| Status | Autorun name | Command | Description |
| X | ExpertAntivirus | ExpertAntivirus.exe | ExpertAntivirus rogue security software - not recommended, removal instructions here |
| X | EXPL0RE.EXE | EXPL0RE.EXE | Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit "0" instead of the uppercase letter "o" |
| X | Expl0rer soft | expl0rer.pif | Added by the RBOT-AQR WORM! |
| X | expler | Updadv.exe | Added by the QQPASS-N TROJAN! |
| X | Explkw | expup.exe | Keywords hijacker |
| X | explord.exe | explord.exe | Added by the DLOADR-AYW TROJAN! |
| X | explore | explore.exe | Added by any number of VIRUSES, WORMS or TROJANS! |
| X | Explore | Explorer.exe | Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | Explore | explore.exe | Adult content dialler |
| X | Explore | PLORE.EXE | Added by the FORBOT-P WORM! |
| X | explore manager | explore.exe | Added by the DONBOMB.A TROJAN! |
| X | explore.exe | Explore.exe | Added by the GRAYBIRD.G TROJAN! |
| X | exploreff.exe | exploreff.exe | Added by the FINFANSE TROJAN! |
| X | explorep.exe | explorep.exe | Added by the LINEAG-I TROJAN! |
| U | explorer | explorer.exe | Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL |
| X | explorer | wscript.exe [filename] | Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted |
| X | Explorer | shellexpl.exe | Added by the SHELDOR TROJAN! |
| X | explorer | expl32.exe | Added by the RATSOU TROJAN! |
| X | Explorer | [path to worm] | Added by the AUTEX WORM! |
| X | Explorer | shellexp.exe | Added by the AGENT-ZY TROJAN! |
| X | EXPLORER | EXPL0RER.EXE | Added by the BEASTDO-Y TROJAN! Note the "0" in the filename rather than upper case "o" |
| X | EXPLORER | sys.exe | Added by the SILLYFDC-A TROJAN! |
| X | Explorer | config_.com | Added by the FLOPPY-D WORM! |
| X | Explorer | drv.exe | Added by the SMALL-FD TROJAN! |
| X | explorer | [path to trojan] | Added by the AGENT-EU TROJAN! |
| X | explorer | explorer.exe | Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service |
| X | EXPLORER | EXPLORER.exe | Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt |
| X | explorer | explorer.exe | Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config |
| X | explorer | Yinstall.exe | PurityScan/Clickspring adware |
| X | Explorer | Windows Explorer.exe | Added by the SILLYFDC-I WORM! |
| X | Explorer | explorar.vbs | Added by the DESKTO-A WORM! |
| X | Explorer | TXP1atform.exe | Added by the FUJACKS.CA VIRUS! |
| X | explorer | system.exe | Added by the AGENT-FI TROJAN! |
| X | Explorer | msrstart.exe | Added by the SOPICLICK TROJAN! |
| X | explorer | main.vbe | Added by the SHUSH-A WORM! |
| X | Explorer | hxpf.exe | Added by the DELF-DMZ TROJAN! |
| X | explorer | bootcfgx.exe | Added by the BANBRA.GQU TROJAN! The file is typically located in %UserProfile%\InstallShield Installation Information\{A5BA14E0-7384-5991B8648CBE70A4} |
| X | explorer | explorer.exe | Added by the AUTORUN-RE WORM! Note - the legitimate Windows Explorer (explorer.exe) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %Windir%\Backup |
| X | explorer | wuauclt.exe | Added by the RISPIF.A WORM! Note - this is not the legitimate wuauclt.exe process, which should not appear in Msconfig/Startup! |
| X | Explorer 2238 | [path to trojan] | Added by the AGENT-CPI TROJAN! |
| X | Explorer Loader | explr32.exe | Added by the AGOBOT.N WORM! |
| X | Explorer Loader | explorerl.exe | Added by the SDBOT-ADI WORM! |
| X | Explorer lptt01 | explorer.exe | RapidBlaster variant (in a "explorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually! |
| X | EXPLORER MICROSOFT SYSTEM | explore.exe | Added by a variant of the RBOT WORM! |
| X | Explorer ml097e | explorer.exe | RapidBlaster variant (in a "explorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it. Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually! |
| X | Explorer soft | explorer.pif | Added by the RBOT-APK WORM! |
| X | Explorer soft | explorer.com | Added by the RBOT-ARM WORM! |
| X | Explorer Updater | IEXPLORE.exe | Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | explorer.exe | explorer.exe | Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | explorer.exe | explorer.exe | Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles% |
| X | Explorer.exe | csrss.exe | Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft |
| X | Explorer32 | explorer6s4.exe | Added by the Downloader.Win32.Small.biq TROJAN! |
| X | Explorer32 | efsdfgxg.exe | Added by the CLICKER-Y TROJAN! |
| X | Explorer32 | Expl32.exe | Added by the HACKTACK.B BACKDOOR! |
| X | Explorer5 | config_.com | Added by the VB.CBG WORM! |
| X | Explorer6.1.EXE | Explorer.exe | Added by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| X | explorerf.exe | explorerf.exe | Added by the AGENT-GDZ TROJAN! |
| X | ExplorerRun | conime.exe | Added by the PROXY.ABL TROJAN! Note - this is not the legitimate Microsoft Console IME process of the same filename which is located in %System% and is used when a Asian language is used in Windows. This one is located in %Temp% |
| X | ExplorerRun | avp.exe | Added by the PINCAV.CQU TROJAN! Not to be confused with Kaspersky internet security products, AOL's Active Virus Shield and Steganos AntiVirus 2007 (both by Kaspersky) - which are found in either a Kaspersky, AOL or Steganos sub-directory. This one is located in %Temp% |
| X | ExplorerTask | explorer.exe | Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the "Fonts" sub-folder |
| X | ExploreUpdSched | [random filename] | Zeno Think-Adz adware |
| X | exporet | winset.exe | Added by the QQPASS-I TROJAN! |
| U | Express ClickYes | ClickYes.exe | "Express ClickYes is a handy tool that runs in the system tray automatically clicks the Yes button for the Outlook Security security prompt, that asks you to confirm mail sending from third party applications" |
| U | Exshow95 | EXSHOW95.exe | Support software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices |
| N | Extender Resource Monitor | RMSysTry.exe | Related to Windows Media Center from Microsoft |
| X | External Dependencies | External.exe | Added by the MYTOB.EC WORM! |
| X | Extra Antivirus | ExtraAV.exe | Extra Antivirus rogue security software - not recommended, removal instructions here |
| U | ExtraDNS | ExtraDNS.exe | ExtraDNS - DNS configuration tool |
| N | ExtraFilmHemmaAgent | Agent.exe | ExtraFilm Photo Assistant |
| ? | Extranet AutoDial | AutoExt.exe | Nortel Networks Contivity Extranet Switching Software |
| ? | ExxtremeHelperDemon | exxdemon.exe | Creative Exxtreme graphics card related? |
| N | Eye Tide Launcher | oneeyetideone.exe | Nascar wallpaper |
| N | Eyeball Chat | EyeballChat.exe | Eyeball Chat free video instant messenger from Eyeball Networks Inc |
| U | Eyes Relax | EyesRelax.exe | Eyes Relax from The Mech - a freeware utility that reminds you about taking breaks from staring at a computer to avoid eye strain |
| X | EYORE | Notepad.scr | Added by the GIMLET-A WORM! |
| Y | EZ Firewall | ca.exe | EZ Firewall - part of the eTrust range of security products formerly available from CA but now discontinued. Available as a stand-alone product or as part of the EZ Armor suite |
| U | EZ-DUB Finder | EZ-DUB.exe | Support software for the Lite-On EZ-DUB external DVD writer from Lite-On IT Corporation |
| N | ezagent | ezagent.exe | EzVCR recording software for the ASUS TV FM card. Available via Start -> Programs |
| N | EzButton | EzButton.EXE | EZbutton is a quick launcher for the Media player app that comes with certain laptops |
| N | EZDesk | EZDESK.EXE | Utility that remembers icon locations for each user and resolution. Available here |
| U | EZEJMNAP | EzEjMnAp.Exe | EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually." Configuration and performing of EasyEject actions is available via Fn+F9 key combination on some models |
| N | EZEJTRAY | EZEJTRAY.EXE | System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually." Configuration and performing of EasyEject actions is available via Fn+F9 key combination on some models |
| N | ezHelper | ezHelper.exe | Part of the ezPeer+ ezHelper music sharing program. |
| X | ezLife | [random name].dll | EZLife adware |
| X | eZmmod | mmod.exe | eZula adware |
| ? | EZNORUN | EZNORUN.EXE | Easy Internet related? |
| N | EzPrint | ezprint.exe | EzPrint - helps users of Lexmark, Dell and LG (and possibly other) printers to enhance, print and manage their photos quickly and easily |
| Y | ezPS_Px | ezSP_Px.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
| Y | ezShieldProtector for Px | ezSP_Px.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
| Y | ezShieldProtector for Px | ezSP_PxEngine.exe | Engine that allows PrimoDVD from Veritas (was Prassi) and Drag'n Drop CD from Easy Systems (and maybe others) to record and protects against other software overwriting the settings |
| U | EZSMART App | ezsmart.exe | EZ-S.M.A.R.T. hard drive monitoring software from StorageSoft - appears to be no longer supported |
| U | EzTune | dthtml.exe | EzTune from Gateway. Rebranded version of Display Tune from Portrait Displays, Inc. - which "is the perfect software utility to initially set-up and adjust your display to achieve its optimum performance. All adjustments are made through a simple graphical user interface" |
| X | ezula | eZmmod.exe | eZula adware |
| X | eZulaMain | eZulaMain.exe | eZula adware |
| X | eZuluMain | eZuluMain.exe | Comes with "KaZaA" installation. Advertising Spyware. Not required but KaZaA won't work |
| X | ezurl | easyurl.exe | Ezurl spyware |
| X | eZWO | wo.exe | eZula adware |
| X | f | ftkclean.exe | FlashEnhancer adware |
| U | F-PROT Antivirus Tray application | FProtTray.exe | System Tray access to F-PROT Antivirus |
| X | F-Secure 2005 | svchost.exe | Added by the BIFROSE-CH TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |