORM!"
|
| X | G_Server.exe | G_Server.exe | "Added by the FEUTEL-C TROJAN!"
|
| X | G_Server1.2.exe | G_Server1.2.exe | "Added by the GRAYBIRD-Z TROJAN!"
|
| U | H/PC Connection Agent | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| X | h4te Service Drivers | h4te.exe | "Added by a variant of the RBOT WORM!"
|
| X | hachimitsu-lemon | hachimitsu-lemon.exe | "Added by the HACHILEM TROJAN!"
|
| U | HalifaxHowardCluster | skinkers.exe | """Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
|
| N | Hard Disk Sentinel | HDSentinel.exe | "Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find |
| X | HardDriveGuard | SysRep.exe | "HardDriveGuard rogue system error and cleaning utility - not recommended |
| X | Hardware Monitor Service | mshms.exe | "Added by the WOLLF-A TROJAN!"
|
| U | Hardware Sensors Monitor | hmonitor.exe | Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
|
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| U | Harmony 98 - CasioOrg | CasAgnt.exe | "Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | HataDuzelticisi | SysRep.exe | "HataDuzelticisi |
| U | Hawking Wireless Utility | HWU8DD.exe | "Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies |
| X | Hbinst | Hbinst.exe | "Hotbar adware"
|
| U | HControlUser | HControlUser.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| N | hcsystray | hc_tray.exe | "Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
|
| N | HDAShCut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| X | hdlfoe df98ndf | svchots.exe | "Added by a variant of the RBOT WORM!"
|
| X | hdlpscom | [8 random letters].exe | "Added by the RBOT-FUL WORM!"
|
| X | HDriveSweeper | HDriveSweeper.exe | "HDriveSweeper rogue privacy program - not recommended |
| X | Hekio Startups | Hnksvc32.exe | "Added by the AGOBOT-QE WORM!"
|
| X | HELLBOT TEST | 1hellbot.exe | "Added by the MYDOOM.BO WORM!"
|
| X | hellfire | svchost.exe | "Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | hellodolly | shost.exe | "Added by the YODO WORM!"
|
| X | helloserv | helloserv.exe | "Added by the ZHELATI.BHA WORM!"
|
| X | help | help.scr | "Added by the BANCOS-BBU TROJAN!"
|
| X | Help | lshost.exe | Identified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
|
| X | Help Temp Files | netreg.exe | "Added by the FORBOT-EM WORM!"
|
| X | Help Temp Files | emp32.exe | "Added by the FORBOT-EC WORM!"
|
| U | HelpCenter | sprtcmd.exe /P HelpCenter | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| U | HelpCenter4.1 | sprtcmd.exe /P HelpCenter4.1 | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| X | Helper | eschlp.exe | "Added by the BLASTER.T WORM!"
|
| X | HELPER | Netherlands.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | sweden.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | helpmanager | spoler.exe | "Added by the RANDEX.J WORM!"
|
| X | heomstool | heomstool.exe | "Added by the HEOMS TROJAN!"
|
| Y | HEProtect | HSockPE.exe | "Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
|
| ? | HerculesCamService | CamService.exe | "Related to the Hercules Dualpix HD Webcam. What does it do and is it required?"
|
| X | hErcUnes | softhost.exe | "Added by the GARROCH WORM!"
|
| U | Hermes Messenger | DGDRHE~1.EXE | "A LAN messenger alternative to WinPopUp - Digital Dreams Software"
|
| X | HF Security | hfsecure.exe | "Added by the AGOBOT-TI WORM!"
|
| X | hfdtubvnx | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| Y | hffsrv | hffsrv.exe | "Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders |
| Y | hffsrv.exe | hffsrv.exe | "Hide Files & Folders - ""great easy-to-use password-protected security utility working at Windows kernel level you can use to password-protect certain files and folders |
| X | hgkytwe | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| N | HGTXPEI | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
|
| X | hhtnsn | rnxntup.exe | "Added by a variant of the ORCU.B TROJAN!"
|
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | "Added by the BOOHOO WORM!"
|
| X | HideStyle | Ante Browse Trust.exe | "IE toolbar taking you to Lop.com. If the exe is running |
| U | Hidetools Spy Monitor | wmispe.exe | "HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
| U | hidserv | hidserv.exe | "This is the Human Interface Device Server for Win98SE/2000/Me/XP |
| X | Hidup_Susah | Pembantu.exe | "Added by the SILLYFDC.BDM WORM!"
|
| X | hid_start | gzmrotate.dll | "AdRotator/IconAds adware"
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| N | High Definition Audio Property Page Shortcut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| Y | HighPoint ATA RAID Management Software | raidman.exe | "HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
|
| X | Highspeeddownloader | SetupClickHere.EXE | "Homepage hijacker |
| U | HijackThis | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| U | HijackThis startup scan | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| X | HijSrv32 | hijsrv.exe | "Added by the BANKGERM-D TROJAN!"
|
| X | HistoriaLout. | GDC.exe | "HistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | HistoryKill | histkill.exe | "HistoryKill removes your web surfing path by removing the URL drop-list history |
| U | Hitman Pro SurfRight Helper | srhelper.exe | "Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
|
| X | HKCU | server.exe | "Added by the AGENT-NLT TROJAN!"
|
| X | HKLM | server.exe | "Added by the AGENT-NLT TROJAN!"
|
| X | HKLMRun | windowsupdate.exe | "Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
|
| X | HKLM\Run | svhost.exe | "Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
|
| U | hkserv | HKserv.exe | Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS
|
| U | hkss | hkss.exe | Compaq HotKey Support - multimedia keyboard support
|
| X | HLcleanup | hlsetup2.exe | "LinkReplacer/FFinder adware"
|
| X | HMI PowerSystem | hmisvc32.exe | "Added by the RANDEX.CZZ WORM!"
|
| X | HML PowerSource | hmlsvc32.exe | "Added by the SDBOT-XL WORM!"
