| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 31st May, 2013
32700 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1133 results found for I
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| test | X | i love you.exe | Added by the SINGU-T TROJAN! | No |
| rate.exe | X | i11r54n4.exe | Added by the BEAGLE-I WORM! | No |
| rate.exe | X | i1ru74n4.exe | Added by the BEAGLE.E WORM and variants! | No |
| I386 | X | I386.exe | Added by the MYPOWER WORM! | No |
| Config Loadatiorin | X | I3Explorer.exe | Added by the SDBOT.H TROJAN! | No |
| i6g8xs | X | i6g8xs.exe | Detected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| I81SHELL | ? | I81SHELL.exe | Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard | No |
| i8kfangui | U | I8kfanGUI.exe | I8kfanGUI - Dell Inspiron/Latitude/Precision fan control utility | No |
| IntruderAlert | X | ia99.exe | Intruder Alert '99 from Bonzi - spyware | No |
| IAAnotif | U | Iaanotif.exe | Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes, HDD I/O errors or HDD SMART event) via a System Tray icon when an event occurs. Via this icon you can then choose to launch the Intel Matrix Storage Console or ignore the current alert | Yes |
| RAID Event Monitor | U | Iaanotif.exe | Part of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes, HDD I/O errors or HDD SMART event) via a System Tray icon when an event occurs. Via this icon you can then choose to launch the Intel Matrix Storage Console or ignore the current alert | Yes |
| iPlusAgent | U | iAgent.exe | iriver PLUS media management utility for their range of portable media devices | No |
| iPlusAgent2 | U | iAgent2.exe | iriver PLUS media management utility for their range of portable media devices | No |
| 3P_UDEC_IA | X | IAInstall.exe | Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions here | No |
| Internet Answering Machine | U | IAM.exe | From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access | No |
| iamapp | Y | iamapp.exe | Part of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Also part of their now discontinued Symantec Desktop Firewall (for business customers). Formally AtGuard by WRQ until their acquisition by Symantec. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Internet Answering Machine | U | IAMNET~1.EXE | From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access | No |
| NAV Auto Update | X | iamsad.exe | Added by the SPYBOT-CE BACKDOOR! | No |
| IaNvSrv | ? | IaNvSrv.exe | Related to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required? | No |
| SM_IAN | X | ian_monitor.exe | AdvancedCleaner rogue security software - not recommended, see here. Removal instructions here | No |
| Iap | ? | iap.exe | Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely? | No |
| Internet Antivirus Pro | X | IAPro.exe | Internet Antivirus Pro rogue security software - not recommended, removal instructions here | No |
| Live Enterprise Suite | X | IAPro.exe | Live Enterprise Suite rogue security software - not recommended, removal instructions here | No |
| ias | U | ias.exe | InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| IASHLPR | X | IASHLPR.EXE | Added by the OPASERV.T WORM! | No |
| Microsoft Keyboard Enhance 2.0. | X | iasrecst.exe | Added by the BCKDR-QIL BACKDOOR! | No |
| Microsoft Keyboard Enhance V2.0 | X | iasrecst.exe | Detected by F-Prot as the DOWNLOADER2.AILI TROJAN! | No |
| Microsoft media services | X | Iassd.exe | Added by the SPYBOT.HE WORM! | No |
| IAStorIcon | U | IAStorIcon.exe | System Tray acces to and notifications for Intel® Rapid Storage Technology - which "provides new levels of protection, performance, and expandability for desktop and mobile platforms. Whether using one or multiple hard drives, users can take advantage of enhanced performance and lower power consumption." If enabled it will give you quick access to the main utility and provide alerts if any problems are detected | Yes |
| iasx | X | iasx.exe | Added by the NURECH TROJAN! | No |
| Microsoft Internet Acceleration Utility | X | iau.exe | EasySearch adware | No |
| Microsoft Office Quick Launcher | X | iau1.exe | Added by the DLOADR-AWD TROJAN! | No |
| Internet Antivirus | X | IAvir.exe | Internet Antivirus rogue security software - not recommended, removal instructions here | No |
| RenolB | ? | ib.exe | ?? | No |
| IBWin Background process | U | IBackground.exe | IBackup for Windows | No |
| Iomega Automatic Backup | U | ibackup.exe | Iomega Automatic Backup - automatic backups for use with Iomega portable HDD | No |
| Iomega Automatic Backup 1.0.1 | U | ibackup.exe | Iomega Automatic Backup - automatic backups for use with Iomega portable HDD | No |
| Instant Buzz Daemon | X | IBDaemon.exe | Instant Buzz adware | No |
| ibm | X | ibm.exe | Added by the LEGMIR-AH TROJAN! | No |
| Shell | X | ibm0000*.exe [* = digit] | Detected by Sophos as Troj/Torpig-C and by Malwarebytes Anti-Malware as Trojan.Agent. Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on and they are typically located in %CommonFiles%\Microsoft Shared\Web Folders | No |
| Shell | X | ibm00001.dll | Added by the TORPIG-Q TROJAN! | No |
| IBMUltraBayHotSwapCPLLoader | U | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops | No |
| IBMUltraBayHotSwapSound | ? | IBMBAYSN.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound? | No |
| Access IBM Message Center | N | ibmmessages.exe | "The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current" | Yes |
| ibmmessages | N | ibmmessages.exe | "The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current" | Yes |
| Ibmmon.exe | ? | Ibmmon.exe | ?? | No |
| IBWin Monitor | U | IBMonitor.exe | IBackup for Windows | No |
| Ibmpmsvc | U | ibmpmsvc.exe | Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes | No |
| IBMPRC | ? | ibmprc.exe | IBM application - what does it do and is it required? | No |
| Taskman | X | ibnzs.exe | Added by the AGENT-NTI TROJAN! | No |
| Shmgrate.exe | X | ibot4.exe | Added by the GASTER TROJAN! | No |
| Ibs | X | ibs.exe | Added by the HIDEDIAL-B TROJAN! | No |
| InstallBuddy | U | Ibtna.exe | InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync | No |
| IcaBar | Y | icabar.exe | Related to Citrix MetaFrame | No |
| Tlwg | X | icardresy.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
| xxps | X | iCare Data & Format Recovery Keygen.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| icasServ | X | icasServ.exe | Browser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN! | No |
| loveqq | X | ICBServer.exe | Detected by Malwarebytes Anti-Malware as Trojan.ChinAd. The file is located in %UserTemp% | No |
| iedecadd | X | iccadd.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieData | No |
| iediescadd | X | iccadd.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieData | No |
| ICcontrol | X | iccontrol.exe | ICcontrol premium rate adult content dialer | No |
| Internet Call Director | U | ICD.EXE | TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet | No |
| Asicfc | X | icfca.exe | Detected by Trend Micro as WORM_AGENT.AAJE | No |
| ichckupd | X | ichckupd.exe | SurfSideKick.B adware | No |
| {48DBCECD-61F9-DBB6-AB03-49E1901B80A7} | X | ichu.exe | Added by the MDROP-CZM TROJAN! | No |
| iClean | U | iClean.exe | IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy" | No |
| Sweep95 | Y | ICLOAD95.EXE | Part of an older version of Sophos anti-virus software | No |
| iCloudServices | U | iCloudServices.exe | Apple iCloud support for Windows users which "lets you access your music, photos, calendars, contacts, documents, and more, from whatever device you're on" | No |
| ICM | U | ICM.EXE | Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail | No |
| Internet Call Manager | U | ICM.EXE | Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail | No |
| InterCheck Monitor | Y | ICMON.EXE | Part of an older version of Sophos antivirus software | No |
| InterCheckMonitor | Y | ICMON.EXE | Part of an older version of Sophos antivirus software | No |
| Enterra Icon Keeper | U | IcnKeepr.exe | Icon Keeper - "tool to save and restore icon positions on the desktop" | No |
| ICO | U | ICO.EXE | Found on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games | No |
| Mouse Suite 98 Daemon | U | ICO.EXE | Found on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games | No |
| ICON 225 USB Connect | ? | ICON 225 USB Connect.exe | Related to the iCON 225 USB modem from Option - as provided by Orange. What does it do and is it required? | No |
| Boingo Wireless Utility | U | Icon###XXX#X#.exe | Starts the Boingo Wireless utility, used to detect and login into Boingo wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start → Programs | No |
| iconcache | Y | icon.bat | Related to the Vista Customization Pack | No |
| Icon lptt01 | X | icon.exe | RapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| Icon ml097e | X | icon.exe | RapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| PocketCam 3Mega Monitor | N | ICON.exe | Installed with the Aiptek PocketCam 3Mega digital camera. Automatically invokes an import process if the camera is connected and has media on it | No |
| ICON2 USB Connect | ? | ICON2 USB Connect.exe | Related to the iCON2 USB modem from Option - as provided by Orange. What does it do and is it required? | No |
| ICONCLNT | Y | iconclnt.exe | APC PowerChute software which controls their range of uninterruptible power supplies (UPS) - to provide unattended shutdown of servers and workstations in the event of an extended power outage and status logging | No |
| ICONDESK | U | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons | No |
| Iconfig.exe | N | Iconfig.exe | System Tray icon associated with a Shuttle Technology LS-120 SuperDisk - which is a high-speed, high-capacity alternative to the standard floppy disk | No |
| E-color | U | IconMgr.Exe | Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program | No |
| Iconoid | N | Iconoid.exe | Iconoid is a desktop icon manager | No |
| Iconsaver | N | Iconsaver.exe | IconSaver is a desktop icon manager | No |
| DesktopX | Y | IconX.exe | IconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate download | Yes |
| IconX | Y | IconX.exe | IconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate download | Yes |
| IconX.exe | Y | IconX.exe | IconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate download | Yes |
| Internet Content Publisher | X | ICP.EXE | Added by the RBOT-UD WORM! | No |
| Avg Antivirus | X | icpldrvx.exe | Added by the BANKER.BYU TROJAN! | No |
| Msconfig | X | icpldrvx.exe | Added by the BANLOAD.BFT TROJAN! | No |
| Mirabilis ICQ | N | icq.exe | If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start → Programs | No |
| ICQ Messenger 2002 | X | ICQ2002.exe | Added by the SDBOT-ABL WORM! | No |
| ICQ Agent | X | icq6.exe | Added by the AGENT-FZJ TROJAN! | No |
| runapp | X | icqchk.exe | Added by the BOMKA TROJAN! | No |
| ICQ Chat Service | X | icqjdhs.exe | Added by a variant of Win32/Rbot | No |
| ICQ Lite | N | ICQLite.exe | ICQ Lite - compact version of the popular messaging program | No |
| ICQ Lite Messenger | X | ICQLITE.EXE | Added by an unidentified VIRUS, WORM or TROJAN! The legitimate ICQ Lite executable is located in %ProgramFiles%\ICQLITE whereas this one is located in %System% | No |
| ICQMonitor | U | ICQMonitor.exe | ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself | No |
| Mirabilis ICQ | N | ICQNet.exe | Automatically runs an old version of ICQ (when it was from Mirabilis) if connected to the internet. Convenience more than anything | No |
| ICQ | X | ICQNET.vbs | Added by the GORMLEZ-A WORM! | No |
| ICQ Hacking Pro | X | ICQpro.exe | Added by a variant of the NETSPY TROJAN! | No |
| Windows UDP Control Center | X | icqversin.exe | Added by the MDROP-DP MALWARE! | No |
| Windows Explorer | X | Icrypt.exe | Detected by McAfee as Generic.dx!bcvd and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| ICServer | N | Icserver.exe | Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations | No |
| ICSMGR | Y | ICSMGR.EXE | Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers | No |
| some | X | icthis.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details | No |
| ^SetupICWDesktop | N | icwconn1.exe | Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start → All Programs → Accessories → Communication (or similar) anyway | No |
| Internet Connection Wizard Setup Tool | X | icwsetup.exe | Added by the PINCAV.HJK TROJAN! | No |
| blah services | X | iczw.exe | Added by the RBOT-GMP WORM! | No |
| stcinstaller | X | id53.exe | Detected by Trend Micro as TROJ_SCTHOUGHT.L | No |
| Id8525 | X | id8525.exe | Added by the ID8525.A TROJAN! | No |
| Id8525 | X | id85255.exe | Added by the ID8525.A TROJAN! | No |
| IDA | ? | IDA.EXE | Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required? | No |
| Internet Download Accelerator | U | ida.exe | Internet Download Accelerator download manager from WestByte Software - "effectively solves three of the biggest problems when downloading files: speed, resuming broken downloads, and management of downloaded files" | No |
| IDBoan | X | IDBoan.exe | IDBoan rogue security software - not recommended, removal instructions here | No |
| iWonIE Browser Plugin Loader | U | idbrmon.exe | IWON IE toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use it | No |
| ID Commander | N | IDCom.exe | Caller ID utility for identifying incoming telephone numbers | No |
| intdctrr | X | idctup20.exe | Added by a variant of Spyware.SafeSurfing | No |
| IDE | X | ide.exe | Added by the ASSASIN.F TROJAN! | No |
| Idecntl | X | idecntl.exe | Added by the GEMA TROJAN! | No |
| IDE Loader | X | IDElibr32.exe | Added by the XILON TROJAN! Related to the game "Diablo II" | No |
| MS Service Manager | X | idemoodp0cetka.exe | Detected by Dr.Web as Win32.HLLW.Autoruner.52646 and by Malwarebytes Anti-Malware as Trojan.VBKrypt | No |
| Data LifeGuard | ? | identify.exe | Part of the Data LifeGuard diagnostic tools for Western Digital's series of hard drives | No |
| iDesktop | U | idesktop.exe | Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse | No |
| Detect | U | idetect.exe | iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled | No |
| idfxauds | X | idfxauds.exe | Detected by McAfee as W32/Ramnit.a. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| ToPicks Starter | X | Idhost.exe | ToPicks adware | No |
| IDM | X | IDM.exe | Detected by Dr.Web as Trojan.Inject1.14260 and by Malwarebytes Anti-Malware as Trojan.Agent.BCM | No |
| ce034ed846a59de9fb1d175d940837e8 | X | IDMan.exe | Detected by Dr.Web as Trojan.DownLoader7.20094 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| IDMan | N | IDMan.exe | Internet Download Manager - download files faster, schedule and resume | No |
| Internet download manager service | X | idman.exe | Added by the RBOT-BMS WORM! | No |
| IdnMail | X | IdnMail.exe | Detected by Malwarebytes Anti-Malware as PUP.CNNIC. The file is located in %System% | No |
| IDrive Tray | U | IDriveEReg2ini.exe | System Tray access to IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accounts | No |
