Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 31st May, 2013
32700 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

521 results found for G

Startup Item or Name Status Command or Data Description Tested
VGAUtilUG-VGA.exeGigabyte VGA Utility - access card options (application needs to be run at startup, but is not system critical)No
g.exeXg.exeAdded by the GRAYBIRD.Q TROJAN!No
Gadu-GaduXg.g.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.GG. Note - do not confuse with the legitimate Polish language Instant Messaging client who's filename is "gg.exe" and the file is located in %Temp%No
G0mezXG0mez.vbsAdded by the GORMLEZ-A WORM!No
GoToAssist Express CustomerUg2ax_service.exeCitrix GotoAssist Express - "provides you with live-support capability. Easily view and control your customers' computers online to quickly resolve their technical issues." End customer's versionNo
GoToAssist Express ExpertUg2ax_start.exeCitrix GotoAssist Express - "provides you with live-support capability. Easily view and control your customers' computers online to quickly resolve their technical issues." Support expert's versionNo
GoToMeetingUg2mstart.exeCitrix GotoMeeting - web conferencing and online meeting tool which "allows you to host an online meeting with up to 15 people - so you can do more and travel less"No
GoToMyPCUg2svc.exeCitrix GoToMyPc - web-based remote-access solution that allows individuals and companies to register their computers online and then securely access those computers from any web browserNo
g3dctl?g3dctl.exe??No
aetgrshjtyjdXg58het6h.exeDetected by McAfee as RDN/Spybot.bfr!a and by Malwarebytes Anti-Malware as Backdoor.AgentNo
BPServerNG6FTPSrv.exeBulletProof FTP ServerNo
G6FTP Server Tray MonitorUG6FTPTray.exeSystem Tray monitoring tool for Gene6 FTP Server - "an advanced FTP server software for Windows developed specifically for security and high performance requirements"No
WindowsXG9DjT9Dj.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserTemp%No
d5jxXg9wsxg.exeAdded by the AGENT-REO TROJAN!No
ga6pcwXga6pcw.exePart of the AVSystemCare rogue security software and other members of this family. See here for more examplesNo
[various names]Xgabber.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
gacXgac.exePart of VirusVakt, Swedish rogue security software - not recommended. A member of the AVSystemCare familyNo
GACService?GACService.exeRelated to a Gemplus product. What does it do and is it required?No
gadcomXgadcom.exeDetected by Sophos as Troj/Agent-HICNo
hpSdwxmarkXGaddw.exeAdded by the SDBOT-RB WORM!No
System32RootXGadu-Gadu.exeAdded by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-GaduNo
Wins Loader5XGadu-Gadu.exeAdded by a variant of the IRCBOT TROJAN! Note - doe not confuse with the Polish language Instant Messaging client also called Gadu-GaduNo
GAELICUM.EXEXGAELICUM.EXEAdded by the PENTA-A TROJAN!No
gah95on6Xgah95on6.exeShopAtHome/SAHagent adwareNo
gaimUgaim.exeGaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networksNo
GalleryPlayerCM?GalleryPlayerCM.exeRelated to GalleryPlayer by RGB Labs - "Discover the easiest way to acquire, organize and display the world's finest art and photography: with GalleryPlayer you can own high definition art and photography from the world's finest museums and galleries." No longer available - is it required?No
GalleryPlayerDM?GalleryPlayerDM.exeRelated to GalleryPlayer by RGB Labs - "Discover the easiest way to acquire, organize and display the world's finest art and photography: with GalleryPlayer you can own high definition art and photography from the world's finest museums and galleries." No longer available - is it required?No
adobeXgam.exeAdded by an unidentified WORM or TROJAN!No
USBHWDRVXgam.exeAdded by a variant of the LOWZONE-I TROJAN!No
MicrosoftXGame.exeDetected by Dr.Web as Trojan.DownLoader7.11541 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
MS-ConnectXgame.exeMS-Connect - Switch dialer and hijacker variant, see here. Also detected as the DIALER.DD TROJAN!No
Win32XGame.exe.vbsAdded by the SCAFENE WORM!No
GameChannelNGameChannel.exeWildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
WT GameChannelNGameChannel.exeWildTangent GameChannel - notification of new games, quick access to games and fast and easy game downloads. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the caseNo
gameflakeSAXgameflakeSA.exeDetected by Malwarebytes Anti-Malware as Adware.HotBar.CP. The file is located in %AppData%\gameflakeSA\bin\[version]No
Game HouseXGameHouse.exeAdded by the DELF-DRA WORM!No
MaplomUGameJackal.exeOlder version of Game Jackal Pro from SlySoft, Inc - the latest version runs the Game Jackal Server (GJService) service instead. Game Jackal Pro allows users to play PC games without the need for the original media inserted into the optical drive. It works in a similar way to other utilities which use virtual drives and need large disc images - but it uses a proprietary format which takes up considerable less spaceNo
Microsoft GamesXgamemanager.exeAdded by the SPYBOT.AHQ WORM!No
FakeUpXgamer.exeDetected by Dr.Web as Trojan.KillProc.22445 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Gamer @mail.ruXgamer.exeDetected by Dr.Web as Trojan.KillProc.22445 and by Malwarebytes Anti-Malware as Trojan.AgentNo
ASUSGamerOSDNGamerOSD.exeGamerOSD by ASUS - for "real-time overclocking, benchmarking and video capturing in any PC game". Free for ASUS graphics cards, 30-day trial for non-ASUS graphics cardsNo
GameShadowNGameShadow.exeGameShadow is "an advertising-supported software utility that keeps PC gamers up-to-date with patches, game demos, trailers, mods and other content"No
gamesleapSAXgamesleapSA.exeDetected by Malwarebytes Anti-Malware as Adware.HotBar.CP. The file is located in %LocalAppData%\gamesleapSA\bin\[version]No
gameutil.exeUgameutil.exePart of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-bootNo
GamevanceXgamevance32.exeGameVance adware - online gaming software that collects anonymous usage information and displays adsNo
GameXLUgamexl.exeGame Accelerator by DefendGate Inc - "is a highly-developed, intelligent program that will assess your PC's hardware and operating environment and optimize it to provide a faster, more stable gaming experience"No
GameXNNGameXNGO.exe"GameXN is dedicated to providing a world class Game channel to the expanding global Skype community"No
GameXN (news)NGameXNGO.exe"GameXN is dedicated to providing a world class Game channel to the expanding global Skype community"No
GameXN (update)NGameXNGO.exe"GameXN is dedicated to providing a world class Game channel to the expanding global Skype community"No
GameXN GONGameXNGO.exeGameXN GO from GameXN AS - is a "FREE app for Windows that allows you to play with Skype friends, play GO games when you don't have an Internet connection, and much more"No
Windows ASN4 ServicesXgamo.exeAdded by the RBOT-EHK WORM!No
gamuxinpuwuxXgamuxinpuwux.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
gangstaXgangsta.exeAdded by the RIMA.A BACKDOOR!No
GartedXGarted.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\GartedNo
gaSrvXgaSrv.exeAdware downloader. Detected by Panda as Downloader.ALQNo
gaSrveXgaSrve.exeAdware downloader. Detected by Panda as Downloader.ALQNo
HKCUXGating.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
HKLMXGating.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Windir%\InstallDirNo
GatorXgator.exeGator eWallet password utility. Contains GAIN adware by Claria CorporationNo
Gator eWalletXgator.exeGator eWallet password utility. Contains GAIN adware by Claria CorporationNo
GStartupXGatorRes.dllPart of Gator adware - see here for removal instructions. Gator Corporation later became Claria Corporation, who distributed GAIN adwareNo
pvieverXGay-Lesbian-Photo.exeAdded by the DELF-EYL TROJAN!No
COM ServiceXgayZZ.exeDetected by Total Defense as Win32.Lioten.FA and by Malwarebytes Anti-Malware as Backdoor.BeastDoorNo
Gay_Sexy_**XGay_Sexy_**.exePremium rate adult content dialler (where * is a random char)No
Microsoft Update MachineXgbhglj.exeAdded by the IRCBOT-ZJ TROJAN!No
GBMHome7AgentYGBMAgent.exeGenie Backup Manager Home 7 - backup softwareNo
GBMLite7AgentYGBMAgent.exeGenie Backup Manager Lite 7 - backup softwareNo
GBMPro7AgentYGBMAgent.exeGenie Backup Manager Pro 7 - backup softwareNo
Windows DefenderXGBMCZQPGTT.exeDetected by McAfee as Generic.dx!bgcv and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
GoBackUGBMenu.exeSystem Tray access to Roxio's GoBack system restoration software (before it became Norton GoBack) - which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty, performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag and not required for WinMe/XP users - but recommended for Win9x/NT/2K users. Previously released by Adaptec and Wild FileNo
DriverXgbot.exeAdded by the JUNTADOR.K TROJAN!No
GbpluginXGbplugin.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile%\DesktopNo
(Default)Xgbpm.exeAdded by the DLOADR.ZZD WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
GoBack Polling ServiceYGBPoll.exePart of Symantec's Norton GoBack system restoration software - which allows you to revert back to a previously working state on your hard drive if you install a new program and your system goes faulty, performing the same functions with extra features as System Restore on XP/Me systems. Provides essential background support services for GoBack. Disable before running Scandisk or Defrag and not required for XP/Me users - but recommended for 2K/NT/9x users. Previously released by Roxio, Adaptec and Wild File. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
(Default)XGbpSv.exeDetected by Dr.Web as Trojan.KillProc.22757 and by Malwarebytes Anti-Malware as Trojan.Banker.Gen. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %ProgramFiles%No
Gbpsv_WinBXGbpsv_WinB.exeDetected by Dr.Web as Trojan.DownLoader7.28867 and by Malwarebytes Anti-Malware as Trojan.Banker.GenNo
Gbps_dmXGbps_dm.exeDetected by Dr.Web as Trojan.DownLoader7.25733 and by Malwarebytes Anti-Malware as Trojan.Banker.GenNo
Gbps_dmrXGbps_dmr.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %Root%No
Gbps_prmXGbps_prm.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %Root%No
Gbps_rgXGbps_rg.exeDetected by Sophos as Troj/Banker-FSV and by Malwarebytes Anti-Malware as Trojan.Banker.GenNo
Gbps_st2XGbps_st2.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %Root%No
Gbps_stvXGbps_stv.exeDetected by McAfee as BackDoor-DOQ.gen.w and by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %Root%No
Gbps_swXGbps_sw.exeDetected by Dr.Web as Trojan.DownLoader7.15273 and by Malwarebytes Anti-Malware as Trojan.Banker.GenNo
Gbps_win_bXGbps_win_b.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker.Gen. The file is located in %Root% - see hereNo
Gbs_gerXGbs_ger.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%No
Gbs_Win08XGbs_Win08.exeDetected by Dr.Web as Trojan.PWS.Banker1.4864 and by Malwarebytes Anti-Malware as Trojan.BankerNo
Gbs_WisXGbs_Wis.exeDetected by Dr.Web as Trojan.DownLoader6.12766 and by Malwarebytes Anti-Malware as Trojan.BankerNo
GoBackUGBTray.exeSystem Tray access to Roxio's GoBack system restoration software (before it became Norton GoBack) - which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty, performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag and not required for WinMe/XP users - but recommended for Win9x/NT/2K users. Previously released by Adaptec and Wild FileNo
Norton GoBackUGBTray.exeSystem Tray access to Symantec's Norton GoBack system restoration software - which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty, performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag and not required for WinMe/XP users - but recommended for Win9x/NT/2K users. Previously released by Roxio, Adaptec and Wild FileYes
GB_Net_ProtectXGB_Net_Protect.exeAdded by the BANKER-FBZ TROJAN!No
GB_SOURCEXGB_SOURCE.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%No
gCacXgcac.exeAdded by the TACTSLAY.U TROJAN!No
Windows Console MonitorXgcasAV32.exeAdded by the KEDEBE-A WORM!No
MicrosoftAntiSpywareCleanerYgcASCleaner.exeMicrosoft Antipsyware - now superseded by Windows DefenderNo
gcasDtServXgcasDtServ.exeAdded by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startupNo
ccAppXgcasServ.exeAdded by a variant of Win32/Rbot. Note - do not confuse with the legitimate Giant Antipsyware (gcasServ.exe) which has now been superseded by Microsoft's Windows DefenderNo
gcasServYgcasServ.exeGiant Antipsyware - now superseded by Microsoft's Windows DefenderNo
WeatherBlink Browser Plugin LoaderUgcbrmon.exeWeatherBlink toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use itNo
Wireless-G Notebook AdapterYGcc.exeDriver for the Cisco Linksys Wireless-G Notebook AdapterNo
GCC Reminder?gccrem.exeAssociated with AcraMax Greeting Card Creator. Is it a registration reminder?No
buohxqtfswbXgcjydr.exeAdded by the AGENT-NRC TROJAN!No
vmtunerXgclib.exeHijacker - detected by Kaspersky as the SMALL.FH TROJAN!No
Microsoft Update MachineXgcm.exeDetected by Trend Micro as WORM_SPYBOT.ABONo
gcodec_update.exeXgcodec_update.exeDetected by Emsisoft as AdWare.Kraddare!IK. The file is located in %ProgramFiles%\gCodecNo
gcsligxhtqglpbpbpwbXgcsligxhtqglpbpbpwb.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %AppData%No
WeatherBlink Search Scope MonitorUgcsrchmn.exeWeatherBlink toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use itNo
gcwXgcw.exePart of BestsellerAntivirus, PCSecureSystem and other members of the AVSystemCare family of rogue security software suites. See here for more examplesNo
sws.exeXgd-dial.exeGlobaldialer adult content premium rate dialerNo
ConducteurPriveXGDC.exeConducteurPrive rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
ConfidentSurfXGDC.exeConfidentSurf rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
ContentEraserXGDC.exeContentEraser rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
DefenseNetSurfageXGDC.exeDefenseNetSurfage rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
Dist-FBGeneveXGDC.exeNettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
DriveDefenderXGDC.exeDriveDefender rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
FestplattenReinigerXGDC.exeFestplattenReiniger, German rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
FilterProgramXGDC.exeFilterProgram rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
HistoriaLout.XGDC.exeHistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
MenaceFighterXGDC.exeMenaceFighter rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
MistikotitaTuIpologistiXGDC.exeMistikotitaTuIpologisti Greek rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
MonContenuassistantXGDC.exeMonContenuassistant French rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
MyContentAssistantXGDC.exeMyContentAssistant rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
NetSurfageAssureXGDC.exeNetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
NettordinateurXGDC.exeNettordinateur rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
NettoyeurDePCXGDC.exeNettoyeurDePC French rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
NoCompromaatXGDC.exeNoCompromaat Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
OczyszczaczKomputerzaXGDC.exeOczyszczaczKomputerza Polish rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
OnlineHelpmateXGDC.exeOnlineHelpmate rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
PC Drive ToolXGDC.exePC Drive Tool rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
PCPrivacyToolXGDC.exePCPrivacyTool rogue privacy tool - not recommended. There are number of variants in this family sharing the same filename and user interface - see hereNo
PrivacyConductorXGDC.exePrivacyConductor rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
PrivacyWarriorXGDC.exePrivacyWarrior rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
ProtectionDeDriverXGDC.exeProtectionDeDriver rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
SanitarDiskaXGDC.exeSanitarDiska Romanian rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
SchijfControleurXGDC.exeSchijfControleur Dutch rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
