| Y | Desktop Armor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | Desktop Calendar | Desktop Calendar.exe | "Desktop Calendar - ""Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar |
| X | Desktop Defender 2010 | Desktop Defender 2010.exe | "Desktop Defender 2010 rogue security software - not recommended |
| U | Desktop iCalendar | Calendar.exe | "Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather |
| U | Desktop iCalendar | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop iCalendar Lite | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar Lite.exe | Desktop iCalendar Lite.exe | "Desktop iCalendar Lite by Desksware - ""is a free desktop calendar for Windows. It allows you to manage your events |
| U | Desktop iCalendar.exe | Desktop iCalendar.exe | "Desktop iCalendar by Desksware - ""is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar |
| U | Desktop Maestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | Desktop Maestro Vista Tray | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | Desktop Plant | AZARE10S.PLT | "Vritual plant from here - this version is an Azalea |
| X | Desktop Search | desktop.exe | "iSearch adware"
|
| X | Desktop Security 2010 | Desktop Security 2010.exe | "Desktop Security 2010 rogue security software - not recommended |
| N | Desktop Service Centre | DSC.exe | OptusNet DSL or Dial-Up connection software
|
| N | Desktop Weather | THE WEATHER CHANNEL.exe | "Desktop Weather by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THE WEATHER CHANNEL.exe | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| N | Desktop Weather 3 | THEWEA~1.EXE | "Desktop Weather 3 by The Weather Channel - provides current temperature |
| Y | DesktopArmor | DesktopArmor.exe | "Desktop Armor from Headlight Software - ""watches dozens and dozens of important settings on your computer and warns you if any program has changed them"" including those made by malware"
|
| U | DesktopIconToy | DesktopIconToy.exe | """Desktop Icon Toy is an easy to use desktop icon enhancement tool |
| U | DesktopMaestro | deskmech.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| U | DesktopMaestro | RMTray.exe | "Part of Desktop Maestro from PC Tools - which ""combines the features of our award winning products |
| N | desktopmgr | desktopmgr.exe | "Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds |
| X | DesktopUpdate | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | DesktopX | DESKTOPX.EXE | "A program that replaces the regular Desktop and Taskbar |
| X | destroyb11 | destroyb11.exe | "Added by the DELF-KO TROJAN!"
|
| U | detect | idetect.exe | "iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled"
|
| ? | detect | turbodetect.exe | "??"
|
| N | Detector | detector.exe | "USB port detector for LG scanners. Sits in the System Tray |
| U | DetectorApp | DetectorApp.exe | "Related to Roxio MyDVD (was Sonic) DVD authoring software"
|
| ? | DevconDefaultDB | READREG | "Appears to be related to older Creative Soundblaster soundcards"
|
| X | Development Environment | devenv.exe | "Added by the DELBOT-AH WORM!"
|
| U | DEventAgent | eventagt.exe | DEvent Agent Module client - part of Dell OpenManage and used for server management. Only required if you use this
|
| X | Device Configuration Loader | msdvc32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| U | Device Detector | DevDetect.exe | "ACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automatically"
|
| N | Device Detector 2 | DevDtct2.exe | "Installed by various Olympus products |
| X | Device IO System | deviceio.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Management | wnsystem.exe | "Added by the AGOBOT-LH WORM!"
|
| X | Device Security | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Driver | devicesec.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Device Security Manager | dvcsecure.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| U | DeviceDiscovery | hpotdd01.exe | "Detection of new imaging |
| X | DevicePath | Proyecto1.exe | "Added by the GRUEL WORM!"
|
| X | DevicePath | Root.exe | "Added by the GRUEL WORM!"
|
| X | Devicewin | [path to trojan] | "Added by the BANKER-AEV TROJAN!"
|
| X | dfgfdgrergd | [path to trojan] | "Added by the RANKY.CK TROJAN!"
|
| X | dgtstart | dgtstart.exe | "DigitalNames.g adware"
|
| Y | dhcpagnt | dhcpagnt.exe | Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
|
| X | DI2 | [path to file] | "BroadcastPC adware"
|
| N | diagent | diagent.exe | System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
|
| X | Diagnostic | diagnostic.exe | "Added by the ALPHA-C TROJAN!"
|
| X | Diagnostic Agent | diagent.exe | "Added by the AGOBOT-CW WORM!"
|
| U | Dialer Control | dc.exe | "Dialer-Control. Detects and protects from premium rate adult content diallers"
|
| U | Dialer Detect | dd.exe | "DialerDetect detects stealth installed premium rate diallers |
| X | DialNet | mxt32.exe | Adult content dialler
|
| N | Dialog Box Assistant | OSDEx.exe | "Dialog Box Assistant from Duality Software. Helps with the standard Open and Save As dialog boxes by showing recently used files and folders"
|
| X | DialUp Network Application | Rnaap.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Diesel | Recalculate.exe | "Added by the LAZAR TROJAN!"
|
| U | DietK | DietK.exe | "Diet Kazaa add-on for Kazaa Media Desktop - ""removes all adware and popups |
| X | DigiD | DigitalSound.exe | Adware downloader
|
| N | DigiGuide | CLIENT.EXE | TV guide and reminder
|
| N | DigiGuide | client01.exe | TV guide and reminder
|
| U | Digisoft AntiDialer | AntiDialer.exe | "Digisoft AntiDialer"
|
| N | Digital Dashboard | devgulp.exe | For Compaq PC's. Loads Digital Dashboard options
|
| N | Digital Line Detect | DLG.exe | Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
|
| Y | Digital Patrol Update 5 | update.exe | "Digital Patrol - ""a powerful anti trojan scanner |
| X | Digital Protection | digprot.exe | "Digital Protection rogue security software - not recommended |
| N | Digital River eBot | downlo~1.exe | "Digital River Systems EBOT for downloading software from their site. In some cases |
| X | DigitalNames | DigitalNamesStart.exe | "DigitalNames spyware variant"
|
| N | DigitalWizard | ISWizard.exe | "InstallShield's DigitalWizard - free |
| N | DigitalWizard Monitor | dwMon.exe | "InstallShield's DigitalWizard - free |
| N | DIGStream | digstream.exe | "DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically"
|
| X | Dinst | dinst.exe | "IMIServer/IEPlugin adware"
|
| X | Direct settings | sdchost.exe | "Added by the DAEMONI-I TROJAN!"
|
| U | Direct Update | DUControl.exe | "DirectUpdate dynamic DNS updater"
|
| X | Direct X Direct3D | dxd3d.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Direct X Opengl | dxopengl.exe | "Added by a variant of the RBOT-CJ WORM!"
|
| X | direct3d.exe | direct3d.exe | "Added by the CERTIF-F TROJAN!"
|
| N | DirectCD | DirectCD.exe | DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
|
| X | Director Video | btnmgern.exe | "Added by the MYTOB-KL WORM!"
|
| Y | Directory Opus Desktop Dblclk | dopusrt.exe | "Directory Opus - an advanced file manager. ""Directory Opus goes beyond the simple file manager metaphor |
| X | directs.exe | directs.exe | "Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!"
|
| U | DIRECTVDSL | Directvdsl.exe | Starts DirectTV DSL modem at boot up. Can also be started manually
|
| X | DirectX | ddhelp32.exe | "Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe"
|
| X | directx | Directx.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | Sqlexploit.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX | DirectX.exe | "Added by the BLAXE or LOGPOLE WORMS!"
|
| X | directx | NTCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | directx | PipeCmd.exe | "Added by the SDBOT.D TROJAN!"
|
| X | DirectX 32 | directx32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | DirectX Driver | stdhost.exe | "Added by the SDBOT.GVJ BACKDOOR!"
|
| X | DirectX For Microsoft Windows | dtxservice.exe | "Added by the PROGENT TROJAN!"
|
| X | DirectX for Microsoft Windows | Fservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX for Microsoft Windows | Sservice.exe | "Added by the PRORAT TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-P TROJAN!"
|
| X | DirectX For Microsoft® Windows | fservice.exe | "Added by the PRORAT-L TROJAN!"
|
| X | DirectX shell driver | [path to trojan] | "Added by the MARKTMAN-B TROJAN!"
|
| X | Directx Startup Drivers | direct.exe | "Added by the RBOT.UXL WORM!"
|
| X | DirectX Video Driver | dxterm5.exe | "Added by the WILAB-A TROJAN!"
|
| X | DirectX64 | DirectXset.exe | "Added by the BROWNEY.A WORM!"
|
| X | DirectX9 | direct3d.exe | "Added by the AGENT.EAK TROJAN!"
|
| X | DirectX9 | svchost32.exe | "Added by the RBOT.AQG WORM!"
|
| X | DirectX9 Diag | dx9diag.exe | "Added by the RBOT-ALT WORM!"
|
| N | Disc Detector | CtNotify.exe | "For Creative sound cards. Detects when you insert a CD |
| ? | disc detector | qnetquestnotifty.exe | "??"
|
| U | DiscUpdateManager | DiscUpdMgr.exe | "Disc Update Manager for Digital interactive's DISCover Console. Provider of on-demand video games"
|
| N | DiscUpdateManager | DiscUpdateMgr.exe | "DISCover from Digital Interactive Systems Corporation Inc. ""The company's patented Drop 'n' Play technology provides a simple |
| U | DiscWizardMonitor.exe | DiscWizardMonitor.exe | "Seagate DiscWizard - hard disk utility for Seagate's SATA and PATA (IDE) drives"
|
| X | Disk Defragmentation Loader | pmsvcr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Essensial Tools | detsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Disk Keeper | [path to trojan] | "Added by the SMALL-VE TROJAN!"
|
| X | Disk Keeper | SECURITY.EXE | "Daosearch adware"
|
| X | Disk Master | [trojan name] | "Added by the DISTER TROJAN! - a spam relayer"
|
| X | Disk Panel Configuration | dpcsvc.exe | "Added by the IRCBOT.BSQ BACKDOOR!"
|
| X | Disk Panel Setup | npcsvc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| N | DiskeeperSystray | DkIcon.exe | "DisKeeper defragmentation software - can be started manually"
|
| X | DiskRetter | SysRep.exe | "DiskRetter |
| X | Diskstart | Code.exe | Adult content dialler
|
| X | Diskstart | cat.exe | MS-Connect dialler
|
| X | Diskstart | hit.exe | Adult content dialler
|
| X | Diskstart | Snt.exe | Adult content dialler
|
| U | DiskSuite | aDSProcMngr.exe | "Part of PC Tools Disk Suite from PC Tools - which ""is an all-in-one hard-disk management utility that integrates disk optimization |
| U | Disk_Monitor | Disk_Monitor.exe | "Multi-media |
| X | Dispatcher | dispatcher.exe | "Added by the DLOADR-AS TROJAN!"
|
| X | dispenter | dispenter.exe | "Added by the AGENT-MKK TROJAN!"
|
| U | display | The_Eye.exe | "ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself"
|
| N | Display Settings | hptasks.exe | "Allows for the adjustment of the display for LCD screen |
| N | DisplayTrayIcon | TrayIcon.exe | "System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution |
| X | Dist-FBGeneve | GDC.exe | "NettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | Distiller Assistant 3.01 | DISTASST.EXE | From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
|
| X | Distributed File System | Dfsvc.exe | "Added by the MYFIP.A or MYFIP.K WORMS!"
|
| X | Distributed File System | kernel32dll.exe | "Added by the MYFIP-C or MYFIP.K WORMS!"
|
| X | Distributed File System | blade.exe | "Added by the MYFIP.AC WORM!"
|
| X | Distributed File System | win.exe | "Added by the MYFIP.AB WORM!"
|
| X | Distributed Link Tracking | ascvt.exe | "Added by the AGOBOT-GH BACKDOOR!"
|
| U | distributed.net client | DNETC.EXE | "Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses"
|
| Y | Dit | dit.exe | ""Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required |
| X | Dit | dit.exe | "Added by the LAZAR-A TROJAN! Note - this is located in %System%"
|
| N | DiTask.exe | DiTask.exe | "Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free |
| X | DivX Updater | DivX.Exe | "Added by the NALDEM TROJAN or MASTAK VIRUS!"
|
| ? | Dixons Insert Detect | InsDetect.exe | "Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | DJRegFix | regedit /s c:hpdjregfix.reg | "DJRegFix showed up first in WinME as a ""clever"" way to ensure that all Hewlett-Packard DeskJet printers actually worked with WinME - since most were having major problems. This ""utility"" adds the functionality and compatibility HP forgot to add in its WinME drivers"
|
| ? | DJSNetCN | DJSNetCN.exe | """Symantec Licensing Detect Internet Connection"" |
| X | djtopr1150.exe | djtopr1150.exe | "WebRebates adware"
|
| X | DKTime | dktime.exe | "Added by the LUNII TROJAN!"
|
| X | Dkware lptt01 | dkware.exe | "RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | dla | tfswctrl.exe | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLA | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| Y | DLACTRLW.EXE | DLACTRLW.EXE | "Drive letter access to a UDF packet writer for CD-RW - from HP |
| N | DlaTray | Dlatray.exe | "System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - ""This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"""
|
| Y | DLBTCATS | "rundll32 [path] DLBTtime.dll | _RunDLLEntry@16" |
| Y | DLBUCATS | "rundll32 [path] DLBUtime.dll | _RunDLLEntry@16" |
| Y | DLBXCATS | "rundll32 [path] DLBXtime.dll | _RunDLLEntry@16" |
| Y | DLCCCATS | "rundll32 [path] DLCCtime.dll | _RunDLLEntry@16" |
| Y | DLCDCATS | "rundll32 [path] DLCDtime.dll | _RunDLLEntry@16" |
| Y | DLCFCATS | "rundll32 [path] DLCFtime.dll | _RunDLLEntry@16" |
| Y | DLCGCATS | "rundll32 [path] DLCGtime.dll | _RunDLLEntry@16" |
| Y | DLCICATS | "rundll32 [path] DLCItime.dll | _RunDLLEntry@16" |
| Y | DLCJCATS | "rundll32 [path] DLCJtime.dll | _RunDLLEntry@16" |
| Y | DLCQCATS | "rundll32 [path] DLCQtime.dll | _RunDLLEntry@16" |
| Y | DLCXCATS | "rundll32 [path] DLCXtime.dll | _RunDLLEntry@16" |
| U | dldtamon | dldtamon.exe | Dell AIO Printer V305 device monitor
|
| U | dldtmon | dldtmon.exe | Dell AIO Printer V305 device monitor
|
| U | dldtmon.exe | dldtmon.exe | Dell AIO Printer V305 device monitor
|
| N | DLHelperEXE | WATCH.exe | Download helper distributed with some software that allows the software installation to redirect download locations. Not required once the installation is finished
|
| X | dlhost | dlhost.exe | "Added by the EXPHOOK-A TROJAN!"
|
| X | DLINK dfe drivers for Windows NT | windfe.exe | "Added by the RANDEX.AK WORM!"
|
| U | DLink System Tray | dlnetst.exe | "Related to D-Link DGE-530T PCI card for servers and workstations"
|
| X | Dlite | dllmanager.exe | "Added by the WOOTBOT.DN WORM!"
|
| X | Dll Boot Loader on Startup (do not remove this) | [various filenames] | Added by an unidentified TROJAN!
|
| X | Dll Link | svchoist.exe | "Added by the AUTOSKY WORM!"
|
| X | Dll Link | svchost.exe | "Added by the AUTOSKY WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Favourites folder"
|
| X | DLL Service Manager | [path to worm] | "Added by the RPCBOT.F TROJAN!"
|
| X | DLL32 | dllhost.dll | "Added by the SUCLOVE.A WORM!"
|
| X | dlldmt | dlldmt.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| X | DllExecutable | [path to file] | "Added by the VB-SP WORM!"
|
| X | DLLHost | dllhst.exe | "Added by the DELBOT-AC WORM!"
|
| X | DllHost | dllhost.exe | "Added by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Inf"
|
| X | dllhostxp.exe | dllhostxp.exe | Browser hijacker and adware downloader
|
| X | DLLUPDATE32 | dllupdate32.exe | "Added by the AGOBOT.IA WORM!"
|
| Y | DLO Agent | DLOClientu.exe | "Part of the backup suites from VERITAS - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005"
|
| ? | DLT | dlt.exe | "??"
|
| U | DMHotKey | DMLoader.exe | HotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1
|
| X | dmtdll | dmtdll.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| U | DmwClient | dmwclient.exe | "DMW ""anti-cheating"" software for online gaming"
|
| X | dm[3 random letters].exe | dm[3 random letters].exe | "Added by the RUINDEM TROJAN!"
|
| X | dm_service | [path to file] | "Added by the MITGLIEDER.P TROJAN!"
|
| N | DNA | btdna.exe | """BitTorrent DNA is a FREE content delivery service based on the BitTorrent protocol which brings the power of user-contributed bandwidth to traditional content publishers while leaving publishers in full control of their files"". Now a stand-alone product where the user creates the download |
| X | dnam | d140113.a.Stub.EXE | "Added by the STUB_A TROJAN!"