| idriveServer | U | idriveProxy.exe | Proxy server for an older version of the IDrive backup utility from Pro Softnet Corporation | No |
| IDriveE Startup | U | IDrvieEStartup.exe | IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accounts. Required if you have scheduled backups | No |
| IDTemplates | X | IDTemplate.exe | Added by the BRONTOK-H WORM! | No |
| Tok-Cirrhatus | X | IDTemplate.exe | Added by the RONTOKBRO.A WORM! | No |
| Windows Service Agent | X | idvcqv.exe | Added by the AGOBOT-AJB WORM! | No |
| Idvmvu | X | Idvmvu.exe | Detected by McAfee as Generic PWS.bfr!c | No |
| IDrive Background process | U | idwbg_501.exe | Background process for an older version of the IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accounts | No |
| IDW Logging Tool | N | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems | No |
| IDrive Monitor | U | idwmonitor.exe | Monitor for an older version of the IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accounts | No |
| IndexCleaner | U | IdxClnR.exe | Utility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online | Yes |
| CCWC7I | U | idxl.exe | Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free | No |
| TGPro Office | N | IdxOffice.exe | With IdiomaX Office Translator "you can translate documents directly from your favorite text editor (Microsoft Word, WordPerfect or Lotus WordPro)" | No |
| syswin.txt | X | idz.exe | Added by the SDBOT.AGT WORM! | No |
| IE**.exe [* = random char] | X | IE**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| IE**32.exe [* = random char] | X | IE**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| 1b8e01fc029dc426f50dc397ed5ce576 | X | IE.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| 360saft | X | ie.exe | Detected by Sophos as Mal/PWS-CS and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft Internet Explorer Manager | X | ie.exe | Detected by Microsoft as Worm:Win32/Slenfbot.JD and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| IE | X | IE2012.exe | Detected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| ieLive | X | ie32.exe | Detected by Kaspersky as Trojan.Win32.Scar.cgsy | No |
| FBSSA | X | ie3sh.exe | Fast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more information | No |
| Olympic | X | IE4321.exe | Adult content premium rate dialer - also detected as SMALL.CZ | No |
| iExplore Ini | X | ie4uini.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| ieLive 512 | X | ie512.exe | Detected by Kaspersky as Trojan.Win32.Scar.cnlh | No |
| ieLive 512 | X | ie512b.exe | Detected by Kaspersky as Trojan.Win32.Scar.coot | No |
| Microsoft Internet Explorer | X | ie8.exe | Added by the BANKER-FBF TROJAN! | No |
| IE8 | X | IE8.pif | Detected by Sophos as Troj/Agent-ABSS and by Malwarebytes Anti-Malware as Trojan.Agent.PFI | No |
| ie8up | X | ie8update.exe | Detected by Dr.Web as Trojan.Siggen4.62713 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| antispy | X | ieav.exe | IE AntiVirus rogue security software - not recommended, removal instructions here | No |
| kokv | X | iebar.exe | DesktopMedia A adware | No |
| IECleanAux | U | Ieboot6.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup | No |
| Ahst | X | iebs.exe | PurityScan adware | No |
| start | X | iebtm.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details | No |
| IECache | X | IECache.exe | Detected by Bitdefender as the DELF.OFC TROJAN! See here | No |
| iecheck | N | iecheck.exe | Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 | No |
| iedll | X | iedll.exe | Homepage hijacker, redirecting to coolwwwsearch.com | No |
| IE Doctor | U | IEDoctor.exe | IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" | No |
| IEDriver | X | IEDriver.exe | IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze | No |
| Microsoft | X | iedw.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System%\internet explorer | No |
| Policies | X | iedw.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\internet explorer | No |
| iedwa104 | X | iedwa104.exe | Added by the DLOADR-BBW TROJAN! | No |
| Config Loadation | X | iEEexplore.exe | Added by the SDBOT.H TROJAN! | No |
| IEengine | X | IEeng.exe | STARTPAG.AI TROJAN! | No |
| Microsoft IE Execute shell | X | IEExec.exe | Added by the ALADINZ.N TROJAN! | No |
| Internet Explorer6 | X | IEexplore.exe | Detected by Trend Micro as WORM_RBOT.AGC. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| IEexplorer AUpdate | X | IEexplore32.exe | Added by the RBOT-GRE WORM! | No |
| Miscrosoft Windows Explorer | X | IEEXPLORER.exe | Reported as the SDBOT.YX WORM! | No |
| IEFeatures | X | iefeatures.exe | Added by the POPMON.A TROJAN - also known as PopMonster adware | No |
| MSVersion | X | iefeaturesversion.exe | Detected by Trend Micro as TROJ_POPMON.A and by Malwarebytes Anti-Malware as Trojan.PopMon. Also known as PopMonster adware | No |
| iefix | X | iefix.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\iexplorer | No |
| IefxTray | X | IefxTray.exe | Added by the RILER-H TROJAN! | No |
| ieharv.exe | X | ieharv.exe | Detected by Sophos as Troj/Banker-HH | No |
| [various names] | X | iehelper.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Bakra | X | IEHost.EXE | Added by the MULTIDR-AH TROJAN! | No |
| IE Java Update | X | iejava.exe | Detected by Sophos as Troj/Agent-HD | No |
| FX | X | ieloader.exe | Added by the SMALL.RR TROJAN! | No |
| IE New Window Maximizer | U | iemaximizer.exe | IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows | No |
| chkdrv | X | iemon.exe | Detected by Symantec as the ADCLICKER TROJAN! | No |
| Internet Explorer | X | IEPLORE32.EXE | Added by the AGOBOT-CU WORM! | No |
| Drivers | X | ieplorer.exe | Detected by McAfee as Generic.bfr | No |
| Policies | X | ieplorer.exe | Detected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.Pgen | No |
| Softwares | X | ieplorer.exe | Detected by McAfee as Generic.bfr | No |
| kxswsoft | X | ierdfgh.exe | Added by the AUTORUN-AAT WORM! | No |
| Iesar | X | Iesar.exe | Browser hijacker - redirecting to an adult web page | No |
| IE-Security | X | iescan.exe | IE-Security rogue spyware remover - not recommended, removal instructions here | No |
| Iesearch.exe | X | Iesearch.exe | LookNSearch adware | No |
| MSN | X | iesec.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.34010 and by Malwarebytes Anti-Malware as Backdoor.Bot | No |
| Microsoft IT Update | X | IEserv.exe | Added by a variant of Win32/Rbot | No |
| IEServer | U | IEServer.exe | HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself | No |
| \IEService.exe | X | IEService.exe | FastFind adware variant | No |
| Winsock6 MIC driver | X | ieservicesupd.exe | Added by the SPYBOT.AFZ WORM! | No |
| [various names] | X | iesetupdll.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| iesetupi.exe | X | iesetupi.exe | Added by a variant of Win32/Rbot | No |
| BitDefender 2009 | Y | IEShow.exe | Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. This entry is from the 2009 versions. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
| BitDefender Antiphishing Helper | Y | IEShow.exe | Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
| IEShow | Y | IEShow.exe | Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor | Yes |
| IESide | X | IESide.exe | Detected by Dr.Web as Trojan.StartPage.48053 and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| NETWIRE | X | IESM.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.NW. The file is located in %AppData%\microsoft | No |
| IETab | X | IETab.exe | Detected by Dr.Web as Trojan.DownLoader6.33407 and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| ietsr | N | ietsr.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc | No |
| Ieudinit | X | ieudinit.exe /waitservice | Detected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate ieudinit.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers | No |
| Microsoft Internet Explorer Update | X | ieupdate.exe | Added by the SHEUR.MH TROJAN! | No |
| window2 | X | ieupdate.exe | Added by the FORBOT-BM WORM! | No |
| ieupdate | X | ieupdates.exe | Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here | No |
| Policies | X | ieupdates.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note that this is not a valid Internet Explorer process and the file is located in %System%\IEupdates | No |
| Realtek HD Audio | X | ieupdates.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note that this is not a valid Realtek or Internet Explorer process and the file is located in %System%\IEupdates | No |
| IEAgent update check | X | iewatch.exe | Added by the BOMKA TROJAN! | No |
| Capricorn | X | iexeplore.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| 360saft | X | iexp.bat | Detected by Dr.Web as Trojan.AVKill.29649 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| fu | X | iexp1ore.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. Note the number "1" in place of a lower case "L" in the filename - which is located in %Windir% | No |
| iestart | X | iexp1orer.exe | Added by the NEMOG.C TROJAN! | No |
| SysRes | X | IExpIore .exe | Added by the ELITPER.E WORM! | No |
| Default web browser | X | IexpIore.exe | Added by the OBLIVION.B TROJAN! Note - do not confuse "iexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a capital "i" in place of lower case "L" | No |
| iexpiore.exe | X | iexpiore.exe | Detected by Dr.Web as Trojan.Click2.51385 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Internet Explorer | X | iexpiore.exe | Added by the RBOT-AZC WORM! | No |
| winprofile | X | iexpiore.exe | Added by a variant of the MONCHER WORM! | No |
| WinProfile | X | iexpIore.exe | Added by the CHUM-C TROJAN! | No |
| [random name] | X | iexpl0ra.exe | Detected by Trend Micro as TROJ_ULPM.BD | No |
| [empty] | X | iexpl0re.exe | Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field | No |
| Configuration Loader | X | IEXPL0RE.EXE | Added by the SDBOT BACKDOOR! Note the number "0" in the filename | No |
| hri | X | iexpl0re.exe | Added by the DLOADER.MAQ TROJAN! Note the number "0" in the filename | No |
| Micrsoft Internet Explorer | X | IEXPL0RE.EXE | Added by the RBOT-AQV WORM! Note the number "0" in the filename | No |
| myMh2 | X | iexpl0re.exe | Added by the AGENT.HWE TROJAN! Note the number "0" in the filename | No |
| ravshell | X | iexpl0re.exe | Added by the NOFERE-A TROJAN! Note the number "0" in the filename | No |
| ravtask | X | iexpl0re.exe | Added by the AGENT.AIR BACKDOOR! Note the number "0" in the filename | No |
| System | X | IEXPL0RE.EXE | Added by the VB.KS WORM! Note the number "0" in the filename | No |
| WinStar | X | IEXPL0RE.exe | Added by the WOSRIST A TROJAN! | No |
| IEXPL0RER | X | IEXPL0RER.EXE | Added by the AGOBOT-QL WORM! Note the filename has a "0" rather than an upper case "o" | No |
| supdate | X | IEXPL0RER.exe | Detected by McAfee as Generic Flooder!bu. Note the filename has a number "0" rather than an upper case "o" | No |
| Windows service | X | iexpl0rer.exe | Detected by Trend Micro as WORM_SDBOT.RO | No |
| @ | X | iexpl0res.exe | Detected by Trend Micro as WORM_RBOT.AEX | No |
| Antivirus | X | iexpl0res.exe | Added by an unidentified WORM or TROJAN! | No |
| Iexploit | X | Iexploit.html | Added by the INKER.B WORM! | No |
| Services | X | iexploler.exe | Added by the RANCK-LT TROJAN! | No |
| AtxBrw | X | Iexplor.exe | "Pop Marketing" adware | No |
| C:\WINDOWS\IEXPLOR.EXE | X | IEXPLOR.EXE | "Pop Marketing" adware | No |
| iexplo | X | iexplor.exe | Added by the SIDEA TROJAN! | No |
| iexplor.exe | X | iexplor.exe | Added by an unidentified WORM or TROJAN! See here | No |
| winsockdriver | X | iexplor.exe | Added by the BLATIC.A WORM! | No |
| IExplorer | X | Iexplor32.exe | Detected by Sophos as Troj/Bdoor-BY and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Macromedia Drive | X | Iexplor32.exe | Added by a variant of Win32/Rbot | No |
| (Default) | X | iexplorar.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System% | No |
| l44sys** | X | iexplore | Added by the VBS.LIDO WORM - where ** is a number between 65 and 76 | No |
| mssysint | X | Iexplore .exe | Detected by Symantec as Infostealer.ABCHlp and by Malwarebytes Anti-Malware as Backdoor.Agent.MINS. Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" | No |
| Protection | X | IExplore .exe | Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" | No |
| Winsock2 driver | X | IEXPLORE .EXE | Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" | No |
| $WindowsRegKey%update | X | IEXPLORE.EXE | Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| 488596faa0c68c3088c3447571a95cbd | X | iexplore.exe | Detected by Dr.Web as Trojan.Siggen4.12852 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| cmssapp | X | iexplore.exe | Detected by Sophos as Troj/Bancban-GF. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Configuration Loader | X | IEXPLORE.EXE | Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Explorer Updater | X | IEXPLORE.exe | Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| IE Security Loader | X | iexplore.exe | Detected by Trend Micro as BKDR_WOOTBOT.I. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| iexplore | X | iexplore.exe | Detected by Sophos as Troj/Banker-BWE. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| IExplore | X | IEXPLORE.EXE | Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a "Custom" subfolder | No |
| Iexplore | X | iexplore.exe | Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| IEXPLORE | X | iexplore.exe | Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Iexplore Services | X | iexplore.exe | Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! | No |
| Iexplore.exe | X | Iexplore.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft\System\Services | No |
| Intel? | X | iexplore.exe | Detected by Dr.Web as Trojan.Siggen5.23631 and by Malwarebytes Anti-Malware as Backdoor.Agent.ITN. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AllUsersProfile%\kernel64 | No |
| Internet Explorer | X | IEXPLORE.EXE | Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Internet Explorer Configuration | X | IEXPLORE.EXE | Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Internet Explorer6.0 | X | IEXPLORE.EXE | Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Intespention | X | IEXPLORE.exe | Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Java Runtimes | X | iexplore.exe | Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in %Windir%\Java\Java | No |
| Microsoft | X | iexplore.exe | Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Microsoft IE | X | Iexplore.exe | Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Microsoft Internet Explorer | X | iexplore.exe | Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Microsoft Windows (D) | X | iexplore.exe | Identified as a variant of the TrojanSpy.Agent malware | No |
| Microsoft© | X | iexplore.exe | Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache | No |
| msmsgs.exe | X | IEXPLORE.EXE | Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| nternet Explorer | X | iexplore.exe | Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| OPTIMIZER | X | iexplore.exe | Added by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| OPTIMIZER | X | iexplore.exe | Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Program in Windows | X | IEXPLORE.exe | Added by the LOVGATE.AB WORM! | No |
