Name Filename Status Description
Absolute Shield dseraser.exe U Absolute Shield/Evidence Eliminator - iternet history eraser
Adaptec DirectCD Directcd.exe N DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
AdaptecDirectCD Directcd.exe N DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
APC UPS Status Display.exe Y APC PowerChute Personal Edition status icon
BayMgr DockApp.exe U Hot-swappable drive management on laptops allowing you to change drives without closing down Windows. Only required if you frequently swap bay devices 
CCD Manager DDS.EXE U Project Labs Century CD manager for their CD/DVD storage device
CLSID dll.exe X Adult content dialler
Codename Dashboard dashboard.exe U Codename: Dashboard - "an application that resides at the side of your screen. Built on the Microsoft .NET Framework, it is a host for interchangeable components through which C.D. allows you to have any information you want, on your desktop, all the time"
COM+ Event System DRWTSN16.EXE X Added by a variant of the LOVGATE WORM!
Configuration Loader dosrun32.exe X Added by the GAOBOT.AO WORM!
Copernic Desktop Search DesktopSearch.exe N Copernic Desktop Search - "Easily search your entire hard drive in less than a second to pinpoint the right file, e-mail, music or pictures"
Corel Desktop Application Director dadx.exe N The Desktop Application Director (DAD) gives you easy access to all Corel applications - x represents ther version number. Available via Start -> Programs
Crusty dmcpl.exe X Added by the RUSTY WORM!
D066UUtility D066UUTY.EXE N TWAIN driver for the CanoScan D660U flatbed scanner. Start scanning via your scanner management software
D4 D4.exe U Dimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
DACONFIGEXE daconfig.exe N 3Com NIC Diagnostics. Available via Start -> Programs
DadApp dadapp.exe Y "DadApp is the SW utility that controls the programmable buttons on Dell Laptops. Not required, but should be left in because it can create a hassle and doesn't always restore functionality to those buttons once unchecked and rechecked" - direct from Dell
Daemon DAEMON32.EXE N Pre-loads game profiles for MS Sidewinder game controllers prior to release 2.0 of the software. Recommend upgrade. Available via Start -> Programs
Daemon Daemon.exe U Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
DAEMON Tools-1033 Daemon.exe U Daemon Tools - used to map an image-file (.iso, .bin etc) to a virtual CD/DVD-drive
Daily Planner dayplan.exe N Daily Planner - discontinued, and now part of KMCS Deluxe System Suite. Tool to plan your days, and check activities off as you complete them
Dap DAP.exe N Download Accelerator Plus from SpeedBit - download manager/accelerator
Data LifeGuard LifeLine Lite installer DLGLI.EXE N Backweb installer - see here
DataLayer DataLayer.exe U Nokia PC Suite 5 - "A collection of powerful tools that you can use to manage your phone features and data." Synchronize the phone with, for example Outlook. You can also use it to browse your phone, edit the phone list and so on
DataViz Messenger DvzMsgr.exe N DataViz Documents to Go - "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts"
Datcheck datcheck.exe X Added by the KEYPANIC TROJAN!
Date Manager datemanager.exe X Date Manager - calender program. Spyware/adware based provided by The Gator Corporation
DateMakerIntl DateMakerIntl.exe X Premium rate adult content dialler
DAupdate DAupdate.exe X NavEnhance adware
DAW9532.exe DAW9532.EXE ? Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required?
DayToday DAYTODAY.EXE U DayToday from RoboMagic Software Corp. Displays the date on the taskbar
DAZEL Delivery Agent DcDaemon.exe U Control and send documents, etc, to any destination - see here
dbserv dbserv.exe N Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled
DCE Manager dcemgr.exe X Added by the TUMAG TROJAN!
DCfssvc dcfssvc.exe U Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
dcfssve dcfssvc.exe U Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example
DDCActiveMenu DDCActiveMenu.exe N Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case
DDCM DDCMan.exe X Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case" rel="nofollow" target="_blank">privacy policy used to state that they also collect and share individuals information but this is no longer the case
DDCMan DDCMan.exe X Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case" rel="nofollow" target="_blank">privacy policy used to state that they also collect and share individuals information but this is no longer the case
ddeproc ddeproc.exe X Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here
DDialler DDialler.exe X Adult content dialler
de32gen de32gen.exe X Added by a variant of the CRYPTER.C TROJAN!
DealHelperBrwsr dhbrwsr.exe X DealHelper adware
DealHelperDown download.exe X DealHelper adware
DealHelperUpdate DHUpdt.exe X DealHelper adware
Debug DebugW32.exe X Added by the GUBED TROJAN Note - this is not the legitimate csrss.exe process which should NOT appear in Msconfig/Startup!
defragm_check defragment.exe X CoolWebSearch parasite variant
defwatch defwatch.exe U Detects out-of-date virus definitions for Norton Anti-Virus Corporate Edition and runs the Defwatch Wizard. Only required if you don't update the virus definitions manually on a regular basis
Delay delayrun.exe U On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
Delayrun delayrun.exe U On HP PCs this program is used to help prevent conflicts or timing issues on fast computers
delcab deltreew.exe C:\cabs ? ??
Dell AIO Printer A*** dlbabmgr.exe N Dell AIO Printer A*** related (*** = model). Not Required at Startup
Dell AIO Printer A*** dlbfbmgr.exe N Dell AIO Printer A*** related (*** = model). Not Required at Startup
Dell AIO Printer A*** dlbkbmgr.exe N Dell AIO Printer A*** related (*** = model). Not Required at Startup
Dell Alert DAMon.exe N "Dell Alert" utility, that's supposed to make interaction with Support easier
DellDMI delldmi.exe ? Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards?
DELLMMKB DELLMMKB.EXE U Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
DellSC dellsc.exe N Dell Solution Center - web-based troubleshooting tools and educational offerings
DellTouch DELLMMKB.EXE U Multimedia keyboard control for Dell based PCs - only required if you use the multimedia keys
delmsbb delmsbb.exe X nCase adware
DelTmp DelTemp.exe ? Added to the startup list after installing a Creative SoundBlaster Audigy soundcard. Deletes temporary files once an installation is complete?
DeltTray deltray.exe N System Tray access to the control panel for the M-Audio Delta 44 PCI Analog Recording Interface. Available via a desktop shortcut, Start -> Programs or Start -> Settings -> Control Panel
demon demon.exe ? Part of the French Wanadoo ADSL extense pack. What does it do and is it required?
Desire desires.exe X Adult content dialler
desk-top-service desk-top-service.exe ? ??
DeskAd Service DeskAdServ.exe X Windupdates adware variant
DeskColor DESKCOLOR.EXE N Provides transparent icon text backgrounds and coloured icon text
Deskflag Deskflag.exe N DeskFlag - animated USA flag on the desktop
DeskMateAutoUpdate DeskMateAutoUpdate.exe X DeskMates: Virtual scantily clad girls enhance your desktop. BargainBuddy adware related
desktop desktop.exe X Added by the SDBOT.MD WORM!
Desktop Architect DATRAY.EXE N Desktop theme manager available here - for managing the desktop appearance, fonts, sounds, etc
Desktop Search desktop.exe X iSearch "Desktop Search" hijacker
Desktop Service Centre DSC.exe N OptusNet DSL or Dial-Up connection software. Reports have shown that this file can cause a huge drain in resources and that disabling it will cause no problems.
desktopmgr desktopmgr.exe N Synchronisation manager for the cradles for the Research In Motion range of wireless handhelds, including the "Blackberry"
DesktopX DESKTOPX.EXE U A program that replaces the regular Desktop and Taskbar, and can be changed to the user's liking
deskup deskup.exe N Adds Iomega Zip drive icons to the desktop
Detector detector.exe N USB port detector for LG scanners. Sits in the System Tray, and when it detects the scanner through the USB port, you can run the scanner software from the tray. It is not required at all, since you can use the scan software from almost any photo editing software
Device Detector DevDetect.exe U Watches for external digital imaging products being connected from ACD Systems
devldr16.exe devldr16.exe U Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices
Devlog devlog.exe ? Apparently mainboard/chipset related, by a French company called AS Media - what exactly is it, and is it required
DGJM DGJM.exe ? ??
dguard dguard.exe N eAcceleration Stop-Sign related; not recommended; see note
dhcpagnt dhcpagnt.exe Y Intel DSL modem driver - leave enabled or you'll have to re-install the drivers
DHNUXB DHNUXB.exe ? ??
diagent diagent.exe N System Tray access for Creative Diagnostics for the Creative SoundBlaster series soundcards. Available via Start -> Programs
Dial22 dlm.exe X Adult content dialer. This infection should not be confused with the legitimate Fileplanet Download Manager program, which has the same filename.
Dial33 dlm.exe X Adult content dialer. This infection should not be confused with the legitimate Fileplanet Download Manager program, which has the same filename.
Dialer Control dc.exe U Dialer-Control. Detects and protects from premium rate p0rn diallers
Dialer Detect dd.exe U DialerDetect detects stealth installed premium rate diallers, and sounds the alarm when such a connection is being installed without you knowing it
DietK DietK.exe U DietK - add-on for Kazaa Media Desktop; "removes all adware and popups, built in Download Accelerator, makes searches faster and helps produce more results"
DigiCell DigiCell.exe U MSI DigiCell - "the most useful and powerful utility that MSI has spent much research and efforts to develop, helps users to monitor and configure all the integrated peripherals of the system, such as audio program, power management, MP3 files management and communication / 802.11g WLAN settings. Moreover, with this unique utility, you will be able to activate the MSI well-known features, Live Update and Core Center"
DigiD DigitalSound.exe X Adware downloader
Digital Dashboard devgulp.exe N For Compaq PC's. Loads Digital Dashboard options
Digital Line Detect DLG.exe N Detects whether your are plugged into a digital telephone line and displays the information graphically. Installed by Dell (and maybe others) and is included with all Connexant V.92 and Broadcom modems
Digital River eBot downlo~1.exe N Digital River Systems EBOT for downloading software from their site. In some cases, if you purchase software online for a download from a software manufacturer, you will be sent to this online company's site for the download after the purchase is complete. Read more here
DigitalNames DigitalNamesStart.exe X DigitalNames spyware variant
DigitalWizard Monitor dwMon.exe N InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
DIGStream digstream.exe N DIGStream Cache Manager - part of ESPN Motion and Disney Motion that periodically check for new videos and indication they're available in the System Tray. Starting ESPN Motion/Disney Motion starts digstream automatically
Dimension Dimension.exe U Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames, personal toast creator, war tools (login flooder), and allows viewing and interacting with the raw MSN protocol
Dimension4 d4.exe U Dimension 4 - network time synchronization freeware - starts-up, adjusts the system clock, then shuts down
Dino3 dino3.exe X Related to Jurassic Park III and enables a dinosaur to walk across the screen. Also generates adverts and classified as adware as a result
Direct Update DUControl.exe U DirectUpdate dynamic DNS updater
Direct X Direct3D dxd3d.exe X Added by a variant of the SDBOT WORM!
Direct X Opengl dxopengl.exe X Added by a variant of the RBOT-CJ WORM!
DirectCD DirectCD.exe N DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
directs.exe directs.exe X Added by the BEAGLE.O or BEAGLE.R or BEAGLE.S or BEAGLE.T WORMS!
DIRECTVDSL Directvdsl.exe U Starts DirectTV DSL modem at boot up. Can also be started manually
DirectX ddhelp32.exe X Added by the BIONET.318 TROJAN! Note - not the DirectX helper which is ddhelp.exe
directx Directx.exe X Added by the SDBOT.D TROJAN!
DirectX DirectX.exe X Added by the BLAXE or LOGPOLE WORMS!
DirectX For Microsoft Windows dtxservice.exe X Added by the PROGENT TROJAN!
DirectX Video Driver dxterm5.exe X Added by the WILAB-A TROJAN!
DirectX64 DirectXset.exe X Added by the BROWNEY.A WORM!
Dirkey Dirkey.exe U Dirkey - small utility that allows you to bookmark up to 9 folders by using the Ctrl+Alt+1..9 shortcut keys in an Open/Save File dialog or in Windows Explorer. After this the Ctrl+1..9 shortcut keys can be used in the same or another window to go to any of the 9 bookmarked folders 
discoveg discoveg.exe ? ??
DiscoverDeskshop Deskshop.exe N Discover Deskshop - single use "virtual" credit card
DiskeeperSystray DkIcon.exe N DisKeeper defragmentation software - can be started manually
diskinf diskinf.exe X Added by the CRYPTER.A TROJAN!
DISKMON.EXE DISKMON.EXE N "DiskMon is a small (55k zip file) that monitors hard disk activity. It's most useful because it puts a little light on your system tray that tells you when your hard disk is reading or writing, saving you having to bend down to look at the light on the front of your system unit."
Disknag disknag.exe N Dell program that reminds you to make your  backup diskettes
Disk_Monitor Disk_Monitor.exe U Multi-media, Smartmedia, Compact Flash card reader for reading digital camera cards. Device is recognised as internal USB disk drive. Necessary if camera cards are to be recognised as soon as they are inserted into the reader
Distiller Assistant 3.01 DISTASST.EXE N From Adobe. Creates PDF universal files for Acrobat Reader. Available via Start -> Programs
Distributed File System Dfsvc.exe X Added by the MYFIP.A or MYFIP.K WORMS!
distributed.net client DNETC.EXE U Dsitributed computing projects client from Distributed.net where numerous computers are used to share a projects workload - similar to SETI@Home and Folding@Home. Also prone to being distributed by viruses
Dit dit.exe Y "Drive Icon and Label Utility" - assigns drive icons and names to flash memory cards. Required, otherwise the drives aren't found
DiTask.exe DiTask.exe N Associated with an Eicon Networks ISDN or ADSL modem. System Tray icon which shows you the status of your lines (free, occupied with incoming or outgoing call). Available via Start -> Programs
Divamon.exe Divamon.exe ? Associated with an Eicon Networks Diva ISDN or ADSL modem - what does it do and is it required?
DivX MediaPlayer 7.0 Dr.DivX.exe X Added by the ALADINZ.G TROJAN!
DivX Player DivXPlayer.exe X Added by a variant of the RBOT WORM!
DivX Updater DivX.Exe X Added by the NALDEM TROJAN or MASTAK VIRUS!
Divx4 codec devldr32.exe X Added by an unidentfied VIRUS! Note - this is not the legitimate Creative Labs devldr32.exe file
DkService DkService.exe Y From Executive Software's Diskeeper defragmenting utility - a replacement for Windows Disk Defragmenter. It's recommended to leave this enabled, otherwise you could have problems starting it manually.
DKTime dktime.exe X Added by the LUNII TROJAN!
Dkware lptt01 dkware.exe X Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Dkware ml097e dkware.exe X Variant of the RapidBlaster parasite (in a "DonkeySoft" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
dkzzixm dkzzixm.exe ? ??
DlaTray Dlatray.exe N System Tray access to DLA - Drive letter access to HP's and Veritas' version of DirectCD. Does the same thing as DirectCD. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones"
dlder dlder.exe X Advertising spyware. Considered to be one oft the worst - even creating a fake "explorer.exe" file. Can be installed via versions of "Grokster", "Lime Wire" and "KaZaA" amongst other file-sharing utilities (see here). Reported in the past as a virus
DLForcerExe DLForcerEXE.exe ? ??
DLG DLGCHBW.exe N Backweb part of Data LifeGuard - diagnostic tools for Western Digital's series of hard drives. Automatically detects an internet connection and downloads any available updates
Dlite dllmanager.exe X Added by the WOOTBOT.DN WORM!
DLL32 dllmem32.exe X Added by the KWBOT.E WORM!
DllCacherv2 dllcachev2.exe X Added by the LATEDA TROJAN!
dlldmt dlldmt.exe X Added by a variant of the CRYPTER.C TROJAN!
dllhelp dllhelp.exe X Added by the STARTPAGE.DQ hijacker
dllhelp dllhlp.exe X Added by the Downloader-HI TROJAN!
dllhostxp.exe dllhostxp.exe X Browser hijacker and adware downloader
dllreg dllreg.exe X Added by the CRYPTER.A TROJAN!
DLLService32 dllsvc32.exe X Added by the AGOBOT.VX WORM!
DLT dlt.exe ? ??
dluca dluca.exe X Added by the DLUCA.C TROJAN!
dluxde dluxde.exe X All-In-One-Telcom (adult content dialler) variant
