Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Esoh Esoh123.exe"Added by the AGOBOT.FF WORM!"
X Especial Deneca.bat"Added by the DELUZ VIRUS!"
N ESPN BottomLine bline.exe"ESPN BottomLine. ""You can dock the BottomLine to the top or bottom of your screen or drag it around on your desktop without even worrying about a browser. As long you keep the BottomLine running you will continue to receive live scores and breaking news and by clicking on any score or news item you will be taken directly to the corresponding page on ESPN.com for a full break down."""
? ESS Daemon Essd.exe"Related to an ESS based soundacard. Is it required?"
? essapm essapm.exe"ESS Solo soundcard driver. Is it required?"
Y Essdc essdc.exeRelated to an ESS Solo soundcard. Seems as though it's required
? ESSNDSYS ESSNDSYS.EXE"Related to an ESS based soundacard. Is it required?"
Y ESSOLO ESSOLO.exeSound card driver that re-instates itself every time it's removed
Y esspk esspk.exeESS Technology modem speaker driver file. Required to get on-line with this modem
U EssSpkPhone essspk.exeESS Technologies Call waiting which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
? eSupInit eSupCmd.exe"Related to SupportSoft (aka Support.com) ""Real-Time Service Management software"". What does it do and is it required?"
X ETB Tester etbtest.exe"Added by the RBOT-ABR WORM!"
X etbrun elit***32.exe [* = random char]"EliteBar adware"
U eTCertManger eTCrtMng.exe"eToken Certificate Manager from Aladdin Knowledge Systems Inc. A USB-based authentication providing strong user authentication and password management solutions"
N Ethernet tcaudiag.exe3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start -> Programs
X ethernet airftp.exe"Added by a variant of the SDBOT WORM!"
X ethernet msnger.exe"Added by a variant of the SDBOT WORM!"
X ethernet msftp.exe"Added by the SDBOT.BXJ WORM!"
X ethernet adapter csrmss.exe"Added by a variant of the RBOT WORM!"
X Ethernet Driver cmsrrs.exe"Added by a variant of the RBOT WORM!"
X Ethernet Drivers smrrs.exe"Added by the RBOT-AAK WORM!"
X Ethernet Drivers ethernet.exe"Added by the GAOBOT.CEZ WORM!"
X Ethernet Linking ethernet.exe"Added by a variant of the IRCBOT TROJAN!"
X Etraffic JavaRun.exe"TopMoxie adware"
Y eTrust EZ Firewall efpeadm.exe"eTrust EZ Firewall"
U eTrust PestPatrol Active Protection PPActiveDetection.exe"PestPatrol real-time protection feature. ""Stops spyware before it infects your system"""
X eTrust Realtime Monitor realmon.exe"Added by the LAZAR.B TROJAN!"
Y eTrustCIPE ezdsmain.exeeTrust EZ Deskshield from Computer Associates. Protects against malicious email attachments and unauthorized use of email by detecting and blocking unusual behavior
X eTunnel winfw.exeAdded by an unidentified TROJAN!
U Eudora Eudora.exe"Eudora from Qualcomm allows you to receive and send Internet e-mails"
X EUP Service eupsvc.exe"Added by the DELBOT-Q WORM!"
U EuroGlot EuroGlot.exe"Euroglot - ""multilanguage translating system available in the languages Dutch English French German Spanish and Italian"""
? Event Log eventlog.exe"??"
N Event Planner Reminders PLNRnote.exeSierra Event Planner tray icon
N Event Reminder pmremind.exeA calendar/alarm program that installs with Br?derbund Printmaster
X EventApplicationCmd smschk.exe"Added by the IRCBOT-AO TROJAN!"
U EVENTLISTENER EvLstnr.exeUsed with a Nikon digital camera to recognize when the camera is plugged in
N eventmgr eventmgr.exeUsed with a Microtek scanner. Manages the scanner's button events. Available via Start -> Programs
X eventwvr eventwvr.exe"Added by the COSIAM_G TROJAN!"
? EverioService EverioService.exe"Related to the Cyberlink software supplied with JVC's Everio camcorders. What does it do and is it required?"