|
| Y | DNE Binding Watchdog | "rundll dnes.dll | DnDneCheckBindings" |
| Y | DNE DUN Watchdog | "rundll dnes.dll | DnDneCheckDUN13" |
| ? | DNS2GoClient | dns2goclient.exe | "DNS2Go is a Domain Name System that will make your computer accessible anytime |
| X | DnsCache | Wscript.exe dns_cache.vbs | "Added by the AUTORUN-AWI WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""dns_cache.vbs"" file is located in %System%"
|
| X | DNSCacheBoost | dnsping.exe | "Added by the DNSBUST-A TROJAN!"
|
| X | DocTor | Doctor.exe | "Added by the DOTOR.A WORM!"
|
| X | Doctor Antivirus 2008 | antvr.exe | "Doctor Antivirus 2008 rogue security software - not recommended |
| N | DocuMagix Init | PWATCH.EXE | "PaperMaster is an application for the PC designed to automate the process of organizing |
| U | Document Manager | docmgr.exe | "Wave Systems Corp. Document Manager - ""provides secure storage and management capabilities for file and folder level encryption"""
|
| X | Doggy Style | MsPMSPSd.exe | "Added by the SDBOT-AAP WORM!"
|
| X | DOGStart | GSDOGST.EXE | "Added by an unidentified VIRUS |
| X | doit.exe | doit.exe | "Added by the FORBOT-EK WORM!"
|
| X | DokterFix | SysRep.exe | "DokterFix |
| U | Don't Panic | dontpanicdemodp.exe | "30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite.""
|
| U | Don't Panic Pop-Up Stopper | dpps2.exe | "Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group"
|
| U | Don't Panic! | DP.EXE | "Don't Panic! privacy software from Panicware. ""Clean up Internet tracks and quickly hide personal documents with this privacy suite"""
|
| X | Dontworry | mysaym.exe | "Added by the SDBOT-RC WORM!"
|
| X | Dos Prompt Loader | cygwin.exe | "Added by the SDBOT-VV WORM!"
|
| ? | Dosbat | ?? | "??"
|
| X | Dot1XCfg | Dot1XCfg.exe | "Added by the AGOBOT.EA TROJAN!"
|
| U | DoubleDesktop | dd.exe | """DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"""
|
| N | DoUWantIt | duwi.exe | DoUWantIt - online shopping assistant. Start it manually
|
| X | down | [trojan filename] | "Added by the SMALL-QJ TROJAN!"
|
| N | Download Accelerator Manager Free Edition | dam.exe | "Download Accelerator Manager Free Edition from Tensons Corp"
|
| N | Download Accelerator Plus 5.0 | DAP.exe | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| N | DownloadAccelerator | DAP.EXE | "Download Accelerator Plus from Speedbit. Download manager for resuming downloads |
| X | Downxz | Downxz.bat | "Added by the MYDOOM.W WORM"
|
| Y | DpAgent | dpagent.exe | "Part of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for example"
|
| N | DPAgnt | DPAgnt.exe | "digitalPersona fingerprint scanner"
|
| Y | DPAS | DPASNT.exe | "DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | DPASUpdate | DPASAutoUpdate.exe | "Automatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1"
|
| Y | DPCProxyLoadOnStartup | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| Y | Dpcstart | dpcstart.exe | "DirecWay from DirectTV (now HughesNet) - satellite based high-speed internet access"
|
| N | dptracker | dptracker.exe | "CamTrack webcam software that enhances the way people video chat"
|
| U | DpUtil | TEDTray.exe | "Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device"
|
| X | dpzProtect | n.vbe | "Added by the RUNAUTO.H WORM!"
|
| X | DR service | [path to worm] | "Added by the RBOT-CZT WORM!"
|
| N | Drag'n'Drop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| N | Drag-to-Disc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| N | DragnDrop_Autolaunch | Autolaunch.exe | "Iomega HotBurn - CD-RW burning software"
|
| X | DRam Monitor 23 | tskman3.exe | "Added by a variant of the RBOT WORM!"
|
| X | DRam prosessor | WindowsUpdate.exe | "Added by the RBOT-BBZ WORM!"
|
| X | DRam prosessor | msupdate.exe | "Added by the DELF-FAW TROJAN!"
|
| X | DRam rar proc | winupdaterar.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | DRam rare proc | updaterarwin.exe | "Added by the RBOT-GQW WORM!"
|
| X | DrAntispy | DrAntispy.exe | "DrAntiSpy rogue security software - not recommended"
|
| X | DrCache | MSTDC.EXE | "Added by the BDOOR-JM BACKDOOR!"
|
| N | DrgToDsc | DrgToDsc.exe | "System Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. ""Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically"". Not required for Roxio to work properly and available via the Start menu"
|
| X | drin | [path to trojan] | "Added by the SMALL.DPB TROJAN!"
|
| X | Driver | gbot.exe | "Added by the JUNTADOR.K TROJAN!"
|
| X | DriverCheck | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | DriverLoad | svchost.exe | "Added by the DELF-KR TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""DriverLoad"" sub-directory of the Root folder (C:\) |
| X | DriverModule | csrnvrt.exe | "Added by the IRCBOT.I TROJAN!"
|
| X | DriverPath | system32.exe | "Added by the PRORAT-S TROJAN!"
|
| X | Drivers for Internet Explorer | accesweb.exe | "Added by the STARTPAGE.FW TROJAN!"
|
| N | DriveSelect | driveselect.exe | "DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs"
|
| X | DriveSystem | maxpaynowti1.exe | "Added by the TIBS.AZT TROJAN!"
|
| U | dRMON SmartAgent | SmartAgt.exe | "Part of the network monitoring program group for 3Com NIC cards. See here for more info"
|
| X | drmsrv32 | stmhosts.exe | "Added by the AGENT.AGWU TROJAN!"
|
| X | DropSpam Lifestyle | dslifestyle.exe | "Dropspam adware"
|
| X | DrProtection | DrProtection.exe | "DrProtection rogue security software - not recommended"
|
| ? | DrvListnr | DrvListnr.exe | "Analog Devices SoundMAX soundcard related. What does it do and is it required?"
|
| X | drvnetw | drvnetw.exe | "Added by the BROGGER-B TROJAN!"
|
| X | DrvStart | HPMedia.exe | "Added by the BANCBAN-QE TROJAN!"
|
| X | drvsyskit | hidr.exe | "Added by the BAGLE.HR WORM!"
|
| X | drvsyskit | hldrrr.exe | "Added by the BAGLE.QU TROJAN!"
|
| X | drv_st_key | hidn.exe | "Added by the BEAGLE.FF WORM!"
|
| X | DrWatson | drwatson_.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWatson | drwatson_32.exe | "Added by the LOHAV-S TROJAN!"
|
| X | DrWeb Antivirus | DRWEBAV.EXE | Added by an unidentified WORM or TROJAN!
|
| X | DSAcass | [path to file] | "Added by the RANKY.M TROJAN!"
|
| U | dscactivate | dsca.exe | Dell Support Agent offers additional support and update features for your Dell computer or laptop
|
| N | DSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| X | Dskcompat | Dskcompat.exe | "Added by the GEMA TROJAN!"
|
| X | DSKEY | [path to trojan] | "Added by the STARTER-G TROJAN!"
|
| N | DSL Monitor | spdstrm.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| Y | DSLagentexe | DSLagent.exe | "Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection"
|
| U | DSLSTATEXE | dslstat.exe | System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
|
| X | DsmSer | msmpatch.exe | "Added by the SERFLOG.B WORM!"
|
| X | DsplObjects | windspl.exe | "Added by the BEAGLE.DN WORM!"
|
| X | DSS | dssagent.exe | "Registration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info"
|
| X | DSS | [path to trojan] | "Added by the DSSDOOR-C TROJAN!"
|
| X | dstiosys | plsitctl.exe | "Added by the MAILBOT-BX TROJAN!"
|
| X | DSystemDriver | windrv.exe | "Added by the DELF.WG TROJAN!"
|
| U | DT 11Mbps WLAN PC Card Station | DTCARDMonitor.exe | 11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT 11Mbps WLAN USB Station | DTUSBMonitor.exe | 11Mbps USB based wireless LAN connection monitor - possibly from Deutsche Telekom
|
| U | DT HPW | DTHtml.exe | "HP My Display from HP. Rebranded version of Display Tune from Portrait Displays |
| U | DT Task | DTHtml.exe | "Display Tune from Portrait Displays |
| N | DTAgent | DTAgent.exe | "System Tray access to DAEMON Tools Pro from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DTlite | DTlite.exe | "Daemon Tools Lite from DT Soft Ltd - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso |
| N | DU Meter | DUMETER.EXE | "Hagel Technologies internet bandwidth monitor"
|
| U | DualCoreCenter | StartUpDualCoreCenter.exe | "Unified control center for overclocking both the graphics card and the CPU |
| ? | Duane Reade Insert Detect | InsDetect.exe | "Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Dulux WeatherShield WeatherDesk | weather.exe | "Dulux WeatherShield WeatherDesk - latest weather information from across Australia"
|
| X | Dumeter Services | dumeter.exe | "Added by the SDBOT-AEQ WORM!"
|
| X | Duweculey | yujixit.exe | "Added by the SDBOT.BRP WORM!"
|
| U | DVD Device Lock for Win95/98/Me/2k/XP | DDLAgent.exe | "Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD |
| N | dvd43 | DVD43_Tray.exe | "DVD43 is ""a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"""
|
| ? | DVDAgent | DVDAgent.exe | "Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?"
|
| U | DVDBitSet | DVDBitSet.exe | DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
|
| X | Dvdcompat | Dvdcompat.exe | "Added by the GEMA TROJAN!"
|
| N | DVDSentry | DSentry.exe | "Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching |
| N | DVDTray | DVDTray.exe | HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
|
| N | DVDXGhost | DVDGhost.EXE | "DVD Ghost - ""utility to make your software DVD players and DVD copy/backup softwares restriction-free |
| Y | DvpInitExe | Dvpinit.exe | "Command Antivirus related"
|
| Y | dvprpt | Dvprpt.exe | "Command Antivirus related"
|
| N | DW4 | Weather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW4 | DesktopWeather.exe | "Desktop Weather 4 by The Weather Channel - provides current temperature |
| N | DW6 | DesktopWeather.exe | "Desktop Weather 6 by The Weather Channel - provides current temperature |
| U | DWHeartbeatMonitor | DWHeartbeatMonitor.exe | DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
|
| N | DwlClient | support.exe | Download manager for Dell support alerts
|
| U | DWQueuedReporting | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| N | dwStart | FireWall.exe | "The Shield firewall from pcsecurityshield.com. Not recommended by some (see here) and there are better free alternatives out there such as Zone Alarm. Located in %ProgramFiles%\PCSecurityShield\The Shield Firewall"
|
| U | dwtrig20 | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| X | DW_Start | rwwnw64d.exe | Identified as a variant of the AdWare.Win32.ZenoSearch.am malware
|
| X | Dx8compat | Dx8compat.exe | "Added by the GEMA TROJAN!"
|
| X | dxdll32 | ntxdll.exe | "Added by the GAOBOT.CPX WORM!"
|
| N | DXM6Patch_981116 | p_981116.exe | "Win32 cabinet self extractor. More info here"
|
| X | Dxsty | Dxsty.exe | "Added by the GEMA TROJAN!"
|
| X | Dxupdate.exe | Dxupdate.exe | "Added by the MAFEG WORM!"
|
| X | DyFuCA | optimize.exe | "Adult content dialler - see here"
|
| X | DyFuCA Active Alert | actalert.exe | "Adult content dialler - see here"
|
| X | Dynamic Dns Binary | dynitora.exe | "Added by the RBOT-WT WORM!"
|
| U | DynDNS Updater | DynDNS.exe | "Dynamic DNS IP address updater tool |
| N | DynDNS-Updater Traytool | ddutray.exe | "DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually"
|
| X | DynHttp Dns Binary | dynizari.exe | "Added by a variant of the RBOT WORM!"
|
| U | DynSite | DynSite.exe | "DynSite - dynamic DNS client |
| U | Dynu Basic Client | dynubas.exe | "Dynu online dynamic IP update client. Useful when using a dial up modem"
|
| U | D_V_T | dvt.exe | "DICOM Validation Tool - ""DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"""
|
| ? | D_V_T | dvt.exe | "Installation could be a crack/hack to NOD32 - see here. Seen and removed in many logs. Investigate it further and if the file C:\d_v_t.reg is present then it should be fixed. Not to be confused with the DICOM entry here"
|
| N | E-Color Registration | SonnReg.exe | "Registration for Colorific® and 3Deep® monitor calibration sofware from E-Color. Now superseded by ColorWizzard™ and 3DxWizzard™"
|
| U | e-Surveiller Station | estation.exe | "ESurveiller - surveillance software. Uninstall this software unless you put it there yourself"
|
| U | E06DXLRD_7604703 | EDICT.EXE | "Related to Microsoft Encarta dictionary functions"
|
| N | E6TaskPanel | TaskPanl.exe | "Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet |
| ? | Eac_rnvdl | ANTIVIRUS_INSTALL.EXE | "??"
|
| Y | EAFRCliStart | EAFRCliStart.exe | "Related to Encryption Anywhere hard disk encryption products from GuardianEdge"
|
| U | EanthologyApp | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | EanthologyApp | eanthology.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanthology_install.exe | eanthology_install.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | eanth_critical_update_alert | EANTHO~1.EXE | "eAcceleration Stop-Sign security software related - previously not recommended (see here). It has now been delisted |
| U | eanth_system_patcher | sys_alert.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| N | Eapcisetup | sbsetup.exe | Rockwell RipTide soundcard application software. Sound works without it
|
| N | EAPCISETUP | wizard.exe | Part of the Creative Sounblaster PIC Installation Wizard. Probably left as a result of a failed installation
|
| Y | Earthlink Protection Control Center | elnk_pcc.exe | "EarthLink Protection Control Center - ""powerful |
| N | EarthLink ToolBar 5.0 | etoolbar.exe | "EarthLink Toolbar is a tool to help you get to all of the resources of the internet. EarthLink 5.0 Setup adds a few basic buttons to the Toolbar |
| N | Easy CD Creator | RoxAssist.exe | "Roxio Assistant is designed to correct engine initialization errors in Easy CD & DVD Creator 6. If the engine does not initialize |
| N | Easy Start Button | esb.exe | Provides functionality on certain laptops that have additional keys. Not required unless you use the extra keys
|
| U | Easy-PrintToolBox | BJPSMAIN.EXE | A utility to launch the applications that are bundled with a Canon bubblejet printer
|
| X | EasyDates | EasyDates.exe | Premium rate adult content dialler
|
| X | EasyDates_gb | EasyDates_gb.exe | """Edate-A"" premium rate adult content dialler"
|
| X | EasyDates_nl | EasyDates_nl.exe | Adult content dialler
|
| U | EasyLinkAdvisor | LinksysAgent.exe | "Linksys EasyLink Advisor - ""the free application that provides and easy way to setup |
| N | EasyNetwork | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| X | EasySearchBar | ESBUpdate.exe | EasySearchBar adware downloader
|
| U | EasySync Pro - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - LtNts4 | NtsAgent.exe | "Lotus Notes 4 specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasySync Pro - PocketPC | AutoDetect.exe | "Windows Mobile Pocket PC specific translator for IBM® Lotus® EasySync® Pro - ""a personal productivity solution that provides data synchronization between your IBM Lotus Notes® desktop and handheld devices running PalmOS and Windows CE/Pocket PC operating systems"""
|
| U | EasyTuneIII | EasyTune.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneIV | ET4Tray.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| U | EasyTuneV | GUI.exe | Tuning (overclocking) utility for Gigabyte motherboards. Shortcut available
|
| X | EbatesMoeMoneyMaker | wjview ...Code | "Ebates adware"
|
| X | EbatesMoeMoneyMaker0 | EbatesMoeMoneyMaker0.exe | "Ebates adware"
|
| X | eBay Toolbar | EBAYTBAR.EXE | "eBay Toolbar - reportes as spyware as it "phones home""
|
| U | eBayToolbar | eBayTBDaemon.exe | "eBay toolabar related - also contains eBay account Guard which monitors for fraudulent eBay sites"
|
| X | ebmmm | ebatesmmmv.exe | "Ebates adware"
|
| N | eBot | DownloadWizard.exe | "eBot from Digital River - ""helps ensure your computer always has the latest technology |
| U | ECenter | gtb.exe | Dell E-Center/Google Toolbar related
|
| N | ECenter | EULALauncher.exe | End User License Agreement (EULA) launcher - related to Dell E-Center/Google Toolbar
|
| U | eDataSecurity Loader | eDSloader.exe | "Part of Acer Empowering Technology. ""Acer eDataSecurity Management is a handy file encryption utility that protects files from being accessed by unauthorized persons |
| N | edexter | edexter.exe | "eDexter supplements internet filtering by substituting local images for filtered images in order to prevent browser stalls and other annoyances. Can be activated manually when starting the browser"
|
| X | editpad | editpad.exe | "Added by the CONSPER-B TROJAN!"
|
| N | EDLoader | DTLoader.exe | Effective Desktop from MiniStars Software - desktop management software no longer being supported
|
| U | EDRestore | ?? | "Set Point from Easy Desk Software - ""small utility that automatically sets System Restore points for WinME/XP"""
|
| X | educational writer | [random filename] | "Added by the RBOT-LZ WORM!"