SecurePCCleanerXGDC.exeSecurePCCleaner rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
SuspenzorPCXGDC.exeSuspenzorPC Czech rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
TemizSurucuXGDC.exeTemizSurucu Turkish rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
TurvaPCXGDC.exeTurvaPC Finnish rogue privacy tool - not recommended. A member of the PCPrivacyTool familyNo
WinAnonymousXGDC.exeWinAnonymous rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
YourPrivacyGuardXGDC.exeYourPrivacyGuard rogue privacy tool - not recommended, removal instructions here. A member of the PCPrivacyTool familyNo
gdcwXGDCW.exePart of ContentEraser, WinAnonymous and other members of the PCPrivacyTool rogue privacy tool and other members of this family. See here for more examplesNo
Ad-Aware Personal FirewallYGDFirewallTray.exePart of the firewall included with Lavasoft's Ad-Aware Total Security internet security product (which is based upon TotalSecurity from G Data Software AG). Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it runningYes
G Data Personal FirewallYGDFirewallTray.exePart of the firewall included with the NotebookSecurity, TotalSecurity and InternetSecurity internet security products from G Data Software AG. Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it running. Also used by versions of Lavasoft's Ad-Aware Total SecurityYes
GDFirewallTrayYGDFirewallTray.exePart of the firewall included with the NotebookSecurity, TotalSecurity and InternetSecurity internet security products from G Data Software AG. Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it running. Also used by versions of Lavasoft's Ad-Aware Total SecurityYes
LocinxXgdicli.exeAdded by the AGENT-PAW TROJAN!No
gdien32Xgdien32.exeDetected by Sophos as Troj/Singu-P and by Malwarebytes Anti-Malware as Backdoor.AgentNo
gdimxXgdimx.exeMPB-D dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx"No
GDMgr.exeUgdmgr.exeGuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computerNo
GDR driverXgdrhost.exeAdded by the RBOT.YIZ BACKDOOR!No
GDriveNGDriver.exeFound on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start → Settings → Control Panel → System → Device ManagerNo
GameDriveNGDTask.exeGameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc, now superseded by VirtualDrive. Available via Start → ProgramsNo
ASDPLUGINXgeaccess.exeAsdPlug premium rate adult content dialerNo
geafajysezazXgeafajysezaz.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see hereNo
AS00_Gear311TUGear311T.exeNetgear WG311T/WG311TSU 108 Mbps Wireless PCI Adapter configuration utilityNo
AS00 Gear511?Gear511.exeSoftware for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required?No
Ai Gear HelpUGearHelp.exeIncluded with some ASUS motherboards (such as the Maximus Extreme & Striker II Extreme), AI Gear "is a utility designed to configure and support all ASUS EPU (Energy Processing Unit) features." Provides system performance profiles to adjust CPU frequency and voltage for different computing needs. Part of AI SuiteNo
GEARsecNgearsec.exeInstalled by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime playerNo
WindowsXgearsec.exeAdded by the STUBBOT-B WORM!No
Windows Sound ManagerXgearsec.exeAdded by the PUSHBOT.DF WORM!No
systemrXgedit.exeAdded by the ADCLICK-AQ TROJAN!No
GEDZACXGEDZAC.exeAdded by the GEMEL WORM!No
AMD PowerNow!UGemBack.exeAMD PowerNow! - "an innovative solution available on all AMD mobile processor-based notebooks that can effectively increase notebook battery life, while delivering performance on demand"No
GemStRmWNGemStRmW.exeFor a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manuallyNo
General AntivirusXGenAvir.exeGeneral Antivirus rogue security software - not recommended, removal instructions hereNo
gencrootXgencroot.exeAdded by the SDBOT-AED WORM!No
Tweak SystemXGenderowo.exeAdded by the SILLYFDC WORM!No
general lptt01Xgeneral.exeRapidBlaster variant (in a "general" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
general ml097eXgeneral.exeRapidBlaster variant (in a "general" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
genivXgeniv.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
GenProtectXGenProtect.exeDetected by Trend Micro as TROJ_ONLINEG.JZT and by Malwarebytes Anti-Malware as Spyware.OnLineGamesNo
RjlEQTc3N0IxQkM3RUM4QjXGeoCthaw.exeDetected by Dr.Web as Trojan.Siggen.65180 and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %UserProfile%No
WindowssystemrecoveryXGerichtsdokumente.exeDetected by Malwarebytes Anti-Malware as Trojan.VBInject. The file is located in %AppData%No
gescwXgescw.exePart of BeschermingsTool, SysDepannage and other members of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examplesNo
Microsoft NetviewXgesfm32.exeAdded by the RANDEX.C WORM!No
WOOKIT?GestMaj.exe EspaceWanadoo.exeWanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?No
WOOKIT?GestMaj.exe GestionnaireInternet.exeWanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?No
GetBooksXGetBooks.exeDetected by Sophos as Troj/DwnLdr-KIR and by Malwarebytes Anti-Malware as PUP.Adware.DownloaderNo
GetITUGetIT.exe"HP GET-IT (Graduate Entrepreneurship Training through Information Technologies) empowers under- or unemployed young people with business and IT skills - helping them find a job or start their own businesses"No
REMOTE MESSENGERXgetmnnt$.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.RMGen. The file is located in %System%No
GetModule18XGetModule18.exeInternet Speed Monitor adware variant - see example hereNo
GetModule19XGetModule19.exeInternet Speed Monitor J adware - see example hereNo
GetModule20XGetModule20.exeInternet Speed Monitor adware variant - see example hereNo
GetModule21XGetModule21.exeInternet Speed Monitor adware variant - see example hereNo
GetModule23XGetModule23.exeInternet Speed Monitor adware variantNo
GetModule24XGetModule24.exeInternet Speed Monitor adware variant - see example hereNo
GetModule25XGetModule25.exeInternet Speed Monitor adware variant - see example hereNo
GetModule26XGetModule26.exeInternet Speed Monitor adware variant - see example hereNo
GetModule27XGetModule27.exeInternet Speed Monitor adware variant - see example hereNo
GetModule29XGetModule29.exeInternet Speed Monitor adware variant - see example hereNo
GetModule30XGetModule30.exeInternet Speed Monitor adware variant - see example hereNo
GetModule31XGetModule31.exeInternet Speed Monitor adware variantNo
GetModule32XGetModule32.exeInternet Speed Monitor adware variantNo
GetModule33XGetModule33.exeInternet Speed Monitor adware variant - see example hereNo
GetModule34XGetModule34.exeInternet Speed Monitor adware variantNo
GetModule35XGetModule35.exeInternet Speed Monitor adware variant - see example hereNo
GetModule36XGetModule36.exeInternet Speed Monitor adware variantNo
GetModule37XGetModule37.exeInternet Speed Monitor adware variant - see example hereNo
GetModule38XGetModule38.exeInternet Speed Monitor adware variant - see example hereNo
GetPack18XGetPack18.exeInternet Speed Monitor adware variant - see example hereNo
GetPack19XGetPack19.exeInternet Speed Monitor J adware - see example hereNo
GetPack20XGetPack20.exeInternet Speed Monitor adware variant - see example hereNo
GetPack21XGetPack21.exeInternet Speed Monitor adware variant - see example hereNo
GetPack22XGetPack22.exeInternet Speed Monitor adware variant - see example hereNo
GetPack23XGetPack23.exeInternet Speed Monitor adware variant - see example hereNo
GetPack24XGetPack24.exeInternet Speed Monitor adware variant - see example hereNo
GetPack25XGetPack25.exeInternet Speed Monitor adware variantNo
GetPack26XGetPack26.exeInternet Speed Monitor adware variantNo
GetPack27XGetPack27.exeInternet Speed Monitor adware variantNo
GetPack28XGetPack28.exeInternet Speed Monitor adware variantNo
GetPack29XGetPack29.exeInternet Speed Monitor adware variantNo
GetPack30XGetPack30.exeInternet Speed Monitor adware variantNo
