Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 29th Apr, 2013
31819 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

1096 results found for D

Startup Item or Name Status Command or Data Description Tested
drocherXd.exeAdult content diallerNo
SYSTEMXd.exeDetected by Trend Micro as WORM_MYTOB.LPNo
WindowsSystem32Xd.exeDetected by Sophos as Troj/Agent-ZGM and by Malwarebytes Anti-Malware as Trojan.BackdoorNo
D066UUtilityND066UUTY.EXETWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management softwareNo
SysteZXd1.exeAdded by the MSNDIABLO.A WORM!No
JufualtXd11host.exeAdded by the SDBOT.ARA WORM!No
systemrXd11host.exeAdded by the VB-GX TROJAN!No
dnamXd140113.a.Stub.EXEAdded by the STUB_A TROJAN!No
D3**.exe [* = random char]XD3**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
D3**32.exe [* = random char]XD3**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
d3790de650d70ac1da4aa0af1beaec99Xd3790de650d70ac1da4aa0af1beaec99.exeDetected by Dr.Web as Trojan.DownLoader8.31938 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d3b723be6cda7831128c70a6114bebc5Xd3b723be6cda7831128c70a6114bebc5.exeDetected by Dr.Web as Trojan.DownLoader7.13092 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Microsoft® Windows® Operating SystemXD3D10Ref.exeDetected by Sophos as Mal/Agent-AIP and by Malwarebytes Anti-Malware as Backdoor.MessaNo
D3DOverriderUD3DOverrider.exeUtility that comes bundled with the RivaTuner graphics tweaking utility which allows you to override the control panel settings and force Triple Buffering to be enabled for Direct3D games. This can improve graphics performance, especially when you have VSync enabled - see hereNo
D3DOverriderUD3DOverriderWrapper.exeUtility that comes bundled with the RivaTuner graphics tweaking utility which allows you to override the control panel settings and force Triple Buffering to be enabled for Direct3D games. This can improve graphics performance, especially when you have VSync enabled - see here. This is the Windows 7/Vista version which loads the main application (D3DOverrider.exe)No
behpyoupXd3drml.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %Temp%No
D4UD4.exeDimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts downNo
Dimension4UD4.exeDimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts downNo
d42f0fa15f4769f5694d7c89fe18e16eXd42f0fa15f4769f5694d7c89fe18e16e.exeDetected by Dr.Web as Trojan.DownLoader7.2094 and by Malwarebytes Anti-Malware as Spyware.Password. Note - the file is located in %UserStartup% and its presence here ensures it runs when Windows startsNo
d4d09436d35da01cf69e37f8597d3266Xd4d09436d35da01cf69e37f8597d3266.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d4f8ba9eae9d84a2873c361974f1f3aaXd4f8ba9eae9d84a2873c361974f1f3aa.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
WinMineXD4NG3.vbsAdded by the BISCUIT.A WORM!No
toastpopXd57BJSail5.exeDetected by Dr.Web as Trojan.KillProc.19830 and by Malwarebytes Anti-Malware as Adware.KorAd.GenNo
toastpop003Xd57BJSail555.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd.Gen. The file is located in %Windir%No
d5a38e9b5f206c41f8851bf04a251d26Xd5a38e9b5f206c41f8851bf04a251d26.exeDetected by Dr.Web as Trojan.DownLoader7.13869 and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d5a38e9b5f206c41f8851bf04a251d26Xd5a38e9b5f206c41f8851bf04a251d26.exeDetected by Dr.Web as Trojan.DownLoader7.21837 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d5e680da0c3a0008bbfd086e30868721Xd5e680da0c3a0008bbfd086e30868721.exeDetected by Dr.Web as Trojan.DownLoader8.19454 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d709f34a2bc48c2ecfacf26803c2c376Xd709f34a2bc48c2ecfacf26803c2c376.exeDetected by Dr.Web as Trojan.DownLoader7.19599 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d7271e2abb6db7647dd37dd76bdecd00Xd7271e2abb6db7647dd37dd76bdecd00.exeDetected by McAfee as Trojan-FAUE!79C0889AC0CB and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
GHWAUC6NNZXD7AB19ECEDE2D[private subnet]FD66CBEF20E0A0911F.exeDetected by McAfee as Downloader-CEW.ap and by Malwarebytes Anti-Malware as Trojan.FakeAlert.SANo
d9347bb67c3915d4b4f4b318a915057bXd9347bb67c3915d4b4f4b318a915057b.exeDetected by Dr.Web as Trojan.Siggen4.33560 and by Malwarebytes Anti-Malware as Worm.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d93cea3f9c93f407bf84abee820b565cXd93cea3f9c93f407bf84abee820b565c.exeDetected by McAfee as RDN/Generic PWS.y!lt and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d9bae609eb51f8ca1766366d36a7ee5dXd9bae609eb51f8ca1766366d36a7ee5d.exeDetected by McAfee as RDN/Generic PUP.x!qk and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
d9fw5i91pXd9fw5i91p.exeDetected by Sophos as Troj/Agent-GIWNo
[random name]Xd?dplay.exePurityScan adwareNo
[random name]Xd?xplore.exePurityScan adwareNo
Windows UpdateXDA2900B2669.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %AppData%No
dab1c01d088e43d83122e84a5262c4d7Xdab1c01d088e43d83122e84a5262c4d7.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
DabayoXDabayoLaunch.exeDetected by Malwarebytes Anti-Malware as Adware.K.Dabayo. The file is located in %ProgramFiles%\DabayoNo
DACONFIGEXENdaconfig.exe3Com NIC Diagnostics. Available via Start → ProgramsNo
DadAppYdadapp.exe"DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from DellNo
Corel Desktop Application DirectorNdadx.exeThe Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start → ProgramsNo
dae.exeXdae.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
dae31c02cb06222e776b9ccb9207edb1Xdae31c02cb06222e776b9ccb9207edb1.exeDetected by McAfee as RDN/Generic.bfr!e and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
daemonNDaemon.exeOlder version of Daemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required on later revisions if you use the automount feature to reload images on a reboot. This version is free for personal use and has a limited feature setYes
DAEMON ToolsNdaemon.exeOlder version of Daemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. This version is free for personal use and has a limited feature setYes
DAEMON Tools LiteNdaemon.exeOlder version of Daemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required on later revisions if you use the automount feature to reload images on a reboot. This version is free for personal use and has a limited feature setYes
DAEMON Tools-1033Ndaemon.exeOlder version of Daemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. This version is free for personal use and has a limited feature setYes
TrackpointSrvUdaemon.exeSupports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to workNo
DaemonXdaemon.exe c daemon2.exeAdded by the SELOTIMA.A WORM!No
DaemonNDAEMON32.EXEPre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start → ProgramsNo
Daemon Tools ATAPI driverXdaemontools.exeAdded by the AGENT-OTX TROJAN!No
DaemonUINDaemonUI.exeDaemonUI - graphical user interface for older versions of the DAEMON Tools CD/DVD emulation utilityNo
DafuXDafu.exeDetected by IKarus as Backdoor.Win32.FlyAgent and by Malwarebytes Anti-Malware as Trojan.Agent.WDR. The file is located in %Windir%No
Administrator di DagoXDago.exeAdded by the PUNYA-B WORM!No
CueX44XDago.exeAdded by the PUNYA-B WORM!No
Micro UpdateXdailin.exeAdded by the RBOT-ER WORM!No
dailyconXdailycon.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\dailycon - see hereNo
userinitXdaipnwf.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Trojan.AgentNo
ZaCkerXDaLaL.vbsDetected by McAfee as W32/Vote.b@MMNo
Download Accelerator Manager Free EditionNdam.exeDownload Accelerator Manager Free Edition from Tensons CorpNo
Dell|AlertNDAMon.exe"Dell Alert" utility, that's supposed to make interaction with Support easierNo
damqysmufaduXdamqysmufadu.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
DanBtR270414XDanBtR270414.exeAdded by the VB-NIB WORM!No
DANEFXICYXZUXdanefxicyxzu.exeDetected by McAfee as Downloader.a!dbf and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
65655dee73cec9bf37410b3a70792d7fXdany.exeDetected by Dr.Web as Trojan.DownLoader8.37150 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
DapNDAP.exeDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start → Programs. Note that the free version is adware basedNo
Download Accelerator Plus 5.0NDAP.exeDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start → Programs. Note that the free version is adware basedNo
DownloadAcceleratorNDAP.EXEDownload Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start → Programs. Note that the free version is adware basedNo
DRan posessorXDAP.exeAdded by a variant of W32/Sdbot.wormNo
load=Xdapdll.exeAdded by the ATAK.E WORM!No
DarkGoldXDarkGold.exeDetected by Sophos as Troj/Bckdr-RNA and by Malwarebytes Anti-Malware as Backdoor.BotNo
DSADFDFXdarki.exeDetected by McAfee as RDN/Generic.grp!d and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
daskgfkkcx15Xdasdsaads15.exeAdded by the ONLINEG-Q TROJAN!No
AllSearch_mainXDaSearchU.exeDaSearch rogue security software - not recommended. One of the OneScan family of rogue scanner programs. Detected by Malwarebytes Anti-Malware as Adware.K.AllSearchNo
Codename DashboardUdashboard.exeCodename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time." No longer availableNo
DashBarState?dashIE??No
asdsaxcxz13Xdasxcsx13.exeAdded by the LEGMIR-ARF TROJAN!No
[40 hex characters]Xdata.pifDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile% - see examples here and hereNo
data.pifXdata.pifDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Backdoor.AgentNo
DataCardMonitorUDataCardMonitor.exeMobile (USB) internet management tool by Huawei Technologies Co., Ltd as used by a number of providers including T-Mobile, Virgin Media, tele.ring and blueconnectNo
DataHealerXDataHealer.exeDataHealer rogue security software - not recommended, removal instructions hereNo
DataKeeperUDataKeeper.exePowerQuest DataKeeper (now owned by Symantec) backup softwareNo
Data Layer 2Xdatalayer.exeAdded by the RBOT-BNF WORM! Note - do not confuse with the legitimate Nokia file sharing the same filename - this one is located in %System%No
DataLayerYDataLayer.exePart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Required by the Nokia status/connection monitor (NclTray.exe)Yes
Nokia PC SuiteYDataLayer.exePart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Required by the Nokia status/connection monitor (NclTray.exe)Yes
DataLayerYDATALA~1.EXEPart of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Required by the Nokia status/connection monitor (NclTray.exe)No
DataMngr?DataMngrUI.exeToolbar associated with the iMesh and BearShare peer-to-peer (P2P) file-sharing clientsNo
DataMngr?DATAMN~1.EXEToolbar associated with the iMesh and BearShare peer-to-peer (P2P) file-sharing clientsNo
Optus Cable Data MonitorUdatamonitor.exeAllows Optus customers to monitor their actual data usage against Optus' "data allowance limits"No
msader15ADOR15Xdatamsadomd2.70.7713.0.exeAdded by the TRITE-A WORM!No
DataProtectXDataProtect.exeDataProtect rogue security software - not recommended, removal instructions hereNo
Dell DataSafe OnlineUDataSafeOnline.exe"Dell DataSafe Online helps protect your music, photos and other important files by placing backup copies on a secure storage site using your internet connection. For your security all data is encrypted and compressed before ever leaving your computer." Required for the automatic backups to runNo
Dell DataSafe SchedulerUDataSafeOnlineScheduler.exeScheduler for Dell DataSafe™ Online which "helps protect your music, photos and other important files by placing backup copies on a secure storage site using your internet connection"No
datasaveXdatasaverun.exeDataSave rogue security software - not recommended, removal instructions hereNo
DatcheckXdatcheck.exeDetected by Symantec as KeyPanic.TrojanNo
DateMakerIntlXDateMakerIntl.exePremium rate adult content diallerNo
Date ManagerXdatemanager.exeDateManager - calendar/reminder utility. Contains GAIN adware by Claria CorporationNo
DateMngrXDATEMNGR.EXEAdded by the SPYBOT-BR BACKDOOR!No
Data ProtectionXdatprot.exeData Protection rogue security software - not recommended, removal instructions hereNo
Desktop ArchitectNDATRAY.EXEDesktop theme manager available here - for managing the desktop appearance, fonts, sounds, etcNo
Google_UpdateXDaumCleans.exeDetected by Dr.Web as Trojan.DownLoader6.49071 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
DAupdateXDAupdate.exeNavEnhance adwareNo
Perfomance MonitorXdavcsync.exeAdded by the LAMUD-A WORM!No
DAW9532.exe?DAW9532.EXELoaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required?No
Daily PlannerNdayplan.exeDaily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete themNo
DayTodayUDAYTODAY.EXEDayToday from RoboMagic Software Corp. Displays the date on the taskbarNo
WIZZXdazzler.exeDetected by Kaspersky as the DIALER.IS TROJAN!No
ASDPLUGINXdbaccess.exeAsdPlug premium rate adult content dialerNo
Win Validation ApplicationXDBExecCom.exeAdded by the VBSILLY-A WORM!No
DebuggerXdbg32.exeAdded by the MYTOB-FW WORM!No
Microsoft Debug ServiceXdbgbgr.exeAdded by a variant of Win32/RbotNo
DbgHlp32XDbgHlp32.exeAdded by the WINKO.AO WORM!No
dbhlp32Xdbhlp32.exeAdded by the GAMEOL.AQ TROJAN!No
DBISQL9Udbisqlg.exeRelated to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologiesNo
 xmens32Xdbm322.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. Note the space at the beginning of the "Startup Item" field and the file is located in %System%No
Microsoft System CheckupXdbnetlib.exeAdded by the DONK.L WORM!No
dbservNdbserv.exeDatabase Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabledNo
Gravis AppawareloaderUdbserver.exeLooks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support themNo
DbxaxdXDbxaxd.exeAdded by the VBKRYPT.GNJU TROJAN!No
BDXdc.exeAdded by the RASDOOR-A TROJAN!No
dcXdc.exeDetected by Sophos as W32/VB-DZENo
Dialer ControlUdc.exeDialer-Control. Detects and protects from premium rate adult content diallersNo
WINSERV SERVICEXdc.exeAdded by the HAMWEQ.DQ WORM!No
DC6cwXDC6cw.exePart of the DriveCleaner rogue security software - not recommended, removal instructions hereNo
DC6Xdc6_startupmon.exePart of the WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions hereNo
DC6_checkXdc6_startupmon.exePart of the WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions hereNo
DcapXDCap.exeDetected by Dr.Web as Trojan.DownLoader6.46786 and by Malwarebytes Anti-Malware as Trojan.BankerNo
_Xdcbcg.exeDetected by Sophos as Troj/Agent-HMTNo
dccXdcc_.exeAdded by the AGENT-GBJ TROJAN!No
[various names]XDCC_send.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DAZEL Delivery AgentUDcDaemon.exeControl and send documents, etc, to any destination. The Dazel Corporation has now been taken over by HPNo
DCE ManagerXdcemgr.exeAdded by the TUMAG TROJAN!No
DCfssvcUdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an exampleNo
dcfssveUdcfssvc.exeAssociated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an exampleNo
Phase One Media ReaderUDCIMImp.exePhase One Media Reader Capture imagesNo
Deus CleanerXDCleaner.exeDeus Cleaner rogue system cleaner utility - not recommendedNo
hunpenigXdclocmwk.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %LocalAppData%No
BMNXdcmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
dc6_checkXdcmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
SalestartXdcmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
audlmne32Xdcmsxe.exeAdded by the MAILBOT-CF TROJAN!No
WINDOWS SYSTEMXdcomuser.exeAdded by the MYTOB.EO WORM!No
SystemXdcomx.exeAdded by the CIREBOT BACKDOOR!No
SalestartXdcpasmon.exeSystemDoctor rogue security software - not recommended, removal instructions hereNo
dlcipsclXdcpavss.exeAdded by the MAILBOT-CB TROJAN!No
dcsmXdcsm.exePart of the PrivacyProtector and DriveCleaner rogue security toolsNo
SalestartXdcsm.exePart of the PrivacyProtector and DriveCleaner rogue security toolsNo
Windows Automatical UpdaterXdcz.exeAdded by the RBOT.CXS WORM!No
D SYSTEMXdd.exeAdded by the MYTOB-FN WORM!No
Dialer DetectUdd.exeDialerDetect detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing itNo
DoubleDesktopUdd.exe"DoubleDesktop is a smart and elegant system tray utility that effectively doubles the width of your Windows desktop"No
DDCActiveMenuNDDCActiveMenu.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
DDCMNDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
DDCManNDDCMan.exeDigital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
WinDirectoriesXddcs.exeAdded by the VB-ETN WORM!No
WindowServerXdddasasa.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.WS. The file is located in %AppData%\windowNo
Windows ServiceXdddd.exeDetected by Kaspersky as Dialer.Salc, also known to come with the Bube family of trojansNo
ddeprocXddeproc.exeWebcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see hereNo
Winsvr managerXDDEsvr.exeAdded by the TIRBOT-C WORM!No
DirectXXddhelp32.exeAdded by an unidentified VIRUS, WORM or TROJAN! Note - not the DirectX helper which is ddhelp.exeNo
DDiallerXDDialler.exeAdult content diallerNo
DDLAgentUDDLAgent.exeLoads DVD Device Lock - which "can be used to restrict read or write access to removable media devices such as CD, DVD, floppy, flash and USB drives. You can also restrict access to partitions of hard disk drives". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UIYes
DVD Device Lock for Win95/98/Me/2k/XPUDDLAgent.exeLoads DVD Device Lock - which "can be used to restrict read or write access to removable media devices such as CD, DVD, floppy, flash and USB drives. You can also restrict access to partitions of hard disk drives". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UIYes
MSConfigXddmlxjwy.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
DDmService?DDmService.exePart of the Web Player which is included with the DivX Plus video software package from DivX, LLC. The exact purpose of this entry and whether it's needed is unknown at present but it appears to be associated with clearing the cache - see hereYes
DivX Download Manager?DDmService.exePart of the Web Player which is included with the DivX Plus video software package from DivX, LLC. The exact purpose of this entry and whether it's needed is unknown at present but it appears to be associated with clearing the cache - see hereYes
DivX Download Manager Service?DDmService.exePart of the Web Player which is included with the DivX Plus video software package from DivX, LLC. The exact purpose of this entry and whether it's needed is unknown at present but it appears to be associated with clearing the cache - see hereYes
Microsoft® Windows® Operating SystemXDDORES.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %Templates%No
Adobes UpdatesXddosw.exeAdded by the BACKDR-DC BACKDOOR!No
CCD ManagerUDDS.EXEProject Labs Century CD manager for their CD/DVD storage deviceNo
PlaySysXddsplay.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
MSRegScanUDDSSDemo.exeSystemSleuth surveillance software. Uninstall this software unless you put it there yourselfNo
DynDNS-Updater TraytoolNddutray.exeDynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manuallyNo
DDWMonUddwmon.exeDirect Disc Writer Event Monitor from TOSHIBANo
De32genXde32gen.exeAdded by the GEMA TROJAN!No
DE58DC232B2EB5B6FC69BBB9A7C86D4CBC512941XDE58DC232B2EB5B6FC69BBB9A7C86D4CBC512941Detected by McAfee as RDN/Generic.bfr!dNo
HKCUXDeadAuth.exeDetected by Kaspersky as Trojan.Win32.VB.ahsj and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXDeadAuth.exeDetected by Kaspersky as Trojan.Win32.VB.ahsj and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
PoliciesXDeadAuth.exeDetected by Kaspersky as Trojan.Win32.VB.ahsj and by Malwarebytes Anti-Malware as Backdoor.Agent.PGenNo
DeadKittyXDeadKitty.exeAdded by the DEADCAT-A WORM!No
deafb983a004e9d6c19560e2100b5de3Xdeafb983a004e9d6c19560e2100b5de3.exeDetected by Dr.Web as Trojan.DownLoader7.12571 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
auUDealioAu.exeDealio Toolbar is a free shopping comparison toolbar that allows users to search for a wide range of consumer productsNo
browserXdeamon.exeAdded by the TACTSLAY.C TROJAN!No
cplXdeamon.exeAdded by the TACTSLAY.C TROJAN!No
httpdXdeamon.exeAdded by the TACTSLAY.C TROJAN!No
MessangerXdeamon.exeAdded by the TACTSLAY.C TROJAN!No
StartMenuXdeamon.exeAdded by the TACTSLAY.C TROJAN!No
Virtual CDROMXdeamon.exeAdded by the RBOT.VP WORM!No
deasycponyfeXdeasycponyfe.exeDetected by McAfee as PWS-Zbot-FAGQ!4B5426148A84 and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
Death.exeXDeath.exeAdded by the DELF-ERW TROJAN!No
DebugerXDebuger.exeDetected by Dr.Web as Trojan.AVKill.28870 and by Malwarebytes Anti-Malware as Trojan.AgentNo
DebugMonitorXdebugmonitor.exeAdded by the MYDOOM.BG WORM!No
DebugXDebugW32.exeAdded by the GUBED TROJAN!No
run=Xdec25.exeAdded by the ATAK.F WORM!No
CiodiagXDECCONF.EXEDetected by Trend Micro as TROJ_STRAT.ELNo
wininfXdecoder.exeDetected by Dr.Web as Trojan.DownLoader5.29928No
what everXdecom.exeAdded by the RBOT-SC WORM!No
DeeEnEsUDeeEnEs.exeDeeEnEs - automatically updates a dynamic IP address when it changesNo
LthoXdees.exePurityScan adwareNo
NAV DefAlertUDefAlert.exeNorton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basisNo
(Default)XDefault.exeAdded by the AUTORUN.BUK WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\RunOnce & HKCU\RunOnce in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
DefaultConfigurationXdefaultconfh.exeAdded by the AGOBOT-JC WORM!No
Defense CenterXdefcnt.exeDefense Center rogue security software - not recommended, removal instructions hereNo
[various names]Xdefect08.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DefenceprivacyXDefencePrivacy.exeDefence Privacy rogue security software - not recommended, removal instructions hereNo
defencevaccinestart.exeXdefencevaccinestart.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Rogue.K.DefenceVaccineNo
defencevaccine mainXdefencevaccineu.exeDetected by McAfee as Generic.tfr and by Malwarebytes Anti-Malware as Rogue.K.DefenceVaccineNo
DefencerGBAXdefend.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserProfile%\[numbers]No
DefendAPcXDefendAPc.exeDefendAPc rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
Security ProtectionXdefender.exeSecurity Protection rogue security software - not recommended, removal instructions hereNo
SpySpotter System DefenderXDefender.exeSpySpotter rogue spyware remover - not recommended, see hereNo
Spyware ProtectionXdefender.exeSpyware Protection rogue security software - not recommended, removal instructions hereNo
tmpXdefender.exeFake Microsoft Security Essentials Alert - removal instructions hereNo
DefenseVirusMainXDefenseVirus.exeDefenseVirus rogue security software - not recommended, removal instructions hereNo
defergui?defergui.exeRelated to IBM Standard Software Installer. What does it do and is it required?No
Default ManagerUDefMgr.exePart of MSN Toolbar from version 4.* onwards (renamed "Bing Bar" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use BingYes
DefMgrUDefMgr.exePart of MSN Toolbar from version 4.* onwards (renamed "Bing Bar" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use BingYes
Microsoft Default ManagerUDefMgr.exePart of MSN Toolbar from version 4.* onwards (renamed "Bing Bar" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use BingYes
DEFINI_INVENTXdefnv.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\definitivaNo
Automatic Defrag ManagerXdefrag.exeAdded by the RBOT-AKE WORM!No
Win DefragsXdefrag.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Windows DLL LoaderXdefragfat32.exeAdded by the SDBOT-SS WORM!No
Windows DLL LoaderXdefragfat32abc.exeAdded by the RBOT-RG WORM!No
Windows DLL LoaderXdefragfat32pi.exeAdded by the RBOT-QQ WORM!No
Windows DLL LoaderXdefragfat32z.exeAdded by the LINKBOT.A WORM!No
Windows DLL LoaderXdefragfat39.exeAdded by the POEBOT-C WORM!No
Windows DLL LoaderXdefragfatx.exeAdded by the POEBOT-F WORM!No
Windows DLL LoaderXdefragfatz.exeAdded by the LINKBOT.H WORM!No
defragm_checkXdefragment.exeCoolWebSearch parasite variantNo
DefragTaskBarUdefragTaskBar.exeSystem Tray access to Ashampoo® Magical Defrag 2/3 - which "defragments your hard drive only when computer is idle, hence enabling you to follow your everyday work routine without any distraction"Yes
defragTaskBar.exeUdefragTaskBar.exeSystem Tray access to Ashampoo® Magical Defrag 2/3 - which "defragments your hard drive only when computer is idle, hence enabling you to follow your everyday work routine without any distraction"Yes
WebScanUDEFSCANGUI.EXEWeb scanner function of eAcceleration Stop-Sign security software - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendationNo
WebScanUDEFSCA~1.EXEWeb scanner function of eAcceleration Stop-Sign security software - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendationNo
defwatchUdefwatch.exeDetects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basisNo
SpywareGuardXdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard applicationNo
Windows Internet ProtocolXdeinst_qfe001.exeAdded by a variant of the Win32.Small TROJAN!No
Deko550UDeko550.exeAssociated with the Deko550 entry-level SD real-time graphics system from Avid TechnologyNo
Windows Service Pack Auto UpdateXdel-me.exeAdware, also detected as the LOWZONES.BH TROJAN!No
HKCUXDelaws.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\usecureNo
HKLMXDelaws.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\usecureNo
PoliciesXDelaws.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.XTR. The file is located in %AppData%\usecureNo
ioloDelayModuleUdelay.exePart of Iolo System Mechanic. Used to delay the start of an application which loads automatically as Windows loadsNo
hpWirelessAssistantUDelayedAppStarter.exe HPWA_Main.exeWireless management utility for HP computers that allows the user to enable individual wireless devices (such as Bluetooth or WLAN devices) and shows the state of the radios for those devicesNo
DelayUdelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computersNo
DelayrunUdelayrun.exeOn HP PCs this program is used to help prevent conflicts or timing issues on fast computersNo
GhostSurfDelSatelliteYDeleteSatellite.exePart of SpyCatcher spyware remover from Tenebril. Prevents rogue programs from sending personal information to a remote user via the Internet. If you use SpyCatcher with real time scanning, you'll want to leave this file in placeNo
Execute?delfolders.exe??No
Delivery Center?DeliveryCenter.exe??No
Diamond Delivery Center?DeliveryCenter.exe??No
DellControlPointUDell.ControlPoint.exeDell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution". Includes Power Manager, Security Manager and Connection Manager functionsNo
DellConnectionManagerUDell.UCM.exePart of the Dell ControlPoint Connection Manager which "provides a complete communications management environment for everything from Ethernet to dial-up to GPS". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution"No
DellDMI?delldmi.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?No
Dell DockUDellDock.exeDell Dock by Stardock Corporation - "created to bring greater organization, personalization and productivity to Dell customers around the globe". Based upon Stardock's own ObjectDeck which is used to "organize your shortcuts, programs and running tasks into an attractive and fun animated dock"No
Dell Dock First RunUDellDock.exeDell Dock by Stardock Corporation - "created to bring greater organization, personalization and productivity to Dell customers around the globe". Based upon Stardock's own ObjectDeck which is used to "organize your shortcuts, programs and running tasks into an attractive and fun animated dock"No
DELLMMKBUDELLMMKB.EXEMultimedia keyboard control for Dell based PCs - only required if you use the multimedia keysNo
DellTouchUDELLMMKB.EXEMultimedia keyboard control for Dell based PCs - only required if you use the multimedia keysNo
DellSCNdellsc.exeDell Solution Center - web-based troubleshooting tools and educational offeringsNo
DELL Webcam ManagerNDellWMgr.exeDell Webcam Manager - Webcam management software provided on Dell PCsNo
delmsbbXdelmsbb.exe180Search adwareNo
delsaapXdelsaap.exeNCase adwareNo
delstart?delstart.exeReportedly part of BT ISP software - what does it do and is it required in startup?No
