| Name | Status | Filename | Description |
|---|
| Explorer64 | X | efsdfgxg.exe | Added by the Troj/Clicker-AA
TROJAN!
Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| erthgdr2 | X | svc23.exe | Added by the BAGLE.CG WORM! |
| EPSON Stylus CX9400Fax Series | U | E_FATICFA.EXE | Related to Epson Status Monitor for Stylus CX9400Fax Series. Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| Error Safe | X | ers.exe | ErrorSafe security risk that may give exaggerated reports of threats on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats
|
| EFI Hot Folders | U | hffw.exe | Related to EFI Production Printing Solutions from Imaging inc. Note: Located in \%Program Files%\FIERY\HotFolder\ |
| ElsaCapiCtl | Y | Rcapi.exe | Assumed to stand for Remote Common Application Programming Interface (RCAPI), this was installed with an Elsa Microlink ISDN modem. If it is not there you can not bring up the dialog box which is sometimes needed to reset the modem |
| Edzy AntiVirus | X | dppsfa.exe | Added by a variant of W32/Rbot-GLY WORM! Note: This worm is located in \%WINDIR%\System32\ Read the link, allows remote access (random filename) used |
| explorer | U | explorer.exe | Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a WORM! such as PE_BISTRO
or DVLDR
or MYDOOM.B
or Troj/Torpig-A
. Note that it is also not the explorer.exe task/service you'll see when via CTRL ALT DEL |
| Elbycheck | U | ElbyCheck.exe | From Elaborate Bytes who make CloneCD - monitors the installed filters of CD-ROMs/DVD-ROMs. Note - under Win2K removing this from startup causes the CD drive in the computer to not be recognized in the OS and after rechecking it prompts that the driver has been corrupted and asks you to restart the computer to fix it |
| ethernet | X | msnger.exe | Added by a variant of the W32/SDBOT WORM!
|
| eSupInit | ? | eSupCmd.exe | Related to SupportSoft "Real-Time Service Management software" - what exactly does it do and is it required? |
| EPSON Stylus CX8400 Series | U | E_FATICEA.EXE | Related to Epson Status Monitor for Stylus CX8400 Series. Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| E_S10IC2 | U | E_S10IC2.exe | Epson Stylus printer monitor - for checking ink levels, etc. |
| EPSON Stylus C66 Series | U | E_S4I0S2.EXE | Related to Epson Status Monitor for Stylus C66 Series. Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| enginecs2 | U | enginecs2.exe | Cyber_Sentinel Internet filtering software
|
| eFax.com Tray Menu | N | HotTray.exe | eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here |
| erthgdr | X | windll.exe | Added by the BAGLE.BD WORM!
|
| Event Planner Reminders | N | PLNRnote.exe | Sierra Event Planner tray icon |
| EbatesMoeMoneyMaker | X | wjview ...Code | Ebates adware |
| Express ClickYes | U | ClickYes.exe | Related to ClickYes Pro is a tuning tool for Microsoft Outlook security settings. It allows to configure which applications can automatically send emails using Outlook and access email addresses stored in Outlook address book. Note: Located in C:\Program Files\Express ClickYes\ |
| EXPL0RE.EXE | X | EXPL0RE.EXE | Added by the Troj/Popno-A
TROJAN!
Note: Notice that (EXPL0RE.EXE) is spelled using the number 0 instead of the letter O.
This trojan is found in the System (95/98/Me) or System32 (Nt/2000/XP) folder. |
| EzEjMnAp | N | EzEjMnAp.exe | For IBM Thinkpad Notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually". Available via Start -> Programs |
| ExploreUpdSched | X | (random,name).exe | Detected as Adware.ZenoSearch by AVG-antispyware |
| erwghjjrjt | X | ucbcg.exe | Identified as the Trojan-Downloader.Win32.Small.cul Trojan. Note: This trojan is located in \%WINDIR%\System32\drivers\ |
| EPSON Stylus Photo R1800 | U | E_FATI9LA.EXE | Related to Epson Status Monitor for Stylus Photo R1800. Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| ELSA WINman Suite | U | Winmsuit.exe | Allows you to totally customize your ELSA graphics card settings, including overclocking the GPU |
| EnergyPlugIn | X | EnergyPlugin.exe | EnergyPlugin adware variant |
| eTCertManger | Y | eTCrtMng.exe | Related to eToken from Aladdin Knowledge Systems, Inc. A USB-based authentication, providing strong user authentication and password management solutions.