GetRightUGetRight.exeGetRight from Headlight Software - shareware download manager for resuming downloads and choosing multiple download locations. The Pro version adds uploading and other features. Earlier 4.x versions included ads, which could be disabled if you chose not to install the Aureate/Radiate software in the registered version - see here. Start it manually unless you want to intercept download links from your browserYes
GetRight - Tray IconUgetright.exeEntry added with older versions of the GetRight download manager from Headlight Software, Inc. Start it manually unless you want to intercept download links from your browserYes
Start GetrightNgetright.exeEntry added with older versions of the GetRight download manager from Headlight Software, Inc. Start it manually unless you want to intercept download links from your browserNo
Get SmileNgetsmile.exePuts smilie faces in your E-mail. Run manually when requiredNo
SymmTimeUGeTTime.exeSymmTime from Symmetricon - freeware utility that "synchronizes your PC clock to Coordinated Universal Time (UTC), the high precision atomic time standard"Yes
SymmTime ApplicationUGeTTime.exeSymmTime from Symmetricon - freeware utility that "synchronizes your PC clock to Coordinated Universal Time (UTC), the high precision atomic time standard"Yes
Critical Error Safe32XGetWaylayer32.exeAdded by a variant of W32/Sdbot.wormNo
ewrgetujXgeurge.exeDetected by Sophos as W32/Autoinf-AKNo
gewavatjimuzXgewavatjimuz.exeDetected by McAfee as Generic Downloader.x and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
wowXgewow.exeAdded by the WOWPWS-KA TROJAN!No
McsoftXgfeqzvq.exeAdded by the SDBOT-NV WORM!No
conimeXgfwz.exeDetected by Malwarebytes Anti-Malware as Backdoor.Small. The file is located in %System%\configNo
3Dfx AccXGFXACC.EXEAdded by the GIBE WORM!No
gg-unitXgg-unit.exeDetected by Malwarebytes Anti-Malware as Trojan.KeyLogger. The file is located in %System%No
Gadu-GaduNgg.exePolish language Instant Messaging clientNo
Gadu-Gadu 10Ngg.exePolish language Instant Messaging clientNo
Nowe Gadu-GaduNgg.exePolish language Instant Messaging clientNo
Microsoft Driver SetupXggdrive32.exeAdded by the AGENT-QGS TROJAN!No
ggePSKfpxtPXggePSKfpxtP.exeAdded by the FAKEAV-DVV TROJAN!No
gf1.0.0.2Xggf.exeDetected by Total Defense as Eddfon A. The file is located in %System%No
StratasXggfig.exeDetected by Trend Micro as WORM_OPANKI.WNo
bdfgerXgggasw.exeAdded by the SDBOT-RT WORM!No
vmtunerXgglib.exeAdded by the QLOWZON-D TROJAN!No
gtydfXggrrgg.exeAdded by the DLOADR-AZK TROJAN!No
google toolbarXggtb32.exeAdded by the AGOBOT-RR WORM!No
gH46Dt3XgH46Dt3.ExeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp%No
Microsoft Driver SetupXghdrive32.exeAdded by the DWNLDR-IXK TROJAN!No
JfwehnrtXghgfjrs.exeAdded by the SDBOT-IJ WORM!No
G_HostXgHost.exeDetected by Sophos as W32/Autoit-BP and by Malwarebytes Anti-Malware as Trojan.FakeFolderNo
Sys_RunXghost.exeAdded by the LINEAGE-N TROJAN!No
Ghost AntivirusXGhostAV.exeGhost Antivirus rogue security software - not recommended, removal instructions hereNo
GhostStartServiceYGhostStartService.exeInstalled with older versions of Symantec's Norton Ghost backup software (either as a standalone product or as part of Norton SystemWorks). This is the background process required for Ghost to work in Windows - when you use the Ghost Explorer (browse/extract files from archives) or start Ghost tasks such as backup and restore. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
GhostStartTrayAppNGhostStartTrayApp.exeSystem Tray access to older versions of Symantec's Norton Ghost backup software (either as a standalone product or as part of Norton SystemWorks)Yes
Norton Ghost 10.0NGhostTray.exeSystem Tray access to version 10.0 of Symantec's Norton Ghost backup software (either as a standalone product or as part of Norton SystemWorks 2006 Premier)No
Norton Ghost 9.0NGhostTray.exeSystem Tray access to version 9.0 of Symantec's Norton Ghost backup software (either as a standalone product or as part of Norton SystemWorks 2005 Premier)No
GhostVaccineXGhostVaccine.exeGhostVaccine rogue security software - not recommended, removal instructions hereNo
gigabit.exeXgigabit.exeAdded by the BEAGLE.U WORM!No
CheatleXGigaByte.exeAdded by the SHODI.B VIRUS!No
Giganews AcceleratorUGiganewsAccelerator.exeGiganews Accelerator from Giganews, Inc. - "a software-based news proxy which will allow you to compress headers and enable 256-bit SSL encryption, regardless of whether or not SSL is supported natively by your news client"No
LG Intelligent UpdateUgiljabistart.exeRelated to LG Electronics system updatesNo
gimmysmileysXgimmysmileys.exeGimmySmileys adwareNo
giqhrhdhldbhyywmetdXgiqhrhdhldbhyywmetd.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
Girder4Ugirder.exeGirder from Promixis - "is the award winning home and industrial automation software that allows users of all skill level to make advanced scripts and macros to automate many functions both on the computer and around the house or office"No
GisdnLog?gisdnlog.exeBT Digital Access USBNo
(Default)XGJHKKT263453.exeDetected by Dr.Web as Trojan.Siggen4.38789 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData%No
gjmtXgjmt.exeAdded by the DELF.DW TROJAN!No
GkwkwqXGkwkwq.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%No
Popup TerminatorUGLADManager.exePopup Terminator - pop-up killerNo
Glass2kUGlass2k.exe"Glass2k is a small little program that allows Win2K/XP users to make any window transparent"No
DesktopX WidgetUGlassy Calculator II.exeGlassy Calculator II widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calculator II.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Glassy Calculator IIUGlassy Calculator II.exeGlassy Calculator II widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calculator II.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUGlassy Calendar.exeGlassy Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Glassy CalendarUGlassy Calendar.exeGlassy Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calendar.exe loads a file called "DXWidget.exe" and exitsYes
DesktopX WidgetUGLASSY~1.EXEGlassy Calculator II widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calculator II.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Glassy Calculator II.exe" is shown as "GLASSY~1.EXE"Yes
Glassy Calculator IIUGLASSY~1.EXEGlassy Calculator II widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calculator II.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Glassy Calculator II.exe" is shown as "GLASSY~1.EXE"Yes
DesktopX WidgetUGLASSY~2.EXEGlassy Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calendar.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Glassy Calendar.exe" is shown as "GLASSY~2.EXE"Yes
Glassy CalendarUGLASSY~2.EXEGlassy Calendar widget for the DesktopX desktop utility from Stardock Corporation. Once started, Glassy Calendar.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Glassy Calendar.exe" is shown as "GLASSY~2.EXE"Yes
SpyBlocsXGLF*.exe [* = random chars]SpyBlocs rogue spyware remover - not recommended, removal instructions hereNo
GlideYGlidew32.exeCirque touchpad driverNo
RUNTIME SYSTEMXglm.exeDetected by McAfee as Generic BackDoor!fq3 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
GLO StartXGLO.exeDetected by Dr.Web as Trojan.MulDrop2.40626 and by Malwarebytes Anti-Malware as Trojan.Agent.GenNo
GlobeTrotter ConnectUglobetrotter connect.exeGlobeTrotter Connect - easy-to-use software application that "simplifies the management of Windows-based broadband Internet connections to WWAN networks, worldwide, automatically configuring connection to the service provider according to the SIM card inserted"No
Glock Suite 1.1Xglock32.exeDetected by Trend Micro as TROJ_TINY.GVNo
MiniphoneNglophone.exeVoiceGlo Glophone - "an affordable and convenient way to call friends and family throughout the world using a dial-up or broadband Internet connection on your computer" using the VoIP (Voice over Internet Protocol). No longer availableNo
RBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc ServerXglossary.exeAdded by the VANEBOT-J WORM!No
gluon?gluon.exeIn a gluon/bin sub-directoryNo
glvXglv.exeAdded by the DLOADER-NG TROJAN!No