|
| X | Edzy AntiVirus | dppsfa.exe | "Added by a variant of the RBOT WORM!"
|
| N | EEventManager | EEventManager.exe | "Part of the Epson Creativity Suite supplied with their multi-function printer/scanners |
| X | Efata | [random 5 characters].exe | "Added by the FLUKAN-D WORM!"
|
| U | eFax 4.1 | J2GTray.exe | "System Tray access to version 4.1 of eFax Messenger from j2 Global Communications |
| U | eFax 4.2 | J2GTray.exe | "System Tray access to version 4.2 of eFax Messenger from j2 Global Communications |
| U | eFax 4.3 | J2GTray.exe | "System Tray access to version 4.3 of eFax Messenger from j2 Global Communications |
| U | eFax 4.4 | J2GTray.exe | "System Tray access to version 4.4 of eFax Messenger from j2 Global Communications |
| N | eFax Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| U | eFax Tray Menu | J2GTray.exe | "System Tray access to eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.3 | J2GTray.exe | "System Tray access to version 3.3 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 3.5 | J2GTray.exe | "System Tray access to version 3.5 of eFax Messenger from j2 Global Communications |
| U | eFax Tray Menu 4.0 | J2GTray.exe | "System Tray access to version 4.0 of eFax Messenger from j2 Global Communications |
| N | eFax.com Tray Menu | HotTray.exe | "eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
|
| X | efaxs lptt01 | efaxs.exe | "RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| U | EFI Hot Folders | hffw.exe | """EFI Hot Folders improves productivity by simplifying the printing of PostScript and PDF files into a select |
| U | EFI Job Monitor | "[path] efjm.dll | run" |
| N | EgisTecLiveUpdate | EgisUpdate.exe | "Software updater for biometric and data encryption products from EgisTec Inc"
|
| U | ehTray | ehtray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | ehTray.exe | ehTray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| U | Eicon NetworksLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| U | Eicon TechnologyLAN_DAEMON | watch.exe | "Associated with an Eicon Networks ISDN or ADSL modem. Watch protocols your connection with numbers and duration. You need callvu.exe (from Start Menu) to see your connection statistics. You can manually start watch.exe before you go online. Needs diinfo.exe (started by DiTask) to work correctly which can be started manually"
|
| X | eixfi | china.bat | "Added by the WCUP.A WORM!"
|
| U | ELBERTRicoh_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Ricoh MFP Type 104 multifunction printer
|
| U | ELBERT_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-5x30 Series multifunction printers
|
| U | Electron Microscope | EMIII.exe | "Electron Microscope or EM - is a program used to track Stanford's distributed computing program client called Folding at Home |
| X | Element | Element.txt | "Added by the ELEM TROJAN!"
|
| X | element furth | [path] repcale.exe [path] palsp.exe | "Added by a variant of the RANDON.AN WORM! Both files are often located in %System%\vert"
|
| U | eLert | eLert.exe | "eLert Emergency Notification System by Kennected Software - ""is an internet based public notification system designed to get emergency and non-emergency information out to the public quickly |
| X | elitemedia | elitemediapop.exe | "Added by the LOWZONE-BB TROJAN! Also known as Elitebar/EliteToolbar/EliteSidebar adware"
|
| X | EliteProtector | EliteProtector.exe | "EliteProtector rogue spyware remover - not recommended |
| ? | ElkCtrl | ElkCtrl.exe | Entry added when you install versions of the Logitech QuickCam webcam software. It's exact purpose is unknown at the present time
|
| U | ELSA WINman Suite | Winmsuit.exe | "Allows you to totally customize your ELSA graphics card settings |
| Y | ElsaCapiCtl | Rcapi.exe | "Assumed to stand for Remote Common Application Programming Interface (RCAPI) |
| U | ELSAChipGuard | elsavect.exe | "ChipGuard for ELSA graphics cards - monitoring solution which monitors both the GPU temperature and fan speed |
| Y | Email Protection | emlproxy.exe | "AntiVirus Quick Heal - E-mail protection"
|
| U | EMBASSY Trust Suite Secure Update | AutoUpdate.exe | "Updates for Wave Systems Corp. Embassy Trust Suite - ""delivers advanced levels of security to the client PC using the TPM security chip found on most enterprise PCs today"""
|
| X | eMCryT Sh3ars Panagers | [path to worm] | "Added by the RBOT-AWI WORM!"
|
| U | EMMeter | EMMeter.exe | """Express Meter lets you track and manage software usage so you can avoid purchasing and supporting applications that aren't being used |
| X | empin | e121307.Stub.exe | "Delfin Media Viewer adware related"
|
| ? | Empowering Technology Launcher | eAPLauncher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| ? | EmpoweringTechnology | Framework.Launcher.exe | "Part of Acer Empowering Technology. What does it do and is it required?"
|
| Y | Emsisoft Anti-Malware | a2guard.exe | "System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides ""comprehensive PC protection against viruses |
| N | eMuleAutoStart | emule.exe | "eMule - ""one of the biggest and most reliable peer-to-peer file sharing clients around the world. Thanks to it's open source policy many developers are able to contribute to the project |
| N | eMusicClient Systray | eMusicClient.exe | "eMusic MP3 download software"
|
| N | EN4060C Taskbar | en4060ct.exe | Comes with Efficient Networks DSL Modems. Little red/green/yellow flashing icon in system tray
|
| ? | encapsulated command tool | wintr.com | "??"
|
| N | Encarta Dictionary Quickshelf | QSHLFED.EXE | "Provides quick access to Encarta's Dictionary features?"
|
| N | ENCMONITOR | monitor.exe | The Encompass Monitor. This program is the Connect Direct Program. It is more trouble than it is worth and few use it
|
| N | Encoder Agent | WMENCAGT.EXE | "MS Windows Media Encoder |
| U | Encompass_ENCMONTR | ENCMONTR.EXE | Optional simple browser from Yahoo (Encompass)
|
| Y | EngUtil | EngUtil.exe | "Part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools - corrects any modification made to the Roxio Engine |
| X | Enh Win Updt | enhupdt.exe | "Adware - detected by Kaspersky as the ONECLICKNETSEARCH.H TROJAN!"
|
| N | EnigmaPopupStop | EnigmaPopupStop.exe | "Part of Enigma SpyHunter - not recommended |
| U | EnsoniqMixer | starter.exe | "Puts the Ensoniq mixer in system tray. From Ensoniq Technologies ""Our mixer is a critical part of the soundcard as it fixes sound problems and replaces the MS mixer which can no longer be used"". If you find you don't need it - try one of the solutions on this special page. Similar to Creative PCI Audio Configuration Utility"
|
| U | Entbloess 2 | Entbloess2.exe | "Related to Window-Switcher (now Reflex Vision) - it allows you to see previews of all your open applications via a single keystroke in a manner similar to Apple's Exposé |
| U | Enterprise Harmony | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| U | Enterprise Harmony '99 | rsMenu.exe | "Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | Enterprise Suite | WE[random characters].exe | "Enterprise Suite rogue security software - not recommended |
| U | Enterra Icon Keeper | IcnKeepr.exe | "Icon Keeper - ""tool to save and restore icon positions on the desktop"""
|
| X | EntraOcio | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | Enumerate Service | wsys.exe | "Added by the MANIFEST TROJAN!"
|
| U | EPGServiceTool | EPGClient.exe | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | EPGServiceTool | EPGCLI~1.EXE | "Electronic Programme Guide (EPG) for the WinTV range of TV Tuners from Hauppauge"
|
| U | ePowerManagement | ePM.exe | "Part of Acer Empowering Technology. ""Acer ePower Management is a straightforward interface that allows users to select from pre-configured power usage profiles |
| N | ePrint 3.0 Service | EPRINT3.EXE | "LEADTOOLS ePrint file conversion software - ""convert any file to and from over 150 document and image formats including searchable PDF |
| N | ePrint 4.0 Service | EPRINT4.EXE | "A component of the ""LEADTOOLS ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF |
| U | ePrompter | ePrompter.exe | "ePrompter - E-mail notification software"
|
| N | EPSON Background Monitor | STMS.EXE | Supposed to keep an Epson printer ready for quick printing. Users report little difference whether it is on or not
|
| U | EPSON CardMonitor | EPSON CardMonitor1.0.exe | Monitors the PCMCIA memory card slot on EPSON cameras and printers and launches PhotoStarter or PhotoPrint
|
| U | EPSON PictureMate Deluxe | E_FATI9TA.EXE | "Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status |
| U | EPSON Status Monitor 3 | E_[various].EXE | "Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| N | EPSON Status Monitor 3 Environment Check | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| N | EPSON Status Monitor 3 Environment Check 2 | e_srcv02.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check
|
| U | EPSON Stylus C120 Series | E_FATICCA.EXE | "Epson Status Monitor 3 for the Stylus C120 Series printer - for monitoring printer status |
| U | EPSON Stylus C40 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C40 Series printer - for monitoring printer status |
| U | EPSON Stylus C41 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C41 Series printer - for monitoring printer status |
| U | EPSON Stylus C42 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C42 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S08IC1.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C43 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C43 Series printer - for monitoring printer status |
| U | EPSON Stylus C44 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status |
| U | EPSON Stylus C45 Series | E_S4I3T1.EXE | "Epson Status Monitor 3 for the Stylus C45 Series printer - for monitoring printer status |
| U | EPSON Stylus C46 Series | E_S4I0T1.EXE | "Epson Status Monitor 3 for the Stylus C46 Series printer - for monitoring printer status |
| U | EPSON Stylus C48 Series | E_S4I091.EXE | "Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status |
| U | EPSON Stylus C60 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C60 Series printer - for monitoring printer status |
| U | EPSON Stylus C61 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C61 Series printer - for monitoring printer status |
| U | Epson Stylus C62 Series | E-S0BIC1.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C62 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C62 Series printer - for monitoring printer status |
| U | EPSON Stylus C63 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C63 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C64 Series | E_S4I2C1.EXE | "Epson Status Monitor 3 for the Stylus C64 Series printer - for monitoring printer status |
| U | EPSON Stylus C66 Series | E_S4I0S2.EXE | "Epson Status Monitor 3 for the Stylus C66 Series printer - for monitoring printer status |
| U | EPSON Stylus C67 Series | E_FATIAAL.EXE | "Epson Status Monitor 3 for the Stylus C67 Series printer - for monitoring printer status |
| U | Epson Stylus C82 Series | E_S0HIC1.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C82 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C82 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C84 Series | E_S4I2D1.EXE | "Epson Status Monitor 3 for the Stylus C84 Series printer - for monitoring printer status |
| U | EPSON Stylus C87 Series | E_FATIABL.EXE | "Epson Status Monitor 3 for the Stylus C87 Series printer - for monitoring printer status |
| U | EPSON Stylus CX2900 Series | E_FATIBFP.EXE | "Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3100 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3100 printer - for monitoring printer status |
| U | EPSON Stylus CX3200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus CX3200 printer - for monitoring printer status |
| U | EPSON Stylus CX3500 Series | E_FATI9 BL.EXE | "Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3600 Series | E_FATI9BE.EXE | "Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3700 Series | E_FATIACP.EXE | "Epson Status Monitor 3 for the Stylus CX3700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3800 Series | E_FATIACA.EXE | "Epson Status Monitor 3 for the Stylus CX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX3900 Series | E_FATIBEP.EXE | "Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4200 Series | E_FATIAEA.EXE | "Epson Status Monitor 3 for the Stylus CX4200 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4500 Series | E_FATI9AP.EXE | "Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4600 Series | E_FATI9AA.EXE | "Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4700 Series | E_FATIADL.EXE | "Epson Status Monitor 3 for the Stylus CX4700 Series printer - for monitoring printer status |
| U | EPSON Stylus CX4800 Series | E_FATIADA.EXE | "Epson Status Monitor 3 for the Stylus CX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5000 Series | E_FATIBVA.EXE | "Epson Status Monitor 3 for the Stylus CX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX5400 | E_S4I2G1.EXE | "Epson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status |
| U | EPSON Stylus CX5500 Series | E_FATICAP.EXE | "Epson Status Monitor 3 for the Stylus CX5500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6000 Series | E_FATIBIA.EXE | "Epson Status Monitor 3 for the Stylus CX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6500 Series | E_FATI9EP.EXE | "Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EE.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX6600 Series | E_FATI9EA.EXE | "Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7000F Series | E_FATIBKA.EXE | "Epson Status Monitor 3 for the Stylus CX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus CX7400 Series | E_FATICDA.EXE | "Epson Status Monitor 3 for the Stylus CX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX7800 Series | E_FATIAFA.EXE | "Epson Status Monitor 3 for the Stylus CX7800 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8300 Series | E_FATICEP.EXE | "Epson Status Monitor 3 for the Stylus CX8300 Series printer - for monitoring printer status |
| U | EPSON Stylus CX8400 Series | E_FATICEA.EXE | "Epson Status Monitor 3 for the Stylus CX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus CX9300F Series | E_FATICFP.EXE | "Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status |
| U | EPSON Stylus CX9400Fax Series | E_FATICFA.EXE | "Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status |
| U | EPSON Stylus D68 Series | E_FATIAAE.EXE | "Epson Status Monitor 3 for the Stylus D68 Series printer - for monitoring printer status |
| U | EPSON Stylus D78 Series | E_FATIBGE.EXE | "Epson Status Monitor 3 for the Stylus D78 Series printer - for monitoring printer status |
| U | EPSON Stylus D88 Series | E_FATIABE.EXE | "Epson Status Monitor 3 for the Stylus D88 Series printer - for monitoring printer status |
| U | EPSON Stylus DX3800 Series | E_FATIACE.EXE | "Epson Status Monitor 3 for the Stylus DX3800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4000 Series | E_FATIBEE.EXE | "Epson Status Monitor 3 for the Stylus DX4000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4400 Series | E_FATICAE.EXE | "Epson Status Monitor 3 for the Stylus DX4400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX4800 Series | E_FATIADE.EXE | "Epson Status Monitor 3 for the Stylus DX4800 Series printer - for monitoring printer status |
| U | EPSON Stylus DX5000 Series | E_FATIBVE.EXE | "Epson Status Monitor 3 for the Stylus DX5000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX6000 Series | E_FATIBIE.EXE | "Epson Status Monitor 3 for the Stylus DX6000 Series printer - for monitoring printer status |
| U | EPSON Stylus DX7000F Series | E_FATIBKE.EXE | "Epson Status Monitor 3 for the Stylus DX7000F Series printer - for monitoring printer status |
| U | EPSON Stylus DX7400 Series | E_FATICDE.EXE | "Epson Status Monitor 3 for the Stylus DX7400 Series printer - for monitoring printer status |
| U | EPSON Stylus DX8400 Series | E_FATICEE.EXE | "Epson Status Monitor 3 for the Stylus DX8400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 1400 Series | E_FATIBUA.EXE | "Epson Status Monitor 3 for the Stylus Photo 1400 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo 2200 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 2200 printer - for monitoring printer status |
| U | EPSON Stylus Photo 825 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 825 printer - for monitoring printer status |
| U | EPSON Stylus Photo 925 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status |
| U | EPSON Stylus Photo R1800 | E_FATI9LA.EXE | "Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status |
| U | EPSON Stylus Photo R200 Series | E_S4I0H2.EXE | "Epson Status Monitor 3 for the Stylus Photo R200 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_S6I2I1.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R220 Series | E_FATIAIE.EXE | "Epson Status Monitor 3 for the Stylus Photo R220 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R240 Series | E_FATIAHE.EXE | "Epson Status Monitor 3 for the Stylus Photo R240 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SA.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R2400 | E_FATI9SE.EXE | "Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status |
| U | EPSON Stylus Photo R260 Series | E_FATIBNA.EXE | "Epson Status Monitor 3 for the Stylus Photo R260 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R280 Series | E_FATICKA.EXE | "Epson Status Monitor 3 for the Stylus Photo R280 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R285 Series | E_FATICKE.EXE | "Epson Status Monitor 3 for the Stylus Photo R285 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I2F1.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R300 Series | E_S4I0F2.EXE | "Epson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R320 Series | E_FATI9FA.EXE | "Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R340 Series | E_FATIAJE.EXE | "Epson Status Monitor 3 for the Stylus Photo R340 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R380 Series | E_FATIBOA.EXE | "Epson Status Monitor 3 for the Stylus Photo R380 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo R800 | E_FATI9YE.EXE | "Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX420 Series | E_FATI9CE.EXE | "Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX430 Series | E_FATI9CP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX500 | E_S4I2K1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX500 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX530 Series | E_FATIAGP.EXE | "Epson Status Monitor 3 for the Stylus Photo RX530 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX600 | E_S4I2M1.EXE | "Epson Status Monitor 3 for the Stylus Photo RX600 printer - for monitoring printer status |
| U | EPSON Stylus Photo RX640 Series | E_FATIAME.EXE | "Epson Status Monitor 3 for the Stylus Photo RX640 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX680 Series | E_FATICJA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX680 Series printer - for monitoring printer status |
| U | EPSON Stylus Photo RX700 Series | E_FATI9IA.EXE | "Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status |
| U | EPSON Stylus Pro 4000 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 4000 printer - for monitoring printer status |
| U | EPSON Stylus Pro 7600 | E_S10IC2.EXE | "Epson Status Monitor 3 for the Stylus Pro 7600 printer - for monitoring printer status |
| U | EPSON Stylus SX200 Series | E_FATIEFE.EXE | "Epson Status Monitor 3 for the Stylus SX200 Series printer - for monitoring printer status |
| U | EPSON SX100 Series | E_FATIEDE.EXE | "Epson Status Monitor 3 for the SX100 Series printer - for monitoring printer status |
| U | EPSON TX100 Series | E_FATIEDP.EXE | "Epson Status Monitor 3 for the TX100 Series printer - for monitoring printer status |
| U | EPSON WorkForce 30 Series | E_FATIEEA.EXE | "Epson Status Monitor 3 for the WorkForce 30 Series printer - for monitoring printer status |
| U | EPSON WorkForce 500 Series | E_FATIEQA.EXE | "Epson Status Monitor 3 for the WorkForce 500 Series printer - for monitoring printer status |
| U | EPSON WorkForce 600 Series | E_FATIEKA.EXE | "Epson Status Monitor 3 for the WorkForce 600 Series printer - for monitoring printer status |
| U | EpsonPhotoStarter | EPSON_PhotoStarter.exe | Only needed if you want to make full use of the capabilities of an Epson printer that included this
|
| X | Eptr | nopdb.exe | Added by an unidentified WORM or TROJAN!