|
| X | HMV PowerSource | hmusvc32.exe | "Added by the SDBOT-YW WORM!"
|
| X | ho2stdll.exe | ho2stdll.exe | "Added by the BANKER-HO TROJAN!"
|
| X | HOI Services | holsvc32.exe | "Added by the AGOBOT-SF WORM!"
|
| N | Holiday Lights | Holiday Lights.exe | "Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs"
|
| X | Hollaback | slvhosts.exe | "Added by the SDBOT.BMO WORM!"
|
| X | Home Antivirus 2010 | HomeAntivirus2010.exe | "Home Antivirus 2010 rogue security software - not recommended |
| N | Home Theater SchSvr | SchSvr.exe | "WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| X | HomeAntivirus 2009 | HomeAntivirus2009.exe | "HomeAntivirus 2009 rogue security software - not recommended |
| X | homepage.monitor.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| U | Hook99startup | hk2re.exe | ""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons |
| U | HookSys | HookSys.exe | "SurfinGuard Pro from Finjan - internet protection software |
| X | Host | N/A | "Added by the POPDIS or STARTPAGE.F TROJANS!"
|
| X | host | help.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
|
| X | Host Process | mame.exe | "Added by the RBOT-APO WORM!"
|
| X | Host Process | svchost.exe | "Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
|
| X | Host Process for Windows Tasks | taskhost.exe | "Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | hostdll.exe | hostdll.exe | "Added by the BANKER-BO TROJAN!"
|
| U | HostManager | AOLHostManager.exe | "Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched |
| N | HostManager | AOLSoftware.exe | "Quoted from AOL Beta Team |
| X | Hostname Manager Server | host32srv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Hostren.exe | Hostren.exe | "Added by PWS.BANKER.F |
| X | hostserv | hostserv.exe | "Added by the RBOT.BPZ WORM!"
|
| X | hostserv | wiz98.exe | "Added by a variant of the SDBOT WORM!"
|
| U | HostsFileMgr | winHostsEdit.exe | "AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
|
| U | HostsMan | hm.exe | """HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost |
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
|
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
|
| X | HostSrv | sachostx.exe... | "Added by the LOOKSKY.E WORM!"
|
| X | HostSVC syse | HostSVC.exe | "Added by the RBOT-ANZ WORM!"
|
| U | Hot Corners | Hotc.exe | "Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
|
| X | HOT FIX | E0chis.exe | "Added by the HUPIGON.JTY TROJAN!"
|
| X | HOT FIX | windsys2.exe | "Added by the AGOBOT.AOI BACKDOOR!"
|
| X | Hot Inside | Hottest Story Ever.exe | "Added by the BHARAT.A WORM!"
|
| U | Hot Key Kbd 2690 Daemon | SK2690DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| U | Hot Key Kbd 9910 Daemon | SK9910DM.exe | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| X | Hotbar | Hbinst.exe | "Hotbar adware"
|
| X | HotbarSA | HotbarSA.exe | "Hotbar adware"
|
| X | hotefix | msnmanegers.exe | "Added by the IRCBRUTE.AS TROJAN!"
|
| X | hotfix | msnnmaneger.exe | "Added by the WOOTBOT.AF WORM!"
|
| X | Hotfix Updat | svdhost32.exe | "Added by the GAOBOT.ZW WORM!"
|
| U | HotKeysCmds | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | HotKeysCmds | [path to worm] | "Added by the PAHATIA-A WORM!"
|
| N | HotSync Manager | hotsync.exe | Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
|
| X | Hot_Kiss | Hot_Kiss.exe | Adult content dialler
|
| X | Hot_Tarts | Hot_Tarts.exe | Adult content dialler
|
| X | Hot_Tarts_** | Hot_Tarts_**.exe | Premium rate adult content dialer (where * is a random char)
|
| X | Hot_Tarts_Au | Hot_Tarts_Au.exe | Premium rate adult content dialler
|
| X | Hot_Tarts_mc | Hot_Tarts_mc.exe | "HotTarts adult content dialer"
|
| U | HoverDesk | HoverDesk.exe | "HoverDesk - desktop replacement software"
|
| N | hp center UI | ShadowBar.exe | "User Interface for HP Center - see here"
|
| X | HP Deskjet | HP_DeskJet_500.exe | "Added by the FORBOT-DA WORM!"
|
| X | HP Desktop | ccappms.exe | "Added by the SDBOT-TG WORM!"
|
| U | HP Display Settings | hpdisply.exe | "Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
|
| U | HP Health Check Schedule | HPHC_Scheduler.exe | HP Health Check Scheduler from Hewlett-Packard
|
| ? | HP IDScheduler | HPIDSCHD.exe | "HP Instant Delivery Scheduler"
|
| N | HP Image Zone Fast Start | hpqthb08.exe | "Improves the startup time of HP Image Zone. If you disable it |
| N | HP Info Express | ?? | "On HP PCs |
| U | HP Instant Support | matcli.exe | ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| N | HP Internet Center | SURFBRD.EXE | Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
|
| N | HP JetDiscovery | HPJETDSC.EXE | HP JetAdmin software which monitors printing jobs on a network environment
|
| N | HP JetSpeed Autostart | AUTOSTART.EXE | Autostart executable for the old multiplayer game HP Jetspeed
|
| U | HP Laser Jet Director | hppdirector.exe | "System Tray icon that opens various functions such as copy |
| ? | HP Network Registry Agent | hpnra.exe | "??"
|
| ? | HP OfficeJet Series xxx Startup | HPOSTR03.EXE | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| ? | HP OfficeJet Series xxx Startup | HPOstr05.exe | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| N | HP Parallel Port Test | hppt.exe | Associated with a HP ScanJet scanner
|
| N | HP Photosmart Premier Fast Start | hpqthb08.exe | "Improves the startup time of HP Image Zone. If you disable it |
| ? | HP Port Resolver | hpbpro.exe | "??"