DesktopX WidgetUGmail Checker.exeGmail Checker widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Gmail Checker.exe loads a file called "DXWidget.exe" and exits. This is the Windows Defender entryYes
Gmail CheckerUGmail Checker.exeGmail Checker widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Gmail Checker.exe loads a file called "DXWidget.exe" and exitsYes
Gmail Notifier PlusUGmail Notifier Plus.exeGmail Notifier Plus email notification utilityNo
Gmail Notifier.exeUGmail Notifier.exeGmail Notifier email notification utilityNo
DesktopX WidgetUGMAILC~1.EXEGmail Checker widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Gmail Checker.exe loads a file called "DXWidget.exe" and exits. This is the Vista/7 MSConfig entry where "Gmail Checker.exe" is shown as "GMAILC~1.EXE"Yes
Gmail CheckerUGMAILC~1.EXEGmail Checker widget for the DesktopX desktop utility from Stardock Corporation. Checks for new E-mail on Google via their Atom feed. Once started, Gmail Checker.exe loads a file called "DXWidget.exe" and exits. This is the XP MSConfig entry where "Gmail Checker.exe" is shown as "GMAILC~1.EXE"Yes
SymantecFilterCheckXgmilogof.exeAdded by the BANKER-EKC TROJAN!No
GmouseYGmouse.exeAmouse mouse driver - required if you use non-standard Windows driver featuresNo
GsAdsXgms2.exePacerD Media/Pacimedia.com adwareNo
Gmsvc32Xgmsvc32.exeAdded by the AGOBOT.ABN WORM!No
gmtXgmt.exePart of Gator adware - see here for removal instructions. Gator Corporation later became Claria Corporation, who distributed GAIN adwareNo
GStartupXGMT.exePart of Gator adware - see here for removal instructions. Gator Corporation later became Claria Corporation, who distributed GAIN adwareNo
Microsoft Internet Firewall ManagerXGMT16.exeAdded by the RANDEX.AT WORM!No
BharatayudaXGNB.exeAdded by the BHARAT.A WORM!No
GnetmousUgnetmous.exeGenius mouse driver - required if you use non-standard Windows driver featuresNo
Scroll Mouse DriversUGNETMOUS.EXEGenius mouse driver - required if you use non-standard Windows driver featuresNo
gngfgfgfhnfg.exeXgngfgfgfhnfg.exeDetected by Dr.Web as BackDoor.IRC.Bot.1919 and by Malwarebytes Anti-Malware as Trojan.ExploitdropNo
iOhvXCFgKA5YwN58Ybt1yVRcgtGb4GXgngfgfgfhnfg.exeDetected by Malwarebytes Anti-Malware as Trojan.Exploitdrop. The file is located in %AppData%No
Gekio StartupsXgnksvc32.exeDetected by Trend Micro as WORM_AGOBOT.AFJNo
{0228e555-4f9c-4e35-a3ec-b109a192b4c2}Ugnotify.exeGoogle Gmail Notifier. Alerts you when you have new Gmail messagesNo
GNUXGNU.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeMS. The file is located in %AppData%\GNUNo
gnub?gnub.exe??No
Go!Zilla Monster DownloadsXGo.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spywareNo
Google Service FRXGO0GLEFREE.EXEAdded by a variant of the SPYBOT WORM!No
Microsoft Intrenet ExplorerXgoaw.pifAdded by the RBOT-API WORM!No
OutlookExpressXgoawv.exeAdded by the RBOT-CC WORM!No
GoogleContactSyncUGOContactSync.exeGO Contact Sync by WebGear - "is an open source tool that synchronizes your contacts between Microsoft Outlook and Google Mail, it removes the hassle of entering details more than once"No
GOGXGOG.exeAdded by the PHILIS.B VIRUS!No
Philips GoGear OPUS Device ManagerNGoGear_OPUS_DeviceManager.exeManagement utility for the Philips GoGear OPUS MP3 video playerNo
RUNGogoToolsXGoGoLaunch.exeGoGoTools adwareNo
goidrXgoidr.exeGoidr adwareNo
GoldenWatchXGoldenWatch.exeDetected by Kaspersky as Trojan.Win32.Buzus.hgvaNo
ExplorerXgoldexc.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
Microsoft Gold ExchangeXgoldexc.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
GoldTachYGoldTach.exeGoldTech personal firewall from Matinsoft Inc - "is a powerful and easy-to-use internet security software that integrates four functions: Personal Firewall, Process Communication Control, E-mail Protection and Webpage Content Filtration"No
mdr procceXgona.exeAdded by the SPYBOT.AUU WORM!No
GoodMEMNGoodMEM.exeGoodMEM from MSI "automatically releases the system memory space, reducing the risk of system hang-up"No
GoodScanMainXGoodScan.exeGoodScan rogue security software - not recommended, removal instructions hereNo
GoodSyncUGoodSync.exeGoodSync file synchronization and backup utility from Siber Systems, Inc - required if you have enabled the automatic optionYes
6e1d0a9f2198bf2fcb3838391d245affXgoogel.exeDetected by Dr.Web as Trojan.DownLoader7.25074 and by Malwarebytes Anti-Malware as Trojan.MSILNo
668e76bd66dc6a580916fbd95cac8d0bXgoogEll.exeDetected by Dr.Web as Trojan.DownLoader7.25594 and by Malwarebytes Anti-Malware as Trojan.MSILNo
958436d9be3c028f3254ca9056e72392XGoogle Chrome.exeDetected by Dr.Web as Trojan.DownLoader8.26322 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Google Chrome browserNo
2420a218059d99c62b890c6698054fb9XGoogle Update.exeDetected by McAfee as RDN/Generic.tfr!cw and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not a valid Google process and it is located in %UserProfile%No
Google UpdateXGoogle Update.exeDetected by Sophos as Troj/DwnLdr-KNN and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not a valid Google process and it is located in %AppData%No
Google UpdateXGoogle Update.exeDetected by Dr.Web as Trojan.MulDrop4.6456. Note - this is not a valid Google process and it is located in %ProgramFiles%\GoogleNo
UpdateXGoogle Update.exeDetected by Dr.Web as Trojan.DownLoader6.22370 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not a valid Google process and it is located in %AppData%\GoogleNo
Google UpdaterXGoogle Updater.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %AppData%\MicrosoftNo
52cf539ca4a7d780842b49cfd8f2521dXgoogle.comDetected by Dr.Web as Trojan.DownLoader8.43772 and by Malwarebytes Anti-Malware as Trojan.MSILNo
Google ChromeXgoogle.comDetected by Malwarebytes Anti-Malware as Trojan.Banker.ACF. Note - this is not a legitimate Google Chrome browser entry and the file is located in %System%No
13e5090cee57967233f9b6a72ec1c5ddXGoogle.exeDetected by Dr.Web as Trojan.DownLoader7.32587 and by Malwarebytes Anti-Malware as Trojan.MSILNo
85ce27c90f0ba2b98ceb888e2ca7acdeXgoogle.exeDetected by Dr.Web as Trojan.DownLoader7.32961 and by Malwarebytes Anti-Malware as Trojan.MSILNo
googleXgoogle.exeAdded by the RBOT-AMW WORM!No
google Intrenet ExplorerXgoogle.pifAdded by the RBOT-ARA WORM!No
Chrome AppXGoogleApp.exeDetected by McAfee as RDN/Generic.grp and by Malwarebytes Anti-Malware as Trojan.Downloader.JKNo
Google One SecureXGoogleApp.exeDetected by Malwarebytes Anti-Malware as Trojan.Clicker.DF. The file is located in %ProgramFiles%\GoogleAppNo
Google Secure SurfingXGoogleApp.exeDetected by Sophos as Troj/Sisron-K and by Malwarebytes Anti-Malware as Trojan.ClickerNo
GoogleAppXGoogleApp.exeDetected by Dr.Web as Win32.HLLW.Autoruner.49527 and by Malwarebytes Anti-Malware as Trojan.AgentNo
GoogleBot.exeXGoogleBot.exeDetected by Total Defense as Downloader GBNo
Google Calendar SyncUGoogleCalendarSync.exe"Google Calendar Sync allows you to sync events between Google Calendar and Microsoft Outlook Calendar. You'll be able to determine the direction of information flow, as well as the sync frequency"No
googlechromeXgooglechrome.exeDetected by Malwarebytes Anti-Malware as Trojan.VBInject. Note - this is not the legitimate Google Chrome browser and the file is located in %AppData%\{1O5FE9-874ZZ-82311B-40456F8-2`266A5}No
GoogleDCClientNGoogleDCC.exeGoogle Compute Client - only present if you installed the Google Toolbar with "Google Compute" client active. Does complex calculations in the background when idle. If you want to turn it off go to your browser, click on the little double-helix on the Google Toolbar, and click "Stop Computing". No longer supportedNo
Google DesktopUGoogleDesktop.exeThe Google Desktop utility integrated Google's search capabilities for files on the user's system and allowed users to include gadgets such as clocks, weather and meters in a sidebar on the user's desktop - like that included with Windows 7 and Vista. Now discontinued and no longer availableYes
Google Desktop SearchUGoogleDesktop.exeThe Google Desktop utility integrated Google's search capabilities for files on the user's system and allowed users to include gadgets such as clocks, weather and meters in a sidebar on the user's desktop - like that included with Windows 7 and Vista. Now discontinued and no longer availableYes
GoogleDesktopUGoogleDesktop.exeThe Google Desktop utility integrated Google's search capabilities for files on the user's system and allowed users to include gadgets such as clocks, weather and meters in a sidebar on the user's desktop - like that included with Windows 7 and Vista. Now discontinued and no longer availableYes
GoogleDriveSyncUgoogledrivesync.exeGoogle Drive syncing feature to make sure all documents are up-to-dateNo
GoogleEarthXGoogleEarth.exeDetected by Malwarebytes Anti-Malware as MSIL.LockScreen. Note - this is not the legitimate Google Earth process which is normally located in %ProgramFiles%\Google\Google Earth\client. This one is located in %Appdata%No
GoogleUpdater3XGoogleMapper.exeDetected by Sophos as Troj/VBInj-FNo
Google Earth ViewerNGOOGLEMAPS.EXEGoogle Earth "combines satellite imagery, maps and the power of Google Search to put the world's geographic information at your fingertips"No
svcXGoogleon.exeDetected by Symantec as W32.Ogleon.ANo
Google IME AutoupdaterUGooglePinyinDaemon.exeGoogle Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone, depending on the system) and then presenting the user with a list of possible characters with that pronunciationNo
Google Pinyin 2 AutoupdaterUGooglePinyinDaemon.exeGoogle Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone, depending on the system) and then presenting the user with a list of possible characters with that pronunciationNo
Google Quick Search BoxUGoogleQuickSearchBox.exePart of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the "Start" button and Quick Launch toolbar and "lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"Yes
GoogleQuickSearchBoxUGoogleQuickSearchBox.exePart of Google Toolbar (from version 6 onwards) for IE. The Quick Search Box sits between the "Start" button and Quick Launch toolbar and "lets you easily search both your computer and the Web from a slick-looking search box that comes up only when you need it"Yes
Google serviceXGooglesetup.exeAdded by the IRCBOT-RJ WORM!No
Google Smart UpdaterXGoogleSmartUpdater.exeDetected by Sophos as Troj/Agent-XIC and by Malwarebytes Anti-Malware as Trojan.MSILNo
googletalkUgoogletalk.exeGoogle Talk "enables you to call or send instant messages to your friends for free-anytime, anywhere in the world". Can be launched manuallyNo
KEYBOARDXGoogleTask.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.DPTNo
Barra de Busca do GoogleXGoogleToolbarNotifier.exeDetected by Dr.Web as Trojan.DownLoad3.22059 and by Malwarebytes Anti-Malware as Trojan.Sasfis. Note - this is not the legitimate Google Toolbar file of the same name which is normally located in %ProgramFiles%\Google\GoogleToolbarNotifier. This one is located in %ProgramFiles%\Windows Media PlayerNo
GoogleToolbarNotifierUGoogleToolbarNotifier.exePart of Google Toolbar (from version 4 onwards) for IE. "Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolvedYes
swgUGoogleToolbarNotifier.exePart of Google Toolbar (from version 4 onwards) for IE. "Google Toolbar Notifier allows you to set Google as your default search engine and prevents your search settings from being changed without your consent. An icon in your system tray blinks if the Notifier identifies an attempt to change your default search engine. You can click the icon to get more details and allow the change". There was a bug in earlier versions where disabling the option resulted in the entry still running at startup but this has now been resolvedYes
1f0531f3509c1a0398b97d77a0dd797bXGoogleUp.exeDetected by Dr.Web as Trojan.DownLoader6.39734 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not a valid Google process and it is located in %Temp%No
GoogleXGoogleup.exeDetected by Dr.Web as Trojan.DownLoader6.10673No
GoogleUp.exeXGoogleUp.exeDetected by Dr.Web as Trojan.Siggen4.10027 and by Malwarebytes Anti-Malware as Trojan.Fakegoogle. The file is located in %AppData%No
GoogleUp.exeXGoogleUp.exeDetected by Dr.Web as Trojan.DownLoader6.10673. The file is located in %Temp%No
AcroreadXGoogleUpdate.exeDetected by Sophos as Troj/Agent-JGI. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %Temp%No
Chrome Automatic UpdaterXGoogleUpdate.exeDetected by McAfee as Generic.dx!bbt4. Note - this is not a legitimate Google Chrome browser fileNo
Google InstallerNGoogleUpdate.exeUpdate manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %LocalAppData%\Google\UpdateNo
Google UpdateNGoogleUpdate.exeUpdate manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %LocalAppData%\Google\UpdateNo
Google UpdateXGoogleUpdate.exeDetected by Kaspersky as Trojan.Win32.Buzus.dbfm. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %System%No
GoogleTaskXgoogleupdate.exeDetected by Dr.Web as Trojan.MulDrop4.3133. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %LocalAppData%\GoogleNo
GoogleUpdXGoogleUpdate.exeDetected by Trend Micro as BKDR_FYNLOS.A and by Malwarebytes Anti-Malware as Trojan.Agent.IGen. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %AppData%No
GoogleUpdateXGoogleUpdate.exeDetected by Microsoft as Backdoor:Win32/Fynloski.A and by Malwarebytes Anti-Malware as Trojan.FakeInv. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %AppData%No
GoogleUpdateXgoogleupdate.exeDetected by Malwarebytes Anti-Malware as Trojan.RemoteAccess. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %AppData%\UpdateNo
GoogleUpdateXGoogleUpdate.exeDetected by Symantec as Backdoor.Banechant. Note - this entry loads from the Windows Startup folder and is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %CommonAppData%\Google2No
GoogleUpdateNGoogleUpdate.exeUpdate manager for the range of tools available from Google - such as the Chrome web browser and Picasa photo manager. Located in %LocalAppData%\Google\UpdateNo
GoogleUpdateXGoogleUpdate.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %Root%\SetupNo
GoogleupdaterXGoogleUpdate.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %Temp%No
GoogleUpdater.exeXGoogleUpdate.exeDetected by McAfee as W32/Autorun.bfr!d and by Malwarebytes Anti-Malware as Spyware.Passwords.XGen. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %AppData%\GoogleToolbarNo
UpdateXGoogleupdate.exeDetected by Symantec as Backdoor.Boda and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid Google program which is normally located in %LocalAppData%\Google\Update. This version is located in %AppData%No
Google UpdaterNGoogleUpdater.exeDownloads and installs updates for Google applications (Google Earth, Picasa, etc.). The file is located in %ProgramFiles%\Google\Google UpdaterNo
Office MonitorsXGoogleUpdater.exeDetected by Sophos as W32~Rbot-GKZ. Note - this is not the updater for the popular Google tools which has the same filename and is normally located in %ProgramFiles%\Google\Google Updater. This one is located in %System%No
Offices MonitorsXGoogleUpdater.exeDetected by Sophos as W32/Rbot-GKO. Note - this is not the updater for the popular Google tools which has the same filename and is normally located in %ProgramFiles%\Google\Google Updater. This one is located in %System%No
Offices MonitorseXGoogleUpdater.exeDetected by Sophos as W32/Rbot-GKO. Note - this is not the updater for the popular Google tools which has the same filename and is normally located in %ProgramFiles%\Google\Google Updater. This one is located in %System%No
UpdaterXGoogleUpdater.exeDetected by Malwarebytes Anti-Malware as Trojan.FakeGoogle. Note - this is not the updater for the popular Google tools which has the same filename and is normally located in %ProgramFiles%\Google\Google Updater. This one is located in %AppData%No
GoogleUpdateTaskXGoogleUpdateTask.exeDetected by McAfee as RDN/Ransom and by Malwarebytes Anti-Malware as Trojan.AgentNo
GoogleUploadXGoogleUpload.exeDetected by Malwarebytes Anti-Malware as Trojan.Delf. The file is located in %Windir%No
Run Google Web AcceleratorUGoogleWebAccWarden.exeGoogle Web AcceleratorNo
Google UpdateXGoogle_Update.exeDetected by McAfee as Generic BackDoor!fgw. Note - this is not a valid Google process and it is located in %Templates%No
Google_UpdateXGoogle_Update.exeDetected by McAfee as Generic BackDoor!fgw. Note - this is not a valid Google process and it is located in %Templates%No
GoogleZxXgoogle_zx.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%\GoogleZxNo
Google UpdaterNGOOGLE~1.EXEDownloads and installs updates for Google applications (Google Earth, Picasa, etc.)No
Google ToolsXgoolge.exeAdded by the CAMBOT.A WORM!No
IEXPLORE.EXEXgoot.exeAdded by the BIFROSE-C TROJAN!No
MSConfigXgoqi.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
5313fc45b4cfca54be5654fded1163c8Xgoran.exeDetected by Dr.Web as Trojan.DownLoader8.32076 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJNo
HOT FIXXGothic.exeAdded by the SDBOT.FIR WORM!No
WINDOWS SYSTEMXgothica.exeDetected by Trend Micro as WORM_MYTOB.HUNo
CommandXGotit.exeAdded by the TITOG WORM!No
gotnewupdate000.exeXgotnewupdate000.exeAdded by the FAKEAV-BGA TROJAN!No
GoTrustedUGoTrusted Secure Tunnel.exe"GoTrusted is the fast, easy way to secure your PC's Internet data and protect your privacy"No
GotSmileyXGotSmiley.exeGotSmiley - E-mail utility. Contains GAIN adware by Claria CorporationNo
Go!ZillaXgozilla.exeDownload manager for resuming downloads and choosing multiple download locations. Advertising spywareNo
Windows Printing DriverXgpedits.exeAdded by the DCKEYG.A WORM!No
SUPPORT GFXXGpers.exeDetected by McAfee as Generic BackDoor!fqp and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
wacultXgpesndr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
Yahoo MessenggerXgphone.exeAdded by the TIOTUA-W WORM!No
gpresultlXgpresultl.exeDetected by Dr.Web as Trojan.DownLoader6.1998 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Windows Host ProcessorXgpresultl.exeDetected by Dr.Web as Trojan.DownLoader6.1998 and by Malwarebytes Anti-Malware as Trojan.Agent.HPGenNo
GPUpdate © Microsoft CorporationXgpupdate.exeDetected by McAfee as RDN/Generic PUP.x and by Malwarebytes Anti-Malware as Trojan.AgentNo
GP UpdaterXgpupdater.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
MaxsizedXgqasqs.exeAdded by the LIOTEN.IR WORM!No
gqgqqgerXgqgeqegl.exeAdded by the SDBOT-CLJ WORM!No
Windows LoL LayerXgqwdcr.exeAdded by the AGOBOT-AHS WORM!No
GRANgra.exeLooks at system resources at startup and warns you if they have dropped. Contains links to the Disk Clean Up, Defrag and Start Up Menu. It does have a link to a startup configuration utility. Similar to msconfig but can keep a list of disabled apps. Not really necessary. Only appears if you load the Gateway Startup UtilityNo
GCSNGrabClipSave.exeGrabClipSave screen capture toolNo
graka.exeXgraka.exeDetected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %AppData%\windowsupdateNo
DarkDevil.Grasiele.BRXGrasiele.VBSAdded by the LEMBRA WORM!No
GRC V2 HyperappelUGRCHA.exeAllows you to select a word or phrase within a document, application, web-page, etc and search for it within the "Le Grand Robert & Collins" French/English dictionary from Le Robert. See here for more informationNo
GrdSys32?GrdSys32.exeX-Stream ISP software. Offers free Net access funded by on-screen ads. Is it required or can you create your own dial-up networking connection to use on demand?No
GreasyPalmUpdateXGreasyPalmUpdate.exeSearchFast adwareNo
GreatDefenderXGreatDefender.exeGreatDefender rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
GreatDefender.exeXGreatDefender.exeGreatDefender rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
HELPERXgreece_nm.exeAsdPlug premium rate adult content dialer variantNo
Verbatim GREEN BUTTONUGREEN BUTTON.exeGREEN BUTTON utility for the Verbatim Store 'n' Go range of portable hard drives - which "reduces energy consumption and extends the drive's life expectancy by automatically placing the Verbatim Store 'n' Go into sleep mode after a programmed period of time or by the user manually clicking on the GREEN BUTTON on the desktop"No
AliUSBfix?GREENMK.exeMay be related to a USB 2.0 PCI card - the IOgear GIC220OU?No
greenopenXgreenopenuper.exeDetected by Dr.Web as Trojan.DownLoader4.21714 and by Malwarebytes Anti-Malware as Adware.GreenOpen. The file is located in %ProgramFiles%\intothemap CPNo
GreenshotNGreenshot.exeGreenshot light-weight screenshot capture utilityNo
Screen_SaverXGreen_Flower.scrDetected by Dr.Web as Trojan.MulDrop3.48888No
55278Xgrepclient1.exeAdded by the LINEAGE-S TROJAN!No
GrfsfyXGrfsfy.exeAdded by the DORKBOT-A MALWARE!No
GridspotUGridspot.exe"Gridspot combines the resources of idle computers all over the world and makes them available to companies and researchers working on big problems"No
grindersXgrinders.exeAdded by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an exampleNo
GroksterNGrokster.exeGrokster peer-to-peer (P2P) file-sharing client - now defunctNo
Groove Virtual OfficeYGroove.exe"Groove Virtual Office uses a peer-to-peer networking model to connect users in Groove Workspaces. In these workspaces geographically dispersed coworkers can do almost everything they could do in the same office. They can hold online meetings, store files and folders, save threaded discussions, scribble on whiteboards, share calendars, and track project information and timelines." Formerly by Groove Networks - now owned by Microsoft and part of MS OfficeNo
Microsoft Office GrooveUGROOVE.EXESystem Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. "A collaboration software program that helps teams work together dynamically and effectively, even if team members work for different organizations, work remotely, or work offline". Users can create workspaces and invite other Groove users to share the workspace and when a document is edited within the workspace the changes made become available to all other users in the workspace when they come online - synchronized using LAN, WAN and the InternetYes
GrooveMonitorUGrooveMonitor.exePart of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. "A collaboration software program that helps teams work together dynamically and effectively, even if team members work for different organizations, work remotely, or work offline". GrooveMonitor is responsible for synchronizing the Groove workspaces between the users PC and those of other workspace participants. If you don't use Groove to collaborate with co-workers you can safely disable this entryYes
GrooveMonitor UtilityUGrooveMonitor.exePart of MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. "A collaboration software program that helps teams work together dynamically and effectively, even if team members work for different organizations, work remotely, or work offline". GrooveMonitor is responsible for synchronizing the Groove workspaces between the users PC and those of other workspace participants. If you don't use Groove to collaborate with co-workers you can safely disable this entryYes
GrpConvNgrpconv.exeMicrosoft Windows Program Group Converter - used by installers (ONLY in the RunOnce keys) - provides the translation of groups and group items to folders and links. Also see this MS Knowledge Base articleNo
Virtual CD v6Xgrplscd.exeDetected by Sophos as W32/Rbot-AXV and by Malwarebytes Anti-Malware as Backdoor.BotNo
System UpdateXgrtbdwmc.exeDetected by McAfee as W32/Pate.bNo
grwinHyperUgrwinHyper.exeAllows you to select a word or phrase within a document, application, web-page, etc and search for it within the "Le Grand Robert" French dictionary from Le Robert. See here for more informationNo
Gravis Xperience Driver SupportUGrxp4exe.exeDriver for Gravis game controllers such as the Eliminator Aftershock. Must be loaded if you run the supplied application software for the controller to be recognized. Start it manually via a shortcut if not usedNo
WIN USB SUPPORTXgrxsrv.exeAdded by a variant of Win32/RbotNo
Gscbc?Gscbc.exe??No
DOGStartXGSDOGST.EXEAdded by an unidentified VIRUS, WORM or TROJAN! A possibility is a trojan known as PENISNo