Note: Located in \%WINDIR%\System32\ |
| EasySync Pro | U | XCPCMenu.exe | EasySync Pro is a Lotus (now owned by IBM) program for synchronizing a PDA with Lotus Notes
|
| ECenter | N | EULALauncher.exe | Related to Google's_Toolbar installed on Dell's computer. Note: Located in \%ROOT%\dell\E-Center\ |
| eSafe Protect | Y | ESPWatch.exe | eSafe from Aladdin - internet security for gateway and E-mail servers |
| Encoder Agent | N | WMENCAGT.EXE | MS Windows Media Encoder, which already has a shortcut in the Start Menu if installed |
| Eac_rnvdl | ? | ANTIVIRUS_INSTALL.EXE | ?? |
| EverioService | U | EverioService.exe | Related to Everio_camcorders from JVC. Note: Located in C:\Program Files\CyberLink\PCM4Everio\ |
| EEventManager | N | EEventManager.exe | Part of the Epson Creativity Suite supplied with their multi-function printer/scanners, Event Manager launches File Manager or PageManager for EPSON automatically when you press the B&W Start or Color Start button on the control panel in Scan mode
|
| EPS | N | e_srcv03.exe | According to the Epson info: "Use this utility to automatically check for errors and also check the level of ink remaining." This utility can also be started on demand when about to print as follows: File menu > Print to bring up the print dialog box. Click on the Properties button which will bring up a display with 4 tabs. Click the Utility tab to get a list of utilities that can be executed including the Status Monitor 3 Environment Check |
| EPSON Stylus CX2900 Series | U | E_FATIBFP.EXE | Related to Epson Status Monitor for Stylus CX2900 Series. Note: Located in \%WINDIR%\System32\spool\DRIVERS\W32X86\3\ |
| EasyKey or Easy Key | U | easykey.exe | For programming of the built-in functions keys on some laptops (and maybe desktops). Required if these are used |
| ePrint 3.0 Service | N | EPRINT3.EXE | Related to LEADTOOLS_ePrint File Conversion Software - Convert ANY file to and from over 150 document and image formats including searchable PDF, DOC, HTML, TXT , Multi-page TIFF, JPG, GIF, PNG and many more! - Can be started manually.
Note: located in C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\ |
| exn | X | exn.exe | Added by the WORM_IRCBOT.RJ WORM! Note: This worm is located in C:\%WINDIR%\System32\ (XP/WinNT/2K) |
| element furth | X | [path],repcale.exe,[path],palsp.exe | Added by a variant of the RANDON.AN WORM! |
| ekor.exe | X | igamatu | Added by the BACKDOOR.SDBOT.AQ TROJAN! |
| Energizer FileSaver | U | Energizer,FileSaver.exe | Energizer FileSaver - UPS back-up utility for Energizer UPS products |
| efaxs ml097e | X | efaxs.exe | RapidBlaster Variant |
| EVOLOSTA | U | EVOLOSTA.EXE | Evolo Status Monitor for wireless network cards. Allows a user to enter a specific access-point mode SSID, peer-to-peer mode channel, link speed, WEP encryption options, and has enable/disable and rescan buttons. It is not needed if using Windows XP or higher, as they have this built-in to the control panel. Also, if the user is very sure that there is ONLY ONE network available to connect to, then they can remove this. If it is not in startup, and the user needs to run it, they can simply type EVOLOSTA in the Start -> Run dialog to run it |
| Eroca | X | Eroca.exe | Identified as TrojanDownloader.Matcash Note: Located in \%Program Files%\Eroca\ Note: Use SDFix under supervision. |
| Extranet AutoDial | ? | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software |
| Element | X | Element.txt | Added by the ELEM TROJAN! |
| elitemedia | X | elitemediapop.exe | Added by the LowZone-BB TROJAN! Note: located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) This infection is also known as Elitebar/EliteToolbar/EliteSidebar infection See Here |
| eMailEncryption | N | velozsys.exe | eAcceleration Stop-Sign related; not recommended; see note |
| Ethernet Drivers | X | smrrs.exe | Added by the W32/RBOT-AAK WORM! |
| eBay Toolbar | X | EBAYTBAR.EXE | eBay Toolbar - reportes as spyware as it "phones home" |
| E-nrgyPlus | X | E-nrgyPlus.exe | Added by the Energyplus TRACKWARE! Tracks internet activity including websites visited and queries made at popular search engines. This information along with some system information is sent to a remote site. |
| EYORE | X | Notepad.scr | Added by the W32/Gimlet-A Worm |
| EUP Service | X | eupsvc.exe | Added by the W32/Delbot-Q WORM! Note: Located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |