| Name | Status | Filename | Description |
|---|
| E-MU Audio Service (emaudsv) | L | emaudsv.exe | Related to E-MU_Audio Service from E-MU Systems Sound Libraries. Note: Located in \%WINDIR%\System32\ |
| E6F7BD90 | X | Random_Name.exe | Troj/BDoor-ADP
|
| E8CA85CC | X | E8CA85CC.EXE | Troj/JD-A Read the link, steals information |
EarthLink Firewall Process Path Service (ElnkFWPPService) | L | EFWPPS~1.EXE | Related to EarthLink_Firewall Process. Note: Located in C:\Program Files\EarthLink\Protection Control Center\ |
| EarthLink Monitor Service (EarthLinkMonitor) | L | wmonitor.exe | Related to Total_Access from EarthLink and SIMPLIFY WI-FI from Boingo Note: Located in \%Program Files%\EarthLink TotalAccess\WENGINE\ |
EarthLink Protection Control Center Service (ELNKService) | L | ELNKServ.exe | Related to EarthLink_Protection_Control Center Service. Note: Located in C:\Program Files\EarthLink\Protection Control Center\ |
| EarthLinkSafeConnectAgent | L | SanaAgent.exe | Part of the EarthLink protection center |
| Earthworks License Manager | L | ewlicense_manager_nt.exe | Software application for mining and related extractive industries and produces two ranges of products under the Datamine and Earthworks labels.
Note: Located in C:\Program Files\Common Files\Earthworks
|
| Earthworks License Services | L | LicenseServicesNT.exe | Software application for mining and related extractive industries and produces two ranges of products under the Datamine and Earthworks labels.
Located in C:\Program Files\Common Files\Earthworks
|
| Easy File & Folder Protector (ACDService) | L | EFPAP.exe | Easy_File_&_Folder_Protector Deny access to certain files and folders, or to hide them securely from viewing and searching |
EasyBits Magic Desktop Services for Windows NT (ezntsvc) | L | ezNTSvc.exe | Related to EasyBits_Magic_Desktop Services. Provides a safe way to share computers with children. Note: Located in \%WINDIR%\System32\ |
| EasyBoxApache | L | Apache.exe | Related to Apache web server Note: Located in \%Program Files%\EasyBox\Apache\ |
| eBoostr Service (EBOOSTRSVC) | L | EBstrSvc.exe | Related to eBoostr service from eBoostr.com. allows you to use an additional drive (flash memory or hard disk) as another layer of performance-boosting cache for your Windows XP®. Note: Located in \%Program Files%\eBoostr\ |
| EC2007 Service 1.40 (EC2007Service) | L | ec27ser.exe | Electronic_Chart_Display_and_Information System (ECDIS). Data production for Electronic Navigational Charts. Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| ECA (cpanel) | X | javapanel.exe | Added by the W32/Tilebot-Y
WORM!
Note: This worm\trojan file is found in the Windows or Winnt folder.
Read the link, rootkit type stealth involved.
|
| EClient | L | Eclient.exe | Related to EClient Wi-Fi network from Ekahau Inc. Note: Located in \%Program Files%\Ekahau\Client\bin\ |
| eDataSecurity Service | L | eDSService.exe | Related to eDataSecurity from Acer. Note: Located in %ROOT%\Acer\Empowering Technology\eDataSecurity\ |
| EditScript Process Monitor (EditScriptProcMon) | L | EditScriptProcMon.exe | Related to EditScript from eScription, Inc. A transcription tools for Computer Aided Medical Transcription streamline workflow and speed document editing using a speech recognition engine. Note: Located in \%Program Files%\eScription\ |
| eDSService.exe (eDataSecurity Service) | L | eDSService.exe | Related to eDataSecurity from Acer. Note: Located in %ROOT%\Acer\Empowering Technology\eDataSecurity\ |
| eEye Application Bus (eeyeevnt) | L | eeyeevnt.exe | Related to eEye Digital Security |
| eEye Retina Engine (RetinaEngine) | L | RetinaEngine.exe | Related to eEye Digital Security |
| eID CRL Service | L | beidservicecrl.exe | Related to Belgium_Identity_Card card reader. Note: Located in \%Program Files%\Belgium Identity Card\ |
| eID Privacy Service | L | beidservicepcsc.exe | Related to Belgium_Identity_Card card reader. Note: Located in \%Program Files%\Belgium Identity Card\ |
| Electronic Arts Licensing (ufoeayeuoqn1) | X | yyebgmvn.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| Electronic Arts Licensing Service | L | EA Licensing Service.exe | Related to EA_Licensing_Service.exe is installed with some games from Electronic Arts. It is required for the games to run. Leave it alone if you want to play any games from EA Note: located in C:\Program Files\Common Files\Electronic Arts Shared\ |
| Electronic Arts Licensing Service (yqaavwiiiza6) | X | wjedvpzzpm.exe | Added by a variant of the Backdoor.Oderoor Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. Note:Random names are used for the service and filename. |
| ELNK Update Service (ELNKUpdateService) | L | UpdateService.exe | Related to EarthLink's protection centre |
| eLock Service (eLockService) | L | eLockServ.exe | Related to eLock service from Acer Empowering Technology. Note: Located in C:\Acer\Empowering Technology\eLock\Service\ |
| EloSystemService | L | EloSrvce.exe | Elo TouchSystems, Inc. - http://www.elotouch.com |
| EloTouchscreen | L | EloTouch.exe | Related to Elo TourchSystems, Inc. |
| elpow_spy | X | elpow_spy.sys | Added by the ElpowKeylogger
Spyware!
Note: This file is found in the System32\drivers folder.
Read the link, rootkit type stealth involved.
|
| Emagic EMI System Tray Service (emitray) | L | emitray.exe | The tray icon of the emagic EMI 2/6 USB audio interface |
| EMCliSrv | L | EMCliSrv.exe | Related to Express_Metrix PC inventory and software usage tracking. Note: Located in C:\WINDOWS\system32\wex4962\ |
| Empty (m_hook) | X | m_hook.sys | Troj/BagleDl-CJ Note: Located in %windir%\system32 Read the link, rootkit stealth involved |
| Enables Java Support (Java) | X | winjava.exe | Added by the W32/Codbot-AA
WORM!
Note: This worm/trojan file is found in the System32 folder. (May use various filenames and will startup with system even in Safe mode.)
|
| Enables Javascript Support (Javascript) | X | javascript.exe | Added by the W32/Codbot-V
WORM!
|
| EnConcertRMS | L | enconcertrms.exe | Related to Xcelera_Echo_Lab_Management Medical services from Philips. |
| Encrypt Local Services | X | svshost.exe | Added by a variant of the SdBot.awe family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| Encryption Service | L | encsvc.exe | Related to Citrix MetaFrame |
| end task (Taskend) | X | Taskend.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ |
| end task (Taskend) | X | Rayfell.exe | Added by a variant of the IRCBOT Note: Located in \%WINDIR%\System32\ Note: Use SDFix under supervision. |
| ENDFORCE Agent API | L | AgentAPI.exe | Related to ENDFORCE from ENDFORCE, Inc. Centraly define endpoint security policies. Note: Located in \%Program Files%\ENDFORCE\ |
Energy Star™ EZ GPO Power Management Configuration Tool (EPA_GPO_PMService) | L | PMService.exe | Related to EZ_GPO_Power_Management from Terra Novum, LLC Note: Located in \%WINDIR%\System32\ |
| eNet Service | L | eNet Service.exe | Related to Empowering_Technology from Acer. Note: Located in \%ROOT%\Acer\Empowering Technology\eNet\ |
| EnGenius Network Analysis Tool | X | winegne.exe | W32/Rbot-GRC Read the link, steals information |
| Entrust Entelligence Logging Service (eelogsvc) | L | eelogsvc.exe | Related to Entrust_Entelligence Logging Service from Entrust. Note: Located in C:\WINDOWS\System32\ |
| Entrust Entelligence Login Service (EELSService) | L | eelssrv.exe | Related to Entrust_Entelligence Logging Service from Entrust. Note: Located in C:\WINDOWS\System32\ |
| Entrust Login Interface (ELIService) | L | etlisrv.exe | Related to Entrust Login Interface service, Made by Entrust
Technologies Ltd. This file is found in the Windows or Winnt folder.