DeltaIITaskbarAppUDeltaIITray.exeSystem Tray access to the Delta Control Panel for the Delta series of PCI audio cardsNo
M-Audio Taskbar IconUDeltaIITray.exeSystem Tray access to the Delta Control Panel for the Delta series of PCI audio cardsNo
DelTmp?DelTemp.exeAdded to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?No
delcab?deltreew.exe C:\cabs??No
DeltTrayUDeltTray.exeSystem Tray access to the Delta Control Panel for the Delta series of PCI audio cardsNo
M-Audio Delta Taskbar IconUDeltTray.exeSystem Tray access to the Delta Control Panel for the Delta series of PCI audio cardsNo
DELUXECCUDELUXECC.exeTwain driver for the SiPix SC-Deluxe digital cameraNo
DELXP ProtocolXdelxp.exeAdded by a variant of W32/Sdbot.wormNo
demm386.exeXdemm386.exeAdded by the RBOT-EO WORM!No
MicrosoftXdemo.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %AppData%No
demon?demon.exePart of the French Wanadoo ADSL extense pack. What does it do and is it required?No
DencnfXDencnf.exeDetected by Malwarebytes Anti-Malware as Trojan.Ircbot. The file is located in %Windir%No
EspecialXDeneca.batAdded by the DELUZ VIRUS!No
WINDOWS DENEMEXdeneme.exeAdded by the MYTOB-CR WORM!No
[various names]XdePloy.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DeploymentUpdateXDeploymentupdt32.exeDetected by Malwarebytes Anti-Malware as Trojan.SHarpro.Pgen. The file is found in %LocalAppData%\Deployment\DeploymentUpdateNo
deptonXdepton.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.DPT. The file is located in %Windir%No
frunXderc32xz.exeAdded by unidentified malware. The file is located in %Windir%No
90efc1c59b4d9e300470f34b7b9e92e3Xdersa.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.MSIL. The file is located in %UserTemp%No
DesireXdesires.exeAdult content diallerNo
desk-top-service?desk-top-service.exe??No
HydarVisionDesktopManagerUdesk95.exeATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this one. HydraVision can be uninstalled through Add/Remove ProgramsNo
HydraVisionDesktopManagerUdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setupNo
DeskAd ServiceXDeskAdServ.exeDeskAd.Service adwareNo
Desktop AdviserUdeskadv.exeALDESI Desktop Adviser surveillance software. Uninstall this software unless you put it there yourselfNo
DeskColorNDESKCOLOR.EXEProvides transparent icon text backgrounds and coloured icon textNo
DeskflagNDeskflag.exeDeskFlag - animated USA flag on the desktopNo
DeskMateAutoUpdateXDeskMateAutoUpdate.exeDeskMates: Virtual scantily clad girls enhance your desktop. Contains BargainBuddy adwareNo
deskmechNdeskmech.exePart of Desktop Maestro from PC Tools - which "combines the features of our award winning products, Registry Mechanic and Privacy Guardian to ensure that you have the range of tools at your fingertips to ensure optimal system performance, stability and user privacy". This entry is created when Desktop Maestro is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervalsYes
Desktop MaestroNdeskmech.exePart of Desktop Maestro from PC Tools - which "combines the features of our award winning products, Registry Mechanic and Privacy Guardian to ensure that you have the range of tools at your fingertips to ensure optimal system performance, stability and user privacy". This entry is created when Desktop Maestro is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervalsYes
DesktopMaestroNdeskmech.exePart of Desktop Maestro from PC Tools - which "combines the features of our award winning products, Registry Mechanic and Privacy Guardian to ensure that you have the range of tools at your fingertips to ensure optimal system performance, stability and user privacy". This entry is created when Desktop Maestro is installed on XP and loads the System Tray icon and runs a registry scan at startup - if either are enabled. Run manually at regular intervalsYes
DeskSaverUDeskSaver.exeDeskSaver from Headway Creative - utility that allows you "to backup and to restore the icons position easily on the Windows desktop". The Pro version also includes a "Taskbar Economizer" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaverYes
desksaverUdesksaver.exePart of Advanced Desktop Shield, Easy Desktop Keeper, 1st Desktop Guard and Desktop Layout Keeper (and maybe others) - which give you the ability to save, restore, manage and lock your desktop layout that includes files and folders located on your desktop, placement of desktop icons, desired wallpaper and screen saver. Located in %ProgramFiles%\[program name]. For more details please see the "00DSKSVR01" or "00DSKSVR00" entriesYes
DeskSaver ProUDeskSaver.exeDeskSaver Pro from Headway Creative - utility that allows you "to backup and to restore the icons position easily on the Windows desktop". Includes a "Taskbar Economizer" which minimizes an open window to the System Tray instead of the taskbar. Located in %ProgramFiles%\Headway Creative\DeskSaverYes
desksaver.exeUdesksaver.exePart of Advanced Desktop Shield, Easy Desktop Keeper, 1st Desktop Guard and Desktop Layout Keeper (and maybe others) - which give you the ability to save, restore, manage and lock your desktop layout that includes files and folders located on your desktop, placement of desktop icons, desired wallpaper and screen saver. Located in %ProgramFiles%\[program name]. For more details please see the "00DSKSVR01" or "00DSKSVR00" entriesYes
00DSKSVR00?desksaver.exe saskdaPart of Advanced Desktop Shield, Easy Desktop Keeper, 1st Desktop Guard and Desktop Layout Keeper (and maybe others) - which give you the ability to save, restore, manage and lock your desktop layout that includes files and folders located on your desktop, placement of desktop icons, desired wallpaper and screen saver. The exact purpose of this startup entry is unknown at presentYes
00DSKSVR01Udesksaver.exe traySystem Tray access to Advanced Desktop Shield, Easy Desktop Keeper, 1st Desktop Guard and Desktop Layout Keeper (and maybe others) - which give you the ability to save, restore, manage and lock your desktop layout that includes files and folders located on your desktop, placement of desktop icons, desired wallpaper and screen saver. Disabling via the program's own options will leave this startup entry but it will not run - "desksaver.exe" does however run as it's also used as a serviceYes
DiscoverDeskshopNDeskshop.exeDiscover Deskshop - single use "virtual" credit cardNo
DeskSlideUDeskSlide.exe"DeskSlide is utility for automating wallpaper changes on your desktop"No
DeskSpaceUdeskspace.exeDeskSpace desktop management utility from Otaku Software Pty Ltd - which "gives you more space for your windows and icons. You can eliminate desktop clutter by arranging your windows and icons across up to six desktops, all easily reachable by navigating a desktop cube"Yes
DeskSpaceUDESKSP~1.EXEDeskSpace desktop management utility from Otaku Software Pty Ltd - which "gives you more space for your windows and icons. You can eliminate desktop clutter by arranging your windows and icons across up to six desktops, all easily reachable by navigating a desktop cube"Yes
Desktop CalendarUDesktop Calendar.exeDesktop Calendar - "Desktop Calendar is a highly customizable calendar program that turns your desktop into a traditional wall calendar, by rotating the background image on a monthly basis"No
Desktop Defender 2010XDesktop Defender 2010.exeDesktop Defender 2010 rogue security software - not recommended, removal instructions hereNo
Desktop iCalendarUDesktop iCalendar Lite.exeDesktop iCalendar Lite by Desksware - "is a free desktop calendar for Windows. It allows you to manage your events, to-do list on desktop. It allows subscribing public Google Calendar, such as holidays, election or NBA. It is full customizable. A build in skin editor makes it easy to set the skin by your own taste"Yes
Desktop iCalendar LiteUDesktop iCalendar Lite.exeDesktop iCalendar Lite by Desksware - "is a free desktop calendar for Windows. It allows you to manage your events, to-do list on desktop. It allows subscribing public Google Calendar, such as holidays, election or NBA. It is full customizable. A build in skin editor makes it easy to set the skin by your own taste"Yes
Desktop iCalendar Lite.exeUDesktop iCalendar Lite.exeDesktop iCalendar Lite by Desksware - "is a free desktop calendar for Windows. It allows you to manage your events, to-do list on desktop. It allows subscribing public Google Calendar, such as holidays, election or NBA. It is full customizable. A build in skin editor makes it easy to set the skin by your own taste"Yes
Desktop iCalendarUDesktop_iCalendar.exeDesktop iCalendar by Desksware - "is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar, share calendars with your family and friends. It also uses high-quality fonts, looks pretty, and has lots of skins"Yes
Desktop iCalendar.exeUDesktop_iCalendar.exeDesktop iCalendar by Desksware - "is a handy desktop calendar for Windows. It stays on your desktop and shows the days of the current month. It can sync with your Google Calendar, share calendars with your family and friends. It also uses high-quality fonts, looks pretty, and has lots of skins"Yes
Desktop Security 2010XDesktop Security 2010.exeDesktop Security 2010 rogue security software - not recommended, removal instructions hereNo
DesktopXDesktop.comAdded by the VB-DRN WORM!No
ba36334ad9883cdf49fcccd0d285d289Xdesktop.exeDetected by McAfee as RDN/Generic PWS.y!l and by Malwarebytes Anti-Malware as Trojan.MSILNo
desktopXdesktop.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. The file is located in %AppData%No
desktopXdesktop.exeDetected by F-Secure as SdBot.MD. The file is located in %System%No
Desktop SearchXdesktop.exeDetected by McAfee as Adware-ISearchNo
desktopXdesktop.ini.vbsIE-Title malwareNo
Desktop ArmorYDesktopArmor.exeDesktop Armor from Headlight Software - "watches dozens and dozens of important settings on your computer and warns you if any program has changed them" including those made by malwareYes
DesktopArmorYDesktopArmor.exeDesktop Armor from Headlight Software - "watches dozens and dozens of important settings on your computer and warns you if any program has changed them" including those made by malwareYes
SkinClockUDesktopClock.exeFree Desktop Clock by Drive Software - replacement for standard Windows tray clock that provides a number of skins and options such a load at start-up, transparent background, seconds display and 12-hour formatNo
DesktopIconToyUDesktopIconToy.exe"Desktop Icon Toy is an easy to use desktop icon enhancement tool, which allows you to make many funny but useful patterns out of your windows desktop icons"No
Lto ManagerYDesktopLtoManager.exeRelated to Global Positioning System (GPS) found on HP iPAQ hw6500 unit and othersNo
Desktop ManagerNDesktopMgr.exeSynchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry"No
Copernic Desktop SearchNDesktopSearch.exeCopernic Desktop Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures"No
Copernic Desktop Search 2UDesktopSearchService.exeCopernic Desktop Search - search agentNo
Motorola Desktop SuiteUDesktopSuite.exeRelated to Motorola Desktop Suite - PC software managing Motorola mobiles such as the A1000No
DW4NDesktopWeather.exeDesktop Weather 4 by The Weather Channel - provides current temperature, conditions, alerts, etcNo
DW6NDesktopWeather.exeDesktop Weather 6 by The Weather Channel - provides current temperature, conditions, alerts, etcNo
DesktopXNDesktopX.exeSystem Tray access to DesktopX from Stardock Corporation - "is a desktop utility designed to enable users to build their own desktops, widgets, and gadgets." Note - if this entry is disabled and DesktopX has been configured to load any desktops, objects or widgets they will still load, along with DesktopX. Also part of the Object Desktop suiteYes
DesktopX.exeNDesktopX.exeSystem Tray access to DesktopX from Stardock Corporation - "is a desktop utility designed to enable users to build their own desktops, widgets, and gadgets." Note - if this entry is disabled and DesktopX has been configured to load any desktops, objects or widgets they will still load, along with DesktopX. Also part of the Object Desktop suiteYes
deskupNdeskup.exeAdds Iomega Zip drive icons to the desktopNo
DeskVaccineXDeskVaccine.exeDeskVaccine rogue security software - not recommended, removal instructions hereNo
desp2kUdesp2k.exePart of the Turbo Analyzer tool from LightComm Brazil Telecom that analyzes and corrects ADSL configurationsNo
[various names]XDest068.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
KernelConfigXdestiny32.exeDetected by Trend Micro as WORM_AGOBOT.AMBNo
destroy11Xdestroy11.exeAdded by the DELF-KO TROJAN!No
destroyb11Xdestroyb11.exeAdded by the DELF-KO TROJAN!No
DesuraNdesura.exe"Desura is a community driven digital distribution service for gamers, putting the best games, mods and downloadable content from developers at gamers fingertips, ready to buy and play"No
DetectorNdetector.exeUSB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing softwareNo
DetectorAppUDetectorApp.exeRelated to Roxio MyDVD (was Sonic) DVD authoring softwareNo
Disk Essensial ToolsXdetsvc.exeAdded by the SLENFBOT.JL WORM!No
Microsoft Windows WorkstationXdevcode.exeAdded by the RBOT-AWL WORM!No
Dev Gnu CppXdevcpp.exeAdded by the RBOT-RU WORM!No
Device DetectorUDevDetect.exeACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automaticallyNo
Camera DetectorUDEVDET~*.EXEACDSee Auto Device Detector detects when a device is connected to your PC and gives you the option to acquire images from it automaticallyNo
Device Detector 2NDevDtct2.exeInstalled by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resourcesNo
Device Detector 3NDevDtct2.exeInstalled by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resourcesNo
Development EnvironmentXdevenv.exeAdded by the DELBOT-AH WORM!No
Mircosoft Windows Developer EnviromentXdevenv.exeAdded by an unidentified WORM or TROJAN!No
Mircosoft Windows Developer EnviromentXdevenv.exeAdded by the RBOT.AUJ BACKDOOR!No
Driver Control Manager v4.6Xdevetnae.exeAdded by the IRCBOT-AGY WORM!No
Digital DashboardNdevgulp.exeFor Compaq PC's. Loads Digital Dashboard optionsNo
SystemDevicXdevic.exeAdded by the MIMBOT.A WORM!No
Device HardwareXdevicehnd.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Device IO SystemXdeviceio.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Device ManagerXDeviceManager.exeDetected by McAfee as RDN/Ransom and by Malwarebytes Anti-Malware as Trojan.AgentNo
PhilipsDMNDeviceManager.exeDevice manager for Philips portable media players such as the GoGearNo
USBDEVICEMANAGERXDeviceManager.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPTNo
win32servXdevicer.exeAdded by the CHECKOUT WORM!No
DriverMaxUdevices.exePart of the DriverMax driver update tool from Innovative SolutionsNo
DriverMax_RESTARTUdevices.exePart of the DriverMax driver update tool from Innovative SolutionsNo
System DeviceXdevices.exeAdded by the AGENT.AFIF WORM!No
CmpntXDevices2.exeAdded by the TOMPAI-D TROJAN!No
Device Security DriverXdevicesec.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Configuration Loader ServiceXdevl32.exeAdded by the SDBOT-XY WORM!No
devldr16Udevldr16.exeAssociated with some Creative Labs sound cards in Win98/Me. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous DevicesNo
devldr16.exeUdevldr16.exeAssociated with some Creative Labs sound cards in Win98/Me. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start → Settings → Control Panel → System → Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous DevicesNo
Microsoft Synchronization ManagerXdevldr32.exeAdded by a variant of Win32/Rbot. Note - do not confuse with the legitimate Creative Labs devldr32.exe fileNo
Devlog?devlog.exeApparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it requiredNo
devmgmtXdevmgmt.exeDetected by Kaspersky as Trojan.Win32.VB.aqvlNo
Microsoft UpdateXdevmks32.exeAdded by a variant of Win32/RbotNo
Device Microsoft SystemXdevsrv.exeDetected by Trend Micro as WORM_RBOT.AHLNo
xdxqaXdewa.exeAdded by the SDBOT-YB WORM!No
autorepairXdexs.exeAdded by a variant of W32/Sdbot.wormNo
Configuration LoaderXdezi.exeAdded by the SDBOT-OB WORM!No
SNMP Detection Secondary ModulesXdffcmgag.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.LBR. The file is located in %System%No
dfgdfgdg.exeXdfgdfgdg.exeDetected by McAfee as Ransom!hm and by Malwarebytes Anti-Malware as Trojan.IRCbotNo
sAGwzfF8s2kTPQ2Av3TFYIjT7EBTtEXdfgdfgdg.exeDetected by McAfee as Ransom!hm and by Malwarebytes Anti-Malware as Trojan.IRCbotNo
Symantec Antivirus professionalXdfrgfrat.exeAdded by a variant of the FORBOT WORM!No
Distributed File SystemXDfsvc.exeAdded by the MYFIP.A or MYFIP.K WORMS!No
Hermes MessengerUDGDRHE~1.EXEA LAN messenger alternative to WinPopUp - Digital Dreams SoftwareNo
DGJM?DGJM.exe??No
Microsoft Security PansasagersXdgkztsqgn.exeAdded by the RBOT-BBJ WORM!No
dgtstartXdgtstart.exeDetected by Kaspersky as AdWare.Win32.DigitalNames.gNo
dguardUdguard.exeDownload guard function of eAcceleration Stop-Sign security software - previously not recommended (see here). It has now been delisted, so make sure you have the latest version - hence the "U" recommendationNo
DealHelperBrwsrXdhbrwsr.exeDetected by Symantec as Adware.DealHelperNo
FatPipeUDHCPSoftware enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 usersNo
LANXdhcp.exeAdded by the RBOT-GYI WORM!No
Microsoft STS ServiceXDHCP32.exeAdded by the SDBOT-UK WORM!No
dhcpagntYdhcpagnt.exeIntel DSL modem driver - leave enabled or you'll have to re-install the driversNo
Windows APCI VerifierXdhcpserv.exeAdded by the RBOT-FON WORM! Note - Disables the automatic startup of other software and deactivates the Microsoft Internet Connection Firewall (ICF)No
DeleteHistoryFreeUdhf.exeDelete History Free - "Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC"No
DHNUXB?DHNUXB.exe??No
DealHelperUpdateXDHUpdt.exeDetected by Symantec as Adware.DealHelperNo
DHxaBSbLeDyP.exeXDHxaBSbLeDyP.exeDetected by Sophos as Troj/Agent-QGYNo
File1XDia Claro.htmAdded by the DLOADER-OR TROJAN!No
SWAPXDiablo3 swapping.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
(Default)Xdiagcfg.exeAdded by the GWGIRL BACKDOOR! Note - this malware actually changes the value data of the "(Default)" key in HKLM\RunServices in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
DiagnosticConfigurationXdiagcfg.exeAdded by the GWGIRL BACKDOOR!No
diagentNdiagent.exeSystem Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start → ProgramsNo
Diagnostic AgentXdiagent.exeAdded by the AGOBOT-CW WORM!No
Microsoft® Windows® Operating SystemXdiager.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %Templates%No
DiagnosticXdiagnostic.exeDetected by Sophos as Troj/Alpha-CNo
InstallerXdial.exeMalware - detected by Kaspersky as the AGENT.MM TROJAN!No
User23.exeXDIAL.exeThis is a trojan trying to disguise itself as User32.dllNo
BTopenworldUDialBTYahoo.exeBT Yahoo! internet connection managerNo
REGRUNXdialer.exeAdware downloader - detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!No
[various names]Xdialer423.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
antidialer.co.ukUDialer_Watcher.exeDialer_Watcher is an application that allows you to detect dialers on your computerNo
ItunesXdials.exeDetected by Kaspersky as the AGENT.MM TROJAN!No
Windows Dialup ServiceXdialup.exeDetected by Trend Micro as WORM_AGOBOT.AAHNo
Diamondview?Diamondview.exeManulife Financial Insurance program. Is it required at startup?No
LivreXDibane.batAdded by the BANEDI VIRUS!No
High Definition DickSprinkles ServiceXdicksprinkles.exeDetected by Dr.Web as Trojan.DownLoader7.15806 and by Malwarebytes Anti-Malware as Trojan.MSILNo
disgxXdidesgx.exeAdded by the SDBOT.BGF WORM!No
SwdaswdwXdidesgx.exeAdded by the SDBOT.BGF WORM!No
yoinkXdidesgx.exeAdded by the SDBOT.BGF WORM!No
rundll***Xdie.exe [path] mdll.exeAdded by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946No
rundll***Xdie.exe [path] secure.batAdded by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946No
rundll***Xdie.exe [path] secure.exeAdded by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946No
rundll***Xdie.exe [path] ttg.exeAdded by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946No
DietKUDietK.exeDiet Kazaa add-on for Kazaa Media Desktop - "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results"No
DigiCellUDigiCell.exeMSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"No
DigiSrvUDigiSrv.exeRelated to camera software from DigitalDreamsNo
DesktopX WidgetUDigitalMETER.exeDigitalMETER widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop. Once started, DigitalMETER.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
DigitalMETERUDigitalMETER.exeDigitalMETER widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop. Once started, DigitalMETER.exe loads a file called "DXWidget.exe" and exitsYes
DigitalNamesXDigitalNamesStart.exeDigitalNames spyware variantNo
DigiDXDigitalSound.exeTheGuardian malware!No
DesktopX WidgetUDIGITA~1.EXEDigitalMETER widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop. Once started, DigitalMETER.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "DigitalMETER.exe" is shown as "DIGITA~1.EXE"Yes
DigitalMETERUDIGITA~1.EXEDigitalMETER widget for the DesktopX desktop utility from Stardock Corporation. Displays free drive space, free memory, CPU usage and system running time on the desktop. Once started, DigitalMETER.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "DigitalMETER.exe" is shown as "DIGITA~1.EXE"Yes
Digital ProtectionXdigprot.exeDigital Protection rogue security software - not recommended, removal instructions hereNo
DIGServicesNDIGServices.exeCreated by Disney but licensed to ESPN for watching videosNo
DIGStreamNdigstream.exeDIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automaticallyNo
iConfigLoaderXDIIhost.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
dikkoceruvynXdikkoceruvyn.exeDetected by McAfee as PWS-FANO!77F138CB9225 and by Malwarebytes Anti-Malware as Trojan.Ransom.GenNo
Diks32XDiks32.exeDetected by Dr.Web as Trojan.PWS.Banker1.2398 and by Malwarebytes Anti-Malware as Trojan.BankerNo
dIlhost.exeXdIlhost.exeAdded by the MDROP-DUW TROJAN! Note the uppercase "i" in place of a lower case "L" after the "d"No
Microsoft Internal AntiVirus SystemsXdIlhost.exeAdded by the RBOT-AEV WORM!No
diloqgohovapXdiloqgohovap.exeDetected by McAfee as RDN/Generic Downloader.x!co and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
DimensionUDimension.exeDimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocolNo
Dino3Xdino3.exeRelated to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a resultNo
DinstXdinst.exeIMIServer/IEPlugin adwareNo
dionpisXdionpis.exeAdded by the PSW-FF TROJAN!No
Direct XXDirect X9.exeAdded by the ZANAYAT.A WORM!No
Directx Startup DriversXdirect.exeDetected by Trend Micro as WORM_CPEX.F. The file is located in %System%\inetsrvNo
direct3d.exeXdirect3d.exeAdded by the CERTIF-F TROJAN!No
DirectX9Xdirect3d.exeAdded by the AGENT.EAK TROJAN!No
Windows SP4XdirectCC.exeAdded by the RBOT-ACX WORM!No
Adaptec DirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start → Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again laterNo
AdaptecDirectCDNDirectcd.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start → Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again laterNo
DirectCDNDirectCD.exeDirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start → Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again laterNo
DirectKeywordXDirectKeyword.exeDetected by Malwarebytes Anti-Malware as Adware.K.DirectKeyWord. The file is located in %AppData%\DirectKeywordNo
directs.exeXdirects.exeAdded by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!No
DIRECTVDSLUDirectvdsl.exeStarts DirectTV DSL modem at boot up. Can also be started manuallyNo
directxXDirectx.exeAdded by the SDBOT.D TROJAN!No
DirectXXDirectX.exeAdded by the BLAXE or LOGPOLE WORMS!No
DirectXXdirectx32.exeAdded by the AGOBOT.CG WORM!No
DirectX 32Xdirectx32.exeAdded by a variant of the AGOBOT WORM!No
DirectX PluginXdirectx32.exeAdded by the KURTAGENT.A TROJAN!No
DirectX 3D ServiceXDirectX3D.exeDetected by Symantec as Backdoor.Revrs and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
WindowsXP ModuleXDirectX3D.exeMalware, reportedly a keylogger - see hereNo
Microsoft DirectxXdirectxat.exeAdded by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)No
Microsoft DirectxspXdirectxbt.exeAdded by a variant of the RBOT-GHT WORM!No
Microsoft Directx clickXdirectxclick.exeAdded by a variant of the RBOT-GHT WORM!No
Microsoft Directx clicksXdirectxclickers.exeAdded by the RBOT-GHT WORM!No
Microsoft DirectxspnewXdirectxnew.exeAdded by a variant of the RBOT-GHT WORM!No
Microsoft Directx pushXdirectxpushup.exeAdded by a variant of the RBOT-GHT WORM!No
DirectX64XDirectXset.exeDetected by McAfee as W32/Browney.a.wormNo
DirecXXDirecX.exeAdded by the AGOBOT-HU BACKDOOR!No
DirkeyUDirkey.exeDirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked foldersNo
DirLockXDirLock.exeAdded by the AUTORUN-APL WORM!No
DirLockerXdirlock.exeAdded by the AUTORUN-AMS WORM!No
SessionMngrXdirlock.exeAdded by the DAPROSY WORM!No
dirnvvXdirnvv.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.TIB. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
Winjava xmlXdirx9.exeDetected by SUPERAntiSpyware as Trojan.DIRX9.Process. The file is located in %System%No
DisableWinXPWZCS?DisableWinXPWZCS.exeAssociated with Qualcomm Atheros wireless chipsetsNo
EDFcsn?discfcsn.exeRelated to Hewlett-Packard's Discovery Agent. What does it do and is it required?No
discoveg?discoveg.exe??No
DISCover?DISCover.exeRelated to DISCover Drop from Digital Interactive Systems Corporation. What does it do and is it required?No
DiscUpdateManagerNDiscUpdateMgr.exeDisc Update Manager for Digital Interactive's DISCover Console. "The company's patented Drop 'n' Play technology provides a simple, console-like experience when playing PC titles allowing for seamless play of CD/DVD-based games while its unique Parental Control system incorporates ESRB ratings to help users limit access to younger players"No
DiscUpdateManagerNDiscUpdMgr.exeDisc Update Manager for Digital Interactive's DISCover Console. "The company's patented Drop 'n' Play technology provides a simple, console-like experience when playing PC titles allowing for seamless play of CD/DVD-based games while its unique Parental Control system incorporates ESRB ratings to help users limit access to younger players"No
DiscWizardMonitor.exeNDiscWizardMonitor.exePart of Seagate DiscWizard - their implementation of the Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mountingNo
disfyqgublyxXdisfyqgublyx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
msigXdisk10.exeDetected by Sophos as Troj/Banbra-KFNo
taskmsgsXdisk10.exeAdded by the BANCOS-BBW TROJAN!No
MSN32Xdisk22.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
Windows (random character)Xdiskcheck.exeAdded by the SINGU.B TROJAN!No
DiskCleanMainXDiskClean.exeDiskClean rogue security software - not recommended, removal instructions hereNo
Disk CleanerUDiskCleaner.ExeHard disk management part of TuneUp Utilities from TuneUp Distribution GmbHNo
(Default)Xdiskete.exeDetected by Microsoft as TrojanDownloader:Win32/Banload and by Malwarebytes Anti-Malware as Trojan.Delf. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
DiskinfXdiskinf.exeAdded by the CRYPTER.A TROJAN!No
CrystalDiskInfoUDiskInfo.exeCrystalDiskInfo - a "HDD/SSD utility software which supports S.M.A.R.T. and a part of USB-HDD"No
DISKMON.EXE?DISKMON.EXE??No
diskchkXdiskmon32.exeAdded by the RBOT-BBI WORM!No
DisknagNdisknag.exeDell program that reminds you to make your backup diskettesNo
DiskPieProNDiskPiePro.exeDiskPie Pro cleaning utility from PC Magazine that provides users with customizable pie charts to find and fix overweight folders, files and disk drivesNo
Microsoft Service Disk CycleXdisksave.exeAdded by the SLENFBOT.II WORM!No
[various names]Xdiskserv.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Disk ManagerXdiskver.exeAdded by a variant of Win32/RbotNo
Disk_MonitorUDisk_Monitor.exeMulti-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the readerNo
I am not Ranky. I am eTunnel!Xdisney.exeAdded by an unidentified WORM or TROJAN!No
disnisaXdisnisa.exeAdded by the DORF-AE WORM!No
DispatcherXdispatcher.exeAdded by the DLOADR-AS TROJAN!No
dispenterXdispenter.exeAdded by the AGENT-MKK TROJAN!No
APC UPS StatusYDisplay.exeSystem Tray access to the APC PowerChute software which controls their range of uninterruptible power supplies (UPS) - to provide unattended shutdown of servers and workstations in the event of an extended power outage and status loggingNo
Windows Display CouplerXdisplay.exeAdded by the IRCBOT-YS TROJAN!No
DisplayFusionUDisplayFusion.exeDisplayFusion from Binary Fortress Software - "is a fantastic application that can make your dual monitor (or triple monitor or more) life much, much easier! From allowing you to use a different wallpaper on each monitor, to integrating with Flickr for image searching, to providing hotkeys for managing your application windows"Yes
NVIDIA DisplayXDisplayMonitor.exeAdded by the ABI.C WORM! Note - this is not a legitimate nVidia entryNo
DisplaySwitchXDisplaySwitch.exeDetected by Sophos as Troj/Ransom-QA and by Malwarebytes Anti-Malware as Trojan.FakeMS.zbNo
DisspyUdisspy.exeDisspy spyware detection and removal softwareNo
Distiller Assistant 3.01NDISTASST.EXEFrom Adobe. Creates PDF universal files for Acrobat Reader. Available via Start → ProgramsNo
DitYDit.exe"Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found. Located in %Windir%No
DitXdit.exeAdded by the LAZAR-A TROJAN! Note - this is located in %System%No
DiTask.exeNDiTask.exeAssociated with an Eicon Networks (now Dialogic) Diva ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call)No
Divamon.exe?Divamon.exeAssociated with an Eicon Networks (now Dialogic) Diva ISDN or ADSL modem - what does it do and is it required?No
DivX UpdaterXDivX.ExeAdded by the NALDEM TROJAN or MASTAK VIRUS!No
Java UpdateXdivx.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.Gen. The file is located in %ProgramFiles%\JavaNo
divxXdivxenc.exeAdded by the SPBOT.B TROJAN!No
DivX PlayerXDivXPlayer.exeAdded by the RBOT.AW BACKDOOR!No
DIVX Video PlayerXDIVXPloyer.exeAdded by an unidentified WORM or TROJAN!No
DivX UpdateNDivXUpdate.exeAutomatic updates for the DivX Plus video software package from DivX, LLC - which includes the free Player, Web Player and Codec Pack and a trial version of the Converter. If disabled, DivXUpdate.exe will run the next time you start one of the components - but will not run on windows start-upYes
DivXUpdateNDivXUpdate.exeAutomatic updates for the DivX Plus video software package from DivX, LLC - which includes the free Player, Web Player and Codec Pack and a trial version of the Converter. If disabled, DivXUpdate.exe will run the next time you start one of the components - but will not run on windows start-upYes
CerbXDivXx.exeAdded by the KEYLOG-LV TROJAN!No
caidiysetupXdiynetsetupuni.exeDIYNet adwareNo
djebmm350.exeXdjebmm350.exeEbates Moe Money Maker adwareNo
DJSNetCN?DJSNetCN.exe"Symantec Licensing Detect Internet Connection", part of Norton Antivirus. What does it do and is it required?No
djtopr1150.exeXdjtopr1150.exeWebRebates adwareNo
ServerXdkdel.exeDetected by Malwarebytes Anti-Malware as Backdoor.Whimoo. The file is located in %System%No
dKernelXdKernel.exeAdded by the DECOY-A WORM!No
DiskeeperSystrayNDkIcon.exeDiskeeper defragmentation utility from Condusiv Technologies (was Diskeeeper Corporation and Executive Software)No
DkServiceYDkService.exePart of the Diskeeper defragmentation utility from Condusiv Technologies (was Diskeeeper Corporation and Executive Software). Recommended to leave this enabled, otherwise you could have problems starting it manually. Runs as a service on Windows XP and laterNo
DKTimeXdktime.exeAdded by the LUNII TROJAN!No
Debugger Windows BuilderXdkuowfxs.exeDetected by Dr.Web as Trojan.DownLoader5.32217No
Dkware lptt01Xdkware.exeRapidBlaster variant (in a "DonkySoft" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Dkware ml097eXdkware.exeRapidBlaster variant (in a "DonkySoft" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
dkzzixm?dkzzixm.exe??No
Win32 UpdateXdl32.exeAdded by an unidentified WORM or TROJAN!No
DLAYDLACTRLW.EXEDrive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"Yes
DLACTRLWYDLACTRLW.EXEDrive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"Yes
DLACTRLW.EXEYDLACTRLW.EXEDrive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"Yes
DlaTrayNDlatray.exeSystem Tray access to DLA (Drive Letter Access) on HP PCs - HP's version of DirectCD (by Veritas - now Symantec). From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"No
HP_dlaNdlatray.exeSystem Tray access to DLA (Drive Letter Access) on HP PCs - HP's version of DirectCD (by Veritas - now Symantec). From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"No
Dell AIO Printer A940Udlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttonsNo
dlbcservNdlbcserv.exeRelated to Dell Photo Printers and provides additional configuration options for these devicesNo
Dell AIO Printer A960Udlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttonsNo
Dell AIO Printer A920Udlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttonsNo
Dell Photo AIO Printer 922Udlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttonsNo
dlbtmon.exeUdlbtmon.exeDell Photo AIO Printer 922 device monitorNo
Dell Photo AIO Printer 942Udlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttonsNo
dlbumon.exeUdlbumon.exeDell Photo AIO Printer 942 device monitorNo
dlbxmon.exeUdlbxmon.exeDell Photo AIO Printer 962 device monitorNo
dlccmon.exeUdlccmon.exeDell Photo AIO Printer 924 device monitorNo
dlcdmon.exeUdlcdmon.exeDell Photo AIO Printer 944 device monitorNo
dlcgmon.exeUdlcgmon.exeDell Photo AIO Printer 810 device monitorNo
dlcimon.exeUdlcimon.exeDell AIO Printer 946 device monitorNo
dlcjmon.exeUdlcjmon.exeDell Photo AIO Printer 964 device monitorNo
dlcqmon.exeUdlcqmon.exeDell Photo AIO Printer 966 device monitorNo
dlcxmon.exeUdlcxmon.exeDell Photo AIO Printer 926 device monitorNo
dlderXdlder.exeDlder spyware. Also creates a fake "explorer.exe" file and can be installed via versions of Grokster, Lime Wire and KaZaA file-sharing utilitiesNo
dldfmon.exeUdldfmon.exeDell AIO Printer 948 device monitorNo
dldnamonUdldnamon.exeDell V105 AIO printer device monitorNo
dldnmon.exeUdldnmon.exeDell V105 AIO printer device monitorNo
dldomon.exeUdldomon.exeDell 968 AIO Printer device monitorNo
dldtamonUdldtamon.exeDell V305 AIO Printer device monitorNo
dldtmonUdldtmon.exeDell V305 AIO Printer device monitorNo
dldtmon.exeUdldtmon.exeDell V305 AIO Printer device monitorNo
dldwamonUdldwamon.exeDell V505 AIO printer device monitorNo
dldwmon.exeUdldwmon.exeDell V505 AIO printer device monitorNo
dleamon.exeUdleamon.exeDell V310-V510 Series AIO printer device monitorNo
dlebmon.exeUdlebmon.exeDell P513w AIO wireless printer device monitorNo
dlecmon.exeUdlecmon.exeDell P713w AIO wireless printer device monitorNo
dleemon.exeUdleemon.exeDell V715w AIO wireless printer device monitorNo
DLForcerExe?DLForcerEXE.exe??No
Digital Line DetectNDLG.exeDetects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modemsNo
DLGNDLGCHBW.exeBackweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updatesNo
Data LifeGuard LifeLine Lite installerNDLGLI.EXEBackweb installer - see hereNo
dlhostXdlhost.exeAdded by the EXPHOOK-A TROJAN!No
Windows System TrayXdlhost.exeIamBigBrother spywareNo
NetworkSetupNdlink.exeD-Link System Tray iconNo
DLKJhghfdhgXDLKJhghfdhg.exeDetected by McAfee as RDN/Generic PWS.y!e and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
hkeyXdllMOLEULTR-A malwareNo
policeXdllMOLEULTR-A malwareNo
AMINAXdll.exeDetected by McAfee as Generic.dx!bhqr and by Malwarebytes Anti-Malware as Backdoor.AgentNo
CLSIDXdll.exeFirstEnter - Switch dialer and hijacker variant, see hereNo
HKCUXdll.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\windowssNo
HKCUXdll.exeDetected by McAfee as Generic.dx!bhqr and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXdll.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\windowssNo
mstwain32XDLL.EXEDetected by Kaspersky as Trojan-Dropper.Win32.Delf.gdj and by Malwarebytes Anti-Malware as Trojan.AgentNo
dll32Xdll32.exeDetected by Kaspersky as Trojan-Downloader.Win32.Banload.bej. The file is located in %System%No
System32DllXDLL32SYS.EXEAdded by the SPYBOT-CZ WORM!No
dllcache.exeXdllcache.exeAdded by the VISPAT.A WORM!No
netmonXdllcache.exeDetected by Sophos as Troj~Bckdr-RAA and by Malwarebytes Anti-Malware as Worm.Autorun.MSOLNo
Windows Dynamic Library CacheXdllcache.exeAdded by the INJECT-HT TROJAN!No
NoDriveTypeAutoRunXdllcache32.exeAdded by the SPUNST TROJAN!No
DllCacherv2Xdllcachev2.exeAdded by the LATEDA TROJAN!No
Winsock2 driverXdllcfg32.exeAdded by the SPYBOT.AG WORM!No
Live MenuNDllcmd32.exeeFax Send button for eFax Messenger Plus. Available via Start → Programs Disabling instructions available hereNo
MSN UpdateXdllcon.exeAdded by the RBOT-EA WORM!No
DlldmtXdlldmt.exeAdded by the GEMA TROJAN!No
dllhelpXdllhelp.exeAdded by the STARTPAGE.DQ hijackerNo
Win32 ConfigurationXdllhelp.exeAdded by the SDBOT.UL WORM!No
dllhelpXdllhlp.exeAdded by the DOWNLOADER-HI TROJAN!No
System RescueXdllhosl.exeDetected by Microsoft as TrojanSpy:Win32/Ranbyus.G and by Malwarebytes Anti-Malware as Trojan.AgentNo
DLL32Xdllhost.dllAdded by the SUCLOVE.A WORM!No
DllHostXdllhost.exeAdded by the PROSTI.AA BACKDOOR! Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\InfNo
Gilat SOM EnumeratorYdllhost.exeFor Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this systemNo
Microsoft Driver SetupXdllhost.exeDetected by Sophos as W32/Autorun-AOZ. Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\driversNo
WinMngnXdllhost.exeDetected by Sophos as Troj/Sivion-A. Note - this is not the legitimate dllhost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\systemNo
DLL Service ManagerXdllhost16.exeAdded by the RPCBOT.F BACKDOOR!No
Index ServiceXdllhost32.exeAdded by a variant of WORM_AGOBOT.GEN. The file is located in %System%No
Microsoft Autorun4Xdllhost32.exeDetected by Symantec as W32.Ogleon.ANo
Windows DLL HostXdllhost32.exeAdded by an unidentified WORM or TROJAN!No
Windows UpdateXdllhostup.exeDetected by Sophos as Troj/Bancban-NB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
dllhostxp.exeXdllhostxp.exeBrowser hijacker and adware downloaderNo
DLLHostXdllhst.exeAdded by the DELBOT-AC WORM!No
Dllhst3gXdllhst3g.exeDetected by Malwarebytes Anti-Malware as Trojan.TDref.Gen. The file is located in %Windir%No
DllHstXdllhst3g.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate dllhst3g.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
[random CLSID]Xdllhsts.exeDetected by Microsoft as Trojan:Win32/Ransom.EJNo
96e72d757b94bf0979ffd7625b311090Xdlllhost.exeDetected by Dr.Web as Trojan.DownLoader8.17228 and by Malwarebytes Anti-Malware as Trojan.MSILNo
UpmeXdllman.exeAdded by the SDBOT.ALX WORM!No
Windows Online UpdaterXdllman.exeAdded by the RBOT-TE WORM!No
dliteXdllmanager.exeAdded by the WOOTBOT.DN WORM!No
NvCplScanXdllmanager.exeAdded by the FORBOT.R WORM!No
Windows Plug and Play Service 32 BITXdllmanager.exeAdded by the RBOT-CGK WORM!No
Microsoft Windows DLL Services ConfigurationXdllmanager32.exeDetected by Sophos as W32/Sdbot-BTUNo
Microsoft Connection ManagerXdllmanger.exeAdded by the RBOT.RG WORM!No
DLL32Xdllmem32.exeAdded by the KWBOT.E WORM!No
Microsoft DLL Host ServiceXdllmemhost.exeAdded by the SLENFBOT.BM WORM!No
Microsoft DLL ManagerXdllmgr.exeAdded by the SDBOT-KJ WORM!No
Module LoaderUDLLML.exeCreative DLL Module Loader for the Sound Blaster range of internal and external soundcards. Used to load modules such as remote control or mixingNo
AudioDrvEmulatorUDLLML.exe AudDrvEm.dllCreative DLL Module Loader for the Sound Blaster range of internal and external soundcards. Used to load modules such as remote control or mixing. This instance is related to an Audio Emulator functionNo
RCSystemUDLLML.exe RCSystemCreative DLL Module Loader for the Sound Blaster range of internal and external soundcards. Used to load modules such as remote control or mixing. This instance appears to be related to a Remote Control functionNo
DLL ManagerXdllmngr32.exeAdded by the RBOT.AAT BACKDOOR!No
Microsoft DLL MonitorXdllmon32.exeAdded by the AGENT.WP WORM!No
Microsoft DLL MonitorXdllmon64.exeAdded by the SLENFBOT.DY WORM!No
Microsoft DLL MonitorXdllmonitor.exeAdded by the SLENFBOT.DR WORM!No
Microsoft Dll Printer ManagerXdllpt.exeAdded by the SDBOT.BIH WORM!No
HKCUXDllrecover.exeDetected by Sophos as Mal/MSIL-FW and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXDllrecover.exeDetected by Sophos as Mal/MSIL-FW and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
PoliciesXDllrecover.exeDetected by Sophos as Mal/MSIL-FW and by Malwarebytes Anti-Malware as Backdoor.Agent.PGenNo
DllregXdllreg.exeAdded by the CRYPTER.A TROJAN!No
run=Xdllreg.exeAdded by the DUMARU-L TROJAN!No
Windows 32-bit DLL Integrity VerifierXdllrun.exeAdded by Remote Storm - a remote control tool that is a network application that allows users to manage and control PCs or networks from a remote locationNo
Microsoft Windows Services EdtXdllrun32.exeAdded by the RBOT-GAF WORM!No
Microsoft DLL AuthentificationXdllsecure.exeAdded by the SLENFBOT.BN WORM!No
Microsoft DLLSet32Xdllset32.exeAdded by the RBOT.OZ WORM!No
Microsoft DLL SourceXdllsrc.exeAdded by a variant of the IRCBOT BACKDOOR!No
RegScanXDLLSRV32.EXEAdded by the AGOBOT.AEW WORM!No
DLLService32Xdllsvc32.exeAdded by the AGOBOT.VX WORM!No
MS DLL Library ManagerXdllsys64.exeDetected by GFI as Trojan.Ranky. The file is located in %System%No
Dllbin32Xdllsysbin.exeAdded by the SLINBOT.FU BACKDOOR!No
DLLUPDATE32Xdllupdate32.exeDetected by Trend Micro as WORM_AGOBOT.IANo
[empty]Xdllvirtual.dllAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
[empty]Xdllvirtual.exeAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
[empty]Xdllvirtual.jsAdded by the DADOBRA-IW TROJAN! Note - has a blank entry under the Startup Item/Name fieldNo
Dial22Xdlm.exeAdult content diallerNo
Dial33Xdlm.exeAdult content diallerNo
DLM.exeNDLM.exeIGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be initialized through that browserNo
igndlm.exeNDLM.exeIGN Download Manager for managing downloads from FilePlanet.comNo
DLink System TrayUdlnetst.exeRelated to D-Link DGE-530T PCI card for servers and workstationsNo
MSConfigXdlnf.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
msvccc66Xdload.exeAdded by a variant of Win32/RbotNo
Cliente DLOYDLOClientu.exePart of the backup suites from Veritas - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005No
DLO AgentYDLOClientu.exePart of the backup suites from Veritas - Backup Exec and NetBackup. Both have now been replaced by their Symantec equivalents since they acquired VERITAS in 2005No
Symantec Backup Exec Desktop AgentYDLOClientu.exePart of Symantec's Backup Exec backup softwareNo
Symantec NetBackup Desktop AgentYDLOClientu.exePart of Symantec's NetBackup backup softwareNo
DLPSPUDLPSP.EXEDell laser printer status monitorNo
dlRBXdlRB.vbsDetected by Malwarebytes Anti-Malware as Script.Reboot.Agent. The file is located in %System%No
li-speed****Xdlres.exeAdult web-dialler - **** is randomNo
dlsp2mxXdlsp2mx.exeAdded by the MPB-B DIALER! An uninstall option can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "dlsp2mx"No
DLT?dlt.exe??No
dlucaXdluca.exeAdded by the DLUCA.C TROJAN!No
dluxdeXdluxde.exeAll-In-One-Telcom (adult content dialler) variantNo
DluxjpXDluxjp.exeAdded by the DLUCA.D TROJAN!No
dm***.exe [* = random char]Xdm***.exe [* = random char]Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DualMatchingXdm.exeDetected by Symantec as Trojan.ADH and by Malwarebytes Anti-Malware as Adware.AdKong. The file is located in %ProgramFiles%\dmNo
Auto UpdateXdma.exeAdded by the RBOT-AVO WORM!No
DMASchedulerNDMAScheduler.exeRelated to DigitalMedia Plus Archiver. This program is non-essential process to the running of the program, but should not be terminated unless suspected to be causing problemsNo
DMCXdmc.exeAdded by Trojan-Downloader.Win32.Dluca.bv TROJAN!No
CrustyXdmcpl.exeAdded by the RUSTY WORM!No
ATKMEDIAUDMEDIA.EXEDriver for the media buttons on the front of some Asus laptops, such as Forward,back,stop,pause etcNo
InControl Desktop ManagerNDMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start → ProgramsNo
DMILDRNdmildr.exePart of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start → ProgramsNo
dmimeXdmime.exeMalware installed by different rogue security software including SpyKillerProNo
DMISLNDMISL.EXEDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more informationNo
DMISLAPPNDMISLAPP.exeDMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more informationNo
iktcXdmiy.exeAdded by the AGENT-RDY TROJAN!No
dmjay?dmjay.exe??No
DMHotKeyUDMLoader.exeHotKey access to the Samsung Display Manager on laptops and ultra-mobiles that support it - such as the M55 and Q1No
dmloaderXdmloader.exeAdded by a variant of Win32/RbotNo
DSServiceXdmrss.exeAdded by the AGOBOT-XX WORM!No
DriverMagicLogonUdmschedule.exePart of DriverMagic - "the easiest way to locate device drivers"No
DM_serverXdmserver.exeComet Cursor adwareNo
PlaySysXdmsplay.exeDetected by Dr.Web as Trojan.DownLoader6.61248 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Dmsvc32XDmsvc32.exeDetected by Trend Micro as WORM_AGOBOT.ABUNo
Windows driver updateXdmsvc32.exeAdded by the SDBOT-GP BACKDOOR!No
DmtdllXdmtdll.exeAdded by the GEMA TROJAN!No
DmwClientUdmwclient.exeDMW "anti-cheating" software for online gamingNo
DMXLauncherUDMXLauncher.exePart of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video filesNo
dm[3 random letters].exeXdm[3 random letters].exeAdded by the RUINDEM TROJAN!No
DM mgrXdm_mgr.exeAdded by the JITTAR TROJAN!No
Windows Data SerivceXdn.exeAdded by the AGENT-NK MALWARE!No
DnarNDnar.exeInstalled on some Dell workstations and DMI related. Tries to access the internet and is known to not be required - but what does it do?No
DancerUDncLE.exePart of Microsoft Plus! Digital Media Edition - see hereNo
dndsiocXdndsioc.exeAdded by the ONLINEGAMES.ALLM TROJAN!No
distributed.net clientUDNETC.EXEDsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by virusesNo
Microsoft Update ProtectionXdnetc.exeDetected by Dr.Web as Trojan.DownLoader8.31919. Note - this entry loads from the Windows Startup folder and the file is located in %ProgramFiles%\dnetcNo
Windows Update FilesXdnetc.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %ProgramFiles%\microsoft hardwareNo
DNHelper32XDNHlp32.exeAdded by an unidentified WORM or TROJAN!No
wpqggejXdnierjk.exeAdded by the FANBOT-F WORM!No
DNS2GoClient?dns2goclient.exeDNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required?No
winhelpXdns32.exeAdded by a variant of Win32/RbotNo
dnscleanerXdnscleaner.exeCoolWebSearch parasite variantNo
DNSEXDNSE.exePart of rogue security tools, including WinAntiVirus Pro 2007, PcTurboPro and SystemDoctorNo
Microsoft System ServiceXdnservice.exeAdded by a variant of the IRCBOT BACKDOOR!No
DNSCacheBoostXdnsping.exeAdded by the DNSBUST-A TROJAN!No
DNS ServiceXdnsresolver.exeAdded by the RBOT-PQ WORM!No
Domain Name Resolve ServiceXdnsresolver.exeAdded by the KIMAN.A WORM!No
Dns ResolverXdnsrslve.exeDetected by Sophos as W32/Rbot-WSNo
NAV Auto ProtectXdnsserv.exeAdded by the SDBOT.AQZ WORM!No
DNS ServiceXdnssvc.exeAdded by the DELBOT-Z WORM!No
SiS DnsXdnssvc.exeAdded by the DLOADER-UE TROJAN!No
ntupdateXdnsvc.exeAdded by the SDBOT-TC WORM!No
dnswinXdnswin.exeAdded by the AGENT.CE BACKDOOR!No
Dns ServerXdnswn.exeDetected by Trend Micro as WORM_RBOT.APKNo
DNXVC?dnxvc.exe??No
docXdoc.exeAdded by the AGOBOT-BJ WORM!No
BayMgrUDockApp.exeHot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devicesNo
Document ManagerUdocmgr.exeWave Systems Corp. Document Manager - "provides secure storage and management capabilities for file and folder level encryption"No
DocTorXDoctor.exeDetected by Trend Micro as WORM_DOTOR.ANo
NDoctorComXDoctorComLaunch.exeDoctorCom rogue security software - not recommended, removal instructions hereNo
DoctorSecurityMainXDoctorSecurity.exeDoctorSecurity rogue security software - not recommended, removal instructions hereNo
DoctorVXDoctorVLaunch.exeDoctorV rogue security software - not recommended, removal instructions hereNo
DocumentXDocument.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %MyDocuments%No
mswordXdocx.exeAdded by the CODOX-A WORM!No
Microsoft UpMachineXdoezs.exeDetected by Trend Micro as WORM_RBOT.BCTNo
Doing?doing.exe??No
doit.exeXdoit.exeAdded by the FORBOT-EK WORM!No
dolkeavukzagXdolkeavukzag.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
DolphinsScreenServerSvcUDolphinsScreenServer.exeScreensaver for the Miami Dolphins NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supportedNo
domXdom.exeDetected by Sophos as Troj/Agent-VGA and by Malwarebytes Anti-Malware as Trojan.AgentNo
DominoNDomino.EXEVimicro based webcam driver - as used by both internal (laptop) and external webcams from Vimicro themselves, A4tech, Canon and othersNo
don't seeUdon't see.exeDon't See! French parental control software by Remy DelefosseNo
donXdon.exeDetected by Dr.Web as Trojan.DownLoader6.60182 and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
Windows FirewallXdone2.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Don't PanicUdontpanicdemodp.exe30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite"No
donxXdonx.exeDetected by Symantec as Infostealer.Donx and by Malwarebytes Anti-Malware as Trojan.AgentNo
dooppXdoop32.exeDetected by Sophos as Troj/Agent-TKDNo
WindowsServerXdoor.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%\WebNo
DopusUdopus.exeDirectory Opus - a file manager from GPSoftNo
Directory Opus Desktop DblclkYdopusrt.exeDirectory Opus - an advanced file manager. "Directory Opus goes beyond the simple file manager metaphor, and offers you a complete replacement for Windows Explorer and many other utility programs for handling FTP, ZIP, viewing files and images, running slideshows and more"No
doqmalnapoqsXdoqmalnapoqs.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile%No
wersdsXdoriot.exeAdded by the JECT.C TROJAN!No
wersds.exeXdoriot.exeDetected by Sophos as Troj/BagleDl-ANo
wpds.exeXdoriot.exeAdded by the SMALL-KY TROJAN!No
doro-searchXdoro-searchUp.exeDetected by Malwarebytes Anti-Malware as Adware.Nieguide. The file is located in %ProgramFiles%\doro-searchNo
DoroServerNDoroServer.exeDoro PDF Writer from The SZ Development. All what you need for creating pdf filesNo
WIN32 DDOSSERXdos.exeAdded by the KELVIR.F WORM!No
Window LoaderXDos32.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
dosXdos64.exeAdware downloader trojanNo
doscpXdoscp.exeAdded by the TATERF-AH WORM!No
Auto StartXdosin.exeAdded by the SDBOT-GO BACKDOOR!No
Configuration LoaderXdosrun32.exeDetected by Symantec as W32.HLLW.Gaobot.AONo
Windows DOSXdosw.exeAdded by the SALAY-A WORM!No
Dot1XCfgXDot1XCfg.exeAdded by the AGOBOT.EA TROJAN!No
doublevaccineXdoublevaccineu.exeDoubleVaccine rogue security software - not recommended. One of the OneScan family of rogue scanner programsNo
DowmingzuXDowmingzu.dll.vbsAdded by the SOLOW-E WORM!No
downXdown.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\programdataNo
Down2HomeUDown2Home.exeDown2Home - "monitors your ADSL/Cablemodem/Dialup traffic and provides you with usefull statistics about the amount of data your PC has transferred"No
DownNowXdownite.exeAdded by the SDBOT.BOA WORM!No
Download Windows 32 64 Bit Gratis Full Version Full SpeedXDownload Windows 32 64 Bit Gratis Full Version Full Speed.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.AI. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
883760087203c8f5444f9b964f8172aeXdownload.exeDetected by Malwarebytes Anti-Malware as Trojan.Facebook. The file is located in %UserTemp%No
DealHelperDownXdownload.exeDetected by Symantec as Adware.DealHelperNo
Eac DownloadXdownload.exeWebcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see hereNo
DGStartXdownloadgetupgrade.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\DownLoadGetNo
DGup2StartXdownloadgetuphp.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %AppData%\DownLoadGetNo
Download PlusXDownloadPlus.exeDownloadPlus adwareNo
eBotNDownloadWizard.exeeBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start → ProgramsNo
Download WonderNDownloadWonder.exeDownload Wonder from Forty Software. Download manager for resuming downloads, amongst other featuresNo
Digital River eBotNdownlo~1.exeDigital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more hereNo
MicrosoftUpdateXdownnew.exeDetected by Sophos as Troj/Tanto-D and by Malwarebytes Anti-Malware as Trojan.AgentNo
downsXdowns.exeAdded by the BCKDR-MNR TROJAN!No
DownsXDownsCK.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\DownsNo
DownxzXDownxz.batDetected by Symantec as W32.Mydoom.W@mmNo
DsiXdp-******.exeAdded by an unidentified adware where ****** are random charactersNo
DsiXdp-him.exeAdded by the MULTIDR-AH TROJAN!No
Don't Panic!UDP.EXEDon't Panic! privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite"No
DpAgentYdpagent.exePart of the DigitalPersona range of fingerprint authentication applications - which are use to replace passwords with fingerprint recognition. Included on some Dell laptop models (such as the Vostro 1720) for exampleNo
DPAgntNDPAgnt.exedigitalPersona fingerprint scannerNo
DPASUpdateYDPASAutoUpdate.exeAutomatic updates for DefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1No
DPASYDPASNT.exeDefenderPro AntiSpy spyware remover - now incorporated Defender Pro 15-in-1 and 5-in-1No
DOPCNOWXdpc32.exeDetected by McAfee as Generic PWS.yk and by Malwarebytes Anti-Malware as Trojan.Agent.DPCNo
DpcnavYdpcnav.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet accessNo
DPConfigNDPConfig.exeCompuware DevPartner Studio Configuration Utility, a tool for software developers - System Tray access to configure the utility's analysis. Not required at startup, can be launched from the Start Menu programs group when neededNo
dpcproxyXdpcproxy.exeAdded by the GOLDENP-A TROJAN!No
DPCProxyLoadOnStartupYdpcstart.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet accessNo
DpcstartYdpcstart.exeDirecWay from DirectTV (now HughesNet) - satellite based high-speed internet accessNo
Disk Panel ConfigurationXdpcsvc.exeAdded by the IRCBOT.BSQ BACKDOOR!No
dpiXdpi.exeDelfin PromulGate adwareNo
dplaysvrXdplaysvr.exeDetected by Dr.Web as Trojan.DownLoader5.44620No
NDPSUDPMW32.EXENovell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this featureNo
dpnsvr32Xdpnsvr32.exeDetected by Sophos as Troj/AOLPass-BNo
Don't Panic Pop-Up StopperUdpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup groupNo
dpps2Udpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup groupNo
Pop-Up StopperUdpps2.exePop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup groupNo
Edzy AntiVirusXdppsfa.exeAdded by a variant of Win32/RbotNo
dpsXdps.exeSmartestSearch parasite - poses as a foistware, bogus adware/spyware remover called "scumware-remover"No
DTRSFRNFYMXdpserialo.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
dptrackerNdptracker.exeCamTrack webcam software that enhances the way people video chatNo
XSRBYJSFXdpwsock5.exeDetected by Dr.Web as Trojan.DownLoader8.24053 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft UpdateXdqbxhupdtAdded by a variant of the SDBOT WORM! See hereNo
ddqdsxnfqsXdqddss.exeAdded by the SDBOT.AEL WORM!No
ffeqfqsXdqddss.exeAdded by the SDBOT-SG WORM!No
dr-infoXdr-inforun.exeDetected by McAfee as Downloader.a!tq and by Malwarebytes Anti-Malware as Rogue.DrInfoNo
DivX MediaPlayer 7.0XDr.DivX.exeAdded by the ALADINZ.G BACKDOOR!No
Speedtouch USB DiagnosticsUDragdiag.exeFor an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)No
DragDropNDragDrop.exeToshiba CD/DVD burning utility - see hereNo
Drag'n Drop CDNDragDrop.exeToshiba CD/DVD burning utility - see hereNo
Drag'n Drop CD+DVDNDragDrop.exeToshiba CD/DVD burning utility - see hereNo
EleFunAnimatedWallpaperUDragon-Fly.exeDragon-Fly animated wallpaper fromNo
DrAntispyXDrAntispy.exeDrAntiSpy rogue security software - not recommended, removal instructions hereNo
Windows Update DravenXdraven.exeDetected by Trend Micro as WORM_SDBOT.AXB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
