Index Introduction Database Detailed Entries Updates Concise List HJT Forums Rogues Message Board

Windows startup programs - Database search

If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.

See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.

Last database update :- 31st May, 2013
32700 items listed

You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.

Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:

A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z

NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.

Please click on the Search button

1133 results found for I

Startup Item or Name Status Command or Data Description Tested
testXi love you.exeAdded by the SINGU-T TROJAN!No
rate.exeXi11r54n4.exeAdded by the BEAGLE-I WORM!No
rate.exeXi1ru74n4.exeAdded by the BEAGLE.E WORM and variants!No
I386XI386.exeAdded by the MYPOWER WORM!No
Config LoadatiorinXI3Explorer.exeAdded by the SDBOT.H TROJAN!No
i6g8xsXi6g8xs.exeDetected by Kaspersky as Virus.Win32.Virut.ce and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
I81SHELL?I81SHELL.exeAppears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboardNo
i8kfanguiUI8kfanGUI.exeI8kfanGUI - Dell Inspiron/Latitude/Precision fan control utilityNo
IntruderAlertXia99.exeIntruder Alert '99 from Bonzi - spywareNo
IAAnotifUIaanotif.exePart of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes, HDD I/O errors or HDD SMART event) via a System Tray icon when an event occurs. Via this icon you can then choose to launch the Intel Matrix Storage Console or ignore the current alertYes
RAID Event MonitorUIaanotif.exePart of Intel® Matrix Storage Manager (formally known as Intel® Application Accelerator and Intel® Application Accelerator RAID Edition). Used in conjunction with the event monitor service (IAANTMON - Iaantmon.exe) to display event notifications (such as RAID volume status changes, HDD I/O errors or HDD SMART event) via a System Tray icon when an event occurs. Via this icon you can then choose to launch the Intel Matrix Storage Console or ignore the current alertYes
iPlusAgentUiAgent.exeiriver PLUS media management utility for their range of portable media devicesNo
iPlusAgent2UiAgent2.exeiriver PLUS media management utility for their range of portable media devicesNo
3P_UDEC_IAXIAInstall.exeInstaller for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions hereNo
Internet Answering MachineUIAM.exeFrom Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet accessNo
iamappYiamapp.exePart of Symantec's now discontinued Norton Personal Firewall and also included in older versions of Norton Internet Security. Also part of their now discontinued Symantec Desktop Firewall (for business customers). Formally AtGuard by WRQ until their acquisition by Symantec. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Internet Answering MachineUIAMNET~1.EXEFrom Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet accessNo
NAV Auto UpdateXiamsad.exeAdded by the SPYBOT-CE BACKDOOR!No
IaNvSrv?IaNvSrv.exeRelated to the option ROM part of the Intel® Matrix Storage Manager. Located in %ProgramFiles%\Intel\Intel Matrix Storage Manager\OROM\aNvSrv. What does it do and is it required?No
SM_IANXian_monitor.exeAdvancedCleaner rogue security software - not recommended, see here. Removal instructions hereNo
Iap?iap.exePossibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?No
Internet Antivirus ProXIAPro.exeInternet Antivirus Pro rogue security software - not recommended, removal instructions hereNo
Live Enterprise SuiteXIAPro.exeLive Enterprise Suite rogue security software - not recommended, removal instructions hereNo
iasUias.exeInvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!No
IASHLPRXIASHLPR.EXEAdded by the OPASERV.T WORM!No
Microsoft Keyboard Enhance 2.0.Xiasrecst.exeAdded by the BCKDR-QIL BACKDOOR!No
Microsoft Keyboard Enhance V2.0Xiasrecst.exeDetected by F-Prot as the DOWNLOADER2.AILI TROJAN!No
Microsoft media servicesXIassd.exeAdded by the SPYBOT.HE WORM!No
IAStorIconUIAStorIcon.exeSystem Tray acces to and notifications for Intel® Rapid Storage Technology - which "provides new levels of protection, performance, and expandability for desktop and mobile platforms. Whether using one or multiple hard drives, users can take advantage of enhanced performance and lower power consumption." If enabled it will give you quick access to the main utility and provide alerts if any problems are detectedYes
iasxXiasx.exeAdded by the NURECH TROJAN!No
Microsoft Internet Acceleration UtilityXiau.exeEasySearch adwareNo
Microsoft Office Quick LauncherXiau1.exeAdded by the DLOADR-AWD TROJAN!No
Internet AntivirusXIAvir.exeInternet Antivirus rogue security software - not recommended, removal instructions hereNo
RenolB?ib.exe??No
IBWin Background processUIBackground.exeIBackup for WindowsNo
Iomega Automatic BackupUibackup.exeIomega Automatic Backup - automatic backups for use with Iomega portable HDDNo
Iomega Automatic Backup 1.0.1Uibackup.exeIomega Automatic Backup - automatic backups for use with Iomega portable HDDNo
Instant Buzz DaemonXIBDaemon.exeInstant Buzz adwareNo
ibmXibm.exeAdded by the LEGMIR-AH TROJAN!No
ShellXibm0000*.exe [* = digit]Detected by Sophos as Troj/Torpig-C and by Malwarebytes Anti-Malware as Trojan.Agent. Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on and they are typically located in %CommonFiles%\Microsoft Shared\Web FoldersNo
ShellXibm00001.dllAdded by the TORPIG-Q TROJAN!No
IBMUltraBayHotSwapCPLLoaderUIBMBAY2N.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptopsNo
IBMUltraBayHotSwapSound?IBMBAYSN.EXESupports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?No
Access IBM Message CenterNibmmessages.exe"The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"Yes
ibmmessagesNibmmessages.exe"The Access IBM Message Center displays messages to inform you about helpful software that may be pre-installed on your PC. The Message Center can also provide messages about new updates available from the IBM Support Center to keep your computer current"Yes
Ibmmon.exe?Ibmmon.exe??No
IBWin MonitorUIBMonitor.exeIBackup for WindowsNo
IbmpmsvcUibmpmsvc.exePower management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modesNo
IBMPRC?ibmprc.exeIBM application - what does it do and is it required?No
TaskmanXibnzs.exeAdded by the AGENT-NTI TROJAN!No
Shmgrate.exeXibot4.exeAdded by the GASTER TROJAN!No
IbsXibs.exeAdded by the HIDEDIAL-B TROJAN!No
InstallBuddyUIbtna.exeInstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSyncNo
IcaBarYicabar.exeRelated to Citrix MetaFrameNo
TlwgXicardresy.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
xxpsXiCare Data & Format Recovery Keygen.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
icasServXicasServ.exeBrowser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN!No
loveqqXICBServer.exeDetected by Malwarebytes Anti-Malware as Trojan.ChinAd. The file is located in %UserTemp%No
iedecaddXiccadd.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieDataNo
iediescaddXiccadd.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.CDAGen. The file is located in %AppData%\ieDataNo
ICcontrolXiccontrol.exeICcontrol premium rate adult content dialerNo
Internet Call DirectorUICD.EXETELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the InternetNo
AsicfcXicfca.exeDetected by Trend Micro as WORM_AGENT.AAJENo
ichckupdXichckupd.exeSurfSideKick.B adwareNo
{48DBCECD-61F9-DBB6-AB03-49E1901B80A7}Xichu.exeAdded by the MDROP-CZM TROJAN!No
iCleanUiClean.exeIEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"No
Sweep95YICLOAD95.EXEPart of an older version of Sophos anti-virus softwareNo
iCloudServicesUiCloudServices.exeApple iCloud support for Windows users which "lets you access your music, photos, calendars, contacts, documents, and more, from whatever device you're on"No
ICMUICM.EXEStarts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemailNo
Internet Call ManagerUICM.EXEStarts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemailNo
InterCheck MonitorYICMON.EXEPart of an older version of Sophos antivirus softwareNo
InterCheckMonitorYICMON.EXEPart of an older version of Sophos antivirus softwareNo
Enterra Icon KeeperUIcnKeepr.exeIcon Keeper - "tool to save and restore icon positions on the desktop"No
ICOUICO.EXEFound on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated gamesNo
Mouse Suite 98 DaemonUICO.EXEFound on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated gamesNo
ICON 225 USB Connect?ICON 225 USB Connect.exeRelated to the iCON 225 USB modem from Option - as provided by Orange. What does it do and is it required?No
Boingo Wireless UtilityUIcon###XXX#X#.exeStarts the Boingo Wireless utility, used to detect and login into Boingo wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start → ProgramsNo
iconcacheYicon.batRelated to the Vista Customization PackNo
Icon lptt01Xicon.exeRapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
Icon ml097eXicon.exeRapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
PocketCam 3Mega MonitorNICON.exeInstalled with the Aiptek PocketCam 3Mega digital camera. Automatically invokes an import process if the camera is connected and has media on itNo
ICON2 USB Connect?ICON2 USB Connect.exeRelated to the iCON2 USB modem from Option - as provided by Orange. What does it do and is it required?No
ICONCLNTYiconclnt.exeAPC PowerChute software which controls their range of uninterruptible power supplies (UPS) - to provide unattended shutdown of servers and workstations in the event of an extended power outage and status loggingNo
ICONDESKUICONDESK.EXESmall utility which will allow you the option of hiding or showing your desktop iconsNo
Iconfig.exeNIconfig.exeSystem Tray icon associated with a Shuttle Technology LS-120 SuperDisk - which is a high-speed, high-capacity alternative to the standard floppy diskNo
E-colorUIconMgr.ExeSets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the programNo
IconoidNIconoid.exeIconoid is a desktop icon managerNo
IconsaverNIconsaver.exeIconSaver is a desktop icon managerNo
DesktopXYIconX.exeIconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate downloadYes
IconXYIconX.exeIconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate downloadYes
IconX.exeYIconX.exeIconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate downloadYes
Internet Content PublisherXICP.EXEAdded by the RBOT-UD WORM!No
Avg AntivirusXicpldrvx.exeAdded by the BANKER.BYU TROJAN!No
MsconfigXicpldrvx.exeAdded by the BANLOAD.BFT TROJAN!No
Mirabilis ICQNicq.exeIf connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start → ProgramsNo
ICQ Messenger 2002XICQ2002.exeAdded by the SDBOT-ABL WORM!No
ICQ AgentXicq6.exeAdded by the AGENT-FZJ TROJAN!No
runappXicqchk.exeAdded by the BOMKA TROJAN!No
ICQ Chat ServiceXicqjdhs.exeAdded by a variant of Win32/RbotNo
ICQ LiteNICQLite.exeICQ Lite - compact version of the popular messaging programNo
ICQ Lite MessengerXICQLITE.EXEAdded by an unidentified VIRUS, WORM or TROJAN! The legitimate ICQ Lite executable is located in %ProgramFiles%\ICQLITE whereas this one is located in %System%No
ICQMonitorUICQMonitor.exeICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourselfNo
Mirabilis ICQNICQNet.exeAutomatically runs an old version of ICQ (when it was from Mirabilis) if connected to the internet. Convenience more than anythingNo
ICQXICQNET.vbsAdded by the GORMLEZ-A WORM!No
ICQ Hacking ProXICQpro.exeAdded by a variant of the NETSPY TROJAN!No
Windows UDP Control CenterXicqversin.exeAdded by the MDROP-DP MALWARE!No
Windows ExplorerXIcrypt.exeDetected by McAfee as Generic.dx!bcvd and by Malwarebytes Anti-Malware as Backdoor.BotNo
ICServerNIcserver.exeIntel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stationsNo
ICSMGRYICSMGR.EXEMonitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computersNo
someXicthis.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for detailsNo
^SetupICWDesktopNicwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start → All Programs → Accessories → Communication (or similar) anywayNo
Internet Connection Wizard Setup ToolXicwsetup.exeAdded by the PINCAV.HJK TROJAN!No
blah servicesXiczw.exeAdded by the RBOT-GMP WORM!No
stcinstallerXid53.exeDetected by Trend Micro as TROJ_SCTHOUGHT.LNo
Id8525Xid8525.exeAdded by the ID8525.A TROJAN!No
Id8525Xid85255.exeAdded by the ID8525.A TROJAN!No
IDA?IDA.EXEPart of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required?No
Internet Download AcceleratorUida.exeInternet Download Accelerator download manager from WestByte Software - "effectively solves three of the biggest problems when downloading files: speed, resuming broken downloads, and management of downloaded files"No
IDBoanXIDBoan.exeIDBoan rogue security software - not recommended, removal instructions hereNo
iWonIE Browser Plugin LoaderUidbrmon.exeIWON IE toolbar - powered by the MyWebSearch toolbar by Mindspark Interactive Network, Inc. Originally considered as adware until Mindspark took over (see here) and put in place a clearly defined EULA, with the toolbar now being installed by choice and easily removed. Recommended "U" status as it depends upon the version and whether you use itNo
ID CommanderNIDCom.exeCaller ID utility for identifying incoming telephone numbersNo
intdctrrXidctup20.exeAdded by a variant of Spyware.SafeSurfingNo
IDEXide.exeAdded by the ASSASIN.F TROJAN!No
IdecntlXidecntl.exeAdded by the GEMA TROJAN!No
IDE LoaderXIDElibr32.exeAdded by the XILON TROJAN! Related to the game "Diablo II"No
MS Service ManagerXidemoodp0cetka.exeDetected by Dr.Web as Win32.HLLW.Autoruner.52646 and by Malwarebytes Anti-Malware as Trojan.VBKryptNo
Data LifeGuard?identify.exePart of the Data LifeGuard diagnostic tools for Western Digital's series of hard drivesNo
iDesktopUidesktop.exeImmersion TouchWare Desktop software for devices such as the Logitech iFeel MouseNo
DetectUidetect.exeiNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabledNo
idfxaudsXidfxauds.exeDetected by McAfee as W32/Ramnit.a. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
ToPicks StarterXIdhost.exeToPicks adwareNo
IDMXIDM.exeDetected by Dr.Web as Trojan.Inject1.14260 and by Malwarebytes Anti-Malware as Trojan.Agent.BCMNo
ce034ed846a59de9fb1d175d940837e8XIDMan.exeDetected by Dr.Web as Trojan.DownLoader7.20094 and by Malwarebytes Anti-Malware as Trojan.AgentNo
IDManNIDMan.exeInternet Download Manager - download files faster, schedule and resumeNo
Internet download manager serviceXidman.exeAdded by the RBOT-BMS WORM!No
IdnMailXIdnMail.exeDetected by Malwarebytes Anti-Malware as PUP.CNNIC. The file is located in %System%No
IDrive TrayUIDriveEReg2ini.exeSystem Tray access to IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accountsNo
idriveServerUidriveProxy.exeProxy server for an older version of the IDrive backup utility from Pro Softnet CorporationNo
IDriveE StartupUIDrvieEStartup.exeIDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accounts. Required if you have scheduled backupsNo
IDTemplatesXIDTemplate.exeAdded by the BRONTOK-H WORM!No
Tok-CirrhatusXIDTemplate.exeAdded by the RONTOKBRO.A WORM!No
Windows Service AgentXidvcqv.exeAdded by the AGOBOT-AJB WORM!No
IdvmvuXIdvmvu.exeDetected by McAfee as Generic PWS.bfr!cNo
IDrive Background processUidwbg_501.exeBackground process for an older version of the IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accountsNo
IDW Logging ToolNidwlog.exeAdded with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problemsNo
IDrive MonitorUidwmonitor.exeMonitor for an older version of the IDrive online backup utility from Pro Softnet Corporation - free full featured online backup up to 5GB with the option of paying for more storage space and managing multiple accountsNo
IndexCleanerUIdxClnR.exeUtility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon OnlineYes
CCWC7IUidxl.exeMoleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for freeNo
TGPro OfficeNIdxOffice.exeWith IdiomaX Office Translator "you can translate documents directly from your favorite text editor (Microsoft Word, WordPerfect or Lotus WordPro)"No
syswin.txtXidz.exeAdded by the SDBOT.AGT WORM!No
IE**.exe [* = random char]XIE**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
IE**32.exe [* = random char]XIE**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
1b8e01fc029dc426f50dc397ed5ce576XIE.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
360saftXie.exeDetected by Sophos as Mal/PWS-CS and by Malwarebytes Anti-Malware as Trojan.AgentNo
Microsoft Internet Explorer ManagerXie.exeDetected by Microsoft as Worm:Win32/Slenfbot.JD and by Malwarebytes Anti-Malware as Backdoor.BotNo
IEXIE2012.exeDetected by McAfee as RDN/Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
ieLiveXie32.exeDetected by Kaspersky as Trojan.Win32.Scar.cgsyNo
FBSSAXie3sh.exeFast Browser Search/Search Guard Plus parasite - installed with "Make the Web Better" applications such as My Web Tattoo, My Face LOL and Google Easy Money Kit. See here and here for more informationNo
OlympicXIE4321.exeAdult content premium rate dialer - also detected as SMALL.CZNo
iExplore IniXie4uini.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
ieLive 512Xie512.exeDetected by Kaspersky as Trojan.Win32.Scar.cnlhNo
ieLive 512Xie512b.exeDetected by Kaspersky as Trojan.Win32.Scar.cootNo
Microsoft Internet ExplorerXie8.exeAdded by the BANKER-FBF TROJAN!No
IE8XIE8.pifDetected by Sophos as Troj/Agent-ABSS and by Malwarebytes Anti-Malware as Trojan.Agent.PFINo
ie8upXie8update.exeDetected by Dr.Web as Trojan.Siggen4.62713 and by Malwarebytes Anti-Malware as Backdoor.BotNo
antispyXieav.exeIE AntiVirus rogue security software - not recommended, removal instructions hereNo
kokvXiebar.exeDesktopMedia A adwareNo
IECleanAuxUIeboot6.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startupNo
AhstXiebs.exePurityScan adwareNo
startXiebtm.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for detailsNo
IECacheXIECache.exeDetected by Bitdefender as the DELF.OFC TROJAN! See hereNo
iecheckNiecheck.exeIntegrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2No
iedllXiedll.exeHomepage hijacker, redirecting to coolwwwsearch.comNo
IE DoctorUIEDoctor.exeIE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"No
IEDriverXIEDriver.exeIEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlazeNo
MicrosoftXiedw.exeDetected by Malwarebytes Anti-Malware as Trojan.VBAgent. The file is located in %System%\internet explorerNo
PoliciesXiedw.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %System%\internet explorerNo
iedwa104Xiedwa104.exeAdded by the DLOADR-BBW TROJAN!No
Config LoadationXiEEexplore.exeAdded by the SDBOT.H TROJAN!No
IEengineXIEeng.exeSTARTPAG.AI TROJAN!No
Microsoft IE Execute shellXIEExec.exeAdded by the ALADINZ.N TROJAN!No
Internet Explorer6XIEexplore.exeDetected by Trend Micro as WORM_RBOT.AGC. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
IEexplorer AUpdateXIEexplore32.exeAdded by the RBOT-GRE WORM!No
Miscrosoft Windows ExplorerXIEEXPLORER.exeReported as the SDBOT.YX WORM!No
IEFeaturesXiefeatures.exeAdded by the POPMON.A TROJAN - also known as PopMonster adwareNo
MSVersionXiefeaturesversion.exeDetected by Trend Micro as TROJ_POPMON.A and by Malwarebytes Anti-Malware as Trojan.PopMon. Also known as PopMonster adwareNo
iefixXiefix.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\iexplorerNo
IefxTrayXIefxTray.exeAdded by the RILER-H TROJAN!No
ieharv.exeXieharv.exeDetected by Sophos as Troj/Banker-HHNo
[various names]Xiehelper.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
BakraXIEHost.EXEAdded by the MULTIDR-AH TROJAN!No
IE Java UpdateXiejava.exeDetected by Sophos as Troj/Agent-HDNo
FXXieloader.exeAdded by the SMALL.RR TROJAN!No
IE New Window MaximizerUiemaximizer.exeIE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windowsNo
chkdrvXiemon.exeDetected by Symantec as the ADCLICKER TROJAN!No
Internet ExplorerXIEPLORE32.EXEAdded by the AGOBOT-CU WORM!No
DriversXieplorer.exeDetected by McAfee as Generic.bfrNo
PoliciesXieplorer.exeDetected by McAfee as Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent.PgenNo
SoftwaresXieplorer.exeDetected by McAfee as Generic.bfrNo
kxswsoftXierdfgh.exeAdded by the AUTORUN-AAT WORM!No
IesarXIesar.exeBrowser hijacker - redirecting to an adult web pageNo
IE-SecurityXiescan.exeIE-Security rogue spyware remover - not recommended, removal instructions hereNo
Iesearch.exeXIesearch.exeLookNSearch adwareNo
MSNXiesec.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.34010 and by Malwarebytes Anti-Malware as Backdoor.BotNo
Microsoft IT UpdateXIEserv.exeAdded by a variant of Win32/RbotNo
IEServerUIEServer.exeHB Screen Spy surveillance software. Uninstall this software unless you put it there yourselfNo
\IEService.exeXIEService.exeFastFind adware variantNo
Winsock6 MIC driverXieservicesupd.exeAdded by the SPYBOT.AFZ WORM!No
[various names]Xiesetupdll.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
iesetupi.exeXiesetupi.exeAdded by a variant of Win32/RbotNo
BitDefender 2009YIEShow.exeAnti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. This entry is from the 2009 versions. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYes
BitDefender Antiphishing HelperYIEShow.exeAnti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYes
IEShowYIEShow.exeAnti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYes
IESideXIESide.exeDetected by Dr.Web as Trojan.StartPage.48053 and by Malwarebytes Anti-Malware as Adware.KorAdNo
NETWIREXIESM.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.NW. The file is located in %AppData%\microsoftNo
IETabXIETab.exeDetected by Dr.Web as Trojan.DownLoader6.33407 and by Malwarebytes Anti-Malware as Adware.KorAdNo
ietsrNietsr.exeIEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etcNo
IeudinitXieudinit.exe /waitserviceDetected by Microsoft as TrojanDownloader:Win32/Horst.Q. Note - this is not the legitimate ieudinit.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\driversNo
Microsoft Internet Explorer UpdateXieupdate.exeAdded by the SHEUR.MH TROJAN!No
window2Xieupdate.exeAdded by the FORBOT-BM WORM!No
ieupdateXieupdates.exeAdded by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see hereNo
PoliciesXieupdates.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note that this is not a valid Internet Explorer process and the file is located in %System%\IEupdatesNo
Realtek HD AudioXieupdates.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. Note that this is not a valid Realtek or Internet Explorer process and the file is located in %System%\IEupdatesNo
IEAgent update checkXiewatch.exeAdded by the BOMKA TROJAN!No
CapricornXiexeplore.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Trojan.AgentNo
360saftXiexp.batDetected by Dr.Web as Trojan.AVKill.29649 and by Malwarebytes Anti-Malware as Trojan.AgentNo
fuXiexp1ore.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. Note the number "1" in place of a lower case "L" in the filename - which is located in %Windir%No
iestartXiexp1orer.exeAdded by the NEMOG.C TROJAN!No
SysResXIExpIore .exeAdded by the ELITPER.E WORM!No
Default web browserXIexpIore.exeAdded by the OBLIVION.B TROJAN! Note - do not confuse "iexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a capital "i" in place of lower case "L"No
iexpiore.exeXiexpiore.exeDetected by Dr.Web as Trojan.Click2.51385 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Internet ExplorerXiexpiore.exeAdded by the RBOT-AZC WORM!No
winprofileXiexpiore.exeAdded by a variant of the MONCHER WORM!No
WinProfileXiexpIore.exeAdded by the CHUM-C TROJAN!No
[random name]Xiexpl0ra.exeDetected by Trend Micro as TROJ_ULPM.BDNo
[empty]Xiexpl0re.exeAdded by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name fieldNo
Configuration LoaderXIEXPL0RE.EXEAdded by the SDBOT BACKDOOR! Note the number "0" in the filenameNo
hriXiexpl0re.exeAdded by the DLOADER.MAQ TROJAN! Note the number "0" in the filenameNo
Micrsoft Internet ExplorerXIEXPL0RE.EXEAdded by the RBOT-AQV WORM! Note the number "0" in the filenameNo
myMh2Xiexpl0re.exeAdded by the AGENT.HWE TROJAN! Note the number "0" in the filenameNo
ravshellXiexpl0re.exeAdded by the NOFERE-A TROJAN! Note the number "0" in the filenameNo
ravtaskXiexpl0re.exeAdded by the AGENT.AIR BACKDOOR! Note the number "0" in the filenameNo
SystemXIEXPL0RE.EXEAdded by the VB.KS WORM! Note the number "0" in the filenameNo
WinStarXIEXPL0RE.exeAdded by the WOSRIST A TROJAN!No
IEXPL0RERXIEXPL0RER.EXEAdded by the AGOBOT-QL WORM! Note the filename has a "0" rather than an upper case "o"No
supdateXIEXPL0RER.exeDetected by McAfee as Generic Flooder!bu. Note the filename has a number "0" rather than an upper case "o"No
Windows serviceXiexpl0rer.exeDetected by Trend Micro as WORM_SDBOT.RONo
@Xiexpl0res.exeDetected by Trend Micro as WORM_RBOT.AEXNo
AntivirusXiexpl0res.exeAdded by an unidentified WORM or TROJAN!No
IexploitXIexploit.htmlAdded by the INKER.B WORM!No
ServicesXiexploler.exeAdded by the RANCK-LT TROJAN!No
AtxBrwXIexplor.exe"Pop Marketing" adwareNo
C:\WINDOWS\IEXPLOR.EXEXIEXPLOR.EXE"Pop Marketing" adwareNo
iexploXiexplor.exeAdded by the SIDEA TROJAN!No
iexplor.exeXiexplor.exeAdded by an unidentified WORM or TROJAN! See hereNo
winsockdriverXiexplor.exeAdded by the BLATIC.A WORM!No
IExplorerXIexplor32.exeDetected by Sophos as Troj/Bdoor-BY and by Malwarebytes Anti-Malware as Trojan.AgentNo
Macromedia DriveXIexplor32.exeAdded by a variant of Win32/RbotNo
(Default)Xiexplorar.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %System%No
l44sys**XiexploreAdded by the VBS.LIDO WORM - where ** is a number between 65 and 76No
mssysintXIexplore .exeDetected by Symantec as Infostealer.ABCHlp and by Malwarebytes Anti-Malware as Backdoor.Agent.MINS. Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe"No
ProtectionXIExplore .exeAdded by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe"No
Winsock2 driverXIEXPLORE .EXEAdded by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe"No
$WindowsRegKey%updateXIEXPLORE.EXEAdded by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
488596faa0c68c3088c3447571a95cbdXiexplore.exeDetected by Dr.Web as Trojan.Siggen4.12852 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
cmssappXiexplore.exeDetected by Sophos as Troj/Bancban-GF. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Configuration LoaderXIEXPLORE.EXEAdded by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Explorer UpdaterXIEXPLORE.exeAdded by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
IE Security LoaderXiexplore.exeDetected by Trend Micro as BKDR_WOOTBOT.I. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
iexploreXiexplore.exeDetected by Sophos as Troj/Banker-BWE. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
IExploreXIEXPLORE.EXEAdded by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a "Custom" subfolderNo
IexploreXiexplore.exeAdded by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
IEXPLOREXiexplore.exeAdded by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Iexplore ServicesXiexplore.exeAdded by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!No
Iexplore.exeXIexplore.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft\System\ServicesNo
Intel?Xiexplore.exeDetected by Dr.Web as Trojan.Siggen5.23631 and by Malwarebytes Anti-Malware as Backdoor.Agent.ITN. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AllUsersProfile%\kernel64No
Internet ExplorerXIEXPLORE.EXEAdded by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Internet Explorer ConfigurationXIEXPLORE.EXEAdded by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Internet Explorer6.0XIEXPLORE.EXEAdded by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
IntespentionXIEXPLORE.exeAdded by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Java RuntimesXiexplore.exeAdded by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in %Windir%\Java\JavaNo
MicrosoftXiexplore.exeAdded by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Microsoft IEXIexplore.exeAdded by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Microsoft Internet ExplorerXiexplore.exeAdded by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Microsoft Windows (D)Xiexplore.exeIdentified as a variant of the TrojanSpy.Agent malwareNo
Microsoft©Xiexplore.exeAdded by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcacheNo
msmsgs.exeXIEXPLORE.EXEAdded by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
nternet ExplorerXiexplore.exeAdded by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
OPTIMIZERXiexplore.exeAdded by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
OPTIMIZERXiexplore.exeAdded by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Program in WindowsXIEXPLORE.exeAdded by the LOVGATE.AB WORM!No
ServicesXiexplore.exeAdded by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Setup Windows Media PlayerXiexplore.exeDetected by Dr.Web as Trojan.DownLoader7.32087 and by Malwarebytes Anti-Malware as Trojan.Agent.SWM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %AppData%No
Shell32Xiexplore.exeAdded by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
ShellRun32Xiexplore.exeAdded by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
slideXIexplore.exeAdded by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!No
starterXiexplore.exeAdded by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
System ConfigurationXiexplore.exeAdded by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
System Information ManagerXiexplore.exeAdded by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Telephony ProviderXIexplore.exeAdded by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
windowsXiexplore.exeAdded by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Windows Configuration SystemXIExplore.exeAdded by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
windows Live MessengerXiexplore.exeAdded by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows ServicesXiexplore.exeDetected by Sophos as W32/Rbot-WE and by Malwarebytes Anti-Malware as Backdoor.Agent.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
WINDOWS SYSTEM CLEANERXiexplore.exeAdded by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Windows USB Control DriverXiexplore.exeAdded by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
Windows Vista TransformationXIEXPLORE.exeAdded by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
WindowsUpdate renewXiexplore.exeAdded by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%No
ZonealarmXiexplore.exeAdded by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%No
Configuration LoadrXiexplore.exeeAdded by an unidentified WORM or TROJAN!No
Internet Explorer SecurityXiexplore.pifAdded by the RBOT-ALQ WORM!No
IELoader32Xiexplore32.exeAdded by the SPEX or SPEX.B WORMS!No
InternetExplorer32Xiexplore32.exeAdded by the RBOT-GRA WORM!No
IExplorer6 Java ScriptingXIExplore326.exeAdded by the RBOT.ANR WORM!No
IExplorer7 Java ScriptingXIExplore327.exeAdded by a variant of W32/Sdbot.wormNo
IExplorer32 Java ScriptingXIExplore32b.exeDetected by Trend Micro as WORM_RBOT.ABONo
IExplorer32c Java ScriptingXIExplore32cb.exeDetected by Trend Micro as WORM_RBOT.ABNNo
IExplorer8 Java ScriptingXIExplore8.exeDetected by Trend Micro as WORM_RBOT.CAG and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Configuration LoadedXiexploree.exeAdded by the SDBOT-KC WORM!No
iexplorenetXiexplorenet.exeDetected by Dr.Web as Trojan.AVKill.22042 and by Malwarebytes Anti-Malware as Trojan.BankerNo
ALG.EXEXiexplorer .exeAdded by the DEMOTRY-B WORM!No
IESetXIExplorer.dllAdded by the PWS-BLUEDIT TROJAN!No
(Default)Xiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% and this is not the legitimate Internet Explorer (iexplore.exe). Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
(Default)Xiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %System% and this is not the legitimate Internet Explorer (iexplore.exe). Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
*iexplorerXiexplorer.exeDetected by McAfee as BackDoor-AWQ.d. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%No
.netshrinkXiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
HKCUXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet ExplorerNo
HKCUXiexplorer.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\installNo
HKCUXiexplorer.exeDetected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet ExplorerNo
HKCUXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\installNo
HKLMXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet ExplorerNo
HKLMXiexplorer.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\installNo
HKLMXiexplorer.exeDetected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet ExplorerNo
HKLMXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\installNo
IE Security LoaderXiexplorer.exeAdded by a variant of BKDR_WOOTBOT.I. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%No
IExplorerXIExplorer.EXEDetected by Sophos as Troj/Bancos-CH and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%No
IexplorerXiexplorer.exeDetected by Dr.Web as Trojan.PWS.Siggen.41334 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%No
iexplorerXiexplorer.exeDetected by McAfee as BackDoor-AWQ.d and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%No
iexplorer lptt01Xiexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
iexplorer ml097eXiexplorer.exeRapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove itNo
iexplorer.exeXiexplorer.exeDetected by McAfee as RDN/Generic.dx!ba. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file is located in %AppData%\eniMbuPhc\SxGHFKvov\4.18.47.9562No
Iexplorer.exeXIexplorer.exeDetected by Sophos as Troj/Bancban-EN. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file is located in %Windir%No
Internet ExplorerXIExplorer.exeDetected by Sophos as Troj/Nethief-O. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file loads from %System% via the HKLM\Run registry keyNo
Internet ExplorerXiexplorer.exeDetected by Symantec as W32.Lorsis.Worm. Note - this is not the legitimate Internet Explorer (iexplore.exe) and the file loads from %Windir%\System via the HKLM\RunServices registry keyNo
Internet Explorer AgentXiexplorer.exeAdded by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Internet Explorer UpdaterXiexplorer.exeAdded by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
irwftpXiexplorer.exeDetected by Sophos as Troj/Banker-AN. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
kernel32sys.dllXIEXPLORER.exeDetected by Sophos as W32/Rbot-MK. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
MAUDIOXiexplorer.exeDetected by McAfee as BackDoor-CZP.dr and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%No
Media PlayerXiexplorer.exeDetected by Trend Micro as TSPY_BANKER.MW. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Microsoft Associates, Inc.Xiexplorer.exeAdded by the LOVGATE.Z WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Microsoft Inc.Xiexplorer.exeDetected by Trend Micro as WORM_LOVGATE.E. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Microsoft Internet ExplorerXiexplorer.exeAdded by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Microsoft Windows ExplorerXiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MWF.Gen. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Msn MessengeXIExplorer.exeAdded by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
MSN MessengerXIExplorer.exeDetected by Sophos as Troj/Banker-FB. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
msqXiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.Dropper.OL. The file is located in %System% and this is not the legitimate Internet Explorer (iexplore.exe)No
PCMONITORXiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.QHost.WNT. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%No
PoliciesXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.rlb and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %ProgramFiles%\Internet ExplorerNo
PoliciesXiexplorer.exeDetected by Kaspersky as Trojan.Win32.VBKrypt.cuc and by Malwarebytes Anti-Malware as Trojan.Backdoor. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\installNo
PoliciesXiexplorer.exeDetected by Trend Micro as BKDR_POISON.BPY and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %System%\Internet ExplorerNo
PoliciesXiexplorer.exeDetected by Kaspersky as Trojan.Win32.Llac.yyo and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %Windir%\installNo
RavshellXIEXPLORER.EXEAdded by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
ServicesXiexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
SxGHFKvovXiexplorer.exeDetected by McAfee as RDN/Generic.dx!ba and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
syscheckXiexplorer.exeAdded by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
sysconfigXiexplorer.exeAdded by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Windows Backup ConfigurationXIEXPLORER.exeAdded by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Windows ExplorerXiexplorer.exeDetected by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the legitimate Internet Explorer (iexplore.exe). The file is located in %UserProfile%\msdataNo
Windows Internet ExplorerXiexplorer.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Windows TaskmanagerXiexplorer.exeAdded by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Windows UDP Control CenterXiexplorer.exeAdded by the POISON-CJ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
winnt DNS identXiexplorer.exeAdded by a variant of Win32/Rbot. Note - this is not the legitimate Internet Explorer (iexplore.exe)No
WINTASKXiexplorer.exeAdded by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
WinVNCXiexplorer.exeAdded by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Yahoo MessenggerXIEXPLORER.exeAdded by the AUTORUN-BDN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
Microsoft Inc.Xiexplorer.exe...Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)No
NameXIexplorer0.exeAdded by the THREADSYS TROJAN!No
Microsoft DevXiexplorer32.exeAdded by a variant of the AGOBOT WORM!No
Microsoft Driver SetupXiexplorer7.exeDetected by Avira as Worm/Pushbot.7577No
iexplorere loaderXiexplorere.exeAdded by the SDBOT.SS WORM!No
Windows UpdateXiexplorere.exeDetected by Symantec as W32.HLLW.Gaobot.AP and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Iexplorerr.exeXIexplorerr.exeAdded by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gfNo
Iexplorerr.exeXIexplorerr.exeAdded by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logsNo
Windows UpdaterXiexplorerrs.exeDetected by Sophos as W32/Rbot-TN and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
iexplorers loaderXiexplorers.exeAdded by the SDBOT-DQ BACKDOOR!No
Yahoo MessenggerXIEXPLORERS.exeAdded by the AUTOIT.DH TROJAN!No
Microsoft Machine ScriptXiexplorersis.exeAdded by the RBOT-CMH WORM!No
Start UppingXiexplorerupdt.exeAdded by the RBOT-RR WORM!No
Update ExplorerXiexploreupd.exeAdded by a variant of Win32/RbotNo
cmssappXiexplore_.exeDetected by Sophos as Troj/Bancban-CQNo
DebuggerXiexplore_dbg.exeAdded by the CWS-M TROJAN!No
IExplUpdXIExplUpd.exeAdded by the MDROP-CXY TROJAN!No
ServicesXiexpolere.exeAdded by the RANCK.LU TROJAN!No
MSStartOptimizerXIEXPRES.EXEDetected by Sophos as Troj/Dasmin-FamNo
iExpresserXiexpresser.exeAdded by the SLENFBOT.AP WORM!No
MSIMEXiexprohlp.exeAdded by the MDROP-CVV TROJAN!No
Microsoft OpeionsXIEXwe.exeAdded by a variant of Win32/RbotNo
bantoolXie_ban.exeDetected as the VB.PO TROJAN!No
signupXie_signup.exeDetected by Kaspersky as Trojan.Win32.Agent.suub and by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %AppData%\signupNo
IExplorer UtilXie_util.exeDetected by Dr.Web as Trojan.Inject1.13820 and by Malwarebytes Anti-Malware as Trojan.Ransom.BLKNo
(Default)Xifconfig.exeAdded by the RBOT-GFW WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run, HKLM\RunServices and HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blankNo
Adobe ARMXifgxpers.exeDetected by Dr.Web as BackDoor.Gbot.2374 and by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this is not the legitimate Adobe update manager (AbodeARM.exe). The file is located in %AppData%No
Adobe ARMXifgxpers.exeDetected by Sophos as Troj/Tobfy-C and by Malwarebytes Anti-Malware as Trojan.FakeMS. Note - this is not the legitimate Adobe update manager (AbodeARM.exe). The file is located in %CommonAppData%No
LmihNjzSczsUOFeQZJkVKCBFozXifkf_mfLEnWa_g.exeDetected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Trojan.Agent.PLR. Note - this entry loads from %System% via the HKCU\Run registry keyNo
LmihNjzSczsUOFeQZJkVKCBFozXifkf_mfLEnWa_g.exeDetected by McAfee as RDN/Generic.bfr!g and by Malwarebytes Anti-Malware as Trojan.Agent.RND. Note - this entry loads from %System% via the HKCU\Policies\Explorer\Run registry keyNo
IPKRunXIfkmain.exeIPKRun rogue security software - not recommended, removal instructions hereNo
iFrmewrkYifrmewrk.exeIntel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display"Yes
Intel(R) PROSet/WirelessYifrmewrk.exeIntel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display"Yes
IntelPANYiFrmewrk.exeIntel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display"No
IntelPROSetYiFrmewrk.exeIntel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display"No
IntelWirelessYifrmewrk.exeIntel PROSet/Wireless management utility including an optional System Tray icon and support for their My WiFi technology - which is included with Centrino wireless products and "transforms your Windows 7 laptop into a Wi-Fi Personal Area Network and enables you wirelessly share your videos, photos, music or the Internet from your laptop to your HDTV with Intel Wireless Display"Yes
IFSplash.exeUIFSplash.exeI-FORCE driver for force feedback steering wheelNo
IFXSPMGTUifxspmgt.exePart of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer, ASUS, HP and SonyNo
Microsoft ValuesXigfkishc.exeAdded by the RBOT-GLO WORM!No
f78ab46e149d2ce1a6b721640ed25616Xigfsystem.exeDetected by McAfee as RDN/Generic.dx!bcj and by Malwarebytes Anti-Malware as Trojan.MSILNo
Intel Software UpdateXigfxau64.exeDetected by Dr.Web as Win32.HLLW.Autoruner1.25469 and by Malwarebytes Anti-Malware as Trojan.AgentNo
Intel iDisplay CoreXigfxbj32.exeDetected by Dr.Web as BackDoor.IRC.Bot.1818No
Intel Display ControlXigfxdc64.exeDetected by Malwarebytes Anti-Malware as Trojan.Fakeintel. The file is located in %System%No
Intel Display ControlXigfxdc64.exeDetected by Malwarebytes Anti-Malware as Trojan.Fakeintel. The file is located in %UserProfile%\NetworkNo
PoliciesXigfxhost.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Windir%\IndexNo
Intel iDevice DriverXigfxks32.exeDetected by Dr.Web as BackDoor.IRC.Bot.1819No
Intel Driver ManagerXigfxpd86.exeDetected by Dr.Web as BackDoor.IRC.Bot.1536No
cmstrpXigfxperf.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%\MicrosoftNo
ctrlmestartupXigfxperf.exeDetected by Malwarebytes Anti-Malware as Trojan.Fakealert. The file is located in %AppData%\MicrosoftNo
igfxpersUigfxpers.exeInstalled with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" statusYes
Intel(R) Common User InterfaceUigfxpers.exeInstalled with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" statusYes
PersistenceUigfxpers.exeInstalled with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. One observed function is that on some notebooks/netbooks it can change the resolution during startup from reduce to full. Otherwise, its purpose or function isn't known at present but users may be able to disable it without any problems - hence the recommended "U" statusYes
RegistryMonitor1Xigfxpers.exeAdded by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filenameNo
hurggbesytXigfxrptgx.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
lgxfsrvcXigfxsrvc.exeAdded by the AUTORUN-BPQ WORM!No
MicroSoft Visual SP2Xigfxsrvc32.exeDetected by Trend Micro as WORM_SDBOT.GAV. The file is located in %System%No
Intel Task ManagementXigfxtm32.exeAdded by the KOLAB.WWH WORM!No
premiumXigfxtrai.exeAdded by the DLOADR-DDX TROJAN!No
igfxtrayXigfxtray.exeDetected by McAfee as BackDoor-EZG.d and by Malwarebytes Anti-Malware as Trojan.Downloader. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %AppData%\igfxNo
IgfxTrayUigfxtray.exeSystem Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and hot key settings via the icon on the System Tray. Different chipset versions may have different options available. These options are normally also available via the system Control Panel - under Display (XP) or Personalization and Appearance (Vista)Yes
igfxtrayXigfxtray.exeDetected by Dr.Web as Trojan.Carberp.33 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
igfxtray ModuleXigfxtray.exeAdded by the VB-RI MALWARE! Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %Windir%No
Intel CprporationXigfxtray.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the legitimate Intel graphics System Tray utility which has the same filename and is located in %System%. This one is located in %ProgramFiles%\igfxtrayNo
Intel(R) Common User InterfaceUigfxtray.exeSystem Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and hot key settings via the icon on the System Tray. Different chipset versions may have different options available. These options are normally also available via the system Control Panel - under Display (XP) or Personalization and Appearance (Vista)Yes
WUPDXiglmtray.exeAdded by the TZET WORM!No
Iglpbv?Iglpbv.exe??No
MS WINS BinaryXign32.pifAdded by the RBOT-ASB WORM!No
mnu?igomnu.exeWanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?No
lspinsXigps.exeDetected by Kaspersky as the VB.KC TROJAN!No
igsex2xXigsex2x.exeNewDial premium rate adult content diallerNo
IGuardPc.exeXIGuardPc.exeIGuardPc rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
MicroSoft Visual SPXigxdfdfds.comAdded by the SDBOT.GAV WORM!No
NcuaXihoo.exePurityScan adwareNo
iHP-100?iHPDetect.exeDrive Letter Searcher, iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time?No
Net iDUiid.exe"With the Net_iD program, you can easily and securely logon with a smart card into a domain, a virtual private network (VPN) or in Citrix and Terminal Server environments"No
MicrosoftXiiexplore.exeDetected by Trend Micro as WORM_SDBOT.TENo
Microsoft Internet ExpXiiexplorer.exeAdded by the RBOT-KX WORM!No
NavegateXiiexplorer.exeAdded by the BANCBAN-OP TROJAN!No
iilcXIILC.EXEHomepage hijackerNo
MSConfigXiirqcobd.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
Intel system worksXiis.exeAdded by the RBOT.QGA WORM!No
gtydfXiisca.exeAdded by the CLAGGER-BB TROJAN!No
iisversXiisvers.exeAdded by unidentified malware. The file is located in %Windir%No
IJ75P2PSERVERYIJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctlyNo
IKE Service 95YIKEService.exeAssociated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anythingNo
IBM Keyboard DriverXikeybdrv.exeAdded by the SDBOT.IC BACKDOOR!No
iKeyWorksUIkeymain.exeA4Tech wireless keyboard driver and utilityNo
AttacherXIkhwan.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AT. The file is located in %System%No
Iknhxbthwzltaibx.exeXIknhxbthwzltaibx.exeDetected by Malwarebytes Anti-Malware as Trojan.PWS.IRCBot. The file is located in %AppData%No
iLeAAmvQHHaCXiLeAAmvQHHaC.exeAdded by the FAKEAV-DIN TROJAN!No
boy lovers of bsdXilikeboys.exeDetected by Trend Micro as WORM_MYTOB.LYNo
iLikeNilikesidebar.exeiLike Sidebar for iTunes and Windows Media PlayerNo
goolgeiLive.exeXiLive.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %Root%\exiploresNo
msngXiLive.exeDetected by Malwarebytes Anti-Malware as Spyware.Banker. The file is located in %Root%\winx32No
reluvageXilulupac.exeAdded by the SDBOT-UJ WORM!No
iLyricUiLyric.exeiLyric plugin for the popular Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button. Not longer availableNo
IMprocessXIM-svr.EXEIMNames adwareNo
AIM AutoRunXIM.exeDetected by McAfee as Generic StartPage!bgl and by Malwarebytes Anti-Malware as Trojan.VBAgent. Note - this entry has nothing to do with the AOL Instant Messenger (AIM)No
ISSXim.exeDetected by McAfee as PWS-Zbot-FAJX!98E04F0440D9 and by Malwarebytes Anti-Malware as Trojan.Agent.SINo
Office DesktopsXimag.exeAdded by the SPYBOT.AQR WORM!No
78ee591d3d1cea63061844894185d677Ximage .exeDetected by Dr.Web as Trojan.DownLoader8.30090 and by Malwarebytes Anti-Malware as Trojan.Agent.PECNo
ff70ef8c4d237338eda652592ce24d91Ximage.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.MSILNo
Image & RestoreYIMAGE32.exePart of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently runNo
ImageDrive-{hex numbers}UImageDrive.exeNero ImageDrive from Ahead - virtual CD/DVD drive softwareNo
ImagefoxUimagefox.exeImageFox 2.0 (formerly available from ACDSee) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxesNo
Imagemgt32XImagemgt32.exeAdded by the GEMA TROJAN!No
ImageViewerXImageViewer.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%No
ImatioUimation.exeImation Disk Manager - enables you to create a password protected area on your Imation USB flash driveNo
imchatXimchat.exeAdded by a variant of the IRCBOT BACKDOOR!No
Microsoft UpdateXimchemaoa.exeAdded by the BANLOAD.KWQ TROJAN!No
HKCUXIMD.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\HM - see hereNo
HKLMXIMD.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %AppData%\HM - see hereNo
PoliciesXIMD.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %AppData%\HM - see hereNo
123456XIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMINNo
[various names]XIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file can be located in a "DCSCMIN" sub-folder in a number of locations including (but not limited to) %System%, %MyDocuments%, %Temp% & %AppData%No
Adobe_ARMXIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserTemp%\DCSCMINNo
CleanerXIMDCSC.exeDetected by McAfee as Generic BackDoor!fcw and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
DarkComet RATXIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file can be located in a "DCSCMIN" sub-folder in a number of locations including (but not limited to) %System%, %MyDocuments%, %Temp% & %AppData%No
ekbfjzefbgjhXIMDCSC.exeDetected by Dr.Web as Trojan.DownLoader6.995 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
IMDCSC.exeXIMDCSC.exeDetected by Dr.Web as Trojan.DownLoader6.59147 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMINNo
IMDCSC.exeXIMDCSC.exeDetected by Dr.Web as Trojan.DownLoader7.22053 and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserProfile%\Desktop\DCSCMINNo
Img CodecXIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %UserTemp%\DCSCMINNo
JavaUpdateXIMDCSC.exeDetected by Dr.Web as Trojan.Inject1.1577 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
JavaUpdaterXIMDCSC.exeDetected by Dr.Web as Trojan.Inject1.1573 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
King AluxXIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMINNo
MicrosoftXIMDCSC.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
NetXIMDCSC.exeDetected by Dr.Web as Trojan.DownLoader6.40541 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
SoundmanXIMDCSC.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\DCSCMINNo
SYST32XIMDCSC.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
system411XIMDCSC.exeDetected by Dr.Web as Trojan.DownLoader7.22053 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
TeamXIMDCSC.exeDetected by McAfee as Generic BackDoor!fq3 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
Team CrackersXIMDCSC.exeDetected by McAfee as PWS-FAHB!90FB97AF0885 and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
WindefenderXIMDCSC.exeDetected by McAfee as Generic BackDoor and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
WWWinXIMDCSC.exeDetected by Symantec as Trojan.Klovbot and by Malwarebytes Anti-Malware as Backdoor.Agent.DCNo
SYSDATAKEYXIMDCSVC.exeDetected by McAfee as Generic BackDoor!fpx and by Malwarebytes Anti-Malware as Backdoor.Agent.DCGenNo
IMEJPDADMXimejpdadm.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%\MicrosoftLiveNo
imekrmigNimekrmig.exeMicrosoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelNo
IMEKRMIG6.1NIMEKRMIG.EXEMicrosoft's Input Method Editor for the Korean language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelNo
ImeshNiMesh.exeImesh peer-to-peer (P2P) file-sharing client. As large amounts of data is shared between multiple users make sure you have good, up-to-date virus protection and check any downloadsNo
IMEvtMgr.exeXIMEvtMgr.exeAdded by the KEYLOG-AR TROJAN!No
(Default)XIMF.exeDetected by Dr.Web as Trojan.DownLoader7.12453 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %UserStartup%No
IMFXIMF.exeDetected by Dr.Web as Trojan.DownLoader7.12453 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
IObit Malware FighterUIMF.exeIObit Malware Fighter optimization utility from IObit - "is an advanced malware & spyware removal utility that detects, removes the deepest infections, and protects your PC from various potential spyware, adware, trojans, keyloggers, bots, worms, and hijackers." Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upNo
ImgIconUImgIcon.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon runningNo
Iomega Disk IconsUimgicon.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon runningNo
Iomega Drive IconsUImgIcon.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon runningNo
Zip Disk IconsUIMGICON.exeDisplays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start → Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon runningNo
GlobalFlagimglogXimglog.exeDetected by Sophos as Troj/Agent-GYKNo
darkXimgrt.scrDetected by Sophos as Troj/Bancban-FH and by Malwarebytes Anti-Malware as Trojan.BankerNo
Audio THXHDXimgsafe.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.BCM. The file is located in %AppData%\TviewerNo
darkXimgst.scrDetected by Symantec as Infostealer.Bancos.U and by Malwarebytes Anti-Malware as Trojan.BankerNo
ImgStartNImgStart.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start → ProgramsNo
Iomega Startup OptionsNImgStart.exeUsed by Iomega drives. Details of its purpose can be found here. Available via Start → ProgramsNo
ImgTaskNImgtask.exeRelated to the WalletPix digital photo album. "On some computers, the Wallet Pix device will leave behind a memory-resident file called ImgTask.exe. This file will be located in the operating system directory on your computer (typically %Windir%). You can remove this file at any time and it will not impact your computer's performance or functionality. The file will be restored each time you plug in the Wallet Pix though"No
Iomega ImIconXPUimiconxp.exeIomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disksNo
IMIIconXIMIIcon.exeDetected by McAfee as FakeAV-N.bfrNo
StringsXIMJDC01.exeDetected by Dr.Web as Trojan.Inject1.18505 and by Malwarebytes Anti-Malware as Trojan.AgentNo
IMJPMIGUIMJPMIG.EXEMicrosoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelYes
IMJPMIG8.1UIMJPMIG.EXEMicrosoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelYes
IMJPMIG9.0UIMJPMIG.EXEMicrosoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelNo
Microsoft IME 2002UIMJPMIG.EXEMicrosoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails, documents, web forms and other files - should you need to. Found on PCs where East Asian languages have been installed through the Regional and Language options icon in the Control PanelYes
Protocol ComponentXimmcceng.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.PCGen. The file is located in %System%No
immcheck.exe?immcheck.exeRelated to I-FORCE driver for force feedback steering wheel?No
LogonAdministratorXimoet.exeAdded by the RAHIWI.A WORM!No
WinLiveXimol.exeDetected by Dr.Web as Trojan.PWS.Banker1.3973 and by Malwarebytes Anti-Malware as Trojan.BankerNo
WinLiveXimola.exeDetected by Kaspersky as Trojan.Win32.Scar.bsjjNo
IMOLUIMOLApp.exeIncrediMail for Office Outlook Add-OnNo
WinLiveMsnXimolav.exeDetected by Kaspersky as Trojan.Win32.Scar.crggNo
Remote Update MonitorYimonitor.exeRemote Update utility for older versions of Sophos antivirus products which provided an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employerNo
IMONTRAYUimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cardsNo
Intel Active MonitorUimontray.exeSystem tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cardsNo
imPlayokXimPlayok.exeDetected by McAfee as Cutwail.gen.oNo
Impulse DockNImpulseDock.exeOlder version of the Impulse digital distribution platform from Stardock CorporationNo
Impulse NowNImpulseNow.exeSystem Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the Windows Defender entryYes
ImpulseNowNImpulseNow.exeSystem Tray access to and notifications for the Impulse digital distribution platform from Stardock CorporationYes
Impulse NowNIMPULS~1.EXESystem Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the Vista/7 MSConfig entryYes
ImpulseNowNIMPULS~1.EXESystem Tray access to and notifications for the Impulse digital distribution platform from Stardock Corporation. This is the XP MSConfig entryYes
ImScInstUImScInst.exeMicrosoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control PanelYes
ImScInst.exeUImScInst.exeMicrosoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control PanelYes
MSPY2002UImScInst.exeMicrosoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails, documents and other files - should you need to. Found on PCs where these languages have been installed through the Regional and Language options icon in the Control PanelYes
IMSCMigUIMSCMIG.EXEAssociated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc)No
imscmigXimscmig.exeDetected by McAfee as W32/Lurka.b. Note - do not confuse with the legitimate MS Input Method Editor entry which shares the same filename and is found in a sub-folder of %CommonFiles%\Microsoft%\IME - this one is found in %Windir%No
IMSCMIG.exeXIMSCMIG.exeDetected by Dr.Web as Trojan.Touch.321 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - do not confuse with the legitimate MS Input Method Editor entry which shares the same filename and is found in a sub-folder of %CommonFiles%\Microsoft%\IME - this one is found in %System%No
Microsoft Pinyin IME MigrationUIMSCMIG.EXEAssociated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc)No
Microsoft(R) Pinyin IME 2007UIMSCMIG.EXEAssociated with Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to (e.g. Chinese, Hindi, Japanese, etc)No
Instant Messenger ServiceXimservice.exeDetected by Kaspersky as the HEUR TROJAN!No
MSN Funny ImagesXimsngsr.exeAdded by the AGOBOT-TT WORM!No
IMStartUIMStart.exeInterMute security software relatedNo
SkypeXImvu.exeDetected by Trend Micro as BKDR_DOKSTORMC.A. Note - this is not a legitimate entry for the popular Skype VOIP softwareNo
IMVUUIMVUClient.exeIMVU chat client that allows you to create "your own avatars who chat in animated 3D scenes"No
IMwireXimwireup.exeAdded by a variant of Spyware.SafeSurfingNo
im_autornXim_1.exeAdded by the IMAV.A WORM!No
im_autornXim_2.exeDetected by Sophos as Troj/BagleDl-BONo
iM Start CenterNiM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start → Programs → iM Networks → iM Radio TunerNo
Ahead Software AG InCDYInCD.exeInCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable itYes
InCDYInCD.exeInCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable itYes
Nero AG InCDYInCD.exeInCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable itYes
Tyig.exeXIncdop.exeDetected by Malwarebytes Anti-Malware as Trojan.VBKrypt. The file is located in %AppData%No
IncMailNIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"No
IncredimailNIncMail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"No
incognitoXincognito.exeAdded by an unidentified WORM or TROJAN! See hereNo
RegistryMonitor1Xincognito.exeAdded by the BUZUS.DAHY TROJAN!No
IncredimailNincredimail.exe"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"No
MRUBlasterUindexcleaner.exeMRU-Blaster from Brightfort (formerly Javacool Software) - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folderNo
IndexCleanerUIndexCleanerR.exeUtility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon OnlineNo
Indexer?Indexer.exePart of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required?No
IndexindicatorXIndexindicator.exeAdded by the LAZAR TROJAN!No
IndexSearchNIndexSearch.exePart of Nuance (was ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". Creates an index of files associated with PaperPort for easy searchingNo
IndexTrayUIndexTray.exePart of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents"No
Fujitsu Hotkey UtilityUIndicatorUty.exeFujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayedNo
IndicatorUtyUIndicatorUty.exeFujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayedNo
CountryXIndonesian.comDetected by Malwarebytes Anti-Malware as Worm.Agent.MLB. The file is located in %Windir%\fontsNo
IISXinet.exeMeplex adwareNo
System64Xinet.exeAdded by the DENGLE-A TROJAN!No
inetcntrlUinetcntrl.exeBsafe Online - internet filterNo
InetConf?inetconf.exe??No
InetdUINETD32.EXEWindows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstationNo
Inet DataBaseXInetdbs.exeAdded by the QEDS WORM!No
Inet DeliveryXinetdl.exeInet Delivery adwareNo
Inet DeliveryXinetdl_2.exeInet Delivery adwareNo
Microsoft Internet Dumping ProtocolXinetdump.exeAdded by the IRCBOT.BLL BACKDOOR!No
Security Antivirus Xp 1Xinetfor.exeAdded by the SDBOT.BAV WORM!No
MMicrosoft Security ManagementXinetforn.exeDetected by Trend Micro as WORM_RBOT.AFZNo
Windows UpdateXinetinf.exeDetected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %System%No
inetinfo.exeUinetinfo.exeExecutable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)No
load=Xinetinfo.exeAdded by the PROXY-GG TROJAN!No
runXinetinfo.exeAdded by the BINGHE TROJAN!No
SystemXinetinfo.exeAdded by the PARDROP-A TROJAN!No
svchostXinetinfo.scrAdded by the ODELUD WORM!No
inetinfomon managerXinetinfomon.exeAdded by the DONBOMB.A TROJAN!No
Microsoft System CheckupXinetman.exeAdded by the DONK.O WORM!No
inetmgrXinetmgr.exeActualNames Internet Keywords parasiteNo
inetrunXinetrun.exeAdded by the AGENT.CE BACKDOOR!No
inetservXinetserv.exeAdded by the AGENT-OWJ TROJAN!No
Internet ServerXinetsrv.exeAdded by the STARTPA-EM TROJAN!No
User32Xinetsrv.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader.USR. The file is located in %Root%\usrs\rb\InfNo
Windows Live UpdateXinetsrv.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%\inetsrvNo
INETXinetsync.exeMeplex adwareNo
Microsoft Internet SyncingXinetsync.exeAdded by the IRCBOT.BLL BACKDOOR!No
Compaq Internet SetupNinetwizard.exeFor Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP listNo
Bron-SpizaetusXinf31.exeAdded by the RONTOKBRO.M WORM!No
InfdiskXinfdisk.exeAdded by the CRYPTER.A TROJAN!No
InfeStopXInfeStopRemover.exeInfeStop rogue spyware remover - not recommended, removal instructions hereNo
infoXinfo.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\WindefenderNo
run=Xinfo32.exeCoolWebSearch Tapicfg parasite variantNo
Info32xXInfo32x.exeAdded by the GEMA TROJAN!No
InfoBoanXInfoBoan.exeInfoBoan rogue security software - not recommended, removal instructions hereNo
Firewall AdminXinfocard.exeAdded by the VBPIT-A MALWARE! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET%\Framework%\v3.0%\Windows Communication Foundation. This one is located in %Windir%No
Firewall AdministratingXinfocard.exeAdded by the AUTORUN-AYV WORM! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft and uses the same filenameNo
Framework module libraryXinfocard.exeAdded by the BUZUS.AYX TROJAN! Note - this is not the valid InfoCard Service which is part of the .NET Framework from Microsoft which is normally found in %Windir%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation. This one is located in %System%No
infodataSXinfodataU.exeInfoData rogue security software - not recommended. One of the OneScan family of rogue scanner programs. Detected by Malwarebytes Anti-Malware as Adware.K.InfoDataNo
Microsoft Update MachineXinfoDLL.exeAdded by the RBOT-EH WORM!No
Microsoft Special offerXinfoebay.exeAdded by a variant of Win32/RbotNo
infoguardrXinfoguardrun.exeInfoGuard rogue security software - not recommended, removal instructions hereNo
infohelperSXinfohelperU.exeInfoHelper rogue security software - not recommended. One of the OneScan family of rogue scanner programs. Detected by Malwarebytes Anti-Malware as Adware.K.InfoHelperNo
MICROUPDATEINFOXInfoMicro.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %MyDocuments%\INFOMICRONo
GetcaYInfoMyCa.exeMonitor for a Belkin USB Wireless adapterNo
Microsoft Synchronization ManagerXInfoNT.exeAdded by the SDBOT-TR BACKDOOR!No
InfoPenMSNUInfoPenIM.exeInfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by handNo
Infoplay.exe?Infoplay.exeWritten by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?No
InfoPureXInfoPure.exeInfoPure rogue security software - not recommended, removal instructions hereNo
InformationXInformation.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.AI. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows startsNo
NVagentXInforme.exeDetected by Symantec as W32.Vig.CNo
SymantecXInforme.exeDetected by Symantec as W32.Vig.CNo
InfoSafeXInfoSafe.exeInfoSafe rogue security software - not recommended, removal instructions hereNo
InfoSaveXInfoSave.exeDetected by Malwarebytes Anti-Malware as Rogue.InfoSave. The file is located in %ProgramFiles%\Info-SaveNo
InfoSevenXInfoSeven.exeInfoSeven rogue security software - not recommended, removal instructions hereNo
InfoShield4XInfoShield4.exeInfoShield4 rogue security software - not recommended, removal instructions hereNo
InfoTabXinfotab.exeInfoTab adwareNo
infusXinfus.exeAdult content diallerNo
InfuzerUInfuzer.exeInfuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"No
infwinXinfwin.exeVX2.Transponder parasite updater/installer relatedNo
SCANINICIOYInicio.exePart of the range of internet security products from Panda Security - including Global Protection, Internet Security and Antivirus Pro. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up timeNo
Win32ConfigXinid.exeDetected by Dr.Web as Trojan.DownLoader4.43527 and by Malwarebytes Anti-Malware as Backdoor.MessaNo
WindowsXinid.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
iniserviceXiniservice.exeDetected by Malwarebytes Anti-Malware as Trojan.Sasfis. The file is located in %AppData%No
Win_LibraryXINISvc.exeAdded by the ANARCH WORM!No
MMCXinisys.exeAdded by the OSCABOT-I WORM!No
initXinit.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Root%\Users\PublicNo
Microsoft Update 33Xinit.exeAdded by the RBOT-ATT WORM!No
SessionInitXinit.exeAdded by the FAKEAV-BRZ TROJAN!No
TrojanShieldUInit.exeTrojanShieldNo
Unix File SupportXinit3.exeAdded by the RBOT-ZN WORM!No
[various names]Xinit32.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
Init32XInit32.exeAdded by the WINEX.A TROJAN!No
PC2XXinitial.batAdded by the DWNLDR-FZZ TROJAN!No
AppletINITXinitiate.exeDetected by Kaspersky as Backdoor.Win32.Agobot.xvNo
Windows LiverXinitmail.exeDetected by Microsoft as Trojan:MSIL/Gillver.ANo
Windows LiverXinitmailer.exeDetected by Microsoft as Trojan:MSIL/Gillver.ANo
Microsoft Initialization ServicesXinitserv.exeAdded by the IRCBOT-ABO TROJAN!No
Microsoft Initialization ServiceXinitsvc.exeAdded by the IRCBOT.AXK BACKDOOR!No
Windows Service ManagerXinitsvc.exeAdded by the RBOT-BWT WORM!No
scheduler_monitorUinit_scheduler.exeScheduler for ReaConverter advanced image converterNo
Naeron InjectorXInjector.exeDetected by Malwarebytes Anti-Malware as HackTool.Agent. The file is located in %System%No
injobXinjobs.exeAdded by the BINJO TROJAN!No
Gateway Ink MonitorNInkMonitor.exeInk level monitor for Gateway branded printersNo
Ink MonitorNInkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-lineNo
InkWatchNInkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-lineNo
InterMoni3XInMonitor.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir%\intermoni3No
ATVYXINnM.exeDetected by McAfee as Generic.dx!bhph and byMalwarebytes Anti-Malware as Trojan.AgentNo
InoRPCYInoRpc.exePart of eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus productsNo
InoRTYInoRT9x.exeReal-time monitor for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus productsNo
InoTaskUInoTask.exeScheduled scans and signature updates for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU usage when performing updatesNo
HKCUXinpp.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
HKLMXinpp.exeDetected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %System%\InstallDirNo
[various names]XInpriseMon.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
InprivacyXInprivacy.exeInprivacy rogue privacy program - not recommended, removal instructions hereNo
InputDirectorUInputDirector.exe"Input Director is a Windows application that lets you control multiple Windows systems using the keyboard/mouse attached to one computer"No
OutLooksXInSane.exeAdded by the SWOOP TROJAN!No
insCOA5?insCOA5.exe??No
Boots Insert Detect?InsDetect.exePart of Boots Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?No
Dixons Insert Detect?InsDetect.exePart of Dixons Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?No
Duane Reade Insert Detect?InsDetect.exePart of Duane Read Picture Suite & Digital Image Pack. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?No
Jessops Insert Detect?InsDetect.exePart of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?No
Tesco Insert Detect?InsDetect.exePart of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?No
MicroUpdateXinsdir.exeDetected by McAfee as Generic BackDoor!fqc and by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %System%\InstNo
Windows IncontextXInSearch.exePacerD_Media/Pacimedia.com/Z-Quest adware installerNo
inshoppingXinshoppingup.exeDetected by Malwarebytes Anti-Malware as Adware.IEShow. The file is located in %ProgramFiles%\inshoppingNo
InsiderXInsider.exeAdded by the AGENT.KMC TROJAN!No
[varies]Xinsidminer.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.BTCGen. The file is located in AppData%\[folder] - see examples here and hereNo
Nielsen NetRatingsXinsight.exeNetRatings Premeter spywareNo
InstaAlertUInstaAlert.exe"Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"No
PCMagInstaback2UInstaBack.exeInstaBack 2 from PC Magazine - instant and automated backup utilityNo
InstafinderXinstafinder.exeTopSearch.D adwareNo
InstaFinderKXInstaFinderK_inst.exeInstaFinder adwareNo
[trojan filename]XInstall.exeDetected by Sophos as Troj/Bancban-FSNo
Adobe_UpdaterXInstall.exeDetected by Dr.Web as Trojan.MulDrop3.48888. Note - this is not the legitimate automatic updater for earlier versions of Adobe products whose filename is Adobe_Updater.exe and this file is located in %AppData%\AdobeNo
d4d09436d35da01cf69e37f8597d3266XInstall.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
Initial PageXinstall.exeEasySearch browser hijack installerNo
InstallXInstall.exeDetected by Sophos as Troj/Bancban-HGNo
MicrosoftXinstall.exeAdded by a variant of the IRCBOT BACKDOOR!No
MSNXinstall.exeAdded by the AGENT-GDO TROJAN!No
MyVBAppXinstall.exeDetected as Generic Downloader.s by McAfee, probable variant of ReferAd adware!No
updata.exeXinstall.exeDetected by Kaspersky as Trojan-Downloader.Win32.Agent.fxzi and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
UPDATEXInstall.exeDetected by Malwarebytes Anti-Malware as Backdoor.Poison. The file is located in %System%No
Windows UpdateXinstall.exeDetected by Sophos as Troj/Banker-IB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
BootCfgXInstall.log.vbsAdded by the YPSAN.D WORM!No
[various names]Xinstall2.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original pageNo
install32xinstall32.exeAdded by the NUCLEAR.DG BACKDOOR!No
InstallAurealDemosNInstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizardNo
InstallCleanerXInstallCleaner.exeAdded by the ANYHOMB.F TROJAN!No
MeteoriteXinstalled.exeDetected by Kaspersky as Net-Worm.Win32.Kolab.eavNo
AntivirusBESTXInstaller.exeInstaller for the AntivirusBEST rogue security software - not recommended. Removal instructions hereNo
tridentXInstaller.exeDetected by McAfee as Generic.tfr!cf and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Windows UDP Control CenterXinstaller.exeAdded by a variant of the IRCBOT BACKDOOR!No
LogitechRegisterVideoApplicationsYInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to register video applications that can use the webcam on the first reboot after installing the softwareYes
LogitechVideo[inspector]UInstallHelper.exeEntry added when you install versions of the Logitech QuickCam webcam software and used to monitor and register video applications that can use the webcam. It isn't normally running but you could disable it and re-enable it before you install supported applicationsYes
Verizon Custom Uninstall Tracking?InstallHelper.exeVerizon related installation tracker. What does it do and is it required?No
InstallIQUpdaterNInstallIQUpdater.exeUpdater for InstallQ from W3iNo
InstallNameXInstallName.exeDetected by McAfee as Generic MSIL.v and by Malwarebytes Anti-Malware as Backdoor.Agent.GenNo
Microsoft Intell ManagementXInstalls.exeDetected by Malwarebytes Anti-Malware as Backdoor.Messa. The file is located in %AppData%No
NetscapeUInstallService.exeRelated to Netscape installationNo
InstallstubUinstallstub.exeTool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phoneNo
SBIXinstall_sbd_**.exeInstaller for a number of rogue security products and error fixing tools - where ** represents a 2 letter language code, i.e., "en" for English, "de" for German, etcNo
InstantDriveUInstantDrive.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems (formerly VOB Computersysteme GmbH, now part of Avid Technology, Inc). Creates a virtual CD/DVD drive on the hard drive.No
VOBIDUInstantDrive.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems (formerly VOB Computersysteme GmbH, now part of Avid Technology, Inc). Creates a virtual CD/DVD drive on the hard drive.No
InstantEyedropperNInstantEyedropper.exe"Instant Eyedropper is a free software tool for webmasters that will identify and automatically paste to the clipboard the HTML color code of any pixel on the screen with just a single mouse click"No
Hyper StartXinstantmsgrs.exeAdded by the RBOT-NH WORM!No
mousedrive.exeXinstantmsgrs.exeAdded by the FORBOT-ER WORM!No
instant messengersXinstantmsgtr.exeAdded by the AGOBOT-PC BACKDOOR!No
InstantPleasureXinstantpleasure.exeAdult content diallerNo
InstantPleasureXXXXinstantpleasurexxx.exeAdult content diallerNo
InstantSpywareRemoval.exeXInstantSpywareRemoval.exeInstant Spyware Removal rogue security software - not recommended, removal instructions hereNo
InstantAccessNINSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start → ProgramsNo
GustavVEDXinstit.batAdded by the OPASERV.H WORM!No
institXinstit.batAdded by the OPASERV.H WORM!No
InstUtlR.exe?InstUtlR.exe??No
InSysSecureXInSysSecure.exeInSysSecure rogue security software - not recommended, removal instructions here. A member of the AntiAID familyNo
WebsxXInt*****.exeAdult content dialler - where ***** are randomNo
ClassesXint1.exePlus18Point - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN!No
MICROMAPELXIntakeman.exeDetected by McAfee as RDN/Generic.dx and by Malwarebytes Anti-Malware as Trojan.Agent.MMPNo
IntarnetXIntarnet.exeDetected by Kaspersky as Trojan-PSW.Win32.Sysrater.r and by Malwarebytes Anti-Malware as Trojan.Agent.INTGenNo
ThreadedXintcp32.exeAdded by the RANDEX.UG WORM!No
Inet DeliveryXIntdel.exeInet Delivery adwareNo
Inet DeliveryXintdel_2.exeInet Delivery adwareNo
Intense Registry Service?IntEdReg.exe /CHECKIntense Educational Ltd - Language Office Software. Is it required?No
ILO_Office_Manager?IntEdReg.exe /OFFMANIntense Educational Ltd - Language Office Software. Is it required?No
IntegardTrayUIntegardTray.exeSystem Tray access to Integardparental control software from Race River CorpNo
Windows FixXintegator.exeAdded by the SDBOT.ZAB WORM!No
Secure SystemXintegitor.exeAdded by the AGOBOT.ACI WORM!No
Intel® InterfaceXIntel®.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%No
Intel(R)GraphicsControlsXIntel(R)GraphicsControls.exeDetected by Sophos as Troj/Agent-ZSX and by Malwarebytes Anti-Malware as Trojan.MSILNo
HKCUXIntel.exeDetected by McAfee as Generic.bfr!ew and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
HKLMXIntel.exeDetected by McAfee as Generic.bfr!ew and by Malwarebytes Anti-Malware as Backdoor.HMCPol.GenNo
InstallerXintel.exeDetected by Microsoft as Backdoor:Win32/Poison.M. The file is located in %System%No
IntelXIntel.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData%\Intel - see hereNo
IntelXIntel.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.KRZ. The file is located in %AppData%\MicrosoftNo
INTELXIntel.exeDetected by Kaspersky as Trojan.Win32.Agent.huan and by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%No
Register_nameXintel.exeDetected by Kaspersky as Trojan-PSW.Win32.Lmir.gen. The file is located in %System%No
intel32.exeXintel32.exeAdded by the SPYJACK-B TROJAN!No
IntelAudioStudioNIntelAudioStudio.exe"Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience". Audio utility supplied with some Intel motherboardsNo
Intel(R) BrowserXintelbrowser.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData%No
IntelCoreXIntelCore.exeDetected by Malwarebytes Anti-Malware as MSIL.LockScreen. The file is located in %MyDocuments%\My MusicNo
RealtekHDAudioManagerXIntelGraphics.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %MyDocuments%\ServicesNo
NMSSupportYIntelHCTAgent.exeNetwork monitor for Intel® Hub Connect TechnologyNo
IntelinetXIntelinet.exeIntelinet rogue security software - not recommendedNo
Microsoft Windows Operating SystemXInteliTrace.exeDetected by McAfee as Generic.dx!bg3q and by Malwarebytes Anti-Malware as Trojan.MWF.GenNo
intell32.exeXintell32.exeAdded by the SmitFraud alias Desktophijack.C TROJAN!No
intell321.exeXintell321.exeAdded by the SPYJACK-B TROJAN!No
Intelliflag_be.exeXIntelliflag_be.exeIntelliflag spywareNo
IntelMEMUIntelMEM.exeRelated to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem lineNo
IntelMonitorXIntelMon.exeDetected by Dr.Web as Trojan.PWS.Banker1.9228No
Intel Product Number UtilityUIntelProcNumUtility.exeIntel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information hereNo
Local ServiceXIntenat.exeAdded by the NUCLEAR-J TROJAN!No
InteractivyXInteractivy.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\InteractivyNo
InterdllXInterdll.exeAdded by the DELF family of TROJANS!No
Windows Media SP 217XInterna.exeDetected by Kaspersky as Trojan-PSW.Win32.Hukle.t. The file is located in %System%No
Microsoft explorer UpdateXinternal.exeAdded by an unidentified WORM or TROJAN!No
PingTimeout InstitutionXinternal.exeAdded by the SDBOT.BMH WORM!No
360safeXinternat.exeDetected by Dr.Web as Trojan.Hoster.577No
CnsMaxXInternat.exeDetected by Symantec as Backdoor.Pointex. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir%No
internatXinternat.exeDetected by Sophos as Troj/Lydra-F. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir%No
internat.exeNinternat.exeMicrosoft language selection icon in system tray, located in %System%No
Internat.exeXinternat.exeDetected by Symantec as Infostealer.Netsnake. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir%No
internetXinternat.exeDetected by Malwarebytes Anti-Malware as Trojan.Downloader. Note - the legitimate internat.exe is located in %System% whereas this version is found in %UserTemp%No
loadXInternat.exeDetected by Symantec as Infostealer.Wowcraft. Note - the legitimate internat.exe is located in %System% whereas this version is found in %Windir%No
Network ConnectionsXinternat.exeDetected by Sophos as Troj/VB-ZDNo
Runtt1XInternat.exeDetected by Sophos as Troj/Lineage-RNo
Windows Taskbar ManagerXinternat.exeDetected by Sophos as W32/Protoride-HNo
3e936482e28cca4a48b713452330a269XInternet Explorer.exeDetected by Dr.Web as Trojan.DownLoader7.14169 and by Malwarebytes Anti-Malware as Trojan.MSILNo
Neospace Internet SecurityXInternet Security.exeNeospace Internet Security rogue spyware remover - not recommendedNo
blah serviceXinternet.exeAdded by a variant of Win32/RbotNo
InternetXInternet.exeDetected by Kaspersky as Trojan-PSW.Win32.Sysrater.r and by Malwarebytes Anti-Malware as Trojan.Agent.INTGenNo
Internet ServicesXinternet.exeAdded by the MYTOB.BT WORM!No
Internet.exeXInternet.exeAdded by the MAGICCALL VIRUS!No
Micrcoft UpdatXInternet.exeAdded by the RBOT-ANA WORM!No
NetworkAssociates IncXinternet.exeAdded by the LOVGATE.AB WORM!No
Runtt1XInternet.exeAdded by the LINEAGE-Q TROJAN!No
Windows connection managerXInternet.exeAdded by the RBOT-APN WORM! Note - file is found in %Windir%. Make sure you check the link on this one, it copies it's self under three other file names and folder locationsNo
Windows Internet Browser ServicesXinternet.exeAdded by the SLENFBOT.GP WORM!No
Windows Internet Browser ServicesXinternet128.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
Windows Internet Browser ServicesXinternet32.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
Windows Internet Browser ServicesXinternet64.exeAdded by a variant of the IRCBOT TROJAN! See hereNo
internetboanXinternetboan_up.exeInternetBoan rogue security software - not recommended, removal instructions hereNo
InternetCallsNInternetCalls.exeInternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
MicrosoftXinternetdat.exeAdded by the RBOT.ETY BACKDOOR!No
InternetDataXInternetData.exeDetected by Dr.Web as Trojan.DownLoader6.14490 and by Malwarebytes Anti-Malware as PasswordStealer.MSILNo
MSVersionXinternetfeatures.exeAdded by the POPMON.A TROJAN - also known as PopMonster adwareNo
InternetShieldXInternetShield.exeInternetShield rogue security software - not recommended, see hereNo
InternetSpyUInternetSpy.exeInternet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself!No
explorerXinternetx.comDetected by McAfee as Generic.bfr!yNo
Internet_Explorer.exeXInternet_Explorer.exeAdded by the BANKER-END TROJAN!No
InterntXInternt.exeDetected by Symantec as Backdoor.Peeper and by Malwarebytes Anti-Malware as Trojan.DownloaderNo
InternetShieldXINTERN~1.EXEInternetShield rogue security software - not recommended, see hereNo
Internet ServicesXinterserv.exeDetected by Trend Micro as WORM_RBOT.BNTNo
Intersoft MsngrXintersoftmsngr.exeAdded by the AGOBOT-NW WORM!No
Internet ServiceXintersvc.exeAdded by the SPYBOT-DE WORM!No
InterVoipNInterVoip.exeInterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular SkypeYes
InterWARNUinterwarn.exeInterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start → ProgramsNo
ClassesXintl.exePlus18Point - Switch dialer and hijacker variant, see here. Also detected as the SWITCH-A TROJAN!No
IntmgrXIntmgr.exeAdded by the GEMA TROJAN!No
cloverXintothemap_CP.exeDetected by Malwarebytes Anti-Malware as Adware.KorAd. The file is located in %ProgramFiles%\intothemap CPNo
clover_uXintothemap_CP_updater.exeDetected by Malwarebytes Anti-Malware as Adware.K.IntoMap. The file is located in %ProgramFiles%\intothemap CPNo
IntranetXintranet.exeAdded by the CHIMOZ.AC TROJAN!No
The IntranetXintranet.exeAdded by a variant of W32/Sdbot.wormNo
Microsoft Intranet PatcherXintranetexplorer.exeDetected by Sophos as Troj/Agent-IRB and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
Intren0tXIntren0t.exeDetected by Trend Micro as TROJ_LEGMIR.IC and by Malwarebytes Anti-Malware as Trojan.DelfNo
GremlinXintrenat.exeAdded by the DOOMJUICE WORM!No
IntrenatXIntrenat.exeAdded by the LEMIR.E TROJAN!No
Norton Personal FirewallYIntroWiz.exePart of Norton Personal Firewall or Norton Internet SecurityNo
WinXP Processor Generator v1.2Xintspnsr32.exeAdded by the SDBOT.LP BACKDOOR!No
Generic Host Process for Win32 ServicesXintspvc.exeAdded by the DINFOR.D WORM!No
Intuit SyncManagerUIntuitSyncManager.exeSynchronizes local Intuit Quickbooks data with online data - "Use the Intuit Sync Manager to find the status of your latest QuickBooks data sync, manage sync frequency, and stop or start syncs at any time." See here for more informationNo
RunCAYInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be requiredNo
WUSB54GSYInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be requiredNo
WUSB54Gv2YInvokeSvc3.exeWireless-G USB Wireless Network Adapter related - would appear to be requiredNo
MircProtectionXIo.vbsAdded by the THEA-A VIRUS!No
io589Xio589.exeDetected by McAfee as Generic PWS.b and by Malwarebytes Anti-Malware as Backdoor.AgentNo
PornfolioXioande.exeAdded by the SDBOT.ATW WORM!No
iobiNiobiClient.exeiobi Home - a mail/voice service by VerizonNo
IObit SmartDefragUIObit SmartDefrag.exeThis is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
Smart DefragUIObit SmartDefrag.exeThis is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
SmartDefragUIObit SmartDefrag.exeThis is the original Smart Defrag disk defragmenter utility from IObit. Required if you use either of the "Auto Defrag" or scheduled options. Smart Defrag 2 runs as a scheduled task - as do both versions on Windows 7/Vista. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
iochviewerXiochviewer.exeDetected by Malwarebytes Anti-Malware as Adware.Kraddare. The file is located in %AppData%\iochviewerNo
iolo AntiVirusYioloAV.exeiolo AntiVirusNo
iolo Personal FirewallYioloFW.exeiolo Personal FirewallNo
CheckVCRYIOMagic.exeDriver for the I/OMagic Personal Video Recorder (DR-PCTV100)No
Iomega Home Storage ManagerUIomega Discovery.exeIomega Home Storage Manager for some of their external hard drivesNo
Iomega Storage ManagerUIomegaStorageManager.exeIomega Storage Manager for some of their external hard drivesNo
Iomega_loaderXIomega_loader.exeDetected by Trend Micro as WORM_ANTINNY.FNo
Iomon98.exeUIomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hangNo
crsmonsXiomssls.exeAdded by the BACKDR-AU TROJAN!No
iosepcdefXiosepcdef.exeDetected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Backdoor.MessaNo
Iomega WatchNiowatch.exeUsed by Iomega drives. Available via Start → ProgramsNo
Windows Live MessengerXiOXGPymMLPPzevA.exeDetected by Sophos as Troj/MSIL-AN and by Malwarebytes Anti-Malware as Trojan.BankerNo
IPO3NIP Operator 2005.exeIP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single buttonNo
IP**.exe [* = random char]XIP**.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
IP**32.exe [* = random char]XIP**32.exe [* = random char]CoolWebSearch/HomeSearch adware - for examples, see this logNo
Net-ipXIP-net.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %System%\Ip-netNo
IPXIP.EXEAdded by the AGOBOT-QO WORM!No
iProtectYouUip.exeiProtectYou - internet filtering/parental control and network monitoring softwareNo
Configuration Loader10Xip7.exeAdded by the AGOBOT-ANZ WORM!No
Windows Relay ServiceXipcbind.exeAdded by the DELFINJECT.F TROJAN!No
IPC ConnectionXipcconn.exeAdded by the RBOT-AEG WORM!No
ipcfg.exeXipcfg.exeAdware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN!No
Reg ServiceXipcfg.exeAdded by the AGOBOT-SO WORM!No
IP Changer 2.0UIPChanger.exeIP Changer 2.0 from Plustech Inc - network configuration management toolNo
Internet Protocol Configuration LoaderXipcl32.exeAdded by the SDBOT BACKDOOR!No
IPInSightLAN 01NIPClient.exeIP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth, Visual Networks and others. If you have more that one such service installed there may be two or more entries - i.e., IPInSightLAN 02, etcNo
SafetyNet_NotifierUipcLn.exeSafety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network"No
IpCtrlXipcon32.exeAdded by an unidentified VIRUS, WORM or TROJAN!No
Windows driver updateXIpconfig32.exeAdded by the SDBOT-JV WORM!No
IPConfigXipconfigs.exeAdded by the HACARMY.C BACKDOOR!No
ipconfigys.exeXipconfigys.exeDetected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System%No
Logitech DesktopXipconn.exeAdded by the SDBOT-WE WORM!No
SafetyNetUipcTray.exeSafety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network"No
ifpXipf.exeAdded by the CLAGGER-AG TROJAN!No
wfipsUiphider.exeICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see hereNo
IPHSend?IPHSend.exeAOL related. What does it do and is it required?No
VPNClientYipigclient.exeiOpus Private Internet Gateway (iPIG) client. 'Using powerful 256-bit AES encryption technology, the iOpus Private Internet Gateway (iPIG) creates a secure "tunnel" that protects your inbound and outbound communications (Email, Web, IM, VOIP, calls, FTP, etc.) at any Wi-Fi hotspot or wired network'No
IPLA!Uipla.exeIPLA! from Redefine - "an application that makes it possible to broadcast TV shows live on the Internet and to watch countless video materials from ipla's own online database"No
IPLog SecurityXiplogsec.exeAdded by the IRCBOT.GP BACKDOOR!No
IPlusUpdateXIPlusUpdate.exeDetected by McAfee as Generic.bfr!dm and by Malwarebytes Anti-Malware as Adware.IplusNo
ipmon.exeXipmon.exeAdded by the RECERV or R3C.B TROJANS!No
IPInSightMonitor 01NIPMon32.exeIP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. Included with services from BellSouth, Visual Networks and others. If you have more that one such service installed there may be two or more entries - i.e., IPInSightMonitor 02, etcNo
IpNetworkXipnetwork.exeMaxifiles adwareNo
IpnukerXIpnuker.vbsAdded by the INKER.B WORM!No
iPodderNiPodder.exeiPodder (now known as Juice) - a free utility that "allows you to select and download audio files from anywhere on the Internet to your desktop". This entry is present if you choose the option to add it to the startup group during installationYes
Microsoft Winedows WinServXiPodFix.exeAdded by a variant of Win32/RbotNo
Windows Secure FixXiPodFixer.exeAdded by the WOOTBOT.BM BACKDOOR!No
iPodManagerUiPodManager.exeApple iPod® management software for the iPod® player - updates, formating, restoring and other functions associated with the iPod®No
iPod USB ServiceXiPODService.exeDetected by Trend Micro as WORM_SDBOT.ATT. Do not confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the %ProgramFiles%\iPod\bin folder and is implemented as a system service. This file is located in %System%No
iPOD USB DriverXIPODUSB.EXEAdded by a variant of Win32/RbotNo
iPodWatcher?iPodWatcher.exeAssociated with Apple's iPod® player. Detects when the iPod® is connected?No
IntelliPointUipoint.exeMicrosoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
ipointUipoint.exeMicrosoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
Microsoft IntelliPointUipoint.exeMicrosoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supportedYes
IPPDetectNIPP4Detect.exePart of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos"No
IP Packet Redirect ServiceXipredirect.exeAdded by the FORBOT.SM WORM!No
ipregXipreg.exeAdded by the ZAGABAN-H TROJAN!No
Authorization InterfaceXiprivcom2.exeDetected by Kaspersky as Trojan-Dropper.Win32.Delf.grqNo
iPrint TrayNiprntctl.exeNovell® iPrint - a "best-of-breed printing solution for businesses running as traditional enterprises, for those operating entirely on the Net, and for those anywhere on the large spectrum in between"No
YKVEJDPMXDXiprtrmgry.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent.QRJ. The file is located in %System% - see hereNo
IPSXips.exeDetected by Dr.Web as Trojan.PWS.Siggen.35050 and by Malwarebytes Anti-Malware as Backdoor.AgentNo
Windows IP SecurityUipsec.exeRelated to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernelNo
iPSec7Xipsec7.exeAdded by the AGENT.AHVR TROJAN!No
Cisco Systems VPN ClientUipsecdialer.exeCisco VPN Client - lets local users gain Administrator privileges on the operating systemNo
ipsecdialerUipsecdialer.exeCisco VPN Client - lets local users gain Administrator privileges on the operating systemNo
ipsecdialerUIPSECD~1.EXECisco VPN Client - lets local users gain Administrator privileges on the operating systemNo
IPSecMonXIPSecMon.exeAdded by the LAZAR.B TROJAN! Note - this is not the legitimate MS L2TP/IPSec file with the same name which is located in a %Program Files%\Microsoft IPSec VPN. This one is located in %CommonFiles%\VPN NetworkNo
IPSecMonYIPSecMon.exeMicrosoft L2TP/IPSec VPN Client that loads via HKLM\RunServices on Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the InternetNo
Windows IP Security ServiceXipsecs.exeDetected by Trend Micro as WORM_RBOT.BPWNo
Windows FirewallXipservice32.exeAdded by a variant of Win32/RbotNo
ipsnowXipsnow.exeAdded by the SNOWDOOR.A BACKDOOR!No
IP StackXipstack.exeDetected by Trend Micro as WORM_AGOBOT.CWNo
IinlXiptl.exePurityScan adwareNo
iptrayNiptray.exeSystem Tray access to Intel Desktop Utilities - "provides you with the means to monitor system temperatures, voltages, fan speeds, and hard drive health; view detailed system information, and test your system hardware for common errors"No
IPWNIPW.exeInternet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone"No
IPFWXipwf.exeAdded by the DLOADER-YF TROJAN!No
ipwfXipwf.exeAdded by the SCHOEBERL TROJAN!No
IpWinsXipwins.exeMaxifiles.ab adwareNo
Client AgentXipxwping.exeAdded by the PPDOOR-N TROJAN!No
ipxwshelXipxwshel.exeAdded by the WAREZOV.DG WORM!No
iprunXiPY.exeiProtectYou spywareNo
IQES.exe?iqes.exe??No
TOPOLOGY NET.TCP BIOMETRIC CONTROLS SOURCEXiqfrcfjyhsr.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System%No
iqmanager.exeXiqmanager.exeIQ-Manager ransomware copyright scanner - not recommended, removal instructions hereNo
Microsoft Firevall EngineXiqs.exeDetected by Sophos as W32/Stekct-B and by Malwarebytes Anti-Malware as Backdoor.AgentNo
SystemMgrXIr32_a.exeAdded by the MAGANIA-OU TROJAN!No
MREUXir41_qcxi.exeDetected by Malwarebytes Anti-Malware as Adware.SanctionedMedia. The file is located in %System%No
iran.taskXiran.exeDetected by McAfee as MultiDropper-DCNo
Winsock32 driverXiran.exeDetected by McAfee as MultiDropper-DCNo
irassyncXirasyncd.exeDetected as SUPERAntiSpyware as Trojan.IRASHoul.Process. The file is located in %System%No
IRBMe Sucks!!XIRBMe.exeAdded by the RANDEX-Y WORM!No
Randex virus built for IRBMeXirbme.exeAdded by the RANDEX.RH WORM!No
winlogonXircbsbot.exeAdded by the AGENT-RGJ TROJAN!No
IREIKEYIreIKE.exeMicrosoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the InternetNo
Windows Relay ServiceXirfnga.exeAdded by the DROPPER.ACO TROJAN!No
IridiumTimeWizardNiridium.exeIridium TimeWizard - a small program for finding out the time in different parts of the worldNo
IrisXIris.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.IS. The file is located in %AppData%\IRisDirNo
Infra-red MonitorUIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devicesNo
IrMonUIRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devicesNo
SMXiro.batAdded by the IROFFER.CT BACKDOOR!No
SMSXiro.batAdded by the IROFFER.CT BACKDOOR!No
IRQ Assigning AgentXIRQconf.exeAdded by the SDBOT-CSV WORM!No
irssyncdXirssyncd.exeAdded by a variant of Spyware.SafeSurfingNo
ssgrate.exeXirun.exeAdded by the MITGLIEDER.D TROJAN!No
ssate.exeXirun4.exeAdded by the BEAGLE.J WORM!No
ssgrate.exeXirun4.exeAdded by the MITGLIEDER.F TROJAN!No
ir_ftpXirwftp.exeAdded by the BANCOS.H TROJAN!No
IrXferUIrXfer.exeMicrosoft Infrared Transfer applicationNo
ir_ftpXir_ftp.exeAdded by the IRFTP TROJAN!No
winzipXir_ftp.exeAdded by the BANCBAN-S TROJAN!No
Info SelectUis.exeInfo Select from Micro Logic - personal information managerNo
Internet Security 2010XIS2010.exeInternet Security 2010 rogue security software - not recommended, removal instructions hereNo
IObit Security 360UIS360tray.exeSystem Tray access to and notifications for Security 360 anti-malware from Iobit - which has now been discontinued. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
IS360trayUIS360tray.exeSystem Tray access to and notifications for Security 360 anti-malware from Iobit - which has now been discontinued. Note - in November 2009 IObit were accused of stealing database information from Malwarebytes Anti-Malware and others so review the links on the Wikipedia page and make your own mind upYes
Microsoft UpdateXIsac.exeAdded by the RBOT-AU WORM!No
CAISafeYisafe.exeE-mail scanning part of EZ Antivirus - part of the eTrust range of security products formerly available from CA but now discontinued. Available as a stand-alone product or as part of the EZ Armor suite. Runs as the CAISafe service in later product versionsNo
iSafeAVXiSafeAV.exeiSafe AntiVirus rogue security software - not recommended, removal instructions hereNo
homepage.monitor.exeXisamonitor.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for detailsNo
isamini.exeXisamonitor.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details. The most popular for this example appears to be "Video ActiveX Object"No
isamonitor.exeXisamonitor.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for detailsNo
-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+XISASS.exeAdded by the ASSIRAL.B WORM!No
AntiXIsass.exeAdded by the BROPIA.K WORM!No
CSNetManagerXpXisass.exeAdded by the HIDER-O TROJAN!No
EDxMC110XIsass.exeAdded by the VB-NIA WORM!No
IsassXIsass.exeAdded by the FUTRO TROJAN!No
isass.exeXisass.exeDetected by Sophos as Troj/Spy-VL and by Malwarebytes Anti-Malware as Trojan.ClonsNo
Kiamat Sudah Dekat_16_04XISASS.exeAdded by the PAHATIA.B WORM!No
Local Security Authority ServiceXIsass.exeAdded by the LINKBOT.M WORM!No
Local windowsXIsass.exeDetected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp%No
Microsoft Hosts ServiceXIsass.exeAdded by a variant of Win32/RbotNo
MicroSoft IE SasserXISASS.EXEAdded by the SDBOT.MX WORM!No
Microsoft Lsass CenterXIsass.exeAdded by a variant of W32/Sdbot.wormNo
NvMsnWXIsass.exeAdded by the BROPIA.K WORM!No
Patah HatiXISASS.exeAdded by the PAHATIA.A WORM!No
boby.XIsass.scrAdded by the BANCBAN-OH TROJAN!No
LSASS32XIsass32.exeAdded by the KELVIR.M WORM!No
LSASS 32XISASS32.pifAdded by the ASSIRAL-C WORM!No
MSControl3d1Xisasse.exeAdded by the RBOT.CGU WORM!No
MICROSOFT FIREWALL CLIENTYISATRAY.EXEMS Internet Security and Acceleration Server - see hereNo
ISBMgr.exeUISBMgr.exeSony ISB Utility - supports the battery management on some Sony laptopsNo
ShellNXisca.exeAdded by the IBILL.Z TROJAN!No
gtydfXiscca.exeAdded by the DWNLDR-GTK TROJAN!No
iscchXiscch.exeAdded by the LCPRANK-A WORM!No
star2Xischot.exeDetected by Trend Micro as TSPY_BANCOS.SMAM and by Malwarebytes Anti-Malware as Trojan.BankerNo
Personal Security Center MonitorXisc_ui.exeDetected by GFI as Trojan.FakeAlert (fs). The file is located in %System%No
isdbdcNisdbdc.exeFor Compaq PC's. May install properties in dial-up networking when you register with an ISPNo
MiciupdateXisdcic.exeDetected by Malwarebytes Anti-Malware as Trojan.Backdoor. The file is located in %MyDocuments%\MSDCSCNo
isDeleteMeUisDel.batUsed by Norton Internet Security to remove certain files and directories on reboot when uninstalling their productNo
hsimXisearch.exeUnidentified malwareNo
Neospace Internet SecurityXisec30.exeNeospace Internet Security rogue spyware remover - not recommendedNo
Internet SecurityXisecurity.exeInternet Security rogue security software - not recommended, removal instructions hereNo
iSeriesChargeUiSeriesCharge.exeASUS Ai Charger utility - which on supported motherboards can be used to charge Apple's iPod, iPhone and iPad whilst the system is working or is in standby, sleep or shutdown modesNo
SystemInitXiservc.exeAdded by the FIZZER WORM!No
cmsXiserver.exeAdded by the DLOADER-WK TROJAN!No
iNoticeXiservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videosNo
zsmsgsXiservice.exeDetected by Sophos as Troj/Bancos-BUNo
INTERNETSERVICEPROTOCOLXIServices.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %System%\microsoftNo
ServerXiservices.exeDetected by Symantec as Backdoor.Graybird.D and by Malwarebytes Anti-Malware as Trojan.Agent.SD. The file is located in %System%No
xeviviXisesobo.exeAdded by the SDBOT-US WORM!No
startXisfmntr.exeAdded by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for detailsNo
ish-b.exeXish-b.exeAdded by the IRCBOT-ACZ TROJAN!No
iShieldUiShield.exe"GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser"No
ishost.exeXishost.exeAdded by the DLOADR-XJ TROJAN!No
isiss.exeXisiss.exeDetected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Root%\MSDCSC - see hereNo
ISLP2STAYISLP2STA.EXEA process from Cisco Systems Inc associated with Windows Update for wireless NIC driversNo
ISMModuleXISMModule.exeInternet Speed Monitor adware - see example hereNo
ISMModule2XISMModule2.exeInternet Speed Monitor adware variant - see example hereNo
ISMModule3XISMModule3.exeInternet Speed Monitor C adwareNo
ISMModule4XISMModule4.exeInternet Speed Monitor A adware - see example hereNo
ISMModule6XISMModule6.exeInternet Speed Monitor adware variant - see example hereNo
ISMModule7XISMModule7.exeInternet Speed Monitor B adware - see example hereNo
ISMModule8XISMModule8.exeInternet Speed Monitor adware variantNo
ISMPack5XISMPack5.exeInternet Speed Monitor adware variant - see example hereNo
ISMPack6XISMPack6.exeInternet Speed Monitor adware variant - see example hereNo
ISMPack7XISMPack7.exeInternet Speed Monitor C adware - see example hereNo
ISMPack8XISMPack8.exeInternet Speed Monitor adware variant - see example hereNo
isndntioXisndntio.exeAdded by the ONLINEGAMES.ALLK TROJAN!No
Regional ValueXisng.exeAdded by the SDBOT-OW WORM!No
iSnoozeUiSnooze.exeiSnooze by Steven Scott - "sits in your system tray and lets you schedule times for iTunes to start playing." Now abandonedNo
ServiceConfigUispbeg.exeComcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendationNo
News Service?ispnews.exeF-Secure antivirus related. However, is this particular item required?No
IsReminderNISPopup.exeRelated to GuardWare iShield - this is the registration reminder for the trial version, so not required in startupNo
ISP?ISPselector.exeFound on some Sony PCs in %ProgramFiles%\Sony\ISPselector. Offers the new user a selection of pre-configured ISPs (Internet Service Providers)?No
iSpyNOWUispynow.exeiSpyNOW - remote monitoring and surveillance softwareNo
IsrafelXIsrafel.vbsAdded by the GAGGLE.D or GAGGLE.E WORMS!No
ISRHelper.exeXISRHelper.exeInstant Spyware Removal rogue security software - not recommended, removal instructions hereNo
wincrt.exeXisrprov.exeAdded by the STRATIO-HA WORM!No
IsassRenascimentoXIssas.exeAdded by the BANKER.GAX TROJAN!No
Microsoft Install ManagerXissas.exeDetected by Sophos as Mal/Sohana-ANo
isschNissch.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
ISUSSchedulerNissch.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
Macrovision Update ServiceNissch.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
issearch.exeXissearch.exeAdded by the ZLOB-QF TROJAN!No
issEnc32SvrXissEnc32.exeAdded by a variant of Win32/Rbot. The file is located in %System%No
ISSI EZUpdate ServiceNissimsvc.exePart of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patchingNo
CyberDefender Early Detection CenterXISSIntro.exeCyberDefender Early Detection Center rogue security software - not recommended. On testing with a clean image, this reported registry entries pointing to the legitimate Java "jqs_plugin.dll" file (located in %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie) as the Anticlear rogue (see an example here). In addition, it claimed that the installer for an older version of HashTab contained W32.MalwareF.KJAE and quarantined a valid 7-zip file ("7zCon.sfx" in %ProgramFiles%\7-Zip) as W32/Malware. Also read this post where a Tech Support person uses other free tools such as MBAM to fix a problemNo
ISStartUISStart.exeInstalled with Logitech's QuickSmart, ImageStudio and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
Logitech ClickSmartUISStart.exeInstalled with Logitech's QuickSmart webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
Logitech ImageStudioUISStart.exeInstalled with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
Logitech QuickCamUISStart.exeInstalled with older versions of Logitech's QuickCam webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
LogitechGalleryRepairUISStart.exeInstalled with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
LogitechVideoRepairUISStart.exeInstalled with Logitech's QuickSmart and QuickCam (older versions) webcam software. The exact purpose of this startup entry is unknown at present, with opinions varying from: (i) adding a tray icon when a camera is connected - apparently no longer the case, (ii) repairing a problem with the image gallery and (iii) being required with some versions to take pictures and capture videosYes
ISSVCYISSVC.exeCommon process for older versions of Symantec's Norton Internet Security and the now discontinued Norton Personal Firewall security products. The exact purpose is unknown at present but neither program can function properly if this process is disabled. Runs as a service on an NT based OS (such as Windows 7/Vista/XP)No
Internet Sharing ServerYiss_srvr.exeIntel AnyPoint internet sharing software. Now discontinuedNo
istinstall zazzer.exeXistinstall zazzer.exeUnidentified adware downloader/installerNo
IST ServiceXistsvc.exeISTBar adwareNo
ISUSPMNISUSPM.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
ISUSPM StartupNISUSPM.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
Macrovision Update ServiceNISUSPM.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
Software ManagerNISUSPM.exeInstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basisYes
Configuration LoadingsXiSVCHOST.exeDetected by Sophos as W32/Agobot-C and by Malwarebytes Anti-Malware as Backdoor.IRCBotNo
ISW.exeYISW.exeAT&T Internet Security Wizard tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabledNo
DigitalWizardNISWizard.exeInstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital contentNo
isxaXisxa.exeAdded by the SMALL-EIV TROJAN!No
ISXAgent?ISXAgent.exeRelated to Imprivata IT security products. What does it do and is it required?No
Internet Explorer Sys32Xisys32.exeAdded by the IRCBOT-ADA WORM!No
iSysCleanerNiSysCleaner.exeiSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the userNo
isystemXisystem.exeAdded by the CHORUS-A TROJAN! Searchforfree browser hijackerNo
WindowsXIsz5suz5.exeAdded by the BUZUS.IIRA TROJAN!No
ISZoneXISZoneUpdate.exeDetected by Malwarebytes Anti-Malware as Adware.Korad. The file is located in %ProgramFiles%\ISZoneNo
Internet Security GuardXIS[random characters].exeInternet Security Guard rogue security software - not recommended, removal instructions hereNo
iTunesAgentXita.exeAdded by the TACTSLAY.U TROJAN!No
ItalUXitalfds.exeAdded by a TROJAN - see hereNo
iTbaMgqSlSQqGXiTbaMgqSlSQqG.exeAdded by the FAKEAV-DVN TROJAN!No
IRPMonitor?itcnmon.exe??No
SSS6_ITD?itd.exePart of the Security Suite 6 set of data protection utilities from Steganos - now superseded by Privacy SuiteNo
SystemsXitDDD.exeAdded by the DLOADER-PP TROJAN!No
SmartGuardianUItesmart.exeHardware monitor (voltages, temperatures, fan speeds, etc) for motherboard system IO devices from ITE - included on some SOYO motherboards (and possibly others)No
iTHINKXiThink.exeDetected by Microsoft as Adware:Win32/Ithink and by Malwarebytes Anti-Malware as Adware.IthinkNo
iTHINKUpdateXiTHINKUpdate.exeDetected by Microsoft as Adware:Win32/Ithink and by Malwarebytes Anti-Malware as Adware.IthinkNo
Internet TimerUITIMER.exeShareware dial-up connection call cost calculator from RatsoftNo
ItkUItk.exeIn The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call itNo
itk.exeUitk.exeInsert ToggleKey by Mike Lin. ITK sounds a tone whenever you press InsertNo
Praize MessengerUitLoad.exePraize IM Christian chat instant messengerNo
iTouchUiTouch.exeLoads the iTouch configuration settings for supported Logitech keyboards. It's required if your keyboard has shortcut buttons and you use them or have reconfigured them for different functions. It's also required if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen display indications for theseYes
zBrowser LauncherUiTouch.exeLoads the iTouch configuration settings for supported Logitech keyboards. It's required if your keyboard has shortcut buttons and you use them or have reconfigured them for different functions. It's also required if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen display indications for theseYes
iTraffic MonitorNiTrafficMon.exe"iTraffic Monitor is a network monitor and reporting tool. It provides real time graph of network traffic. Detailed stats provide daily/weekly/monthly/yearly stats. Stop watch, Session stats"No
ItsDeductiblePopUpNItsDeductible.exeItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tipNo
ITSecMngNItSecMng.exeRelated to Bluetooth wireless support on both notebooks and via USB dongles. IF this entry is disabled you can still access your Bluetooth devicesNo
ITUNESXitune.exeAdded by the RBOT-ZU WORM!No
Apple iPod ServiceXiTunes.exeAdded by the AUTORUN-BLL WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %AppData%No
ITUNESXitunes.exeAdded by a variant of Win32/Rbot. Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %System%No
ItunesXitunes.exeAdded by the OSCABOT-L WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %Windir%No
itunesffXitunesff.exeAdded by the EB adult premium dialerNo
MSNXiTuneshelp.exeAdded by a variant of the IRCBOT BACKDOOR! See hereNo
iTunesUiTunesHelper.exeInstalled with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few timesYes
iTunesXiTunesHelper.exeAdded by the ITUNEHLP-A TROJAN! Note - this is not the legitimate Apple iTunes file of the same name which is normally found in %ProgramFiles%\iTunes. This one is found in %Root%\iTunesNo
iTunes HelperUiTunesHelper.exeInstalled with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few timesNo
iTunesHelperUiTunesHelper.exeInstalled with Apple's iTunes media management software. Tested without an iPod or iPhone, and on a system with more than 1GB of memory, disabling it does not adversely affect iTunes loading times - but it may help on systems with less memory. iPod and iPhone users report this is required to autostart iTunes when they are connected (can anyone confirm this?). In older versions, if it was disabled in it would re-instate itself after running iTunes a few timesYes
iTunes MusicXiTunesHelper32.exeAdded by the SDBOT.CHK WORM!No
LOCALHOSTXiTunse.exeDetected by McAfee as Backdoor-CEP.gen.ad and by Malwarebytes Anti-Malware as Backdoor.Agent.CNMNo
itypeUitype.exeMicrosoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any keys or key combinations that are changed by the user to perform functions other than default settings, defer back to their default settings and supported keys will not function in applications with advanced text services enabledYes
Microsoft IntelliType ProUitype.exeMicrosoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabledYes
InterTrust Quick StartNit_cpq~1.exeInterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related businessNo
Information UpdateXiu.exeDetected by Kaspersky as the CENTIM.CH TROJAN!No
AcerVGA Engine Drivers V1.2Xiuengine32.exeAdded by the AGENT.QWQ TROJAN!No
USB3MONUiusb3mon.exeSupports USB 3.0 ports based upon Intel chipsets. Disabling it didn't seem to have any ill effects on USB 3.0 transfer speeds but it may be required to support power management featuresNo
iMarkup ClientNiUtil.exeEnables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start → ProgramsNo
ivXiv.exePart of the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions hereNo
MS Host ManagerXivhost.exeAdded by the RBOT-BJN WORM!No
sistemXivi.exeDetected by Kaspersky as Backdoor.Win32.Agent.anylNo
IVONA ControlCenter?IVONA ControlCenter.exeControlCenter for IVONA text-to-speech softwareNo
IVPServiceMgrNivpsvmgr.exeToshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updatesNo
MSConfigXivscjcqv.exeDetected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile%No
ivy.exeXivy.exeAdded by the AGENT-ENZ TROJAN!No
Internet Washer ProXiw.exeInternet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003No
InternetWasherProXiw.exeInternet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003No
eWare StartupNiWareStart.exeeWare iWare task bar. Not requiredNo
ISDNwatchUIWatch.exeFRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"No
IW ControlCenterUiwctrl.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basisNo
IW_Drop_IconUiwctrl.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basisNo
iwctrlUiwctrl.exePart of Pinnacle Instant CD/DVD burning and authoring software from Pinnacle Systems. InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basisNo
StartupBinXiwnujdss.exeAdded by the SDBOT-XZ WORM!No
StsXiwnujdss2.exeAdded by the SDBOT-YI WORM!No
Camio ViewerNIXApplet.exePart of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading themNo
Camio Viewer 1.8.7NIXApplet.exePart of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading themNo
Camio Viewer 2.0NIXApplet.exePart of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading themNo
Camio Viewer 3.2NIXApplet.exePart of Sierra Image Expert, an image viewing program that comes with digital cameras which shows pictures that are in the camera before downloading themNo
ixploreXixplore.exeAdded by the SDBOT-CY TROJAN!No
scvhost loaderXixplore.exeAdded by the SDBOT-CY TROJAN!No
ixploresXixplores.exeAdded by the SDBOT-CE WORM!No
ixssoXixsso.exeAdded by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark"No
Windows Service AgentXizszbayz.exeAdded by the KOLAB.TC WORM!No
CorelCENTRAL 10NI_26dadCC.exeCorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start → ProgramsNo

Notes & Warnings

If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).

"Status" key:

Variables:

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.

WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.

There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program

NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.

SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.

Copyright

Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved

Valid XHTML 1.0 Transitional

Privacy Policy Site Map Home