|
| N | HP Precision Scan | hpmdlbwx.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| N | HP Presentation Ready | PresRdy.exe | HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
|
| U | hp psc 2000 Series | hpobnz08.exe | System Tray icon indicating when the printer is ready. Can be started manually with HP Director but takes time to start
|
| U | HP ScanPatch | HPScanFix.exe | "Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used |
| N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| U | HP SchedIndexer | hppschedindexer.exe | "Installed by HP multi-function printer driver software |
| X | HP Service Drivers | hdsys.exe | "Added by the SDBOT-ZE WORM!"
|
| ? | hp Silent Service | HpSrvUI.exe | "HP related"
|
| N | HP Simple Trax | Hpcron.exe | Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
|
| N | HP software update | HPWuSchd2.exe | HP software updates. If a shortcut doesn't exist create your own and run it manually
|
| N | HP software update | HPWuSchd.exe | "HP software updates. If a shortcut doesn't exist |
| N | HP Status | hpstatus.exe | HP Printer Status and Alerts
|
| ? | HP Status Server | hpboid.exe | "Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?"
|
| X | HP Update Assistant | HPAware.exe | Added by the MRO TROJAN!
|
| N | HP Updates | ?? | "On HP PCs |
| ? | HP Visualize Init | HpVisIni.exe | "HP Visualize software related. What does it do and is it required?"
|
| U | HPADVISOR | HPAdvisor.exe | HP Total Care Advisor - a suite of help and hardware check programs to help you check the health of your PCs
|
| ? | HPAiODevice(hp officejet g series) | hpoavn07.exe | "HP Printer related |
| N | HPAiODevice(hp psc 900 series) -1 | hpobrt07.exe | "Installed with a Hewlett Packard 900 series colour printer |
| X | hpdeskjet | hpdeskjet.exe | "Added by the GENOME.AQUV TROJAN!"
|
| U | HPDJ Taskbar Utility | hpztsb01.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb02.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb04.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb05.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb07.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb09.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb06.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb08.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb03.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb10.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb11.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb12.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb13.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| N | hpfsched | hpfsched.exe | HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature
|
| U | HPGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| N | hpgs2wnd | hpgs2wnd.exe | "Share-to-Web - HP-created software and Internet-based application that enables easy uploading and sharing of photos via affiliated photo-sharing Web sites. Available via Start → Programs"
|
| X | Hphome | hphome.js | Homepage hijacker
|
| ? | hpjsiroute | hpjsira.exe | "Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2""
|
| X | HPl Services | hmlsvc32.exe | "Added by the AGOBOT-SI WORM and variants!"
|
| U | HPLaptopGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| Y | HPLJ Config | SetConfig.exe | Connects system to networked HP printer.
|
| X | HpPrinter | hpserver.exe | "Added by the CMJSPY-W TROJAN!"
|
| U | HPPWRSAV | HPPWRSAV.EXE | "Power save related for HP Scanners. Many users have complained of system freezes with it running but it stops the light from remaining on all the time. Try www.hp.com |
| ? | hpqSRMon | hpqSRMon.exe | "Related to HP Digital Imaging products. What does it do and is it required?"
|
| U | HPSCANMonitor | hpsjvxd.exe | HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
|
| ? | hpScannerFirstBoot | scannerfb.exe | "HP scanner related"
|
| X | hpSdwxmark | Gaddw.exe | "Added by the SDBOT-RB WORM!"
|
| N | hpsjbmgr | hpsjbmgr.exe | "HP ScanJet Button Manager. It allows users of the HPScanJet scanners to indicate what the buttons on the scanner will do automatically if pushed. Not required at startup |
| N | HPStart | hpstart.wsf | This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
|
| X | hpsysconf1 | [random filename] | "Added by a variant of the VIVIA.A TROJAN!"
|
| U | hpsysdrv | hpsysdrv.exe | "This item keeps track of how many times the system has been recovered and the times of the first and last recoveries done on the system. Leaving unchecked will sometimes prevent the Keyboard Manager program from detecting that the computer is an HP. Since this program/driver was only made to run on HP |
| X | hptools | hptools.exe | "Added by a variant of the SDBOT WORM!"
|
| X | hptools | microsoft.exe | "Added by a variant of the SDBOT WORM!"
|
| N | HPU | ProvenTactics.exe | "Proven Internet Marketing software"
|
| U | hpWirelessAssistant | HP Wireless Assistant.exe | The HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
|
| U | hpWirelessAssistant | HPWAMain.exe | Wireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
|
| N | HPZTS04 | hpzts04.exe | Hewlett Packard printer toolbox shortcut that resides in the system tray
|
| U | hpztsb02 | hpztsb02.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb04 | hpztsb04.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb05 | hpztsb05.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb07 | hpztsb07.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb09 | hpztsb09.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsbol | hpztsbol.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| X | HQI Services | hqisvc32.exe | "Added by the AGOBOT-RO WORM!"
|
| X | HQI Services | hqlsvc32.exe | "Added by the AGOBOT-RP WORM!"
|
| U | HREF.OCX | regsvr32.exe ....HREF.OCX | "HREF.OCX is an ActiveX control developed by xFX JumpStart and used to provide HTML-alike clickable links on Windows-based programs such as PopUpKiller"
|
| X | Hrn_qtv | hrnsvc32.exe | "Added by the SDBOT-AET WORM!"
|
| X | Hservice | msservice.exe | "Added by the AUTORUN-KL WORM!"
|
| X | hsim | isearch.exe | Unidentified malware
|
| X | hsim | sexgame.exe | Unidentified malware
|
| X | hsim | toolbar.exe | Unidentified malware
|
| U | HSLAB Logger | logger.exe | "HSLABLogger logs user activity and Internet activity. The gathered information can be sent to a predetermined email address. If you didn't install this yourself uninstall it"
|
| U | HSON | HSON.exe | Toshiba HotStart button support for instant-on entertainment on their laptops
|
| U | HSTrans | hstrans.exe | "Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
|
| ? | HsuGuiControl | HsuGuiControl.exe | "Part of the Starband Internet satellite client. What does it do and is it required?"