| Services | X | iexplore.exe | Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Setup Windows Media Player | X | iexplore.exe | Detected by Dr.Web as Trojan.DownLoader7.32087 and by Malwarebytes Anti-Malware as Trojan.Agent.SWM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Shell32 | X | iexplore.exe | Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| ShellRun32 | X | iexplore.exe | Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| slide | X | Iexplore.exe | Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! | No |
| starter | X | iexplore.exe | Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| System Configuration | X | iexplore.exe | Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| System Information Manager | X | iexplore.exe | Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Telephony Provider | X | Iexplore.exe | Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| windows | X | iexplore.exe | Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Windows Configuration System | X | IExplore.exe | Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| windows Live Messenger | X | iexplore.exe | Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Services | X | iexplore.exe | Detected by Sophos as W32/Rbot-WE and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| WINDOWS SYSTEM CLEANER | X | iexplore.exe | Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Windows USB Control Driver | X | iexplore.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Vista Transformation | X | IEXPLORE.exe | Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| WindowsUpdate renew | X | iexplore.exe | Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Zonealarm | X | iexplore.exe | Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% | No |
| Configuration Loadr | X | iexplore.exee | Added by an unidentified WORM or TROJAN! | No |
| Internet Explorer Security | X | iexplore.pif | Added by the RBOT-ALQ WORM! | No |
| IELoader32 | X | iexplore32.exe | Added by the SPEX or SPEX.B WORMS! | No |
| InternetExplorer32 | X | iexplore32.exe | Added by the RBOT-GRA WORM! | No |
| IExplorer6 Java Scripting | X | IExplore326.exe | Added by the RBOT.ANR WORM! | No |
| IExplorer7 Java Scripting | X | IExplore327.exe | Added by a variant of W32/Sdbot.worm | No |
| IExplorer32 Java Scripting | X | IExplore32b.exe | Detected by Trend Micro as WORM_RBOT.ABO | No |
| IExplorer32c Java Scripting | X | IExplore32cb.exe | Detected by Trend Micro as WORM_RBOT.ABN | No |
| IExplorer8 Java Scripting | X | IExplore8.exe | Detected by Trend Micro as WORM_RBOT.CAG and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Configuration Loaded | X | iexploree.exe | Added by the SDBOT-KC WORM! | No |
| iexplorenet | X | iexplorenet.exe | Detected by Dr.Web as Trojan.AVKill.22042 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| ALG.EXE | X | iexplorer .exe | Added by the DEMOTRY-B WORM! | No |
| IESet | X | IExplorer.dll | Added by the PWS-BLUEDIT TROJAN! | No |
| (Default) | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% and this is not the legitimate Internet Explorer (iexplore.exe). Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| (Default) | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %System% and this is not the legitimate Internet Explorer (iexplore.exe). Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| *iexplorer | X | iexplorer.exe | Detected by McAfee as BackDoor-AWQ.d. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir% | No |
| .netshrink | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| HKCU | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet Explorer | No |
| HKCU | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\install | No |
| HKCU | X | iexplorer.exe | Detected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet Explorer | No |
| HKCU | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\install | No |
| HKLM | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet Explorer | No |
| HKLM | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\install | No |
| HKLM | X | iexplorer.exe | Detected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet Explorer | No |
| HKLM | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\install | No |
| IE Security Loader | X | iexplorer.exe | Added by a variant of BKDR_WOOTBOT.I. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System% | No |
| IExplorer | X | IExplorer.EXE | Detected by Sophos as Troj/Bancos-CH and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles% | No |
| Iexplorer | X | iexplorer.exe | Detected by Dr.Web as Trojan.PWS.Siggen.41334 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System% | No |
| iexplorer | X | iexplorer.exe | Detected by McAfee as BackDoor-AWQ.d and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir% | No |
| iexplorer lptt01 | X | iexplorer.exe | RapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| iexplorer ml097e | X | iexplorer.exe | RapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| iexplorer.exe | X | iexplorer.exe | Detected by McAfee as RDN/Generic.dx!ba. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file is located in %AppData%\eniMbuPhc\SxGHFKvov\4.18.47.9562 | No |
| Iexplorer.exe | X | Iexplorer.exe | Detected by Sophos as Troj/Bancban-EN. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file is located in %Windir% | No |
| Internet Explorer | X | IExplorer.exe | Detected by Sophos as Troj/Nethief-O. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file loads from %System% via the HKLM\Run registry key | No |
| Internet Explorer | X | iexplorer.exe | Detected by Symantec as W32.Lorsis.Worm. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file loads from %Windir%\System via the HKLM\RunServices registry key | No |
| Internet Explorer Agent | X | iexplorer.exe | Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Internet Explorer Updater | X | iexplorer.exe | Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| irwftp | X | iexplorer.exe | Detected by Sophos as Troj/Banker-AN. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| kernel32sys.dll | X | IEXPLORER.exe | Detected by Sophos as W32/Rbot-MK. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| MAUDIO | X | iexplorer.exe | Detected by McAfee as BackDoor-CZP.dr and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir% | No |
| Media Player | X | iexplorer.exe | Detected by Trend Micro as TSPY_BANKER.MW. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Microsoft Associates, Inc. | X | iexplorer.exe | Added by the LOVGATE.Z WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Microsoft Inc. | X | iexplorer.exe | Detected by Trend Micro as WORM_LOVGATE.E. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Microsoft Internet Explorer | X | iexplorer.exe | Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Microsoft Windows Explorer | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MWF.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Msn Messenge | X | IExplorer.exe | Added by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| MSN Messenger | X | IExplorer.exe | Detected by Sophos as Troj/Banker-FB. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| msq | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.Dropper.OL. The file is located in %System% and this is not the legitimate Internet Explorer (iexplore.exe) | No |
| PCMONITOR | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.QHost.WNT. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir% | No |
| Policies | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet Explorer | No |
| Policies | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\install | No |
| Policies | X | iexplorer.exe | Detected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet Explorer | No |
| Policies | X | iexplorer.exe | Detected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\install | No |
| Ravshell | X | IEXPLORER.EXE | Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Services | X | iexplorer.exe | Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| SxGHFKvov | X | iexplorer.exe | Detected by McAfee as RDN/Generic.dx!ba and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| syscheck | X | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| sysconfig | X | iexplorer.exe | Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Windows Backup Configuration | X | IEXPLORER.exe | Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Windows Explorer | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %UserProfile%\msdata | No |
| Windows Internet Explorer | X | iexplorer.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Windows Taskmanager | X | iexplorer.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Windows UDP Control Center | X | iexplorer.exe | Added by the POISON-CJ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| winnt DNS ident | X | iexplorer.exe | Added by a variant of Win32/Rbot. Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| WINTASK | X | iexplorer.exe | Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| WinVNC | X | iexplorer.exe | Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Yahoo Messengger | X | IEXPLORER.exe | Added by the AUTORUN-BDN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Microsoft Inc. | X | iexplorer.exe... | Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) | No |
| Name | X | Iexplorer0.exe | Added by the THREADSYS TROJAN! | No |
| Microsoft Dev | X | iexplorer32.exe | Added by a variant of the AGOBOT WORM! | No |
| Microsoft Driver Setup | X | iexplorer7.exe | Detected by Avira as Worm/Pushbot.7577 | No |
| iexplorere loader | X | iexplorere.exe | Added by the SDBOT.SS WORM! | No |
| Windows Update | X | iexplorere.exe | Detected by Symantec as W32.HLLW.Gaobot.AP and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Iexplorerr.exe | X | Iexplorerr.exe | Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf | No |
| Iexplorerr.exe | X | Iexplorerr.exe | Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs | No |
| Windows Updater | X | iexplorerrs.exe | Detected by Sophos as W32/Rbot-TN and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| iexplorers loader | X | iexplorers.exe | Added by the SDBOT-DQ BACKDOOR! | No |
| Yahoo Messengger | X | IEXPLORERS.exe | Added by the AUTOIT.DH TROJAN! | No |
| Microsoft Machine Script | X | iexplorersis.exe | Added by the RBOT-CMH WORM! | No |
| Start Upping | X | iexplorerupdt.exe | Added by the RBOT-RR WORM! | No |
| Update Explorer | X | iexploreupd.exe | Added by a variant of Win32/Rbot | No |
| cmssapp | X | iexplore_.exe | Detected by Sophos as Troj/Bancban-CQ | No |
| Debugger | X | iexplore_dbg.exe | Added by the CWS-M TROJAN! | No |
| IExplUpd | X | IExplUpd.exe | Added by the MDROP-CXY TROJAN! | No |
| Services | X | iexpolere.exe | Added by the RANCK.LU TROJAN! | No |
| MSStartOptimizer | X | IEXPRES.EXE | Detected by Sophos as Troj/Dasmin-Fam | No |
| iExpresser | X | iexpresser.exe | Added by the SLENFBOT.AP WORM! | No |
| MSIME | X | iexprohlp.exe | Added by the MDROP-CVV TROJAN! | No |
| Microsoft Opeions | X | IEXwe.exe | Added by a variant of Win32/Rbot | No |
| bantool | X | ie_ban.exe | Detected as the VB.PO TROJAN! | No |
| signup | X | ie_signup.exe | Detected by Kaspersky as Trojan.Win32.Agent.suub and by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %AppData%\signup | No |
| IExplorer Util | X | ie_util.exe | Detected by Dr.Web as Trojan.Inject1.13820 and by Malwarebytes Anti-Malware as Trojan.Ransom.BLK | No |
| (Default) | X | ifconfig.exe | Added by the RBOT-GFW WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run, HKLM\RunServices and HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| Adobe ARM | X | ifgxpers.exe | Detected by Dr.Web as BackDoor.Gbot.2374 and by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this is not the legitimate Adobe update manager (AbodeARM.exe). The file is located in %AppData% | No |
| Adobe ARM | X | ifgxpers.exe | Detected by Sophos as Troj/Tobfy-C and by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this is not the legitimate Adobe update manager (AbodeARM.exe). The file is located in %CommonAppData% | No |
| LmihNjzSczsUOFeQZJkVKCBFoz | X | ifkf_mfLEnWa_g.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent.PLR. Note - this entry loads from %System% via the HKCU\Run registry key | No |
| LmihNjzSczsUOFeQZJkVKCBFoz | X | ifkf_mfLEnWa_g.exe | Detected by McAfee as RDN/Generic.bfr!g and by Malwarebytes Anti-Malware as Trojan.Agent.RND. Note - this entry loads from %System% via the HKCU\Policies\Explorer\Run registry key | No |
| IPKRun | X | Ifkmain.exe | IPKRun rogue security software - not recommended, removal instructions here | No |
| iFrmewrk | Y | ifrmewrk.exe | Intel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display" | Yes |
| Intel(R) PROSet/Wireless | Y | ifrmewrk.exe | Intel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display" | Yes |
| IntelPAN | Y | iFrmewrk.exe | Intel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display" | No |
| IntelPROSet | Y | iFrmewrk.exe | Intel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display" | No |
| IntelWireless | Y | ifrmewrk.exe | Intel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display" | Yes |
| IFSplash.exe | U | IFSplash.exe | I-FORCE driver for force feedback steering wheel | No |
| IFXSPMGT | U | ifxspmgt.exe | Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer, ASUS, HP and Sony | No |
| Microsoft Values | X | igfkishc.exe | Added by the RBOT-GLO WORM! | No |
| f78ab46e149d2ce1a6b721640ed25616 | X | igfsystem.exe | Detected by McAfee as RDN/Generic.dx!bcj and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Intel Software Update | X | igfxau64.exe | Detected by Dr.Web as Win32.HLLW.Autoruner1.25469 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Intel iDisplay Core | X | igfxbj32.exe | Detected by Dr.Web as BackDoor.IRC.Bot.1818 | No |
| Intel Display Control | X | igfxdc64.exe | Detected by Malwarebytes Anti-Malware as Trojan.Fakeintel. The file is located in %System% | No |
| Intel Display Control | X | igfxdc64.exe | Detected by Malwarebytes Anti-Malware as Trojan.Fakeintel. The file is located in %UserProfile%\Network | No |
| Policies | X | igfxhost.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\Index | No |
| Intel iDevice Driver | X | igfxks32.exe | Detected by Dr.Web as BackDoor.IRC.Bot.1819 | No |
| Intel Driver Manager | X | igfxpd86.exe | Detected by Dr.Web as BackDoor.IRC.Bot.1536 | No |
| cmstrp | X | igfxperf.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\Microsoft | No |
| ctrlmestartup | X | igfxperf.exe | Detected by Malwarebytes Anti-Malware as Trojan.Fakealert. The file is located in %AppData%\Microsoft | No |
| igfxpers | U | igfxpers.exe | Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" status | Yes |
| Intel(R) Common User Interface | U | igfxpers.exe | Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" status | Yes |
| Persistence | U | igfxpers.exe | Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" status | Yes |