|
| ENUFF Server (ENXPSVR) | L | ENSERVS.EXE | Enuff Parental Control Software by Akrontech |
| ENUFF XP Service (ENXPSVC) | L | CVSEXPSS.EXE | Enuff Parental Control Software by Akrontech |
| EP2005-SAGEM Usb Switcher (EpMonitor) | ? | EpMonitor.exe | Appears to be related to EpMonitor from "Eightfold Technologies" |
| EPAService | L | EPAService.exe | Related to EPAService service. Note: Located in \%ROOT%\epa.epa\ |
| ePerformance Service (AcerMemUsageCheckService) | L | MemCheck.exe | Found on Acer laptops |
| EPGService | L | EPGService.exe | Related to EPG_application for WINTV from Hauppauge Computer Works, Inc. Note: Located in \%Program Files%\WinTV\EPG Services\System\ |
| EPMService | L | EPMService.exe | Related to EPMService service. Note: Located in \%ROOT%\epa.epa\ |
| ePower Service (WMIService) | L | ePowerSvc.exe | Related to Empowering_Technology from Acer. Note: Located in \%ROOT%\Acer\Empowering Technology\ePower\ |
| EPrint III Service | L | LPSVS03N.EXE | Related to LEADTOOLS_ePrint From Lead Tech. Perform additional processing to your print job before sending it to the driver. |
| EPS Printer Driver | X | EPSONSYS.SYS | Added by the Goldun.I
TROJAN!
Note: This trojan file is found in the System32 (NT/2000/XP) folder.
Also look for Winlogon Notify: printpnp - printpnp.dll
|
EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) | L | EpStsSrv.exe | Related to EPSON_ESC/POS Status service by SEIKO EPSON Corp. Note: Located in C:\WINDOWS\SYSTEM32\ |
| Epson Printer Status Agent (StatusAgent) | L | SAgentNT.exe | Related to Epson_Printer Status agent. Note: Located in C:\Program Files\Common Files\EPSON\EBAPI\ |
| EPSON Printer Status Agent2 (EPSONStatusAgent2) | L | SAgent2.exe | detects and configures an Epson Printer Port where applicable |
| Epson Printer Status Agent4 (StatusAgent4) | L | SAgent4.exe | Related to Epson Corp. |
| EPSON V3 Service2(02) (EPSON_PM_RPCV2_02) | L | E_S00RP2.EXE | Related to the EPSON Status Monitor 3 |
| EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) | L | E_S00RP1.EXE | Related to the EPSON Status Monitor 3 |
| EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) | L | E_S30RP1.EXE | Epson status monitor |
| EpsonBidirectionalAgent | L | eEBAgent.exe | Related to eEBAgent a process installed alongside Epson Status Agent and provides additional configuration options for these devices. Note: Located in \%Program Files%\EPSON\ESM2\eEBAgent.exe
|
| EpsonBidirectionalService | L | eEBSVC.exe | Related to Epson printers. |
| EQ Shared Engine (EQSharedEngine) | L | EQSharedEngine.exe | Related to EQ_Shared_Engine from Equitrac Corp. Reduce print waste and cost. Note: Located in \%Program Files%\Equitrac\Office\Client\ |
| Eraser Service (EraserThread) | L | erasrv.exe | Related to Evidence_Exterminator from Softstack.com Allows for complete removal of data from your hard drive. Note: Located in \%Program Files%\Evidence Exterminator\ More here |
| eRecovery Service (eRecoveryService) | L | eRecoveryService.exe | Related to eRecoveryService Management from Acer Empowering Technology Note: Located in C:\Acer\Empowering Technology\eRecovery\ |
| Error Monitor Service | X | svshost.exe | A variant of the BackDoor.SdBot family of worms and IRC backdoor Trojans. Note: Located in \%WINDIR%\System32\ |
| eScan Monitor Service | L | avpm.exe | eScan Antivirus |
| eScan Server-Updater | L | TRAYSSER.EXE | eScan antivirus |
| Escritorio remoto compartido de NetMeeting (mnmsrvc) | L | mnmsrvc.exe | Spanish Windows 2000 Netmeeting remote desktop sharing service |
| Eset HTTP Server (EhttpSrv) | L | EHttpSrv.exe | ESET_Smart_Security |
| Eset Service (ekrn) | L | ekrn.exe | ESET_Smart_Security |
| eSettings Service (eSettingsService) | L | capuserv.exe | Related to Empowering_Technology from Acer. Note: Located in \%ROOT%\Acer\Empowering Technology\eSettings\Service\ |
| Esker FTPD (ftpds) | L | WFTPDSNT.EXE | Related to Esker software |
| Esker License Control (EskerLicenseControl) | L | eslcbcst.exe | Related to Esker License control |
| Esker LPD (lpds) | L | WLPDSNT.EXE | Related to Esker software |
| Esker NFSD (nfsds) | L | WNFSDSNT.EXE | Related to Esker software |
| ESRI License Manager | L | Lmgrd.exe | Related to Macrovision application-generic license server. Note: Located in \%Program Files%\ESRI\License\ESRI.ArcGis.83.desktop.crack.(work)\ |
| Estacióe trabajo | L | services.exe | Spanish Windows 2000 "workstation" |
| ET54FG | X | ET54FG.SYS | Added by the TROJ_ROOTKIT.N
TROJAN!
Read the link, rootkit type stealth involved.
|
| eToken Notification Service (ETOKSRV) | L | eTSrv.exe | Related to eToken Notification Service from Aladdin Knowledge Systems, Ltd. Authentication and password management. Note: Located in C:\WINDOWS\system32\ |
| eTrust Antivirus Admin Server (InoNmSrv) | L | InoNmSrv.exe | Related to eTrust_Antivirus Admin Server from Computer Associates Int. Note: Located in \%Program Files%\CA\eTrust Antivirus\ |
| eTrust Antivirus Job Server (InoTask) | L | InoTask.exe | Associated with eTrust Antivirus/InoculateIT |
| eTrust Antivirus Realtime Server (InoRT) | L | InoRT.exe | Related to eTrust's AntiVirus Internet Security solution. |
| eTrust Antivirus Realtime Service (InoRT) | L | InoRT.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\CA\eTrustITM\ |
| eTrust Antivirus RPC Server (InoRPC) | L | InoRpc.exe | Associated with eTrust Antivirus/InoculateIT |
| eTrust InoculateIT Job Server (InoTask) | L | InoTask.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\\CA\eTrust\InoculateIT\ |
| eTrust InoculateIT Realtime Server (InoRT) | L | InoRT.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\\CA\eTrust\InoculateIT\ |
| eTrust InoculateIT RPC Server (InoRPC) | L | InoRpc.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\\CA\eTrust\InoculateIT\ |
| eTrust ITM Job Service (InoTask) | L | InoTask.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\CA\eTrust\eTrustITM\ |
| eTrust ITM Realtime Service (InoRT) | L | InoRT.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\CA\eTrust\eTrustITM\ |
| eTrust ITM RPC Service (InoRPC) | L | InoRpc.exe | Associated with eTrust Antivirus/InoculateIT from Computer Associates International Note: Located in \%Program Files%\CA\eTrust\eTrustITM\ |
| EUQ_Monitor | L | EUQMonitor.exe | Related to a Trend Micro product |
| Event Log Watch (LogWatch) | L | LogWatNT.exe | Computer Associates |
| Event Monitor (evmon) | X | spoolcll.exe" -netcvs | Added by the W32.Spybot.IVQ WORM! |
| EvtEng | L | EvtEng.exe | Related to Intel Corporation |
| ewido anti-spyware 4.0 guard | L | guard.exe | Related to ewido_suite Note: located C:\Program Files\ewido anti-spyware 4.0/ |
| ewido security suite control | L | ewidoctrl.exe | Related to ewido networks |
| ewido security suite guard | L | ewidoguard.exe | Related to ewido networks |
| Examinador de equipos | L | services.exe | Spanish Windows 2000 computers browser |
| ExecView Communication Module (ECM) (ECM Service) | L | ECM.exe | Related to VERITAS_ExecView
|
| Exten. controlador Instrumental de admon. de Windows | L | services.exe | Spanish Windows 2000 windows management instrumentation drive extension |
| Extend360 Agent (ServiceMgr) | L | ServiceMgr.exe | Related to Fiberlink's Extend360 TM mobile Note: Located in C:\Program Files\Fiberlink\Extend360\ |
Extended Windows Security (Microsoft Extended Windows Security) | X | elRecvr.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\ (Win9x/Me), C:\%WINDIR%\ (XP/WinNT/2K) |
| Extensible Authentication Protocol (EapHost) | L | eapsvc.dll | Part of Windows Vista
Note:Located in C:\%WINDIR%\System32 |
| Externtelecom | X | extel.exe | Added by the W32/Sdbot-AAX
WORM!
Read the link, rootkit type stealth involved.
|
| Eyeline Service (EyelineService) | L | eyeline.exe | Related to Eyeline_Service from NCH Swift Sound. Note: Located in \%Program Files%\NCH Software\Eyeline\ |