DM mgr dm_mgr.exe X Added by the JITTAR TROJAN!
DMILDR dmildr.exe N Part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely. Uses the DMI and/or common information model (CIM) protocols, which are systems management protocols defined by industry standards. Available via Start -> Programs 
DMISL DMISL.EXE N DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
DMISLAPP DMISLAPP.exe N DMI (Desktop Management Interface) Service Layer for Intel TokenExpress network card software. DMI support for the Intel network card managed through the Desktop Management Interface. See here for more information
Dmsvc32 Dmsvc32.exe X Added by the AGOBOT.ABU WORM!
dmtdll dmtdll.exe X Added by a variant of the CRYPTER.C TROJAN!
DM_server dmserver.exe X Comet Cursor adware
Dnar Dnar.exe X Unknown, except that it is not necessary. Tends to phone home a lot. DMI related
DNS Service dnsresolver.exe X Added by the RBOT-PQ WORM!
DNS2GoClient dns2goclient.exe ? DNS2Go is a Domain Name System that will make your computer accessible anytime, anywhere by associating a domain name of your choice to your currently assigned IP address. Is it required?
DNXVC dnxvc.exe ? ??
DocTor Doctor.exe X Added by the DOTOR.A WORM!
Doing doing.exe ? ??
Don't Panic dontpanicdemodp.exe U 30-day trial version of Don't Panic privacy software from Panicware. "Clean up Internet tracks and quickly hide personal documents with this privacy suite."
Don't Panic Pop-Up Stopper dpps2.exe U Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
dos dos64.exe X Adware downloader trojan
DoUWantIt duwi.exe N DoUWantIt - online shopping assistant. Start it manually
Download Accelerator Plus 5.0 DAP.exe N Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is "adware" based
Download Plus DownloadPlus.exe X DownloadPlus parasite - opens pop-up adverts
Download Wonder DownloadWonder.exe N Download Wonder from Forty Software. Download manager for resuming downloads, amongst other features
DownloadWare dw.exe X DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
DownloadWare Engine Dwe.exe X DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
Downxz Downxz.bat X Added by the MYDOOM.W WORM
DPAgnt DPAgnt.exe N digitalPersona fingerprint scanner
Dpcnav dpcnav.exe Y DirecWay from DirectTV satellite based high-speed internet access
dpcproxy dpcproxy.exe X Added by the GOLDENP-A TROJAN!
DPCProxyLoadOnStartup dpcstart.exe Y DirecWay from DirectTV satellite based high-speed internet access
Dpcstart dpcstart.exe Y DirecWay from DirectTV satellite based high-speed internet access. Proxy software
Dpcstart dpcstart.exe U Startup program for Direcway 2-way satellite internet service. Loads DirecWay's Navigator, tray icon, etc
dpi dpi.exe X Delfin Media Viewer or "Promulgate" adware
dpps2 dpps2.exe U Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
dps dps.exe X scumware-remover.org foistware, bogus adware/spyware remover, is in fact itself a browser hijacker, redirecting to smartestsearch.com
DragDrop DragDrop.exe ? ??
DrgToDsc DrgToDsc.exe N Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
dried.exe dried.exe ? ??
DriveSelect driveselect.exe N DVD X Copy XPress by 321 Studios. Creates a pop-up at Windows startup that asks for the DVD drive to be selected. Available via Start -> Programs
drocher d.exe X Adult content dialler
drvddll.exe drvddll.exe X Added by the BEAGLE.AP WORM!
Drvddll_exe drvddll.exe X Added by the BEAGLE.X WORM!
DrvListnr DrvListnr.exe ? Analog Devices SoundMAX soundcard related. What does it do and is it required?
drvlsnr drvlsnr.exe U Compaq/ADI SoundMAX integrated digital audio controller related. May solve a problem if your sound cuts out unexpectedly
drvr32h drvr32h.exe X Added by an unidentified VIRUS, WORM or TROJAN!
drvrmanager drvrquery32.exe X Added by the BOOHOO WORM!
drvsys.exe drvsys.exe X Added by the BEAGLE.W WORM!
Drwebscheduler Drwebscd.exe Y Dr. Web antivirus related - scheduler that allows you to manage an automatic launch of applications, in particular the antivirus scanner or the update subsystem
DR_S DR_S.exe X AdShooter adware
DS Clock dsclock.exe U Digital desktop clock including synchronization with atomic servers - see here
dsa dsa.exe X Homepage hijacker - redirecting to downseek.com
DSB DSB.exe X EnergyPlugin adware
DSentry DSentry.exe N Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
Dsi dp-******.exe X Added by an unidentified adware where ****** are random characters
Dskcompat Dskcompat.exe X Added by the GEMA TROJAN!
DSLagentexe DSLagent.exe Y Used in conjunction with USB connected ADSL modems from Eicon Networks (as used by BT for its Broadband internet service for example). Required for a permanent ADSL connection
dslmon dslmon.exe Y Sagem DSL modem related. Apparently needed to detect the modem
DSLSTATEXE dslstat.exe U System tray connection status for ADSL modems from Eicon Networks (as used by BT Broadband for example)
DSS dssagent.exe X DSSAgent by Brøderbund - spyware. Sends encrypted emails about the system back to the originators of the program. Also a resource hog. See here for more info
DSSSGENS dssagens.exe ? ??
DU Meter DUMETER.EXE N Hagel Technologies internet bandwidth monitor
dumprep 0 -k dumprep.exe N Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out. More information can also be found here.
dumprep 0 -u dumprep.exe N Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
dvd43 DVD43_Tray.exe N DVD43 is "a small tool that integrates into Windows and overrides CSS copy-protection found on DVD movies"
DVDBitSet DVDBitSet.exe U DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used
Dvdcompat Dvdcompat.exe X Added by the GEMA TROJAN!
DVDLauncher DVDLauncher.exe N A process belonging to the Cyberlink PowerCinema video viewing software which allows you to play DVDs upon insertion. Non-essential process - and is installed for ease of use
DVDSentry DSentry.exe N Anti-spyware from Dell. Seems that after Dell found out certain applications being installed from DVD's would report back information about what customers were watching, they decided to implement an anti-spyware service. Run manually before installation starts
DVDTray DVDTray.exe N HP CD/DVD Tray icon.
DVDUpgrade DVDUpgrd.exe ? ??
Dvp95 Dvp95.exe Y Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine
dvpapi9x DVPAPI9X.exe Y Command AntiVirus for Windows 95/98/Me
DvpInitExe Dvpinit.exe Y Command Antivirus related
dvprpt Dvprpt.exe Y Command Antivirus real time protection
dvraudio dvraudio.exe X Added by a variant of the CRYPTER.C TROJAN!
DVSync dvsync.exe U DVSync is the program that allows you to synchronize your daVinci’s PDA's data with your Personal Information Manager on the PC
dw dw.exe X DownloadWare - executes arbitrary code from advertisers and not considered to be adware but is a security risk (see here). If a network connection is available it will connect to its servers, which can direct it to download and install software from advertisers. Installed along with programs such as MovieNetworks, Medialoads and PAgent
DWHeartbeatMonitor DWHeartbeatMonitor.exe U DWHeartbeatMonitor.exe is installed alongside the Weather.com instant messaging utility. This is a non-essential process. Disabling or enabling this is down to user preference
Dx8compat Dx8compat.exe X Added by the GEMA TROJAN!
DXDllRegExe dxdllreg.exe N Created when you select "Yes" to check the "WHQL Digital signatures" in the DirectX9 files at the first time you open it
DxLoad DX3DRndr.exe X Added by the GIBE.B WORM!
Dxsty Dxsty.exe X Added by the GEMA TROJAN!
Dxupdate.exe Dxupdate.exe X Added by the MAFEG WORM!
DynDNS-Updater Traytool ddutray.exe N DynDNS updater tray icon - allows easy configuration of the Dynamic DNSSM service. Can be run manually
Dynu Basic Client dynubas.exe U Dynu online dynamic IP update client. Useful when using a dial up modem
DZKillMe DZSAVEME.EXE ? ??
Eac Download download.exe X Associated with Webcelerator - spyware. Read eAcceleration's privacy statement here
eBot DownloadWizard.exe N eBot from Digital River - "helps ensure your computer always has the latest technology, fixes, add-ons, upgrades and 'cool stuff'." Can optionally be installed with software such as Net Nanny internet filtering software. Available via Start -> Programs
EDLoader DTLoader.exe N Effective Desktop from MiniStars Software - desktop management software no longer being supported
Execute delfolders.exe Y The Tools folder, also known as a directory in this case, is created during various installations which often include drivers connected with motherboards or chipsets.  DelFolders.exe is designed to run once to remove this directory including itself once the installation is complete.  Security programs may block it from running which results in the folder and file remaining on the computer.  It may also show up if the installation was incomplete.
FatPipe DHCP U Software enabling high speed internet browsing (2-4 times faster) and internet connection sharing for up to 5 users
GhostSurfDelSatellite DeleteSatellite.exe ? SpyCatcher spyware remover related. What does it do and is it required?
Gilat SOM Enumerator dllhost.exe Y For Gilat Communications internet satellite systems - associated with SkyBlaster modem. Required if you have this system
Gravis Appawareloader dbserver.exe U Looks like it's associated with Gravis game controllers and the Keyset Manager, allowing the user to program the buttons for games that don't support them
Hermes Messenger DGDRHE~1.EXE U A LAN messenger alternative to WinPopUp - Digital Dreams Software
HP_dla dlatray.exe N On HP PCs, tray icon for dla - which provides drive letter access to HP's and Veritas' version of DirectCD
HydarVisionDesktopManager desk95.exe U ATI's HydraVision desktop management software, allowing for multi-monitor support, as included in ATI HydraVision versions 2.5 and earlier. Has been reported to cause problems, such as this one. HydraVision can be uninstalled through Add/Remove Programs
HydraVisionDesktopManager desk98.exe U ATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
iConfigLoader DIIhost.exe X Added by the GAOBOT.AO WORM!
InControl Desktop Manager DMHKEY.EXE N For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
DellBIOS DellBIOS.Sys Y Driver used to flash the bios on a Dell computer to a newer version.
Iomega Backup Scheduler dtiom98.exe N Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
KE9801 DriBat32.exe U KE-9801 multimedia keyboard - required if you use the multimedia keys
kernelfaultcheck dumprep.exe N Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
li-speed**** dlres.exe X Adult web-dialler - **** is random
Live Menu Dllcmd32.exe N eFax Send button for eFax Messenger Plus. Available via Start -> Programs Disabling instructions available here
Livre Dibane.bat X Added by the BANEDI VIRUS!
load= dapdll.exe X Added by the ATAK.E WORM!
LoadDvpApi9x DVPAPI9X.exe ? Part of Command AntiVirus for Windows 95/98/Me. Is it needed?
MediaLoads dw.exe X Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
MediaLoads Installer dw.exe X Medialoads is advertising software - running DownloadWare as its executable. Installed as a bundle with Kazaa Media Desktop. See here for more information
messnger Dvldr32.exe X Added by the DELODER.A WORM!
Microsoft System Checkup dbnetlib.exe X Added by the DONK.L WORM!
Microsoft Time Manager dveldr.exe X Added by the RBOT-HQ WORM!
NAV DefAlert DefAlert.exe U Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
NDPS DPMW32.EXE U Novell Distributed Printer Services - part of Novell's Netware Client and Groupwise products. Not required if you don't use this feature
NetworkSetup dlink.exe N D-Link System Tray icon
No-IP DUC DUC20.exe U Part of http://www.no-ip.com provided service. Keeps No-IP's dynamic nameserver (DNS) updated if and when your computer's (network's) dynamic IP-address changes so that you can run servers on computers with dynamic IP. Shortcut available
ntupdate dnsvc.exe X Added by the SDBOT-TC WORM!
NWEReboot dummy.exe Y Temporary file used during the installation of Ahead Nero CD/DVD burning software.
Optus Cable Data Monitor datamonitor.exe U Allows Optus customers to monitor their actual data usage against Optus' "data allowance limits"
Pop-Up Stopper dpps2.exe U Pop-Up Stopper Companion from Panicware. Pop-up blocker integrated into the IE toolbar. Note that the Pro version doesn't load in startup as it is installed as an Internet Explorer toolbar. Can cause problems with IE if you use WinXP and uninstall Service Pack 1. Uninstalling the software leaves it in the startup group
Printer dipset.exe X Added by a variant of the FBSR TROJAN!
rn4d dirote.exe X Added by the BKDR_MAROON.A TROJAN!
RoxioDragToDisc DrgToDsc.exe N Part of Roxio EasyCD Creator 6.0 - places the Roxio Drag-to-Disc icon in you system tray. "Easily drag and drop files for burning to CD or DVD. Disc formatting and burning will happen automatically". Not required for Roxio to work properly
run= dec25.exe X Added by the ATAK.F WORM!
rundll*** die.exe [path] mdll.exe X Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll*** die.exe [path] secure.bat X Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll*** die.exe [path] secure.exe X Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
rundll*** die.exe [path] ttg.exe X Added by the SUMTAX TROJAN! where *** is 134, 569, 777 or 946
Service Manager dxsound.exe X Added by the PROXY-GRIC TROJAN!
Sharing and Mapping Software DShmap.exe Y Intel AnyPoint internet sharing software
Speedtouch USB Diagnostics Dragdiag.exe U For an external Alcatel ADSL high-speed modem. A diagnostic tool and can be run from the Start menu when required. The only reason it might be useful on startup is if you like seeing an 'at-a-glance' status indicator on the taskbar (the icon is a different colour depending on the status of the device/line)
sstata dwdas.exe X Added by the DASDA TROJAN!
STManager drst.exe N Dr. SpeedTouch is some sort of diagnostics software which sends out information to a server which then relays the information back to the program to test the network to see if the SpeedTouch ADSL modem connection is working properly. Not required if connected via Ethernet (and probably USB). Can cause a slow down in Win2K - see here
Sync Server drwatsoon.exe X Added by the WATSOON.A TROJAN!
syspath drv.exe X Added by the SOBER WORM!
System dcomx.exe X Added by the CIREBOT TROJAN!
System32Dll DLL32SYS.EXE X Added by the SPYBOT-CZ WORM!
TrackpointSrv daemon.exe U Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work
upme dllman.exe X Added by the MUGLY.F WORM!
User23.exe DIAL.exe X This is a trojan trying to disguise itself as User32.dll
UserFaultCheck dumprep.exe N Used in connection with memory dumps - you can disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out
WebScan DEFSCANGUI.EXE N eAcceleration Stop-Sign related; not recommended; see note
wersds doriot.exe X Added by the JECT.C TROJAN!
Win32 Configuration dllhelp.exe X Added by the SDBOT.UL WORM!
Window Loader Dos32.exe X Added by the GAOBOT.AO WORM!
Windows (random character) diskcheck.exe X Added by the SINGU.B TROJAN!
Windows Automatic Updates dvldr.exe X Added by the RBOT.MF WORM!
Windows DLL Loader defragfat32z.exe X Added by the LINKBOT.A WORM!
Windows DLL Loader defragfat32pi.exe X Added by the RBOT-QQ WORM!
Windows DLL Loader defragfat39.exe X Added by the POEBOT-C WORM!
Windows DLL Loader defragfatz.exe X Added by the LINKBOT.H WORM!
Windows Update Files dnetc.exe X Added by an unidentified VIRUS, WORM or TROJAN! Note - wupdmgr.exe is the real Windows Update
WindowsXP Module DirectX3D.exe X Malware, reportedly a keylogger - see here
WinMine D4NG3.vbs X Added by the BISCUIT.A WORM!
wpds.exe doriot.exe X Added by the SMALL-KY TROJAN!
YAMAHA DS-XG Launcher dslaunch.exe N System Tray access for the features of the Yamaha DS-XG soundcard unless you regularly change set-ups
djtopr1150.exe djtopr1150.exe X Unknown malware. Located in %temp%djtopr1150.exe"
Winsvr manager DDEsvr.exe X Added by the W32/Tirbot-B WORM! Found in the Windows system folder.
Answer Problem dSAFsqs.exe X W32/Sdbot-SC is an IRC backdoor Trojan! Found in the WIndows system folder.
doit.exe doit.exe X Added by the W32/Forbot-EK WORM! This file is found in the Windows system folder. May also create a Windows service called doit.exe.
DownloadAccelerator DAP.EXE N Download Accelerator Plus from Speedbit. Download manager for resuming downloads, amongst other features. Available via Start -> Programs. Note that the free version is "adware" based
Dns Resolver dnsrslve.exe X Added by W32/Rbot-WS, a WORM!
Dynamic Dns Binary dynitora.exe X Added by W32/Rbot-WT, a WORM/backdoor, and will be found in the Windows system folder.
duck duck.exe X Added by W32/Agobot-APO, a WORM/backdoor. It is found in the Windows system folder.
DirectX DLL Register Support Service DXDLLSVC.EXE X Added by W32/Codbot-I, a WORM/IRC backdoor TROJAN!
run DLLREG.EXE X Added by the W32/Dumaru.w Trojan! Acts as a keylogger and sends out the stolen information to a predetermined email address.
Dev Manager devspecs.exe X An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user.
Dns Server dnswn.exe X An Rbot variant. This infection connects to an IRC server where it will await commands from a remote user.
WinMngn dllhost.exe X Added by the Troj/Sivion-A TROJAN by appearing to be an anti-virus program. Additional files are installed to the Program Files to enable unauthorised access by way of IRC channels.
Daemon daemon.exe c daemon2.exe X The WORM W32/Esalone-A will add the file, corrupt WINZIP and WINRAR archives, and also create other files.
Device Detector 2 DevDtct2.exe N Installed by various Olympus products, this program detects the active connection of a speech device (voice recorder, etc) to a USB port then runs specific client software used to access that device. The DevDtct2 process has a "high" priority level which can negatively impact system resources.
DSService dmrss.exe X Added by the AGOBOT-XX network Worm!
regscan DLLSRV32.EXE X Added by the AGOBOT.AEW WORM!
Windows Online Updater dllman.exe X Added by the RBOT-TE WORM!
Windows Service dddd.exe X Identified by Kaspersky Labs as PornWare.Dialer.Salc, also known to come with the Bube family trojans
WIN32 DDOSSER dos.exe X Added by the W32/Rbot-YY to the Windows system folder,it has a backdoor functionality exploiting IRC channels.
DebugMonitor debugmonitor.exe X A MyDoom WORM variant adds this file, exploiting P2P and email clients.
Windows DLL Loader DEFRAGFAT34.EXE X Added by the W32/Poebot-B WORM/IRC backdoor!
DPConfig DPConfig.exe N Compuware DevPartner Studio Configuration Utility, a tool for software developers - system tray access to configure the utility
Disk Manager diskver.exe X Added by a Rbot variant.
Down2Home Down2Home.exe U Down2Home allows you to monitor your Internet connections traffic and provides statistics on the amount of data transferred and received.
DameWare NT Utilities 2.6 DNTUS26.EXE U Dameware NT Utilities program that allows remote access and control of a computer. This is a common program for hackers to install on a computer, so if it is installed, and you did not install it, it should be removed.
Compuware Distributed Analyzer Service DASVCNT.exe Y Added as part of the Compuware DevPartner Studio.
(default) diagcfg.exe X Added by the Backdoor.GWGirl trojan.
autorepair dexs.exe X Added by a variant of the W32/SDBOT WORM!
DrWeb Antivirus DRWEBAV.EXE X Added by an unidentified WORM or TROJAN!
winhelp dns32.exe X Added by a variant of the WIN32.RBOT WORM!
Windows DLL Loader defragfatz.exe. X Added by the W32/Poebot-D WORM/IRC backdoor!
Micro Process dosprmwin.exe X Added by the W32/Rbot-BC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MSN Update DLLCON.EXE X Added by the W32/Rbot-EA trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
rCron dservice.exe X Switch Dialer Variant.
demm386.exe DEMM386.EXE X Added by the W32/Rbot-EO trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Micro Update DAILIN.EXE X Added by the W32/Rbot-ER trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
AvSer dsm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
DsmSer dsm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
rollbk dsm.exe X Added by the W32.Serflog.B worm. This worms spreads through file-sharing networks and MSN Messenger.
draw32 draw32.dll X Part of the Troj/Haxdoor-AE rootkit. This is installed as a system driver service so will not be seen in the services.msc control panel.
Especial Deneca.bat X Added by the WM97/Acened-A word macro virus.
debugg debugg.dll X Added by the HaxDoor.B rootkit/backdoor Trojan.
ASDPLUGIN dslgeacc.exe X Added by the Dial/Asd-A dialer.
Symantec Client Security Loader DHCP.DLL X Added by the Troj/DllLoad-B trojan dll loader. DHCP.DLL is a file that tells the service what malicious DLL to load.
Microsoft STS Service DHCP32.exe X Added by the W32/Sdbot-UK worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
boqamah dytevevi.exe X Added by the W32/Sdbot-UH worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
Windows DLL Loader defragfatx.exe X Added by the W32/Poebot-F trojan. When started this infection connects to a remote IRC server where it waits for commands to execute.
doc doc.exe X Added by the W32/Agobot-PJ trojan. When started this infection connects to a remote IRC server where it waits for commands to execute. This infection will add entries to your HOSTS file, so the hosts file should be restored after cleaning this infection.
DDEsvr ddesvr.exe X Added by the W32/Agobot-QI worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
DataViz Inc Messenger DvzIncMsgr.exe U Installed with DataViz "Documents to Go" software
drct16 drct16.dll X Added by the Troj/Haxdoor-CN rootkit infection. This file is installed as system driver and is used to hide processes, files, and registry keys from being seen.
Dll executer_AutoStarter Dll executer_AutoStarter.exe X Added by the W32/VB-SP worm.
DNSCacheBoost dnsping.exe X Added by the Troj/DNSBust-A trojan. This infection modifies your dns servers that your computer uses in order to redirect popular sites to an address of its choice.
Configuration Loader Service devl32.exe X Added by the W32/Sdbot-XY worm.
[various names] driver32.exe X Added by a variant of the W32/SDBOT WORM!
daudi daudi.exe X Malware, as yet unidentified
dbtmon dbtmon.exe N Dell button monitor for 9XX series printer most commonly associated with 922. Can safely be turned off does not hamper printer operations. Can be
directx directx32.exe X Added by the AGOBOT.CG WORM!
djsnetcn DJSNetCN.exe ? "Symantec Licensing Detect Internet Connection", part of Norton antivirus - what does it do and is it required?
dll manager dllmngr32.exe X Added by a variant of the WIN32.RBOT WORM!
dnscleaner dnscleaner.exe X CoolWebSearch parasite related
windows system tray dlhost.exe U Related to IamBigBrother Internet monitoring software.
RUN DRDOOM.EXE X Added by the W32/Semapi-A. This mass-mailing worm may display a message: "Unable to locate 'semapi.dll' reinstalling this application may fix this problem."
xdxqa dewa.exe X Added by the W32/Sdbot-YB. This infection exploits vulnerabilities Microsoft has identified and a patch is available, please visit their updating website. MS04-011
Microsoft Windows dlIhost.exe X Added by the W32/Rbot-QC worm. This infection connects to an IRC server where it waits for remote commands.
Windows DLL Loader defragfat32abc.exe X Added by the W32/Rbot-RG worm. This infection connects to an IRC server where it waits for remote commands.
Dev Gnu Cpp devcpp.exe X Added by the W32/Rbot-RU worm. This infection connects to an IRC server where it waits for remote commands.
what ever decom.exe X Added by the W32/Rbot-SC worm. This infection connects to an IRC server where it waits for remote commands.
divx divxenc.exe X Added to the Spbot.B TROJAN!
virtual cdrom deamon.exe X Added by the RBOT.VP WORM!
windows dll loader defragfat32.exe X Added by the W32/SDBOT-SS WORM!
Microsoft DLL Manager dllmgr.exe X Added by the W32/Sdbot-KJ worm. When started this infection connects to an IRC server where it waits for remote commands.
at&t dsl service pca program dslpca.exe ? AT&T DSL related - what does it do and is it required?
dynhttp dns binary dynizari.exe X Added by a variant of the WIN32.RBOT WORM!
dashie dashIE.exe systray ? Could be related to "Dash Power Shopping" tool bar in IE?
Windows SP4 directCC.exe X Added by the W32/Rbot-ACX worm. When started this infection connects to an IRC server where it waits for remote commands.
wsaconfiguration drrss.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
dcomdriver DCCOM32.EXE X Added by the W32/Nymph.gen@MM mass-mailing worm.
fddddHOME dxxatp.exe X Added by the Troj/Ranck-AF proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location.
systeminfo DRIVER.EXE X Added by the W32/Randon-Y worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands.
mdetect divxencoder.exe X Added by the Troj/Sqdload-A downloader trojan.
dell aio printer a920 dlbkbmgr.exe ? Button manager for the Dell AIO Printer A920?
dell aio printer a960 dlbfbmgr.exe ? Dell A960 All-In-One Printer related - what does it do and is it required?
windows driver update dmsvc32.exe X Added as result of a W32/Sdbot-GP worm infection
dancer DncLE.exe U Part of Microsoft Plus! Digital Media Edition - see here
disspy disspy.exe U Disspy spyware detection and removal software
dmxlauncher DMXLauncher.exe U Part of Dell's Media Experience, a multimedia suite which offers the user functionality to organise and play music and digital video files.
microsoft debug service dbgbgr.exe X Added by a variant of the WIN32.RBOT WORM!
directx 32 directx32.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
ktubqr dxcqqijz.exe X Added by the Troj/Sdbot-DF backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Microsoft DLL Manager dllmnr.exe X Added by the W32/Sdbot-DM backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Auto Start dosin.exe X Added by the W32/SdBot-GO worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[unknown] DNETLIB.EXE X Added by the W32/Sdbot-HA worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Dll6d AutoLoader DLL6DSYS.EXE X Added by the W32/Sdbot-HX worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[unknown] DLL9DSYS.EXE X Added by the W32/Sdbot-HZ worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[random name] d?xplore.exe X PurityScan/Clickspring adware
[unknown name] DLLSYSBIN.EXE X Added by the W32/Sdbot-IZ worm. When started this infection connects to an IRC server where it waits for remote commands.
microsoft internet, varying file names dmsvc32.exe X Added as result of a W32/Sdbot-AZ worm infection
Microsoft Internal AntiVirus Systems dIlhost.exe X Added by the W32/Rbot-AEV worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
systemr d11host.exe X Added by the Troj/VB-GX downloading trojan.
Monitor SynManager dcvwed.exe X Added by the W32/Sdbot-NL worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Configuration Loader dezi.exe X Added by the W32/Sdbot-OB worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
WINDOWS SYSTEM dcomuser.exe X Added by the W32/Mytob-BJ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
DASDS VSAVdjs dsabdw.exe X Added by the W32/Sdbot-RE worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
ffeqfqs dqddss.exe X Added by the W32/Sdbot-SG worm. When started, this infection will connect to a remote IRC server and wait for commands to execute.
Perfomance Monitor davcsync.exe X Added by the W32/Lamud-A worm.
file1 Dia Claro.htm X Added by the Troj/Dloader-OR
Cmpnt Devices2.exe X Added by the Troj/Tompai-D backdoor trojan.
Managing FAT and NTFS partitions dfrgfat16.exe X Added by the W32/Codbot-N worm and IRC backdoor.
destroy11 destroy11.exe X Added by the Troj/Delf-KO keylogging trojan.
DUN_SERVICES3 DUN_SERVICES3 X Added by the Trojan.Sokiron trojan.
DD2SERVICE DDClient.exe U Added by the Spyware.DesktopD surveillance software. If you did not install this program, you should uninstall it immediately.
DD2KPECLIENT DDClient.exe U Added by the Spyware.DesktopD surveillance software. If you did not install this program, you should uninstall it immediately.
DesktopSpy dsa.exe U Added by the Spyware.DesktopSpy surveillance software. If you did not install this program, you should uninstall it immediately.
DHCP Client dhcpclient.exe X Added by the W32/Codbot-AG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
WINDOWS DENEME deneme.exe X Added by the W32/Mytob-CR worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
destroyb11 destroyb11.exe X Added by the Troj/Delf-KO
dun_services3 dun3.exe X Added by the Trojan.Sokiron
dxmsrv dxmsrv.exe X Added by an unidentified WORM or TROJAN!
MicrosoftKs Drivers.bat X Added by the Troj/Shutdown-F trojan. This trojan attempts to shut down your computer.
direct3d.exe direct3d.exe X Added by the Troj/Certif-F password-stealing trojan.
drwatson drwatson_32.exe X Added by the TROJ/LOHAV-S TROJAN!
microsoft dll printer manager dllpt.exe X Added by the SDBOT.BIH WORM!
microsoft upmachine doezs.exe X Added by the RBOT.BCT WORM!
microsoft windows dll services configuration dllmanager32.exe X Added by a variant of the W32/SDBOT WORM!
windows service pack auto update del-me.exe X Adware, also detected as the Lowzones.BH TROJAN!
windows dialup service dialup.exe X Added by the AGOBOT.AAH WORM!
installer dial.exe X Malware - detected by Kaspersky antivirus as trojan-dropper.win32.agent.mm
windows deneme deneme.exe X Added by the W32/Mytob-CR
Diagnostic diagnostic.exe X Added by the Troj/Alpha-C backdoor trojan.
DirectX Graphics dxdmain.exe X Added by the W32/Codbot-O worm.
[not used] dllcnfg.exe X Added by the Backdoor.Samkams backdoor Trojan.
dell photo aio printer 922 dlbtbmgr.exe N Adds an icon to the system tray for a Dell printer solution center.
dellsupport DSAgnt.exe U Dell Support Agent offers additional support and update features for your Dell computer or laptop.
avidrv drvsc.exe X Detected as the Trojan-Downloader.Win32.Agent.ph TROJAN! by Kaspersky Anti-Virus. Note: No URL available at this time.
spywareguard deinst_qfe001.exe X Added by a variant of the Win32.Small TROJAN! - Do NOT confuse with the legitimate SpywareGuard application as described here
dgtstart dgtstart.exe X DigitalNames.g adware
diamondview Diamondview.exe ? Manulife Financial Insurance program. Note: This file is legitimate. It is not known if it needs to run at startup.
dinst dinst.exe X GrandStreet parasite variant - detected by Kaspersky antivirus as Trojan-Downloader.Win32.Intexp.d
dvd43 DVD43.exe U DVD43
dyndns updater DynDNS.exe U Dynamic DNS IP address updater tool, used as a client for Dynamic DNS service providers such as http://www.DynDNS.org.
dynsite DynSite.exe U DynSite is a dynamic DNS client, also called an automatic IP updater.
i am not ranky. i am etunnel! disney.exe X Added by an unidentified WORM or TROJAN!
itunes dials.exe X Detected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus. Note: A Url is not available at this time.
regrun dialer.exe X Adware downloader - also detected as a variant of the TROJ_LOWZONES.BW or TROJ_AGENT.RD TROJAN!
ultradvdmon DVDMon.exe ? UltraDVD DVD player software - is it required?
windows internet protocol deinst_qfe001.exe X Added by a variant of the Win32.Small TROJAN!
windows update checker deinst_qfe002.exe X Added by a variant of the Win32.Small TROJAN!
[various names] dePloy.exe X TROJAN! - part of Wareout, malware masquerading as a spyware and dialer remover, see here
BD dc.exe X Added by the Troj/Rasdoor-B Trojan.
dmserver dmsrv.dll X Added by the Backdoor.Fuwudoor backdoor.
dlhost dlhost X Added by the Troj/ExpHook-A Trojan.
Automatic Defrag Manager defrag.exe X Added by the W32/Rbot-AKE worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
DVDrealm DVDrealm.sys X Added by the W32/Tilebot-G worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Logical Disk Manager Administrative Service dmadmin.exe Y This Windows service manages hard disk and volume functions in Windows.
dopus dopus.exe U Directory Opus - a file manager from GPSoft
Distributed Link Tracking Extensions dltksvc.exe X Added by the W32.Myfip.K worm.
DirectX9 Diag dx9diag.exe X Added by the W32/Rbot-ALT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Driver Cache Driver Cache.exe X Added by the Troj/Feutel-S keylogging Trojan.
ss dssa.dll X Added by the Backdoor.Xebiz backdoor Trojan.
Systask dll.dll X Added by the PWSteal.Ldpinch.B password-stealing Trojan.
dell photo aio printer 962 dlbxmon.exe ? DellPhoto AIO Printer 962 Device Monitor - is it required?
index service dllhost32.exe X Added by the AGOBOT.CH WORM!
windows dll host dllhost32.exe X Added by an unidentified WORM or TROJAN!
DW4 DesktopWeather.exe N The Weather Channel's desktop weather program.
dcznetv2 dcznetv2.exe X Added by the W32/Tilebot-O worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
dxdiags.exe dxdiags.exe X Added by the Troj/Certif-G Trojan.
SiS Dns dnssvc.exe X Added by the Troj/Dloader-UE Trojan.
DamedWare Services dwdrce.exe X Added by the W32/Rbot-AOJ worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
antidialer.co.uk Dialer_Watcher.exe U Dialer_Watcher is an application that allows you to detect Dialers on your computer.
deeenes DeeEnEs.exe U DeeEnEs - automatically updates a dynamic IP address when it changes.
delsaap delsaap.exe X nCase adware
dlbcserv dlbcserv.exe ? Related to a Dell Photo Printer - what does it do and is it required?
microsoft dllset32 dllset32.exe X Added by the RBOT.OZ WORM!
DIGServices DIGServices.exe N Created by Disney but licensed to ESPN for watching videos
Defragmentation Management Handler dfrgfat32.exe X Added by the W32/Codbot-AB backdoor worm.
DLL32 dllhost.dll X Added by the W32/Lovelet-DR worm. It will also create the following files:



%SystemDrive%sender.vbs (also detected as W32/Lovelet-DR)

%SystemDrive%winlogon.exe (copy of the worm EXE)

%ProgramFiles%microsoft frontpageoutlook.vbs (also detected as W32/Lovelet-DR)

%System%loader32.com (copy of the worm EXE)

%WinDir%LoveLetter.doc.exe (copy of the worm EXE)
WinSec32 dhcp.sys X Added by the Troj/Rawdoor-A backdoor Trojan.
dpti2o dpti2o.sys Y DPT SmartRAID miniport driver added by Microsoft.
Microsoft Config dczznet.exe X Added by the W32/Rbot-ARL worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. This infection will also install the rootkit rdriv.sys in the Windows System folder.
System d.exe X Added by the W32.Mytob.KU@mm worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
microsoft compiler pack DSDEV.EXE X Added by a variant of the W32.SPYBOT WORM!
dsi dp-him.exe X Added by the Troj/Multidr-AH TROJAN!
[default] DrWatson32.exe X Added by the DREMN TROJAN!
AdPopup dcf5678.exe X Added by the Troj/Agent-FZ Trojan.
dlsp2mx dlsp2mx.exe X Added by the Dial/MPB-B porn dialer.
dpnsvr32 dpnsvr32.exe X Added by the Troj/AOLPass-B password-stealing Trojan.
Dumeter Services dumeter.exe X Added by the W32/Sdbot-AEQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. This infection will also create the file msdirectx.sys in the Windows System folder.
[not used] DAinit.dll Y Used by Desktop Authority desktop management software.
delstart delstart.exe ? Reportedly part of BT ISP software - what does it do and is it required in startup?
Dit dit.exe X Added by the Troj/Lazar-A backdoor Trojan. The real Dit.exe is located in the Windows folder.
Auto Update dma.exe X Added by the W32/Rbot-AVO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
drvnetw drvnetw.exe X Added by the Troj/Brogger-B information stealing Trojan.
Windows DOS dosw.exe X Added by the W32/Salay-A network worm.
Microsoft Windows Workstation devcode.exe X Added by the W32/Rbot-AWL worm and IRC backdoor.
dstray dstray.exe X Added by the Troj/CmjSpy-AA Trojan.
Windows Archiver devldr.exe X Added by the W32/Prex-J worm and IRC backdoor.
D System dd.exe X Added by the W32/Mytob-FN worm and IRC backdoor.
DynamicHost dlhost.exe X Added by the W32/Tilebot-BO worm and IRC backdoor.
Win Validation Application DBExecCom.exe X Added by the W32/VBSilly-A worm.
ds ds.exe X Added by the Backdoor.Spymon backdoor Trojan.
00dsksvr00 desksaver.exe N Related to Advanced_Desktop_Shield
dmc dmc.exe X Added by Trojan-Downloader.Win32.Dluca.bv TROJAN!
dxvid dxvid.exe X Added by Trojan-Downloader.Win32.Dluca.by TROJAN!
windowsupdate dupadupam2.exe X Added by the Troj/Dupa-B
windowsupdatedirect dupadirect.exe X Added by the Troj/Dupa-C
(D1589445-4C2D-4827-6486-8C9674D8B206) dkxcj32.dll X Added by the W32/Korgo-Z network worm.
diskchk diskmon32.exe X Added by the W32/Rbot-BBI worm and IRC backdoor.
Driver Data Monitor datasys.exe X Added by the W32/Rbot-BBN worm and IRC backdoor.
Microsoft Security Pansasagers dgkztsqgn.exe X Added by the W32/Rbot-BBJ worm and IRC backdoor.
Microsoft Windows Workstation devcode32.exe X Added by the W32/Rbot-BBT worm and IRC backdoor.
Windows 64bit DLL Manager dllmgr64.exe X Added by the W32/Tilebot-CP worm and IRC backdoor.
[not used] dpnetmsg.exe X Added by the Troj/PPdoor-Q backdoor Trojan. This infection may also make the files C:\Windows\System32\dpnetmsg.exe, C:\Windows\System32\iueninet.dll, C:\Windows\System32\fsmgntfs.dll, C:\Windows\System32\ntmapast.dll, C:\Windows\System32\ir50psrv.exe, C:\Windows\System32\kbd1uery.dll, C:\Windows\System32\lfyockaa.dll, C:\Windows\System32\a15svcs.exe, C:\Windows\System32\dpnmdlib.exe, C:\Windows\System32\c_28usic.dll, C:\Windows\System32\atiysnpn.dll, C:\Windows\System32\treemqoa.dll, C:\Windows\System32\arptutdn.dll, C:\Windows\System32\eulapart.dll, C:\Windows\System32\smlo8thk.exe, C:\Windows\System32\odbcfwci.ime, C:\Windows\System32\hgakheg.dll, C:\Windows\System32\jkwbhew.dll, and C:\Windows\System32\testtest.exe.
diskchk32 dskmon32.exe X Added by the W32/Rbot-BCL worm and IRC backdoor.
Winxp update Drivxp.exe X Added by the W32/Sdbot-AIP worm and IRC backdoor.
DcomHelper Service dcmhelp.exe X Added by the W32/Sdbot-AJA worm and IRC backdoor.
Windows Disk Check dskcheck.exe X Added by the W32/Tilebot-CQ worm and IRC backdoor.
Microsoft Winsock dczwin32.exe X Added by the W32/Rbot-BFW worm and IRC backdoor.
Windows Update dllhostup.exe X Added by the Troj/Bancban-NB Trojan.
drsmartloadb drsmartloadb.exe X Added by the Troj/Drsmartl-D Trojan.
debugger dbg32.exe X Added by W32/Mytob-FW WORM!
wizz dazzler.exe X Reported by Kaspersky Anti-Virus as Win32.Dialer.is TROJAN!
[Various Names] Dest068.exe X Part of the Wareout infection as described here.
[Various Names] dialer423.exe X Part of the Wareout infection as described here.
[Various Names] DCC_send.exe X Part of the Wareout infection as described here.
[Various Names] diskserv.exe X Part of the Wareout infection as described here.
[Various Names] DTOURS.exe X Part of the Wareout infection as described here.
[Various Names] defect08.exe X Part of the Wareout infection as described here.
[Various Names] driver64.exe X Part of the Wareout infection as described here.
dmcoj.exe dmcoj.exe X Added by the Troj/RuinDl-K Trojan.
BODefenderDrv DefenderDrv.sys X Added by the Troj/GrayBrd-BF backdoor Trojan.
dKernel dkernel.exe X Added by the W32/Decoy-A worm.
Data Layer 2 datalayer.exe X Added by the W32/Rbot-BNF worm and IRC backdoor.
Domain Name Resolve Service dnsresolver.exe X Added by the W32/Rbot-BYB worm and IRC backdoor.
DirectX Service directx.exe X Added by the Troj/Crybot-B worm and IRC backdoor.
configuration loader DVD-Player.exe X Added by a variant of the W32/SDBOT WORM!
dlink system tray dlnetst.exe U Related to D-Link DGE-530T PCI card for servers and workstations.
{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D} dxmpp.dll X A file used by the rogue antispyware app, SpyFalcon, to issue fake security alerts on your taskbar.
DirectX Plugin dxreg.exe X Added by the Troj/Theef-M backdoor Trojan.
directut directut.dll X Added by the Troj/Goldun-BX Trojan. This infection utilizes the directout.sys rootkit.
Windows Plug and Play Service 32 BIT dllmanager.exe X Added by the W32/Rbot-CGK worm and IRC backdoor.
directpt directpt.dll X Added by the Troj/Haxdoor-AX Trojan. This infection utilizes the directprt.sys rootkit.
atomix dho.exe X Added by the W32.Hotmatom MSN Hotmail worm.
wininet.dll dfrgsrv.exe X Added by the Troj/DwnLdr-FS downloader Trojan.
dvd4free dvd4free.dll X Added by the Troj/Haxdoor-BC Trojan. This infection utilizes the dvdkernl.sys rootkit.
UDP checksum correction dvdkernl.sys X Added by the Troj/Haxdoor-BC Trojan.
Win32_Duel_v2 Duel_v2.exe X Added by the W32/Dref-L mass-mailing worm and virus.
digisrv DigiSrv.exe U Related to camera software from Digital_Dreams._
dvdcheck DVDCheck.exe N Automatic firmware updates for HP DVD writers.
lto manager DesktopLtoManager.exe Y Related to Global_Positioning_System (GPS) found on HP iPAQ hw6500 unit and others.
watchdog DVDCheck.exe N Automatic firmware updates for HP DVD writers.
{8c-c4-4a-a4-zn} dwdsregt.exe X Added by Adware.ZenoSearch ADAWARE!
dropspam lifestyle dslifestyle.exe X Added by the AdwareDropspam Slyware! Note: This will install even if you try to abort it.
[not used] dcompcss.exe X Added by the Troj/PPdoor-AQ Trojan.
Win32_Duel Duel.exe X Added by the PE_LUDER.A-O virus/worm. This virus infects only .exe and .scr files.
Printer direct access directout.sys X Added by the TSPY_GOLDUN.EG rootkit.
dcomcfg.exe dcomcfg.exe X Added by the Troj/Zlob-IK downloader Trojan.
(2C1CD3D7-86AC-4068-93BC-A02304BB8C34) dcom_16.dll X Added by the Troj/Agent-BIW backdoor Trojan.
(9F81D88C-C298-9935-C5D1-40AA4DB91155) dmdlgs.exe X Added by the Troj/Zlob-JF downloader Trojan.
ipconfig drvsys.exe X Added by the Troj/Erazer-A Trojan.
WDVB 05 dvb06a.sys X A variant of Troj/Haxdor-Fam rootkit.
dvb03a dvb03a.dll X Added by the Troj/Haxdoor-CF Trojan. This infection is stealthed/hidden by the dvb06a.sys rootkit.
{1C3B31AE-FD16-D2CE-43FF-DC4CD5C1BC5E} dvdcap.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
DllHost dllhost.exe X Added by the BKDR_PROSTI.A backdoor.
{2C1CD3D7-86AC-4068-93BC-A02304BB8C34}] dcom_20.dll X Identified by Kaspersky Antivirus as Trojan-Proxy.Win32.Xmiler.b.
ddcyw ddcyw.dll X Added by the Troj/ConHook-I information stealing Trojan.
[not used] dmadoin.exe X Added by the Troj/Prosti-BU backdoor Trojan.
{3e4155b8-5a4a-4e95-83b2-ab032da9acbc} dnefhw.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
caidiysetup DIYNETSetupUni.exe X Added by the DIYNet Installer adware installer.
DiscUpdateManager DiscUpdateMgr.exe N Digital Interactive Systems Corporation Inc's DISCover

Found on Windows Media Center versions. "The company’s patented Drop ’n’ Play technology provides a simple, console-like experience when playing PC titles allowing for seamless play of CD/DVD-based games while its unique Parental Control system incorporates ESRB ratings to help users limit access to younger players."
IO Direct printing service directprt.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
Microsoft Directx directxat.exe X Added by the W32/Sdbot-BXF worm and IRC backdoor.
MMX virtualization service dxtpdh.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
MMX2 virtualization service dxtpdx.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
dxtpdx dxtpdx.dll X Added by the Troj/Haxdoor-CI Trojan. This infection utilizes the dxtpdh.sys rootkit to hide itself and its components.
[not used] dllhst2d.exe X Added by the Troj/Sharp-R backdoor Trojan.
soldig digsol.exe X Added by the W32.Kidala.E@mm mass-mailing worm.
ControlPanel datingtool.exe X Added by the Trojan.Bookmarker.K Trojan that adds bookmarks to Internet Explorer.
DNS Event dllhost.exe X Added by the Infostealer.Svcstor information stealing Trojan. This infection should not be confused with the legitimate Windows file c:\Windows\System32\dllhost.exe.
INPUT/OUTPUT printing ddirectxt.sys X A variant of the Haxdoor rootkit.
ddirectz ddirectz.dll X A variant of the Haxgen Trojan. This infection utilizes the ddirectxt.sys rootkit to hide itself.
MS Software Shadow Download Provider dnlsvc.exe X Added by the Troj/NTRootK-AA Trojan . This infection is installed with the msdirect.sys rootkit in order to hide itself.
dptracker dptracker.exe U Related to CamTrack webcam software that enhances the way people video chat. Note: located in C:\Program Files\DigitalPeers\CamTrack\
dla DLACTRLW.EXE U Related to Sonic CD/DVD burning applications.
dnam d140113.a.Stub.EXE X Added by Downloader_Stub_A TROJAN! Can severely compromise system security, stealth installed.
btopenworld DialBTYahoo.exe U Related to British Telecommunications Yahoo! Internet Connection Manager.
defender defender25.exe X Known malware identified by PREVX Note: located in C:\
deletehistoryfree dhf.exe U Related to Delete_History_Free Privacy protection software for deleting Internet surfing and other computer activity tracks from your PC.
dell photo aio printer 942 dlbubmgr.exe N Related to Dell_Photo_Printers and provides additional configuration options for these devices. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems. Note: located in C:\Program Files\Dell Photo AIO Printer 942\
dvdxghost DVDGhost.EXE U Related to DVD_Ghost utility to make your software DVD players and DVD copy/backup softwares restriction-free, and copy/backup DVD to hard disk. Note: located in C:\Program Files\DVD Ghost\
m-audio delta taskbar icon DeltTray.exe N M-Audio Delta Control Panel for M-Audio brand Delta series audio cards. Shows an icon notification tray (like antivirus and messenger programs), but it can also be accessed through the control panel.
motorola desktop suite DesktopSuite.exe U Related to Motorola_ Desktop_Suite This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems. Note: located in C:\Program Files\Motorola\Motorola Desktop Suite\
nero drivespeed DRIVESPEED.EXE N Related to Ahead_Nero CD writing software.
windows automatical updater dcz.exe X Added by the RBOT.CXS
sidebar dsidebar.exe U Related to Desktop_Sidebar provides you with instant access to the information you most desire by grabbing data from your PC and the internet. The result is a dynamic visual display you configure and control.
atuvp dtor.exe U Added by the Spyware.Ultraview surveillance software. This software should be uninstalled if not installed by yourself.
MicrosoftUpdate downnew.exe X Added by the Troj/Tanto-D backdoor Trojan.
downs downs.exe X Added by the Troj/Bckdr-MNR Trojan.
[Unknown] docentd.sys X A variant of the Haxdoor rootkit.
docent0 docent0.dll X Added by a variant of the Haxdoor Trojan. This infection utilizes the docentd.sys rootkit.
Desktop Adviser deskadv.exe U Added by the Spyware.Deskadv surveillance software. Spyware.Deskadv captures screenshot of your computer. It can record all desktop activity including web browsing, applications used, email activity and anything else which is visible on the screen. This software should be uninstalled if not installed by yourself.
DP1112 DP.sys X Added by the Troj/Puper-RU data-harvesting Trojan.
<not used> DisMgnt.exe X Added by the Troj/Enfal-A Trojan.
docent2 docent2.dll X Added by a variant of the Goldun Trojan.
Duty Manager Helper dutymgx.exe X Added by the Troj/Agent-CIT backdoor Trojan. Troj/Agent-CIT provides a remote command shell, allowing an attacker to run arbitrary commands on the infected system.
MSRegScan DDSSDemo.exe U Added by the Spyware.SystemSleuth surveillance software. Spyware.SystemSleuth is a spyware program that monitors user activity, logs keystrokes, and captures screenshots. This program should be uninstalled if not installed by yourself.
WINDOWS SYSTEM64 DVDdriver3628.exe X Added by the W32/Mytob-IY mass-mailing worm and IRC backdoor Trojan..
Explorer 2238 dxvwogky.exe X Added by the Troj/Agent-CPI backdoor Trojan. Please note that the filename for this infection is random. It will always start with dxvw, but the characters afterwards will not be shown. Other examples include dxvwevgm.exe, DXVWGFZV.EXE, and dxvwtsqn.exe.
dmjht.exe dmjht.exe X Added by the Troj/DownLd-AAJ Trojan.
mallarmust dmhelpserver.exe X Added by the W32.Rahack.H worm. W32.Rahack.H is a polymorphic worm that spreads to computers running Radmin software by exploiting weak passwords to connect to the Radmin server.
Advanced DHTML Enable dihd.exe X Added by the Troj/Ranck-EV proxy Trojan. Troj/Ranck-EV allows a malicious user to relay HTTP traffic through a compromised computer.
{6570b782-1a41-4053-b2c9-12c7fcf0d84d} duxzj.dll X A Trojan used by the rogue anti-spyware program VirusBurst. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBurst program on your computer.
<not used> daniwshb.dll X Added by the W32.Stration.AC@mm worm. W32.Stration.AC@mm is a mass-mailing worm that gathers email addresses from the compromised computer.
Dragon Age - Bioware dragonage.exe X Added by the W32/Vanebot-M worm and IRC backdoor.
Windows APCI Verifier dhcpserv.exe X Added by the W32/Rbot-FON worm and IRC backdoor.

W32/Rbot-FON spreads:
- to computers vulnerable to common exploits, including: SRVSVC (MS06-040), WKS (MS03-049), MSSQL (MS02-039) and Realcast
- to network shares
DeluxeCommunications Dxc.exe X DeluxeCommunications is the successor to the Surf Sidekick series of popup delivery adware programs. These programs will display popups on your computer based upon the content of pages you are currently viewing. This program tends to be bundled with other malware.
DLMon DLMain.dll X Added by the Troj/Agent-DIX Trojan.
<not used> dmdsmp4s.dll X Added by the W32/Stratio-AR mass-mailing worm and backdoor.
(default) DDRAWX32.VDX X Added by the W32/VB-CQZ worm.
{dfa61db1-388e-4c87-8d56-540fa229bcb4} dpfwu.dll X A Trojan used by the rogue anti-spyware program VirusBurst. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBurst program on your computer.
EGO31/08/2053 dfinstall.exe X Added by the Troj/Nopride-A backdoor Trojan. is the your Windows Internet Explorer favorites folder.
COM+ System Service dllhost.exe X Added by the W32/Tilebot-HT worm and IRC backdoor. W32/Tilebot-HT spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), PNP (MS05-039) and ASN.1 (MS04-007). The worm may also spreads via network shares and MSSQL servers protected by weak passwords.
{A5CDF7EC-751B-46aa-AD69-4005FE080DE8} dllsvc.exe X Added by the Backdoor.Bifrose.G backdoor. Backdoor.Bifrose.G is a Trojan horse that opens a back door and sends information to a remote server.
Microsoft Windows Services Edt dllrun32.exe X Added by the W32/Rbot-FUP worm and IRC backdoor. W32/Rbot-FUP spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user and by exploting WKS (MS03-049) (CAN-2003-0812) vulnerability.
DB08A038 DB08A038.EXE X Added by the Troj/PopWin-B Trojan.
AleVi DISKMONITOR.EXE X Added by the WORM_NETSKY.CA worm.
CTDrive drv???.dll X This malware is added by various rogue antispyware infections. The question marks (?) in the filename above are random letters. Rundll32.exe is a legitimate Windows file.
dc6_check dcmon.exe X Part of the rogue anti-spyware application SystemDoctor 2006. This application is known to install with malware that issues fake security warnings in your taskbar as a goad to scare you into purchasing the full version of this software. You should use the removal guide in the link below to remove this software.
DNS Support Protocol dnssvc.exe X Added by the Troj/Wollf- Trojan.
{40dcff6e-af8d-4183-8ebe-a82270ac449e} dcvwaah.dll X A Trojan used by the rogue anti-spyware program VirusBursters. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBursters program on your computer. This infection also loads under the gimmicks value in the ShellServiceObjectDelayLoad registry key.
directx.exe directx.exe X Added by the W32/Sdbot-CUJ worm and IRC backdoor.
Windows_systemD ddos.exe X Added by the Troj/DDoS-N DDOS Trojan.
{af4fd984-a939-4c32-82b2-8bae7abe9aec} dbqlrij.dll X A Trojan used by the rogue anti-spyware program VirusBursters. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBursters program on your computer. This infection also loads under the benumbment value in the ShellServiceObjectDelayLoad registry key.
Microsoft Update drive.exe X Added by the W32/Bifrose-PN worm and IRC backdoor.
DC6 dc6_startupmon.exe X Part of WinAntivirus Pro. This program is fake, stealth installed, and bundled with other malware. It is also on the Rogue anti-spyware list.
Provisioning Service Transaction down.exe X Added by the W32.Tanexor.A worm. W32.Tanexor.A is a worm that can spread through removable storage devices. It also opens a back door and downloads potentially malicious files on to the compromised computer.
Transaction Provisioning Service Down(0).exe X Added by the Troj/DDos-Q DDos Trojan.
System Distribution Controller disctrl.exe X Added by the W32/Rbot-GAM worm and IRC backdoor. W32/Rbot-GAM spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: SRVSVC (MS06-040), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812) and ASN.1 (MS04-007).
Windows Host Services dllhost.exe X Added by the W32/Tilebot-IH worm and IRC backdoor. W32/Tilebot-IH spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012), PNP (MS05-039), ASN.1 (MS04-007) and RealVNC (CVE-2006-2369).
MSWindows dmhelpserver.exe X Added by the W32.Rahack.W worm. W32.Rahack.W is a polymorphic worm that spreads to computers by exploiting weak passwords for Radmin servers and Windows network shares.
DMAScheduler DMAScheduler.exe N Associated with the HP DigitalMedia Archive product that comes bundled with many computers.
dd.92045.cc dd.92045.cc.exe X Added by the Troj/DDos-S ddos Trojan.
drivemngr drivemngr.sys X Added by the Troj/LdPinch-QB rootkit. This program, once loaded, hides other files related to this infection.
DxDialog dxdlg32.exe X Added by the Troj/VB-CXT Trojan.
Death.exe Death.exe X Added by the Troj/Delf-DZX Trojan.
Dispatcher dispatcher.exe X Added by the Troj/Dloadr-AS downloading Trojan.
<not used> dllvirtual.exe X Added by the Troj/Dadobra-IW information stealing Trojan for online banks.
<not used> dllvirtual.dll X Added by the Troj/Dadobra-IW information stealing Trojan for online banks.
<not used> dllvirtual.js X Added by the Troj/Dadobra-IW information stealing Trojan for online banks.
Dynamic DHCP dydhcp.exe X Added by the BackDoor-DKV backdoor Trojan.
Microsoft Directx clicks directxclickers.exe X Added by the W32/Rbot-GHT worm and IRC backdoor.
Disk Indexing Service disvc.exe X Added by the Troj/IRCBot-UX worm and IRC backdoor.
WDVB 05 drtw6a.sys X Added by the Troj/Haxdoor-DO rootkit.
Local Connection Manager DWUXJ.DLL X Added by the Troj/QQHelp-Gen downloader Trojan.
Plug and Play Support Driver driverpp.sys X Added by the Troj/RKProc-Fam rootkit. Can be installed with SmitFraud related Trojans.
{64281F9B-71AE-4C6B-9688-C3E820D99255} D563BA79B410.dll X Added by the W32.Gammima worm. W32.Gammima is a worm that spreads through removable media and steals information related to the MapleStory online game.
dservice dservices.exe X Added by the W32/Spybot-NM worm and IRC backdoor.
DNS Service dnssvc.exe X Added by the W32/Delbot-Z worm. W32/Delbot-Z spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: Symantec (SYM06-010) and SRVSVC (MS06-040). The worm may also spread via networks shares protected by weak passwords. W32/Delbot-Z includes functionality to download, install and run new software.
DLLHost dllhst.exe X Added by the W32.Rinbot.AR worm. W32.Rinbot.AR is a worm that spreads through network shares and by exploiting certain vulnerabilities. It also opens a back door on the compromised computer.
DVD43 DVDRegionFree.exe N Added by the DVD Region+CSS Free program. This program makes a DVD appear region free so you can watch it on any PC DVD reader. It only needs to be started when you are watching movies.
dimsntfy dimsntfy.dll Y Microsoft file related to credential roaming. Found in Windows 2003 and Windows XP SP3.
{716002db-288c-4bf0-80cd-a467e78d8b55} dxovx.dll X Part of the Zlob trojan that displays fake security alerts for the rogue anti-spyware program called SpyLocked.
Development Environment devenv.exe X Added by the W32/Delbot-AH worm and IRC backdoor.
Windows DLLISP Service dllisp.exe X Added by the W32/Tilebot-JN worm and IRC backdoor.
Microsoft Windows DMR Service dmrproc.exe X Identified by Kaspersky antivirus as Backdoor.Win32.SdBot.azs.
Desktop Desktop.com X Added by the W32/VB-DRN virus and worm.
dokument dokument.exe X Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded.
daLang MistiQ daLang MistiQ.exe X Added by the W32.Yadurna.A worm. The user is presented with a password recovery dialogue once the malicious program is downloaded.
DNSE DNSE.exe X Startup program associated with WinAntiVirus Pro 2007 and Privacy Protector. WinAntiVirus Pro 2007 and Privacy Protector are rogue anti-spyware programs that displays fake alerts, and downloads other programs onto user's machine without permission.
Creative Devldr32 devldr32.exe X A variant of the IRCBot family of worms and IRC backdoors.
DELXP Protocol delxp.exe X A variant of the IRCBot family of worms and IRC backdoors.
DeadKitty DeadKitty.exe X Added by the W32/DeadCat-A network worm.
DIVX Video Player DIVXPloyer.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DRam prosessor dll.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
DRan posessor DAP.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Dowmingzu Dowmingzu.dll.vbs X Added by the VBS/Solow-E worm.
msig disk10.exe X Added by the Troj/Banbra-KF Trojan.
DSKEY DsKey.exe X Added by the Troj/Starter-G Trojan.
ReminderPostBoot dobo.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
drtw3a drtw3a.dll X Added by the Troj/Haxdoor-DO Trojan. This infection utilizes the NvVid.sys and drtw6a.sys rootkits to hide itself.
DRVMCDB drvmcdb.sys U Related to Sonic CD and DVD burning products.
{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} dosmouse.exe X Added by the W32.Dosmouse worm. W32.Dosmouse is a worm that copies itself to the root of all drives, including network shares and removable media.
{283542BD-85A0-E2C1-0101-050306050500} d6k3S.exe X Identified by Kaspersky as Backdoor.Win32.Bifrose.acs.
{0c5a0fff-9164-493b-93e0-17446374e0a0} dtjby.dll X Trojan that infects your computer with the rogue anti-spyware program called SpyLocked.
dpl1npwm dpl1npwm.dll X Added by the W32/Stration-NZ worm.
dlcipscl dcpavss.exe X Added by the Troj/Mailbot-CB Trojan.
DirectX d3d8xof.dll X Added by the W32.Almanahe.C worm.
Directory Opus Desktop Dblclk dopusrt.exe U Part of the Directory Opus Desktop Windows shell replacement.
Windows Security System drivers.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winjava xml dirx9.exe X Identified as the Sdbot.EEB worm and IRC backdoor Trojan.
DNS Manager dnsmgr.exe X Identified as W32.Wargbot.
DanBtR270414 DanBtR270414.exe X Added by the W32/VB-NIB worm.
Windows DHCP Client Service dhcp.exe X Added by the W32/Tilebot-JU worm.
ddivmw dvcsetup.exe X Identified as the Trojan-Proxy.Win32.Slaper Trojan.
jcidls dfmmaps.exe X Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
Debug Log dbglg.exe X Added by the Troj/Dloadr-BAJ Trojan downloader.
Microsoft IInternet domal.exe X Identified by Panda antivirus as Trj/Banker.HYW. If you are infected with this file then you should immediately change your online banking passwords and notify your banks.
dc dc.exe X Added by the W32/CoiDung-A worm.
{1871276A-3AE9-E43D-0400-000505000107} div52x.exe X Added by the Troj/Agent-FWO Trojan.
dlcgmon.exe dlcgmon.exe U Printer monitor for the DellP AIO 810 Photo printer.
dlcg_device dlcgcoms.exe U Printer monitor for Dell printers.
{44e670f2-d57b-4815-a576-955d17dbbf2d} dooep.dll X Part of the Zlob trojan that displays fake security alerts for the rogue anti-spyware program called SpyLocked.
DNS-Cache DNS.exe X Added by the Troj/Wollf-M Trojan.
audlmne32 dcmsxe.exe X Added by the Troj/MailBot-CF spam Trojan.
DoctorV DoctorVD.exe X Added by the DoctorVaccineZ rogue anti-spyware program.
Microsoft Autorun4 dllhost32.exe X Added by the W32.Ogleon.A worm. W32.Ogleon.A is a worm that spreads through removable storage devices. It also drops a copy of Infostealer.Gampass, on to the compromised computer.
UPSI_1.exe dc2.exe X Added by the W32/SillyFD-C worm that spreads to removeable storage devices.
UPSI_1.exe dc1.exe X Added by the W32/SillyFD-C worm that spreads to removeable storage devices.
Micosoft Data Core stuff datacorez.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Directxsp directxbt.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Directxspnew directxnew.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Directx push directxpushup.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Directx click directxclick.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Desktop Lock Loader DLoader.exe Y Added by the Desktop Lock program. Desktop Lock allows you to lock down your computer so other can not access it without the correct password.
Document Manager docmgr.exe Y Part of the EMBASSY Trust Suite program. Document Manager allows you secure folders and drives with encryption.
Desktop Satellite desksat.exe Y Client agent for the Desktop Orbiter remote administration program.
windows hostsrv dllhstsrv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojan
MS DLL Library Manager dllsys64.exe X Added by the Backdoor.Ranky backdoor Trojan.
Windows Protocol Deployment Manager D.tmp X Added by the Backdoor.Ranky backdoor Trojan.
Administrator di Dago Dago.exe X Added by the W32/Punya-B worm.
CueX44 Dago.exe X Added by the W32/Punya-B worm.
dllcache.exe dllcache.exe X Added by the W32.Vispat.A@mm worm.
dlcc_device dlcccoms.exe U Part of the Dell Printer software.
dlccmon.exe dlccmon.exe U Part of the Dell Printer software.
Windows Firewall Updater directxxx32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Desync Control desyncx.exe X A variant of the IRCBot.UG family of worms and IRC backdoor Trojans.
79F5137E DBB6ED81.EXE X Added by the W32/SlliyFD-G worm.
daskgfkkcx15 dasdsaads15.exe X Added by the Troj/OnlineG-Q password-stealing Trojan for online games.
dsadlsa14 dsakfsak14.exe X Added by the Troj/OnlineG-P password-stealing Trojan for online games..
daskaskfsak6 dsfids6.exe X Added by the Troj/OnLineG-K password-stealing Trojan for online games.
asdsaxcxz13 dasxcsx13.exe X Added by the Troj/LegMir-ARF password-stealing Trojan for the online game, The Legend of Mir.
{eb86b46a-d6db-4478-8f5f-06cb2ebc1b35} dyrwls.dll X Zlob Trojan that installs VirusProtectPro 3.5 and shows fake security alerts from your Windows taskbar.
{45120101-18A2-C5D7-C989-600851395B52} d3dx9_62.exe X Added by a variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
Windows Dos Service dsserv.exe X A variant of the SDBot.bhk family of worms and IRC backdoor Trojans.
httpd deamon.exe X Added by the Win32.Tactslay backdoor Trojan.
Messanger deamon.exe X Added by the Win32.Tactslay backdoor Trojan.
browser deamon.exe X Added by the Win32.Tactslay backdoor Trojan.
StartMenu deamon.exe X Added by the Win32.Tactslay backdoor Trojan.
cpl deamon.exe X Added by the Win32.Tactslay backdoor Trojan.
Copernic Desktop Search 2 DesktopSearchService.exe U The Copernic Desktop Search program. This program allows you to index all the data on your machine and quickly search for it at a later time.
TA_Start dwdsregt.exe X Added by a variant of the Zenosearch adware. Adware.ZenoSearch is an adware that displays pop-up ads based on searches the user performs on popular web search engines.
DRam prosessor DTBoT.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
Windows Updt Maschishkha Dnmee33.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DivX video codec library DivXsm.exe X Added by the W32/Sdbot-DHC worm and IRC backdoor.
DOSPrint Service DOSPrint.exe Y Added by the DOSPRINT printer program. Allows your DOS programs to print to Windows printers.
Driver Update dvupdate.exe X Added by the W32/MyDoom-BX email worm.
igndlm.exe DLM.exe N Added by the Fileplanet Download Manager. If you do not have this program start automatically, then any queued or broken downloads will not automatically resume. You can, though, start the program as necessary to continue these instructions.
Microsoft Agent dvdhost.exe X A variant of the Sdbot-DFH family of worms and IRC backdoor Trojans.
dmupdate dmupdate.exe X Added by the W32/Agent-GAT worm.
{B7-7D-D0-08-ZN} dwdsregt.exe X Added by the Troj/Agent-GBC Trojan.
dcc dcc_.exe X Added by the Troj/Agent-GBJ Trojan.
msword docx.exe X Added by the W32/Codox-A worm.
dumprep dump.exe X Added by the W32/Codox-A worm.
{42311A42-AC1B-158F-FD32-5674345F23A4} dhdpri.dll X Added by the Troj/QQPass-AOX Trojan.
documenti_personali.exe documenti_personali.exe X Added by the W32.Vispat.C@mm worm.
SysLibrary DefLib.sys X Added by the Troj/NtRootK-CA rootkit.
DL5 deamon.dll X Added by the W32.Almanahe.A worm.
Microsoft DLL Verifier Desktop.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
{9f5cb985-d4a4-49af-9185-133f956b5756} ddomv.dll X Zlob Trojan that installs VirusProtectPro 3.7 and shows fake security alerts from your Windows taskbar.
{b8ea5f37-7327-4923-9808-8fd3b6f0d529} ddllup.dll X Added by a Zlob Trojan which installs AntiVirgear 3.7 and display fake security alerts in your Windows taskbar.
Version3 direct3dx.dll X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Update DBOT.exe X Added by the W32/Sdbot-DHT worm and IRC backdoor.
Windows Update Draven draven.exe X A variant of the WORM_SDBOT.AXB family of worms and IRC backdoor Trojans.
AudioDrvEmulator DLLML.exe Y Part of Creative Labs sound card drives. Used to load DLL programs.
Systems Service drivex.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Directx Startup Drivers direct.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
drvsvp drvsvp.dll X Added by a variant of the MyGeek/CPVFeed adware.
Microsoft Dir32 Dirhost.com X Added by the W32/IRCBot-YC worm and IRC backdoor.
MicrosoftDriverService32 drsys32.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft System Service dnservice.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Salestart dcmon.exe X Related to the rogue anti-spyware application System Doctor. This application is known to install with malware that issues fake security warnings in your taskbar as a goad to scare you into purchasing the full version of this software. You should use the removal guide in the link below to remove this software.
Mircosoft Windows Development Environment devenv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microst Serviment da.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Datakey's Token Service dkcktkn.exe Y Security software used with Datakey products.
Datakey's Log Service DkLog.exe Y Security software used with Datakey products.
TempCom D4C4B.com X Added by the W32/Traxg-M worm.
bokard dfrep.dll X Zlob Trojan that installs the rogue anti-spware program, VirusRay 3.8.
Windows Display Coupler display.exe X Added by the Troj/IRCBot-YS worm and IRC backdoor.
DrAntispy DrAntispy.exe X Added by the DrAntiSpy rogue anti-spyware program. DrAntiSpy is a misleading application described as a spyware removal utility that may give exaggerated reports about potential risks on the computer.
DioCleaner DioCleaner.exe X The rogue anti-spyware program called DioCleaner.
albury dsibr.dll X Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar.
DolphinsScreenServer DolphinsScreenServer.exe N Software from the MercurySports for streaming information about the Miami Dolphins US Football team. Slightly loose Terms or Use and Privacy policy, so make sure you read it when installing.
DolphinsScreenServerSvc DolphinsScreenServer.exe N Software from the MercurySports for streaming information about the Miami Dolphins US Football team. Slightly loose Terms or Use and Privacy policy, so make sure you read it when installing.
Symantec Antivirus professional dfrgfrat.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Symantec Antivirus professional dyndns.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Win32 Update dl32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows ACPI Verifier dhcpserv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Automatical Updater dcz.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ddkret ddkret.dll X Added by a variant of the MyGeek/CPVFeed adware.
DrvIcon DrvIcon.exe Y Vista Drive Icon changes the drive icons shown in Windows "My Computer", to a nearly Vista drive icon, showing the drive's free space with a smooth colored horizontal bar.
DLBTCATS DLBTtime.dll ? Part of the Dell Printer software.
Deus Cleaner DCleaner.exe X Rogue anti-spyware that uses misleading and aggressive advertising as well as exaggerated security reports.
dpup dpup.exe X Added by the Troj/Dloadr-BFT Trojan.
DeviceNP DeviceNP.dll Y Installed with certain Hewlett Packard software/hardware.
DWQueuedReporting dwtrig20.exe N The file has a description of Watson Subscriber for SENS Network Notifications and is installed with Windows Live program. It is related to System Event Notification Services from Microsoft.
DrProtection DrProtection.exe X Added by the DrProtection rogue security software. The program reports false or exaggerated system security threats on the computer.
Rising Driver driver.exe X Added by the W32/SillyFD-TL worm.
DelAutorun DelAutorun.bat X Added by the W32/Silly-G worm.
d9fw5i91p d9fw5i91p.exe X Added by the Troj/Agent-GIW backdoor Trojan.
disnisa disnisa.exe X Added by the W32/Dorf-AE worm.
Microsoft derservice.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
win32serv devicer.exe X Added by a variant of the Win32/Pushbot worm and IRC backdoor. Win32/Pushbot is a family of worms that spread using MSN Messenger.
System Device devices.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemDevic devic.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
DirectX For Microsoft® Windows dtxservice.exe X Added by the Troj/ProAgent-A Trojan.
CatalystRegistration dolce.exe N Program which will periodically remind you to register your ATI products.
Microsoft DLL Source dllsrc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft DLL Authentification dllsecure.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft DLL Host Service dllmemhost.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
dhlp dhlp.sys X Identified as a variant of the Win32.Rootkit.Gen rootkit.
msvccc66 dload.exe X A variant of the W32/Rbot-GLS family of worms and IRC backdoor Trojans.
Microsoft DLL Suspension dllsuspend.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft DLL Monitor dllmonitor.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
{A9260CCB-B2B6-7B3B-D778-C92DBC5AEE18} dev-point.exe X Identified as a variant of the Trojan-Downloader.Win32.Small.hjf Trojan.
Capture Device Service DevSvc.exe ? Manages device arrival and removal event. This service is provided by InterVideo.
Microsoft DLL Monitor dllmon64.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
mp3 audio dxdss.sys X Identified as a variant of the Backdoor:Win32/Rustock.gen!C malware.
DWPopup DWPopup.exe X Added by the DwrWeb potentially unwanted anti-spyware application.
BitTorrent DNA dna.exe N Added by the BitTorrent DNA bittorrent client.
Dot1XCfg Dot1XCfg.exe X Identified as a variant of the Trojan-Downloader.Win32.Adload.pr malware.
DirectX9 direct3d.exe X Identified by Kaspersky Antivirus as a variant of the Trojan.Win32.Agent.eak Trojan.
<not used> DTMONX.EXE ? Desktop Printer Driver from Microsoft. Anyone know what it does?
CTDrive drvsoh.dll X Identified as a variant of the Trojan.Win32.Dialer.yz malware. Do not delete C:\Windows\System32\rundll32.exe as it is a valid file.
MSDrive drvsoh.dll X Identified as a variant of the Trojan.Win32.Dialer.yz malware. Do not delete C:\Windows\System32\rundll32.exe as it is a valid file.
CTDrive drvmod.dll X Identified as a variant of the Trojan:Win32/Adialer.OP Trojan. Do not delete C:\Windows\System32\rundll32.exe as it is a valid file.
MSDrive drvmod.dll X Identified as a variant of the Trojan:Win32/Adialer.OP Trojan. Do not delete C:\Windows\System32\rundll32.exe as it is a valid file.
DetectorApp DetectorApp.exe U Related to the MyDVD DVD authoring program.
dscactivate dsca.exe N Starts Dell's remote support program.
<not used> ddcyvtr.dll X Added by an unknown malware.
Desktop SMS DesktopSMS.exe U Desktop SMS gives you the functionality and SMS sending capability at www.aql.com directly from your desktop
DVD-RAM_Service DVDRAMSV.exe Y Matsushita DVD-Ram driver.
Disk Volume Shadow Copy dvssvc.exe X A variant of the Backdoor.Win32.SdBot.aad family of worms and IRC backdoor Trojans.
WinSysModule dsrss.exe X Added by the Trojan-Spy.Win32.KeyLogger.lp keylogger. If you are infected with this malware it is advised that you immediately change all of your online passwords.
Windows Management Service dmodo.exe X Added by the Trojan.Flush.A Trojan.
DLADiag DLADiag.EXE ? Related to products from Added by the Sonic Solutions.
Drmupgds Drmupgds.exe X Identified by Kaspersky antivirus as a variant of the Trojan-Downloader.Win32.Adload.qy Trojan.
DrvUnknown DrvUnknown.dll X Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
DrvBoot DrvBoot.dll X Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
DriveComponent DriveComponent.dll X Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
DrvRom DrvRom.dll X Identified by Kaspersky as a variant of the Trojan.Win32.Agent.evy Trojan.
Microsoft Service Disk Cycle disksave.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
WinDLL (dlfksdld.exe) dlfksdld.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Disk Essensial Tools detsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Disk Panel Configuration dpcsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> dnsq.dll X Added by the PE_PAGIPEF.CE-O virus.
Windows Advanced Manager dodolook_7630.exe X Added by the Troj/Agent-GSJ Trojan.
<not used> ddabc.exe X Added by the PE_TRATS.E-O virus.
Win Defrags defrag.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
diskmgr diskmgr.dll U Added by the Spyware.PCAgent surveillance software. This software should be removed from your computer if installed without your knowledge.
Windows 32-bit DLL Integrity Verifier dllrun.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
OracleOraHome81Agent dbsnmp.exe Y Oracle Intelligent Agent Executable. The displayname, service name, and path name may be different depending on the version of Oracle installed.
dwnrpofk dwnrpofk.dll X Added by a variant of the MyGeek/CPVFeed adware.
Dcom Helper dcmhelp.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DataHealer DataHealer.exe X Added by the DataHealer rogue anti-spyware program.
Windows Advanced Manager dodolook_7494.exe X Added by the Troj/Lodok-A Trojan.
DvVideo32 dvvid32.exe X Identified as a variant of the TROJ_TINY.FD malware.
DbgHlp32 DbgHlp32.exe X Added by the Trojan.Vaklik.OT password-stealing Trojan.
AutoInclude DIL<number>.tmp X Added by the Trojan-Downloader.VB.AWJ Trojan. Please note that the filename will start with DIL, then have a number, and then end with .tmp. So an example filename would be DIL2.tmp.
important dcggain.dll X Zlob Trojan that infects you with the VirusHeat rogue anti-spyware program. Please use the guide below to remove this infection.
DrvDrive DrvDrive.dll X Related to various rogue anti-spyware programs and the fake codecs that install them.
dsktbwfe dsktbwfe.dll X Identified as a variant of the Adware.Agent malware.
DRM Upgrade drmupgd.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DVD Upgrade dvdupgd.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DTM Protector dprot.sys X A variant of the Haxdoor rootkit.
divxrs divxrs.dll X A variant of the Haxdoor Trojan. This infection is hidden by the dprot.sys rootkit.
divxps divxps.dll X A variant of the Haxdoor Trojan. This infection is hidden by the klite.sys rootkit.
DCOM CNF dcomcnf.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
DDE Sharer ddesharer.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Defrag FAT32 dfrgfat32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
droute droute.dll X Identified as a variant of the BDS/Agent.evh malware.
Windows Management Service dmnds.exe X Added by the Troj/DNSChan-MK dns changing Trojan.
Windows Management Service dmkkn.exe X Added by the TROJ_ALUREON.AI Trojan.
DELL Webcam Manager DellWMgr.exe U Webcam software bundled with Dell laptops.
DXEC02 dxec02.sys Y Audio driver for audio chipset from Knowles.
DirectX multi version dxcombin.exe X Unknown malware.
Desktop Manager DesktopMgr.exe N Added by the Blackberry Desktop software. This software allows you to manage your device and synchronize it with desktop software.
dionpis dionpis.exe X Added by the Troj/PSW-FF password-stealing Trojan.
KAT Dank.vbs X Added by the VBS/Keyes-A VBScript worm.
Systray Dank.vbs X Added by the VBS/Keyes-A VBScript worm.
M-Audio Taskbar Icon DeltaIITray.exe U Software to manage M-Audio Delta audio cards.
DeltaIITaskbarApp DeltaIITray.exe U Software to manage M-Audio Delta audio cards.
dllcache32.exe dllcache32.exe X Added by the W32/SillyFD-S removable media worm.
%Temp%\delwdef2008.bat delwdef2008.bat X Added by the WinDefender 2008 rogue privacy program.
darkbyte23 darkbyte23.exe X Added by the W32/DarkBit-A worm.
PHIME2002ASync dumprep.exe X Added by the W32/Puress-B worm. This infection should not be confused with the legitimate C:\Windows\System32\dumprep.exe.
VisualStyle desktop.sysm X Added by the W32.Azero.A virus.
Virtual CD-ROM Driver dwave.sys X Identified as a variant of the Trojan-Spy.Win32.Goldun.api rootkit.
Windows Services dllhost.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Device Hardware devicehnd.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Device IO System deviceio.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Device Security Driver devicesec.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Device Security dvcsecure.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Device Security Manager dvcsecure.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Debug Manager DebugManager.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
dgksvbpn dgksvbpn.dll X Identified as a variant of the VideoAccessCodec adware.
Windows Service Agent dsass.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
WinDLL (dasda.com) dasda.com X Identified as a variant of the Backdoor:Win32/Akbot.gen malware.
MSN DebugMan.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
dtseqrxk dtseqrxk.dll X Identified as a variant of the VideoAccessCodec adware.
Windows DreamScene DreamScene.dll Y Part of Windows Vista Ultimate's DreamScene extra.
{164EB102-BDC3-BC08-0004-000303080604} divxupdate.exe X Identified as a variant of the Worm.AutoRun.DHA malware.
DscSmartSrv DscSmartSrv.dll X Identified as a variant of the Win32:PureMorph malware. This malware will issue fake security alerts on your computer.
ddwmon ddwmon.exe ? Unknown Toshiba driver.
headstock dvxwfz.dll X Zlob Trojan which installs the VirusResponse Lab 2009 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusResponse Lab onto your computer without permission. This Trojan pretends to be a fake video codec required to watch videos online.
DNHelper32 DNHlp32.exe Y Related to the DESkey data security program.
hemielytron duzakwq.dll X Zlob Trojan which installs the VirusResponse Lab 2009 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusResponse Lab onto your computer without permission. This Trojan pretends to be a fake video codec required to watch videos online.
System Security drivers.exe X Added by the W32/AutoRun-NN removable media worm.
DW_Start dwwnw64r.exe X Identified as a variant of the AdWare.Win32.ZenoSearch.am malware.
internet security manager dll32.exe X Identified as a variant of the IRC-Worm.Win32.Small worm.
.Net Recovery dotnetfx.dll X Added by the W32.Delezium virus. W32.Delezium is a virus that infects executable files and deletes certain files on the compromised computer.
JDe-sign Electronic Signature Capture dsignature.exe ? Related to software from John Deere.
DiscWizardMonitor.exe DiscWizardMonitor.exe ? This file is associated with Seagate's DiscWizard software which may come bundled with various hard-drives or may be installed separately.  What this particular file does has yet to be determined.

GPS driver dfrhost.exe X Added by the W32/Tilebot-LA worm.
Portrait Displays Display Tune Service DTSRVC.exe U This file is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.  If using the monitor buttons is sufficient for you, you can disable the service.  Unknown at this time if setting the service to manual would cause the program to not work.
Portrait Displays Display Tune Service DTSRVC.exe U This file is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.  If using the monitor buttons is sufficient for you, you can disable the service.  Unknown at this time if setting the service to manual would cause the program to not work.
DISCover DISCover.exe N Preinstalled on certain computers, DISCover Drop and Play, developed by Digital Interactive Systems Corporation, is used in playing games.
dll dll32.dll X Identified by Nod32 as a variant of the Win32/Tinxy.AB malware.
{28ABC5C0-4FCB-11CF-AAX5-21CX1C635622} Drive13.exe X Added by the W32.SillyFDC.BBL removable media worm.
DUSB DarksUSB.exe X Added by the W32/AutoRun-ADT worm.
compmgmt.exe debug_32.exe X Added by the W32/AutoIt-BS worm.
DW6 DesktopWeather.exe N The Weather Channel's desktop weather program.
{9D71D88C-C598-4935-C5D1-43AA4DB90836} Dr-Crypter.exe s X Added by the Troj/Bifrose-XI Trojan.
DrvFltIp Drvfltip.sys X Added by the UnVirex rogue anti-virus program.
Windows Dynamic Library Cache dllcache.exe X Added by the Troj/Inject-HT injector Trojan.
Data Transfer Service DTS.exe U Used by IBM Thinkpad's fingerprint identification software.
<Random Names> dinizuha.dll X Vundo file with random names and means of starting up and other ways of getting into the computer.

Please note that the CSLID is also random.
<Random Names> dinizuha.dll X Vundo file with random names and means of starting up and other ways of getting into the computer.

Please note that the CSLID is also random.
SessionMngr dirlock.exe X Added by the W32.Daprosy worm. W32.Daprosy is a worm that spreads through mapped, fixed, and removable drives. It may also spread through email.
DirLocker dirlock.exe X Added by the W32/Autorun-AMS removable media worm.
DT HPW DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
Microsoft Driver Setup dllhost.exe X Added by the W32/Autorun-AOZ worm and IRC backdoor.
%Temp%\delInstav2009.bat delInstav2009.bat X Added by the unregistered version of the Personal Anti Malware Center rogue anti-spyware program.
%Temp%\delav2009.bat delav2009.bat X Added by the registered version of the Personal Anti Malware Center rogue anti-spyware program.
%Temp%\delUpdav2009.bat delUpdav2009.bat X Added by the registered version of the Personal Anti Malware Center rogue anti-spyware program.
%Temp%\delInstavp2009.bat delInstavp2009.bat X Added by the registered version of the Personal Anti Malware Center rogue anti-spyware program.
DpAgent dpagent.exe U Program that allows you to login via a fingerprinter reader on certain Dell laptops.
Desktop Defender 2010 Desktop Defender 2010.exe X Added by the Desktop Defender 2010 rogue anti-spyware program.
Cerb DivXx.exe X Added by the Troj/KeyLog-LV Trojan.
Portrait Displays Display Tune Service dtsrvc.exe U This file is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.  If using the monitor buttons is sufficient for you, you can disable the service.  Unknown at this time if setting the service to manual would cause the program to not work.
Portrait Displays Display Tune Service dtsrvc.exe U

This file is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.  If using the monitor buttons is sufficient for you, you can disable the service.  Unknown at this time if setting the service to manual would cause the program to not work.

DQLWinService DQLWinService.exe ?

This file is a service associated with Intel Viiv Software which is installed on certain computers designed for digital media entertainment.

netmon dllcache.exe X Added by the Troj/Bckdr-RAA backdoor Trojan.
<Not Used> dinizuha.dll X Vundo file with random names and means of starting up and other ways of getting into the computer.
DnsCache dns_cache.vbs X Added by the W32/Autorun-AWI removable media worm. Please note that wscript.exe is a legitimate program and should not be deleted.
<Random names> dinizuha.dll X

Vundo file with random names and means of starting up and other ways of getting into the computer.

Please note, C:\Windows\System32\rundll32.exe is a legitimate program and should not be deleted.

<Random names> dinizuha.dll X Vundo file with random names and means of starting up and other ways of getting into the computer.  Please note that the CLSID will likely vary as well.
DefendAPc DefendAPc.exe X Added by the DefendAPc rogue anti-spyware program.
Desktop Security 2010 Desktop Security 2010.exe X Added by the Desktop Security 2010 rogue anti-spyware program.
DLCCCATS DLCCtime.dll Y Installed with certain Dell printers, this driver resolves timing issues involving communication between a Dell service and the printer.
Dump Dump.exe X Added by the W32.Zimuse worm. W32.Zimuse is a worm that spreads by copying itself to removable drives
dispenter dispenter.exe X Added by the Troj/Agent-MKK Trojan.
LAN dhcp.exe X Added by the W32/Rbot-GYI worm and IRC backdoor.
Dr. Guard drguard.exe X Added by the Dr. Guard rogue anti-spyware program.
DLCICATS DLCItime.dll Y This file coordinates timing between a print job and the computer when the computer is too busy to process the print job.
EDFcsn discfcsn.exe ? This file is part of the Enterprise Discovery Agent software originally developed by Peregrine Systems which was acquired by Hewlett-Packard.  Research has been unable to determine just what this file does, how it gets on the computer, in what instances it's needed, or if it's necessary to run at startup.
Digital Protection digprot.exe X Added by the Digital Protection rogue anti-spyware program.
davclnt.exe davclnt.exe X Identified by Sunbelt as a variant of the Trojan.Win32.Generic.pak!cobra malware.
DXEC01 dxec01.sys Y A sound driver from Knowles Acoustics.
COM+ System Application dllhost.exe Y Windows service that manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Dragon Age: Origins - Content Updater DAUpdaterSvc.Service.exe U Digital management system for Dragon Age: Origins downloadable content. If this service is disable downloadable content for Dragon Age: Origins will no longer function.
{67KLN5J0-4OPM-01WE-AAX5-314CCA322142} DT.exe X Added by the W32.Ircbrute.C worm. W32.Ircbrute.C is a worm that spreads by copying itself to removable drives and opens a back door on the compromised computer.
Data Protection datprot.exe X Added by the Data Protection rogue anti-spyware program.
DT ACR DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
Disk Defragmenter defragsvc.dll Y Provides Disk Defragmentation Capabilities.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
DHCP Client dhcpcore.dll Y Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
DNS Client dnsrslvr.dll Y The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not be registered. If the service is disabled, any services that explicitly depend on it will fail to start.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Wired AutoConfig dot3svc.dll Y The Wired AutoConfig (DOT3SVC) service is responsible for performing IEEE 802.1X authentication on Ethernet interfaces. If your current wired network deployment enforces 802.1X authentication, the DOT3SVC service should be configured to run for establishing Layer 2 connectivity and/or providing access to network resources. Wired networks that do not enforce 802.1X authentication are unaffected by the DOT3SVC service.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Diagnostic Policy Service dps.dll Y The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Juniper Network Connect Service dps.dll Y Manages secure network connections for the Juniper VPN client.
Defense Center defcnt.exe X Added by the Defense Center rogue anti-spyware program.
MagicTune DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
DivXUpdate DivXUpdate.exe N This file is the updater for the DivX video player.
WinDirectories ddcs.exe X Added by the W32/VB-ETN worm.
DellConnectionManager Dell.UCM.exe U Part of the Dell ControlPoint Connection Manager developed by SmithMicro Software .  Cannot discover what this specific file does.
DellControlPoint Dell.ControlPoint.exe U Part of the Dell ControlPoint software preinstalled on certain Dell computers.
Dell ControlPoint Button Service DCPButtonSvc.exe Y

This service is preinstalled on some Dell computers and is part of Dell ControlPoint software  and manages support for the Dell ControlPoint button.  Necessary if you want to use this software.

Adobes Updates ddosw.exe X Added by the Troj/Backdr-DC backdoor Trojan.
tmp defender.exe X Added by the Fake Microsoft Security Essentials Alert Trojan.
Driver Control Manager v4.6 devetnae.exe X Added by the W32/IRCBot-AGY worm and IRC backdoor.
police dll X Added by the Sus/MoleUltr-A malware.
Daemon Tools ATAPI driver daemontools.exe X Added by the Troj/Agent-OTX Trojan.
<not used> desktoplayer.exe X Added by the W32.Ramnit!inf worm and file infector.
Driver Control Manager v5.1 dvadescetr.exe X Added by the Troj/Agent-OVL Trojan.
doscp doscp.exe X Added by the W32/Taterf-AH worm.
DataMngr DataMngrUI.exe X MediaBar is Installed often without user's knowledge with various P2P programs, such as the free version of Bearshare.  Adware and redirections are associated with this toolbar and a companion toolbar that is installed with it.  Note, this file is often abbreviated as such: DATAMN~1.EXE

Other command lines and file paths associated with this file:

%programfiles%\Windows Searchqu Toolbar\DataMngr\DataMngrUI.exe

%programfiles%\BearShare Applications\MediaBar\DataMngr\DataMngrUI.exe

%programfiles%\Shareaza Applications\MediaBar\Datamngr\datamngrUI.exe
<not used> dwme.exe X Part of the family of the Rogue.WinAVPro family of rogues.
<not used> Desktop Security 2010.exe X Added by the Desktop Security 2010 rogue security program.
<not used> Desktop Defender 2010.exe X Added by the Desktop Defender 2010 rogue security program.
dslagent.exe dslagent.exe X Added by the Mal/Agent-UE malware.
Microsoft Default Manager DefMgr.exe U

Bundled with MSN Toolbar now known as Bing Bar, this file is also installed with Windows Live Essentials.  It sets the browser search defaults and notifies you when other programs try to change them.  If you don't use this toolbar, you don't need this program.

Note that this program includes the option of sending Microsoft further information about the configuration of your computer.

dso32 dsoqq.exe X Added by the W32/Taterf-AO worm.
dsc dsc.exe X Added by the Troj/Agent-SYC Trojan.
Dell DataSafe Online DataSafeOnline.exe U

Part of Dell DataSafe Online which is a file and disc backup service.  If you wish to use this service, this file must run at startup.

Windows Printing Driver doskeys.exe X Identified as a variant of the Backdoor.Graybird malware.
NT Printing Services6 dllhosts.exe X Identified by Kaspersky Antivirus as a variant of the Trojan-Downloader.Win32.Agent.aswc malware.
DllHst dllhst3g.exe X Added by the Troj/Bckdr-QQX backdoor Trojan.
NVIDIA Update Service Daemon daemonu.exe N Part of the display driver for Nvidia cards. The NVIDIA Settings Update Manager service is used to check new updates from NVIDIA's server.
DaemonUI DaemonUI.exe N This software provides a graphical user interface for the DaemonTools program.
TweakVIDesktops desktops.exe N Added by the TweakVI Vista system optimization software.
DualVaccine DualVaccine.exe X Added by the Korean rogue called DualVaccine.
DefenseVirusMain DefenseVirus.exe X Added by the Korean rogue called Defensevirus.
DriveHQ FileManager DriveHQClient.exe Y DriveHQ FileManager allows you to backup, synchronize, restore, and host files using DriveHQ online storage.
DrivehqBackup DrivehqBackup.exe Y DriveHQ Online Backup allows you to backup your files, emails, servers, and database online to DriveHQ's online storage facilities.
DSPrintKey DSPrintKey.exe N UPS label printing software.
DSPrinterMgr DSPrinterMgr.exe N UPS label printing software.
DivX Connected DivXConnected.exe Y Allows you to stream media stored on your computer to a TV that is connected to a DivX Connected device.
DS3 Tool DS3_Tool.exe Y MotioninJoy driver that allows you to use your Playstation 3 controller (Sixaxis or Dualshock 3) on a Windows computer.
DAmirr DAmirr.sys Y Part of the Desktop Authority administration program.
SQL Anywhere - bsiv dbeng50.exe Y Added by the SQL Anywhere database utility.
forteManager DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
ImageTune DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
DT Task DTHtml.exe U This file is the system tray icon of a program which is preinstalled on many computers, is in many monitor software packages, and is involved in adjusting monitor display settings by using a mouse instead of the monitor buttons.  EzTune, MagicTune, ImageTune, and forteManager are just a few of the software products this file is found in.
WinXPService DriverUpdate.exe X Unidentified worm and IRC backdoor.
Dock Login Service DockLogin.exe U Installed by Dell Dock. Only need to start if you use Dell Dock.
MediaFaceOnlinePluginsService dolcore.exe ?

Installed with MediaFACEOnline by Neato. Unable to determine as yet what this file does and if it's needed to run at startup.

DivX Download Manager DDmService.exe N

Installed with  DivX Web Player, a part of various Video software packages, this file is the download manager for the webplayer.  It does not need to run at startup as it will start when you start the web player.

Adaptive Server Anywhere - [varies] dbsrv9.exe ?

This file is the main executable for Sybase's Adaptive Server Anywhere version 9, also known as sql anywhere, intended for use in a server client setup.  Given that, please check with the database manager about whether this service needs to run at startup.  Note that the database is on the server, or should be to avoid file corruption.  There are ways to start the file manually, but that would have to be set by the one managing the database and server in question.  If you are NOT in a client server environment, this is not the correct version of the software to use for database management.

ATKMEDIA DMedia.exe N Asus software that is commonly installed on their laptops. This software allows Windows Media Center to be opened when you press the multimedia keys on the laptop.
Diagnostic Service System Host dcomcnfgui.exe X Added by the ACCDFISA Ransomware.
dom dom.exe X Added by the Troj/Agent-VGA Trojan.
drm drm.exe X Added by the Troj/Agent-VVY Trojan.
dplaysvr dplaysvr.exe X Added by the Troj/Mdrop-EBJ Trojan.
Defenceprivacy DefencePrivacy.exe X A Korean rogue anti-spyware program.
DriverMax_RESTART drivermax.exe Y This is the primary file for DriverMax by Innovative Solutions.  You can use the program to update, backup, and restore drivers.  When RESTART is part of the name and command for the file, this means that the computer must reboot in order to finish updating or restoring drivers.  Once that is accomplished, it should no longer be running in start up.
DriverMax drivermax.exe N

This is the primary file for DriverMax by Innovative Solutions.  You can use the program to update, backup, and restore drivers.  This program may be started manually when needed.

Adaptive Server Anywhere - [varies] dbeng7.exe U This file is the main executable for Sybase's Adaptive Server Anywhere version 7 personal database server, also known as sql anywhere, intended for use on a standalone computer and may be used for development.  Number of simultaneous connections are 10.  It is not for use in a server client setup; a different version of the software is needed for that.  There are ways to set up the software so that this file starts manually, such as when opening the database.  Please read the software manual for how to do that if you prefer to start the program manually.
Adaptive Server Anywhere - [varies] dbeng8.exe U This file is the main executable for Sybase's Adaptive Server Anywhere version 8 personal database server, also known as sql anywhere, intended for use on a standalone computer and may be used for development.  Number of simultaneous connections are 10.  It is not for use in a server client setup; a different version of the software is needed for that.  There are ways to set up the software so that this file starts manually, such as when opening the database.  Please read the software manual for how to do that if you prefer to start the program manually.
Adaptive Server Anywhere - [varies] dbsrv8.exe ? This file is the main executable for Sybase's Adaptive Server Anywhere version 8, also known as sql anywhere, intended for use in a server client setup.  Given that, please check with the database manager about whether this service needs to run at startup.  Note that the database is on the server, or should be to avoid file corruption.  There are ways to start the file manually, but that would have to be set by the one managing the database and server in question.  If you are NOT in a client server environment, this is not the correct version of the software to use for database management.
donx donx.exe X Added by the Infostealer.Donx Trojan.
Sysinternals Desktops desktops.exe U Added by the Sysinternals Desktops applications. Desktops allows you to organize your applications on up to four virtual desktops.
Denzi Denzi.exe N Denzi scans installed software and notifies you when a new version is available.
Symantec SymSnap VSS Provider dllhost.exe Y Services used to create system snapshots in Ghost and Backup Exec. If this service is not running it could cause certain functionality to be disabled from these programs.
DNSBENKELMAN DNSBENKELMAN X Added by the DNS-Keeper adware. DNS-Keeper hijacks your DNS settings and injects advertisements into web sites that you visit.
DoctoAVDownloadMgr DoctoAntiVirus.exe N Related to the DoctoAntivirus anti-malware program. This program is commonly bundled with free programs that you download off of the Internet. The developer uses shady tactics to promote their product.
IBUpdaterService dmwu.exe N Related to the SweetPacks Toolbar adware program. If you have trouble uninstalling this program, you can use the removal guide below.
shopper-z Updater Donte.exe X Added by the Shopper-Z adware. Shopper-Z is an adware program that displays intrusive advertisements in web sites that you visit.
Search Startups

Login

Remember Me
Sign in anonymously