| RegistryMonitor1 | X | igfxpers.exe | Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename | No |
| hurggbesyt | X | igfxrptgx.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
| lgxfsrvc | X | igfxsrvc.exe | Added by the AUTORUN-BPQ WORM! | No |
| MicroSoft Visual SP2 | X | igfxsrvc32.exe | Detected by Trend Micro as WORM_SDBOT.GAV. The file is located in %System% | No |
| Intel Task Management | X | igfxtm32.exe | Added by the KOLAB.WWH WORM! | No |
| premium | X | igfxtrai.exe | Added by the DLOADR-DDX TROJAN! | No |
| igfxtray | X | igfxtray.exe | Detected by McAfee as BackDoor-EZG.d and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %AppData%\igfx | No |
| IgfxTray | U | igfxtray.exe | System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and hot key settings via the icon on the System Tray. Different chipset versions may have different options available. These options are normally also available via the system Control Panel - under Display (XP) or Personalization and Appearance (Vista) | Yes |
| igfxtray | X | igfxtray.exe | Detected by Dr.Web as Trojan.Carberp.33 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| igfxtray Module | X | igfxtray.exe | Added by the VB-RI MALWARE! Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %Windir% | No |
| Intel Cprporation | X | igfxtray.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %ProgramFiles%\igfxtray | No |
| Intel(R) Common User Interface | U | igfxtray.exe | System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and hot key settings via the icon on the System Tray. Different chipset versions may have different options available. These options are normally also available via the system Control Panel - under Display (XP) or Personalization and Appearance (Vista) | Yes |
| WUPD | X | iglmtray.exe | Added by the TZET WORM! | No |
| Iglpbv | ? | Iglpbv.exe | ?? | No |
| MS WINS Binary | X | ign32.pif | Added by the RBOT-ASB WORM! | No |
| mnu | ? | igomnu.exe | Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required? | No |
| lspins | X | igps.exe | Detected by Kaspersky as the VB.KC TROJAN! | No |
| igsex2x | X | igsex2x.exe | NewDial premium rate adult content dialler | No |
| IGuardPc.exe | X | IGuardPc.exe | IGuardPc rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| MicroSoft Visual SP | X | igxdfdfds.com | Added by the SDBOT.GAV WORM! | No |
| Ncua | X | ihoo.exe | PurityScan adware | No |
| iHP-100 | ? | iHPDetect.exe | Drive Letter Searcher, iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time? | No |
| Net iD | U | iid.exe | "With the Net_iD program, you can easily and securely logon with a smart card into a domain, a virtual private network (VPN) or in Citrix and Terminal Server environments" | No |
| Microsoft | X | iiexplore.exe | Detected by Trend Micro as WORM_SDBOT.TE | No |
| Microsoft Internet Exp | X | iiexplorer.exe | Added by the RBOT-KX WORM! | No |
| Navegate | X | iiexplorer.exe | Added by the BANCBAN-OP TROJAN! | No |
| iilc | X | IILC.EXE | Homepage hijacker | No |
| MSConfig | X | iirqcobd.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| Intel system works | X | iis.exe | Added by the RBOT.QGA WORM! | No |
| gtydf | X | iisca.exe | Added by the CLAGGER-BB TROJAN! | No |
| iisvers | X | iisvers.exe | Added by unidentified malware. The file is located in %Windir% | No |
| IJ75P2PSERVER | Y | IJ75P2PS.EXE | Printer utility which is required in order to make the printer work correctly | No |
| IKE Service 95 | Y | IKEService.exe | Associated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything | No |
| IBM Keyboard Driver | X | ikeybdrv.exe | Added by the SDBOT.IC BACKDOOR! | No |
| iKeyWorks | U | Ikeymain.exe | A4Tech wireless keyboard driver and utility | No |
| Attacher | X | Ikhwan.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AT. The file is located in %System% | No |
| Iknhxbthwzltaibx.exe | X | Iknhxbthwzltaibx.exe | Detected by Malwarebytes Anti-Malware as Trojan.PWS.IRCBot. The file is located in %AppData% | No |
| iLeAAmvQHHaC | X | iLeAAmvQHHaC.exe | Added by the FAKEAV-DIN TROJAN! | No |
| boy lovers of bsd | X | ilikeboys.exe | Detected by Trend Micro as WORM_MYTOB.LY | No |
| iLike | N | ilikesidebar.exe | iLike Sidebar for iTunes and Windows Media Player | No |
| goolgeiLive.exe | X | iLive.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\exiplores | No |
| msng | X | iLive.exe | Detected by Malwarebytes Anti-Malware as Spyware.Banker. The file is located in %Root%\winx32 | No |
| reluvage | X | ilulupac.exe | Added by the SDBOT-UJ WORM! | No |
| iLyric | U | iLyric.exe | iLyric plugin for the popular Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button. Not longer available | No |
| IMprocess | X | IM-svr.EXE | IMNames adware | No |
| AIM AutoRun | X | IM.exe | Detected by McAfee as Generic StartPage!bgl and by Malwarebytes Anti-Malware as Trojan.VBAgent. Note - this entry has nothing to do with the AOL Instant Messenger (AIM) | No |
| ISS | X | im.exe | Detected by McAfee as PWS-Zbot-FAJX!98E04F0440D9 and by Malwarebytes Anti-Malware as Trojan.Agent.SI | No |
| Office Desktops | X | imag.exe | Added by the SPYBOT.AQR WORM! | No |
| 78ee591d3d1cea63061844894185d677 | X | image .exe | Detected by Dr.Web as Trojan.DownLoader8.30090 and by Malwarebytes Anti-Malware as Trojan.Agent.PEC | No |
| ff70ef8c4d237338eda652592ce24d91 | X | image.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Image & Restore | Y | IMAGE32.exe | Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run | No |
| ImageDrive-{hex numbers} | U | ImageDrive.exe | Nero ImageDrive from Ahead - virtual CD/DVD drive software | No |
| Imagefox | U | imagefox.exe | ImageFox 2.0 (formerly available from ACDSee) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes | No |
| Imagemgt32 | X | Imagemgt32.exe | Added by the GEMA TROJAN! | No |
| ImageViewer | X | ImageViewer.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Imatio | U | imation.exe | Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive | No |
| imchat | X | imchat.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Microsoft Update | X | imchemaoa.exe | Added by the BANLOAD.KWQ TROJAN! | No |
| HKCU | X | IMD.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\HM - see here | No |
| HKLM | X | IMD.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\HM - see here | No |
| Policies | X | IMD.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %AppData%\HM - see here | No |
| 123456 | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMIN | No |
| [various names] | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file can be located in a "DCSCMIN" sub-folder in a number of locations including (but not limited to) %System%, %MyDocuments%, %Temp% & %AppData% | No |
| Adobe_ARM | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserTemp%\DCSCMIN | No |
| Cleaner | X | IMDCSC.exe | Detected by McAfee as Generic BackDoor!fcw and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| DarkComet RAT | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file can be located in a "DCSCMIN" sub-folder in a number of locations including (but not limited to) %System%, %MyDocuments%, %Temp% & %AppData% | No |
| ekbfjzefbgjh | X | IMDCSC.exe | Detected by Dr.Web as Trojan.DownLoader6.995 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| IMDCSC.exe | X | IMDCSC.exe | Detected by Dr.Web as Trojan.DownLoader6.59147 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMIN | No |
| IMDCSC.exe | X | IMDCSC.exe | Detected by Dr.Web as Trojan.DownLoader7.22053 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserProfile%\Desktop\DCSCMIN | No |
| Img Codec | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserTemp%\DCSCMIN | No |
| JavaUpdate | X | IMDCSC.exe | Detected by Dr.Web as Trojan.Inject1.1577 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| JavaUpdater | X | IMDCSC.exe | Detected by Dr.Web as Trojan.Inject1.1573 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| King Alux | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMIN | No |
| Microsoft | X | IMDCSC.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Net | X | IMDCSC.exe | Detected by Dr.Web as Trojan.DownLoader6.40541 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Soundman | X | IMDCSC.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMIN | No |
| SYST32 | X | IMDCSC.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| system411 | X | IMDCSC.exe | Detected by Dr.Web as Trojan.DownLoader7.22053 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Team | X | IMDCSC.exe | Detected by McAfee as Generic BackDoor!fq3 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Team Crackers | X | IMDCSC.exe | Detected by McAfee as PWS-FAHB!90FB97AF0885 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Windefender | X | IMDCSC.exe | Detected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| WWWin | X | IMDCSC.exe | Detected by Symantec as Trojan.Klovbot and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| SYSDATAKEY | X | IMDCSVC.exe | Detected by McAfee as Generic BackDoor!fpx and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGen | No |
| IMEJPDADM | X | imejpdadm.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\MicrosoftLive | No |
| imekrmig | N | imekrmig.exe | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | No |
| IMEKRMIG6.1 | N | IMEKRMIG.EXE | Microsoft's Input Method Editor for the Korean language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | No |
| Imesh | N | iMesh.exe | Imesh peer-to-peer (P2P) file-sharing client. As large amounts of data is shared between multiple users make sure you have good, up-to-date virus protection and check any downloads | No |
| IMEvtMgr.exe | X | IMEvtMgr.exe | Added by the KEYLOG-AR TROJAN! | No |
| (Default) | X | IMF.exe | Detected by Dr.Web as Trojan.DownLoader7.12453 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %UserStartup% | No |
| IMF | X | IMF.exe | Detected by Dr.Web as Trojan.DownLoader7.12453 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| IObit Malware Fighter | U | IMF.exe | IObit Malware Fighter optimization utility from IObit - "is an advanced malware & spyware removal utility that detects, removes the deepest infections, and protects your PC from various potential spyware, adware, trojans, keyloggers, bots, worms, and hijackers." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | No |
| ImgIcon | U | ImgIcon.exe | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running | No |
| Iomega Disk Icons | U | imgicon.exe | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running | No |
| Iomega Drive Icons | U | ImgIcon.exe | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running | No |
| Zip Disk Icons | U | IMGICON.exe | Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running | No |
| GlobalFlagimglog | X | imglog.exe | Detected by Sophos as Troj/Agent-GYK | No |
| dark | X | imgrt.scr | Detected by Sophos as Troj/Bancban-FH and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Audio THXHD | X | imgsafe.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.BCM. The file is located in %AppData%\Tviewer | No |
| dark | X | imgst.scr | Detected by Symantec as Infostealer.Bancos.U and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| ImgStart | N | ImgStart.exe | Used by Iomega drives. Details of its purpose can be found here. Available via Start → Programs | No |
| Iomega Startup Options | N | ImgStart.exe | Used by Iomega drives. Details of its purpose can be found here. Available via Start → Programs | No |
| ImgTask | N | Imgtask.exe | Related to the WalletPix digital photo album. "On some computers, the Wallet Pix device will leave behind a memory-resident file called ImgTask.exe. This file will be located in the operating system directory on your computer (typically %Windir%). You can remove this file at any time and it will not impact your computer's performance or functionality. The file will be restored each time you plug in the Wallet Pix though" | No |
| Iomega ImIconXP | U | imiconxp.exe | Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks | No |
| IMIIcon | X | IMIIcon.exe | Detected by McAfee as FakeAV-N.bfr | No |
| Strings | X | IMJDC01.exe | Detected by Dr.Web as Trojan.Inject1.18505 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| IMJPMIG | U | IMJPMIG.EXE | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| IMJPMIG8.1 | U | IMJPMIG.EXE | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| IMJPMIG9.0 | U | IMJPMIG.EXE | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | No |
| Microsoft IME 2002 | U | IMJPMIG.EXE | Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| Protocol Component | X | immcceng.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PCGen. The file is located in %System% | No |
| immcheck.exe | ? | immcheck.exe | Related to I-FORCE driver for force feedback steering wheel? | No |
| LogonAdministrator | X | imoet.exe | Added by the RAHIWI.A WORM! | No |
| WinLive | X | imol.exe | Detected by Dr.Web as Trojan.PWS.Banker1.3973 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| WinLive | X | imola.exe | Detected by Kaspersky as Trojan.Win32.Scar.bsjj | No |
| IMOL | U | IMOLApp.exe | IncrediMail for Office Outlook Add-On | No |
| WinLiveMsn | X | imolav.exe | Detected by Kaspersky as Trojan.Win32.Scar.crgg | No |
| Remote Update Monitor | Y | imonitor.exe | Remote Update utility for older versions of Sophos antivirus products which provided an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer | No |
| IMONTRAY | U | imontray.exe | System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards | No |
| Intel Active Monitor | U | imontray.exe | System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards | No |
| imPlayok | X | imPlayok.exe | Detected by McAfee as Cutwail.gen.o | No |
| Impulse Dock | N | ImpulseDock.exe | Older version of the Impulse digital distribution platform from Stardock Corporation | No |
| Impulse Now | N | ImpulseNow.exe | System Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the Windows Defender entry | Yes |
| ImpulseNow | N | ImpulseNow.exe | System Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation | Yes |
| Impulse Now | N | IMPULS~1.EXE | System Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the Vista/7 MSConfig entry | Yes |
| ImpulseNow | N | IMPULS~1.EXE | System Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the XP MSConfig entry | Yes |
| ImScInst | U | ImScInst.exe | Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| ImScInst.exe | U | ImScInst.exe | Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| MSPY2002 | U | ImScInst.exe | Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control Panel | Yes |
| IMSCMig | U | IMSCMIG.EXE | Associated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc) | No |
| imscmig | X | imscmig.exe | Detected by McAfee as W32/Lurka.b. Note - do not confuse with the legitimate MS Input Method Editor entry which shares the same filename and is found in a sub-folder of %CommonFiles%\Microsoft%\IME - this one is found in %Windir% | No |