U Evidence Cleaner ecleaner.exe"Evidence Cleaner cleans up tracks left by your PC and Internet activities"
N Evidence Eliminator ee.exe"Evidence Eliminator - cover the tracks of your browsing habits and E-mails if you think you need to. Run manually on a regular basis"
X Evil Evil.exe"Added by the MYTOB.JM WORM!"
N evntsvc evntsc.exe"Application Scheduler installed along with RealOne Player. Once installed it runs independently of RealOne Player. See here for more information including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK"
U EVOLOSTA EVOLOSTA.EXEEvolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID peer-to-peer mode channel link speed WEP encryption options and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher as they have this built-in to the control panel. Also if the user is very sure that there is ONLY ONE network available to connect to then they can remove this. If it is not in startup and the user needs to run it they can simply type EVOLOSTA in the Start -> Run dialog to run it
U Evoluent Mouse Manager EvoMouExec.exe"Mouse manager for Evoluent VertcialMouse"
X EvtHtm evthtm.exe"Added by the DLUCA-EJ TROJAN!"
U EW Message Server msg32.exeConexant (older versions are Brooktree) Wavestream Message Server - associated with Conexant based audio devices
N eWare Startup iWareStart.exe"eWare iWare task bar. Not required"
X ewupdater ewupdater.exe"EasyWebSearch adware updater"
X example [random filename].exe"Added by the NUCLEAR TROJAN! Note - this trojan file is found in the WindowsNR or WinntNR folder"
N Excite Platform Exlaunch.exeLoads an Icon in the startup tray that allows you to receive service update notices for Excite@Home if you desire (note that since Excite@Home appears to be winding down this becomes irrelevant). May also allow you to kill the Excite Toolbar that automatically loads in Internet Explorer
? Excite Private Messenger Pipe x8impipe.exe"??"
N ExciteAssistantEXE ASSISTANT.EXEWith Excite Assistant you can access a wide variety of online information including email news and stock quotes without having to have a browser window open
X exdl.exe exdl.exe"BargainBuddy adware"
X exe lptt01 exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X exe ml097e exe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X execfg4 execfg4.exe"Added by the ELECTRON WORM!"
X ExecUser ExecUser.exe"Added by a variant of the RBOT WORM!"
? Execute delfolders.exe"??"
X ExeName32 Warm.scr"Added by the SCOLD WORM!"
X ExFilter Rundll32.exe [path] cdnspie.dll ExecFilter"CNNIC Update pest"
? exgiwsl exgiwsl.exe"??"
U Exif Launcher Exiflaquickdcr.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U Exif Launcher QuickDCF.exeUSB mass storage driver used by some digital cameras such as the Fuji Finepix. Only required if you use it regularly
U ExitKiller Ekiller.exe"Exit Killer - automatically closes pop-up windows in your browser"
? exmon hpimoniter.exe"Some kind of hp digital camera maybe or a photo smart connection probe?"
X Exn exn.exe"Added by the IRCBOT.RJ WORM!"
X exo.exe exo.exe"Added by the AGOBOT.ALD WORM!"
X Expatch [random filename]"Added by the PWSLMIR-G TROJAN!"
X expcrt [random filename]"Added by a variant of the SLAPER TROJAN!"
X ExpertAntivirus ExpertAntivirus.EXE"ExpertAntiVirus misleading antivirus program - not recommended see here"
X EXPL0RE.EXE EXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
X Expl0rer soft expl0rer.pif"Added by the RBOT-AQR WORM!"
X expler Updadv.exe"Added by the QQPASS-N TROJAN!"
X Explkw expup.exeKeywords hijacker
X explord.exe explord.exe"Added by the DLOADR-AYW TROJAN!"
X explore explore.exeAdded by any number of VIRUSES WORMS or TROJANS!
X Explore Explorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X Explore explore.exeAdult content dialler
X explore manager explore.exe"Added by the DONBOMB.A TROJAN!"
X explore.exe Explore.exe"Added by the GRAYBIRD.G TROJAN!"
X exploreff.exe exploreff.exe"Added by the FINFANSE TROJAN!"
U explorer explorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
X explorer wscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
X Explorer shellexpl.exe"Added by the SHELDOR TROJAN!"
X explorer expl32.exe"Added by the RATSOU TROJAN!"
X Explorer [path to worm]"Added by the AUTEX WORM!"
X Explorer shellexp.exe"Added by a variant of the SHELDOR TROJAN!"
X EXPLORER EXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
X EXPLORER sys.exe"Added by the SILLYFDC-A TROJAN!"
X Explorer config_.com"Added by the FLOPPY-D WORM!"
X Explorer drv.exe"Added by the SMALL-FD TROJAN!"
X explorer [path to trojan]"Added by the AGENT-EU TROJAN!"
X explorer explorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
X EXPLORER EXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
X explorer explorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
X explorer Yinstall.exe"PurityScan/Clickspring adware"
X Explorer Windows Explorer.exe"Added by the SILLYFDC-I WORM!"
X Explorer explorar.vbs"Added by the DESKTO-A WORM!"
X Explorer Loader explr32.exe"Added by the AGOBOT.N WORM!"
X Explorer Loader explorerl.exe"Added by the SDBOT-ADI WORM!"
X Explorer lptt01 explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
X EXPLORER MICROSOFT SYSTEM explore.exe"Added by a variant of the RBOT WORM!"
X Explorer ml097e explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
X Explorer soft explorer.pif"Added by the RBOT-APK WORM!"
X Explorer soft explorer.com"Added by the RBOT-ARM WORM!"
X Explorer Updater IEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X explorer.exe explorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
X explorer.exe explorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
X Explorer.exe csrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
X Explorer32 Expl32.exe"Added by the HACKTACK.B TROJAN!"
X Explorer32 explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
X Explorer32 efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
X Explorer5 config_.com"Added by the VB.CBG WORM!"
X Explorer6.1.EXE Explorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
X ExploreUpdSched [random filename]"ZenoSearch adware"
X exporet winset.exe"Added by the QQPASS-I TROJAN!"
U Express ClickYes ClickYes.exe"""Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt that asks you to confirm mail sending from third party applications"""
U Exshow95 EXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
N Extender Resource Monitor RMSysTry.exe"Related to Windows Media Center from Microsoft"
X External Dependencies External.exe"Added by the MYTOB.EC WORM!"
U ExtraDNS ExtraDNS.exe"ExtraDNS - DNS configuration tool"
N ExtraFilmHemmaAgent Agent.exe"ExtraFilm Photo Assistant"
? Extranet AutoDial AutoExt.exeNortel Networks Contivity Extranet Switching Software
? ExxtremeHelperDemon exxdemon.exe"Creative Exxtreme graphics card related?"
N Eye Tide Launcher oneeyetideone.exeNascar wallpaper
X EYORE Notepad.scr"Added by the GIMLET-A WORM!"
Y EZ Firewall ca.exe"eTrust EZ Armor Internet Security"
U EZ-DUB Finder EZ-DUB.exe"Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation"
N ezagent ezagent.exe"EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs"
N EzButton EzButton.EXEEZbutton is a quick launcher for the Media player app that comes with certain laptops
N EZDesk EZDESK.EXE"Utility that remembers icon locations for each user and resolution. Available here"
N EzEjMnAp EzEjMnAp.exe"For IBM Thinkpad Notebooks. Quote: ""The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once rather than stopping each device individually"". Available via Start -> Programs"
N ezHelper ezHelper.exe"Part of the ezPeer+ ezHelper music sharing program."
X eZmmod mmod.exe"eZula TopText adware"
? EZNORUN EZNORUN.EXE"Easy Internet related?"
N EzPrint ezprint.exeLexmark Fast Pics - helps users of their printers to enhance print and manage their photos quickly and easily
Y ezPS_Px ezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezPS_Px ezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezShieldProtector for Px ezSP_Px.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
Y ezShieldProtector for Px ezSP_PxEngine.exe"Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings"
U EZSMART App ezsmart.exeEZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported
X ezula eZmmod.exe"eZula TopText adware"
X eZulaMain eZulaMain.exe"eZula TopText adware"
X eZuluMain eZuluMain.exeComes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work
X eZWO wo.exe"eZula TopText adware"
U E_S10IC2 E_S10IC2.EXEEpson Status Monitor 3 for the Stylus C44 Series printer - for monitoring printer status checking ink levels etc
U E_S23 E_SICN03.exeEpson printer status monitor - for checking ink levels etc.
U E_S4I2F1 E_S4I2F1.EXEEpson Status Monitor 3 for the Stylus Photo R300 Series printer - for monitoring printer status checking ink levels etc
U E_S4I2G1 E_S4I2G1.EXEEpson Status Monitor 3 for the Stylus CX5400 printer - for monitoring printer status checking ink levels etc
U E_SOEIC1 E_SOEIC1.exeEpson Status Monitor 3 - for monitoring printer status checking ink levels etc
U E_S[numbers] [path] E_[various].EXE [path] E_S[numbers].tmpTemporary entry related to Epson Status Monitor 3 for their range of printer and AIO devices - for monitoring printer status checking ink levels etc
X f ftkclean.exe"FlashEnhancer adware"
U F-PROT Antivirus Tray application FProtTray.exe"System Tray access to F-PROT Antivirus"
X F-Secure 2005 svchost.exe"Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
Y F-Secure 2006 fspex.exe"F-Secure Anti-Virus automatic updater"
U F-Secure Management Agent FSMA32.EXE"F-Secure antivirus - F-Secure Policy Manager provides tools for administering F-Secure software products"
Y F-Secure Manager FSM32.EXE"F-Secure antivirus - carry out scheduled virus scans automatically"
Y F-Secure Startup Wizard FSSW.EXE"F-Secure antivirus"
Y F-Secure TNB TNBUtil.exe"F-Secure antivirus"
Y F-StopW F-StopW.exe"F-Prot anti-virus background scanner by F-Risk Software"
U f1Tray.exe F1TRAY.EXE"System Tray icon for FusionOne's MightyPhone software. ""MightyPhone is a concept for wirelessly synchronizing the data on your mobile phone with your web-based or PC based organizer"""
? f23mxins f23mxins"Related to the now discontinued ATI Fire GL3 graphics card. What does it do and is it required?"
X f607 f607.exe"Added by the URAT.B TROJAN!"
X f73cdc8ee94e btsendto.exeAssociated with mysearchnow.com/searchbar.html
X f94mggfhfghodftdf [path to trojan]"Added by the SMALL.JHZ TROJAN!"
U Fabrik Ultimate Backup Status fabrikhomestat.exe"Status monitor for Fabrik Ultimate Backup from Fabrik Inc. ""No matter what happens to the drive on your desk - a spilled drink a curious toddler a theft or a natural disaster - you know your files are still safe and secure on Fabrik Ultimate Backup's off-site servers"""
U FamilyKeyLogger cisvc.exe"Family Keylogger keystroke logger/monitoring program - remove unless you installed it yourself! Located in %System%\CTF"
X Fantasia injector wincfg.exe"Added by the AGOBOT.US WORM!"
? fapmon fapmon.exe"Fair Access Policy monitor for DirecPC/DirecWay internet access"
X farkrish farkrish.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X farmmext farmmext.exe"VX2.Transponder parasite updater/installer related"
X Fash Fash.exeUnidentified adware
X faslkakj11 kjgagklj11.exe"Added by the LEGMIE-ARE TROJAN!"
N fast fast.exeInstalls as part of Windows XP PowerToys as an option for very-fast user switching (allowing a keystoke to switch users instead of using the login screen). It is only used for the hot-key switch and yet it hogs 1.5 megs of memory in two separate processes (one run by the user & one by the system). Optional install in PowerToys
N FAST Defrag FAST2.EXE"FastDefrag defragmenting software"
X Fast Home svcnvt.exe"Detected by Kaspersky as the DELF.KS TROJAN! This file may be found in the System folder on 9x machines however as of this writing it has only been seen in the System32 folder"
X Fast Search svcnv.exeHomepage Startpage hijacker. Possible variant of Trojan-Downloader.Win32.Delf
X Fast start Ntut.exe"Adware - deteced by Kaspersky as the FAVADD.I TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list