|
| X | EQArticle | EQArticle.exe | "EQArticle adware"
|
| U | eRecoveryService | Monitor.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| U | eRecoveryService | eRAgent.exe | "Part of Acer Empowering Technology. ""Acer eRecovery Management is a powerful utility that does away with the need for recovery disks provided by the manufacturer |
| X | ErrorProtector Free | ertmain.exe | "ErrorProtector rogue system error and cleaning utility - not recommended"
|
| X | ErrorRepairTool | ErrorRepairTool.exe | "ErrorRepairTool rogue system error and cleaning utility - not recommended"
|
| X | ERS | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | ERS_check | ers_startupmon.exe | "Part of the WinAntiVirus Pro 2006 rogue security software - not recommended |
| X | erthegdr | windll2.exe | "Added by the BEAGLE.CG WORM!"
|
| X | erthgdr | windll.exe | "Added by the BEAGLE.AO or BEAGLE.AQ WORMS!"
|
| X | erthgdr | svc.exe | "Added by the BEAGLE.BN or BEAGLE.BP WORM!"
|
| X | erthgdr2 | svc23.exe | "Added by the BAGLE.CG WORM!"
|
| ? | ERTS0749 | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| X | ertyuop | rttrwq.exe | "Added by the AUTORUN-APA WORM!"
|
| U | ERUNT AutoBackup | AUTOBACK.EXE | "ERUNT backup utility - when added to the user's startup folder automatically backs up the registry each time the system boots |
| X | erwghjjrjt | ucbcg.exe | "Added by the SMALL.CUL TROJAN!"
|
| U | ES Current Services | [FILE NAME].exe | "123Keylogger surveillance software. Uninstall this software unless you put it there yourself"
|
| Y | eSafe Protect | ESPWatch.exe | "eSafe from Aladdin - internet security for gateway and E-mail servers"
|
| Y | eScan Monitor | AVKWCTL9X.EXE | "MicroWorld eScan antivirus"
|
| U | eScan Updater | Trayicos.exe | "MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads"
|
| N | ESFTP | esftp.exe | "ESftp - FTP client for transfering files between a local PC and another remote computer"
|
| U | eSnips | ClientGW.exe | "eSnips Client Gateway from eSnips"
|
| X | Especial | Deneca.bat | "Added by the DELUZ VIRUS!"
|
| X | Esph | ortu.exe | "PurityScan adware"
|
| N | ESPN BottomLine | bline.exe | "ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop |
| ? | eSupInit | eSupCmd.exe | "Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
|
| X | Esutityde | osutityde.exe | "Added by the SDBOT.BQD WORM!"
|
| X | ETB Tester | etbtest.exe | "Added by the RBOT-ABR WORM!"
|
| X | etbrun | elit***32.exe [* = random char] | "EliteBar adware"
|
| U | eTCertManger | eTCrtMng.exe | "eToken Certificate Manager from Aladdin Knowledge Systems |
| U | ETDWare | ETDCtrl.exe | Elantech smart-pad touchpad driver for the Asus Eee PC range
|
| X | eth0 driver | exec.exe | "Added by the SPYBOT-Z WORM!"
|
| N | Ethernet | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
|
| X | ethernet | airftp.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msnger.exe | "Added by a variant of the SDBOT WORM!"
|
| X | ethernet | msftp.exe | "Added by the SDBOT.BXJ WORM!"
|
| X | ethernet adapter | csrmss.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Driver | cmsrrs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ethernet Drivers | smrrs.exe | "Added by the RBOT-AAK WORM!"
|
| X | Ethernet Drivers | ethernet.exe | "Added by the GAOBOT.CEZ WORM!"
|
| X | Ethernet Linking | ethernet.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Etraffic | JavaRun.exe | "TopMoxie adware"
|
| Y | eTrust EZ Firewall | efpeadm.exe | "eTrust EZ Firewall"
|
| U | eTrust PestPatrol Active Protection | PPActiveDetection.exe | "PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
|
| X | eTrust Realtime Monitor | realmon.exe | "Added by the LAZAR.B TROJAN!"
|
| Y | eTrustCIPE | ezdsmain.exe | eTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
|
| X | eTunnel | winfw.exe | Added by an unidentified TROJAN!
|
| U | EuroGlot | EuroGlot.exe | "Euroglot - ""multilanguage translating system |
| ? | Event Log | eventlog.exe | "??"
|
| N | Event Planner Reminders | PLNRNote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Planner Reminders Tray Icon | PLNRnote.exe | Part of Sierra/Hallmark Card Studio - System Tray notification of events such as birthdays and anniversaries that you've scheduled with the customizable Event Planner
|
| N | Event Reminder | pmremind.exe | "Event reminder for calendar dates |
| X | EventApplicationCmd | smschk.exe | "Added by the IRCBOT-AO TROJAN!"
|
| U | EVENTLISTENER | EvLstnr.exe | Used with a Nikon digital camera to recognize when the camera is plugged in
|
| N | eventmgr | eventmgr.exe | Used with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
|
| X | eventwvr | eventwvr.exe | "Added by the COSIAM_G TROJAN!"
|
| N | Evidence Eliminator | ee.exe | "Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
|
| N | evntsvc | evntsc.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| U | EVOLOSTA | EVOLOSTA.EXE | "Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID |
| U | Evoluent Mouse Manager | EvoMouExec.exe | "Mouse manager for Evoluent VertcialMouse"
|
| X | EvtHtm | evthtm.exe | "Added by the DLUCA-EJ TROJAN!"
|
| U | EvtMgr6 | Setpoint.exe | "Logitech SetPoint control software for their range of wired and wireless keyboards and pointing devices (mice |
| N | eWare Startup | iWareStart.exe | "eWare iWare task bar. Not required"
|
| Y | ewido anti-spyware | ewido.exe | "System Tray access to and notifications for Ewido Anti-Spyware 4.0. Ewido is now part of AVG Technologies so this has been superseded by AVG Anti-Virus which includes Anti-Spyware"
|
| X | ewrgetuj | geurge.exe | "Added by the AUTOINF-AK WORM!"
|
| X | Ewth | tasn.exe | "PurityScan adware"
|
| X | ewupdater | ewupdater.exe | "EasyWebSearch adware updater"
|
| N | Excite Platform | Exlaunch.exe | Loads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
|
| ? | Excite Private Messenger Pipe | x8impipe.exe | "??"
|
| N | ExciteAssistantEXE | ASSISTANT.EXE | "With Excite Assistant |
| X | exe lptt01 | exe.exe | "RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| ? | Execute | delfolders.exe | "??"
|
| X | ExFilter | "Rundll32.exe [path] cdnspie.dll | ExecFilter" |
| U | ExitKiller | Ekiller.exe | "Exit Killer - automatically closes pop-up windows in your browser"
|
| ? | exmon | hpimoniter.exe | "Some kind of hp digital camera maybe or a photo smart connection probe?"
|
| X | Expatch | [random filename] | "Added by the PWSLMIR-G TROJAN!"
|
| X | expcrt | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| X | ExpertAntivirus | ExpertAntivirus.exe | "ExpertAntivirus rogue security software - not recommended |
| X | Expl0rer soft | expl0rer.pif | "Added by the RBOT-AQR WORM!"
|
| X | explorer | wscript.exe [filename] | "Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
|
| X | Explorer | [path to worm] | "Added by the AUTEX WORM!"
|
| X | explorer | [path to trojan] | "Added by the AGENT-EU TROJAN!"
|
| X | explorer | Yinstall.exe | "PurityScan/Clickspring adware"
|
| X | Explorer | TXP1atform.exe | "Added by the FUJACKS.CA VIRUS!"
|
| X | explorer | system.exe | "Added by the AGENT-FI TROJAN!"
|
| X | Explorer | msrstart.exe | "Added by the SOPICLICK TROJAN!"
|
| X | Explorer 2238 | [path to trojan] | "Added by the AGENT-CPI TROJAN!"
|
| X | Explorer lptt01 | explorer.exe | "RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
|
| X | EXPLORER MICROSOFT SYSTEM | explore.exe | "Added by a variant of the RBOT WORM!"
|
| X | Explorer soft | explorer.pif | "Added by the RBOT-APK WORM!"
|
| X | Explorer soft | explorer.com | "Added by the RBOT-ARM WORM!"
|
| X | Explorer Updater | IEXPLORE.exe | "Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | ExplorerTask | explorer.exe | "Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
|
| X | exporet | winset.exe | "Added by the QQPASS-I TROJAN!"
|
| N | Extender Resource Monitor | RMSysTry.exe | "Related to Windows Media Center from Microsoft"
|
| X | External Dependencies | External.exe | "Added by the MYTOB.EC WORM!"
|
| X | Extra Antivirus | ExtraAV.exe | "Extra Antivirus rogue security software - not recommended |
| U | ExtraDNS | ExtraDNS.exe | "ExtraDNS - DNS configuration tool"
|
| N | ExtraFilmHemmaAgent | Agent.exe | "ExtraFilm Photo Assistant"
|
| ? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software
|
| ? | ExxtremeHelperDemon | exxdemon.exe | "Creative Exxtreme graphics card related?"
|
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper
|
| X | EYORE | Notepad.scr | "Added by the GIMLET-A WORM!"
|
| N | ezagent | ezagent.exe | "EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
|
| N | EzButton | EzButton.EXE | EZbutton is a quick launcher for the Media player app that comes with certain laptops
|
| N | EZEJTRAY | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | EzPrint | ezprint.exe | "Lexmark Fast Pics - helps users of their printers to enhance |
| Y | ezShieldProtector for Px | ezSP_Px.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | "Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
|
| U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
|
| U | EzTune | dthtml.exe | "EzTune from Gateway. Rebranded version of Display Tune from Portrait Displays |
| U | E_S[numbers] | [path] E_[various].EXE [path] E_S[numbers].tmp | "Temporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status |
| X | f | ftkclean.exe | "FlashEnhancer adware"
|
| U | F-PROT Antivirus Tray application | FProtTray.exe | "System Tray access to F-PROT Antivirus"
|
| X | F-Secure 2005 | svchost.exe | "Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | F-Secure Gatekeeper | [malware name].exe | "Added by the NUWAR.AXQ WORM!"
|
| U | F-Secure Management Agent | FSMA32.EXE | "F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
|
| Y | F-Secure Startup Wizard | FSSW.EXE | "F-Secure antivirus"
|
| Y | F-Secure TNB | TNBUtil.exe | "F-Secure antivirus"
|
| Y | F-StopW | F-StopW.exe | "F-Prot anti-virus background scanner by F-Risk Software"
|
| U | f1Tray.exe | F1TRAY.EXE | "System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
|
| X | f2install.exe | f2install.exe | "Added by the IEFEAT-I TROJAN!"
|
| X | f73cdc8ee94e | btsendto.exe | Associated with mysearchnow.com/searchbar.html
|
| X | f94mggfhfghodftdf | [path to trojan] | "Added by the SMALL.JHZ TROJAN!"
|
| U | Fabrik Ultimate Backup Status | fabrikhomestat.exe | "Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink |
| X | FaltCheck | allps.exe | "Added by the AGENT.RAP TROJAN!"
|
| X | Fantasia injector | wincfg.exe | "Added by the AGOBOT.US WORM!"
|
| X | farmmext | farmmext.exe | "VX2.Transponder parasite updater/installer related"
|
| N | fast | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | fast | A-fast.exe | "A-fast Antivirus rogue security software - not recommended |
| X | Fast Antivirus 2009 | FastAV.exe | "Fast Antivirus rogue security software - not recommended |
| N | FAST Defrag | FAST2.EXE | "FastDefrag defragmenting software"
|
| X | Fast Home | svcnvt.exe | "Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines |
| X | Fast Search | svcnv.exe | "Homepage |
| X | Fast start | Ntut.exe | "Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"
|
| X | Fast start | svcnt.exe | "Adware - detected by Kaspersky as a variant of the FAVADD TROJAN!"
|
| U | FastCache | fc.exe | "FastCache from AnalogX - speeds up browsing by resolving DNS requests locally"
|
| X | FastDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | fastsmell | fastsmell.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | FastStart | ntnut32.exe | "Added by the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| X | FastStart | svcnut32.exe | "Browser hijacker - a variant of the STARTPAGE.L TROJAN!"
|
| N | FastTrack Accelerator | SPEED UP.EXE | "FastTrack Accelerator - ""speedup"" utility for programs that use the FastTrack network such as KaZaA Media Desktop |
| X | FASTTRACKNETVISION | NETVISION.exe | "DialCar-Z premium rate dialer"
|
| U | FastTVSync | FastTVSync.exe | "Part of InterVideo (now Corel) DVD Copy - ""fast DVD copying and file conversion software. In just three steps |
| N | FastUser | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| N | FastUsr | fast.exe | Installs as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
|
| X | faT | faT.exe | "Added by the BANKER-DFP TROJAN!"
|
| X | fat.exe | fat.exe | "Part of the WinAntiVirus Pro 2006 and WinAntiVirus Pro 2007 rogue security programs - not recommended |
| X | Fat32 Microsoft | fat32.exe | "Added by the RBOT-EL WORM!"
|
| U | FatPipe | DHCP | Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | Fatpipe Dialer | fpdialer.exe | Dailler for Fatpipe - software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
|
| U | fatrecov | fatrecov.exe | SCKeyLog.j keystroke logger/monitoring program - remove unless you installed it yourself!
|
| U | FavoriteSync | FavoriteSync.exe | "FavoriteSync keeps the same set of Internet Explorer Favorites on several computers in sync"
|
| U | FaxCenterServer | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCenterServer4_in_1 | fm3032.exe | "FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software. Incorporated into software by Lexmark |
| U | FaxCtrl.exe | ASMediaProxyServer.exe | "Part of Avaya's Contact Center Express - ""a multi-channel |
| N | FaxTalk CallControl 6.0 | FTClCtrl.EXE | This allows the software to handle incoming and outgoing communications without requiring the FaxTalk Communicator application to be loaded into memory. Can be started manually
|
| U | FBDirect | FBDirect.exe | "Software that monitors the status of a Visioneer OneTouch scanner button and allows you to scan |
| X | FBSearch | FastBrowserSearchProtection.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | Fdaemon security | fsecur.exe | "Added by the SDBOT.KXO WORM!"
|
| X | FDD SYSTEM | Fdd.exe | "Added by the MYTOB-FO WORM!"
|
| X | fddddHOME | dxxatp.exe | "Added by the RANKY.AA TROJAN!"
|
| X | feelalright | mirc.exe | "Added by the IRCFLOOD-M WORM!"
|
| U | FEELitDeviceManager | feelitdm.exe | Associated with Immersion TouchSense devices (Logitech Wingman Force Feedback Mouse and possibly other peripherals)
|
| X | fegoze | SVCH0ST.EXE | "Added by the GRAYBIRD.D VIRUS! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
| X | Fen Startups | fensvc32.exe | "Added by the RANDEX.CCF WORM!"
|
| X | Fenio Startups | fnesvc32.exe | "Added by the AGOBOT-OS BACKDOOR!"
|
| X | FestPlattenCleaner | SysRep.exe | "FestPlattenCleaner |
| X | FestplattenReiniger | GDC.exe | "FestplattenReiniger |
| X | ff | [path to worm] | "Added by the RBOT-XL WORM!"
|
| X | ff | svhost32.exe | "Added by the LINEAG-AFF TROJAN!"
|
| U | FG1_00 | frntgate.exe | "FrontGate MX - e-mail spam blocker"
|
| X | fGQEGqHOME | gwwgtp.exe | "Added by the RANKY.J TROJAN!"
|
| X | FHStart | shdocsvc.exe | "Added by the WINHOUND TROJAN!"
|
| U | Fhtisxk | fhtisxk.exe | XtraKeys keystroke logger/monitoring program - remove unless you installed it yourself!