| IMSCMIG.exe | X | IMSCMIG.exe | Detected by Dr.Web as Trojan.Touch.321 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - do not confuse with the legitimate MS Input Method Editor entry which shares the same filename and is found in a sub-folder of %CommonFiles%\Microsoft%\IME - this one is found in %System% | No |
| Microsoft Pinyin IME Migration | U | IMSCMIG.EXE | Associated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc) | No |
| Microsoft(R) Pinyin IME 2007 | U | IMSCMIG.EXE | Associated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc) | No |
| Instant Messenger Service | X | imservice.exe | Detected by Kaspersky as the HEUR TROJAN! | No |
| MSN Funny Images | X | imsngsr.exe | Added by the AGOBOT-TT WORM! | No |
| IMStart | U | IMStart.exe | InterMute security software related | No |
| Skype | X | Imvu.exe | Detected by Trend Micro as BKDR_DOKSTORMC.A. Note - this is not a legitimate entry for the popular Skype VOIP software | No |
| IMVU | U | IMVUClient.exe | IMVU chat client that allows you to create "your own avatars who chat in animated 3D scenes" | No |
| IMwire | X | imwireup.exe | Added by a variant of Spyware.SafeSurfing | No |
| im_autorn | X | im_1.exe | Added by the IMAV.A WORM! | No |
| im_autorn | X | im_2.exe | Detected by Sophos as Troj/BagleDl-BO | No |
| iM Start Center | N | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start → Programs → iM Networks → iM Radio Tuner | No |
| Ahead Software AG InCD | Y | InCD.exe | InCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable it | Yes |
| InCD | Y | InCD.exe | InCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable it | Yes |
| Nero AG InCD | Y | InCD.exe | InCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable it | Yes |
| Tyig.exe | X | Incdop.exe | Detected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %AppData% | No |
| IncMail | N | IncMail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" | No |
| Incredimail | N | IncMail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" | No |
| incognito | X | incognito.exe | Added by an unidentified WORM or TROJAN! See here | No |
| RegistryMonitor1 | X | incognito.exe | Added by the BUZUS.DAHY TROJAN! | No |
| Incredimail | N | incredimail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" | No |
| MRUBlaster | U | indexcleaner.exe | MRU-Blaster from Brightfort (formerly Javacool Software) - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder | No |
| IndexCleaner | U | IndexCleanerR.exe | Utility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online | No |
| Indexer | ? | Indexer.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required? | No |
| Indexindicator | X | Indexindicator.exe | Added by the LAZAR TROJAN! | No |
| IndexSearch | N | IndexSearch.exe | Part of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". Creates an index of files associated with PaperPort for easy searching | No |
| IndexTray | U | IndexTray.exe | Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" | No |
| Fujitsu Hotkey Utility | U | IndicatorUty.exe | Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed | No |
| IndicatorUty | U | IndicatorUty.exe | Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed | No |
| Country | X | Indonesian.com | Detected by Malwarebytes Anti-Malware as Worm.Agent.MLB. The file is located in %Windir%\fonts | No |
| IIS | X | inet.exe | Meplex adware | No |
| System64 | X | inet.exe | Added by the DENGLE-A TROJAN! | No |
| inetcntrl | U | inetcntrl.exe | Bsafe Online - internet filter | No |
| InetConf | ? | inetconf.exe | ?? | No |
| Inetd | U | INETD32.EXE | Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation | No |
| Inet DataBase | X | Inetdbs.exe | Added by the QEDS WORM! | No |
| Inet Delivery | X | inetdl.exe | Inet Delivery adware | No |
| Inet Delivery | X | inetdl_2.exe | Inet Delivery adware | No |
| Microsoft Internet Dumping Protocol | X | inetdump.exe | Added by the IRCBOT.BLL BACKDOOR! | No |
| Security Antivirus Xp 1 | X | inetfor.exe | Added by the SDBOT.BAV WORM! | No |
| MMicrosoft Security Management | X | inetforn.exe | Detected by Trend Micro as WORM_RBOT.AFZ | No |
| Windows Update | X | inetinf.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System% | No |
| inetinfo.exe | U | inetinfo.exe | Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) | No |
| load= | X | inetinfo.exe | Added by the PROXY-GG TROJAN! | No |
| run | X | inetinfo.exe | Added by the BINGHE TROJAN! | No |
| System | X | inetinfo.exe | Added by the PARDROP-A TROJAN! | No |
| svchost | X | inetinfo.scr | Added by the ODELUD WORM! | No |
| inetinfomon manager | X | inetinfomon.exe | Added by the DONBOMB.A TROJAN! | No |
| Microsoft System Checkup | X | inetman.exe | Added by the DONK.O WORM! | No |
| inetmgr | X | inetmgr.exe | ActualNames Internet Keywords parasite | No |
| inetrun | X | inetrun.exe | Added by the AGENT.CE BACKDOOR! | No |
| inetserv | X | inetserv.exe | Added by the AGENT-OWJ TROJAN! | No |
| Internet Server | X | inetsrv.exe | Added by the STARTPA-EM TROJAN! | No |
| User32 | X | inetsrv.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.USR. The file is located in %Root%\usrs\rb\Inf | No |
| Windows Live Update | X | inetsrv.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%\inetsrv | No |
| INET | X | inetsync.exe | Meplex adware | No |
| Microsoft Internet Syncing | X | inetsync.exe | Added by the IRCBOT.BLL BACKDOOR! | No |
| Compaq Internet Setup | N | inetwizard.exe | For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list | No |
| Bron-Spizaetus | X | inf31.exe | Added by the RONTOKBRO.M WORM! | No |
| Infdisk | X | infdisk.exe | Added by the CRYPTER.A TROJAN! | No |
| InfeStop | X | InfeStopRemover.exe | InfeStop rogue spyware remover - not recommended, removal instructions here | No |
| info | X | info.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\Windefender | No |
| run= | X | info32.exe | CoolWebSearch Tapicfg parasite variant | No |
| Info32x | X | Info32x.exe | Added by the GEMA TROJAN! | No |
| InfoBoan | X | InfoBoan.exe | InfoBoan rogue security software - not recommended, removal instructions here | No |
| Firewall Admin | X | infocard.exe | Added by the VBPIT-A MALWARE! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET%\Framework%\v3.0%\Windows Communication Foundation. This one is located in %Windir% | No |
| Firewall Administrating | X | infocard.exe | Added by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filename | No |
| Framework module library | X | infocard.exe | Added by the BUZUS.AYX TROJAN! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation. This one is located in %System% | No |
| infodataS | X | infodataU.exe | InfoData rogue security software - not recommended. One of the OneScan family of rogue scanner programs. Detected by Malwarebytes Anti-Malware as Adware.K.InfoData | No |
| Microsoft Update Machine | X | infoDLL.exe | Added by the RBOT-EH WORM! | No |
| Microsoft Special offer | X | infoebay.exe | Added by a variant of Win32/Rbot | No |
| infoguardr | X | infoguardrun.exe | InfoGuard rogue security software - not recommended, removal instructions here | No |
| infohelperS | X | infohelperU.exe | InfoHelper rogue security software - not recommended. One of the OneScan family of rogue scanner programs. Detected by Malwarebytes Anti-Malware as Adware.K.InfoHelper | No |
| MICROUPDATEINFO | X | InfoMicro.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\INFOMICRO | No |
| Getca | Y | InfoMyCa.exe | Monitor for a Belkin USB Wireless adapter | No |
| Microsoft Synchronization Manager | X | InfoNT.exe | Added by the SDBOT-TR BACKDOOR! | No |
| InfoPenMSN | U | InfoPenIM.exe | InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand | No |
| Infoplay.exe | ? | Infoplay.exe | Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed? | No |
| InfoPure | X | InfoPure.exe | InfoPure rogue security software - not recommended, removal instructions here | No |
| Information | X | Information.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| NVagent | X | Informe.exe | Detected by Symantec as W32.Vig.C | No |
| Symantec | X | Informe.exe | Detected by Symantec as W32.Vig.C | No |
| InfoSafe | X | InfoSafe.exe | InfoSafe rogue security software - not recommended, removal instructions here | No |
| InfoSave | X | InfoSave.exe | Detected by Malwarebytes Anti-Malware as Rogue.InfoSave. The file is located in %ProgramFiles%\Info-Save | No |
| InfoSeven | X | InfoSeven.exe | InfoSeven rogue security software - not recommended, removal instructions here | No |
| InfoShield4 | X | InfoShield4.exe | InfoShield4 rogue security software - not recommended, removal instructions here | No |
| InfoTab | X | infotab.exe | InfoTab adware | No |
| infus | X | infus.exe | Adult content dialler | No |
| Infuzer | U | Infuzer.exe | Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities" | No |
| infwin | X | infwin.exe | VX2.Transponder parasite updater/installer related | No |
| SCANINICIO | Y | Inicio.exe | Part of the range of internet security products from Panda Security - including Global Protection, Internet Security and Antivirus Pro. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time | No |
| Win32Config | X | inid.exe | Detected by Dr.Web as Trojan.DownLoader4.43527 and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| Windows | X | inid.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| iniservice | X | iniservice.exe | Detected by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %AppData% | No |
| Win_Library | X | INISvc.exe | Added by the ANARCH WORM! | No |
| MMC | X | inisys.exe | Added by the OSCABOT-I WORM! | No |
| init | X | init.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\Users\Public | No |
| Microsoft Update 33 | X | init.exe | Added by the RBOT-ATT WORM! | No |
| SessionInit | X | init.exe | Added by the FAKEAV-BRZ TROJAN! | No |
| TrojanShield | U | Init.exe | TrojanShield | No |
| Unix File Support | X | init3.exe | Added by the RBOT-ZN WORM! | No |
| [various names] | X | init32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Init32 | X | Init32.exe | Added by the WINEX.A TROJAN! | No |
| PC2X | X | initial.bat | Added by the DWNLDR-FZZ TROJAN! | No |
| AppletINIT | X | initiate.exe | Detected by Kaspersky as Backdoor.Win32.Agobot.xv | No |
| Windows Liver | X | initmail.exe | Detected by Microsoft as Trojan:MSIL/Gillver.A | No |
| Windows Liver | X | initmailer.exe | Detected by Microsoft as Trojan:MSIL/Gillver.A | No |
| Microsoft Initialization Services | X | initserv.exe | Added by the IRCBOT-ABO TROJAN! | No |
| Microsoft Initialization Service | X | initsvc.exe | Added by the IRCBOT.AXK BACKDOOR! | No |
| Windows Service Manager | X | initsvc.exe | Added by the RBOT-BWT WORM! | No |
| scheduler_monitor | U | init_scheduler.exe | Scheduler for ReaConverter advanced image converter | No |
| Naeron Injector | X | Injector.exe | Detected by Malwarebytes Anti-Malware as HackTool.Agent. The file is located in %System% | No |
| injob | X | injobs.exe | Added by the BINJO TROJAN! | No |
| Gateway Ink Monitor | N | InkMonitor.exe | Ink level monitor for Gateway branded printers | No |
| Ink Monitor | N | InkMonitor.exe | Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line | No |
| InkWatch | N | InkWatch.exe | Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line | No |
| InterMoni3 | X | InMonitor.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\intermoni3 | No |
| ATVY | X | INnM.exe | Detected by McAfee as Generic.dx!bhph and byMalwarebytes Anti-Malware as Trojan.Agent | No |
| InoRPC | Y | InoRpc.exe | Part of eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products | No |
| InoRT | Y | InoRT9x.exe | Real-time monitor for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products | No |
| InoTask | U | InoTask.exe | Scheduled scans and signature updates for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU usage when performing updates | No |
| HKCU | X | inpp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDir | No |
| HKLM | X | inpp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDir | No |
| [various names] | X | InpriseMon.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Inprivacy | X | Inprivacy.exe | Inprivacy rogue privacy program - not recommended, removal instructions here | No |
| InputDirector | U | InputDirector.exe | "Input Director is a Windows application that lets you control multiple Windows systems using the keyboard/mouse attached to one computer" | No |
| OutLooks | X | InSane.exe | Added by the SWOOP TROJAN! | No |
| insCOA5 | ? | insCOA5.exe | ?? | No |
| Boots Insert Detect | ? | InsDetect.exe | Part of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? | No |
| Dixons Insert Detect | ? | InsDetect.exe | Part of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? | No |
| Duane Reade Insert Detect | ? | InsDetect.exe | Part of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? | No |
| Jessops Insert Detect | ? | InsDetect.exe | Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? | No |
| Tesco Insert Detect | ? | InsDetect.exe | Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? | No |
| MicroUpdate | X | insdir.exe | Detected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\Inst | No |
| Windows Incontext | X | InSearch.exe | PacerD_Media/Pacimedia.com/Z-Quest adware installer | No |
| inshopping | X | inshoppingup.exe | Detected by Malwarebytes Anti-Malware as Adware.IEShow. The file is located in %ProgramFiles%\inshopping | No |
| Insider | X | Insider.exe | Added by the AGENT.KMC TROJAN! | No |
| [varies] | X | insidminer.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.BTCGen. The file is located in AppData%\[folder] - see examples here and here | No |
| Nielsen NetRatings | X | insight.exe | NetRatings Premeter spyware | No |
| InstaAlert | U | InstaAlert.exe | "Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly" | No |
| PCMagInstaback2 | U | InstaBack.exe | InstaBack 2 from PC Magazine - instant and automated backup utility | No |
| Instafinder | X | instafinder.exe | TopSearch.D adware | No |
| InstaFinderK | X | InstaFinderK_inst.exe | InstaFinder adware | No |
| [trojan filename] | X | Install.exe | Detected by Sophos as Troj/Bancban-FS | No |
| Adobe_Updater | X | Install.exe | Detected by Dr.Web as Trojan.MulDrop3.48888. Note - this is not the legitimate automatic updater for earlier versions of Adobe products whose filename is Adobe_Updater.exe and this file is located in %AppData%\Adobe | No |
| d4d09436d35da01cf69e37f8597d3266 | X | Install.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| Initial Page | X | install.exe | EasySearch browser hijack installer | No |
| Install | X | Install.exe | Detected by Sophos as Troj/Bancban-HG | No |
| Microsoft | X | install.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| MSN | X | install.exe | Added by the AGENT-GDO TROJAN! | No |
| MyVBApp | X | install.exe | Detected as Generic Downloader.s by McAfee, probable variant of ReferAd adware! | No |
| updata.exe | X | install.exe | Detected by Kaspersky as Trojan-Downloader.Win32.Agent.fxzi and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| UPDATE | X | Install.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Poison. The file is located in %System% | No |
| Windows Update | X | install.exe | Detected by Sophos as Troj/Banker-IB and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| BootCfg | X | Install.log.vbs | Added by the YPSAN.D WORM! | No |
| [various names] | X | install2.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| install32 | x | install32.exe | Added by the NUCLEAR.DG BACKDOOR! | No |
| InstallAurealDemos | N | InstallAurealDemos.js | Used to initialize the Aureal A3D demos InstallShield wizard | No |
| InstallCleaner | X | InstallCleaner.exe | Added by the ANYHOMB.F TROJAN! | No |
| Meteorite | X | installed.exe | Detected by Kaspersky as Net-Worm.Win32.Kolab.eav | No |
| AntivirusBEST | X | Installer.exe | Installer for the AntivirusBEST rogue security software - not recommended. Removal instructions here | No |
| trident | X | Installer.exe | Detected by McAfee as Generic.tfr!cf and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Windows UDP Control Center | X | installer.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| LogitechRegisterVideoApplications | Y | InstallHelper.exe | Entry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the software | Yes |
| LogitechVideo[inspector] | U | InstallHelper.exe | Entry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applications | Yes |
| Verizon Custom Uninstall Tracking | ? | InstallHelper.exe | Verizon related installation tracker. What does it do and is it required? | No |
| InstallIQUpdater | N | InstallIQUpdater.exe | Updater for InstallQ from W3i | No |
| InstallName | X | InstallName.exe | Detected by McAfee as Generic MSIL.v and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen | No |
| Microsoft Intell Management | X | Installs.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData% | No |
| Netscape | U | InstallService.exe | Related to Netscape installation | No |
| Installstub | U | installstub.exe | Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone | No |
| SBI | X | install_sbd_**.exe | Installer for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code, i.e., "en" for English, "de" for German, etc | No |
| InstantDrive | U | InstantDrive.exe | Part of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems (formerly VOB Computersysteme GmbH, now part of Avid Technology, Inc). Creates a virtual CD/DVD drive on the hard drive. | No |
| VOBID | U | InstantDrive.exe | Part of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems (formerly VOB Computersysteme GmbH, now part of Avid Technology, Inc). Creates a virtual CD/DVD drive on the hard drive. | No |
| InstantEyedropper | N | InstantEyedropper.exe | "Instant Eyedropper is a free software tool for webmasters that will identify and automatically paste to the clipboard the HTML color code of any pixel on the screen with just a single mouse click" | No |
| Hyper Start | X | instantmsgrs.exe | Added by the RBOT-NH WORM! | No |
| mousedrive.exe | X | instantmsgrs.exe | Added by the FORBOT-ER WORM! | No |
| instant messengers | X | instantmsgtr.exe | Added by the AGOBOT-PC BACKDOOR! | No |
| InstantPleasure | X | instantpleasure.exe | Adult content dialler | No |
| InstantPleasureXXX | X | instantpleasurexxx.exe | Adult content dialler | No |
| InstantSpywareRemoval.exe | X | InstantSpywareRemoval.exe | Instant Spyware Removal rogue security software - not recommended, removal instructions here | No |
| InstantAccess | N | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start → Programs | No |
| GustavVED | X | instit.bat | Added by the OPASERV.H WORM! | No |
| instit | X | instit.bat | Added by the OPASERV.H WORM! | No |
| InstUtlR.exe | ? | InstUtlR.exe | ?? | No |
| InSysSecure | X | InSysSecure.exe | InSysSecure rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Websx | X | Int*****.exe | Adult content dialler - where ***** are random | No |
| Classes | X | int1.exe | Plus18Point - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN! | No |
| MICROMAPEL | X | Intakeman.exe | Detected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.MMP | No |
| Intarnet | X | Intarnet.exe | Detected by Kaspersky as Trojan-PSW.Win32.Sysrater.r and by Malwarebytes Anti-Malware as Trojan.Agent.INTGen | No |
| Threaded | X | intcp32.exe | Added by the RANDEX.UG WORM! | No |
| Inet Delivery | X | Intdel.exe | Inet Delivery adware | No |
| Inet Delivery | X | intdel_2.exe | Inet Delivery adware | No |
| Intense Registry Service | ? | IntEdReg.exe /CHECK | Intense Educational Ltd - Language Office Software. Is it required? | No |
| ILO_Office_Manager | ? | IntEdReg.exe /OFFMAN | Intense Educational Ltd - Language Office Software. Is it required? | No |
| IntegardTray | U | IntegardTray.exe | System Tray access to Integardparental control software from Race River Corp | No |
| Windows Fix | X | integator.exe | Added by the SDBOT.ZAB WORM! | No |
| Secure System | X | integitor.exe | Added by the AGOBOT.ACI WORM! | No |
| Intel® Interface | X | Intel®.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System% | No |
| Intel(R)GraphicsControls | X | Intel(R)GraphicsControls.exe | Detected by Sophos as Troj/Agent-ZSX and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| HKCU | X | Intel.exe | Detected by McAfee as Generic.bfr!ew and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| HKLM | X | Intel.exe | Detected by McAfee as Generic.bfr!ew and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen | No |
| Installer | X | intel.exe | Detected by Microsoft as Backdoor:Win32/Poison.M. The file is located in %System% | No |
| Intel | X | Intel.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\Intel - see here | No |
| Intel | X | Intel.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.KRZ. The file is located in %AppData%\Microsoft | No |
| INTEL | X | Intel.exe | Detected by Kaspersky as Trojan.Win32.Agent.huan and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System% | No |
| Register_name | X | intel.exe | Detected by Kaspersky as Trojan-PSW.Win32.Lmir.gen. The file is located in %System% | No |
| intel32.exe | X | intel32.exe | Added by the SPYJACK-B TROJAN! | No |
| IntelAudioStudio | N | IntelAudioStudio.exe | "Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience". Audio utility supplied with some Intel motherboards | No |
| Intel(R) Browser | X | intelbrowser.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| IntelCore | X | IntelCore.exe | Detected by Malwarebytes Anti-Malware as MSIL.LockScreen. The file is located in %MyDocuments%\My Music | No |
| RealtekHDAudioManager | X | IntelGraphics.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %MyDocuments%\Services | No |
| NMSSupport | Y | IntelHCTAgent.exe | Network monitor for Intel® Hub Connect Technology | No |
| Intelinet | X | Intelinet.exe | Intelinet rogue security software - not recommended | No |
| Microsoft Windows Operating System | X | InteliTrace.exe | Detected by McAfee as Generic.dx!bg3q and by Malwarebytes Anti-Malware as Trojan.MWF.Gen | No |
| intell32.exe | X | intell32.exe | Added by the SmitFraud alias Desktophijack.C TROJAN! | No |
| intell321.exe | X | intell321.exe | Added by the SPYJACK-B TROJAN! | No |
| Intelliflag_be.exe | X | Intelliflag_be.exe | Intelliflag spyware | No |
| IntelMEM | U | IntelMEM.exe | Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line | No |
| IntelMonitor | X | IntelMon.exe | Detected by Dr.Web as Trojan.PWS.Banker1.9228 | No |
| Intel Product Number Utility | U | IntelProcNumUtility.exe | Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here | No |
| Local Service | X | Intenat.exe | Added by the NUCLEAR-J TROJAN! | No |
| Interactivy | X | Interactivy.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\Interactivy | No |
| Interdll | X | Interdll.exe | Added by the DELF family of TROJANS! | No |
| Windows Media SP 217 | X | Interna.exe | Detected by Kaspersky as Trojan-PSW.Win32.Hukle.t. The file is located in %System% | No |
| Microsoft explorer Update | X | internal.exe | Added by an unidentified WORM or TROJAN! | No |
| PingTimeout Institution | X | internal.exe | Added by the SDBOT.BMH WORM! | No |
| 360safe | X | internat.exe | Detected by Dr.Web as Trojan.Hoster.577 | No |
| CnsMax | X | Internat.exe | Detected by Symantec as Backdoor.Pointex. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir% | No |
| internat | X | internat.exe | Detected by Sophos as Troj/Lydra-F. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir% | No |
| internat.exe | N | internat.exe | Microsoft language selection icon in system tray, located in %System% | No |
| Internat.exe | X | internat.exe | Detected by Symantec as Infostealer.Netsnake. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir% | No |
| internet | X | internat.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - the legitimate internat.exe is located in %System% whereas this version is found in %UserTemp% | No |
| load | X | Internat.exe | Detected by Symantec as Infostealer.Wowcraft. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir% | No |
| Network Connections | X | internat.exe | Detected by Sophos as Troj/VB-ZD | No |
| Runtt1 | X | Internat.exe | Detected by Sophos as Troj/Lineage-R | No |
| Windows Taskbar Manager | X | internat.exe | Detected by Sophos as W32/Protoride-H | No |
| 3e936482e28cca4a48b713452330a269 | X | Internet Explorer.exe | Detected by Dr.Web as Trojan.DownLoader7.14169 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Neospace Internet Security | X | Internet Security.exe | Neospace Internet Security rogue spyware remover - not recommended | No |
| blah service | X | internet.exe | Added by a variant of Win32/Rbot | No |
| Internet | X | Internet.exe | Detected by Kaspersky as Trojan-PSW.Win32.Sysrater.r and by Malwarebytes Anti-Malware as Trojan.Agent.INTGen | No |
| Internet Services | X | internet.exe | Added by the MYTOB.BT WORM! | No |
| Internet.exe | X | Internet.exe | Added by the MAGICCALL VIRUS! | No |
| Micrcoft Updat | X | Internet.exe | Added by the RBOT-ANA WORM! | No |
| NetworkAssociates Inc | X | internet.exe | Added by the LOVGATE.AB WORM! | No |
| Runtt1 | X | Internet.exe | Added by the LINEAGE-Q TROJAN! | No |
| Windows connection manager | X | Internet.exe | Added by the RBOT-APN WORM! Note - file is found in %Windir%. Make sure you check the link on this one, it copies it's self under three other file names and folder locations | No |
| Windows Internet Browser Services | X | internet.exe | Added by the SLENFBOT.GP WORM! | No |
| Windows Internet Browser Services | X | internet128.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| Windows Internet Browser Services | X | internet32.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| Windows Internet Browser Services | X | internet64.exe | Added by a variant of the IRCBOT TROJAN! See here | No |
| internetboan | X | internetboan_up.exe | InternetBoan rogue security software - not recommended, removal instructions here | No |
| InternetCalls | N | InternetCalls.exe | InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| Microsoft | X | internetdat.exe | Added by the RBOT.ETY BACKDOOR! | No |
| InternetData | X | InternetData.exe | Detected by Dr.Web as Trojan.DownLoader6.14490 and by Malwarebytes Anti-Malware as PasswordStealer.MSIL | No |
| MSVersion | X | internetfeatures.exe | Added by the POPMON.A TROJAN - also known as PopMonster adware | No |
| InternetShield | X | InternetShield.exe | InternetShield rogue security software - not recommended, see here | No |
| InternetSpy | U | InternetSpy.exe | Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself! | No |
| explorer | X | internetx.com | Detected by McAfee as Generic.bfr!y | No |
| Internet_Explorer.exe | X | Internet_Explorer.exe | Added by the BANKER-END TROJAN! | No |
| Internt | X | Internt.exe | Detected by Symantec as Backdoor.Peeper and by Malwarebytes Anti-Malware as Trojan.Downloader | No |
| InternetShield | X | INTERN~1.EXE | InternetShield rogue security software - not recommended, see here | No |
| Internet Services | X | interserv.exe | Detected by Trend Micro as WORM_RBOT.BNT | No |
| Intersoft Msngr | X | intersoftmsngr.exe | Added by the AGOBOT-NW WORM! | No |
| Internet Service | X | intersvc.exe | Added by the SPYBOT-DE WORM! | No |
| InterVoip | N | InterVoip.exe | InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype | Yes |
| InterWARN | U | interwarn.exe | InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start → Programs | No |
| Classes | X | intl.exe | Plus18Point - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN! | No |
| Intmgr | X | Intmgr.exe | Added by the GEMA TROJAN! | No |
| clover | X | intothemap_CP.exe | Detected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\intothemap CP | No |
| clover_u | X | intothemap_CP_updater.exe | Detected by Malwarebytes Anti-Malware as Adware.K.IntoMap. The file is located in %ProgramFiles%\intothemap CP | No |
| Intranet | X | intranet.exe | Added by the CHIMOZ.AC TROJAN! | No |
| The Intranet | X | intranet.exe | Added by a variant of W32/Sdbot.worm | No |
| Microsoft Intranet Patcher | X | intranetexplorer.exe | Detected by Sophos as Troj/Agent-IRB and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Intren0t | X | Intren0t.exe | Detected by Trend Micro as TROJ_LEGMIR.IC and by Malwarebytes Anti-Malware as Trojan.Delf | No |
| Gremlin | X | intrenat.exe | Added by the DOOMJUICE WORM! | No |
| Intrenat | X | Intrenat.exe | Added by the LEMIR.E TROJAN! | No |
| Norton Personal Firewall | Y | IntroWiz.exe | Part of Norton Personal Firewall or Norton Internet Security | No |
| WinXP Processor Generator v1.2 | X | intspnsr32.exe | Added by the SDBOT.LP BACKDOOR! | No |
| Generic Host Process for Win32 Services | X | intspvc.exe | Added by the DINFOR.D WORM! | No |
| Intuit SyncManager | U | IntuitSyncManager.exe | Synchronizes local Intuit Quickbooks data with online data - "Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync, manage sync frequency, and stop or start syncs at any time." See here for more information | No |
| RunCA | Y | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required | No |
| WUSB54GS | Y | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required | No |
| WUSB54Gv2 | Y | InvokeSvc3.exe | Wireless-G USB Wireless Network Adapter related - would appear to be required | No |
| MircProtection | X | Io.vbs | Added by the THEA-A VIRUS! | No |
| io589 | X | io589.exe | Detected by McAfee as Generic PWS.b and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Pornfolio | X | ioande.exe | Added by the SDBOT.ATW WORM! | No |
| iobi | N | iobiClient.exe | iobi Home - a mail/voice service by Verizon | No |
| IObit SmartDefrag | U | IObit SmartDefrag.exe | This is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| Smart Defrag | U | IObit SmartDefrag.exe | This is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| SmartDefrag | U | IObit SmartDefrag.exe | This is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| iochviewer | X | iochviewer.exe | Detected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %AppData%\iochviewer | No |
| iolo AntiVirus | Y | ioloAV.exe | iolo AntiVirus | No |
| iolo Personal Firewall | Y | ioloFW.exe | iolo Personal Firewall | No |