DrBoanXDrBoan.exedr.Boan rogue security software - not recommended, removal instructions hereNo
run=XDRDOOM.EXEAdded by the SEMAPI-A WORM!No
Drag-to-DiscNDrgToDsc.exeSystem Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly and available via the Start menuYes
DrgToDscNDrgToDsc.exeSystem Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly and available via the Start menuYes
RoxioDragToDiscNDrgToDsc.exeSystem Tray access to Roxio Drag-to-Disc - part of the Roxio Easy CD & DVD Creator and Easy Media Creator series of CD/DVD tools. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly and available via the Start menuYes
Dr. GuardXdrguard.exeDr. Guard rogue security software - not recommended, removal instructions hereNo
KE9801UDriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keysNo
dried.exe?dried.exe??No
Microsoft UpdateXdrive.exeAdded by the BIFROSE-PN WORM!No
DriveIconsUDriveIcon.exeDrive Icons from Realtek - shows a specific icon for each card type for their card reader controllersNo
audiodriverXdriver.exeDetected by Dr.Web as Win32.HLLW.Autoruner.55901 and by Malwarebytes Anti-Malware as Trojan.FakealertNo
drvXdriver.exeAdded by the AUTORUN.ZZ WORM!No
Rising DriverXdriver.exeAdded by the SILLYFD-TL WORM!No
[various names]Xdriver32.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
[various names]Xdriver64.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
MicrosoftKsXDrivers.batAdded by the SHUTDOWN-F TROJAN!No
win32Xdrivers.vbsDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.VBGenNo
AXIS Print System DriverScannerUDriverScanner.exePart of AXIS Print System from AXIS Communications - "adds printer discovery, printer driver installation printing on Windows platforms. Printing is enabled by AXIS Print Monitor, which is one of the components. Another component in AXIS Print System is AXIS IP Installer." Now discontinuedNo
AXIS Print System DriverServerUDriverServer.exePart of AXIS Print System from AXIS Communications - "adds printer discovery, printer driver installation printing on Windows platforms. Printing is enabled by AXIS Print Monitor, which is one of the components. Another component in AXIS Print System is AXIS IP Installer." Now discontinuedNo
DriveSelectNdriveselect.exeDVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start → ProgramsNo
DriveSitterUDriveSitter.exe"DriveSitter is a deluxe hard disk drive diagnostic and background monitoring tool. Based on the well proven S.M.A.R.T. (Self-Monitoring Analysis and Reporting Technology), it reliably detects and forecasts up to 70% of all HDD crashes before they occur!"No
Modulo_administrativoXdrivesom.exeAdded by the VB.WWI TROJAN!No
Nero DriveSpeedNDriveSpeed.exeUtility included with some Nero digital media suites (CD/DVD burning, authoring, etc) which allows the user to set the reading speed an spin down time of a CD/DVD drive on-the-fly - typically to avoid read errors on discs with surface scratches and to reduce the noise on high-speed drivesNo
DRIVES~1NDRIVES~1.EXEUtility included with some Nero digital media suites (CD/DVD burning, authoring, etc) which allows the user to set the reading speed an spin down time of a CD/DVD drive on-the-fly - typically to avoid read errors on discs with surface scratches and to reduce the noise on high-speed drivesYes
DriveSpeed ApplicationNDRIVES~1.EXEUtility included with some Nero digital media suites (CD/DVD burning, authoring, etc) which allows the user to set the reading speed an spin down time of a CD/DVD drive on-the-fly - typically to avoid read errors on discs with surface scratches and to reduce the noise on high-speed drivesYes
Nero DriveSpeedNDRIVES~1.EXEUtility included with some Nero digital media suites (CD/DVD burning, authoring, etc) which allows the user to set the reading speed an spin down time of a CD/DVD drive on-the-fly - typically to avoid read errors on discs with surface scratches and to reduce the noise on high-speed drivesYes
Systems ServiceXdrivex.exeAdded by a variant of Win32/RbotNo
Drive XpertUDriveXpert.exeHard drive management utility included with some ASUS motherboards. "Without drivers or BIOS setups, the ASUS exclusive Drive Xpert is ideal for anyone who needs to secure data on their hard drives or enhance hard drive performances without the hassles of complicated configurations"No
TethXdrle.exePurityScan adwareNo
(Default)XDrm.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
drmXdrm.exeDetected by Kaspersky as Trojan.Win32.Swisyn.bpqf and by Malwarebytes Anti-Malware as Trojan.VBInjectNo
DRM UpgradeXdrmupgd.exeAdded by the IRCBOT.AWU BACKDOOR!No
DrmupgdsXDrmupgds.exeMaxfiles adwareNo
DropboxNDropbox.exeSystem Tray access to the Dropbox online storage service which provides 2GB of space for free for you to save, sync and share filesYes
[random name]Xdropped.exeAdded by the VERTEXBOT BACKDOOR!No
vnetXdropped.exeDetected by McAfee as Generic.bfr!do and by Malwarebytes Anti-Malware as Trojan.Agent.AINo
DropRum.exeXDropRum.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.FXD. The file is located in %LocalAppData%\FFoxDostNo
DrPcFreeXDrPFUpdate.exeDetected by Dr.Web as Trojan.DownLoader5.24152No
DrProtectionXDrProtection.exeDrProtection rogue security software - not recommendedNo
0003d449Xdrprov32.exeAdded by the WEBPREFI-B TROJAN!No
WSAConfigurationXdrrss.exeAdded by a variant of the AGOBOT WORM!No
STManagerNdrst.exeDr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see hereNo
MicrosoftDriverService32Xdrsys32.exeAdded by the IRCBOT.AKX BACKDOOR!No
ExplorerXdrv.exeAdded by the SMALL-FD TROJAN!No
syspathXdrv.exeAdded by the SOBER WORM!No
drvddll.exeXdrvddll.exeAdded by the BEAGLE.AP WORM!No
Drvddll_exeXdrvddll.exeAdded by the BEAGLE.X WORM!No
DLLCONFIG32Xdrvdsk32.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
DrvIconUDrvIcon.exeVista Drive Icon changes the drive icons shown in Windows "My Computer", to a nearly Vista drive icon, showing the drive's free space with a smooth colored horizontal bar'No
DrvListnr?DrvListnr.exeAnalog Devices SoundMax integrated soundcard related. What does it do and is it required?No
drvlsnrUdrvlsnr.exeCompaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedlyNo
main_moduleXdrvmmx32.exeDetected by Kaspersky as Trojan-Downloader.Win32.DilaNo
DrvMon.exeUDrvMon.exeAlcor drive monitor softwareNo
drvnetwXdrvnetw.exeAdded by the BROGGER-B TROJAN!No
drvr32hXdrvr32h.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
drvrmanagerXdrvrquery32.exeAdded by the BOOHOO WORM!No
avidrvXdrvsc.exeDetected by Kaspersky as the AGENT.PH TROJAN!No
drvsys.exeXdrvsys.exeAdded by the BEAGLE.W WORM!No
[default]XDrWatson32.exeAdded by the DREMN TROJAN!No
DrWatsonXdrwatson_.exeAdded by the LOHAV-S TROJAN!No
DrWatsonXdrwatson_32.exeAdded by the LOHAV-S TROJAN!No
Sync ServerXdrwatsoon.exeAdded by the WATSOON.A TROJAN!No
DrWeb AntivirusXDRWEBAV.EXEAdded by an unidentified WORM or TROJAN!No
DrwebschedulerYDrwebscd.exeDrWeb antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystemNo
DrWindowsNDrWindows.exeDr.Windows is "a harmless joke/prank/trick program that will periodically display funny joke error messages to unsuspecting users"No
COM+ Event SystemXDRWTSN16.EXEAdded by the LOVGATE.AB WORM!No
DR_SXDR_S.exeIstBar adwareNo
dsXds.exeAdded by the SPYMON TROJAN!No
dsaXdsa.exeHomepage hijacker - redirecting to downseek.comNo
DASDS VSAVdjsXdsabdw.exeAdded by the SDBOT-RE WORM!No
Answer ProblemXdSAFsqs.exeAdded by the SDBOT-SC WORM!No
DellSupportUDSAgnt.exeDell Support Agent offers additional support and update features for your Dell computer or laptopNo
dsadlsa14Xdsakfsak14.exeAdded by the ONLINEG-P TROJAN!No
Windows Service AgentXdsass.exeAdded by the RBOT.MIRCO.BNG WORM!No
DSBXDSB.exeEnergyPlugin adwareNo
dsbua.exeXdsbua.exeDetected by Dr.Web as Trojan.Disabler.84 and by Malwarebytes Anti-Malware as Trojan.Agent. The file location variesNo
Desktop Service CentreNDSC.exeOptusNet DSL or Dial-Up connection softwareNo
dscXdsc.exeAdded by the AGENT-SYC TROJAN!No
OptusNet Desktop Service CentreNDSC.exeOptusNet DSL or Dial-Up connection softwareNo
dscactivateUdsca.exeDell Support Agent offers additional support and update features for your Dell computer or laptopNo
DS ClockUdsclock.exeDigital desktop clock including synchronization with atomic servers - see hereNo
DSentryNDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation startsNo
DVDSentryNDSentry.exeAnti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation startsNo
Absolute ShieldUdseraser.exeAbsolute Shield Evidence Eliminator - internet history eraserNo
rCronXdservice.exePageOn1 - Switch dialer and hijacker variant, see hereNo
Windows Reg ServicesXdservice.exeAdded by the PRORAT-D TROJAN!No
daskaskfsak6Xdsfids6.exeAdded by the ONLINEG-J TROJAN!No
Sharing and Mapping SoftwareYDShmap.exeIntel AnyPoint internet sharing software. Now discontinuedNo
SIDEBARNdsidebar.exe"Desktop Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control"No
DskcompatXDskcompat.exeAdded by the GEMA TROJAN!No
DSKEYUDsKey.exePart of PC PhoneHome - "secretly sends an invisible email message to an email address of your choice containing the physical location of your computer every time you get an Internet connection". Security software from Brigadoon Security Group for tracking down lost/stolen computersNo
DSLagentexeYDSLagent.exeUsed in conjunction with USB connected ADSL modems from Eicon Networks (now Dialogic). Required for a permanent ADSL connectionNo
YAMAHA DS-XG LauncherNdslaunch.exeSystem Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-upsNo
ASDPLUGINXdsldbaccess.exeAsdPlug premium rate adult content dialerNo
ASDPLUGINXdslgeaccess.exeAsdPlug premium rate adult content dialerNo
DropSpam LifestyleXdslifestyle.exeDetected by McAfee as Adware-DropSpamNo
DSLMONYDSLMON.exeSagem based DSL modem related - apparently needed to detect the modemNo
DSLSTATEXEUdslstat.exeSystem tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)No
AvSerXdsm.exeAdded by the SERFLOG.B WORM!No
DsmSerXdsm.exeAdded by the SERFLOG.B WORM!No
rollbkXdsm.exeAdded by the SERFLOG.B WORM!No
dsmsysXdsmsys.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir%No
adi DSndUpYDSndUp.exeUtility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used onYes
DSndUpYDSndUp.exeUtility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used onYes
SpkrCnfgYDSndUp.exeUtility that only runs once after installing the drivers for Analog Devices SoundMax integrated soundcards. It's exact purpose is unknown at the present time but from the filename it's probably used to configure the default or generic speaker arrangement for the system it's used onYes
dso32Xdsoqq.exeDetected by Sophos as W32/Taterf-AONo
DSSSGENS?dssagens.exe??No
DSSXdssagent.exeRegistration reminder for Mattel Interactive (Broderbund) applications and games. Spyware as it sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more infoNo
HARRRRRXdssdfdfd.exeDetected by McAfee as BackDoor-EKP and by Malwarebytes Anti-Malware as Backdoor.AgentNo
DsSearchBarOSXDsSearchBar.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\Downs\DsSearchBarNo
[various names]Xdstart2.exeAdware - detected by Kaspersky as the SMALL.ALW TROJAN!No
Windows ServiceXdstart4.exeAdded by an unidentified TROJAN! The file is located in %System%No
DAEMON Tools ProNDTAgent.exeSystem Tray access to DAEMON Tools Pro - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a rebootYes
DAEMON Tools Pro AgentNDTAgent.exeSystem Tray access to DAEMON Tools Pro - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a rebootYes
DTAgentNDTAgent.exeSystem Tray access to DAEMON Tools Pro - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a rebootYes
DT 11Mbps WLAN PC Card StationUDTCARDMonitor.exe11Mbps PC Card based wireless LAN connection monitor - possibly from Deutsche TelekomNo
SkinClockUDTClock.exeDesktop Tray Clock by Drive Software - "highly customizable, feature-rich clock that takes the place of the standard Windows clock on your system tray"No
DT HPWUDTHtml.exeHP My Display from HP. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface"No
DT TaskUDTHtml.exeDisplay Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface." Also licensed and renamed by manufacturers such as Gateway (EzTune), HP (HP My Display), Hyundai ImageQuest (ImageTune), LG (forteManager) and ViewSonic (PerfectSuite™ Plus)No
EzTuneUdthtml.exeEzTune from Gateway. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface"No
forteManagerUdthtml.exeforteManager from LG. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface"No
ImageTuneUdthtml.exeImageTune from Hyundai ImageQuest. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface"No
PerfectSuiteUdthtml.exePerfectSuite™ from ViewSonic. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface"No
Iomega Backup SchedulerNdtiom98.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start → ProgramsNo
DAEMON Tools LiteNDTlite.exeDaemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a reboot. This version is free for personal use and has a limited feature setYes
DTliteNDTlite.exeDaemon Tools Lite - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a reboot. This version is free for personal use and has a limited feature setYes
EDLoaderNDTLoader.exeEffective Desktop from MiniStars Software - desktop management software no longer being supportedNo
atuvpUdtor.exeEZKeylogger keystroke logger/monitoring program - remove unless you installed it yourself!No
[various names]XDTOURS.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
DAEMON Tools Pro AgentNDTProAgent.exeSystem Tray access to an older version of DAEMON Tools Pro - used to create an image of a CD/DVD/Blu-ray disc and mount the created image-file (.iso, .bin, etc) to a virtual CD/DVD/Blu-ray drive. The original can be stored in a safe place and the loading times are significantly reduced as the virtual drive is much faster. Required if you use the automount feature to reload images on a rebootNo
DT 11Mbps WLAN USB StationUDTUSBMonitor.exe11Mbps USB based wireless LAN connection monitor - possibly from Deutsche TelekomNo
WinFastDTVUDTVSchdl.exeScheduler for LeadTech WinFast DTV digital TV productsNo
DirectX For Microsoft WindowsXdtxservice.exeAdded by the PROGENT TROJAN!No
DualVaccineXDualVaccine.exeDualVaccine rogue security software - not recommended, removal instructions hereNo
No-IP DUCUDUC20.exePart of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut availableNo
duckXduck.exeAdded by the AGOBOT-AVG WORM!No
Direct UpdateUDUControl.exeDirectUpdate dynamic DNS updaterNo
DU MeterNDUMeter.exeHagel Technologies internet bandwidth monitorNo
Dumeter ServicesXdumeter.exeAdded by the SDBOT-AEQ WORM!No
NWEReboot?dummy.exe??No
dumprepXdump-k.exeAdded by the BUZUS-U WORM!No
DumpXDump.exeAdded by the ZIMUSE WORM!No
dumprepXdump.exeAdded by the CODOX-A WORM!No
KERNELFAULTEXXdumpkernel.exeDetected by McAfee as Downloader.a!d2y! and by Malwarebytes Anti-Malware as Trojan.AgentNo
vmregXdumpre.exeDetected by Dr.Web as Trojan.Siggen3.64173 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
dumprep 0 -kNdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way outNo
kernelfaultcheckNdumprep 0 -kUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way outNo
dumprep 0 -uNdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way outNo
UserFaultCheckNdumprep 0 -uUsed in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way outNo
DUN_SERVICES3Xdun3.exeAdded by the SOKIRON TROJAN!No
CVHOSTXDung.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
dunniscezugxXdunniscezugx.exeDetected by McAfee as Downloader.a!dc3 and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
WindowsUpdateDirectXdupadirect.exeAdded by the DUPA-C TROJAN!No
WindowsUpdateX[path to file]Added by the DUPA-B TROJAN!No
DoUWantItNduwi.exeDoUWantIt - online shopping assistant. Start it manuallyNo
DUX StartXDUX.exeDetected by Malwarebytes Anti-Malware as Trojan.Keylogger. The file is located in %CommonAppData%\XOQCUENo
duxurlarfakkXduxurlarfakk.exeDetected by McAfee as Downloader.gen.a and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
Driver Control Manager v5.1Xdvadescetr.exeAdded by the AGENT-OVL TROJAN!No
Device SecurityXdvcsecure.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
Device Security ManagerXdvcsecure.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
DVD43UDVD43.exeDVD43 is a small tool that overrides CSS copy-protection found on DVD moviesNo
dvd43NDVD43_Tray.exeDVD43 is a small tool that overrides CSS copy-protection found on DVD moviesNo
DVD@ccessNDVDAccess.exePart of DVD Studio Pro from Apple Inc. - "The DVD@CCESS feature allows you to add additional interactivity to your DVD title when it is played on a computer"No
DVDAgent?DVDAgent.exeFound on the HP Touchsmart range of desktops and notebooks. What does it do and is it required?No
Modulo_Ad_AutorizadorXDVDAgent.exeAdded by the VB.WWI TROJAN!No
DVDBitSetUDVDBitSet.exeDVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always usedNo
DVD Check?DVDCheck.exeRelated to an old Intervideo (now Corel) program. What does it do and is it required in startup?No
DVDCheck?DVDCheck.exeRelated to an old Intervideo (now Corel) program. What does it do and is it required in startup?No
WatchDog?DVDCheck.exeRelated to an old Intervideo (now Corel) program. What does it do and is it required in startup?No
DvdcompatXDvdcompat.exeAdded by the GEMA TROJAN!No
DVDFab PasskeyNDVDFabPasskey.exe"DVDFab Passkey by Fengtao Software Inc. - "is a great DVD/Blu-ray decrypter which is powerful to remove almost all known DVD and Blu-ray copy protections to decrypt any protected DVD/Blu-ray and allows you to watch them freely, or use any other software to access and edit the movie content as you like"No
DVDXGhostNDVDGhost.EXEDVD Ghost - "utility to make your software DVD players and DVD copy/backup softwares restriction-free, and copy/backup DVD to hard disk"No
DVDLauncherNDVDLauncher.exePart of Cyberlink's Power Cinema - allows you to play DVDs upon insertionNo
UltraDVDMon?DVDMon.exeUltraDVD DVD player software - is it required?No
[random name]Xdvdplay.exePurityScan adwareNo
DvdPlayerXDvdPlayer.exeDetected by Dr.Web as Trojan.KillProc.23363No
DVDTrayNDVDTray.exeHP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmwareNo
DVD UpgradeXdvdupgd.exeAdded by a variant of the IRCBOT BACKDOOR!No
DVDUpgradeNDVDUpgrd.exeMicrosoft program to upgrade your DVD decoder program - see Q306331. Available via Start → ProgramsNo
DVDXGhostUDVDXGhost.EXEDVD X Ghost - "utility to make your software DVD players and DVD copy/backup softwares restriction-free, and copy/backup DVD to hard disk"No
Microsoft Time ManagerXdveldr.exeAdded by the RBOT-HQ WORM!No
Java UpdateXDVhVSMebyisyuHXYtv.exeDetected by McAfee as Generic Dropper!fhvNo
Windows Automatic UpdatesXdvldr.exeAdded by the RBOT.MF WORM!No
messngerXDvldr32.exeAdded by the DELODER.A WORM!No
AidemHotKey?DVMAIN.EXEKeyboard relatedNo
Dvp95YDvp95.exeScan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engineNo
dvpapi9xYDVPAPI9X.exePart of Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch)No
LoadDvpApi9xYDVPAPI9X.exePart of Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch)No
DvpInitExeYDvpinit.exePart of Command AntiVirus for 9x/Me by Command Software Systems, Inc (who became Authentium and are now Commtouch)No
DvprptYDvprpt.exePart of Commtouch Command Antivirus (was Authentium)No
DvraudioXdvraudio.exeAdded by the GEMA TROJAN!No
DriverConfXdvrconf.exeAdded by the AGOBOT-IY WORM!No
DvrvideoXdvrvideo.exeAdded by the GEMA TROJAN!No
DVSyncUdvsync.exeDVSync is the program that allows you to synchronize your daVinci's PDA's data with your Personal Information Manager on the PCNo
D_V_TUdvt.exeDICOM Validation Tool - "DICOM is increasingly being used as the standard communication mechanism when integrating various medical products in a hospital environment"No
D_V_T?dvt.exeInstallation could be a crack/hack to NOD32 - see here. Seen and removed in many logs. Investigate it further and if the file C:\d_v_t.reg is present then it should be fixed. Not to be confused with the DICOM entryNo
DvVideo32Xdvvid32.exeAdded by the TINY.FD TROJAN!No
MSConfigXdvynjmsr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
DataViz Inc MessengerNDvzIncMsgr.exeInstalled with DataViz Documents to Go - which "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"No
DataViz MessengerNDvzMsgr.exeInstalled with DataViz Documents to Go - which "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"No
DownloadWareXdw.exeDownloadWare adwareNo
dwXdw.exeDownloadWare adwareNo
MediaLoadsXdw.exeDownloadWare adwareNo
MediaLoads InstallerXdw.exeDownloadWare adwareNo
sstataXdwdas.exeAdded by the DASDA TROJAN!No
DamedWare ServicesXdwdrce.exeAdded by the RBOT-AOJ WORM!No
{**-**-**-**-**}Xdwdsregt.exeZenoSearch adware variant where ** are random charactersNo
{1C-CC-C5-54-ZN}Xdwdsregt.exeZenoSearch adwareNo
{B7-7D-D0-08-ZN}Xdwdsregt.exeAdded by the AGENT-GBC TROJAN!No
DownloadWare EngineXDwe.exeDownloadWare adwareNo
dwgrunXdwgrun.batAdded by the DWGUN.A VIRUS!No
DWHeartbeatMonitor?DWHeartbeatMonitor.exeInstalled alongside the Desktop Weather by The Weather Channel - which provides current temperature, conditions, alerts, etc. Exact purpose unknown at presentNo
dwintlXdwintl.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\3083No
dwintl.dllXdwintl.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\3083No
WindowsTranslatorUDWinTrsl.exeMicropower Delta Translator English < > Portuguese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet"No
WindowsTranslator_EspanholUDWinTrsl.exeMicropower Delta Translator - Spanish < > Portuguese (Brazilian) version - "an automatic, bi-directional machine translation software system that quickly and automatically translates multiple pages, paragraphs, sentences, phrases or just individual words in documents, letters, memos, faxes, reports, manuals, booklets, publications, spreadsheets, e-mail and even web pages as you browse the Internet"No
Driver WizardNDWLauncher.exeDriver Wizard driver update toolNo
D-Link AirPlus G+ Wireless Adapter UtilityUDWLGTI.EXED-Link DWL-G520+ AirPlus G+ Wireless LAN PCI Adapter configuration utilityNo
aXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserProfile%\DesktopNo
bXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserProfile%\Start Menu\ProgramsNo
cXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %MyDocuments%No
dXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserProfile%\FavoritesNo
dwmXdwm.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %AppData%No
dwmXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
dwmXdwm.exeDetected by Sophos as Mal/Agent-WS. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserTemp%No
dwmsXdwm.exeDetected by McAfee as RDN/Sdbot.bfr!c and by Malwarebytes Anti-Malware as Backdoor.IRCBot. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %WinTemp%\CookiesNo
eXdwm.exeDetected by Dr.Web as Trojan.DownLoader6.5550. Note - this is not the legitimate Desktop Window Manager (dwm.exe) process from Windows 7/Vista which loads as a service and is found in %System%. This one is located in %UserProfile%\Start MenuNo
ezftsXdwm32.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.PS. The file is located in %AppData%\Microsoft\DLL - see hereNo
PSDRVXdwm32.exeDetected by McAfee as RDN/Generic.dx!xw and by Malwarebytes Anti-Malware as Trojan.Agent.PSNo
DigitalWizard MonitorNdwMon.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital contentNo
Sys32bitsXdwmsys.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor.VIT. The file is located in %Root%\twain_32\wiatwain\wiatwainNo
dwmw.exeXdwmw.exeDetected by McAfee as RDN/Generic.tfr and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
dwnXdwn.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
PoliciesXdwn.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Root%\Database\Microsoft\Windows\dwnNo
Creative Media BlasterXdwrdsyetp.exeDetected by Dr.Web as Trojan.PWS.Siggen1.911No
DWPersistentQueuedReportingUdwtrig20.exeUsed to launch Microsoft Error Reporting (DW20.exe) - if, for example, there have been an error downloading malware definition updates for Windows Defender - which gives the user the chance to send the error report to Microsoft to improve their softwareNo
DWQueuedReportingUdwtrig20.exeUsed to launch Microsoft Error Reporting (DW20.exe) - if, for example, there have been an error downloading malware definition updates for Windows Defender - which gives the user the chance to send the error report to Microsoft to improve their softwareYes
dwtrig20Udwtrig20.exeUsed to launch Microsoft Error Reporting (DW20.exe) - if, for example, there have been an error downloading malware definition updates for Windows Defender - which gives the user the chance to send the error report to Microsoft to improve their softwareYes
Watson Subscriber for SENS Network NotificationsUdwtrig20.exeUsed to launch Microsoft Error Reporting (DW20.exe) - if, for example, there have been an error downloading malware definition updates for Windows Defender - which gives the user the chance to send the error report to Microsoft to improve their softwareYes
appsXdx2u12.exeDetected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
DxLoadXDX3DRndr.exeAdded by the GIBE.B WORM!No
RunmeAtStartupXdx5.exeDetected by Microsoft as TrojanDownloader:Win32/Bulilit.ANo
RunmeAtStartupXdx8.exeDetected by Malwarebytes Anti-Malware as Trojan.ChinAd. The file is located in %Root%\Documents and SettingsNo
Dx8compatXDx8compat.exeAdded by the GEMA TROJAN!No
DirectX9 DiagXdx9diag.exeAdded by the RBOT-ALT WORM!No
DeluxeCommunicationsXDxc.exeDeluxe Communications adware - successor to SurfSideKickNo
Direct X Direct3DXdxd3d.exeAdded by a variant of W32/Sdbot.wormNo
dxdiags.exeXdxdiags.exeAdded by the CERTIF-G TROJAN!No
DxDialogXdxdlg32.exeAdded by the VB-CXT TROJAN!No
dxdllregNdxdllreg.exeRegisters with Windows the DLL (Dynamic Link Library) files that are part of Microsoft DirectX9. Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it after a manual installation or after a new application is installed that also installs DirectX9. This entry should only appear once and can cause boot error messages if it remains so remove itYes
DXDllRegExeNdxdllreg.exeRegisters with Windows the DLL (Dynamic Link Library) files that are part of Microsoft DirectX9. Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it after a manual installation or after a new application is installed that also installs DirectX9. This entry should only appear once and can cause boot error messages if it remains so remove itYes
dxmsrvXdxmsrv.exeAdded by an unidentified WORM or TROJAN!No
Direct X OpenglXdxopengl.exeAdded by a variant of the RBOT-CJ WORM!No
Service ManagerXdxsound.exeDetected by McAfee as Proxy-GricNo
DxstyXDxsty.exeAdded by the GEMA TROJAN!No
DirectX Video DriverXdxterm5.exeAdded by the WILAB-A TROJAN!No
Dxupdate.exeXDxupdate.exeAdded by the MAFEG WORM!No
dxvidXdxvid.exeAdded by the DLUCA-Y TROJAN!No
fddddHOMEXdxxatp.exeAdded by the RANKY.AA TROJAN!No
Dynamic DHCPXdydhcp.exeAdded by the RINBOT.B BACKDOOR!No
STARTUPXdylan.exeDetected by McAfee as RDN/Spybot.bfr and by Malwarebytes Anti-Malware as Backdoor.AgentNo
DynDNS UpdaterUDynDNS.exeDynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.orgNo
Symantec Antivirus professionalXdyndns.exeAdded by a variant of the FORBOT WORM!No
Dynamic Dns BinaryXdynitora.exeAdded by the RBOT-WT WORM!No
DynHttp Dns BinaryXdynizari.exeAdded by the RBOT.AUO WORM!No
DynSiteUDynSite.exeDynSite - dynamic DNS client, also called an automatic IP updaterNo
Dynu Basic ClientUdynubas.exeDynu online dynamic IP update client. Useful when using a dial up modemNo
DynDNS UpdaterUDynUpPs.exeDynDNS Updater from Dynamic Network Services - "is a lightweight application designed to keep hostnames in DynDNS' free and paid DNS services up-to-date with your current IP address. This allows one to run Web or e-mail services at home, even on a dynamic IP address"No
boqamahXdytevevi.exeAdded by the SDBOT-UH WORM!No
disgxXdywwif.exeAdded by the SDBOT.BGF WORM!No
SwdaswdwXdywwif.exeAdded by the SDBOT.BGF WORM!No
yoinkXdywwif.exeAdded by the SDBOT.BGF WORM!No
DZKillMe?DZSAVEME.EXE??No
Windows Reg ServicesXd_service.exeDetected by Microsoft as Backdoor:Win32/ProratNo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home