gserverXgserver.exeDetected by Dr.Web as BackDoor.IRC.NgrBot.189 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Realtek Sound ManagersXgsfttmhq.exeDetected by McAfee as W32/Sdbot.worm.gen.ca and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
zzgshpXgshp.vbsHomepage hi-jacker that re-defines your IE or Netscape start pageNo
GsiconexeNGsicon.exeADSL modem monitor from Eicon Networks (now Dialogic). Can safely be disabled without affecting the connection - all this does is give an indication of connectivity and access to the diagnostic facilitiesNo
GSISETUP?GsiInst.exeRelated to a BT Voyager ADSL modem. What does it do and is it required?No
GMedia2XGSM2.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!No
G3XGSMedia3.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!No
GMedia2XGSMedia3.exeMalware downloader - detected by Kaspersky as the VB.UX TROJAN!No
GSOrganizerNGSOrganizer.exeGoldenSection Organizer (now WinOrganizer - personal information manager)No
VideoDriverXgspotbot.exeAdded by the SPIGOT.C TROJAN!No
GhostSecuritySuiteUgss.exeGhost Security Suite - protect the registry from unauthorized reading and modification and other toolsNo
gssomaticXgssomatic.exeSearchcentrix hijackerNo
gStartYgStart.exeGarmin Training Center® software for their sports GPS devices. "Track and analyze your fitness activities with Garmin Training Center. Use it to review activity history as well as create workouts and send them to your Garmin fitness device"No
Genie TimeLine TrayUGSTimeLineAgent.exeSystem Tray access to the Genie Timeline backup utility from Genie9 CorporationNo
gsvXgsv.exeAdded by the ROBAL 1.0 backdoor TROJAN!No
GazelDisplayUgsyno.exeBT Digital Access USB - Gazel ISDN installation System Tray iconNo
GotSmileyXGSYUpdater.exeGotSmiley - E-mail utility. Contains GAIN adware by Claria CorporationNo
GTXGT.EXEAdded by the SDBOT-AJ WORM!No
Microsoft Windows WKS ServiceXgt.exeAdded by the SDBOT.IR BACKDOOR!No
1cefa624caa8a35f6e2e9f51e9ca3c81XGTA iv.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
ECenterUgtb.exeDell E-Center/Google Toolbar relatedNo
GamingWonderland Browser Plugin LoaderUgtbrmon.exeGamingWonderland toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use itNo
GameTrackerNGTLite.exeGameTracker - "Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!"No
GreedyTorrentNGTor.exeGreedyTorrent by Alex N J - "is a freeware software program that can boost your BitTorrent upload ratio." As BitTorrent is a peer-to-peer (P2P) file-sharing client used to distribute large amounts of data between multiple users make sure you have good, up-to-date virus protection and check any downloadsNo
GamingWonderland Search Scope MonitorUgtsrchmn.exeGamingWonderland toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use itNo
GTVEpgUGTVEpg.exePart of Got All Media - control your TV tuner and other utilities from your PCNo
GTVRecUGTVRec.exePart of Got All Media - control your TV tuner and other utilities from your PCNo
GtwatchNgtwatch.exeAssociated with a Mustec scanner and not requiredNo
GuardUGuard.exeRelated to Phoenix Technologies Core Managed Environment (cME) Integration and Certification programNo
MicrosoftXguard.exeAdded by a variant of W32/Sdbot.wormNo
GuardCenterXGuardCenter.exeGuardCenter rogue security software - not recommendedNo
GuardSupportXGuardConvert.exeDetected by Malwarebytes Anti-Malware as Adware.K.MicronamesNo
Ashampoo AntiVirus ServiceYGuardGui.exeSystem Tray access to the main user interface for Ashampoo® AntiVirusYes
GuardGui ApplicationYGuardGui.exeSystem Tray access to the main user interface for Ashampoo® AntiVirusYes
Guard.Mail.ru.guiYGuardMailRu.exeAssociated with Mail.Ru - "the largest free e-mail service of the Runet". Guard Mail.Ru - is "a multifunctional safety management programs to protect your PC from unwanted user actions"No
kernel32dllXguardpc.exeAdded by the FORBOT-CU WORM!No
GuardPcs.exeXGuardPcs.exeGuardPcs rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
GuardWWWXGuardWWW.exeGuardWWW rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
guarnsetXguarnset.exeAdlogix adwareNo
gubqiqnyxlafXgubqiqnyxlaf.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile%No
gudacxazteahXgudacxazteah.exeDetected by McAfee as Downloader.a!dcl and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
wsdpa64Xgudio32.exeDetected by Dr.Web as Trojan.MulDrop4.26419 and by Malwarebytes Anti-Malware as Trojan.AgentNo
gufxadycvyptXgufxadycvypt.exeDetected by McAfee as BackDoor-FAFP!B25E94A7C875 and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
EasyTuneVUGUI.exeEasyTune 5 for Gigabyte motherboards. A "simple and easy-to-use interface that allows users to fine-tune their system settings or do overclock/overvoltage in Windows environment"No
Startup Launcher GUI?GUI.exeStartup manager?No
GuideOnXGuideOn.exeDetected by Microsoft as Adware:Win32/PinGuideNo
gummyXgummy.exeAdded by the VANEBOT-AQ WORM!No
gtalkupdateXgupd.exeDetected by Microsoft as Worm:Win32/Enosch.ANo
Google UpdateXgupdate.exeDetected by Kaspersky as Trojan.Win32.Menti.hckx and by Malwarebytes Anti-Malware as Trojan.Agent.HNo
GURLXgurl.exeGURLWatcher spywareNo
WinTOTAL SchedulerNguru.exeWinTOTAL Real estate appraisal software relatedNo
GuruNetUGuruNet.exeGuruNet (now replaced by Answers.com) was a utility that let you click on any word on your screen to get the relevant information you wantNo
4-gusdurXgusdur.exeAdded by the BRONTOK-CR WORM!No
guyik45hbhXguyik45hbh.exeDetected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
guyik45hbhxXguyik45hbhx.exeDetected by Kaspersky as Trojan.Win32.Scar.dheq and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
guzsicfylnahXguzsicfylnah.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %AppData%\hzvfmstrmyhymt - see hereNo
gvaccinestart.exeXgvaccinestart.exeDetected by Malwarebytes Anti-Malware as Rogue.K.Vaccine. The file is located in %ProgramFiles%\gvaccineNo
GvCXGVC.exeAdded by the RBOT.CB WORM!No
Gateway Extended WarrantyNGWCares.exeGateway Extended Warranty reminderNo
Microsoft Driver SetupXgwdrive32.exeAdded by the VB-FBT TROJAN!No
Multi-function keyboardUGWHotkey.exeSoftware that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail, browser, volume and CD/DVD controls, etc)No
Gateway Ink MonitorNGWInkMonitor.exeInk level monitor for Gateway branded printersNo
GWInkMonitorNGWInkMonitor.exeInk level monitor for Gateway branded printersNo
GWMDMMSGNGWMDMMSG.exeUsed with internal modems on Gateway and vprMatrix PCs. This is the "GTW modem messaging applet" and is not required for the modem to work correctlyNo
GWMDMpiUGWMDMpi.exePatch for internal modems on Gateway 450 and 500 series laptops. Required for audio settings to be maintained and does not remain in memory once runNo
SourcePathNgwreg.exeUsed to update Gateway registry settings for System Restoration Kit and Web update programsNo
Greetings WorkshopNGWREMIND.EXEYou really want to be reminded about somebody's birthday at the expense of resources?No
Microsoft Greetings Workshop ReminderNGwremind.exeYou really want to be reminded about somebody's birthday at the expense of resources?No
oxbvpenXgwthtis.exeAdded by the SILLYFDC-AH WORM!No
GWUMUgwum.exeGigabyte utility manager. Loads if you have a Gigabyte motherboard and got a full bundle of utilities installed. Monitors CPU, fans, BIOS etc. Only used by system "tweakers"No
fGQEGqHOMEXgwwgtp.exeAdded by the RANKY.J TROJAN!No
vmcleanerXgxlib.exeAdded by the SMALL-HS TROJAN!No
SnaSystemXGY68r78.exeDetected by Dr.Web as Trojan.DownLoader8.31722 and by Malwarebytes Anti-Malware as Backdoor.Agent.SVRNo
gycnakajahyzXgycnakajahyz.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile%No
gydufbeawungzapXgydufbeawung.exeDetected by Sophos as Troj/DwnLdr-KMO and by Malwarebytes Anti-Malware as Trojan.Agent.USNo
hid_startXgzmrotate.dllAdRotator/IconAds adwareNo
G_Server.exeXG_Server.exeDetected by Kaspersky as Backdoor.Win32.Agent.px and by Malwarebytes Anti-Malware as Trojan.Backdoor.DFNo
G_Server1.2.exeXG_Server1.2.exeAdded by the GRAYBIRD-Z TROJAN!No

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home