|
| U | hsys | HSYS.EXE | "Keylogger Express keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | HTML Help System | hhs.pif | "Added by the RBOT-ATB WORM!"
|
| X | HTML32 Help System | hhs32.pif | "Added by the RBOT-ATE WORM!"
|
| X | htssv32.exe | htssv32.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | HTTP Tunneling Server | mstunnel.exe | "Added by the RBOT.EDL WORM!"
|
| X | httpd | msgaol.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | browse.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | https-ssl | https.exe | "Added by the MOEGA.D WORM!"
|
| U | HughesNet Tools | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| X | huigezi | HgzServer.exe | "Added by the GRAYBIRD.C TROJAN!"
|
| X | huigezi | SP00LSV.EXE | "Added by the GRAYBIRD.J BACKDOOR! Note the digit ""0"" in the command"
|
| X | Hvewsveqmg | ANACON.EXE | "Added by the NACO.A WORM!"
|
| Y | HWinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
|
| X | Hwp | system_wc.exe | "Eziin adware"
|
| X | hws | hws.exe | "Added by the STARTPA-CT TROJAN!"
|
| U | HWSetup | HWSetup.exe hwSetUP | """Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS |
| X | hxadsec | [path to trojan] | "Added by the ADCLICK-AP TROJAN!"
|
| U | HydarVisionDesktopManager | desk95.exe | "ATI's HydraVision desktop management software |
| U | HydraVisionDesktopManager | desk98.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionDesktopManager | HydraDM.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes |
| U | HydraVisionViewport | viewport.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionViewPort | HydraMD.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates |
| X | Hyper Files | phfhost.exe | "Added by the AGENT-JQO TROJAN!"
|
| X | Hyper Start | instantmsgrs.exe | "Added by the RBOT-NH WORM!"
|
| X | I am not Ranky. I am eTunnel! | msyervice.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | winsys.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | disney.exe | Added by an unidentified WORM or TROJAN!
|
| X | I just want to say I love Milko and I need a drink | svchost.exe | "Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
|
| X | I/O Controllers | svcnet.exe | "Added by the TIBIK-B TROJAN!"
|
| ? | I81SHELL | I81SHELL.exe | "Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard"
|
| X | Iamnacho On Irc.MusIrc.com Is a Homosexual! | XBox64.exe | "Added by the RANDEX.Y WORM!"
|
| ? | IaNvSrv | IaNvSrv.exe | "Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?"
|
| U | ias | ias.exe | "InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | IASHLPR | IASHLPR.EXE | "Added by the OPASERV.T WORM!"
|
| Y | IBM Client Security | certtool.exe | "Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk) |
| N | IBM Client Security Software | csecwiz.exe | "Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once |
| Y | IBM Password Manager | pwmgr.exe | "Part of Client Security Software for IBM\Lenovo notebooks - IBM® Client Security Password Manager ""enables you to manage your sensitive and easy-to-forget login information |
| U | IBM ThinkPad EasyEject Support Application | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad EasyEject Tray Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| U | IBM TrackPoint Accessibility Features | tp4ex.exe | "Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound"" |
| ? | IBM Warranty Notification | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| N | ibmmessages | ibmmessages.exe | """The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"""
|
| U | Ibmpmsvc | ibmpmsvc.exe | "Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn |
| U | IBMUltraBayHotSwapCPLLoader | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
|
| ? | IBMUltraBayHotSwapSound | IBMBAYSN.EXE | "Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
|
| X | Ibs | ibs.exe | "Added by the HIDEDIAL-B TROJAN!"
|
| U | IBWin Background process | IBackground.exe | "IBackup for Windows"
|
| X | icasServ | icasServ.exe | "Browser hijacker |
| X | icccomp | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| N | ICH Synth | eusexe.exe | "Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
|
| X | ICManagement | msic32.exe | "Added by the MSIC BACKDOOR!"
|
| U | ICONDESK | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons
|
| X | iConfigLoader | DIIhost.exe | "Added by the GAOBOT.AO WORM!"
|
| N | Iconsaver | Iconsaver.exe | "IconSaver is a desktop icon manager"
|
| X | ICQ | ICQNET.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | ICQ Chat Service | icqjdhs.exe | "Added by a variant of the RBOT WORM!"
|
| X | icq lite | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | ICQ Lite Messenger | ICQLITE.EXE | "Added by an unidentified VIRUS |
| X | ICQ Messenger 2002 | ICQ2002.exe | "Added by the SDBOT-ABL WORM!"
|
| N | ICQ Plus | vplus.exe | "ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs"
|
| X | ICQMsn | [path to trojan] | "Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
|
| X | icrosof Avps32 Control | av32.pif | "Added by the RBOT-AVC WORM!"
|
| X | icrosoft Visual | plscx.exe | "Added by the RBOT-AYO WORM!"
|
| X | icrosoft Visual InterDevc | zvslmqb.exe | "Added by the RBOT-AYP WORM!"
|
| X | icrosoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AER WORM!"
|
| X | icrosoftf Avpx Control | avpx.exe | "Added by the RBOT-AYN WORM!"
|
| U | ICSDCLT | "rundll32.exe Icsdclt.dll | ICSClient" |
| N | ICServer | Icserver.exe | Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
|
| Y | ICSMGR | ICSMGR.EXE | Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers
|
| X | ICU-Sucker | Service32.exe | "Added by the ILLNOTIFIER.D TROJAN!"
|
| N | IC_KEY_3 | spvic.exe | "Instant Chess related"
|
| U | iDesktop | idesktop.exe | "Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse"
|
| X | idlesam | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| X | idmlssp | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| U | IDriveE Startup | IDrvieEStartup.exe | "IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
|
| X | IDTemplates | IDTemplate.exe | "Added by the BRONTOK-H WORM!"
|
| X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | "Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | IE Runtimes | winis.exe | "Added by the RBOT-ADZ TROJAN!"
|
| X | IE-Security | iescan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE-Security | wdscan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE6 | wkstmg.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IE6 | ssmss.exe | "Added by the GAOBOT.DXO WORM!"
|
| X | IE6 | winsnt.exe | "Added by the RBOT-GOV WORM!"
|
| X | IEACCESS | temp532.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | IEACCESS | surfya.exe | "
| X | IECheck | MSDTCs.exe | "Added by the TIRBOT-D WORM!"
|
| X | IECheck | xpssl.exe | "Added by the TIRBOT-E WORM!"
|
| X | IECheck | mssvp.exe | "Added by the TIRBOT-G WORM!"
|
| X | IEFeatures | IEFeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | IEFeatures | Internetfeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | Iehelper | syslaunch.exe | Outwar adware downloader
|
| X | Iesar | Iesar.exe | Browser hijacker - redirecting to an adult web page
|
| X | Iesearch.exe | Iesearch.exe | "LookNSearch adware"
|
| U | IEServer | IEServer.exe | "HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself"
|
| X | IEService.exe | IEService.exe | "FastFind adware variant"
|
| X | IESet | IExplorer.dll | "Added by the PWS-BLUEDIT TROJAN!"
|
| X | iesetupi.exe | iesetupi.exe | "Added by a variant of the RBOT WORM!"
|
| Y | IEShow | IEShow.exe | "Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames |
| X | iestart | iexp1orer.exe | "Added by the NEMOG.C TROJAN!"
|
| N | ietsr | ietsr.exe | "IEClean by Kevin McAleavy - cookie manager |
| X | ieupdates | ieupdates.exe | "Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
|
| X | IEWinserv | winserv.exe | "Added by the BANKER-MY TROJAN!"
|
| X | IExploer | svshosts.exe | "Added by the IRCBOT.BT TROJAN!"
|
| X | Iexplore Services | iexplore.exe | "Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
|
| X | IEXPLORER | msiecfg.exe | "Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
|
| X | IExplorer32 Java Scripting | IExplore32b.exe | "Added by the RBOT.ABO WORM!"
|
| X | IExplorer32c Java Scripting | IExplore32cb.exe | "Added by the RBOT.ABN WORM!"
|
| X | IExplorer6 Java Scripting | IExplore326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorer7 Java Scripting | IExplore327.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IExplorerService | WinSock.exe | "Added by the AGENT.KIU TROJAN!"
|
| X | iExpresser | iexpresser.exe | "Added by the SLENFBOT.AP WORM!"
|
| U | IFSplash.exe | IFSplash.exe | I-FORCE driver for force feedback steering wheel
|
| U | IFXSPMGT | ifxspmgt.exe | "Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer |
| U | igfxpers | igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
| X | igfxtras | svchots.exe | "Added by the AUTORUN-AIW WORM!"
|
| X | igsex2x | igsex2x.exe | "NewDial premium rate adult content dialler"
|
| X | IISADMINS | systems.exe | "Added by the AGOBOT.U WORM!"
|
| X | iisvers | iisvers.exe | Added by an unidentified TROJAN or adware
|
| N | iIWiper | Systemwiper.exe | "System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
|
| Y | IJ75P2PSERVER | IJ75P2PS.EXE | Printer utility which is required in order to make the printer work correctly
|
| U | IJNetworkScanUtility | CNMNSUT.EXE | Network utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
|
| Y | IKE Service 95 | IKEService.exe | "Associated with PGP. The PGP Tray can be disabled |
| U | iKeyWorks | IKEYMAIN.EXE | "A4Tech wireless keyboard driver and utility"
|
| X | ilasss | lsass.exe | "Added by the INJECT-GZ TROJAN! Note - the legitimate lsass.exe process should not normally figure in Msconfig/Startup!"
|
| N | iLike | ilikesidebar.exe | "iLike Sidebar for iTunes and Windows Media Player"
|
| X | ilortgdg | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| N | iM Start Center | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
|
| Y | Image & Restore | IMAGE32.exe | "Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased |
| X | Image Remote Players | sysvn.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| N | Image Transfer | SonyTray.exe | Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
|
| U | ImageDrive-{hex numbers} | ImageDrive.exe | "Nero ImageDrive from Ahead - virtual CD/DVD drive software"
|
| X | ImagePath | taskbarmngr.exe | "Added by the SDBOT-XB WORM!"
|
| X | IMClass | Svhosl.exe | Added by an unidentified WORM or TROJAN!
|
| X | imcssl | xmliwvug.exe | "Added by the SLAPER.U TROJAN!"
|
| N | Imesh | ?? | "Imesh is a file sharing system"
|
| N | Imesh Auto Update | ?? | "Update check for the Imesh file sharing system. Turn the update off under ""options"""
|
| N | ImgStart | ImgStart.exe | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| N | ImgTask | Imgtask.exe | "Related to the WalletPix digital photo album. ""On some computers |
| X | IMJPMIG8.2 | msime82.exe | "Added by the VB-CYG WORM!"
|
| X | IMJPMIG8.2 | msime80.exe | "Added by the VB-CYJ TROJAN!"
|
| X | ImMsn | timed.exe | "Added by the WEBDOR.AK TROJAN!"
|
| X | IMprocess | IM-svr.EXE | "IMNames adware"
|
| U | ImScInst | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | ImScInst.exe | ImScInst.exe | "Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails |
| U | IMStart | IMStart.exe | "InterMute security software related"
|
| X | imwinsrvc | acpmonsrv.exe | "Added by the SLAPER.E TROJAN!"
|
| X | imxecs | vbrun70sp4.exe | "Added by the AGOBOT.ALA WORM!"
|
| N | InControl Desktop Manager | DMHKEY.EXE | For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
|
| X | Index Service | dllhost32.exe | "Added by the AGOBOT.CH WORM!"
|
| U | Index Washer | WashIdx.exe | "Window Washer from Webroot Software. Useful utility that deletes safe to remove files |
| N | IndexSearch | IndexSearch.exe | "Part of Nuance (ScanSoft) PaperPort - ""scan |
| U | IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMIndexStoreSvr.exe | "Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
|
| X | ine | svchosts.exe | "Added by the RBOT.BNL WORM!"
|
| X | INET | inetsync.exe | "Meplex adware"
|
| X | Inet DataBase | Inetdbs.exe | "Added by the QEDS WORM!"
|
| X | InetChk | ms[random value].exe | "Added by the AGENT-IRL TROJAN!"
|
| X | InetMSN | msnet.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | InetServices | wsock32.exe | "Added by the WOCK32-A TROJAN!"
|
| X | infamous.exe | wmplayer.exe | Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
|
| X | InfeStop | InfeStopRemover.exe | "InfeStop rogue spyware remover - not recommended |
| X | info | smss.exe | "Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
|
| U | Info Select | is.exe | "Info Select from Micro Logic - personal information manager"
|
| U | InfoPenMSN | InfoPenIM.exe | "InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
|
| X | infus | infus.exe | Adult content dialler
|
| X | Initial Page | install.exe | EasySearch browser hijack installer
|
| X | inixs | minix32.exe | "Added by the AGENT.CKQX TROJAN!"
|
| X | injob | injobs.exe | "Added by the BINJO TROJAN!"
|
| X | Inom | snmoo.exe | "Added by the RBOT-DPM WORM!"
|
| U | InoTask | InoTask.exe | "Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
|
| X | iNotice | iservice.exe | Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
|
| ? | insCOA5 | insCOA5.exe | "??"
|
| X | Insider | Insider.exe | "Added by the AGENT.KMC TROJAN!"
|
| U | InstaAlert | InstaAlert.exe | """Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
|
| X | Instafinder | instafinder.exe | "TopSearch.D adware"
|
| X | InstaFinderK | InstaFinderK inst.exe | "InstaFinder adware"
|
| X | Install | Install.exe | "Added by the BANCBAN-HG TROJAN!"
|
| X | Install part II | updates.exe | "Added by the RELFEERWORM!"
|
| ? | Install Pending Files | sifxinst.exe | "Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
|
| x | install32 | install32.exe | "Added by the NUCLEAR.DG BACKDOOR!"
|
| N | InstallAurealDemos | InstallAurealDemos.js | Used to initialize the Aureal A3D demos InstallShield wizard
|
| U | InstallBuddy | Ibtna.exe | "InstallBuddy - automatically translates and installs your desktop documents |
| X | InstallCleaner | InstallCleaner.exe | "Added by the ANYHOMB.F TROJAN!"
|
| X | Installed shell32.dll | Office.exe... | "Added by the LOVGATE.AO WORM!"
|
| X | Installed shell32.dll | Office.exe | "Added by the LOVGATE.E WORM!"
|
| X | Installer | dial.exe | "Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
|
| ? | InstallNAIProduct | SETUP.EXE | "Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
|
| X | InstallProgram | [path to trojan] | "Added by the AGENT-HHU TROJAN!"
|
| X | InstallProvider | newsoftware2007install.exe | "Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
|
| X | Installs SP2 | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
|
| X | Installs SP4 | [path] repcale.exe [path] p0rd.exe | "Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
|
| U | Installstub | installstub.exe | "Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
|
| X | Instance 001 | [path to worm] | "Added by the ALASROU-A WORM!"
|
| X | Instant Access | "rundll32.exe EGDHTML_1023.dll | InstantAccess" |
| X | Instant Access | "rundll32.exe eg_auth_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMLIB_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe EGCOMSERVICE_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | "rundll32.exe p2esocks_****.dll | InstantAccess [**** = digits]" |
| X | Instant Access | mwsrvacc.exe | "InstantAccess premium rate adult content dialer"
|
| X | Instant Access | linewsrv.exe | "InstantAccess premium rate adult content dialer variant"
|
| X | Instant Buzz Daemon | IBDaemon.exe | "Instant Buzz adware"
|
| X | Instant Messenger Service | imservice.exe | "Detected by Kaspersky as the HEUR TROJAN!"
|
| X | instant messengers | instantmsgtr.exe | "Added by the AGOBOT-PC BACKDOOR!"
|
| N | Instant Update Center | reminder.exe | "Event reminder for calendar dates |
| U | Instant Wireless Configuration Utility | WUSB11cfg.exe | "Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| U | Instant Wireless Configuration Utility | WPC11Cfg.exe | "Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
|
| N | InstantAccess | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
|
| U | InstantDrive | InstantDrive.exe | "Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
|
| X | InstantPleasure | instantpleasure.exe | Adult content dialler
|
| X | InstantPleasureXXX | instantpleasurexxx.exe | Adult content dialler
|
| N | InstantTray | PCLETray.exe | "Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
|
| X | instit | instit.bat | "Added by the OPASERV.H WORM!"
|
| X | instit | INSTIT.BAT | "Added by the OPASERV.K WORM!"
|
| ? | InstUtlR.exe | InstUtlR.exe | "??"
|
| X | InSysSecure | InSysSecure.exe | "InSysSecure rogue security software - not recommended |
| X | Intec Service Drivers | msmsgrs.exe | "Added by the SDBOT-ADN WORM!"
|
| X | Intec Service Drivers | [path to worm] | "Added by the RBOT-GLU WORM!"
|
| X | Intec Service Drivers | wing32.exe | "Added by the RBOT.HAZ WORM!"
|
| X | Intec Service Drivers | msmsgredss.exe | "Added by the SDBOT-AGL WORM!"
|
| X | Intec Services Driverrs | winrvc.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Intec Services Drivers | msupdate22e.exe | "Added by the RBOT-CGC WORM!"
|
| X | Intel Audio Studio V2.0 | fmideploy.exe | Detected by VBA32 as the BIFROSE.ADR TROJAN!
|
| X | Intel Driver | csrs.exe | "Added by a variant of the SDBOT WORM!"
|
| U | Intel File Transfer | xfr.exe | Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
|
| X | Intel Management Services v32 | mstime32.exe | "Added by the AUTORUN-AYG WORM!"
|
| U | Intel PDS | pds.exe | Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
|
| X | Intel Physical Routine 1.2A | stnetlib.exe | "Added by the BACKDR-AS BACKDOOR!"
|
| N | Intel PROSet Tray Icon | promon.exe | System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
|
| X | Intel Service Drivers | msconfig16.exe | "Added by the MSCONFIG16 TROJAN!"
|
| X | Intel system tool | hookdump.exe | "Added by the SPYRE-H TROJAN!"
|
| X | Intel system tool | winnook.exe | "Added by the SPYRE-C TROJAN!"
|
| X | Intel system tool | svehost.exe | "Added by the AGENT-EBT TROJAN!"
|
| X | Intel system works | iis.exe | "Added by the RBOT.QGA WORM!"
|
| U | Intel(R) Common User Interface | igfxtray.exe | "System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| U | Intel(R) Common User Interface | igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
| N | IntelAudioStudio | IntelAudioStudio.exe | """Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience"". Audio utility supplied with some Intel motherboards"
|
| X | InteliSys | smss.exe | "Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Intelli Mouse Pro Version 2.0B | ncsjapi32.exe | "Added by the BUZUS-O WORM!"
|
| X | Intelprc | Aas3lovu.exe | "Added by the SILLYFDC-CG WORM!"
|
| Y | IntelWireless | ifrmewrk.exe | Associated with the Intel PRO/Set Wireless software
|
| U | IntelZeroConfig | ZCfgSvc.exe | "Zero Config MFC Application |
| ? | Intense Registry Service | IntEdReg.exe /CHECK | "Intense Educational Ltd - Language Office Software. Is it required?"
|
| X | InterceptedSystem | [path to worm] | "Added by the ANACON-B WORM!"
|
| X | Internal | regedit.exe /s c[month number] | "Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir% |
| X | Internal Memory File | sysintmemory.exe | "Added by the RBOT-GKT WORM!"
|
| X | InternalSystray | Kazza.exe | "Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable |
| X | Internat | systray.exe | "Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
|
| X | Internat | msgsrv32.exe | "Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
|
| X | internct | WinSocks5.exe | "Added by the GRAYBIRD.F TROJAN!"
|
| X | internet | smss.exe | "Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
|
| X | Internet | nteusodp.exe | "Added by the RBOT-GFJ WORM!"
|
| X | internet | winsas32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | internet | lsass.exe | "Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | Internet | alm7tas.exe | "Added by a variant of the RBOT WORM!"
|
| X | Internet | wins.exe | "Added by the RBOT.AAYF WORM!"
|
| U | Internet Answering Machine | IAMNET~1.EXE | "From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| U | Internet Answering Machine | IAM.exe | "From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
|
| X | Internet Antivirus | IAvir.exe | "Internet Antivirus rogue security software - not recommended |
| X | Internet Antivirus Pro | IAPro.exe | "Internet Antivirus Pro rogue security software - not recommended |
| X | Internet Config | svchosts.exe | "Added by the SDBOT TROJAN!"
|
| X | Internet Connection Wizard | stisvsq.exe | "EasySearch adware"
|
| X | Internet Connection Wizard | stisvsq1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Internet Content Publisher | ICP.EXE | "Added by the RBOT-UD WORM!"
|
| U | Internet Disk Cleaner | CLEARH~1.EXE | """Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
|
| X | Internet download manager service | idman.exe | "Added by the RBOT-BMS WORM!"
|
| X | Internet Exploere Services | urlmon32.dll.exe | "Added by the EVIAN.C WORM!"
|
| X | Internet Explore Microsoft | lEXPLORE.EXE | "Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
|
| X | Internet Explorer Security | iexplore.pif | "Added by the RBOT-ALQ WORM!"
|
| X | Internet Explorer Sys32 | isys32.exe | "Added by the IRCBOT-ADA WORM!"
|
| X | Internet Firewall Layer | tsqla.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | Internet History Eraser | HERASER.exe | "Internet History Eraser - deletes your browsing tracks"
|
| X | Internet Loader1 | MSInstall61.exe | "Added by the KWBOT.B WORM!"
|
| X | Internet Mail and News | msqdevl.exe | "EasySearch adware"
|
| X | Internet Mail and News | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Internet Mail and News | msqdevl1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Internet Security 2010 | IS2010.exe | "Internet Security 2010 rogue security software - not recommended |
| X | Internet Security Service | msq32.exe | "Added by the RBOT-GFP WORM!"
|
| X | Internet Security Service | msq23.exe | "Added by the RBOT-GQL WORM!"
|
| X | Internet Security Service | msql23.exe | "Added by the RBOT-GML WORM!"
|
| X | Internet Security Service | mysqlwin32.exe | "Added by the RBOT.UX TROJAN!"
|
| X | Internet Security Service | expllorer.exe | "Added by the REFROSO.AFF TROJAN!"
|
| X | Internet Send | More log.exe | Unidentfied adware
|
| X | Internet Server | inetsrv.exe | "Added by the STARTPA-EM TROJAN!"
|
| X | Internet Service | intersvc.exe | "Added by the SPYBOT-DE WORM!"
|
| X | internet service | syscfg32.exe | "Added by the RBOT-QS WORM!"
|
| X | internet service | ssvhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | internet service | svho0st98.exe | "Added by the RBOT.EAT WORM!"
|
| X | Internet Services | systemdev.exe | "Added by the SDBOT-PW WORM!"
|
| X | Internet Services | internet.exe | "Added by the MYTOB.BT WORM!"
|
| X | Internet Services | interserv.exe | "Added by the RBOT.BNT WORM!"
|
| X | Internet Services | Netsvc.exe | "Added by the MYTOB.MN WORM!"
|
| X | INTERNET SERVISES | winz32.exe | "Added by the KWBOT.Z WORM!"
|
| Y | Internet Sharing Server | iss_srvr.exe | "Intel AnyPoint internet sharing software. Now discontinued"
|
| X | Internet Suspention | story.exe | "Added by the WOOTBOT.HV WORM!"
|
| N | Internet Sweeper | Sweeper.exe | "Internet Sweeper - removes unnecessart left over files after browsing the internet"
|
| X | Internet Washer Pro | iw.exe | "Internet Washer manages temporary browser files |
| X | internet.exe | yinyin3345.vbs | "Added by the YINI MACRO!"
|
| N | InternetCalls | InternetCalls.exe | "InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| X | InternetExplorer2 | windows.exe | "Added by the SDBOT-CZP WORM!"
|
| X | InternetGetConnectedState | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetGetConnectedStateEx | winupdate.exe | "Added by the SDBOT-JN WORM!"
|
| X | InternetShield | INTERN~1.EXE | "InternetShield rogue security software - not recommended |
| X | InternetShield | InternetShield.exe | "InternetShield rogue security software - not recommended |
| U | InternetSpy | InternetSpy.exe | "Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!"
|
| X | InternetWasherPro | iw.exe | "Internet Washer manages temporary browser files |
| X | Internet_Explorer | microsoft.exe | "Added by the BANKER-EUQ TROJAN!"
|
| X | INTERNET_SERVISES | winz32.exe | "Added by the SDBOT.Q TROJAN!"
|
| U | InternodeUsage | mum.exe | Australian ISP's free monthly download meter
|
| X | Inters Configuration Loader | RCL0ADERS.exe | "Added by the SDBOT-KX WORM!"
|
| X | Intersoft Msngr | intersoftmsngr.exe | "Added by the AGOBOT-NW WORM!"
|
| N | InterTrust Quick Start | it_cpq~1.exe | "InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business"
|
| N | Intervideo WinScheduler | WinScheduler.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| N | Intervideo WinScheduler | SchSvr.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| X | Intespention | IEXPLORE.exe | "Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | intranet | SYS32CFG.EXE | "Added by the SPYBOT-DW WORM!"
|
| X | Intranet | schost.exe | "Added by the RBOT.SV BACKDOOR!"
|
| N | Introducing Media Manager | SPLASHA.EXE | "MS Media Manager tour. Not required"
|
| N | Introduction-Registration | ?? | "For Compaq PC's. Should only run first time |
| X | IntSys1 | [path to trojan] | "Added by the BANLOA-ASE TROJAN!"
|
| Y | Intuit SyncManager | IntuitSyncManager.exe | "Synchronizes local Intuit Quickbooks data with online data - ""Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync |
| U | Inventory Scan | LDISCN32.EXE | "LANDesk® Management Suite software component"
|
| Y | iolo AntiVirus | ioloAV.exe | "iolo AntiVirus"
|
| Y | iolo Personal Firewall | ioloFW.exe | "iolo Personal Firewall"
|
| U | Iolo Task Agent | Task_Agent.exe | "Iolo System Mechanic Task Agent. Scheduled maintenance"
|
| N | iolo Utility Bar | SMUtilityBar.exe | "Iolo System Mechanic Utility Bar - can be launched manually"
|
| N | Iomega Backup Scheduler | dtiom98.exe | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| U | Iomega Disk Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| U | Iomega Drive Icons | IMGICON.EXE | "Displays Iomega icons in Explorer/My Computer |
| ? | Iomega QuickSync | Quicksync.exe | "??"
|
| N | Iomega Startup Options | IMGSTART.EXE | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
| X | ioroxxo microsoft sux | system32.exe | "Added by a variant of the RBOT WORM!"
|
| X | IP Packet Redirect Service | ipredirect.exe | "Added by the FORBOT.SM WORM!"
|
| X | IP Stack | ipstack.exe | "Added by the AGOBOT.CW WORM!"
|
| X | IPC Spool Manager | wnmgre.exe | "Added by the SDBOT-ZC WORM!"
|
| X | IPC Spool Manager | winspec.exe | "Added by the SDBOT-BLU WORM!"
|
| X | IPConfig | svcxnv32.exe | "Added by the HACARMY.E TROJAN!"
|
| X | IPConfig | svcxnw32.exe | "Added by a variant of the HACARMY.E TROJAN!"
|
| X | IPConfig | ipconfigs.exe | "Added by the HACARMY.C BACKDOOR!"
|
| ? | IPHSend | IPHSend.exe | "AOL related. What does it do and is it required?"
|
| N | IPInSightLAN 01 | IPClient.exe | "IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth |
| N | IPInSightMonitor 01 | IPMon32.exe | "IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth |
| Y | IPinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
|
| X | IPLog Security | iplogsec.exe | "Added by the IRCBOT.GP BACKDOOR!"
|
| ? | iPlusAgent2 | iAgent2.exe | "Related to iriver portable media products. What does it do and is it required?"
|
| X | Ipnuker | Ipnuker.vbs | "Added by the INKER.B WORM!"
|
| X | Ipod Help | [9 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | iPOD USB Driver | IPODUSB.EXE | "Added by a variant of the RBOT WORM!"
|
| X | iPod USB Service | iPODService.exe | "Added by a variant of the RBOT WORM! Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service |
| X | IPOT Service Drivers | compaq.exe | "Added by a variant of the FUROOTKIT TROJAN!"
|
| X | IPOT USB Service DRIVER | hpsebc087.exe | "Added by the SDBOT-WA WORM!"
|
| X | IPOT USB Service DRV32 | hpsebc08.exe | "Added by the SDBOT-WH WORM!"
|
| X | IPSEC Configuration | wsupdate.exe | "Added by the AGOBOT-IQ WORM!"
|
| X | iPSec7 | ipsec7.exe | "Added by the AGENT.AHVR TROJAN!"
|
| U | ipsecdialer | IPSECD~1.EXE | "Cisco VPN Client - lets local users gain Administrator privileges on the operating system"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
|