| CheckVCR | Y | IOMagic.exe | Driver for the I/OMagic Personal Video Recorder (DR-PCTV100) | No |
| Iomega Home Storage Manager | U | Iomega Discovery.exe | Iomega Home Storage Manager for some of their external hard drives | No |
| Iomega Storage Manager | U | IomegaStorageManager.exe | Iomega Storage Manager for some of their external hard drives | No |
| Iomega_loader | X | Iomega_loader.exe | Detected by Trend Micro as WORM_ANTINNY.F | No |
| Iomon98.exe | U | Iomon98.exe | PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang | No |
| crsmons | X | iomssls.exe | Added by the BACKDR-AU TROJAN! | No |
| iosepcdef | X | iosepcdef.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Messa | No |
| Iomega Watch | N | iowatch.exe | Used by Iomega drives. Available via Start → Programs | No |
| Windows Live Messenger | X | iOXGPymMLPPzevA.exe | Detected by Sophos as Troj/MSIL-AN and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| IPO3 | N | IP Operator 2005.exe | IP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single button | No |
| IP**.exe [* = random char] | X | IP**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| IP**32.exe [* = random char] | X | IP**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log | No |
| Net-ip | X | IP-net.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%\Ip-net | No |
| IP | X | IP.EXE | Added by the AGOBOT-QO WORM! | No |
| iProtectYou | U | ip.exe | iProtectYou - internet filtering/parental control and network monitoring software | No |
| Configuration Loader10 | X | ip7.exe | Added by the AGOBOT-ANZ WORM! | No |
| Windows Relay Service | X | ipcbind.exe | Added by the DELFINJECT.F TROJAN! | No |
| IPC Connection | X | ipcconn.exe | Added by the RBOT-AEG WORM! | No |
| ipcfg.exe | X | ipcfg.exe | Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN! | No |
| Reg Service | X | ipcfg.exe | Added by the AGOBOT-SO WORM! | No |
| IP Changer 2.0 | U | IPChanger.exe | IP Changer 2.0 from Plustech Inc - network configuration management tool | No |
| Internet Protocol Configuration Loader | X | ipcl32.exe | Added by the SDBOT BACKDOOR! | No |
| IPInSightLAN 01 | N | IPClient.exe | IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth, Visual Networks and others. If you have more that one such service installed there may be two or more entries - i.e., IPInSightLAN 02, etc | No |
| SafetyNet_Notifier | U | ipcLn.exe | Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" | No |
| IpCtrl | X | ipcon32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| Windows driver update | X | Ipconfig32.exe | Added by the SDBOT-JV WORM! | No |
| IPConfig | X | ipconfigs.exe | Added by the HACARMY.C BACKDOOR! | No |
| ipconfigys.exe | X | ipconfigys.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| Logitech Desktop | X | ipconn.exe | Added by the SDBOT-WE WORM! | No |
| SafetyNet | U | ipcTray.exe | Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" | No |
| ifp | X | ipf.exe | Added by the CLAGGER-AG TROJAN! | No |
| wfips | U | iphider.exe | ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here | No |
| IPHSend | ? | IPHSend.exe | AOL related. What does it do and is it required? | No |
| VPNClient | Y | ipigclient.exe | iOpus Private Internet Gateway (iPIG) client. 'Using powerful 256-bit AES encryption technology, the iOpus Private Internet Gateway (iPIG) creates a secure "tunnel" that protects your inbound and outbound communications (Email, Web, IM, VOIP, calls, FTP, etc.) at any Wi-Fi hotspot or wired network' | No |
| IPLA! | U | ipla.exe | IPLA! from Redefine - "an application that makes it possible to broadcast TV shows live on the Internet and to watch countless video materials from ipla's own online database" | No |
| IPLog Security | X | iplogsec.exe | Added by the IRCBOT.GP BACKDOOR! | No |
| IPlusUpdate | X | IPlusUpdate.exe | Detected by McAfee as Generic.bfr!dm and by Malwarebytes Anti-Malware as Adware.Iplus | No |
| ipmon.exe | X | ipmon.exe | Added by the RECERV or R3C.B TROJANS! | No |
| IPInSightMonitor 01 | N | IPMon32.exe | IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth, Visual Networks and others. If you have more that one such service installed there may be two or more entries - i.e., IPInSightMonitor 02, etc | No |
| IpNetwork | X | ipnetwork.exe | Maxifiles adware | No |
| Ipnuker | X | Ipnuker.vbs | Added by the INKER.B WORM! | No |
| iPodder | N | iPodder.exe | iPodder (now known as Juice) - a free utility that "allows you to select and download audio files from anywhere on the Internet to your desktop". This entry is present if you choose the option to add it to the startup group during installation | Yes |
| Microsoft Winedows WinServ | X | iPodFix.exe | Added by a variant of Win32/Rbot | No |
| Windows Secure Fix | X | iPodFixer.exe | Added by the WOOTBOT.BM BACKDOOR! | No |
| iPodManager | U | iPodManager.exe | Apple iPod® management software for the iPod® player - updates, formating, restoring and other functions associated with the iPod® | No |
| iPod USB Service | X | iPODService.exe | Detected by Trend Micro as WORM_SDBOT.ATT. Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service. This file is located in %System% | No |
| iPOD USB Driver | X | IPODUSB.EXE | Added by a variant of Win32/Rbot | No |
| iPodWatcher | ? | iPodWatcher.exe | Associated with Apple's iPod® player. Detects when the iPod® is connected? | No |
| IntelliPoint | U | ipoint.exe | Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported | Yes |
| ipoint | U | ipoint.exe | Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported | Yes |
| Microsoft IntelliPoint | U | ipoint.exe | Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported | Yes |
| IPPDetect | N | IPP4Detect.exe | Part of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos" | No |
| IP Packet Redirect Service | X | ipredirect.exe | Added by the FORBOT.SM WORM! | No |
| ipreg | X | ipreg.exe | Added by the ZAGABAN-H TROJAN! | No |
| Authorization Interface | X | iprivcom2.exe | Detected by Kaspersky as Trojan-Dropper.Win32.Delf.grq | No |
| iPrint Tray | N | iprntctl.exe | Novell® iPrint - a "best-of-breed printing solution for businesses running as traditional enterprises, for those operating entirely on the Net, and for those anywhere on the large spectrum in between" | No |
| YKVEJDPMXD | X | iprtrmgry.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.QRJ. The file is located in %System% - see here | No |
| IPS | X | ips.exe | Detected by Dr.Web as Trojan.PWS.Siggen.35050 and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Windows IP Security | U | ipsec.exe | Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel | No |
| iPSec7 | X | ipsec7.exe | Added by the AGENT.AHVR TROJAN! | No |
| Cisco Systems VPN Client | U | ipsecdialer.exe | Cisco VPN Client - lets local users gain Administrator privileges on the operating system | No |
| ipsecdialer | U | ipsecdialer.exe | Cisco VPN Client - lets local users gain Administrator privileges on the operating system | No |
| ipsecdialer | U | IPSECD~1.EXE | Cisco VPN Client - lets local users gain Administrator privileges on the operating system | No |
| IPSecMon | X | IPSecMon.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate MS L2TP/IPSec file with the same name which is located in a %Program Files%\Microsoft IPSec VPN. This one is located in %CommonFiles%\VPN Network | No |
| IPSecMon | Y | IPSecMon.exe | Microsoft L2TP/IPSec VPN Client that loads via HKLM\RunServices on Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet | No |
| Windows IP Security Service | X | ipsecs.exe | Detected by Trend Micro as WORM_RBOT.BPW | No |
| Windows Firewall | X | ipservice32.exe | Added by a variant of Win32/Rbot | No |
| ipsnow | X | ipsnow.exe | Added by the SNOWDOOR.A BACKDOOR! | No |
| IP Stack | X | ipstack.exe | Detected by Trend Micro as WORM_AGOBOT.CW | No |
| Iinl | X | iptl.exe | PurityScan adware | No |
| iptray | N | iptray.exe | System Tray access to Intel Desktop Utilities - "provides you with the means to monitor system temperatures, voltages, fan speeds, and hard drive health; view detailed system information, and test your system hardware for common errors" | No |
| IPW | N | IPW.exe | Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone" | No |
| IPFW | X | ipwf.exe | Added by the DLOADER-YF TROJAN! | No |
| ipwf | X | ipwf.exe | Added by the SCHOEBERL TROJAN! | No |
| IpWins | X | ipwins.exe | Maxifiles.ab adware | No |
| Client Agent | X | ipxwping.exe | Added by the PPDOOR-N TROJAN! | No |
| ipxwshel | X | ipxwshel.exe | Added by the WAREZOV.DG WORM! | No |
| iprun | X | iPY.exe | iProtectYou spyware | No |
| IQES.exe | ? | iqes.exe | ?? | No |
| TOPOLOGY NET.TCP BIOMETRIC CONTROLS SOURCE | X | iqfrcfjyhsr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| iqmanager.exe | X | iqmanager.exe | IQ-Manager ransomware copyright scanner - not recommended, removal instructions here | No |
| Microsoft Firevall Engine | X | iqs.exe | Detected by Sophos as W32/Stekct-B and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| SystemMgr | X | Ir32_a.exe | Added by the MAGANIA-OU TROJAN! | No |
| MREU | X | ir41_qcxi.exe | Detected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System% | No |
| iran.task | X | iran.exe | Detected by McAfee as MultiDropper-DC | No |
| Winsock32 driver | X | iran.exe | Detected by McAfee as MultiDropper-DC | No |
| irassync | X | irasyncd.exe | Detected as SUPERAntiSpyware as Trojan.IRASHoul.Process. The file is located in %System% | No |
| IRBMe Sucks!! | X | IRBMe.exe | Added by the RANDEX-Y WORM! | No |
| Randex virus built for IRBMe | X | irbme.exe | Added by the RANDEX.RH WORM! | No |
| winlogon | X | ircbsbot.exe | Added by the AGENT-RGJ TROJAN! | No |
| IREIKE | Y | IreIKE.exe | Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet | No |
| Windows Relay Service | X | irfnga.exe | Added by the DROPPER.ACO TROJAN! | No |
| IridiumTimeWizard | N | iridium.exe | Iridium TimeWizard - a small program for finding out the time in different parts of the world | No |
| Iris | X | Iris.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.IS. The file is located in %AppData%\IRisDir | No |
| Infra-red Monitor | U | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices | No |
| IrMon | U | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices | No |
| SM | X | iro.bat | Added by the IROFFER.CT BACKDOOR! | No |
| SMS | X | iro.bat | Added by the IROFFER.CT BACKDOOR! | No |
| IRQ Assigning Agent | X | IRQconf.exe | Added by the SDBOT-CSV WORM! | No |
| irssyncd | X | irssyncd.exe | Added by a variant of Spyware.SafeSurfing | No |
| ssgrate.exe | X | irun.exe | Added by the MITGLIEDER.D TROJAN! | No |
| ssate.exe | X | irun4.exe | Added by the BEAGLE.J WORM! | No |
| ssgrate.exe | X | irun4.exe | Added by the MITGLIEDER.F TROJAN! | No |
| ir_ftp | X | irwftp.exe | Added by the BANCOS.H TROJAN! | No |
| IrXfer | U | IrXfer.exe | Microsoft Infrared Transfer application | No |
| ir_ftp | X | ir_ftp.exe | Added by the IRFTP TROJAN! | No |
| winzip | X | ir_ftp.exe | Added by the BANCBAN-S TROJAN! | No |
| Info Select | U | is.exe | Info Select from Micro Logic - personal information manager | No |
| Internet Security 2010 | X | IS2010.exe | Internet Security 2010 rogue security software - not recommended, removal instructions here | No |
| IObit Security 360 | U | IS360tray.exe | System Tray access to and notifications for Security 360 anti-malware from Iobit - which has now been discontinued. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| IS360tray | U | IS360tray.exe | System Tray access to and notifications for Security 360 anti-malware from Iobit - which has now been discontinued. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind up | Yes |
| Microsoft Update | X | Isac.exe | Added by the RBOT-AU WORM! | No |
| CAISafe | Y | isafe.exe | E-mail scanning part of EZ Antivirus - part of the eTrust range of security products formerly available from CA but now discontinued. Available as a stand-alone product or as part of the EZ Armor suite. Runs as the CAISafe service in later product versions | No |
| iSafeAV | X | iSafeAV.exe | iSafe AntiVirus rogue security software - not recommended, removal instructions here | No |
| homepage.monitor.exe | X | isamonitor.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details | No |
| isamini.exe | X | isamonitor.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. The most popular for this example appears to be "Video ActiveX Object" | No |
| isamonitor.exe | X | isamonitor.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details | No |
| -=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+ | X | ISASS.exe | Added by the ASSIRAL.B WORM! | No |
| Anti | X | Isass.exe | Added by the BROPIA.K WORM! | No |
| CSNetManagerXp | X | isass.exe | Added by the HIDER-O TROJAN! | No |
| EDxMC110 | X | Isass.exe | Added by the VB-NIA WORM! | No |
| Isass | X | Isass.exe | Added by the FUTRO TROJAN! | No |
| isass.exe | X | isass.exe | Detected by Sophos as Troj/Spy-VL and by Malwarebytes Anti-Malware as Trojan.Clons | No |
| Kiamat Sudah Dekat_16_04 | X | ISASS.exe | Added by the PAHATIA.B WORM! | No |
| Local Security Authority Service | X | Isass.exe | Added by the LINKBOT.M WORM! | No |
| Local windows | X | Isass.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| Microsoft Hosts Service | X | Isass.exe | Added by a variant of Win32/Rbot | No |
| MicroSoft IE Sasser | X | ISASS.EXE | Added by the SDBOT.MX WORM! | No |
| Microsoft Lsass Center | X | Isass.exe | Added by a variant of W32/Sdbot.worm | No |
| NvMsnW | X | Isass.exe | Added by the BROPIA.K WORM! | No |
| Patah Hati | X | ISASS.exe | Added by the PAHATIA.A WORM! | No |
| boby. | X | Isass.scr | Added by the BANCBAN-OH TROJAN! | No |
| LSASS32 | X | Isass32.exe | Added by the KELVIR.M WORM! | No |
| LSASS 32 | X | ISASS32.pif | Added by the ASSIRAL-C WORM! | No |
| MSControl3d1 | X | isasse.exe | Added by the RBOT.CGU WORM! | No |
| MICROSOFT FIREWALL CLIENT | Y | ISATRAY.EXE | MS Internet Security and Acceleration Server - see here | No |
| ISBMgr.exe | U | ISBMgr.exe | Sony ISB Utility - supports the battery management on some Sony laptops | No |
| ShellN | X | isca.exe | Added by the IBILL.Z TROJAN! | No |
| gtydf | X | iscca.exe | Added by the DWNLDR-GTK TROJAN! | No |
| iscch | X | iscch.exe | Added by the LCPRANK-A WORM! | No |
| star2 | X | ischot.exe | Detected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Personal Security Center Monitor | X | isc_ui.exe | Detected by GFI as Trojan.FakeAlert (fs). The file is located in %System% | No |
| isdbdc | N | isdbdc.exe | For Compaq PC's. May install properties in dial-up networking when you register with an ISP | No |
| Miciupdate | X | isdcic.exe | Detected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %MyDocuments%\MSDCSC | No |
| isDeleteMe | U | isDel.bat | Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product | No |
| hsim | X | isearch.exe | Unidentified malware | No |
| Neospace Internet Security | X | isec30.exe | Neospace Internet Security rogue spyware remover - not recommended | No |
| Internet Security | X | isecurity.exe | Internet Security rogue security software - not recommended, removal instructions here | No |
