| Status | Autorun name | Command | Description |
| X | data | msngs.exe | Added by the RBOT-ADQ WORM! |
| X | Data File | vdehost.exe | Added by the SDBOT-DOS TROJAN! |
| X | Data Layer 2 | datalayer.exe | Added by the RBOT-BNF WORM! Note - do not confuse with the legitimate Nokia file sharing the same filename - this one is located in %System% |
| N | Data LifeGuard | BACKWE~1.EXE | Data LifeGuard diagnostic tools for Western Digital's series of hard drives |
| N | Data LifeGuard LifeLine Lite installer | DLGLI.EXE | Backweb installer - see here |
| X | Data Protection | datprot.exe | Data Protection rogue security software - not recommended, removal instructions here |
| X | Data Restore Service | prq8.exe | Added by the KELVIR.AI WORM! |
| X | Data789 | Regedit.exe ....data789.tmp | Homepage hijacker |
| X | DATABASE MySql | [path] repcale.exe [path] beird.exe | Added by the RANDON-AL WORM! Both files are often located in %System%\qsws |
| N | DataCaching | FlashKsk.exe | SmartMedia Card management from the installation of a SanDisk reader for a camera's SmartMedia card and also adds the "Unplug and Eject Hardware" System Tray icon |
| U | DataCardMonitor | DataCardMonitor.exe | Mobile (USB) internet management tool by Huawei Technologies Co., Ltd as used by a number of providers including T-Mobile, Virgin Media, tele.ring and blueconnect |
| X | DataHealer | DataHealer.exe | DataHealer rogue security software - not recommended, removal instructions here |
| U | DataKeeper | DataKeeper.exe | PowerQuest DataKeeper (now owned by Symantec) backup software |
| Y | DataLayer | DataLayer.exe | Part of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Required by the Nokia status/connection monitor (NclTray.exe) |
| Y | DataLayer | DATALA~1.EXE | Part of Nokia PC Suite version 5 - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." Required by the Nokia status/connection monitor (NclTray.exe) |
| ? | DATAMNGR | DATAMN~1.EXE | Toolbar associated with the iMesh and BearShare peer-to-peer (P2P) file-sharing clients |
| ? | DataMngr | DataMngrUI.exe | Toolbar associated with the iMesh and BearShare peer-to-peer (P2P) file-sharing clients |
| X | DataProtect | DataProtect.exe | DataProtect rogue security software - not recommended, removal instructions here |
| N | DataViz Inc Messenger | DvzIncMsgr.exe | Installed with DataViz Documents to Go - which "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts" |
| N | DataViz Messenger | DvzMsgr.exe | Installed with DataViz Documents to Go - which "allows you to use your Word, Excel and PowerPoint files on your handheld anywhere, anytime. In addition, it now synchronizes e-mail with attachments, PDF files, pictures and Excel-like charts" |
| X | Datcheck | datcheck.exe | Added by the KEYPANIC TROJAN! |
| X | Date Manager | datemanager.exe | Date Manager - calender program. Spyware/adware based provided by The Gator Corporation. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| ? | Datechecker | N/A | Could be related to this? |
| X | DateMakerIntl | DateMakerIntl.exe | Premium rate adult content dialler |
| X | DateMngr | DATEMNGR.EXE | Added by the SPYBOT-BR BACKDOOR! |
| X | DAupdate | DAupdate.exe | NavEnhance adware |
| ? | DAW9532.exe | DAW9532.EXE | Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required? |
| U | DayToday | DAYTODAY.EXE | DayToday from RoboMagic Software Corp. Displays the date on the taskbar |
| U | DAZEL Delivery Agent | DcDaemon.exe | Control and send documents, etc, to any destination. The Dazel Corporation has now been taken over by HP |
| X | dbar_starter | starter.exe | Deskbar adware - adds a search bar to your Windows taskbar which performs searches on www.w-w-w-dot-com.com |
| X | DbgHlp32 | DbgHlp32.exe | Added by the WINKO.AO WORM! |
| U | DBISQL9 | dbisqlg.exe | Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies |
| N | dbserv | dbserv.exe | Database Server for Norton Ghost on Win2k Pro. Ghost works fine when it is disabled |
| X | dc | dc.exe | Added by the COIDUNG-A WORM! |
| X | dc2k5 | SVIQ.EXE | Added by the COIDUNG-A WORM! |
| U | DC300 Monitor | cmonitor.exe | Monitor for a Acer DC300 digital camera |
| X | DC6 | dc6_startupmon.exe | Part of the WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions here |
| X | DC6_Check | uwasdc.exe | Part of the WinAntiSpyware 2006 and WinAntiSpyware 2007 rogue spyware removers - not recommended |
| X | DC6_check | dc6_startupmon.exe | Part of the WinAntiVirus Pro 2006 rogue security software - not recommended, removal instructions here |
| X | dc6_check | dcmon.exe | SystemDoctor rogue security software - not recommended, removal instructions here |
| X | DC6cw | DC6cw.exe | Part of the DriveCleaner rogue security software - not recommended, removal instructions here |
| X | dcc | dcc_.exe | Added by the AGENT-GBJ TROJAN! |
| X | DCE Manager | dcemgr.exe | Added by the TUMAG TROJAN! |
| U | DCfssvc | dcfssvc.exe | Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example |
| U | dcfssve | dcfssvc.exe | Associated with digital cameras and can cause problems which disappear if disabled. If this program is unchecked in startup, your camera will not cause your computer to open a pop-up window when you connect it. Leave enabled if you can't load pictures from your camera/dock - Kodak's dock is an example |
| X | DCOM Server | [path to trojan] | Added by the AGENT-CCQ BACKDOOR! |
| X | Dcom System Patch | Microsoft.exe | Added by the RANDEX.MS WORM! |
| Y | DCPstrApp | SecurityDeviceInfoSetRegistryString.exe | Part of the Dell ControlPoint Security Manager - which "provides access to your security, user identification, fingerprint readers, and smartcard security technology". Dell ControlPoint is "designed to simplify and unify the execution of what should be simple system functions" and "integrates best-of-breed software and utility solutions into one helpful solution" |
| X | dcsm | dcsm.exe | Part of the PrivacyProtector and DriveCleaner rogue security tools |
| N | DDCActiveMenu | DDCActiveMenu.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | DDCM | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| N | DDCMan | DDCMan.exe | Digital Distribution Channel - formally part of the WildTangent on-line games delivery service. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case |
| X | ddeproc | ddeproc.exe | Webcelerator from eAcceleration speeds your Web browsing by both remembering where you have been and anticipating where you will go. Only needed if you find it improves web browsing. Now no longer available and supported and when available was classed as spyware - see here |
| U | ddhelper | W815DM.EXE | Enuff Parental Control Software by Akrontech |
| X | DDialler | DDialler.exe | Adult content dialler |
| X | ddivmwa | [random filename] | Added by a variant of the SLAPER TROJAN! |
| U | DDLAgent | DDLAgent.exe | Loads DVD Device Lock - which "can be used to restrict read or write access to removable media devices such as CD, DVD, floppy, flash and USB drives. You can also restrict access to partitions of hard disk drives". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UI |
| ? | DDmService | DDmService.exe | Part of the Web Player which is included with the DivX Plus video software package from DivX, LLC. The exact purpose of this entry and whether it's needed is unknown at present but it appears to be associated with clearing the cache - see here |
| U | ddoctorv2 | sprtcmd.exe /P ddoctorv2 | Comcast Desktop Doctor (provided by SupportSoft, Inc) is a free self-help tool for Comcast broadband users. Identifies and automatically fixes typical problems that may occur with your high-speed internet service |
| X | ddqdsxnfqs | DQDDSS.EXE | Added by the SDBOT.AEL WORM! |
| X | DDriver | windrv.exe | Added by the DELF.WG TROJAN! |
| X | DDriver | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies |
| ? | DDT | N/A | ?? |
| U | DDWMon | ddwmon.exe | Direct Disc Writer Event Monitor from TOSHIBA |
| X | de32gen | de32gen.exe | Added by a variant of the CRYPTER.C TROJAN! |
| N | DeadAIM | rundll32.exe DeadAIM.ocm, ExportedCheckODLs | DeadAIM - feature enhancing product for AOL's Instant Messenger program |
| X | DeadKitty | DeadKitty.exe | Added by the DEADCAT-A WORM! |
| X | DealHelperBrwsr | dhbrwsr.exe | DealHelper adware |
| X | DealHelperDown | download.exe | DealHelper adware |
| X | DealHelperUpdate | DHUpdt.exe | DealHelper adware |
| X | Death.exe | Death.exe | Added by the DELF-ERW TROJAN! |
| U | DeathAdder | razerhid.exe | Razer DeathAdder gaming mouse driver - required if you use the additional features and programmed keys/macros |
| X | Debug | DebugW32.exe | Added by the GUBED TROJAN! |
| X | Debug | SMSS.exe | DreamAd adware. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Debugger | dbg32.exe | Added by the MYTOB-FW WORM! |
| X | Debugger | explorer32dbg.exe | Added by the CWS-M TROJAN! |
| X | Debugger | iexplore_dbg.exe | Added by the CWS-M TROJAN! |
| X | debugger | help.pif | Added by the DELF-DRA WORM! |
| X | DebugMonitor | debugmonitor.exe | Added by the MYDOOM.BG WORM! |
| U | DeeEnEs | DeeEnEs.exe | DeeEnEs - automatically updates a dynamic IP address when it changes |
| X | deejay | forboo.exe | Added by the FORBOT-AY WORM! |
| X | Deewoo | ncntnkwd.exe | ZenoSearch adware variant |
| X | Default | explore.vbs | Added by the ALLEM WORM! |
| X | Default | mtask.vbe | Added by the ALLEM WORM! |
| X | default | shell32.exe | Added by the BINGHE TROJAN! |
| X | Default | _default.pif | Added by the RUBBLE-C WORM! |
| U | default | mskbw.exe | PC Surveillance PRO surveillance software. Uninstall this software unless you put it there yourself |
| X | Default | lsassM.exe | Added by the RBOT-UW WORM! |
| X | default | kernel.exe | Added by the SALUNI TROJAN! |
| U | Default Manager | DefMgr.exe | Part of MSN Toolbar from version 4.* onwards (renamed "Bing Bar" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing |
| X | Default System Research | vhchost.exe | Added by the TARNO.I TROJAN! |
| X | Default web browser | iexpIore.exe | Added by the OBLIVION.B TROJAN! Note - do not confuse "iexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a capital "i" in place of lower case "L" |
| X | Default_Page_URL | http://find.naupoint.com | Naupoint browser hijacker |
| X | Default_Search_URL | http://find.naupoint.com | Naupoint browser hijacker |
| X | DefaultConfiguration | defaultconfh.exe | Added by the AGOBOT-JC WORM! |
| X | DefendAPc | DefendAPc.exe | DefendAPc rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | defender | [spyware filename] | DollarRevenue spyware. The file is located in %Root% (i.e. C:\ D:\, etc) |
| X | defender | [path to trojan] | Added by the VB-BAQ TROJAN! |
| X | DefensaAntiMalware | pgs.exe | DefensaAntiMalware, Spanish rogue security software - not recommended. A member of the AVSystemCare family |
| X | Defense Center | defcnt.exe | Defense Center rogue security software - not recommended, removal instructions here |