|
| X | FiendlyType | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| X | file laoder configuration | rnd32.exe | "Added by the RBOT.BQJ WORM!"
|
| X | File Protection Monitor | filemon.exe | "Added by a variant of the RBOT WORM!"
|
| X | File System | taskmqrs.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | File System | taskmqr.exe | "Added by the RBOT.BWQ WORM!"
|
| X | File System Service | wmiprvsc.exe | "Added by the AGOBOT-HZ TROJAN!"
|
| X | File1 | Dia Claro.htm | "Added by the DLOADER-OR TROJAN!"
|
| X | FileFreedom_Plugin | wtm.exe | "FileFreedom peer-to-peer sharing program"
|
| N | filehippo.com | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| N | FileHippo.com Update Checker | UpdateChecker.exe | "Checks for new releases available in the popular FileHippo.com repository for any software you may already have installed on your computer. Run manually when required"
|
| X | FileManager32 | Wscript.exe ChkMgr32.vbs | "Added by the NOTUP.A WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ChkMgr32.vbs"" file is located in %System%"
|
| X | Files Driver | sdphost.exe | "Added by the SDBOT-DKZ WORM!"
|
| X | Files Driver | sfdhost.exe | "Added by the AGOBOT-AJC BACKDOOR!"
|
| X | FileSoft | Wscript.exe UpdataFiles.vbs | "Added by the SST.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""UpdataFiles.vbs"" file is located in %Windir%"
|
| U | FilterGate | filtergate.exe | "Filtergate internet filtering software - filters sounds |
| U | Filterguard | Filtrgrd.exe | "An icon located in the lower left of the screen and looks like a lifesaver. This icon is a ""short-cut"" to access the basic features of SOS-Guardian |
| X | FilterProgram | GDC.exe | "FilterProgram rogue privacy tool - not recommended |
| N | Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
|
| X | findfast | findfast.exe | "Added by the DLOADER.PFR TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office"
|
| X | findfast.exe | findfast.exe | Identified as the RUNDIS.A TROJAN! Note - the is not the legitimate file of the same name installed with older versions of MS Office
|
| X | FindHack | [path to worm] | "Added by the KELVIR-BA WORM!"
|
| U | FinePrint Dispatcher v4 | fpdisp4a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v4 | fpdisp4.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 4.x of the software. ""FinePrint saves ink |
| U | FinePrint Dispatcher v5 | fpdisp5a.exe | "FinePrint Dispatcher - handles the spooling of print jobs to the FinePrint printer. Version 5.x of the software. ""FinePrint saves ink |
| U | FingerPrintSoftware | fpapp.exe | Supports the fingerprint reader on selected IBM/Lenovo Thinkpad notebooks
|
| ? | FireBox Control Panel | FireBox.exe | "Control panel for the Presonus FireBox firewire based music recording system. Is it required?"
|
| X | FireExplore Update | FireExplore.exe | "Added by a variant of the RBOT WORM!"
|
| X | FireFox Startup Drivers | wuaclt.exe | "Added by the RBOT.BYX WORM!"
|
| X | Firevall Administrating | rndll.exe | "Added by the PUSHBOT-B WORM!"
|
| X | Firewall | SP2 UPDATE.exe | "Added by the ELITPER.E WORM!"
|
| X | Firewall | Firewall.bat | "Added by the YPSAN.G WORM!"
|
| X | Firewall | ctfmon.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate ctfmon.exe process associated with alternate text inputs which is always located in %System%. This one is located in %Windir%"
|
| X | Firewall Administrating | infocard.exe | "Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename"
|
| X | Firewall auto setup | winlogon.exe | "Added by the AGENT-EDB TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
|
| X | Firewall auto setup | [path to trojan] | "Added by the AGENT-GLY TROJAN!"
|
| X | Firewall Controls | sys32.exe | "Added by the SDBOT-DGI WORM!"
|
| X | Firewall Sp2 system | sys32Conf.exe | "Added by the RBOT-ABT WORM!"
|
| X | Firewall Update System1 | WinedowsUpdater1.exe | "Added by the RBOT-ARU WORM!"
|
| X | Firewall Updater | msnupdateit.exe | "Added by the RBOT-AAQ WORM!"
|
| X | FirewallActivies | csrss.exe | "Added by the BANKER-AQ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""3041"" subfolder"
|
| U | FirewallStartup | Firewallstartup.exe | "Innovative Startup Firewall - ""designed to protect your computer from programs that install themselves in the StartUp area of your Windows without asking for your approval. Innovative StartUp Firewall will help you keep your computer clean |
| X | firewall_anti | firewall_anti.exe | "Added by the NETDENY-B TROJAN!"
|
| X | First Home Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| ? | First Principle Group | fpg.exe | "Related to the E-Players Card from First Principle Group"
|
| X | Fix Tool | Fix-Tool.exe | "Fix Tool rogue system error and cleaning utility - not recommended"
|
| Y | Fix-it | mxtask.exe | "Part of Ontrack's Fix-it Utilities Suite. Loads a System Tray icon that lets you access the full program. Needed if you run the crash guard |
| Y | Fix-it AV | memcheck.exe | Part of Ontrack's Fix-it Utilities Suite anti-virus. Performs a quick check of memory for signs of any virus. Exits afterward and returns all resources used in one user's experience. Not required but could be left without a drain on resources
|
| X | fjdslssdfd | mat2.exe | "Added by the SLAPEW.C TROJAN!"
|
| U | FJTWAIN Setup | FjtwSetup.exe | Fujitsu scanner utility
|
| N | FJUPDNV_Chitose | fjdvrupd.exe | Driver update for a Fujitsu Siemens Lifebook laptop
|
| X | Flash Driver | [path to trojan] | "Added by the AGENT.CWVT TROJAN!"
|
| X | Flash Media | [path to trojan] | "Added by the IRCBOT.AUR TROJAN!"
|
| X | Flash Player2 | [path to worm] | "Added by the IRCBOT.PD WORM!"
|
| N | Flashget | FlashGet.exe | "FlashGet download manager"
|
| X | Flashget Download Manager | Flashget.exe | "Added by the RBOT-AGZ WORM!"
|
| U | FlashMute | FlashMute.exe | """FlashMute is a tool which allows you to mute/unmute Flash Movies loaded in a browser exclusively |
| N | FlashPath Monitor | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Monitor | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | SDSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| N | FlashPath Status | FLSHSTAT.EXE | System Tray icon that you can't get rid of - and does not need to run!. Tells you the battery status in the floppy disk adapter for the smartmedia cards. Available via Start -> Programs
|
| X | Flashy Bot | Flashy.exe | "Added by the GLUPZY.A WORM!"
|
| X | Flash_Player_Install | ying.exe | "Constructor VC2000 malware"
|
| U | FLMLABTECMOUSE | mouse32A.exe | Mouse utility for a Labtec brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| U | FLMTRUSTKB | KbdAp32A.exe | Keyboard utility for a Trust brand keyboard. If you disable this entry you will not be able to use any of the keyboard hotkeys or other non-standard functions on the keyboard
|
| U | FLMTRUSTMOUSE | mouse32a.exe | Mouse utility for a Trust brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| X | FLooDNeT | FLooDeR.exe | "Added by the ENDOOL TROJAN!"
|
| X | Floppy Master | [path to trojan] | "Added by the ZONIT-F TROJAN!"
|
| ? | Flow Go TV | flogotv.exe | "??"
|
| X | flpycntl | flpycntl.exe | "Added by the CRYPTER.C TROJAN!"
|
| Y | FltProcess | msinet.exe | "Part of Cyber Patrol internet filtering software to restrict access to certain types of material on the internet. It can be disabled but do not ask how it's done"
|
| X | FlyswatDesktop | flydesk.exe | Advertising spyware
|
| U | FmctrlTray | Fmctrl.EXE | Genius SM-Live Control Panel. Enhances audio output through Genius sound cards (makes a big difference and worth the 3MB Ram used)
|
| X | fmnwebassist | fmnwebassist.exe | Adware popup generator
|
| U | FMStart | Fmstart.exe | "GFI FAXmaker - native fax connector for Microsoft Exchange Server or for networks |
| X | fnmwebassist | fnmwebassist.exe | "WinPL adware"
|
| X | Folder Service | wssdtu.exe | "Added by the MANIFEST TROJAN!"
|
| X | FolderRaper | [path to worm] | "Added by the VB.GOZ WORM!"
|
| N | FoneSyncSystemTray | FoneSyncSystemTray.exe | System Tray icon for Nokia FoneSync utility for the 7160/7190 mobiles. Useful to send data from/to the cell phone and the computer. You can use it to backup data or even to input data through the computer keyboard (which naturally is much more comfortable). Run manually when required
|
| X | Font | boot.exe | "Added by the AGENT-LZW TROJAN!"
|
| X | Font Viewer | fontviewer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | FontFix | fontfix.exe | "Added by an unidentified VIRUS |
| N | fontnav | FontNav.exe | "Font Navigator from Bitstream Inc. - a font management utility"
|
| X | FontsLoader | ldfnt32.hta | Unidentified malware
|
| X | FONTVIEW | FONTVIEW.EXE | "Added by the OPASERV.T WORM!"
|
| X | foobin lptt01 | adaware.exe | "RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| N | Forbes | ForbesAlerts.exe | Forbes Business News Alerts - displays business news headlines in a little window on the screen
|
| N | Forget Me Not | AGRemind.exe | "Calendar reminder part of Broderbund's American Greetings® CreataCard®"
|
| U | forteManager | dthtml.exe | "forteManager from LG. Rebranded version of Display Tune from Portrait Displays |
| Y | FortiClient | FortiClient.exe | "Fortinet security systems are the new generation of real time network protection systems"
|
| U | Fortis Secure Layer Config | cseinst.exe | Fortis Bank Home Banking part. Installed during the installation of the software necessary to run the Home Banking. According to Fortis Bank this will not in any way be harmful to the system or relay system information
|
| X | fotos | fotos.exe | "Added by the BANKER-FP TROJAN!"
|
| N | FotoStation Easy AutoLaunch | FotoStation Easy AutoLaunch.exe | Installed with a Nikon digital camera. Used to collect photos uploaded from camera program NkVwMon.exe. If your camera is not connected (via USB port) you do not need this program loaded either
|
| U | FourthDay | FourthDay.exe | "The Fourth Day - ""astronomical clock and almanac for your system tray"""
|
| N | fpassist | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| X | fqor | stub_113_4_0_4_0.exe | "TargetSaver adware"
|
| X | France | svchost.exe | "Added by the MIMAIL.L WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| ? | Free Downloads Monitor | fdcmon.exe | "??"
|
| N | Free DVD Direct | FreeDVDDirect.exe | "Free DVD Direct - provides a program to access a peer-to-peer (P2P) file-sharing network (see here)"
|
| U | Free Ram Optimizer | fro.exe | "Free Ram Optimizer monitors your memory |
| X | free-save | [path to risk] | "Freesave security risk that tracks and sends browser information and visited websites on the computer. Uninstall this software unless you put it there yourself"
|
| X | FreeAttention | eqsefeqe.exe | Added by an unidentified WORM or TROJAN!
|
| N | Freebie Notes | FreebieNotes.exe | "Freebie Notes by Power Soft - create electronic notes (stickers)"
|
| N | FreePDF Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| N | FreePDF_Assistant | fpassist.exe | "Part of FreePDF (was FreePDF XP) - a utility used to create Adobe compatible PDF files from virtually any Windows application. This executable needs to be running when you want to send a printer output to a PDF file via the FreePDF virtual printer"
|
| X | freestyle | lockx.exe | "Added by the RBOT-ATH WORM!"
|
| X | freexstyle | lockbar.exe | "Added by the LOXBOT.D WORM!"
|
| X | freexstyle | lockbr.exe | "Added by the LOXBOT.C WORM!"
|
| X | freinst | pgs.exe | "Part of the AVSystemCare rogue security software and other members of this family. See here for more examples"
|
| U | Fresh Desktop | freshdesktop.exe | "Fresh Desktop is a utility that lets you manage vast collections of wallpapers for your desktop with ease. When run on bootup it changes the desktop wallpaper at startup or at specified intervals"
|
| ? | FridaysInHellInstaller | FridaysInHellInstaller.exe | "??"
|
| X | FriendlyType | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | FriendlyTypeName | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| X | FriendlyTypeName | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| N | FriendlyWebQuick-Launch | SELFCERT.EXE | selfcert.exe is a stand alone program for creating your own digital certificates for macros - the .exe is installed as an extra basically by clicking on MS Office in add/remove programs and selecting remove - also I would do away with the FriendlyWebQuickLaunchBar as well
|
| ? | FRITZ!DSL Startcenter | StCenter.exe | "FRITZ! ISP software ""StartCenter"" User interface that allows you to manage |
| U | FRITZ!webProtect | FwebProt.exe | Firewall included in FRITZ! ISP DSL software
|
| X | froody | timoty.exe | Added by an unidentified malware
|
| X | FS Agent | fagent.exe | "Added by the VOLVER-B TROJAN!"
|
| X | fsdsft | [path to backdoor] | "Added by the RANKY.S BACKDOOR!"
|
| N | FSScrCtl | FSScrCtl.exe | Screen saver control applet used by the "Stardust Screen Saver Toolkit" and "SolidWorks Screen Saver"
|
| X | fstsvc | "rundll32.exe fstsvc.dll | start" |
| X | ftk | ftkclean.exe | "FlashEnhancer adware"
|
| X | FtkCPY | ftkcpy.exe | "FlashEnhancer adware"
|
| U | FtLnSOP_setup | FtLnSOP.exe | Fujitsu scanner utility
|
| U | FTMSFLT(USB) | FTMSFLTU.EXE | Fujitsu's Touch Panel Message Notifier
|
| X | FTP FOR WINDOWS | ftpwin32.exe | "Added by a variant of the RBOT WORM!"
|
| X | FTPGraber | FTPGraber.exe | "Added by the DLOADER-DT TROJAN!"
|
| N | FTPManager | FTPDM.exe | """Robust FTP is a Windows-based file transfer client application that transfers files between a user's local PC and another |
| U | Ftpqueue | Ftpsched.exe | "Part of WS_FTP Pro from Ipswitch. Queueing facility for scheduling FTP transfers"
|
| ? | FtpServer.exe | FtpServer.exe | "Part of the Sharpdesk from Sharp Electronics. ""A desktop-based |
| U | ftutil2 | "rundll32.exe ftutil2.dll | SetWriteCacheMode" |
| U | Fujitsu Hotkey Utility | IndicatorUty.exe | "Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook |
| U | Fujitsu Menu | FjMnuIco.exe | "From the ""Fujitsu Menu"" tray icon you have instant access to the Control Panel |
| N | FullAudio | WMPImporter.exe | Used to import settings from Windows Media Player into Music Now software (from www.musicnow.com - which is no longer available) and possibly others
|
| N | FusionHdtvTray | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| U | FusionRemote | FusionRc.exe | "Remote control manager for DVICO FusionHDTV"
|
| N | FusionTrayAgent | FusionHdtvTray.exe | "FusionTrayAgent - main executable for DVICO FusionHDTV software. It adds an icon to system tray that allows you to easily access Fusion HDTV software"
|
| Y | FveNotify | fveNotify.exe | "Windows Vista - BitLocker Drive Encryption Notification Utility. Available with Enterprise and Ultimate versions of Vista |
| N | fwrastrc | fwrastrc.exe | Dial-up software for Friendly Technologies/1NationOnLine free ISP
|
| X | Fxoekm | miyhart.exe | "Added by the SDBOT-CZQ WORM!"
|
| X | fzg | svhost32.exe | "Added by the DLOADER.BDK TROJAN!"
|
| ? | g3dctl | g3dctl.exe | "??"
|
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | "System Tray monitoring tool for Gene6 FTP Server - ""an advanced FTP server software for Windows developed specifically for security and high performance requirements"""
|
| N | Gadwin PrintScreen | PrintScreen.exe | "Gadwin PrintScreen - utility to capture |
| U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel
|
| X | game | shit.exe | Added by the Netclap Gold backdoor TROJAN!
|
| X | game | patcher.scr | "Added by the PSW-ED TROJAN!"
|
| N | GameDrive | GDTask.exe | "GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs"
|
| X | Games Acceleration | svshost.exe | "EasySearch adware"
|
| X | Games Acceleration | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Games Acceleration | svshost1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | "Topconverting.com/180Search ""Games Toolbar"" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| N | GameSpot | kontiki.exe | "Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
|
| N | GameTracker | GTLite.exe | "GameTracker - ""Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"""
|
| U | gameutil.exe | gameutil.exe | Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot
|
| X | gamma | svchost.exe | "Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies"
|
| U | GammaHotKeys | setgamma.exe | "Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop"
|
| X | gangsta | gangsta.exe | "Added by the RIMA.A BACKDOOR!"
|
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers
|
| X | Gate Personal Firewall | Systpl.exe | "Added by the RBOT.ADC WORM"
|
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder
|
| X | Gator | gator.exe | "Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | Gator eWallet | gator.exe | "Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| Y | GBMHome7Agent | GBMAgent.exe | "Genie Backup Manager Home 7 - backup software"
|
| Y | GBMLite7Agent | GBMAgent.exe | "Genie Backup Manager Lite 7 - backup software"
|
| Y | GBMPro7Agent | GBMAgent.exe | "Genie Backup Manager Pro 7 - backup software"
|
| U | GBTray | GBTray.exe | "System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup
|
| X | GDAX | [path to backdoor] | "Added by the RANKY.K TROJAN!"
|
| Y | GDFirewallTray | GDFirewallTray.exe | "System Tray access to the firewall part of G Data range of internet security products"
|
| X | Gekio Startups | gnksvc32.exe | "Added by the AGOBOT.AFJ WORM!"
|
| N | GemStRmW | GemStRmW.exe | "For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card |
| X | gencroot | gencroot.exe | "Added by the SDBOT-AED WORM!"
|
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives
|
| X | General Antivirus | GenAvir.exe | "General Antivirus rogue security software - not recommended |
| X | general lptt01 | general.exe | "RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Generic host proccess for windows | SVCHOSTS.EXE | "Added by the SPYBOT-GQ WORM!"
|
| X | Generic Host Process | SCHOST.EXE | "Added by the RBOT-NC WORM!"
|
| X | Generic Host Process | svchost.exe | "Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Generic Host Process | camacttiv.exe | "Detected by AVG as the CIADOOR.13 TROJAN!"
|
| X | Generic Host Process | lsassw.exe | "Added by the AGOBOT-N WORM!"
|
| X | Generic Host Process for Win Services | mscvs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Process for Win32 Service | svlhost.exe | "Added by the WOOTBOT.EX WORM!"
|
| X | Generic Host Process for Win32 Service | rpchost.exe | "Added by the IRCBOT.DCN WORM!"
|
| X | Generic Host Process for Win32 Services | ntspcv.exe | "Added by the SDBOT.S TROJAN!"
|
| X | Generic Host Process for Win32 Services | intspvc.exe | "Added by the DINFOR.D WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc.exe | "Added by the SDBOT-O WORM!"
|
| X | Generic Host Process for Win32 Services | bazzi.exe | "Added by the AHKER.E WORM!"
|
| X | Generic Host Process for Win32 Services | winsvc32.exe | "Added by the SDBOT-P WORM!"
|
| X | Generic Host Process for Win32 Services | lspsvc.exe | "Added by the MUMU.C WORM!"
|
| X | Generic Host Process for Win32 Services | SPSVC.EXE | "Added by the SDBOT.DA WORM!"
|
| X | Generic Host Process for Win32 Services | svchost32.exe | "Added by the AGOBOT.ALH WORM!"
|
| X | Generic Host Process for Win32 Services | svñhîst.exe | "Added by the DLOADER.AK TROJAN!"
|
| X | Generic Host Process for Win32 Services | winlogon.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | Generic Host Process For Win32 Services | mtsc32.exe | "Added by the VB-CPL TROJAN!"
|
| X | Generic Host Process for WinXP Services | mshelp.exe | "Added by the AGENT-GQP TROJAN!"
|
| X | Generic Host Process2 System Backup | scvhost2.exe | "Added by the RBOT-BAH WORM!"
|
| X | Generic Host Process326a System Backup | scvhost326a.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Generic Host Service | lshost.exe | "Added by the RBOT.LU WORM!"
|
| X | Generic Service Process | srvhost.exe | "Added by the AGOBOT-FX WORM!"
|
| X | Generic Service Process | SRCHOST.EXE | "Added by the AGOBOT-DG WORM!"
|
| X | GenericHostXP | WinLoaderXP.exe | "Added by the BDOOR-ACX BACKDOOR!"
|
| Y | Genie USB Monitor | USBmonitor.exe | Port monitor for an external USB hard drive. Required to enable access to the drive
|
| X | Genius Mose Driver | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | genserv path | sdqdqg.exe | "Added by the SDBOT-RF WORM!"
|
| X | Geography TX 1.0 NT | CompuSpeed.vbs | "Added by the NEWLEY-A WORM!"
|
| X | Gerenciamento de arquivos do Windows | Winmod32.exe | "Added by the DLOADER-WG TROJAN!"
|
| X | german.exe | winsystems.exe | "Added by the BAGLEDl-AE TROJAN!"
|
| X | german.exe | wintems.exe | "Added by the BAGLE-AS TROJAN!"
|
| X | Gestionnaire de disques universel | sysoobe.exe | "Added by the TOADER-A TROJAN!"
|
| N | Get Smile | getsmile.exe | Puts smilie faces in your E-mail. Run manually when required
|
| X | Get-Torrent Service | wakeservice.exe | Get-Torrent bittorrent client - Installs LOP adware
|
| Y | Getca | InfoMyCa.exe | "Monitor for a Belkin USB Wireless adapter"
|
| U | GetIT | GetIT.exe | """HP GET-IT (Graduate Entrepreneurship Training through Information Technologies) empowers under- or unemployed young people with business and IT skills - helping them find a job or start their own businesses"""
|
| X | GetitAll | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetModule18 | GetModule18.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule19 | GetModule19.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule20 | GetModule20.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule21 | GetModule21.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule23 | GetModule23.exe | "Internet Speed Monitor adware related"
|
| X | GetModule24 | GetModule24.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule25 | GetModule25.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule27 | GetModule27.exe | "Internet Speed Monitor adware related"
|
| X | GetModule29 | GetModule29.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetModule30 | GetModule30.exe | "Internet Speed Monitor adware related"
|
| X | GetMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | GetPack18 | GetPack18.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack19 | GetPack19.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack20 | GetPack20.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack21 | GetPack21.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack22 | GetPack22.exe | "Internet Speed Monitor adware related"
|
| X | GetPack23 | GetPack23.exe | "Internet Speed Monitor adware related"
|
| X | GetPack24 | GetPack24.exe | "Internet Speed Monitor adware related - see example here"
|
| X | GetPack25 | GetPack25.exe | "Internet Speed Monitor adware related"
|
| U | GetRight | GetRight.exe | "GetRight from Headlight Software - shareware download manager for resuming downloads and choosing multiple download locations. The Pro version adds uploading and other features. Earlier 4.x versions included ads |
| U | GetRight - Tray Icon | getright.exe | "Entry added with older versions of the GetRight download manager from Headlight Software |
| X | GetTheMusic | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | Getting started with MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | getwin | winB_.exe | "Added by the BANKER-HS TROJAN!"
|
| X | gfxtray | "rundll32 ctccw32.dll | findwnd" |
| X | Ghost Antivirus | GhostAV.exe | "Ghost Antivirus rogue security software - not recommended |
| X | Ghost Relay | [random filename] | "Added by the DNSCHANG.EK TROJAN!"
|
| U | GhostSecuritySuite | gss.exe | "Ghost Security Suite - protect the registry from unauthorized reading and modification and other tools"
|
| N | GhostStartService | GhostStartService.exe | "Required to run the Windows based wizard in Norton Ghost - added from the 2003 version. Will start automatically when you run the wizard"
|
| N | GhostStartTrayApp | GhostStartTrayApp.exe | "System Tray access to Norton Ghost - added from the 2003 version"
|
| Y | GhostSurfDelSatellite | DeleteSatellite.exe | "Part of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning |
| X | gigabit.exe | gigabit.exe | "Added by the BEAGLE.U WORM!"
|
| X | GigaByte | Cheatle.exe | "Added by the SHODI.B VIRUS!"
|
| U | Giganews Accelerator | GiganewsAccelerator.exe | "Giganews Accelerator from Giganews |
| Y | Gilat SOM Enumerator | dllhost.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| Y | GilatFTC | ftc.exe | For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
|
| X | gimmygames | [path to trojan] | "Added by the DLOADR-LN TROJAN!"
|
| X | GinaDll | ntgina.dll | "Added by the ANIG.A WORM!"
|
| X | GLF Network Lan Monitor | NPFMNTOR.exe | "Added by the RBOT-AGY WORM!"
|
| X | Global Startup | WinDash.EXE | "Detected by Kaspersky as the VB.Q WORM!"
|
| X | Glock Suite 1.1 | glock32.exe | "Added by the TINY.GV TROJAN!"
|
| X | GLSetIT32 | msiexec16.exe | "Added by the OPTIX PRO TROJAN!"
|
| X | GLSetIT32 | isass.exe | "Added by a variant of the OPTIX PRO TROJAN!"
|
| X | GLSetT32 | smsiexec.exe | "Added by the OPTIX-D TROJAN!"
|
| U | Gnetmous | gnetmous.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| U | GNETMOUSE | gnetmouse.exe | "Genius mouse driver - required if you use non-standard Windows driver features"
|
| X | GNP Generic Host Process | svchost.exe | "Added by the ZAPCHAS-F BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| X | Go And Start | svdll32.exe | "Added by the RBOT.AI BACKDOOR!"
|
| X | Go!Zilla Monster Downloads | Go.exe | Download manager for resuming downloads and choosing multiple download locations. Advertising spyware
|
| U | GoBack | GBTray.exe | "System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| U | GoBack Tray Icon | GBTray.exe | "Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users |
| X | GoldenAntiSpy | pgs.exe | "GoldenAntiSpy rogue security software - not recommended. A member of the AVSystemCare family"
|
| U | Goldensoft_MndlSvr | MndlSvr.exe | "Goldensoft CD Ghost related - turns a computer into a 200X-speed CD-ROM tower. Working from the hard drive |
| U | Google Desktop | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| U | Google Desktop Search | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| X | Google Earth | [random filename] | "Added by the RBOT-AXK TROJAN!"
|
| N | Google Earth Viewer | GOOGLEMAPS.EXE | "Google Earth ""combines satellite imagery |
| U | Google IME Autoupdater | GooglePinyinDaemon.exe | "Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone |
| X | google Intrenet Explorer | google.pif | "Added by the RBOT-ARA WORM!"
|
| X | Google service | Googlesetup.exe | "Added by the IRCBOT-RJ WORM!"
|
| X | google toolbar | ggtb32.exe | "Added by the AGOBOT-RR WORM!"
|
| N | Google Update | GoogleUpdate.exe | "Update manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %AppData%\Google\Update"
|
| X | Google Update | GoogleUpdate.exe | "Added by the BUZUS.DBFM TROJAN! Note - this is not the valid Google program which is normally located in %AppData%\Google\Update. This version resides in %System%"
|
| N | Google Updater | GOOGLE~1.EXE | "Downloads and installs updates for Google applications (Google Earth |
| N | Google Updater | GoogleUpdater.exe | "Downloads and installs updates for Google applications (Google Earth |
| X | GoogleBot.exe | GoogleBot.exe | "Added by the GB TROJAN!"
|
| N | GoogleDCClient | GoogleDCC.exe | "Google Compute Client - only present if you installed the Google Toolbar with ""Google Compute"" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser |
| U | GoogleDesktop | GoogleDesktop.exe | "Google Desktop - ""a desktop search application that provides full text search over your email |
| U | googletalk | googletalk.exe | "Google Talk ""enables you to call or send instant messages to your friends for free-anytime |
| U | GoogleToolbarNotifier | GoogleToolbarNotifier.exe | "Part of Google Toolbar (from version 4 onwards) for IE. ""Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change"". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolved"
|
| X | GoogleUpdater3 | GoogleMapper.exe | "Added by the ROUTROBOT WORM!"
|
| X | gotnewupdate000.exe | gotnewupdate000.exe | "Added by the FAKEAV-BGA TROJAN!"
|
| U | GoToMyPC | g2svc.exe | "ExpertCity GoToMyPc logon - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browser"
|
| U | GoTrusted | GoTrusted Secure Tunnel.exe | """GoTrusted is the fast |
| X | GotSmiley | GotSmiley.exe | "GotSmiley - ad supported program that provides the user with smileys for use in emails. Not recommended. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | govurarope | "Rundll32.exe retasevo.dll | s" |
| X | GP Updater | gpupdater.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| ? | gramdate | 2Stop.exe | "??"
|
| X | Graphic Loader | ntvdm32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Graphic Update | openglx.exe | "Added by the IRCBOT.AMU WORM!"
|
| X | Graphics | _default.pif | "Added by the AUTOSKY WORM!"
|
| X | Graphics adapter service | windll.exe | "Added by the ATNAS.A WORM!"
|
| U | Gravis Xperience Driver Support | Grxp4exe.exe | "Driver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not used"
|
| X | GreasyPalmUpdate | GreasyPalmUpdate.exe | "SearchFast adware"
|
| X | GreatDefender | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDefender.exe | GreatDefender.exe | "GreatDefender rogue security software - not recommended |
| X | GreatDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Greetings Workshop | GWREMIND.EXE | You really want to be reminded about somebody's birthday at the expense of resources?
|
| X | gremier | wscript.exe gpremier.vbs | "Added by the GPREMIER WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""gpremier.vbs"" file is located in %System%"
|
| X | Gremlin | intrenat.exe | "Added by the DOOMJUICE WORM!"
|
| X | grgtgvgb.exe | [random].exe | "Added by the AGENT-EBF TROJAN!"
|
| N | Grokster | Grokster.exe | "Grokster Peer-To-Peer File Sharing program"
|
| Y | Groove Virtual Office | Groove.exe | """Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings |
| U | GrooveMonitor | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GrooveMonitor Utility | GrooveMonitor.exe | "Part of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| U | GroupWise PDA Connect - 3CmPlm | AutoDet.exe | "3Com Palm PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - GrpWse | Agnt.exe | "GroupWise PDA Connect PDA synchronisation utility - from Novell"
|
| U | GroupWise PDA Connect - PocketPC | AUTODE~1.EXE | "Windows Mobile Pocket PC specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| U | GroupWise PDA Connect - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for the GroupWise PDA Connect PDA synchronisation utility from Novell"
|
| ? | GSISETUP | [path] GsiInst.exe INSTALL [path] V205Res 13 | "BT Voyager ADSL modem related - what does it do and is it required?"
|
| X | gssomatic | gssomatic.exe | "Searchcentrix hijacker"
|
| Y | gStart | gStart.exe | gStart GPS software from Garmin
|
| X | GStartup | GMT.exe | "Gator spyware component - see here. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | GT | GT.EXE | "Added by the SDBOT-AJ WORM!"
|
| X | GT15J4R49V | cpuserv.exe | Identified as a variant of the Trojan.Win32.Radi.gu malware
|
| U | GTVEpg | GTVEpg.exe | "Part of Got All Media - control your TV tuner and other utilities from your PC"
|
| U | GTVRec | GTVRec.exe | "Part of Got All Media - control your TV tuner and other utilities from your PC"
|
| N | Gtwatch | gtwatch.exe | Associated with a Mustec scanner and not required
|
| X | gtydf | iisca.exe | "Added by the CLAGGER-BB TROJAN!"
|
| X | gtydf | iscca.exe | "Added by the DWNLDR-GTK TROJAN!"
|
| X | gtydf | ggrrgg.exe | "Added by the DLOADR-AZK TROJAN!"
|
| X | GuardCenter | GuardCenter.exe | "GuardCenter rogue security software - not recommended"
|
| Y | GuardGui Application | GuardGui.exe | "System Tray access to the main user interface for Ashampoo® AntiVirus from Ashampoo GmbH & Co. KG."
|
| U | Guardian PC Security Tools | Pfft.exe | "Boomerang Software's Guardian PC Security Tools - now rebranded as the eXtendia Security Suite"
|
| X | guarnset | guarnset.exe | "Adlogix adware"
|
| U | GuruNet | GuruNet.exe | "GuruNet lets you click on any word on your screen to get the relevant information you want"
|
| X | GustavVED | [filename].exe | "Added by the OPASERV.H WORM!"
|
| Y | gw port controller | PORTCT95.EXE | "From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties |
| N | GWInkMonitor | GWInkMonitor.exe | "Gateway ink monitor - makes an annoying popup that says your printer may be running out of ink |
| X | gwiz | ntsystem.exe | "Added by the NITWIZ.A TROJAN!"
|
| X | G_Host | gHost.exe | "Added by the AUTOIT-BP WORM!"
|
| U | H/PC Connection Agent | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| X | h4te Service Drivers | h4te.exe | "Added by a variant of the RBOT WORM!"
|
| X | hachimitsu-lemon | hachimitsu-lemon.exe | "Added by the HACHILEM TROJAN!"
|
| X | HackMuFpt | HackMuFpt.exe | "Added by the SCLOG-AG TROJAN!"
|
| X | hagent | avp.exe | "Added by the ""Herman Agent"" remote access TROJAN!"
|
| U | HalifaxHowardCluster | skinkers.exe | """Howard the Weatherman"" desktop client from Halifax by Skinkers - marketing/messaging tool. Leave enabled if you want to receive messages"
|
| U | HaMFrontPanel | hampanel.exe | "Displays a panel simulating modem lights for the Intel HaM internal modem. The lights are useful as a reminder to disconnect from the net if you are likely to forget |
| U | Handy Backup 3.9 | hbagent.exe | "Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
|
| X | HanUpdate | hanz.exe | "Added by the RBOT-GLJ WORM!"
|
| N | Hard Disk Sentinel | HDSentinel.exe | "Hard Disk Sentinel - a multi-OS hard disk drive monitoring application. Its goal is to find |
| X | Hard drive Controller | hdcontroller.exe | "Added by the KIMAN.B WORM!"
|
| U | Hardware Doctor | Hwdoctor.exe | "Winbond Hardware Doctor - as included on some motherboard using Winbond's hardware monitoring chips. Displays fan speeds |
| X | Hardware Monitor Service | mshms.exe | "Added by the WOLLF-A TROJAN!"
|
| U | Hardware Sensors Monitor | hmonitor.exe | Utility to monitor fan speed and temperatures - similar to Motherboard Monitor. Only required if you're concerned about your system temperature - typically for "overclocked" systems
|
| X | Hardware Shell Detection | WinHSD.exe | "Added by a variant of the RBOT WORM!"
|
| U | Harmony 98 - CasioOrg | CasAgnt.exe | "Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
|
| X | HataDuzelticisi | SysRep.exe | "HataDuzelticisi |
| X | HATAPE | [path to trojan] | "Added by the BANKER-QF TROJAN!"
|
| U | HawkEye IV Control Panel | HAWK_32.EXE | "Control Panel application for the old Number Nine graphics cards to change resolution |
| U | Hawking HWU54G Utility | HWU54G.exe | "Wireless management utility for the HWU54G Mini Wireless-G USB Adapter from Hawking Technologies |
| U | Hawking Wireless Utility | HWU8DD.exe | "Wireless management utility for the HWU8DD Hi-Gain™ USB Wireless-G Dish Adapter from Hawking Technologies |
| X | Hbinst | Hbinst.exe | "Hotbar adware"
|
| N | HCDetect | HCDetect.exe | "MS HomeClick Network - simple home network setup and configuration program included with 3Com HomeConnect home networking products. Runs in the background for network printer notification |
| U | hcenter | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | hcenter | hcenter.exe | "Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | Hcontrol | hcontrol.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| U | HControlUser | HControlUser.exe | Hotkeys on an ASUS Notebook. Only required if you use the additional keys
|
| N | hcsystray | hc_tray.exe | "Kuma Notifier for the Shootout! game from the History Channel. ""It lets you know whenever there's a new episode that's been released or an announcement from the Kuma team. Just click it to get up-to-the-minute game and event information"""
|
| N | HD Audio Control Panel | RtHDVCpl.exe | "Realtek HD Audio Manager |
| N | HDAShCut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | HDDControlGuard | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| U | HDDControlGuard.exe | HDDControlGuard.exe | "Part of Ashampoo® HDD Control from Ashampoo GmbH & Co. KG - a hard drive monitoring utility which also incorporates defragmentation and cleaners for browsing history and unnecessary files. This entry loads the Ashampoo HDD Control Guard component on startup which runs in the background and monitors the hard drives and provides System Tray access"
|
| U | HDDHealth | hddhealth.exe | "HDD Health is a ""full-featured failure-prediction agent for machines using Windows 95 |
| ? | HDhelp | tbhdhelp.exe | "Associated with Philips Edge series soundcards. Is it required?"
|
| X | hdlfoe df98ndf | svchots.exe | "Added by a variant of the RBOT WORM!"
|
| X | hdlpscom | [8 random letters].exe | "Added by the RBOT-FUL WORM!"
|
| N | HDtray | HDtray.exe | Philips Edge Series Control Panel Tray Utility - system tray icon for a Philips Edge series soundcards. Available via Start -> Settings -> Control Panel
|
| X | Hekio Startups | Hnksvc32.exe | "Added by the AGOBOT-QE WORM!"
|
| X | HELLBOT TEST | 1hellbot.exe | "Added by the MYDOOM.BO WORM!"
|
| X | HELLBOT3 | coolbot.exe | "Added by the MYTOB.AB WORM!"
|
| X | hellfire | svchost.exe | "Added by the LEOX.D TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | hellodolly | shost.exe | "Added by the YODO WORM!"
|
| X | HelloInt | hello3.exe | "Added by the CASAL.A TROJAN!"
|
| X | helloworld | nb32ext2.exe | "Added by the MYDOOM.BV WORM!"
|
| X | helloworld | nb32ext3.exe | "Added by the MYTOB.JT WORM!"
|
| X | helloworld3 | nb32ext4.exe | "Added by the RITDOOR.A WORM!"
|
| ? | Help | helpext.exe | "??"
|
| X | Help | lshost.exe | Identified as a variant of the Trojan-Clicker.Win32.Delf.aro malware
|
| X | Help Temp Files | netreg.exe | "Added by the FORBOT-EM WORM!"
|
| X | Help Temp Files | emp32.exe | "Added by the FORBOT-EC WORM!"
|
| U | HelpCenter | sprtcmd.exe /P HelpCenter | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| U | HelpCenter4.1 | sprtcmd.exe /P HelpCenter4.1 | "Self-help support tool for BellSouth's FastAccess® DSL (now owned by AT&T) broadband service (provided by SupportSoft |
| X | helpctl.exe | helpctl.exe | "Added by the GASLIDE TROJAN!"
|
| X | HELPER | Netherlands.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | HELPER | temp532.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | helper.dll | rundll32.exe [path] helper.dll | "CnsMin (Chinese Keywords) hijacker related. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | heomstool | heomstool.exe | "Added by the HEOMS TROJAN!"
|
| Y | HEProtect | HSockPE.exe | "Part of the AntiSpam function of the HAURI ViRobot Desktop internet security suite"
|
| X | hErcUnes | softhost.exe | "Added by the GARROCH WORM!"
|
| X | Hewlett Packard Manager | hpmanager.exe | "Added by the MYTOB.KE WORM! Note - this is not a valid Hewlett-Packard program"
|
| N | Hewlett Packard Recorder | Remind32.exe | HP multifunction registration
|
| X | HF Security | hfsecure.exe | "Added by the AGOBOT-TI WORM!"
|
| X | hfdtubvnx | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| X | hgkytwe | keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
| N | HGTXPEI | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel
|
| X | Hhjg5jfd93dftdf | winlogan.exe | "Added by the ERTFOR.A TROJAN!"
|
| X | hhtnsn | rnxntup.exe | "Added by a variant of the ORCU.B TROJAN!"
|
| ? | HiberMonitor | HCount.exe | "??"
|
| U | Hibernation | hib32.exe | "Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate |
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | "Added by the BOOHOO WORM!"
|
| X | HideStyle | Ante Browse Trust.exe | "IE toolbar taking you to Lop.com. If the exe is running |
| U | Hidetools Spy Monitor | wmispe.exe | "HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself"
|
| X | Hidup_Susah | Pembantu.exe | "Added by the SILLYFDC.BDM WORM!"
|
| X | hid_start | gzmrotate.dll | "AdRotator/IconAds adware"
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| N | High Definition Audio Property Page Shortcut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required
|
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | "Realtek audio card related. Probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required"
|
| Y | HighPoint ATA RAID Management Software | raidman.exe | "HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID"
|
| X | Highspeeddownloader | SetupClickHere.EXE | "Homepage hijacker |
| U | HijackThis | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| U | HijackThis startup scan | HijackThis.exe | """HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware |
| X | himem.exe | [path to worm] | "Added by the STRATION-FW WORM!"
|
| X | HistoriaLout. | GDC.exe | "HistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | HistoryKill | histkill.exe | "HistoryKill removes your web surfing path by removing the URL drop-list history |
| U | Hitman Pro SurfRight Helper | srhelper.exe | "Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy"
|
| X | HitQ | HitQ.exe | "Hijacker |
| U | HitwarePKLite | HITWAR~1.EXE | "Hitware Popup Killer Lite"
|
| X | HKLMRun | windowsupdate.exe | "Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)!"
|
| X | HKLM\Run | svhost.exe | "Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)!"
|
| X | HLcleanup | hlsetup2.exe | "LinkReplacer/FFinder adware"
|
| X | hlhtxo.exe | hlhtxo.exe | "Added by the QLOWZONES-27 TROJAN!"
|
| X | HLL Data Parameter | hllcxpa.exe | "Added by the RBOT.AFG WORM!"
|
| X | HMI PowerSystem | hmisvc32.exe | "Added by the RANDEX.CZZ WORM!"
|
| U | Hmonitor | Hmonitor.exe | Hardware sensor monitoring program. Only required if you overclock your system and want to check on the status
|
| X | ho2stdll.exe | ho2stdll.exe | "Added by the BANKER-HO TROJAN!"
|
| N | Holiday Lights | Holiday Lights.exe | "Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs"
|
| X | Hollaback | slvhosts.exe | "Added by the SDBOT.BMO WORM!"
|
| X | Home Antivirus 2010 | HomeAntivirus2010.exe | "Home Antivirus 2010 rogue security software - not recommended |
| N | Home Theater SchSvr | SchSvr.exe | "WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| X | HomeAntivirus 2009 | HomeAntivirus2009.exe | "HomeAntivirus 2009 rogue security software - not recommended |
| ? | HomeCentre WakeUp | LGWAKEUP.EXE | "Associated with the no longer supported Xerox HomeCentre printer/scanner"
|
| X | Homeland Network | HomelandNetwork.exe | Homeland Network Notifier - pops ads
|
| X | homepage.monitor.exe | isamonitor.exe | "Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as ""iCodecPack"" |
| U | Hook99startup | hk2re.exe | ""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons |
| U | HornetMonitor | MntrHrnt.exe | "Hornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network"
|
| Y | HorngTech4D | bally4d.exe | HorngTech 4D mouse driver
|
| X | Host | N/A | "Added by the POPDIS or STARTPAGE.F TROJANS!"
|
| X | host | help.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN!
|
| X | Host Process | mame.exe | "Added by the RBOT-APO WORM!"
|
| X | Host Process | svchost.exe | "Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory"
|
| X | Host Process for Windows Tasks | taskhost.exe | "Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also ""Host Process for Windows Tasks"". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | hostdll.exe | hostdll.exe | "Added by the BANKER-BO TROJAN!"
|
| U | HostManager | AOLHostManager.exe | "Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched |
| N | HostManager | AOLSoftware.exe | "Quoted from AOL Beta Team |
| X | Hostname Manager Server | host32srv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Hostren.exe | Hostren.exe | "Added by PWS.BANKER.F |
| X | hostserv | hostserv.exe | "Added by the RBOT.BPZ WORM!"
|
| X | hostserv | wiz98.exe | "Added by a variant of the SDBOT WORM!"
|
| U | HostsFileMgr | winHostsEdit.exe | "AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file"
|
| U | HostsMan | hm.exe | """HostsMan is a freeware application that lets you manage your Hosts file with ease"". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost |
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.H WORM! Drops multiple files in %System%"
|
| X | HostSrv | sachostx.exe | "Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS!"
|
| X | HostSrv | sachostx.exe... | "Added by the LOOKSKY.E WORM!"
|
| X | HostSVC syse | HostSVC.exe | "Added by the RBOT-ANZ WORM!"
|
| X | Hot 8.0 Live | hot.exe | "Added by the BANKER.EIE TROJAN!"
|
| U | Hot Corners | Hotc.exe | "Hot Corners - ""lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen"""
|
| X | HOT FIX | Gothic.exe | "Added by the SDBOT.FIR WORM!"
|
| X | HOT FIX | filename.exe | "Added by the SDBOT-DKM WORM!"
|
| X | HOT FIX | E0chis.exe | "Added by the HUPIGON.JTY TROJAN!"
|
| X | HOT FIX | QOching.exe | "Added by the WOOTBOT.VH WORM!"
|
| X | HOT FIX | View.exe | "Added by the WOOTBOT.BN WORM!"
|
| X | HOT FIX | windsys2.exe | "Added by the AGOBOT.AOI BACKDOOR!"
|
| X | Hot Inside | Hottest Story Ever.exe | "Added by the BHARAT.A WORM!"
|
| U | Hot Key Kbd 2690 Daemon | SK2690DM.EXE | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| U | Hot Key Kbd 9910 Daemon | SK9910DM.exe | Multi-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
|
| ? | Hot Party 22 | hotpart22.exe | "??"
|
| X | HotAction_hr | hotaction_hr.exe | "Added by the SITEICON-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as ""HotAction_hr"""
|
| X | Hotbar | Hbinst.exe | "Hotbar adware"
|
| X | Hotbar | HbOEAddOn.exe | "Hotbar adware"
|
| X | HotbarOE | OEAddOn.exe | "Hotbar adware"
|
| X | HotbarSA | HotbarSA.exe | "Hotbar adware"
|
| X | hotdlll | remote.cmd | "Added by the BANKER-EHG TROJAN!"
|
| X | hotdlll | vmmreg32.exe | "BANKER.DX spyware"
|
| X | hotefix | msnmanegers.exe | "Added by the IRCBRUTE.AS TROJAN!"
|
| X | hotfix | msnnmaneger.exe | "Added by the WOOTBOT.AF WORM!"
|
| X | Hotfix Updat | svdhost32.exe | "Added by the GAOBOT.ZW WORM!"
|
| U | HOTFOON2 | hotfoon4.exe | "Related to Hotfoon - a developer and provider of Internet Telephony technology based on LTP (Lightweight Telephony Protocol)"
|
| U | HotIDE | hotide.exe | HotIDE allows Acer TravelMate owners to hot-swap external drives without switching of their notebooks
|
| U | HotkeyApp | HotkeyApp.exe | "Programmable keys on Acer |
| U | HotKeysCmds | hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
| X | HotKeysCmds | [path to worm] | "Added by the PAHATIA-A WORM!"
|
| X | HotPix | hotpix.exe | Adult content dialler
|
| X | hotplug | hotplug.exe | "Added by the SILLYDL TROJAN!"
|
| U | Hotplug | hot_plug.exe | "Related to the SiS_Hot_Plug_Application. Enables automated driver loading for hotpluggable devices. If this service is stopped |
| N | HotSync Manager | hotsync.exe | Installed when connecting a Palm HotSync cradle up to a USB port. The Blue and Red Arrow Icon that enables Palm / Handspring Synchronizing. Available via Start → Programs
|
| X | hotwetlove | hotwetlove.exe | Adult content dialler. Will not uninstall - components have to be manually deleted
|
| X | Hot_Kiss | Hot_Kiss.exe | Adult content dialler
|
| X | Hot_Tarts | Hot_Tarts.exe | Adult content dialler
|
| X | Hot_Tarts_** | Hot_Tarts_**.exe | Premium rate adult content dialer (where * is a random char)
|
| X | Hot_Tarts_Au | Hot_Tarts_Au.exe | Premium rate adult content dialler
|
| X | Hot_Tarts_mc | Hot_Tarts_mc.exe | "HotTarts adult content dialer"
|
| U | HP AutoIndexer | hppautoindexer.exe | "Installed by HP multi-function printer driver software |
| N | HP CD Writer | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| N | HP CD-DVD | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| N | HP CD-Writer | hpcdtray.exe | System Tray access to a HP CD-Writer's functions. Available via Start -> Programs
|
| X | hp center | BACKWEB-*****.exe | "See here - ""messaging service that automatically sends you support information |
| N | hp center UI | ShadowBar.exe | "User Interface for HP Center - see here"
|
| N | HP Component Manager | hpcmpmgr.exe | "Checks the internet for updated drivers/utilities for your HP product - update manually. Disabling will remove the error ""Windows can't shutdown the computer because hpcmpmgr.exe can't be ended"""
|
| X | HP Deskjet | HP_DeskJet_500.exe | "Added by the FORBOT-DA WORM!"
|
| X | HP Desktop | ccappms.exe | "Added by the SDBOT-TG WORM!"
|
| U | HP Digital Imaging Monitor | hpqtra08.exe | "System Tray access to HP Director. Required if you prefer to use the all-in-one buttons to manually scan documents or transfer photos froma camera |
| U | HP Display Settings | hpdisply.exe | "Sets default display settings. Unchecking this item has been reported to cure a ""Problem sending command to keyboard"" error message"
|
| U | HP Health Check Schedule | HPHC_Scheduler.exe | HP Health Check Scheduler from Hewlett-Packard
|
| N | HP Image Zone Fast Start | hpqthb08.exe | "Improves the startup time of HP Image Zone. If you disable it |
| U | HP Instant Support | matcli.exe | ""matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| N | HP Internet Center | SURFBRD.EXE | Loads the HP Internet center surfboard on startup. HP Internet Center allows you to customize the multimedia keys on the fly without having to go the Control Panel --> Keyboards to change them
|
| N | HP JetDiscovery | HPJETDSC.EXE | HP JetAdmin software which monitors printing jobs on a network environment
|
| N | HP JetSpeed Autostart | AUTOSTART.EXE | Autostart executable for the old multiplayer game HP Jetspeed
|
| U | HP Laser Jet Director | hppdirector.exe | "System Tray icon that opens various functions such as copy |
| ? | HP Network Registry Agent | hpnra.exe | "??"
|
| ? | HP OfficeJet Series xxx Startup | HPOSTR03.EXE | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| ? | HP OfficeJet Series xxx Startup | HPOstr05.exe | "xxx represents the series number - such as 700. What does it do and it it required?"
|
| N | HP Parallel Port Test | hppt.exe | Associated with a HP ScanJet scanner
|
| X | HP Photo Manager | HPPhotoManager.exe | "Added by the SDBOT.AXU WORM!"
|
| N | HP Photosmart Premier Fast Start | hpqthb08.exe | "Improves the startup time of HP Image Zone. If you disable it |
| ? | HP Port Resolver | hpbpro.exe | "??"
|
| N | HP Presentation Ready | PresRdy.exe | HP Omnibook related: "Press a dedicated button above the keyboard and the system will instantly load your presentation software and change the screen resolution to match your display device"
|
| U | HP ScanPatch | HPScanFix.exe | "Program that starts up and automatically fixes earlier versions of the Scanjet 5100c software. If a Scanjet 5100C scanner is not going to be used |
| N | HP ScanPicture | hpsplmwa.exe | HP multifunction scanner software. Available from HP Office Jet R Toolbox so not required
|
| ? | hp Silent Service | HpSrvUI.exe | "HP related"
|
| N | HP Simple Trax | Hpcron.exe | Supplied with HP CD-RW drives - stores information about CD contents on your hard drive. Available via Start -> Programs or Desktop Icon
|
| N | HP software update | HPWuSchd2.exe | HP software updates. If a shortcut doesn't exist create your own and run it manually
|
| N | HP software update | HPWuSchd.exe | "HP software updates. If a shortcut doesn't exist |
| N | HP Status | hpstatus.exe | HP Printer Status and Alerts
|
| ? | HP Status Server | hpboid.exe | "Copied during installation of HP Inkjet Printer Drivers in Win2K/XP. What does it do and is it required?"
|
| U | HP TV Now | HpTvNow.exe | Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts)
|
| X | HP Update Assistant | HPAware.exe | Added by the MRO TROJAN!
|
| N | HP Updates | ?? | "On HP PCs |
| ? | HP Visualize Init | HpVisIni.exe | "HP Visualize software related. What does it do and is it required?"
|
| N | HP-Aio Flight | Remind32.exe | HP multifunction registration
|
| ? | HPAiODevice(hp officejet g series) | hpoavn07.exe | "HP Printer related |
| N | HPAiODevice(hp psc 900 series) -1 | hpobrt07.exe | "Installed with a Hewlett Packard 900 series colour printer |
| N | HPAIO_PrintFolderMgr | hpoopm07.exe | "Directly from HP: "This process has one purpose - detects if the device moves to a different port |
| U | HPBootOp | HPBootOp.exe | """HP Boot Optimizer intelligently and dynamically launches software during startup |
| U | HPDAgent | HPDAgent.exe | "Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive |
| X | hpdeskjet | hpdeskjet.exe | "Added by the GENOME.AQUV TROJAN!"
|
| U | HPDJ Taskbar Utility | hpztsb01.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb02.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb04.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb05.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb07.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb09.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb06.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb08.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb03.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb10.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb11.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb12.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPDJ Taskbar Utility | hpztsb13.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | HPGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| ? | hpjsiroute | hpjsira.exe | "Related to HP laserjet printers and IP addresses. An IP address is appended to the name field - ie "hpjsiroute192.168.1.2""
|
| U | HPLaptopGamesActiveMenu | ActiveMenu.exe | Wild Tangent demo games that come with some HP computers. Unchecking it can prevent the games from running occasionally. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
|
| Y | HPLJ Config | SetConfig.exe | Connects system to networked HP printer.
|
| U | HPMVTray | HPMVTray.exe | "HP Media Vault Networked Storage Device - System Tray management utility"
|
| X | HPNT | hpdll.exe | "Malware downloader - detected by Kaspersky as the VB.KU TROJAN!"
|
| N | hpoddt01.exe | N/A | "Installed by the ""HP Photo and Imaging Director"" software. If you ask for the imaging software |
| U | hpoddt01.exe | hpotdd01.exe | "Detection of new imaging |
| Y | hpppt | hpppt.exe | Related to the drivers for HP ScanJet scanners
|
| Y | hpppta | HPPPTA.exe | HP parallel port driver for certain hardware
|
| X | HpPrinter | hpserver.exe | "Added by the CMJSPY-W TROJAN!"
|
| N | HPPROPTY | HPPROPTY.EXE | "HP LaserJet Toolbox"
|
| U | HPSCANMonitor | hpsjvxd.exe | HP scanning software that enables you to scan images from your scanner. Needed if you're using the scanner
|
| ? | hpScannerFirstBoot | scannerfb.exe | "HP scanner related"
|
| N | HPStart | hpstart.wsf | This a script used by HP that runs the first time one of their computers is started. Can't imagine why it would be starting up after the first boot
|
| X | hptools | hptools.exe | "Added by a variant of the SDBOT WORM!"
|
| X | hptools | microsoft.exe | "Added by a variant of the SDBOT WORM!"
|
| N | HPU | ProvenTactics.exe | "Proven Internet Marketing software"
|
| U | hpWirelessAssistant | HP Wireless Assistant.exe | The HP Wireless Assistant is a user application that provides a way to control the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices
|
| U | hpWirelessAssistant | HPWAMain.exe | Wireless application bundled with HP computers that allows you to control different settings on the computer's wireless devices such as Bluetooth and WLAN
|
| N | HPZTS04 | hpzts04.exe | Hewlett Packard printer toolbox shortcut that resides in the system tray
|
| U | hpztsb02 | hpztsb02.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb04 | hpztsb04.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb05 | hpztsb05.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb07 | hpztsb07.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsb09 | hpztsb09.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| U | hpztsbol | hpztsbol.exe | HP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
|
| N | HP_dla | dlatray.exe | "On HP PCs |
| X | HP_runner | front.exe | "Added by the SILLYFDC WORM!"
|
| N | hqtray | hqtray.exe | "VMware Host Network Access Status Tray Application - part of both VMware Player (from version 2.0) and Workstation (until version 6.5) - which allow you to ""run multiple operating systems simultaneously on a single PC."" It's function is uknown at present and it displays no tray icon as the name suggests. Can be disabled without affecting the operation of either product"
|
| X | Hrn_qtv | hrnsvc32.exe | "Added by the SDBOT-AET WORM!"
|
| X | hsim | toolbar.exe | Unidentified malware
|
| U | HSTrans | hstrans.exe | "Homescan Internet Transporter - part of ACNielson Homescan. Recognizes when the ACNielsen Homescan Scanner is attached to the computer and allows it to transmit scanner information to ACNielsen"
|
| ? | HsuGuiControl | HsuGuiControl.exe | "Part of the Starband Internet satellite client. What does it do and is it required?"
|
| U | Hti | npdor.exe | "Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
|
| X | HTML Help System | hhs.pif | "Added by the RBOT-ATB WORM!"
|
| X | HTML32 Help System | hhs32.pif | "Added by the RBOT-ATE WORM!"
|
| U | HTpatch | htpatch.exe | HTpatch.exe is part of the SiS AGP patch - BUT unless your processor (and motherboard) supports HyperThreading (HT) and this feature is enabled it will actually SLOW your graphics card by around 6%
|
| X | HtProtect | AVprotect.exe | "Added by the NETSKY.L WORM!"
|
| X | htssv32.exe | htssv32.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | HTTP Tunneling Server | mstunnel.exe | "Added by the RBOT.EDL WORM!"
|
| X | http://www.lienvandekelder.be | LienVandeKelder.exe | "Added by the MYTOB-AZ WORM!"
|
| X | http://www.lienvandekelder.be | Lien Van de Kelder.exe | "Added by the MYTOB-AP WORM and variants!"
|
| X | http://www.lienvandekelder.be | Lien Vande Kelder.exe | "Added by the MYTOB-AQ WORM!"
|
| X | http://www.lienvandekelder.be | Lien vd Kelder.exe | "Added by the MYTOB-M WORM!"
|
| X | http://www.lienvandekelder.be | Lien.exe | "Added by the MYTOB-CZ WORM!"
|
| X | http://www.lienvandekelder.be | Lientjeuh.exe | "Added by the MYTOB-P WORM!"
|
| X | http://www.lienvandekelder.be | LienVdK.exe | "Added by the MYTOB-U WORM!"
|
| X | http://www.lienvandekelder.be | Van de Kelder Lien.exe | "Added by the MYTOB-BF WORM!"
|
| X | http://www.lienvandekelder.be | We Love Lien Van de Kelder.exe | "Added by the MYTOB-CV WORM!"
|
| X | http://www.lienvandekelder.com | Lien Van de Kelder.exe | "Added by the MYTOB-EQ WORM!"
|
| X | http://www.lienvandekelder.com/ | LienVandeKelder.exe | "Added by the MYTOB-EO WORM!"
|
| X | httpd | c_pan.exe | Added by a variant of the DELF-A TROJAN!
|
| X | httpd | deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | msgaol.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | browse.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | httpd | deamon.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | https-ssl | https.exe | "Added by the MOEGA.D WORM!"
|
| U | HughesNet Tools | matcli.exe | """matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address |
| Y | HWinst | N/A | For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out
|
| X | Hwp | system_wc.exe | "Eziin adware"
|
| U | HWSetup | HWSetup.exe hwSetUP | """Toshiba Hardware Setup is the Toshiba configuration management tool available through Windows."" Allows the user to change BIOS |
| X | hxadsec | [path to trojan] | "Added by the ADCLICK-AP TROJAN!"
|
| U | HydarVisionDesktopManager | desk95.exe | "ATI's HydraVision desktop management software |
| U | HydraVisionDesktopManager | desk98.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionDesktopManager | HydraDM.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is the HYDRAVISION Desktop Manager - which ""customizes the behaviour of windows and dialog boxes |
| U | HydraVisionViewport | viewport.exe | ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
|
| U | HydraVisionViewPort | HydraMD.exe | "Part of HYDRAVISION - ATI's software for managing mutliple displays and virtual desktops. This is HYDRAVISION MultiDesk - which ""creates |
| X | Hyper Files | phfhost.exe | "Added by the AGENT-JQO TROJAN!"
|
| X | Hyper Start | instantmsgrs.exe | "Added by the RBOT-NH WORM!"
|
| X | I am not Ranky. I am eTunnel! | msyervice.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | winsys.exe | Added by an unidentified WORM or TROJAN!
|
| X | I am not Ranky. I am eTunnel! | disney.exe | Added by an unidentified WORM or TROJAN!
|
| X | I just want to say I love Milko and I need a drink | svchost.exe | "Added by the CHIKO WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\Administrator\Local Settings\Application Data"
|
| X | I/O Controllers | svcnet.exe | "Added by the TIBIK-B TROJAN!"
|
| U | IAAnotif | Iaanotif.exe | "Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes |
| X | ibin | [path to trojan] | "Added by the PERDA-C TROJAN!"
|
| Y | IBM Client Security | certtool.exe | "Part of Client Security Software for IBM\Lenovo notebooks. If you have configured the software via the associated wizard this will need to be running if you want to mount password protected areas of the disk (created with SafeGuard PrivateDisk) |
| N | IBM Client Security Software | csecwiz.exe | "Setup wizard for the Client Security Software for IBM\Lenovo notebooks. This entry only runs once |
| U | IBM ThinkPad EasyEject Support Application | EzEjMnAp.Exe | "EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad EasyEject Tray Utility | EZEJTRAY.EXE | "System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once |
| N | IBM ThinkPad Tray Utility | TP98TRAY.EXE | "System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility |
| U | IBM ThinkPad Utility | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models
|
| U | IBM TrackPoint Accessibility Features | tp4ex.exe | "Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as ""Click Sound"" |
| ? | IBM Warranty Notification | ERTS0749.exe | "IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
|
| U | IBMUltraBayHotSwapCPLLoader | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
|
| ? | IBMUltraBayHotSwapSound | IBMBAYSN.EXE | "Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?"
|
| U | IBWin Monitor | IBMonitor.exe | "IBackup for Windows"
|
| X | icccomp | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| X | ICcontrol | iccontrol.exe | "ICcontrol premium rate adult content dialer"
|
| N | ICH Synth | eusexe.exe | "Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices"
|
| X | icifati | yujixit.exe | "Added by the SDBOT.ZZH WORM!"
|
| X | ICManagement | msic32.exe | "Added by the MSIC BACKDOOR!"
|
| N | Icon Animation | HDE.EXE | Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons
|
| N | Icon Hearit 95 | hearit95.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| N | Icon Hearit 98 | hearit98.exe | Audio desktop customization utility from Moon Valley Software. Resource hog
|
| X | Icon lptt01 | icon.exe | "RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| Y | iconcache | icon.bat | "Related to the Vista Customization Pack"
|
| Y | ICONCLNT | iconclnt.exe | "APC PowerChute® Personal Edition tray icon"
|
| X | iConfigLoader | DIIhost.exe | "Added by the GAOBOT.AO WORM!"
|
| X | ICQ | ICQNET.vbs | "Added by the GORMLEZ-A WORM!"
|
| X | ICQ Agent | icq6.exe | "Added by the AGENT-FZJ TROJAN!"
|
| X | ICQ Center | [path to worm] | "Added by the RANDIN WORM!"
|
| X | ICQ Chat Service | icqjdhs.exe | "Added by a variant of the RBOT WORM!"
|
| N | ICQ Lite | ICQLite.exe | "ICQ Lite - compact version of the popular messaging program"
|
| X | icq lite | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | icq lite | winlog.exe | "Added by the IRCBOT-TJ TROJAN!"
|
| X | ICQ Lite Messenger | ICQLITE.EXE | "Added by an unidentified VIRUS |
| X | ICQ Net | winlogon.exe | "Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup!"
|
| X | IcqBeta | webcamupdate.exe | Added by an unidentified TROJAN!
|
| U | ICQMonitor | ICQMonitor.exe | "ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself"
|
| X | ICQMsn | [path to trojan] | "Added by the RANCK-AH TROJAN! The most common example is ""cbfks.exe"" located in %System%"
|
| X | ICQNet | winlogon.exe | "Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | icrosof Avps32 Control | av32.pif | "Added by the RBOT-AVC WORM!"
|
| X | icrosoft Visual | plscx.exe | "Added by the RBOT-AYO WORM!"
|
| X | icrosoft Visual InterDevc | zvslmqb.exe | "Added by the RBOT-AYP WORM!"
|
| X | icrosoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AER WORM!"
|
| X | icrosoftf Avpx Control | avpx.exe | "Added by the RBOT-AYN WORM!"
|
| U | ICSDCLT | "rundll32.exe Icsdclt.dll | ICSClient" |
| X | idecntl | idecntl.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| U | iDesktop | idesktop.exe | "Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse"
|
| X | idlesam | [8 random letters].exe | "Added by the ZHELATIN.EQ WORM!"
|
| U | IDriveE Startup | IDrvieEStartup.exe | "IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts"
|
| X | IDTemplates | IDTemplate.exe | "Added by the BRONTOK-H WORM!"
|
| N | IDW Logging Tool | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
|
| U | IE Doctor | IEDoctor.exe | "IE Doctor Toolbar - ""IE Doctor can help you to Repair IE easily |
| X | IE Java Update | iejava.exe | "Added by the AGENT-HD TROJAN!"
|
| X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | "Topconverting.com/180Search ""IEMenuExtension"" toolbar. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | IE Runtime | wini.exe | "Added by the PICRATE.B WORM!"
|
| X | IE Runtimes | winis.exe | "Added by the RBOT-ADZ TROJAN!"
|
| X | IE-Security | iescan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE-Security | wdscan.exe | "IE-Security rogue spyware remover - not recommended |
| X | IE6 | wkstmg.exe | "Added by a variant of the SDBOT WORM!"
|
| X | IE6 | winsnt.exe | "Added by the RBOT-GOV WORM!"
|
| X | IEACCESS | temp532.exe | "AsdPlug premium rate adult content dialer variant"
|
| X | IEAgent update check | iewatch.exe | "Added by the BOMKA TROJAN!"
|
| X | IECheck | MSDTCs.exe | "Added by the TIRBOT-D WORM!"
|
| U | IECleanAux | Ieboot6.exe | "IEClean by Kevin McAleavy - cookie manager |
| X | IEDriver | TD.exe | "IeDriver adware variant"
|
| X | IEexplorer AUpdate | IEexplore32.exe | "Added by the RBOT-GRE WORM!"
|
| X | IEFeatures | IEFeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | IEFeatures | Internetfeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | IefxTray | IefxTray.exe | "Added by the RILER-H TROJAN!"
|
| X | IESet | IExplorer.dll | "Added by the PWS-BLUEDIT TROJAN!"
|
| X | iesetupi.exe | iesetupi.exe | "Added by a variant of the RBOT WORM!"
|
| X | iestart | iexp1orer.exe | "Added by the NEMOG.C TROJAN!"
|
| N | ietsr | ietsr.exe | "IEClean by Kevin McAleavy - cookie manager |
| X | ieupdate | MCP****.exe [**** = random char] | "Added by the ASOXY TROJAN!"
|
| X | ieupdate | mcpdll32.exe | Adware downloader trojan
|
| X | ieupdate | [random filename] | "Added by the AGENT-C BACKDOOR!"
|
| X | ieupdates | ieupdates.exe | "Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
|
| X | IExploer | svshosts.exe | "Added by the IRCBOT.BT TROJAN!"
|
| X | Iexploit | Iexploit.html | "Added by the INKER.B WORM!"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252