| iSeriesCharge | U | iSeriesCharge.exe | ASUS Ai Charger utility - which on supported motherboards can be used to charge Apple's iPod, iPhone and iPad whilst the system is working or is in standby, sleep or shutdown modes | No |
| SystemInit | X | iservc.exe | Added by the FIZZER WORM! | No |
| cms | X | iserver.exe | Added by the DLOADER-WK TROJAN! | No |
| iNotice | X | iservice.exe | Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos | No |
| zsmsgs | X | iservice.exe | Detected by Sophos as Troj/Bancos-BU | No |
| INTERNETSERVICEPROTOCOL | X | IServices.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\microsoft | No |
| Server | X | iservices.exe | Detected by Symantec as Backdoor.Graybird.D and by Malwarebytes Anti-Malware as Trojan.Agent.SD. The file is located in %System% | No |
| xevivi | X | isesobo.exe | Added by the SDBOT-US WORM! | No |
| start | X | isfmntr.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details | No |
| ish-b.exe | X | ish-b.exe | Added by the IRCBOT-ACZ TROJAN! | No |
| iShield | U | iShield.exe | "GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser" | No |
| ishost.exe | X | ishost.exe | Added by the DLOADR-XJ TROJAN! | No |
| isiss.exe | X | isiss.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MSDCSC - see here | No |
| ISLP2STA | Y | ISLP2STA.EXE | A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers | No |
| ISMModule | X | ISMModule.exe | Internet Speed Monitor adware - see example here | No |
| ISMModule2 | X | ISMModule2.exe | Internet Speed Monitor adware variant - see example here | No |
| ISMModule3 | X | ISMModule3.exe | Internet Speed Monitor C adware | No |
| ISMModule4 | X | ISMModule4.exe | Internet Speed Monitor A adware - see example here | No |
| ISMModule6 | X | ISMModule6.exe | Internet Speed Monitor adware variant - see example here | No |
| ISMModule7 | X | ISMModule7.exe | Internet Speed Monitor B adware - see example here | No |
| ISMModule8 | X | ISMModule8.exe | Internet Speed Monitor adware variant | No |
| ISMPack5 | X | ISMPack5.exe | Internet Speed Monitor adware variant - see example here | No |
| ISMPack6 | X | ISMPack6.exe | Internet Speed Monitor adware variant - see example here | No |
| ISMPack7 | X | ISMPack7.exe | Internet Speed Monitor C adware - see example here | No |
| ISMPack8 | X | ISMPack8.exe | Internet Speed Monitor adware variant - see example here | No |
| isndntio | X | isndntio.exe | Added by the ONLINEGAMES.ALLK TROJAN! | No |
| Regional Value | X | isng.exe | Added by the SDBOT-OW WORM! | No |
| iSnooze | U | iSnooze.exe | iSnooze by Steven Scott - "sits in your system tray and lets you schedule times for iTunes to start playing." Now abandoned | No |
| ServiceConfig | U | ispbeg.exe | Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation | No |
| News Service | ? | ispnews.exe | F-Secure antivirus related. However, is this particular item required? | No |
| IsReminder | N | ISPopup.exe | Related to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup | No |
| ISP | ? | ISPselector.exe | Found on some Sony PCs in %ProgramFiles%\Sony\ISPselector. Offers the new user a selection of pre-configured ISPs (Internet Service Providers)? | No |
| iSpyNOW | U | ispynow.exe | iSpyNOW - remote monitoring and surveillance software | No |
| Israfel | X | Israfel.vbs | Added by the GAGGLE.D or GAGGLE.E WORMS! | No |
| ISRHelper.exe | X | ISRHelper.exe | Instant Spyware Removal rogue security software - not recommended, removal instructions here | No |
| wincrt.exe | X | isrprov.exe | Added by the STRATIO-HA WORM! | No |
| IsassRenascimento | X | Issas.exe | Added by the BANKER.GAX TROJAN! | No |
| Microsoft Install Manager | X | issas.exe | Detected by Sophos as Mal/Sohana-A | No |
| issch | N | issch.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| ISUSScheduler | N | issch.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| Macrovision Update Service | N | issch.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| issearch.exe | X | issearch.exe | Added by the ZLOB-QF TROJAN! | No |
| issEnc32Svr | X | issEnc32.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| ISSI EZUpdate Service | N | issimsvc.exe | Part of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching | No |
| CyberDefender Early Detection Center | X | ISSIntro.exe | CyberDefender Early Detection Center rogue security software - not recommended. On testing with a clean image, this reported registry entries pointing to the legitimate Java "jqs_plugin.dll" file (located in %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie) as the Anticlear rogue (see an example here). In addition, it claimed that the installer for an older version of HashTab contained W32.MalwareF.KJAE and quarantined a valid 7-zip file ("7zCon.sfx" in %ProgramFiles%\7-Zip) as W32/Malware. Also read this post where a Tech Support person uses other free tools such as MBAM to fix a problem | No |
| ISStart | U | ISStart.exe | Installed with Logitech's QuickSmart, ImageStudio and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| Logitech ClickSmart | U | ISStart.exe | Installed with Logitech's QuickSmart webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| Logitech ImageStudio | U | ISStart.exe | Installed with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| Logitech QuickCam | U | ISStart.exe | Installed with older versions of Logitech's QuickCam webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| LogitechGalleryRepair | U | ISStart.exe | Installed with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| LogitechVideoRepair | U | ISStart.exe | Installed with Logitech's QuickSmart and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videos | Yes |
| ISSVC | Y | ISSVC.exe | Common process for older versions of Symantec's Norton Internet Security and the now discontinued Norton Personal Firewall security products. The exact purpose is unknown at present but neither program can function properly if this process is disabled. Runs as a service on an NT based OS (such as Windows 7/Vista/XP) | No |
| Internet Sharing Server | Y | iss_srvr.exe | Intel AnyPoint internet sharing software. Now discontinued | No |
| istinstall zazzer.exe | X | istinstall zazzer.exe | Unidentified adware downloader/installer | No |
| IST Service | X | istsvc.exe | ISTBar adware | No |
| ISUSPM | N | ISUSPM.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| ISUSPM Startup | N | ISUSPM.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| Macrovision Update Service | N | ISUSPM.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| Software Manager | N | ISUSPM.exe | InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis | Yes |
| Configuration Loadings | X | iSVCHOST.exe | Detected by Sophos as W32/Agobot-C and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| ISW.exe | Y | ISW.exe | AT&T Internet Security Wizard tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| DigitalWizard | N | ISWizard.exe | InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content | No |
| isxa | X | isxa.exe | Added by the SMALL-EIV TROJAN! | No |
| ISXAgent | ? | ISXAgent.exe | Related to Imprivata IT security products. What does it do and is it required? | No |
| Internet Explorer Sys32 | X | isys32.exe | Added by the IRCBOT-ADA WORM! | No |
| iSysCleaner | N | iSysCleaner.exe | iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user | No |
| isystem | X | isystem.exe | Added by the CHORUS-A TROJAN! Searchforfree browser hijacker | No |
| Windows | X | Isz5suz5.exe | Added by the BUZUS.IIRA TROJAN! | No |
| ISZone | X | ISZoneUpdate.exe | Detected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\ISZone | No |
| Internet Security Guard | X | IS[random characters].exe | Internet Security Guard rogue security software - not recommended, removal instructions here | No |
| iTunesAgent | X | ita.exe | Added by the TACTSLAY.U TROJAN! | No |
| ItalU | X | italfds.exe | Added by a TROJAN - see here | No |
| iTbaMgqSlSQqG | X | iTbaMgqSlSQqG.exe | Added by the FAKEAV-DVN TROJAN! | No |
| IRPMonitor | ? | itcnmon.exe | ?? | No |
| SSS6_ITD | ? | itd.exe | Part of the Security Suite 6 set of data protection utilities from Steganos - now superseded by Privacy Suite | No |
| Systems | X | itDDD.exe | Added by the DLOADER-PP TROJAN! | No |
| SmartGuardian | U | Itesmart.exe | Hardware monitor (voltages, temperatures, fan speeds, etc) for motherboard system IO devices from ITE - included on some SOYO motherboards (and possibly others) | No |
| iTHINK | X | iThink.exe | Detected by Microsoft as Adware:Win32/Ithink and by Malwarebytes Anti-Malware as Adware.Ithink | No |
| iTHINKUpdate | X | iTHINKUpdate.exe | Detected by Microsoft as Adware:Win32/Ithink and by Malwarebytes Anti-Malware as Adware.Ithink | No |
| Internet Timer | U | ITIMER.exe | Shareware dial-up connection call cost calculator from Ratsoft | No |
| Itk | U | Itk.exe | In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it | No |
| itk.exe | U | itk.exe | Insert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert | No |
| Praize Messenger | U | itLoad.exe | Praize IM Christian chat instant messenger | No |
| iTouch | U | iTouch.exe | Loads the iTouch configuration settings for supported Logitech keyboards. It's required if your keyboard has shortcut buttons and you use them or have reconfigured them for different functions. It's also required if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen display indications for these | Yes |
| zBrowser Launcher | U | iTouch.exe | Loads the iTouch configuration settings for supported Logitech keyboards. It's required if your keyboard has shortcut buttons and you use them or have reconfigured them for different functions. It's also required if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen display indications for these | Yes |
| iTraffic Monitor | N | iTrafficMon.exe | "iTraffic Monitor is a network monitor and reporting tool. It provides real time graph of network traffic. Detailed stats provide daily/weekly/monthly/yearly stats. Stop watch, Session stats" | No |
| ItsDeductiblePopUp | N | ItsDeductible.exe | ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip | No |
| ITSecMng | N | ItSecMng.exe | Related to Bluetooth wireless support on both notebooks and via USB dongles. IF this entry is disabled you can still access your Bluetooth devices | No |
| ITUNES | X | itune.exe | Added by the RBOT-ZU WORM! | No |
| Apple iPod Service | X | iTunes.exe | Added by the AUTORUN-BLL WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %AppData% | No |
| ITUNES | X | itunes.exe | Added by a variant of Win32/Rbot. Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %System% | No |
| Itunes | X | itunes.exe | Added by the OSCABOT-L WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %Windir% | No |
| itunesff | X | itunesff.exe | Added by the EB adult premium dialer | No |
| MSN | X | iTuneshelp.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| iTunes | U | iTunesHelper.exe | Installed with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few times | Yes |
| iTunes | X | iTunesHelper.exe | Added by the ITUNEHLP-A TROJAN! Note - this is not the legitimate Apple iTunes file of the same name which is normally found in %ProgramFiles%\iTunes. This one is found in %Root%\iTunes | No |
| iTunes Helper | U | iTunesHelper.exe | Installed with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few times | No |
| iTunesHelper | U | iTunesHelper.exe | Installed with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few times | Yes |
| iTunes Music | X | iTunesHelper32.exe | Added by the SDBOT.CHK WORM! | No |
| LOCALHOST | X | iTunse.exe | Detected by McAfee as Backdoor-CEP.gen.ad and by Malwarebytes Anti-Malware as Backdoor.Agent.CNM | No |
| itype | U | itype.exe | Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any keys or key combinations that are changed by the user to perform functions other than default settings, defer back to their default settings and supported keys will not function in applications with advanced text services enabled | Yes |
| Microsoft IntelliType Pro | U | itype.exe | Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled | Yes |
| InterTrust Quick Start | N | it_cpq~1.exe | InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business | No |
| Information Update | X | iu.exe | Detected by Kaspersky as the CENTIM.CH TROJAN! | No |
| AcerVGA Engine Drivers V1.2 | X | iuengine32.exe | Added by the AGENT.QWQ TROJAN! | No |
| USB3MON | U | iusb3mon.exe | Supports USB 3.0 ports based upon Intel chipsets. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management features | No |
| iMarkup Client | N | iUtil.exe | Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start → Programs | No |
| iv | X | iv.exe | Part of the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions here | No |
| MS Host Manager | X | ivhost.exe | Added by the RBOT-BJN WORM! | No |
| sistem | X | ivi.exe | Detected by Kaspersky as Backdoor.Win32.Agent.anyl | No |
| IVONA ControlCenter | ? | IVONA ControlCenter.exe | ControlCenter for IVONA text-to-speech software | No |
| IVPServiceMgr | N | ivpsvmgr.exe | Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates | No |
| MSConfig | X | ivscjcqv.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| ivy.exe | X | ivy.exe | Added by the AGENT-ENZ TROJAN! | No |
| Internet Washer Pro | X | iw.exe | Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 | No |
| InternetWasherPro | X | iw.exe | Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 | No |
| eWare Startup | N | iWareStart.exe | eWare iWare task bar. Not required | No |
| ISDNwatch | U | IWatch.exe | FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks" | No |
| IW ControlCenter | U | iwctrl.exe | Part of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis | No |
| IW_Drop_Icon | U | iwctrl.exe | Part of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis | No |
| iwctrl | U | iwctrl.exe | Part of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis | No |
| StartupBin | X | iwnujdss.exe | Added by the SDBOT-XZ WORM! | No |
| Sts | X | iwnujdss2.exe | Added by the SDBOT-YI WORM! | No |
| Camio Viewer | N | IXApplet.exe | Part of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading them | No |
| Camio Viewer 1.8.7 | N | IXApplet.exe | Part of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading them | No |
| Camio Viewer 2.0 | N | IXApplet.exe | Part of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading them | No |
| Camio Viewer 3.2 | N | IXApplet.exe | Part of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading them | No |
| ixplore | X | ixplore.exe | Added by the SDBOT-CY TROJAN! | No |
| scvhost loader | X | ixplore.exe | Added by the SDBOT-CY TROJAN! | No |
| ixplores | X | ixplores.exe | Added by the SDBOT-CE WORM! | No |
| ixsso | X | ixsso.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" | No |
| Windows Service Agent | X | izszbayz.exe | Added by the KOLAB.TC WORM! | No |
| CorelCENTRAL 10 | N | I_26dadCC.exe | CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start → Programs | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |