| Index | Introduction | Database | Detailed Entries | Updates | Concise List | HJT Forums | Rogues | Message Board |
If you're frustrated with the time it takes your Windows 7/Vista/XP PC to boot and then it seems to be running slowly you may have too many programs running at start-up - and you have come to the right place to identify them. This is the original start-up programs (as opposed to processes/tasks) list - one of the most accurate and comprehensive. Services are not included - see below. For further information on this and how to identify and disable start-up programs please visit the Introduction page.
See here for further information on random entries - which are typically added by viruses and other malware or unwanted programs.
Last database update :- 29th Apr, 2013
31819 items listed
You can search for any of the following terms to find and display entries in the start-up programs database but the minimum search is 3 characters and you must click on the "Search" button. Results are sorted by the Startup Item/Name field.
Alternatively, you can browse the full database (without the search facility) over a number of pages or you can use the alphabetical index below to list the entries for that letter by the Command/Data field, but the results may take longer to appear due to the number of them:
A | B | C | D | E | F | G | H | I | J | K | L | B | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
NOTE: Searching for common words (i.e. "the" or "where") will mean the results take longer to appear due to the number of them.
Please click on the Search button
1036 results found for T
| Startup Item or Name | Status | Command or Data | Description | Tested |
|---|---|---|---|---|
| tcomantidialerrun | U | T-Com Antidialer.exe | T-Com Antidialer from T-Com internet provider. It's a small antidialer utility which monitors whether you're trying to dial a new connection. It basically asks you do you want to dial the shown number or not. Protects agains dialer malware | No |
| Sygate Personal Firewall | X | t1ktik.exe | Added by the RBOT-VP WORM! | No |
| micrososot | X | t2.exe | Detected by Dr.Web as Trojan.DownLoader2.45503 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| tsrv | X | t2serv.exe | Added by the WAREZOV.AT WORM! | No |
| T3Console | U | T3Console.exe | Related to T3 Security Suite - prevents unauthorized or inappropriate access to your PC and data | No |
| WINTASK | X | t4skgmr.exe | Added by the MYTOB.CM WORM! | No |
| WINTASK | X | t4skmgr.exe | Added by the MYTOB-AK WORM! | No |
| [random name] | X | t?skmgr.exe | PurityScan adware | No |
| 605841003a1df2009d118a55e0046a30 | X | Taa.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| TabbtnEx | X | TabbtnEx.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %LocalAppData%\Microsoft\Windows\[numbers] | No |
| tabchoice | X | tabchoiceu.exe | Detected by Malwarebytes Anti-Malware as Adware.Winggo.K. The file is located in %ProgramFiles%\TabChoice | No |
| tablet s | Y | tablet s | Starts the Wacom Penabled driver on Acer Tablet PCs (tablet icon with a green check appears during startup if successful) | No |
| Tablet | N | Tablet.exe | Loads the tablet drivers for the Wacom Graphics Tablet. This can be unchecked in msconfig without problems if you don't need the tablet functional all the time. Create your own shortcut if you need to run it ad hoc. If you forget to run it before running Paint Shop Pro & Adobe Photo Shop) you may find the following: (1) Paint Shop Pro (version 7.04) - (a) Browse function will NOT work (program freezes) (b) On program exit, PSP does not terminate (you have to CTRL+ALT+DEL to close it) (2) Photo Shop (version 6.01) - (a) Program functions slowdown (d) On program exit it takes noticeably longer to shut down (like 30-45 seconds) | No |
| Microsoft Text Input Processor | X | TableTextService.exe | Added by the DUBERATH.A TROJAN! | No |
| Tablet Task | X | tabletsk32.exe | Added by the RBOT-AJB WORM! | No |
| tabsync | X | tabsyncu.exe | Detected by McAfee as Generic PUP.x and by Malwarebytes Anti-Malware as Adware.Winggo.K | No |
| TabletTip | U | tabtip.exe | This is the Tablet PC Input Panel for Windows XP Tablet PC Edition. This utility allows you to use a pen (in conjunction with a touchscreen or tablet) to enter text into a document or input field (such as a URL in a browser) using either handwriting or the on-screen keyboard. This utility is also included with Windows 7 and Vista but only appears to run at startup if using the XP Tablet PC version. This cannot be confirmed at present | No |
| TabUserW.exe | Y | TabUserW.exe | Wacom pen tablet driver | No |
| Tacawcxlkorxopzk.exe | X | Tacawcxlkorxopzk.exe | Detected by Malwarebytes Anti-Malware as Trojan.PWS.IRCBot. The file is located in %AppData% | No |
| TAcelMgr | ? | TAcelMgr.exe | TOSHIBA Acceleration Utilities related. What does it do and is it required? | No |
| Tad | N | tad.exe | From Turtle Beach's Santa Cruz on a Dell WinME system. Not required - works fine without it including keyboard hot controls for volume and mute | No |
| Rnudll32 | X | tadxtr.exe | Added by the QQPASS-O TROJAN! | No |
| Pruo | X | taee.exe | PurityScan adware | No |
| TAG | ? | tag.exe | ?? | No |
| Windows Tagmsnger | X | tagmr.exe | Added by the MYTOB-G WORM! | No |
| Tahni Deskmate | N | Tahni.exe | Tahni Deskmate - "Interactive cartoon character that lives on your Windows desktop" | No |
| LoadFonts | X | Tahoma.vbs | Homepage hijacker that changes your homepage to an adult content site | No |
| taiak | X | taiak.exe | Added by the AUTORUN-BTP WORM! | No |
| Start Upping | X | taksmgr.exe | Added by the RBOT-QK WORM! | No |
| Windows Service Controller Agent | X | taksmgr.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| WinXPService | X | taksmgr.exe | Added by the KIRSUN.A BACKDOOR! The file is located in %System% | No |
| WinXPService | X | taksmgr.exe | Detected by Microsoft as Backdoor:Win32/Kirsun.A. The file is located in %Windir%\Fonts | No |
| WinXPService | X | taksmgr.exe | Detected by Trend Micro as BKDR_KIRSUN.A. The file is located in %Root% | No |
| Windows UDP Control Center | X | taksmrg.exe | Added by the AGENT.WOH TROJAN! | No |
| talk | X | talk.bat | Added by the TIOTUA-G WORM! | No |
| TalkingReminder | N | TALKINGREMINDER.EXE | Talking Reminder from Software River Solutions - talking calendar reminder | No |
| talknow | ? | talknow.exe | Could it be related to this or something similar? | No |
| tamio | X | tamio.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom.BL. The file is located in %AppData% | No |
| Service ares | X | tanga.exe | Added by the IRCBOT-AHO TROJAN! | No |
| TangoManager | ? | TangoManager.exe | Tango Broadband access software. Is it required? | No |
| taobet | X | taobet.exe | Added by the VB-FGV WORM! | No |
| [foreign characters] | X | TaoLiSrv.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %System% | No |
| TAPNET | X | tap.exe | Detected by McAfee as PWS-Zbot.gen.aru and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Tapicfg | X | Tapicfg.exe | CoolWebSearch Tapicfg parasite variant | No |
| Tapicfg.exe | X | tapicfg.exe | Malware installed by different rogue security software including SpyKillerPro | No |
| TapiTNA | U | TapiTNA.exe | Telephony Location Selector allowing mobile users to change dialling locations - part of the Win95 Power Toys | No |
| Tardis | U | Tardis.exe | Tardis - time synchronization software | No |
| Taesk managers | X | tase.pif | Added by the RBOT-AYK TROJAN! | No |
| Task Scheduler | X | task scheduler.exe | Detected by Microsoft as Trojan:Win32/Reveton | No |
| Windows Bootup | X | task-mngr.exe | Added by the RBOT-AWP WORM! | No |
| PC | X | task.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| jv16PT - Privacy Protector | U | Task.jvb | jv16 PowerTools Privacy Protector - "allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer, every time you start your computer" | No |
| run32dll | X | task32.exe | Added by an unidentified VIRUS, WORM or TROJAN! | No |
| MS taskbar W | X | task32w.exe | Added by the RBOT.CCK WORM! | No |
| Auto Switch | U | TASKBAR.exe | Related to 2-port Bitronics AutoSwitch kit from Belkin | No |
| Microsoft | X | taskbar.exe | Added by a variant of the RBOT WORM! | No |
| Redline Taskbar | N | taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards | No |
| Search Bar | X | taskbar.exe | Added by the OPANKI-F WORM! | No |
| Task Bar | X | TASKBAR.EXE | Detected by Trend Micro as WORM_FRETHEM.J | No |
| Taskbar | N | Taskbar.exe | Taskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards | No |
| Taskbar Service | X | taskbar.svc | Unidentified adware | No |
| Task BarClient | ? | TaskBarClient.exe | Responsible for creating the System Tray icon and associated display system for the Starband satellite always on internet service | No |
| WOOTASKBARICON | N | TaskbarIcon.exe | Wanadoo broadband ISP (now rebranded as Orange) taskbar icon - not required | No |
| ImagePath | X | taskbarmngr.exe | Added by the SDBOT-XB WORM! | No |
| Taskbar++ | N | TaskbarPP.exe | Taskbar++ is a software that allows you to sort (move) the buttons of the Windows taskbar by Drag & Drop | No |
| MS taskbar | X | taskbars.exe | Added by the RBOT.BRW WORM! | No |
| MS Taskbars | X | taskbars.exe | Detected by Sophos as W32/Sdbot-ACV | No |
| Taskbar Shuffle | Y | taskbarshuffle.exe | "Taskbar Shuffle is a simple, small, free utility that lets you drag and drop your Windows taskbar buttons to rearrange them" | No |
| taskbarshuffle | Y | taskbarshuffle.exe | "Taskbar Shuffle is a simple, small, free utility that lets you drag and drop your Windows taskbar buttons to rearrange them" | No |
| Task BarSvr | ? | TaskBarSvr.exe | Part of the Starband satellite always on internet service. Not included on the current system. What does it do and is it needed? | No |
| taskdir | X | taskdir.exe | Added by the ABWIZ.F TROJAN! | No |
| Task manager | X | taskemngr.exe | Added by the RBOT-AGA WORM! | No |
| HControlUser | X | taskeng.exe | Added by a variant of Trojan.MulDrop4.3133. The file is located in %AppData%\Microsoft | No |
| MicrosoftUpdate | X | taskeng.exe | Detected by Kaspersky as Trojan.Win32.Buzus.brrj and by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| sysclean | X | taskenv.exe | Detected by McAfee as Generic.grp!mq and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Task | X | tasker.exe | Added by the MYDOOM.R WORM! | No |
| Tarefas do Windows | X | taskexec.exe | Added by the AGENT-LSD TROJAN! | No |
| WINTASK | X | taskfile.exe | Added by the MYTOB.EF WORM! | No |
| WINTASK | X | taskgamr.exe | Added by the MYTOB.AU WORM! | No |
| WINTASK | X | taskgm.exe | Added by the MYTOB-AO WORM! | No |
| WINMGR | X | taskgmgr.exe | Added by the MYTOB.AN WORM! | No |
| SVCHOST | X | taskgmr.exe | Added by the MYTOB.F or MYTOB.H WORMS! | No |
| Windows Shell | X | taskgmr.exe | Detected by ESET as Win32/Mytob.BV | No |
| Windows Task Manager | X | taskgmr.exe | Added by the MYTOB.BJ WORM! | No |
| WINRUN | X | taskgmr.exe | Added by the MYTOB-BX WORM! | No |
| WINTASK | X | taskgmr.exe | Added by the MYTOB.I WORM and variants! | No |
| WINTASKMANAGER | X | taskgmr.exe | Added by the MYTOB-AF WORM! | No |
| WINTASKS | X | taskgmr.exe | Added by the MYTOB.BO WORM! | No |
| WINRUN | X | taskgmr32.exe | Added by the MYTOB.AP WORM! | No |
| WINTASK | X | taskgmr32.exe | Added by the MYTOB.BU WORM! | No |
| WINTASK32 | X | taskgmr32.exe | Added by the MYTOB.BN WORM! | No |
| WINTASK32 | X | taskgmrr.exe | Added by the MYTOB.FX WORM! | No |
| WINDRUN | X | taskgmrs.exe | Added by the MYTOB-BT WORM! | No |
| WINTASK | X | taskgmrs.exe | Added by the MYTOB.DH WORM! | No |
| 1ffcf52b0cd64d83554855bd6f04fc1f | X | taskhost.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the valid Windows 7 process which has the same filename, is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% | No |
| abb278f5f94f5be17c28e4761048b650 | X | taskhost.exe | Detected by Dr.Web as Trojan.DownLoader8.19299 and by Malwarebytes Anti-Malware as Trojan.MSIL. Note - this is not the valid Windows 7 process which has the same filename, is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| C:\WINDOWS\temp\taskhost.exe | X | taskhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the valid Windows 7 process which has the same filename, is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %WinTemp% | No |
| Host Process for Windows Tasks | X | taskhost.exe | Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also "Host Process for Windows Tasks". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Taskhost | X | taskhost.exe | Detected by Dr.Web as BackDoor.Butirat.91 and by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not the valid Windows 7 process which has the same filename, is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Windows Task Host | X | taskhost.exe | Added by the AUTORUN-BML WORM! Note - this is not the valid Windows 7 process which has the same filename, is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Container | X | taskhost32.exe | Detected by Dr.Web as Trojan.AVKill.18125 | No |
| Microsoft .NET Framework | X | taskhost32.exe | Detected by Dr.Web as Trojan.Siggen3.61467 | No |
| qlchr | X | taskhost32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.MLBGen. The file is located in %AppData%\Microsoft\[3 letters] - see examples here and here | No |
| taskmrg.exe | X | taskimg.exe | Added by the DLOADER-QZ TROJAN! | No |
| CentralProcessor | X | taskimgr.exe | Added by the BANCOS.J TROJAN! | No |
| WallPaper | X | taskimgr.exe | Added by the BANKER-GX TROJAN! | No |
| kernel44.dll | X | taskkill /f /fi "PID ge 0" /im * | Added by the VBS.LIDO WORM! | No |
| Tasklist | X | tasklist.exe | Detected by Malwarebytes Anti-Malware as Trojan.TDref.Gen. The file is located in %Windir% | No |
| Tasklist | X | tasklist.exe | Detected by McAfee as Generic.dx. The file is located in %AppData% | No |
| TaskList | X | tasklist32.exe | Detected by Sophos as Troj/Bancos-DX and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Shell | X | taskmam.exe | Added by the BANCBAN-OL TROJAN! | No |
| Windows pack Control Center | X | taskmam.exe | Added by the TOMETA-J TROJAN! | No |
| TASKMAN | X | TASKMAN-.exe | Added by the BANLOAD.BEJ TROJAN! | No |
| System Update2 | X | taskman.exe | Detected by Sophos as Troj/Autotroj-C | No |
| Task Manager | X | taskman.exe | Added by the FORBOT-T WORM! | No |
| taskman | X | taskman.exe | Added by the SILLYFDC.BBB WORM! | No |
| Task Manager Settings | X | taskman32.exe | Detected by Trend Micro as WORM_RBOT.ALM | No |
| Microsoft Update Machine | X | TASKMAN4.EXE | Added by a variant of the RBOT WORM! | No |
| Win Drivers SSL | X | TASKMAN4.exe | Added by a variant of the RBOT WORM! | No |
| (Default) | X | taskmanager.exe | Detected by Malwarebytes Anti-Malware as Trojan.GamesThief. Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %AppData% | No |
| ivHost | X | taskManager.exe | Added by a variant of the SPYBOT WORM! See here | No |
| NAV | X | TaskManager.exe | Added by the SYGINRE TROJAN! | No |
| SysRes | X | TASKMANAGER.exe | Added by the ELIPTER.A or ELIPTER.B WORMS! | No |
| taskmanager | X | taskmanager.exe | Added by the AGOBOT-TF WORM! | No |
| taskmgr | X | taskmanager.exe | Added by the BCKDR-QHT BACKDOOR! | No |
| Microsoft Windows Task Manager | X | taskmanagr.exe | Added by the SDBOT.CM WORM! | No |
| taskmanger | X | taskmanger.exe | Added by a variant of Win32/Rbot. The file is located in %System% | No |
| Microsoft Update 32 | X | taskMangr.exe | Added by the RBOT.AIE BACKDOOR! | No |
| Task manager | X | taskmangr.exe | Added by the SPYBOT-CH WORM! | No |
| Mirsoft sdcE | X | taskmegr.exe | Added by the RBOT-AWY WORM! | No |
| Task managebrkb | X | taskmg.exe | Added by a variant of the SPYBOT WORM! See here | No |
| Windows Task Manager | X | taskmg.exe | Browser hijacker - identified by DrWeb antivirus as "Trojan.StartPage.601" | No |
| Winsock2 driver | X | taskmger.exe | Detected by Trend Micro as WORM_SPYBOT.GEN | No |
| Windows Task Manager | X | taskmgn.exe | Added by the AGENT-CIP BACKDOOR! | No |
| cftmon32 | X | taskmgr*.exe [* = number] | Added by the SOWSAT.C and SOWSAT.J WORMS! | No |
| Tasmgr | X | Taskmgr.bat | Added by the YPSAN.G WORM! | No |
| taskmanager | X | taskmgr.com | Added by the BEREB WORM! | No |
| Configuracion Del Sistema | X | taskmgr.exe | Added by the AGENT-SWD TROJAN! Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| Microsoft | X | taskmgr.exe | Detected by Sophos as Troj/Agent-VUT. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserTemp% | No |
| Microsoft Security | X | Taskmgr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Sombra. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| MSE | X | taskmgr.exe | Detected by Dr.Web as Trojan.DownLoader5.54207 and by Malwarebytes Anti-Malware as Trojan.Agent.SME. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp% | No |
| NETCER | X | taskmgr.exe | Detected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Trojan.Agent.TMGen. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| Policies | X | taskmgr.exe | Detected by McAfee as Generic.dx!bdtb and by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\taskmgr | No |
| REALS | X | taskmgr.exe | Detected by McAfee as RDN/Generic.bfr!h and by Malwarebytes Anti-Malware as Trojan.Agent.TMGen. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| Skype | X | taskmgr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. Note - this is not a legitimate entry for the popular Skype VOIP software and also it is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% | No |
| taskmgr | X | taskmgr.exe | Added by the STARTPAGE.G hijacker. Note - this is NOT the Windows Task Manager file! | No |
| TaskMgr | X | taskmgr.exe | Detected by Dr.Web as Trojan.DownLoader6.51056. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft | No |
| taskmgr | X | taskmgr.exe | Detected by McAfee as RDN/Generic.bfr!l and by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\taskmgr | No |
| taskmgr | X | taskmgr.exe | Detected by McAfee as Generic.bfr!cp. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\taskmgr | No |
| taskmgr | X | taskmgr.exe | Detected by McAfee as Generic.dx!bdtb. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\taskmgr | No |
| Taskmgr | X | Taskmgr.exe | System1060 homepage hi-jacker. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "1060" sub-folder | No |
| taskmgr.exe | X | taskmgr.exe | Detected by Dr.Web as Trojan.DownLoader6.64429 and by Malwarebytes Anti-Malware as Trojan.Agent.TSK. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Java | No |
| taskmgr.exe | X | taskmgr.exe | Detected by Sophos as W32/Ainslot-AK and by Malwarebytes Anti-Malware as Trojan.FkTech. Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Windows | No |
| taskmgr.exe | N | taskmgr.exe | Windows Task Manager in Windows XP. If run from the Startup folder, the tray icon will be put to the system tray after boot. Useful to check if XP has finished running the delayed services after boot. Available via a desktop shortcut | No |
| Windows Dump Error | X | taskmgr.exe | Added by the PALEVO-X WORM! Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% | No |
| Windows Service Manager | X | taskmgr.exe | Detected by Kaspersky as the IAMBIGBROTHER.91 TROJAN! Note - this is not the legitimate taskmgr.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a "fonts\svc" sub-folder | No |
| Microsoft System Service | X | taskmgr1.exe | Added by a variant of the SPYBOT WORM! See here | No |
| MACROMEDIAFLASHUPDATESERVICE | X | taskmgr16.exe | Detected by McAfee as RDN/Spybot.bfr!d and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| Task manager | X | taskmgr2.exe | Added by a variant of the RBOT WORM! | No |
| ctfmon32 | X | taskmgr32*.exe [* = digit] | Detected by Trend Micro as WORM_SOWSAT.C | No |
| ctfmon | X | taskmgr32*.exe [* = number] | Added by the SOWSAT.B WORM! | No |
| Microsoft Task32 Protocol | X | taskmgr32.exe | Added by a variant of W32/Sdbot.worm | No |
| Microsoft Update | X | taskmgr32.exe | Added by the RBOT-CV WORM! | No |
| Windows Service Agent | X | taskmgr32.exe | Added by the RBOT-GMN WORM! | No |
| WINRUN | X | TASKMGR32.exe | Added by the MYTOB.AX WORM! | No |
| Service Registry NT Save | X | taskmgrnt.exe | Detected by Sophos as Troj/Bancos-BY | No |
| TaskS manager | X | taskmgrs.exe | Detected by Trend Micro as WORM_AGOBOT.QU | No |
| Windows Manager | X | taskmgrs.exe | Added by the SILLYFDC.BBZ WORM! | No |
| TASKMGRU | X | TASKMGRU.EXE | Added by the CWS-M TROJAN! | No |
| Task service | X | taskmgs.exe | Added by a variant of the RBOT WORM! | No |
| taskmgs | X | taskmgs.exe | Detected by Malwarebytes Anti-Malware as Trojan.FiviGen. The file is located in %AppData% | No |
| Microsoft Task Messenger Config | X | taskmgsr.exe | Added by the SDBOT-JK WORM! | No |
| Svchost | X | taskmmgr.EXE | Added by the AUTORUN-F WORM! | No |
| TasKmgr | X | taskmmgr.EXE | Added by the AUTORUN-F WORM! | No |
| Microsoft sddcE Contol | X | taskmn.exe | Added by the RBOT-BJZ WORM! | No |
| Microsoft sddcE Contol | X | taskmnegr.exe | Added by the RBOT-AUM WORM! | No |
| Microsoft sdDDE Control | X | taskmnegr.exe | Added by the RBOT-AVU WORM! | No |
| AdslTaskBars | X | taskmng.exe | Added by the RBOT-AXZ WORM! | No |
| Microsoft Windows Tasks Management | X | taskmng.exe | Added by the RBOT-FXK WORM! | No |
| Task Manager | X | taskmng.exe | Added by the TIOTUA-E WORM! | No |
| [random name] | X | taskmngr.exe | Added by the AGOBOT-CB WORM! | No |
| Task Manager | X | taskmngr.exe | Detected by Trend Micro as WORM_RBOT.Y | No |
| taskmngr lptt01 | X | taskmngr.exe | RapidBlaster variant (in a "taskmngr" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| taskmngr ml097e | X | taskmngr.exe | RapidBlaster variant (in a "taskmngr" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it | No |
| VITAL BOOT PROCESS | X | taskmngr.exe | Added by a variant of the RBOT WORM! | No |
| Win32 NT Adv Services | X | taskmngr.exe | Added by the RBOT-ADE WORM! | No |
| Windows | X | taskmngr.exe | Added by a variant of W32/Sdbot.worm | No |
| Windows modez Verifier | X | taskmngr.exe | Added by a variant of the RBOT WORM! | No |
| Windows Task Manager | X | taskmngr.exe | Detected by Sophos as W32/Rbot-ANM | No |
| Task Manager Win32 | X | taskmngr32.exe | Added by the RANCK-EX BACKDOOR! | No |
| MICROSFT MX UPDATE SUPPORT | X | taskmngrs.exe | Added by the RBOT-AUZ WORM! | No |
| Microsoft Update Machine | X | taskmngrs.exe | Added by the RBOT-CR WORM! | No |
| VITAL BOOT PROCESS | X | taskmnsgr.exe | Added by the Rbot-VY WORM! | No |
| Job-oversigt | U | taskmon.exe | Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) | No |
| System Update2 | X | taskmon.exe | Detected by Sophos as Troj/Autotroj-C. Note - this is not the legitimate Win98/Me file of the same name which is located in %Windir% as this version is located in %System%. It is not normally found on a WinXP system | No |
| Taakcontrole | U | taskmon.exe | Task Monitor (on Dutch language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) | No |
| TaskMon | X | taskmon.exe | Added by the MYDOOM.A or MYDOOM.J WORMS! Note - this is not the legitimate Win98/Me file of the same name which is located in %Windir% as this version is located in %System%. It is not normally found on a WinXP system | No |
| TaskMonitor | U | taskmon.exe | The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) | No |
| taskmone | X | taskmone.exe | Added by the SINGU-S TROJAN! | No |
| File System | X | taskmqr.exe | Added by the RBOT.BWQ WORM! | No |
| File System | X | taskmqrs.exe | Added by a variant of the TOXBOT WORM! | No |
| TAKSMGN | X | taskmr.exe | Added by the RBOT-AHS WORM! | No |
| Windows Update | X | taskmr.exe | Detected by Sophos as W32/Mytob-GZ and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| Auto WinUpdate | X | taskmrg.exe | Added by the RBOT-AFA WORM! | No |
| Microsoft Configuration Wizard | X | taskmrg.exe | Added by the SDBOT-MX TROJAN! | No |
| Shell | X | taskmrg.exe | Detected by Sophos as Troj/Bancban-FT | No |
| Start Upping | X | taskmrg.exe | Added by the RBOT-MA WORM! | No |
| System Task Manager | X | taskmrg.exe | Added by a variant of the SPYBOT WORM! See here | No |
| task manager | X | taskmrg.exe | Added by the SDBOT.CCD WORM! | No |
| Task Manager for Plugins | X | taskmrg.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.TKM. The file is located in %Windir% | No |
| taskmrg | X | taskmrg.exe | Added by the BANKER-BZZ TROJAN! | No |
| Windows Task Manager | X | taskmrg.exe | Added by the MYTOB.AV WORM! | No |
| Windows Taskmanager | X | taskmrg.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| candynet | X | Taskmsg.exe | Added by the RBOT-NA WORM! | No |
| [name].exe | X | tasknetwork.exe | Detected by Dr.Web as Trojan.DownLoader7.28571 | No |
| MSN | X | taskngr.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| taskngr | X | taskngr.exe | Added by the BANCOS-AWX TROJAN! | No |
| Windows Taskmanager | X | taskngr.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| Windows Update | X | taskngr.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\System | No |
| taskopen.exe | X | taskopen.exe | Added by the HIDD.C TROJAN! | No |
| E6TaskPanel | N | TaskPanl.exe | Earthlink Task Panel - part of Earthlink TotalAccess 2003 internet access software. Quick access to internet, E-mail and web-space | No |
| Ashampoo WinOptimizer Platinum Suite 2 TaskPlaner | U | TaskPlaner.exe | Part of Ashampoo® WinOptimizer Platinum Suite 2 tweaking suite. The Taskplaner automates this system optimization according to the user defined schedule and gives System Tray access to the main program | No |
| TaskPlus | N | TASKPLUS0.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN | No |
| TaskPlus | N | TASKPL~1.EXE | Task and calendar management software available as freeware or as a "Professional" version for sharing over a LAN | No |
| TaskScheduler | U | TaskSch.exe | ProSeries accounting software related | No |
| task service | X | taskservices.exe | Added by a variant of Win32/Rbot | No |
| TASK SETUP | X | tasksetup.exe | Added by the RBOT-YR WORM! | No |
| taskshell.exe | X | taskshell.exe | Detected by Dr.Web as Trojan.DownLoader7.6647 and by Malwarebytes Anti-Malware as Trojan.VBLogger | No |
| Windows Registry Manager | X | tasksmanagers.exe | Added by the MYTOB.ER WORM! | No |
| BONZI Task Switcher | X | Taskswitch.exe | Detected by Trend Micro as WORM_SPYBOT.DTR | No |
| CoolSwitch | U | taskswitch.exe | ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen | No |
| taskswitch | U | taskswitch.exe | ALT+TAB replacement Powertoy for Windows XP - enhances the graphics displayed when you want to switch between programs running full-screen | No |
| TaskSwitchXP | U | TaskSwitchXP.exe | "TaskSwitchXP from NTWind Software. Advanced task management utility that picks up where the standard Windows Alt Tab switcher leaves off. It provides the same functionality, and adds visual styles to the dialog and also enhances it by displaying thumbnail preview of the application that will be switched to" | No |
| Taskbar System | X | tasksys.exe | Added by a variant of W32/Sdbot.worm | No |
| Windows Task Service (32-bits) | X | tasksys.exe | Detected by Trend Micro as WORM_DREFIR.D | No |
| Windows Taskbar System | X | tasksys.exe | Added by a variant of the SDBOT BACKDOOR! | No |
| tasksys | X | tasksys.vbs | Added by the BYRON WORM! | No |
| WinSysStartUpWKbLw | X | TaskSystemDll.Exe | Added by the BACKZAT.G WORM! | No |
| Task Catcher | U | tasktrap.exe | Real-time monitor for Task Catcher from BillP Studios - which "allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available | No |
| Task Catcher Monitor | U | tasktrap.exe | Real-time monitor for Task Catcher from BillP Studios - which "allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available | Yes |
| Task Catcher Real-Time Detector | U | tasktrap.exe | Real-time monitor for Task Catcher from BillP Studios - which "allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available | No |
| tasktrap | U | tasktrap.exe | Real-time monitor for Task Catcher from BillP Studios - which "allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available | Yes |
| All Sea screen saver | X | TaskTray.exe | Free screensaver, installs lots of foistware - remove it | No |
| taskung | X | taskung.exe | Detected by Dr.Web as Trojan.PWS.Siggen.40456 and by Malwarebytes Anti-Malware as Worm.AutoRun. The file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Config | X | TaskUpdate.exe | Added by the MDROP-BRO TROJAN! | No |
| Windows Taskmanager | X | taskxphost.exe | Added by the PUSHBOT.BI WORM! | No |
| Iolo Task Agent | U | Task_Agent.exe | Iolo System Mechanic Task Agent. Scheduled maintenance | No |
| 285616f5a7218ee9a4267c8e6d37acf5 | X | tasmgr.exe | Detected by Dr.Web as Trojan.DownLoader6.58283 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| tasmgr | X | tasmgr.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %ProgramFiles%\Internet Explorer | No |
| WinXPService | X | tasmgr.exe | Detected by Microsoft as Backdoor:Win32/Kirsun.A. The file is located in %System% | No |
| Ewth | X | tasn.exe | PurityScan adware | No |
| tastylbojozt | X | tastylbojozt.exe | Detected by Malwarebytes Anti-Malware as Trojan.Gen. The file is located in %UserProfile% | No |
| ttaa | X | tata.exe | Added by the LINEAGE-T TROJAN! | No |
| tat | X | tatss.exe | Delfin PromulGate adware | No |
| TAudEffect | ? | TAudEff.exe | TOSHIBA Notebook related. What does it do and is it required? | No |
| Tau monitor | Y | Taumon.exe | "Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system." Now discontinued | No |
| tava | X | tavo.exe | Added by the CRPYT.DE TROJAN! | No |
| Trend Micro AntiVirus 2007 | Y | tavui.exe | Part of Trend Micro AntiVirus 2007 | No |
| office | X | tawisys.ini | Detected by Dr.Web as Trojan.Hitpop.4296. Note - this entry loads from the Windows Startup folder and the file is located in %Windir% | No |
| Taxie Information | X | taxie.exe | Added by the SDBOT.BIB WORM! | No |
| aldefr ere service | X | tay0x.exe | Added by the RBOT-XS WORM! | No |
| blah service | X | tazkmgr.exe | Added by the RBOT.UA WORM! | No |
| Total Anti Malware Protection | X | TA[random].exe | Total Anti Malware Protection rogue security software - not recommended, removal instructions here | No |
| TLogonPath | U | tb2logon.exe | Timbuktu Pro - remote desktop access software | No |
| TB2PROEXE | U | tb2start.exe | Timbuktu Pro - remote desktop access software | No |
| tbbMeter | U | tbbmeter.exe | tbbMeter - bandwidth meter developed by thinkbroadband.com "to help you monitor your Internet usage. It allows you to see how much your computer is sending to and receiving from the Internet in real time. It also shows you how your Internet usage varies at different times of the day" | Yes |
| REMOVE ME | X | tbbzxzxcxxcx.exe | Added by the SDBOT-TA WORM! | No |
| msnmsg | X | TBC.exe | Added by an unidentified TROJAN! | No |
| TBC.exe | U | TBC.exe | TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus | No |
| TBC Pro | U | tbcpro.exe | TitleBarClock Pro - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus | No |
| tbctray | N | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start → Settings → Control Panel | No |
| TraySantaCruz | N | tbctray.exe | Provides quick access via a System Tray icon to the control panel for Turtle Beach's Santa Cruz or VideoLogic's SonicFury soundcards. Available via Start → Settings → Control Panel | No |
| HDhelp | ? | tbhdhelp.exe | Associated with Philips Edge series soundcards. Is it required? | No |
| TBLFUNC | Y | tblmouse.exe | Aiptek HyperPen graphics tablet driver | No |
| Taskbar Button Manager | Y | tbm.exe | Taskbar Button Manager from Innovative Solutions - "is a simple utility that helps you arrange the buttons on your Windows taskbar in any way you want by using drag and drop" | No |
| tbm | Y | tbm.exe | Taskbar Button Manager from Innovative Solutions - "is a simple utility that helps you arrange the buttons on your Windows taskbar in any way you want by using drag and drop" | No |
| Textbridge Instant Access OCR | N | TBMenu.exe | Part of the now discontinued TextBridge OCR (optical character recognition) software from Nuance (was Scansoft) - for scanning documents into popular editing applications. Available via Start → Programs | No |
| Network Associates Error Reporting Service | U | TBMon.exe | Network Associates Error Reporting Tool - tool traps errors and requests submission to NAI for the purpose of betatesting new software | No |
| TurboNote | N | tbnote.exe | Post-It's on your desktop. Available via Start → Programs | No |
| tbon | X | tbon.exe | BestOffers adware | No |
| Gainward | U | TBPanel.exe | Configuration utility for Gainward (a Palit Microsystems subsidiary) graphics cards. Not required unless you use non-default settings. Available via Start → Settings → Control Panel | No |
| TBPanel | U | TBPanel.exe | Configuration utility for Palit Microsystems (and their Gainward subsidiary) graphics cards. Not required unless you use non-default settings. Available via Start → Settings → Control Panel | No |
| TBPS | X | TBPS.exe | WebSearch Toolbar - HuntBar hijacker, toolbar installer variant | No |
| MSTaskbar 32 | X | tbsvc32.exe | Added by the RBOT.BQZ WORM! | No |
| TBTray | N | tbtray.exe | VLSI/QSound ThunderBird PCI Control Panel. System Tray access to the settings for this and related soundcards. Available via Start → Settings → Control Panel | No |
| Uninstall_TBPS | X | TBuninst.exe | WebSearch Toolbar - HuntBar hijacker, toolbar installer variant | No |
| Bayswap2 | U | TbUpdate.exe | Hot-swappable drive management on Compaq Notebooks which allows you to swap drives without closing down Windows. Only required if you frequently swap bay devices | No |
| TB_setup | ? | TB_ANI~1.EXE | ?? | No |
| TB_setup | X | tb_setup.exe | HuntBar hijacker, toolbar installer | No |
| TimeCalendar | U | tc.exe | TimeCalendar digital planner | No |
| tcactive | Y | tca.exe | Part of The Cleaner from MooSoft - stops malware before it can do any damage | No |
| TCASUTIEXE | N | TCASUTI.exe | Associated with the 3COM diagnostic module (3COM NIC Doctor).?No further information is available | No |
| TCASUTIEXE | N | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start → Programs | No |
| TCAUDIAG -off | N | tcaudiag.exe | 3Com NIC Installation/Diagnostic MFC application. Diagnostics may be run from the Start → Programs | No |
| TCDPbtn | ? | TCDPbtn.exe | Found on a Toshiba laptop | No |
| TCDPlay | ? | TCDPlay.drv | Found on a Toshiba laptop - sounds like the driver for the CD-ROM but why doesn't it use the standard Windows drivers - any comments? | No |
| Trojancheck 6 Guard | U | tcguard.exe | TrojanCheck anti-trojan software | No |
| tciocp64 | X | tciocp64.exe | Added by the GAMEOL.AQ TROJAN! | No |
| tcjavacpl | X | tcjavacpl.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %ProgramFiles%\Java\jre1.6.0_07\bin | No |
| TClock | U | TCLOCK.EXE | Kazubon TClock. Utility that amongst other things synchronizes your system clock with Internet time servers. Available via Start → Programs | No |
| TClockEx | U | TCLOCKEX.EXE | Puts a configurable time/date display in the tray (and other features). Freeware by Dale Nurden and is popular on cover disks | No |
| TClock.exe | X | tclock_install.exe | TClock - distributed and installed without user permission by other rogue software or malware. TClock contains no uninstall facility through Windows. As TClock is of dubious origin and usefulness, it should be terminated and removed if detected | No |
| tcmonitor | Y | tcm.exe | Part of The Cleaner from MooSoft - warns of changes to the registry | No |
| TCOYFReminder | U | tcoyftray.exe | My ParenTime Fertility Planner Reminder. The calendar provides a quick overview of the status of your fertility | No |
| Adobe Update System | X | tcp.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here | No |
| tcp checker | X | tcpcheck.exe | Added by the VBBOT-A TROJAN! | No |
| tcpipmon | X | tcpipmon.exe | Added by the CLICKER-EF TROJAN! | No |
| tcpippui | X | tcpippui.exe | Added by the RBOT-APS WORM! | No |
| tcpippui32 | X | tcpippui32.exe | Added by the RBOT-ART WORM! | No |
| tcpipsvc.exe | X | tcpipsvc.exe | Added by the AGOBOT-PG WORM! | No |
| Winsock driver | X | tcpmngr.exe | Added by the SPYBOT-CK WORM! | No |
| TCPServer | X | TCPServer.exe | Added by a variant of W32/Sdbot.worm | No |
| Adware.Admess | X | tcpservice2.exe | Admess adware | No |
| Run Services as Application | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Services Administrator | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Spooler SubSystem Application | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Tcp Application Manager | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows .Net Manager | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Local Services | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Service Manager | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| Windows Web Services | X | tcpsvc.exe | Added by the DLOADER-NY TROJAN! | No |
| TCP Internet Services | X | TCPSVC32.EXE | Added by the SPYBOT.X BACKDOOR! | No |
| TCPXP Update | X | tcpxp.exe | Added by the RBOT-UL WORM! | No |
| 00TCrdMain | Y | TCrdMain.exe | Related to the flash card slot on a Toshiba laptop. Ending this process will disable access to the flash cards | No |
| Adv_TopC | X | TCSearch.exe | Detected by Dr.Web as Trojan.DownLoader7.18341 and by Malwarebytes Anti-Malware as Adware.K.AdvTop | No |
| TCtrlIOHook | U | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. Required if you want the hotkeys to work properly | No |
| TCtrlIOHook.exe | U | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. Required if you want the hotkeys to work properly | No |
| TCtryIOHook | U | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. Required if you want the hotkeys to work properly | No |
| tcupdater | X | tcupdater.exe | Topconverting.com/180Search adware updater | No |
| IEDriver | X | TD.exe | IeDriver adware variant | No |
| TD813SNIA02O.exe | X | TD813SNIA02O.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %UserProfile% | No |
| TDAlert | U | TDAlert.exe | Part of Trust Delete from EgisTec Inc - which "is a remote data deletion software to protect your confidential data and prevent them from falling into the wrong hands when your PC is stolen or missing" | Yes |
| TRUST DELETE | U | TDAlert.exe | Part of Trust Delete from EgisTec Inc - which "is a remote data deletion software to protect your confidential data and prevent them from falling into the wrong hands when your PC is stolen or missing" | Yes |
| TrustDelete Alert | U | TDAlert.exe | Part of Trust Delete from EgisTec Inc - which "is a remote data deletion software to protect your confidential data and prevent them from falling into the wrong hands when your PC is stolen or missing" | Yes |
| WinDirectories | X | tdirs.exe | Added by the VB-EPB VIRUS! | No |
| TDispVol | U | TDispVol.exe | Used on Toshiba computers to make the Fn key have control over the volume on/off | No |
| TDKSTART | U | TDKSTART.EXE | Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. | No |
| TDKTASK | N | TDKTASK.EXE | Taskbar utility for a "control panel" for a CD-RW | No |
| TDS3 | Y | TDS-3.exe | DiamondCS TDS-3 antitrojan. Can be used to scan on demand, but required in startup if you prefer real time protection. No longer available | No |
| TDspOff | ? | Tdspoff.exe | Found on a Toshiba laptop | No |
| Tracks Eraser | U | te.exe | Tracks Eraser from Acesoft - "Erases all tracks of your internet activity" | No |
| Tracks Eraser Pro | U | te.exe | Tracks Eraser Pro from Acesoft - "Erases all tracks of your internet activity" | No |
| TurboExplorer | U | TE.exe | Web accelerator - "TurboExplorer 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer 4/5 to achieve a faster and more effective approach to the internet". Only needed if you find it improves web browsing | No |
| MJ | X | te32.exe | Added by the AGENT.HAA TROJAN | No |
| Teach In Box | N | teachbox.exe | Tutoring program that comes with a SystemAX Computer | No |
| WGAA | X | team.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| 1fec1ae9366168d9d4cf848c29e7b19c | X | TeamViewer.exe | Detected by McAfee as RDN/Generic.grp!cw and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ. Note - this is not the legitimate TeamViewer remote support tool which is usually located in %ProgramFiles%\TeamViewer\Version*. The one is located in %UserProfile% | No |
| Steam | X | Teamviewer.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this is not a valid entry for either the Steam game distribution software or TeamViewer remote support tool. The file is located in %MyDocuments%\Services | No |
| Spybot - Search & Destroy | Y | TeaTimer.exe | Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. "Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future". Also provides System Tray access to Spybot S&D and detects when processes want to change critical registry settings such as the startup entries - giving the user the option to allow/deny the change | Yes |
| SpybotSD TeaTimer | Y | TeaTimer.exe | Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. "Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future". Also provides System Tray access to Spybot S&D and detects when processes want to change critical registry settings such as the startup entries - giving the user the option to allow/deny the change | Yes |
| TeaTimer | Y | TeaTimer.exe | Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. "Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future". Also provides System Tray access to Spybot S&D and detects when processes want to change critical registry settings such as the startup entries - giving the user the option to allow/deny the change | Yes |
| teavamefqehu | X | teavamefqehu.exe | Detected by McAfee as RDN/Generic Downloader.x!o and by Malwarebytes Anti-Malware as Trojan.Agent.US | No |
| Tech-In-A-Box | Y | techbox.exe | Tech-in-a-Box "provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running" | No |
| ATI Technology Startup | X | techstart.exe | Added by the RBOT-AEU WORM! | No |
| CNET TechTracker | N | TechTracker.exe | "CNET TechTracker is a free application from CNET that helps keep the software on your computer up-to-date and secure. TechTracker works by scanning the software installed on your computer and alerting you when updates are available" | No |
| Teco | U | Teco.exe | Toshiba's Eco Utility that "offer improved energy management. With a single click you can switch to a pre-configured power plan that will not only let you go green, but let you see the measurable savings too" | No |
| Realtek Sound Manager | X | Tecompntwx.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| DpUtil | U | TEDTray.exe | Main executable for TOSHIBA DualPoint Utility Main Module. It is a system tray icon program that provides configuration options for dual pointing device | No |
| Microsoft Inet Xp.. | X | teekids.exe | Detected by Symantec as W32.Blaster.C.Worm | No |
| teeveewatchSA | X | teeveewatchSA.exe | Detected by Malwarebytes Anti-Malware as Adware.HotBar.CP. The file is located in %AppData%\teeveewatchSA\bin\[version] | No |
| teiteq | X | teiteq.exe | Added by the VB-WC MALWARE! | No |
| Winsock32 driver | X | tekno.scr | Detected by McAfee as MultiDropper-DC | No |
| tekur | X | tekur.exe | Added by the SILLYFDC-GI WORM! | No |
| ovyriwi | X | telace.exe | Added by the SDBOT.BVS WORM! | No |
| Microsoft Telecoms Center | X | telcoms.exe | Added by the AGOBOT.GJ WORM! | No |
| Microsoft Lsass Center | X | telecomes.exe | Added by a variant of the RBOT WORM! See here | No |
| Telemeter 3.0 | N | telemeter3.exe | Internet connection bandwidth meter from a user ISP | No |
| Telepath | Y | telepath.exe | Drivers for the WinModem versions of the US Robotics "Telepath" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information | No |
| KernelFaultCheck | X | tell32.exe | Added by the LEGMIR-BF TROJAN! | No |
| Microsoft Telecoma Center | X | tellcoma.exe | Added by the RBOT-AWX WORM! | No |
| Microsoft Telecom Center | X | tellecom.exe | Added by a variant of the RBOT WORM! | No |
| Telnet | X | Telnet.exe | Added by the VOUMIT-A WORM! Note - this is not the legitimate telnet.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder | No |
| BigPondWirelessBroadbandCM | Y | TelstraUCM.exe | Telstra wireless broadband manager | No |
| 461ed17e3be8f358a9046d667554a33a | X | temp.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| csrss | X | temp.exe | Detected by Microsoft as Trojan:Win32/Delf.KJ and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| HKCU | X | temp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp% | No |
| HKLM | X | temp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.HMCPol.Gen. The file is located in %Temp% | No |
| Microsoft Machine | X | temp.exe | Added by the RBOT-FSQ WORM! | No |
| Policies | X | temp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.PGen. The file is located in %Temp% | No |
| SystemRegistryRepair | X | temp.exe | Added by the NOKPUDA WORM! | No |
| temp32 | X | temp32.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Windir% | No |
| temp32 | X | temp32.exe | Detected by McAfee as Generic.dx. The file is located in %System% | No |
| ASDPLUGIN | X | temp532.exe | AsdPlug premium rate adult content dialer | No |
| HELPER | X | temp532.exe | AsdPlug premium rate adult content dialer variant | No |
| IEACCESS | X | temp532.exe | AsdPlug premium rate adult content dialer variant | No |
| IntelAgent | X | temp68.exe | Detected by Microsoft as Backdoor:Win32/Kelihos.F | No |
| Microsoft MachineUpdatese | X | tempes.exe | Added by the RBOT.EWN BACKDOOR! | No |
| TempReader | X | TempFile.exe | Detected by Dr.Web as Trojan.MulDrop3.55199 and by Malwarebytes Anti-Malware as Trojan.FakeMS | No |
| suicide | X | tempfile2.bat | Personal Protector rogue security software - not recommended, removal instructions here | No |
| [various names] | X | TemplateDongle.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| WinCheck | X | tempo.Exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| jv16 PT TempFileTool | U | TempTool.exe | jv16 PowerTools File Cleaner - "allows you to find obsolete and left-over temporary files" | No |
| tempx | X | tempx.exe | Added by the TEMPEX.A TROJAN! | No |
| AARC | X | temsc.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %MyDocuments%\SYS | No |
| 54rk | X | Tencentl00.exe | Detected by Malwarebytes Anti-Malware as Spyware.OnLineGames. The file is located in %System% | No |
| 54rk | X | Tencentl6c.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| 54rk | X | Tencethw.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %System% | No |
| TenClips | U | TenClips.exe | "TenClips is a lightweight and must have multiple clipboards for software developers. It is fast and very easy to use. There is no superfluous window or manipulation" | No |
| TEPA.exe | Y | TEPA.exe | TELUS eProtect Advisor tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| [various names] | X | teqq32.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| TE_RegProtect | U | TERegPct.exe | Registry repair utility part of the Anti Trojan Elite (ATE) anti-malware tool | No |
| MSN | X | tesakmger.exe | Added by the SPYBOT.AVJ WORM! | No |
| Windeows NetStart Service2 | X | tesakrmger.exe | Added by the RBOT-AMY WORM! | No |
| TEscKey | U | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the | No |
| Microsoft sddcE Contol | X | teskmangr.exe | Added by a variant of the RBOT-AUM WORM! | No |
| System Service | X | teskmangr.exe | Added by the RBOT-AUV WORM! | No |
| Tesla | ? | TESLA.EXE | ?? | No |
| Tesseract-OCR | N | tesseract.exe | Tesseract OCR (Optical Character Recognition) open source software for scanning and converting documents | No |
| (Default) | X | test.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %UserProfile%\Desktop | No |
| af8e95a43cac5319b6cccfe239aa33bd | X | test.exe | Detected by McAfee as RDN/Generic.dx!bc3 and by Malwarebytes Anti-Malware as Backdoor.Agent.TRJ | No |
| d4f8ba9eae9d84a2873c361974f1f3aa | X | Test.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| LoadWatcher | ? | Test.exe | Reportedly part of a webcam surveillance program that's supposed to test SMTP dialling in the event of an alert? Is this correct? | No |
| MS-GRT32 | X | test.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Temp%\IXP000.TMP | No |
| MSIEXEC.EXE | X | test.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.TPGen. The file is located in %Temp% | No |
| Test* | X | Test.exe | Added by the AUTORUN-SG WORM - where * represent a number. If, for example, you have four physical hard drive partitions and one removable drive, the file "Test.exe" will be present in the root of the partition (ie, C:\, D:\) with startup entries of "Test1" through "Test5" | No |
| WINDOWS SYSTEM | X | test.exe | Added by the MYTOB.DJ WORM! | No |
| WinUpdate | X | test.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| WINDOWS SYSTEM | X | test2.exe | Added by the MYTOB.DJ WORM! | No |
| WINDOWS SYSTEM | X | test3.exe | Added by the MYTOB.DV WORM! | No |
| me1 | X | TestApp.exe | Detected by Dr.Web as Trojan.SMSSend.2969 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| mstwain32 | X | teste.exe | Detected by McAfee as Generic Dropper.f and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| [various names] | X | Testimonials.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Winsock32 driver | X | TESTING.EXE | Added by the SPYBOT-B WORM! | No |
| Windows | X | TestingSHitwithhost.exe | Detected by Malwarebytes Anti-Malware as Trojan.FakeFlash. The file is located in %AppData% | No |
| testit.exe | X | testit.exe | ISTBar adware | No |
| TESTT | X | testt | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.DC. The file is located in %Temp% | No |
| System | X | testtestt.exe | Added by the DWNLDR-ZLC TROJAN! | No |
| SystemTools | X | testtestt.exe | Added by the DWNLDR-ZLC TROJAN! | No |
| TTS Sync | X | testtts.exe | Added by the SDBOT.BVA WORM! | No |
| AlienAutopsy | N | Test_BS.exe | Alienware computer technical support software | No |
| JuliaPerez | X | Tetek_Gede_Julia_Perez.exe | Added by the AUTORUN-BS WORM! | No |
| TExBUtil Registry | ? | TExBUtil.exe | ?? | No |
| texe32 | X | texe32.exe | Detected by Dr.Web as Trojan.Siggen4.27324 and by Malwarebytes Anti-Malware as Trojan.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| Link Human Video Bus Extender CNG DCOM | X | texeokatr.exe | Detected by McAfee as Generic.dx!bcwj | No |
| TextAloud | N | TextAloudMP3.exe | TextAloud MP3 - convert text into spoken words and MP3s | No |
| Text Monkey PRO | N | TextMonkeyPRO.exe | Text Monkey PRO by Boxer Software - "has dozens of useful text processing functions that were designed to save you time and effort on all types of editing tasks. Because Text Monkey operates on text while it resides on the Windows clipboard, it extends the functionality of every program you use" | No |
| Memory+ | U | tfimemsr.exe | Memory+ memory optimizer | No |
| TFncKy | U | TFncky.exe | Deals with the | No |
| TFNF5 | U | TFNF5.exe | Toshiba Hotkey Utility for Display Devices. By pressing | No |
| [various names] | X | TForm1.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| dla | Y | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" | Yes |
| tfswctrl | Y | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" | Yes |
| tfswctrl.exe | Y | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas (now Symantec) and others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controls the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but won't be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" | Yes |
| TFTP*** | X | tftp*** | Added by a variant of the SPYBOT WORM! where *** can be any number | No |
| TFTray | Y | TFTray.exe | System Tray access to ThreatFire no-signature anti-malware from PC Tools - which "features innovative real-time behavioral technology that provides powerful protection against both known and unknown viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware" | Yes |
| ThreatFire | Y | TFTray.exe | System Tray access to ThreatFire no-signature anti-malware from PC Tools - which "features innovative real-time behavioral technology that provides powerful protection against both known and unknown viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware" | Yes |
| TFunckey | U | TFuncKey.exe | Deals with the | No |
| Windows Manager Update Inc | X | tgb.exe | Added by the SDBOT-ACM WORM! | No |
| hcenter | U | tgcmd.exe | Part of software from Support.com (aka SupportSoft or Tioga) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the "TgAddServer" entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" | No |
| Support.com Scheduler and Command Dispatcher | U | tgcmd.exe | Part of software from Support.com (aka SupportSoft or Tioga) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the "TgAddServer" entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" | Yes |
| tgcmd | U | tgcmd.exe | Part of software from Support.com (aka SupportSoft or Tioga) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the "TgAddServer" entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" | Yes |
| tgcmdprovidersbc | U | tgcmd.exe | Part of software from Support.com (aka SupportSoft or Tioga) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the "TgAddServer" entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" | No |
| TGDC IE Plugin | X | tgdc.exe | ShopForGood spyware - see here | No |
| MSConfig | X | tgdnunbg.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %UserProfile% | No |
| TgAddServer | N | tgfix | Software from Support.com (aka SupportSoft or Tioga) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can potentially cause deterioration in a PC's performance. This part looks after the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinXP/Me). If not available via Add/Remove try here | No |
| TgAddServer | N | tgfix.exe | Software from Support.com (aka SupportSoft or Tioga) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can potentially cause deterioration in a PC's performance. This part looks after the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinXP/Me). If not available via Add/Remove try here | No |
| Tgsetsite | U | tgfix.exe | Also see the "TgAddServer" entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation | No |
| ComcastSUPPORT | N | tgkill.exe | Comcast struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This "beta" release was made available to download by mistake and should be removed via Start → Control Panel → Add/Remove Programs | No |
| tgkill | N | tgkill.exe | Comcast struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This "beta" release was made available to download by mistake and should be removed via Start → Control Panel → Add/Remove Programs | No |
| TgstatFix | ? | tgstat.exe | Part of software from Support.com (aka SupportSoft or Tioga) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the "TgAddServer" entry | No |
| thn4n | X | th7dg2h.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader. The file is located in %MyDocuments%\Services | No |
| Java | X | thanksbrogame.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %AppData% | No |
| Thdetrf | ? | thdetr32.exe | Appears to be related to Lycos advertising | No |
| The Registry Sentinel | X | The Registry Sentinel.exe | The Registry Sentinel rogue security software - not recommended, removal instructions here | No |
| Desktop Weather | N | THE WEATHER CHANNEL.exe | Desktop Weather by The Weather Channel - provides current temperature, conditions, alerts, etc | No |
| Desktop Weather 3 | N | THE WEATHER CHANNEL.exe | Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc | No |
| The Web Sentinel | X | The Web Sentinel.exe | The Web Sentinel rogue security software - not recommended, removal instructions here | No |
| TheDefend.exe | X | TheDefend.exe | TheDefend rogue security software - not recommended, removal instructions here. A member of the AntiAID family | No |
| Windows Guardian | U | thehel1iawgrd32.exe | Part of First Aid by Cybermedia who were subsequently bought by McAfee (Network Associates). Protects your Windows system from application failure and crashes | No |
| them windows7 | X | them windows7.exe | Detected by McAfee as RDN/Generic.bfr and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - the file is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| TheSpyBot | X | TheSpyBot.exe | TheSpyBot rogue security software - not recommended, removal instructions here | No |
| Desktop Weather 3 | N | THEWEA~1.EXE | Desktop Weather 3 by The Weather Channel - provides current temperature, conditions, alerts, etc | No |
| display | U | The_Eye.exe | ComSpySysSvr surveillance software. Uninstall this software unless you put it there yourself | No |
| Gallery | X | thG.exe | Added by the AUTORUN-JR WORM! | No |
| THGuard | U | THGuard.exe | Resident memory scanning for TrojanHunter | No |
| Think Green Weather | U | Think Green Weather.exe | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| Think Green Weather.exe | U | Think Green Weather.exe | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| Think Green Weather | U | THINKG~1.EXE | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com | Yes |
| this | X | this.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.KR. The file is located in %AppData%\Microsoft\This | No |
| pop06apelt | X | thiselt.exe | ZenoSearch adware variant | No |
| THKem | U | THKem.exe | Toshiba Hot Key emulation for their laptops | No |
| Thumbs Plus *.* | X | thmbplus**.exe | Added by the AGOBOT-AAF WORM! ** is a combination of a random digits and characters | No |
| Thoosje Vista Sidebar | U | Thoosje Vista Sidebar.exe | Thoosje's Vista Sidebar - sidebar and skins for microsoft Windows XP and Vista | No |
| THOTKEY | U | THotkey.exe | Associated with the Fn+ keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen | No |
| ThpSrv | Y | thpsrv.exe | Toshiba Hard Drive Protection Utility - moves the Hard Drive head to a safe position in case of shock or vibration to reduce the risk of damage that could be caused by head-to-disk contact | No |
| EleFunAnimatedWallpaper | U | Three Windmills.exe | Three Windmills animated wallpaper from | No |
| T_H_S_M | Y | THSM.EXE | Part of The Hacker Anti-malware from Peruvian company Hacksoft S.R.L. | No |
| thuder | X | thuder.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.THU. The file is located in %ProgramFiles%\SSFKLJ | No |
| 32-bit Thunking service | X | thunk32.exe | Added by the DERDERO.A WORM! | No |
| Microsoft Update Machine | X | thvfyq.exe | Added by the RBOT.AEA BACKDOOR! | No |
| THX TruStudio NB Settings | U | THXAudNB.exe | Part of Creative's THX TruStudio Pro - which "is specially designed to bring the same great audio experience found in live performances, films, and recording studios - to the PC" | No |
| THGuard | U | TH_Guard.exe | Resident memory scanning for TrojanHunter | No |
| tibs3 | X | tibs3.exe | Premium rate adult content dialler - see here | No |
| tibs5 | X | tibs5.exe | Premium rate adult content dialer. The file is located in %System% | No |
| True Internet Color Icon | U | TICIcon.exe | Part of 3Deep® from E-Color (superseded by 3DxWizzard) - "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images" | No |
| ticisms | X | ticisms.exe | Added by the PWSDLB-B TROJAN! | No |
| TIxDSL | U | tidslmon.exe | Actiontec DSL modem. Associated with High Speed AOL DSL. Used to get line sync with the Actiontec DSL USB Modem. Available via Start → Programs | No |
| tigixbakydqy | X | tigixbakydqy.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| TiKL | U | tikl.exe | TinyKeylogger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| Task manager | X | TikTo.exe | Added by the RBOT.LV WORM! | No |
| Tilerun | X | Tilecom32.com | Added by a variant of W32/Sdbot.worm | No |
| TileFree | X | Tilecomfree.com | Added by the RBOT.CQE WORM! | No |
| Top Tilecom | X | Tilecomtop.com | Added by the RBOT.BXD WORM! | No |
| Topic Soft | X | Tilesoft.com | Added by the RBOT.GDH WORM! | No |
| Topic Tilesys | X | Tilesys.com | Added by a variant of the RBOT WORM! | No |
| timber | X | timber.exe | Detected by Malwarebytes Anti-Malware as Spyware.Password. The file is located in %AppData%\timber | No |
| Microsoft DirectX | X | time123.exe | Added by the SDBOT.MD WORM! | No |
| timestamp | X | timeapr32.exe | Added by the AGENT-DRU TROJAN! | No |
| ImMsn | X | timed.exe | Added by the WEBDOR.AK BACKDOOR! | No |
| Timer | X | timed.exe | Added by the BDOOR-LV BACKDOOR! | No |
| TimeDateMUICallback | X | TimeDateMUICallback.exe | Detected by Malwarebytes Anti-Malware as Trojan.Ransom. The file is located in %AppData%\Microsoft\Windows\[4 numbers] | No |
| TimeDateMUICallback | X | TimeDateMUICallback.exe | Detected by Symantec as Trojan.Ransomcrypt.C and by Malwarebytes Anti-Malware as Trojan.Ransom.Gen. The file is located in %AppData%\SQL Server Compact Edition | No |
| TimeLeft | U | TimeLeft.exe | TimeLeft by NesterSoft Inc. - "countdown, reminder, clock, alarm clock, tray clock, stopwatch, timer, sticker, auction watch, web countdown and time synchronization utility" | No |
| Time Manager | X | TimeManager.exe | Added by the MYTOB-BV WORM! | No |
| Timemanager.exe | U | Timemanager.exe | Time Manager will let you track billable and non-billable time by customer, by category and by associate and then integrate directly to our custom billing package | No |
| TimeOnline | N | TIMEONLINE.EXE | Lightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start → Programs | No |
| MacDrive7.0.4TimeOutPatch | ? | TimeOutPatch.EXE | Part of MacDrive 7 from Mediafour Corporation - "enables anyone using Windows Vista, XP, and 2003 Server to seamlessly access Mac disks (HFS/HFS+) of all types, including CDs, DVDs, hard drives, floppy, Zip, Jaz, and more!" Interim patch for an older version? Is it no longer required? | No |
| TIMER | X | TIMER.EXE | Added by the TIMESE.AG WORM! | No |
| Windows Time Server | X | TimeSRV.exe | Added by the SPYBOT.DNC WORM! | No |
| timessquare | X | timessquare.exe | MediaMotor.IEMonitor malware! | No |
| Atomic Time Synchronizer | U | TimeSync.exe | TimeSync - lets you synchronize your computer's clock with any internet atomic clock | No |
| TimeSyncApp | X | TimeSynchronize.exe | DealHelper adware | No |
| TimeUp | N | Timeup.exe | TimeUp - internet online timer | No |
| Windows Registry Scan | X | timeupdate.exe | Added by the SPYBOT.JE WORM! | No |
| MS Time | X | timezone.exe | Detected by Trend Micro as WORM_AGOBOT.ADY | No |
| Timezone | U | TimeZone.exe | Microsoft Daylight Saving Time Update Utility - see here | No |
| TIMHost | X | TIMHost.exe | Added by the PWS-ANT TROJAN! | No |
| froody | X | timoty.exe | Detected by Trend Micro as WORM_NUCRP.GEN. The file is located in %System% | No |
| version | X | timoty.exe | Detected by Trend Micro as WORM_NUCRP.GEN. The file is located in %System% | No |
| Acronis True Image | U | TimounterMonitor.exe | Part of Acronis True Image backup software - with which you can create backups of individual directories, partitions (ie, C:, D:) or a whole hard drive - and mount those images onto a drive/partition with sufficient space. If you mount an image in "Read Only" you cannot change any contents. In "Read & Modify" mode you can change the contents and in this mode TimounterMonitor ensures that any changes made to the mounted image will not allow it to grow larger than the disk on where the backup image is stored. . Required if you mount partitions or disk images in "Read & Modify" mode and are concerned about disk space in the partition/disk where the backup images are stored. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| AcronisTimounterMonitor | U | TimounterMonitor.exe | Part of Acronis True Image backup software - with which you can create backups of individual directories, partitions (ie, C:, D:) or a whole hard drive - and mount those images onto a drive/partition with sufficient space. If you mount an image in "Read Only" you cannot change any contents. In "Read & Modify" mode you can change the contents and in this mode TimounterMonitor ensures that any changes made to the mounted image will not allow it to grow larger than the disk on where the backup image is stored. . Required if you mount partitions or disk images in "Read & Modify" mode and are concerned about disk space in the partition/disk where the backup images are stored. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| TimounterMonitor | U | TimounterMonitor.exe | Part of Acronis True Image backup software - with which you can create backups of individual directories, partitions (ie, C:, D:) or a whole hard drive - and mount those images onto a drive/partition with sufficient space. If you mount an image in "Read Only" you cannot change any contents. In "Read & Modify" mode you can change the contents and in this mode TimounterMonitor ensures that any changes made to the mounted image will not allow it to grow larger than the disk on where the backup image is stored. . Required if you mount partitions or disk images in "Read & Modify" mode and are concerned about disk space in the partition/disk where the backup images are stored. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| PHIME2002A | U | TINTSETP.EXE | Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to. Found on PCs where Asian languages (e.g. Chinese, Hindi, Japanese, etc) have been installed through the Regional and Language options icon in the Control Panel | Yes |
| PHIME2002ASync | U | TINTSETP.EXE | Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to. Found on PCs where Asian languages (e.g. Chinese, Hindi, Japanese, etc) have been installed through the Regional and Language options icon in the Control Panel | Yes |
| TINTSETP | U | TINTSETP.EXE | Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails, documents and other files - should you need to. Found on PCs where Asian languages (e.g. Chinese, Hindi, Japanese, etc) have been installed through the Regional and Language options icon in the Control Panel | Yes |
| Tinue | X | Tinue.exe | Added by the SILLYFDC.BCO WORM! | No |
| tinySpell | U | tinyspell.exe | Tinyspell - "allows you to easily and quickly check the spelling of words in any Windows application. Monitors your typing on the fly, alerts you whenever it detects a misspelled word, and checks the spelling of every word you copy to the clipboard" | No |
| TiomanExe | U | Tioman.Exe | Agate Tioman - warm and hot swap removable bay device manager for IBM laptops | No |
| tipguard.exe | X | tipguard.exe | Privacy Commander rogue privacy program - not recommended, removal instructions here | No |
| TitleTime | U | TiTime.exe | "TitleTime adds the current date and/or time to the Caption of the currently active application window. Additional options are a second clock (with a different time), week number, GMT/UTC time, Swatch Internet Time and Sounds at each full, half or quarter hour" | No |
| Titlebar Date | U | Titlebar Date.exe | Titlebar Date by Titlebar Software - displays the day of the week and date and time in the active window's tile bar. For example, open Notepad and the day and date will appear at the top of the window. The originator's website is no longer available but you can still download it here | Yes |
| Titlebar Time | U | Titlebar Time.exe | Titlebar Time by Titlebar Software - displays the day of the week, date and time in the active window's tile bar. For example, open Notepad and the day, date and time will appear at the top of the window. The originator's website is no longer available but you can still download it here | Yes |
| TiTleBarClock | U | TiTleBarClock.exe | TitleBarClock - displays Day, Time, Date, Month, Year, FreeMem, and FreeDriveSpace on the right side of the title bar in any main window that has the mouse or keyboard focus | No |
| TivoNotify | ? | TiVoNotify.exe | Part of Tivo Desktop. What does it do and is it required? | No |
| TivoServer | U | TiVoServer.exe | Tivo Server - installed with the TiVo Home Media Option. It streams audio files to your television/home theater from your PC | No |
| TivoTransfer | U | TivoTransfer.exe | Tivo Transfer Service. TiVo Desktop is an easy-to-use application that lets you publish and share digital music, photos and TiVo recordings between your networked TiVo Series2 DVR and your computer | No |
| tiwi | X | tiwi | Added by the RAHIWI.A WORM! | No |
| TI WLAN | U | TIWLANCu.exe | Texas Instruments TI wireless LAN products | No |
| TizzleTalk | N | TizzleTalk.exe | TizzeTalk is a dialect translator for Yahoo, MSN, AOL Instant Messengers. Bundles adware, hence not recommended. From their EULA : "As a result of installing the Company's Software, you will see occasional banner ads, pop-up or pop-under ads, or other types of ads selected based on your online activities .../... Occasionally, we may automatically or through other remote means, update, upgrade, patch or uninstall the Company's Software, including the Company's advertising-supported software, without further notice to you. These upgrades also may include installation of additional applications from the Company as well as third party applications" | No |
| Anti Trojan Elite | Y | TJEnder.exe | Anti Trojan Elite (ATE) anti-malware tool | No |
| tJeOfxpyoLkuKU.exe | X | tJeOfxpyoLkuKU.exe | Detected by Malwarebytes Anti-Malware as Rogue.Fakealert. The file is located in %AppData% | No |
| Windows Service Agent | X | tjybssd.exe | Added by the RBOT.XVD BACKDOOR! | No |
| TkBell.Exe | N | tkbell.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools → Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK | No |
| TkBellExe | N | tkbell.exe | Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools → Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK | No |
| Winhelp | X | TkBellExe.exe | Detected by Trend Micro as WORM_LOVGATE.E | No |
| Winhelp | X | TkBellExe.exe... | Added by the LOVGATE.Z WORM! | No |
| tkonnect | N | TKONNECT.EXE | Dialer for the Tiscali internet service provider. Available as a desktop shortcut | No |
| Ticket API Monitor | ? | tktmon.exe | Syntegra Device Identification Logger. What does it do and is it required? | No |
| TurboLaunch | U | Tlaunch.exe | TurboLaunch is a tool-bar style application that can be set up to run many programs and perform certain pre-programmed actions | No |
| Komunikator | U | tlen.exe | Tlen - a Polish language instant messaging client | No |
| Sen | X | tlii.exe | Detected by Kaspersky as PurityScan.ah | No |
| tljyxiiw | X | tljyxiiw.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %System% | No |
| tljyxiiw | X | tljyxiiw.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Bot. The file is located in %UserProfile% | No |
| NBCnClt | X | TLnbLdr.exe | Detected by Kaspersky as Trojan.Win32.Vilsel.axfk and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| tlntsvr | U | tlntsvr.exe | Microsoft program associated with Telnet | No |
| Password Door Loader | Y | tlpd.exe | Password Door from TopLang software - lets "you add password protection to any software. When software is protected by Password Door, anyone who wants to use that software must enter the correct password in order to launch it" | No |
| Service Host | X | tm32.exe | Added by the POISON-AG TROJAN! | No |
| Torrent Management Service | X | TMANAGESVC.EX | Added by a variant of the IRCBOT BACKDOOR! | No |
| Trend Micro Anti-Spyware | Y | Tmas.exe | Trend Micro Anti-Spyware - required when using real time monitoring but now discontinued | No |
| OE_OEM | Y | TMAS_OEMon.exe | Related to Trend Micro PC-cillin - Internet Security 12 | No |
| tmchook | X | tmchook.exe | Detected by Kaspersky as the VB.AA TROJAN! | No |
| TMEEJME.EXE | U | TMEEJME.EXE | Toshiba TME (Toshiba Mobile Extension) Control | No |
| Microsoft Update Machine | X | TMEMSER.EXE | Added by the RBOT-NQ WORM! | No |
| TMERzCtl.EXE | U | TMERzCtl.EXE | Toshiba TME (Toshiba Mobile Extension) Control | No |
| TSBxLogon | ? | TMESBS2.EXE | Found on a Toshiba laptop. May be related to the TMESBS entry? | No |
| TMESBS | U | TMESBS21.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on | No |
| TMESBS.EXE | U | TMESBS21.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on | No |
| TMESBS.EXE | U | TMESBS31.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on | No |
| TMESBS.EXE | U | TMESBS32.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on | No |
| TMESBS32 | U | TMESBS32.EXE | Utility related to inserting and removing the slim bay device (such as a DVD/CD-writer) on Toshiba laptops. You can disable this task if you have no intention of ever taking the device out while the laptop is turned on | No |
| TMExLogon | U | TMESRV.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station | No |
| TMESRV.EXE | U | TMESRV11.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station | No |
| TMESRV.EXE | U | TMESRV21.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station | No |
| TMESRV.EXE | U | TMESRV31.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station | No |
| TMESRV31 | U | TMESRV31.EXE | Toshiba utility related to inserting and removing a laptop from a docking station. Not required if you don't use a docking station | No |
| history | X | tmhelp.exe | Detected by Dr.Web as Trojan.MulDrop4.6401 and by Malwarebytes Anti-Malware as Trojan.Agent.HY. The file is located in %System% | No |
| TrendMicro OfficeScan NT | Y | TMLISTEN.EXE | Virus scanner | No |
| Tmmkb | ? | Tmmkysvr.exe | Toshiba multi-media keyboard software - possibly including creating keyboard shortcuts? | No |
| TMMonitor | N | tmmonitor.exe | System Tray access and sync monitor for TotalMedia from Arcsoft - "an all-in-one multimedia application that allows you to access and work with digital photos, home videos, recorded TV programs, radio and your digital music library right from your TV or home computer." The sync monitor initiates the sync schedule that you have set and once it's time to sync the scheduled files, the program starts automatically. Exiting the sync monitor prevents scheduled sync from occurring until it is restarted | Yes |
| Microsoft Windows Updater | X | TMNTSrv.exe | Detected by Malwarebytes Anti-Malware as Trojan.MWF.Gen. The file is located in %System% | No |
| Tmntsrv32 | X | Tmntsrv32.exe | Added by the STARTPAGE.O TROJAN! | No |
| TM Outbreak Agent | U | TMOAgent.exe | Part of Trend Micro web-security products - PC-cillin 2004 and Virus Buster 2003-2004. Notifies users of virus outbreaks and offers to update the scanner | No |
| TMOUSE | U | tmouse.exe | Component of the Toshiba Mouse Control that allows users with an AccuPoint mouse to scroll MS-scroll-compatible documents by holding CTRL + ALT and moving the AccuPoint up or down. It also allows zooming by holding CTRL + SHIFT and moving the AccuPoint up or down. Disabling this item has no adverse effects, except disabling the scroll/zoom features of the AccuPoint | No |
| [9 or 10 numbers] | X | tmp#.tmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.TMPGen. Where # represents a number and the file is located in %Temp% | No |
| [9 or 10 numbers].exe | X | tmp#.tmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.TMPGen. Where # represents a number and the file is located in %Temp% | No |
| MyAccessMedia | X | tmp**.exe [* = random char/digit] | My AccessMedia toolbar related, stealth installed! | No |
| Adobe IX | X | tmp*.tmp.exe | Detected by Sophos as Troj/MSIL-BS and by Malwarebytes Anti-Malware as Backdoor.Agent.TMP | No |
| Adobe XI.exe | X | tmp*.tmp.exe | Detected by Sophos as Troj/Mdrop-EYH and by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen | No |
| appdata.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| explorer.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| Java.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| javaw.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| Skype.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| svchost.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| tmp3 | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| vbc.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| Windows Defender.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| WindowsUpdate.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| WindowsUpdates.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| winprocess.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| WinUpdate.exe | X | tmp*.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent.TMPGen - where * represents anything. The file is located in %Temp% | No |
| tmp.exe | X | tmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| [9 to 10 numbers].exe | X | tmpE.tmp.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Temp% - see examples here and here | No |
| MICROSOFT MOUSE AND KEYBOARD CENTER.EXE | X | tmpE.tmp.exe | Detected by McAfee as RDN/Generic.dx!dp and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| NETSERV32.EXE | X | tmpE.tmp.exe | Detected by McAfee as Generic BackDoor!fqd and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| TMPF | X | tmpE.tmp.exe | Detected by McAfee as Generic BackDoor!fql and by Malwarebytes Anti-Malware as Backdoor.Agent.DC | No |
| Windows Operating System.exe | X | tmpE.tmp.exe | Detected by McAfee as RDN/Generic BackDoor!g and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| tmpF.tmp.exe | X | tmpF.tmp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %Temp% | No |
| tmproxy | Y | tmproxy.exe | Part of Trend Micro web-security products - Internet Security 2005, PC-cillin 2003, and Virus Buster 2003-2004 | No |
| Windows UDP Control Center | X | tmps.exe | Added by the SDBOT.EBA BACKDOOR! | No |
| TMRUBottedTray | U | TMRUBottedTray.exe | RUBotted (from Trend Micro) monitors your computer for suspicious activities and regularly checks with an online service to identify behavior associated with Bots. Upon discovering a potential infection, RUBotted prompts you to scan and clean your computer | No |
| Windows Time | X | tmservice.exe | Added by a variant of the RBOT-YK WORM! | No |
| ThrustTSR | U | TMTMTSR.exe | Thrustmaster Thrustmapper - "t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly" | No |
| TMTMTSR | U | TMTMTSR.exe | Thrustmaster Thrustmapper - "t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly" | No |
| TweakMASTER | U | TMTray.exe | TweakMASTER Internet Optimizer | No |
| F-Secure TNB | Y | TNBUtil.exe | F-Secure antivirus | No |
| TNFQ | X | TNF.exe | Detected by Malwarebytes Anti-Malware as Backdoor.Agent. The file is located in %Windir% | No |
| TNTClk | U | TNTCLK.exe | Overclocking program for TNT, TNT2, and other graphics cards. This program can overclock the graphics card manually after startup when needed, especially before starting a gaming session. However, for simplicity, it can be left checked to let it run once at startup to automatically overclock the graphics card. In this case, it doesn't even run in the background after doing its job | No |
| MS Update- Client "support" 608 | X | tNWCBsrdy.exe | Added by the MDROP-CWJ TROJAN! | No |
| ToADiMon.exe | U | ToADiMon.exe | T-Online ISP software connection assistant | No |
| toastpop | X | toastpop.exe | Detected by Dr.Web as Trojan.KillProc.19830 and by Malwarebytes Anti-Malware as Adware.KorAd.Gen | No |
| toastpop3 | X | toastpop2.exe | Detected by Dr.Web as Trojan.MulDrop4.8014 and by Malwarebytes Anti-Malware as Adware.KorAd.Gen | No |
| Pex Sound Driver | X | Today's Results.vbs | Added by the TRODE-A WORM! | No |
| pex Sound driver 2 | X | Today's Results.vbs | Added by the TRODE-A WORM! | No |
| Today | U | Today.exe | Today from Xarka Software - "a calendar/event journal based on the Greek Orthodox Church holidays" which displays a panel including a calendar, events, feasts, astronomical data and the photo of the day | Yes |
| XarkaToday | U | Today.exe | Today from Xarka Software - "a calendar/event journal based on the Greek Orthodox Church holidays" which displays a panel including a calendar, events, feasts, astronomical data and the photo of the day | Yes |
| TodayTab Client | X | TodayTab.exe | Detected by McAfee as Generic.dx!bbbt | No |
| Toggler | U | toggler.exe | "Toggler allows you to gain control over your Caps Lock, Num Lock, and Insert keys. It prevents you from writing in ALL CAPS when your finger has slipped to accidentally hit the Caps Lock key" | No |
| Registration Service | X | toker.exe | Added by the SDBOT-BB WORM! | No |
| Tommorrow | ? | tomorrow.exe | ?? | No |
| TomTomHOME.exe | N | TomTomHOME.exe | TomTom HOME - free management program for your PC to look after their GPS navigation products | No |
| TomTomHOME.exe | N | TomTomHOMERunner.exe | TomTom HOME - free management program for your PC to look after their GPS navigation products | No |
| sibawerix | X | tomup.exe | Detected by Trend Micro as WORM_SDBOT.AVB and by Malwarebytes Anti-Malware as Backdoor.IRCBot | No |
| firefox | X | tonight.exe | Detected by McAfee as Generic BackDoor | No |
| msresearch | X | tool3.exe | Added by the SpySheriff rogue spyware remover - not recommended, removal instructions here | No |
| AVGTOOLBAR | X | toolbar.exe | Detected by McAfee as RDN/Autorun.worm.bbp!a and by Malwarebytes Anti-Malware as Backdoor.Agent. Note - this is not a valid entry for the AVG Toolbar | No |
| hsim | X | toolbar.exe | Unidentified malware | No |
| Policies | X | toolbar.exe | Detected by McAfee as RDN/Autorun.worm.bbp!a and by Malwarebytes Anti-Malware as Backdoor.Agent | No |
| ToolbarRestore | X | ToolbarRestore.exe | Detected by McAfee as Generic Downloader.x!gfk and by Malwarebytes Anti-Malware as Adware.K.ILike. The file is located in %ProgramFiles%\ILikeClick | No |
| CheckIt | U | ToolBox.exe | CheckIt Toolbox from WinCheckIt Diagnostic Software. Toolbox automatically backs up critical system files (such as .ini files and the Windows Registry), and performs a check on various system parameters at intervals you specify | No |
| PC Spy Keylogger | U | ToolKeylogger.exe | PCSpyKeyLogger keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| XP Advanced Keylogger | U | ToolKeylogger.exe | XP Advanced Keylogger surveillance software. Uninstall this software unless you put it there yourself | No |
| adobe_System_App | X | Toolkit.exe | Added by the FAKEAV-ELH TROJAN! | No |
| Perfect Memory Optimizer | U | ToolMemoryOptimizer.exe | Perfect Utilities Memory Optimizer (the same as WinUtilities Memory Optimizer) | No |
| WinUtilities Memory Optimizer | U | ToolMemoryOptimizer.exe | "WinUtilities Memory Optimizer optimizes the memory management of your system and boost-up its performance amazingly!" | No |
| ToolNotifier | X | ToolNotifier.exe | Added by the DWNLDR-IUD TROJAN! | No |
| \tools.exe | X | tools.exe | FastFind adware variant | No |
| Clik Status Monitor | N | toolsclickstat.exe | Part of Iomega Tools to let you know whether an Iomega PocketZip (nee Clik) removable drive cartridge is installed | No |
| Windows More Choice | X | TopContext.exe | ZQuest adware | No |
| TopDesk | U | TopDesk.exe | TopDesk windows management utility from Otaku Software Pty Ltd which allows you to quickly tile windows (all, application or visible) as well as hiding visible windows | Yes |
| topi | ? | topi.exe | Toshiba Online Product Information. What does it do and is it required? | No |
| TopmostClock | U | TopMostClock.exe | TopMost Clock - transparent analog clock which displays on top of your other windows | No |
| TopSearch | X | TopSearch.exe | TopSearch adware | No |
| topsearch.exe | X | topsearch.exe | Detected by Dr.Web as Trojan.DownLoad3.15877 and by Malwarebytes Anti-Malware as Adware.Korad | No |
| Tor | N | tor.exe | Tor anonymity package | No |
| tor anonymous proxy | X | tor32.exe | Added by the SDBOT-ADR WORM! | No |
| TorCP | N | torcp.exe | TorCP controller for the Tor anonymity package - which "runs in your system's notification area, giving you a way to check on the status of Tor without having to have the console window open all the time" | No |
| ad0cf09be9d9be35254a664a06d4d9b1 | X | torjan.exe | Detected by McAfee as Generic.dx and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| [various names] | X | TorontoMail.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| System Support | X | torrent.exe | Added by a variant of the RBOT WORM! | No |
| TOSCDSPD | N | toscdspd.exe | Related to Toshiba laptop CD/DVD drivers. This is a non-essential process. Disabling or enabling this is down to user preference | No |
| Toshiba TEMPO | N | Toshiba.Tempo.UI.TrayApplication.exe | TEMPO is a software service developed by Toshiba. It will advise you on how to fine-tune the performance of your notebook and keep you informed of the latest Toshiba software and driver updates as soon as they are released. It does this by delivering various types of alerts into a special TEMPO inbox area on your notebook PC | No |
| ToshibaAppPlace | U | ToshibaAppPlace.exe | Toshiba AppPlace - cloud based apps "specially designed to work for you and your Toshiba laptop" | No |
| Toshiba Registration | N | ToshibaRegistration.exe | Toshiba Registration - available via Start → Programs | No |
| ToshibaServiceStation | N | ToshibaServiceStation.exe | Toshiba Service Station "enables your computer to periodically search for Toshiba Software updates or alerts from Toshiba that are specific to your laptop" | No |
| TOSHIBSU | U | Toshibsu.exe | Reduces the power consumption when the laptop isn't being used to preserve battery power. Hibernate function doesn't work if this is disabled. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run off battery regularly | No |
| TosHKCW | U | TosHKCW.exe | Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed) | No |
| TosHKCW.exe | U | TosHKCW.exe | Toshiba Hot Key Change/Control Wireless. Permits you to use a hot key to activate/deactivate built-in 802.11b wireless transmission on a laptop (if installed) | No |
| gmail | X | toskngr.exe | Detected by Trend Micro as TROJ_VB.FPW | No |
| TosMem | Y | tosmem.exe | Toshiba laptop related. Win98/Me ACPI system can not hibernate or go on standby if all of the physical memory lower than 640KB is locked. This utility allocates and locks three pages on boot and then releases them on standby/hibernation for ACPI.SYS in order to solve the above problem | No |
| TosNC | U | TosNcCore.exe | Part of Toshiba's Bulletin Board - "a visual tool that uses the PC's touch screen to keep you organized with sticky notes, to-do lists and more". Available on some newer model laptops | No |
| TOSHIBA Picture Enhancement Utility | ? | TosPEHK.exe | The Toshiba Picture Enhancement Utility improves the image quality of functions such as watching a DVD movie, viewing information from a video camcorder or recorder, or receiving input from a console such as a PlayStation or X-Box on some laptop models | No |
| TosPEHK | ? | TosPEHK.exe | The Toshiba Picture Enhancement Utility improves the image quality of functions such as watching a DVD movie, viewing information from a video camcorder or recorder, or receiving input from a console such as a PlayStation or X-Box on some laptop models | No |
| TosReelTimeMonitor | U | TosReelTimeMonitor.exe | Toshiba's ReelTime software is a "free app shows you a visual timeline of your recently accessed files using graphic thumbnails like movie frames, so you can get to your files faster". Available on newer models | No |
| tostpop.exe | X | tostpop.exe | Detected by Malwarebytes Anti-Malware as Adware.K.TostPop. The file is located in %ProgramFiles%\tostpop | No |
| tostpop_.exe | X | tostpop_.exe | Detected by Malwarebytes Anti-Malware as Adware.K.TostPop. The file is located in %ProgramFiles%\tostpop | No |
| TosSENotify | U | TosWaitSrv.exe | Part of Toshiba's Hard Drive Impact Sensor - 'a complex system of hardware and software designed to detect sudden movements (as when your laptop starts to fall off the table) and "park" the heads of your hard drive before damage occurs'. Available on some models | No |
| TosWaitSrv | U | TosWaitSrv.exe | Part of Toshiba PC Health Monitor - which "takes protection to the next level by proactively checking your machine and alerting you to issues ahead of time" | No |
| totacon | X | totacon.exe | Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example | No |
| Total PC Defender 2010 | X | Total PC Defender 2010.exe | Total PC Defender rogue security software - not recommended, removal instructions here | No |
| Total PC Defender | X | Total PC Defender.exe | Total PC Defender rogue security software - not recommended, removal instructions here | No |
| [32 random numbers] | X | total.exe | Total Antivirus rogue security software - not recommended, removal instructions here | No |
| totalvaccine | X | totalvaccineu.exe | TotalVaccine rogue security software - not recommended | No |
| Total Virus Protection | X | TotalVirusProtection.exe | Total Virus Protection rogue security software - not recommended, removal instructions here | No |
| Total Recorder | U | TotRecSched.exe | Scheduler for Total Recorder from High Criteria Inc - which allows you to schedule playbacks or recordings using either the built-in scheduler or use command line options with an external scheduler, such as Microsoft Task Scheduler | Yes |
| TotalRecorderScheduler | U | TotRecSched.exe | Scheduler for Total Recorder from High Criteria Inc - which allows you to schedule playbacks or recordings using either the built-in scheduler or use command line options with an external scheduler, such as Microsoft Task Scheduler | Yes |
| TotRecSched | U | TotRecSched.exe | Scheduler for Total Recorder from High Criteria Inc - which allows you to schedule playbacks or recordings using either the built-in scheduler or use command line options with an external scheduler, such as Microsoft Task Scheduler | Yes |
| TouchED | U | TouchED.exe | TouchPad On/Off Utility on a Toshiba laptop | No |
| TouchFreeze | U | TouchFreeze.exe | TouchFreeze is simple utility for Windows that automatically disables the touchpad on notebooks while you are typing text - so that you can avoid accidentally changing the position of the cursor in your document or clicking on an option | No |
| Touch-It | U | TouchIt.exe | Touch-It virtual keyboard by Chessware - "is a powerful set of tools to build and use on screen keyboards. You can type right away using the preset templates or create your own from scratch using the Designer." Pro version | No |
| Touch-It | U | TouchItf.exe | Touch-It virtual keyboard by Chessware - "is a powerful set of tools to build and use on screen keyboards. You can type right away using the preset templates or create your own from scratch using the Designer." Free version | No |
| WinBackup | X | Tower_Defensev2.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. The file is located in %AppData% | No |
| Windows Repair | X | toxikx.exe | Added by the SDBOT-ADL WORM! | No |
| IBM TrackPoint Accessibility Features | U | tp4ex.exe | Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as "Click Sound", "Button Lock" and "Cross Hair cursor" are enabled this entry will run at startup. If none of the accessibility features are used it remains as a startup entry but doesn't run | Yes |
| TP4EX | U | tp4ex.exe | Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as "Click Sound", "Button Lock" and "Cross Hair cursor" are enabled this entry will run at startup. If none of the accessibility features are used it remains as a startup entry but doesn't run | Yes |
| TrackPoint Accessibility Features | U | tp4ex.exe | Supports accessibility features for the TrackPoint stick and associated buttons on IBM/Lenovo ThinkPad notebooks. If features such as "Click Sound", "Button Lock" and "Cross Hair cursor" are enabled this entry will run at startup. If none of the accessibility features are used it remains as a startup entry but doesn't run | Yes |
| tp4mon | U | tp4mon.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work | No |
| TrackPointSrv | U | tp4mon.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work | No |
| tp4serv | U | tp4serv.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work | No |
| TrackpointSrv | U | tp4serv.exe | Supports the "pointer stick" in lieu of a mouse on an IBM ThinkPad laptop. Necessary for the "scroll" button to work | No |
| TP98UTIL | N | TP98.EXE | IBM Thinkpad feature setup & configuration utility | No |
| IBM ThinkPad Tray Utility | N | TP98TRAY.EXE | System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. "The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility, you can setup or change your device configurations for ThinkPad hardware and options" | Yes |
| ThinkPad Configuration Utility | N | TP98TRAY.EXE | System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. "The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility, you can setup or change your device configurations for ThinkPad hardware and options" | Yes |
| TP98TRAY | N | TP98TRAY.EXE | System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. "The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility, you can setup or change your device configurations for ThinkPad hardware and options" | Yes |
| TPTRAY | N | TP98TRAY.EXE | System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. "The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility, you can setup or change your device configurations for ThinkPad hardware and options" | Yes |
| Tpam.exe | ? | tpam.exe | TP Attach Manager - part if IBM Personal Communications. What does it do and is it required? | No |
| Windows | X | tPDAZRDA.exe | Added by the VBKRYPT.HDQM TROJAN! | No |
| LENOVO.TPFNF6R | U | TPFNF6R.exe | Supports the Fn+F6 hotkey combination on IBM/Lenovo Thinkpad notebooks which mutes the microphone | No |
| TPFNF7 | U | TPFNF7SP.exe | Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options via the Fn+F7 key combination | No |
| TPFNF7SP | U | TPFNF7SP.exe | Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and multiple display options via the Fn+F7 key combination | No |
| TPHKMGR | U | TPHKMGR.exe | Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue "ThinkVantage" or "Access IBM" help key, Fn+Fx (where x is a number) key combinations (for access to features such as quickly locking the computer, wireless management, EasyEject and full-screen magnifier) and audio buttons (mute and volume up/down) | Yes |
| TPHKMGR.exe | U | TPHKMGR.exe | Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue "ThinkVantage" or "Access IBM" help key, Fn+Fx (where x is a number) key combinations (for access to features such as quickly locking the computer, wireless management, EasyEject and full-screen magnifier) and audio buttons (mute and volume up/down) | Yes |
| TPHOTKEY | U | TPHKMGR.exe | Hotkey manager for IBM/Lenovo Thinkpad notebooks. Supports the blue "ThinkVantage" or "Access IBM" help key, Fn+Fx (where x is a number) key combinations (for access to features such as quickly locking the computer, wireless management, EasyEject and full-screen magnifier) and audio buttons (mute and volume up/down) | Yes |
| Keyboard Customizer | N | TpKmapAp.exe | Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also, it doesn't appear to need to be running for custom key combinations to work (via TpKmapMn.exe) | Yes |
| TpKmapAp | N | TpKmapAp.exe | Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also, it doesn't appear to need to be running for custom key combinations to work (via TpKmapMn.exe) | Yes |
| TPKMAPHELPER | N | TpKmapAp.exe | Part of the Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This is the main user interface for the utility but it doesn't normally seem to be running if enabled at startup. Also, it doesn't appear to need to be running for custom key combinations to work (via TpKmapMn.exe) | Yes |
| TPKMAPMN | U | TpKmapMn.exe | Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This startup entry will be enabled if either the default or custom key combinations are selected for use with the built-in keyboard (such as AltGr for the Windows key) or an external keyboard (such as Right Ctrl + Up arrow for volume up) | Yes |
| TpKmapMn.exe | U | TpKmapMn.exe | Keyboard Customizer Utility for IBM/Lenovo Thinkpad notebooks. This startup entry will be enabled if either the default or custom key combinations are selected for use with the built-in keyboard (such as AltGr for the Windows key) or an external keyboard (such as Right Ctrl + Up arrow for volume up) | Yes |
| tpopservice | U | tpopservice.exe | DirecWay two-way satellite internet service enhanced POP proxy server for email | No |
| On screen display | U | TPOSDSVC.exe | Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example, whenever a user changes system speaker volume, this program displays a volume indicator on the desktop screen | Yes |
| ThinksPower | X | TPOSDSVC.exe | Detected by Dr.Web as Trojan.DownLoader6.64496 and by Malwarebytes Anti-Malware as Trojan.Agent.cn. Note - this is not the legitimate on-screen display for hotkeys on IBM/Lenovo ThinkPad notebooks that is normally found in %ProgramFiles%\Lenovo\HOTKEY. This one is located in %Windir% | No |
| TPHOTKEY | U | TPOSDSVC.exe | Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example, whenever a user changes system speaker volume, this program displays a volume indicator on the desktop screen | Yes |
| tposdsvc | X | tposdsvc.exe | Detected by Dr.Web as Trojan.DownLoader6.64496 and by Malwarebytes Anti-Malware as Trojan.Agent.cn. Note - this is not the legitimate on-screen display for hotkeys on IBM/Lenovo ThinkPad notebooks that is normally found in %ProgramFiles%\Lenovo\HOTKEY. This one is located in %UserStartup% and its presence there ensures it runs when Windows starts | No |
| TPOSDSVC | U | TPOSDSVC.exe | Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example, whenever a user changes system speaker volume, this program displays a volume indicator on the desktop screen | Yes |
| TPOSDSVC.exe | U | TPOSDSVC.exe | Supports the hotkeys on IBM/Lenovo ThinkPad notebooks - displays the result of the using of function keys on the desktop screen. For example, whenever a user changes system speaker volume, this program displays a volume indicator on the desktop screen | Yes |
| TPP Auto Loader | U | Tppaldr.exe | Installed with DataStor (and some other manufacturers) USB 2.0 based external DVD, CD-ROM and CD-RW drives. System tray icon allowing the user to disconnect the external drive without an error message being displayed | No |
| Tprtray | U | Tprtray.exe | Displays the Power icon in the System Tray on a Toshiba laptop | No |
| Tpscrex | U | Tpscrex.exe | Lenovo (IBM) ThinkPad hotkey related | No |
| TPKBDLED | U | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED | Yes |
| TpScrLk | U | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED | Yes |
| TpScrLk.exe | U | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED | Yes |
| n/a TpShocks | Y | TpShocks.exe | Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T, W, X and Z series. This provides airbag-like protection for your hard drive as the system has "an integrated motion sensor that continuously monitors the movement of the notebook, and, if a sudden change in motion is detected, it temporarily stops the hard drive to protect it from a potential crash". The user can also temporarily suspend APS via the Start Menu or (optional) System Tray icon and view the real-time status | Yes |
| ThinkVantage Active Protection System | Y | TpShocks.exe | Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T, W, X and Z series. This provides airbag-like protection for your hard drive as the system has "an integrated motion sensor that continuously monitors the movement of the notebook, and, if a sudden change in motion is detected, it temporarily stops the hard drive to protect it from a potential crash". The user can also temporarily suspend APS via the Start Menu or (optional) System Tray icon and view the real-time status | Yes |
| TpShocks | Y | TpShocks.exe | Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T, W, X and Z series. This provides airbag-like protection for your hard drive as the system has "an integrated motion sensor that continuously monitors the movement of the notebook, and, if a sudden change in motion is detected, it temporarily stops the hard drive to protect it from a potential crash". The user can also temporarily suspend APS via the Start Menu or (optional) System Tray icon and view the real-time status | Yes |
| TPSmain | U | TPSMain.exe | Toshiba Power Saver utility - which "manages the power consumption of various devices on Toshiba notebook computers. Its primary purpose is to extend the amount of time that your machine can run from its battery or batteries" | No |
| TPSODDCtl | Y | TPSODDCtl.exe | Power saving software on Toshiba laptops | No |
| TPNF | N | TPTray.exe | Touchpad configuration tray icon for Toshiba laptops. Available via Start → Settings → Control Panel | No |
| TPTray | N | TPTray.exe | Touchpad configuration tray icon for Toshiba laptops. Available via Start → Settings → Control Panel | No |
| TPWAUDAP | U | TpWAudAp.exe | Provides support for volume changes via hotkeys on IBM/Lenovo Thinkpad notebooks | No |
| TPwrMain | Y | TPwrMain.EXE | Power management software for Toshiba laptops | No |
| TPwrMgr | ? | TPwrMgr.exe | Found on a Toshiba laptop. Related to power management? | No |
| Tpwrtray | Y | TPWRTRAY.EXE | Toshiba laptop's own Advanced Power Management system which disables Windows APM (greyed-out in Control Panel). You can't choose which of the 2 systems to use | No |
| tqrecv | U | tqrecv.exe | Tellique satellite broadcast reception software | No |
| Keyboard Tracer | U | Tracer.exe | Keyboard Tracer by UpClock Software - "is an easy-to-use and practical tool for tracking all keypresses on your computer keyboard" | No |
| tracesweeper | X | tracesweeper.exe | Trace Sweeper rogue privacy tool - not recommended | No |
| Tracker | ? | Tracker.exe | Possibly associated with My Deluxe Invoices program | No |
| sys.exe | X | Trading file.exe | Detected by Malwarebytes Anti-Malware as Trojan.Injector.MSIL. The file is located in %AppData% | No |
| Windows Start Server 2000 | X | traficy.exe | Added by the RBOT-AHM WORM! | No |
| tranicon | U | tranicon.exe | Component from the Tweak-XP optimization utility for Windows XP from Totalidea Software. Makes Desktop icons transparent | No |
| TransparentIcons | U | tranicon.exe | Component from the Tweak-XP optimization utility for Windows XP from Totalidea Software. Makes Desktop icons transparent | No |
| Transcode360 | N | Transcode360Tray.exe | Designed for WinXP Media Center Edition 2005 and the Xbox 360, Transcode360 aims to broaden the support for a wide range of video media including DivX and XviD | No |
| DellTransferAgent | ? | TransferAgent.exe | Found on Dell computers. Possibly the Transfer MyPC utility (by Orlogix), which is optionally installed when a user configures a new system and is used to move all your files, applications and settings to the new PC? | No |
| translation3 | X | translation2.exe | Detected by Dr.Web as Trojan.MulDrop4.303 and by Malwarebytes Anti-Malware as Adware.KorAd | No |
| Transparent | U | TransparentB.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here | No |
| Transparent | U | TransparentD.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here | No |
| Transparent | U | TransparentW.exe | Utility to turn desktop icon text backgrounds transparent. The last letter defines the icon text color: D= as desktop, W=white, B=black. Available from here | No |
| TransTask | U | transtask.exe | Component from the Tweak-XP optimization utility for Windows XP from Totalidea Software. Makes Taskbar icons transparent | No |
| Trashgrd | U | TRASHGRD.EXE | Part of McAfee Nuts & Bolts. Protects all the files you delete, even files deleted in DOS or in 16-bit Windows applications, by sending them to the Recycle Bin | No |
| Microsoft Legacy Device | X | trass.exe | Added by the RBOT-AIX WORM! | No |
| Tray Date | N | Tray Date.exe | Tray Date by Titlebar Software - displays a simple icon in the System Tray (that can't be configured) which shows the current date. The originator's website is no longer available but you can still download it here. Whilst it only uses around 10MB of memory, you can run it via the Start menu - or you can simply move the cursor over the clock time on the System Tray to show the date | Yes |
| Tray Folder | U | Tray Folder.exe | Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here | Yes |
| TrayFolder | U | Tray Folder.exe | Tray Folder by Titlebar Software - creates a hidden folder that is only normally accessible by double-clicking on a System Tray icon that shows the current date. You can also hide files and other folders in that hidden folder. The originator's website is no longer available but you can still download it here | Yes |
| AdwareKiller_tray | X | tray.exe | EAdwareKiller rogue spyware remover - not recommended | No |
| Shell | X | Tray.exe | Homepage hijacker re-directing browsers to adult content websites | No |
| System Tray Monitor | X | tray.exe | Added by the RBOT.UXR WORM! | No |
| Vongo Tray | N | Tray.exe | System Tray access the now discontinued Vongo video-on-demand service | No |
| Traymin900 | U | Tray900.exe | Related to the Philips SPC webcam - System Tray manager for Personal 900 series camera | No |
| PCSuiteTrayApplication | N | TrayApplication.exe | System Tray access to Nokia PC Suite - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu | No |
| PCSuiteTrayApplication | N | TRAYAP~1.EXE | System Tray access to Nokia PC Suite - which "is a free PC software product that allows you to connect your Nokia device to a PC and access mobile content as if the device and the PC were one." This allows you (amongst other options) to backup your devices contents to your PC, use it to connect to the internet, transfer files and synchronize contacts, etc. Available from the start menu | No |
| Camera Assistant Software | U | traybar.exe | Camera Assistant Software utility for Toshiba laptops - allows you to take pictures with and control the integrated WebCam | No |
| MSN Internet Access | N | trayclnt.exe | Quick way to connect to MSN internet service - replaces "MSN Quick View" from V5.6 onwards | No |
| SarbyxTrayClock | U | trayclock.exe | Sarbyx TrayClock by Sarbyxlabs.com - "is the replacement for standard Windows clock, it builds itself right into the taskbar and doesn't eat any desktop space. It includes numerous useful features that extend standard Windows clock functionality" | No |
| NovaNet-WEB Tray Control | U | TrayControl.exe | System Tray access to Packard Bell EverSafe backup and restore software by NovaStor | No |
| Packard Bell EverSafe Tray Control | U | TrayControl.exe | System Tray access to Packard Bell EverSafe backup and restore software by NovaStor | No |
| Propel Accelerator | U | trayctl.exe | Propel Internet Accelerator | No |
| traydate.exe | U | TRAYDATE.EXE | TrayDate - displays the date as well as the time in the System Tray | No |
| AGEIA PhysX SysTray | N | TrayIcon.exe | System Tray access to display properties for AGEIA PhysX graphics cards. Unless you change your desktop resolution, etc, regularily use Control Panel → Display Properties or right-click on the desktop | No |
| AXIS Print System TrayIcon | U | TrayIcon.exe | System Tray access to AXIS Print System from AXIS Communications - "adds printer discovery, printer driver installation printing on Windows platforms. Printing is enabled by AXIS Print Monitor, which is one of the components. Another component in AXIS Print System is AXIS IP Installer." Now discontinued | No |
| CacheBoost | U | trayicon.exe | CacheBoost "optimizes the System Cache-Management of Windows XP/2000/NT and Windows .Net Servers, resulting in a performance boost" | No |
| DisplayTrayIcon | N | TrayIcon.exe | System Tray access to display properties for ABIT graphics cards. Unless you change your desktop resolution, etc regularily use Control Panel → Display | No |
| eScan Updater | U | Trayicos.exe | MicroWorld eScan antivirus updater - allows users to automatically download updates and set the auto time interval for downloads | No |
| TrayIt! | U | trayit!.exe | TrayIt! minimizes open windows to the System Tray as icons instead of the usual taskbar | No |
| TrayManager | U | Trayman.exe | TrayManager hides system tray icons (FreeCell won't work when TrayMan is loaded) | No |
| JavaTray | X | traymgr.exe | Added by a variant of the IRCBOT BACKDOOR! See here | No |
| MicrosoftCorp | X | traymgr.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| MicrosoftNAPC | X | traymgr.exe | Added by a variant of the IRCBOT BACKDOOR! | No |
| 0ATMGR | X | traymgr1.exe | Detected by McAfee as Downloader.a!dc3 and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Traymon | U | traymon.exe | Netropa Internet Receiver traymonitor. Will only launch the bar if you are connected to the internet and there's new news | No |
| 1A:MacVisionTrayMonitor | U | TrayMonitor.exe | Part of MacVision by Jeff Bargmann - an discontinued program that makes your PC's desktop look and feel incredibly like that of a Macintosh OS8 computer. Handler that puts the icons that are in your system tray into the MacVision taskbar, beside the clock | No |
| Tray Pilot Lite | U | TrayPlt.exe | Tray Pilot allows you to hide the System Tray window. No longer supported by the authors | No |
| AAATraySaver | N | TraySaver.exe | System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray | No |
| 1A:Stardock TrayMonitor | Y | TrayServer.exe | For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX | No |
| TrayServer | Y | TrayServer.exe | For monitoring tray icons - if disabled icons will not be displayed in ObjectBar or DesktopX | No |
| TrayServer | ? | TrayServer_en.exe | Related to MAGIX Movie Edit Pro MX video editing software | No |
| System Icon Tray | X | traysys.exe | Detected by Trend Micro as WORM_RBOT.GBI. The file is located in %System% | No |
| Tray manager system | X | traysys.exe | Added by a variant of Backdoor.Rizo.A. The file is located in %System%\Com | No |
| Taskschd | X | TRAYWND.EXE | Added by the LITMUS.002 BACKDOOR! | No |
| [various names] | X | Trayz.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| tray_helper | N | tray_helper.exe | Tray Helper is an Email checker with additional tools, including a popup window killer, pinger module to monitor hosts and an event reminder | No |
| Brct | X | trdb.exe | Detected by Kaspersky as the PURITYSCAN.Y TROJAN! | No |
| RunSearvices | X | tread.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! | No |
| TRE AntiVirus | X | treav.exe | TRE AntiVirus rogue security software - not recommended, removal instructions here | No |
| trend | X | trend.exe | Added by the BANCOS-AZ TROJAN! | No |
| Trend Micro AV | X | trendav.exe | Detected by Sophos as W32/Agobot-OH. Note - this is not a valid Trend Micro antivirus entry | No |
| OEM Tools 32 | X | tres32.exe | Detected by Trend Micro as WORM_RBOT.QB | No |
| Windows Update Service | X | trest.exe | Detected by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %Windir% | No |
| TridTray | ? | TridTray.exe | System Tray access to Trident 4DWave soundcards? | No |
| ComponentTRIEDIT | X | triedittriedit.exe | Added by the TRITE-A WORM! | No |
| SDJobCheck | ? | triggusr.exe | Part of CA Unicenter Software Delivery - manage software across various systems, from desktops and servers to PDAs and mobile phones, in a controlled and standardized way - is it required at startup? | No |
| Messanger | X | trillian.exe | Added by the RBOT.CKI WORM! | No |
| Trillian | U | trillian.exe | Part of Trillian IRC client | No |
| trimbuffer11_3 | X | trimbuffer11_3.exe | Detected by McAfee as Downloader.a!c2a and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| trirot | Y | trirot.exe | Trident Microsystems 3D video driver | No |
| TRIXX | U | TRIXX.exe | Sapphire TRIXX overclocking tool for the X800 GTO graphics card (and possiby others) - "push default clock speeds to 560MHz or better" | No |
| mmnext06 | X | trjdwnl.dll | Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series | No |
| TrojanScanner | U | Trjscan.exe | Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed | No |
| Trkwks | X | trkwksvc.exe | Detected by Trend Micro as WORM_IRCBOT.AW | No |
| MS Unix Binary | X | trmupdate.exe | Added by the RBOT-ACC WORM! | No |
| ComStart | X | Trojan Guarder.exe | TrojanGuarder rogue security software - not recommended | No |
| Trojan Guarder Gold Version | X | Trojan Guarder.exe | TrojanGuarder rogue security software - not recommended | No |
| 46d93431630fc8e404fed7204e708738 | X | trojan.exe | Detected by Dr.Web as Trojan.DownLoader7.12801 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 51ad2a8a7f579910bc41f6de9e2a3fcf | X | Trojan.exe | Detected by Dr.Web as Trojan.DownLoader6.28912 and by Malwarebytes Anti-Malware as Trojan.Agent.WSG | No |
| 5cd8f17f4086744065eb0992a09e05a2 | X | Trojan.exe | Detected by Dr.Web as Trojan.DownLoader6.34043 and by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %Temp% | No |
| 81ed0e74a40ed4fe8a36a7b819c4279f | X | Trojan.exe | Detected by Dr.Web as Trojan.Siggen4.11140 and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| 8515eb34d8f9de5af815466e9715b3e5 | X | Trojan.exe | Detected by Dr.Web as Trojan.DownLoader7.28225 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| c7192e982641757f14f66356bb4cf303 | X | Trojan.exe | Detected by McAfee as RDN/Generic Dropper!h and by Malwarebytes Anti-Malware as Trojan.MSIL | No |
| Tro3 | X | Trojan3.exe | Detected by Malwarebytes Anti-Malware as Trojan.AVDis. The file is located in %System% | No |
| Loaris Trojan Remover | U | TrojanRemover.exe | Loaris Trojan Remover - "aids in the removal of Malware - Trojan Horses, Worms, Adware, Spyware - when standard anti-virus software either fails to detect them or fails to effectively eliminate them" | No |
| Trojan | X | TrojanS_P.exe | Added by the AGENT-CQ TROJAN! | No |
| 5e98a48b3c3d4c2eebca8c9cdf08880b | X | trojen.exe | Detected by McAfee as RDN/Generic PWS.y and by Malwarebytes Anti-Malware as Trojan.Agent.Ezrz | No |
| (Default) | X | troll.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent. Note - this malware actually changes the value data of the "(Default)" key in HKCU\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank and the file is located in %Temp% | No |
| TosRotation | U | TRot.exe | TOSHIBA Rotation Utility - allows users to rotate a notebook's screen image 180 degrees in order to share information on the screen with others seated across a table or desk | No |
| avast | X | troyan.exe | Detected by Kaspersky as Backdoor.Win32.Small.cz | No |
| [various names] | X | TRPT.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| trrpug | X | trrpug.exe | Added by the MDROP-DLW TROJAN! | No |
| 7345073328183258bd730bbcb1a66582 | X | trt22.exe | Detected by Malwarebytes Anti-Malware as Trojan.MSIL. The file is located in %UserTemp% | No |
| TrueAssistant | N | TrueAssistant.exe | Browser toolbar - part of TrueSuite by Esaya, Inc - "a solution that allows users to use the existing tools that came with their PCs and provides new tools to help them take true control of their Internet experience" | No |
| TrueCrypt | U | TrueCrypt.exe | TrueCrypt - is "Free open-source disk encryption software for Windows 7/Vista/XP, Mac OS X, and Linux". This entry will run TrueCrypt when Windows starts, prompt for passwords, automount selected volumes and runs the main background task that supports functions such as hot-keys, autodismount, notifications and the System Tray icon | Yes |
| Acronis True Image | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| Acronis True Image Monitor | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
| Acronis*True*Image Monitor | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
| AcronisTrueImage Monitor | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
| SAOB Monitor | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks for the Online Backup feature. When disabled it appears to have no impact with interactive and scheduled backups | No |
| TrueImageMonitor | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting. Also included in Seagate's DiscWizard and BlackArmor Backup implementations of True Image | No |
| TrueImageMonitor.exe | N | TrueImageMonitor.exe | Part of Acronis True Image backup software. Provides the interface between the various tasks. When disabled it appears to have no impact with interactive and scheduled backups and image mounting | No |
| truetype | X | truetype.exe | Added by the COSIAM-I TROJAN! | No |
| TrueAssistant | U | TrueWizard.exe | "TrueSwitch makes changing your Internet Service Provider easy. We copy all your personal data to the new account, notify everyone with the new email address, forward emails sent to your old email address and help you cancel the old account" | No |
| SystemSettingf | X | TRUG.vbs | Added by the TRUG.B MACRO! | No |
| TimeService | X | trun.exe | TlfLic-A premium rate adult content dialler | No |
| ntdll.dll | X | TrustCleaner.exe | Trust Cleaner rogue security software - not recommended | No |
| Trust Cleaner | X | TrustCleaner.exe | Trust Cleaner rogue security software - not recommended | No |
| TrustCop | X | TrustCop.exe | TrustCop rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| TrustDoctor | X | TrustDoctor.exe | TrustDoctor rogue security software - not recommended, removal instructions here | No |
| TrustFighter | X | TrustFighter.exe | TrustFighter rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| TrustIn Popups | X | TrustInPopups.exe | TrustInPopups adware | No |
| JavaSoft | X | trustlib.exe | Detected by Dr.Web as Trojan.Inject.46880 | No |
| TrustNinja | X | TrustNinja.exe | TrustNinja rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| trustras.exe | ? | trustras.exe | Trust ADSL modem related. Is it required? | No |
| TrustSoldier | X | TrustSoldier.exe | TrustSoldier rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| TrustWarrior | X | TrustWarrior.exe | TrustWarrior rogue security software - not recommended, removal instructions here. A member of the WiniGuard family | No |
| TrustyHound-TS | X | TrustyHound-TS.exe | TrustyHound spyware | No |
| [various names] | X | trycrt.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| T-Com WLAN Manager | U | TS154USB.exe | Wireless management utility for the T-Com Sinus 154 Data II WLAN adapter | No |
| Tsa.exe | Y | Tsa.exe | TELUS security advisor tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled | No |
| TimeSink Add Client | X | TSADBOT.EXE | Advertising spyware | No |
| TsAdbot | X | TSADBOT.EXE | TimeSink Add Client - advertising spyware | No |
| recbwuih | X | tsamcpcx.exe | Detected by Malwarebytes Anti-Malware as Trojan.Downloader.FW. The file is located in %LocalAppData% | No |
| Video Card Driver (do not remove) | X | tsasi.exe | Added by the SPYBOT-EF WORM! | No |
| [32 random hex numbers] | X | tsc.exe | Total Security rogue security software - not recommended, removal instructions here | No |
| CS | X | tsc.exe | Cyber Security rogue security software - not recommended, removal instructions here | No |
| TS | X | tsc.exe | Total Security rogue security software - not recommended, removal instructions here | No |
| TSClientMSIUninstaller | U | tscuinst.vbs | Related to Terminal Services Client Remote Desktop Connection Software from Microsoft | No |
| tserv | X | tserv.exe | Added by the STRATION.AD WORM! | No |
| runner1 | X | tsitra.exe | Added by the AGENT.ABFQ TROJAN! | No |
| RVC6Player | X | tskdbg.exe | Added by the ZAPCHAS-M TROJAN! | No |
| Task Debugger | X | tskdbg.exe | Added by the AGOBOT-KK WORM! | No |
| tskdbg | X | tskdbg.exe | Added by the FLOOD.E TROJAN! | No |
| WinXPService | X | Tskdbg.exe | Added by the MDROP-BPQ TROJAN! | No |
| MNMMSN.EXE | X | tskhot.exe | Detected by McAfee as RDN/Generic Downloader.x!bv and by Malwarebytes Anti-Malware as Trojan.Banker | No |
| Tsklist | X | tsklist32.exe | Detected by Kaspersky as the BANCOS.SP TROJAN! | No |
| sysPersonalFirewall | X | tskm0nitor.exe | Added by the SDBOT.APC WORM! | No |
| DRam Monitor 23 | X | tskman3.exe | Added by a variant of the RBOT WORM! | No |
| #ozkan# | X | tskmanager.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here | No |
| tskmanager.exe | X | tskmanager.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here | No |
| winsockdriver | X | tskmg.exe | Added by the WARPIGS.C WORM! | No |
| Microsoft Updaters | X | tskmgr.exe | Added by a variant of the RBOT WORM! | No |
| Ms task manager | X | tskmgr.exe | Added by the SDBOT.CCD WORM! | No |
| MS taskmanager | X | tskmgr.exe | Added by the RBOT-AKA WORM! | No |
| Taskmgr | X | tskmgr32.exe | Homepage hi-jacker | No |
| Task Manager | X | tskmngr.exe | Added by the RBOT-GOU WORM! | No |
| win32 security updates downloader | X | tskmngr.exe | Added by a variant of the SDBOT BACKDOOR! See here | No |
| Windows Taskmanager | X | tskmngr.exe | Added by the IRCBOT.DHR BACKDOOR! | No |
| Windows Update | X | tskmngr.exe | Detected by Kaspersky as Backdoor.Win32.Agent.aly and by Malwarebytes Anti-Malware as Backdoor.IRCBot. The file is located in %CommonFiles%\System | No |
| TaskManager Load Module | X | TSKMNGR32.EXE | Added by the SPYBOT.I WORM! | No |
| Microsoft Video Controls | X | tskmsgr.exe | Added by a variant of the SPYBOT WORM! | No |
| TSkrMain | U | TSkrMain.exe | TOSHIBA Accelerometer Utilities - hardware utilities that work with the motion sensors built into their Tablet PCs. Detect the way you are holding it at any given moment, you can set the machine to perform a specific function when the unit is quickly tilted to the left or right, or to the front or back and you can also take control of the cursor in some applications and make it move by leaning the PC in a certain direction | No |
| Tsl | X | tsl.exe | Uploader-R adware | No |
| Tsl2 | X | tsl2.exe | TargetSaver adware | No |
| TSleepSrv | U | TSleepSrv.exe | Related to the USB Sleep-and-Charge feature included on some Toshiba laptops which allows users to charge a USB device whilst the laptop is a sleep mode | No |
| tsa | X | tsm.exe | TargetSaver adware | No |
| Tsa2 | X | tsm2.exe | TargetSaver adware | No |
| TSMAgent | ? | TSMAgent.exe | Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required? | No |
| TSMsger | N | TSMsger.exe | Epson scannner software - required for "one-touch" operation. Can be launched manually | No |
| LOCKDOWN | X | tsnj5jdt5Lj.exe | Detected by McAfee as W32/Valla.a. Note - the filename can be random | No |
| tsnp2std | N | tsnp2std.exe | Digital camera related | No |
| tsnpstd3 | Y | tsnpstd3.exe | Related to Sonix Inc. Camera Monitor MFC Application | No |
| TSNxG4Tray | N | TSNxGTray.exe | Part of the Data Safe feature (also known as TopSecret) included with the NotebookSecurity security product from G Data Software AG - which "is designed for protecting sensitive data and uses powerful encryption algorithms to do so". On the tested version (2012) the file doesn't exist so the exact purpose is therefore unknown and the recommendation is to disable it | Yes |
| Internet Firewall Layer | X | tsqla.exe | Added by a variant of the SPYBOT WORM! | No |
| tsrv | X | tsrv.exe | Added by the WAREZOV.W WORM! | No |
| Tapisys | X | tss.exe | Added by the SMALL TROJAN! | No |
| ToshibaServiceStation | N | TSS.exe | Toshiba Service Station "enables your computer to periodically search for Toshiba Software updates or alerts from Toshiba that are specific to your laptop" | No |
| TrojanSimulator | X | TSServ.exe | Trojan Simulator security risk which simulates a trojan infection and may be used to verify whether a virus scanner can properly detect the file | No |
| TrueSync Launcher | N | tstool.exe | Starfish TrueSync - for synchronization between Windows platforms and popular devices, applications and services. Stafish became Intellisync which was acquired by Nokia and is now no longer supported | No |
| Text Tray Service | X | tstray.exe | Added by the SILLYFDC.BCC WORM! | No |
| tsyssmon | ? | tsyssmon.exe | Found in a Toshiba\sysstability directory | No |
| RealJukeboxSystray | N | tsystray.exe | System Tray icon for RealJukebox | No |
| ttasq | ? | ttasq.exe | ?? | No |
| tTEvbsKqrbOXLI.exe | X | tTEvbsKqrbOXLI.exe | Detected by Malwarebytes Anti-Malware as Trojan.Foury. The file is located in %CommonAppData% | No |
| Nasiso | X | ttgcfdj.exe | Detected by Dr.Web as Trojan.DownLoader6.57525 and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Ttt | X | Ttt.exe | Added by the VB.AMX TROJAN! | No |
| WinService | X | Ttt.exe | Added by the MSNVB-D WORM! | No |
| TerraTec Remote Control | U | TTTVRC.exe | Remote Control software for TerraTec Home Cinema | No |
| Aida | X | ttuh.exe | PurityScan adware | No |
| ttupt | X | ttupt.exe | eZula adware | No |
| Aica | X | tuaa.exe | PurityScan adware | No |
| ISBvmWqfQjOgdtXNXzSrrHHcWk | X | TUHDl_WpenzfbO.exe | Detected by Malwarebytes Anti-Malware as Trojan.Banker. The file is located in %System% | No |
| Banyak_Kerjaan | X | Tukang.exe | Added by the SILLYFDC.BDM WORM! | No |
| Tukati | ? | TukatiRedistributor.exe | Tukati Digital Content Distribution. Is it required? | No |
| tunebite | N | tunebite.exe | "Tunebite lets you make unprotected copies of copy-protected music files by recording them while they are being played". Can be launched from it's Start Menu shortcut | No |
| WinSistem | X | Tunggul.vbs | Added by the VBS.STEMCLOVER WORM! | No |
| Turbine Download Manager Tray Icon | N | TurbineDownloadManagerIcon.exe | Turbine Download Manager (TDM) - download manager associated with the game "The Lord of the Rings Online". No longer available | No |
| detect | ? | turbodetect.exe | ?? | No |
| TurboHddUsb | U | TurboHddUsb.exe | LaCie USB Boost or PQI TurboHDD advanced driver for their range of USB hard disks which increases USB performance by up to 53%. Not required unless you use a supported external drive frequently | No |
| UsbBoost | U | TurboHddUsb.exe | LaCie USB Boost advanced driver for their range of USB hard disks which increases USB performance by up to 33%. Not required unless you use a supported external drive frequently | No |
| Turbo Key | U | TurboKey.exe | Supports the "Turbo Key" on some ASUS motherboards which turns the power button into a physical overclocking button | No |
| TurboMemoryCharger | U | TurboMemoryCharger.exe | Turbo Memory Charger - memory optimizer. No longer supported or available from the author | No |
| TurboTop | U | TurboTop.exe | TurboTop - make any window "Always on top" | No |
| turgidkubytw | X | turgidkubytw.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| ASDPLUGIN | X | turkey.exe | AsdPlug premium rate adult content dialer | No |
| tutcdchk2 | X | tutcdchk2.exe | Added by unidentified malware. The file is located in %System% | No |
| Tuto4pc | X | tuto4pc.exe | Detected by McAfee as Adware-Tuto4PC and by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| Tutorials | X | tuto4pc.exe | Detected by McAfee as Adware-Tuto4PC and by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| LingvoTraining | U | Tutor.exe | ABBYY Lingvo Electronic Dictionaries | No |
| Tuto4pc | X | tutorials.exe | Detected by McAfee as Adware-Tuto4PC and by Malwarebytes Anti-Malware as Adware.EoRezo | No |
| TVAgent | ? | TVAgent.exe | Found on the HP Touchsmart range of desktops and notebooks. What does it do and is it required? | No |
| tvctray | X | tvctray.exe | Added by the VB.QJ TROJAN! | No |
| CyberLink TV Enhance | N | TVEService.exe | Preloads TV related parts of CyberLink's PowerCinema digital home entertainment software to speed up the launch of that feature. Only required on slower/older systems | Yes |
| TVEService | N | TVEService.exe | Preloads TV related parts of CyberLink's PowerCinema digital home entertainment software to speed up the launch of that feature. Only required on slower/older systems and included with versions of PowerCinema bundled (and re-branded) with systems from Acer, Dell, ASUS and others | Yes |
| TridentTVIcon | Y | tvicon.exe | Trident Microsystems, Inc Display driver | No |
| TV Media | X | Tvm.exe | TVMedia adware | No |
| TVMD | X | TVMD.EXE | T.V. Media - adware installed with Memory Meter or Speed Blaster from Total Velocity | No |
| BJPD HID Control | U | TVMon.exe | Related to Canon Photo viewer | No |
| TV Now | U | TvNow.exe | Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) | No |
| TvNow | U | TvNow.exe | Application supplied with HP notebooks. It activates the S-Video port and is said to improve the quality of the output signal (resolution/timeouts) | No |
| tvncontrol | U | tvnserver.exe | Part of TightVNC - "a free remote control software package. With TightVNC, you can see the desktop of a remote machine and control it with your local mouse and keyboard, just like you would do it sitting in the front of that computer" | No |
| Remote Controller | N | TVRMVCR.EXE | ProLink PlayTVpro TV tuner software | No |
| TV Scheduler | U | TVSCHL.EXE | ProLink PlayTVpro TV tuner software scheduler | No |
| Tvs | N | TvsTray.exe | Toshiba Virtual Sound on a notebook. Allows you to change sound settings on the fly - default setting is "build-in speaker". You can also select external speaker, open type headphone, or closed type headphone. Each setting has presets for Bass, Stereo, and Clarity - which can also be changed by user if desired. Can also be launched from Start → Programs → Toshiba → Utilities | No |
| tvs_b | X | tvs_b.exe | Detected by Symantec as Adware.Broadcastpc | No |
| tvs_b | X | tvs_ln.exe | Added by a variant of Adware.Broadcastpc | No |
| tvs_re | X | tvs_re_inst.exe | Detected by Symantec as Adware.Broadcastpc | No |
| TVTunerLib | U | TVTLInstTool.exe | Related to Sony installer tool for Sony TV tuner library | No |
| TVTMD | X | TVTMD.EXE | T.V. Media - adware installed with Memory Meter or Speed Blaster from Total Velocity | No |
| TVWakeup | N | tvwakeup.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it | No |
| Tvwatch | ? | tvwatch.exe | Associated with the TV-oOut option on Asus AGP or Intel graphics cards. Is it required? | No |
| Common Files | X | twain.exe | Added by the AGENT.BEA TROJAN! | No |
| ComPlus Applications | X | twain.exe | Added by the AGENT.AQO TROJAN! | No |
| Internet Explorer | X | twain.exe | Added by the AGENT.BEA TROJAN! | No |
| microsoft frontpage | X | twain.exe | Added by the AGENT.AQO TROJAN! | No |
| MSN Gaming Zone | X | Twain.exe | Added by the AGENT.BEA TROJAN! | No |
| Online Services | X | twain.exe | Added by the AGENT.BEA TROJAN! | No |
| Twain | X | Twain.exe | Added by the STIRAUT WORM! The file is located in %Windir% | No |
| Twain | X | Twain.exe | Added by the AGENT.QKA TROJAN! The file is located in %ProgramFiles%\Twain | No |
| Windows NT | X | twain.exe | Added by the AGENT.BEA TROJAN! | No |
| WindowsUpdate | X | twain.exe | Added by the AGENT.BEA TROJAN! | No |
| xerox | X | Twain.exe | Added by the AGENT.CBLX TROJAN! | No |
| twain_32 | X | twain_32.exe | Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" | No |
| TWarnMsg | U | twarnmsg.exe | Toshiba System Warning Function for Windows 98, Me, 2000 - provides notification dialog when the cooling fan stops | No |
| TWBrowse | ? | TWBrowse.drv | Found on a Toshiba laptop. Possibly related to TWAIN drivers (ie, scanners, etc) - see this? | No |
| TabletWorks | Y | TWCP.exe | Tabletworks driver for digitizers from GTCO CalComp | No |
| TP-LINK Wireless Configuration Utility | U | TWCU.exe | TP-LINK Wireless configuration utility | No |
| TP-LINK Wireless Utility | U | TWCU.exe | TP-LINK Wireless configuration utility | No |
| TWCU | U | TWCU.exe | TP-LINK Wireless configuration utility | No |
| Tweak-7 | U | Tweak-7.exe | Tweak-7 optimization utility for Windows 7 from Totalidea Software | No |
| Tweak-Me | U | TWEAK-ME.exe | 3rd party version of Miscrosoft'sTweak UI "powertoy" with many more options and controls (plus full support), designed specifically to take advantage of features in WinMe/2K and above, available from here | No |
| Tweak-xp | U | Tweak-xp.exe | Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| Tweak-XP Pro | U | Tweak-xp.exe | Tweak-XP optimization utility for Windows XP from Totalidea Software | No |
| TweakDUN | U | tweakdun.exe | Utility to optimize your Internet Browser Software. TweakDUN promotes faster Internet data transfer rates and faster downloads by eliminating fragmentation of data packets | No |
| tweakico | ? | tweakico.exe | May be a HP program to control their icons? | No |
| TweakVI | U | tweakvi.exe | TweakVI from Totalidea Software - "Tweak hundreds of hidden features of Windows Vista, optimize your machine and customize it to your needs" | No |
| TweakYC | ? | TweakYC.exe | VideoMate TV tuner and capture card related - what does it do and is it required? | No |
| TWebCamera | U | TWebCamera.exe | Toshiba webcam support | No |
| ControlPanel | X | twink64.exe internat.dll,LoadKeyboardProfile | Detected by Sophos as Troj/Dloader-BW. Note - the "twink64.exe" file is found in %System% | No |
| twister | U | twister.exe | Twister "AntiTrojanVirus" | No |
| TwitterSubmitter | N | TwitAheadForPC.exe | TwitAhead scheduler for the Twitter micro-blogging service | No |
| Twitter.exe Espanha | X | Twitter.exe | Added by the BANKER.BBAT TROJAN! | No |
| systwtray | X | twitty**.exe [** = random digits] | Added by the KOOBFACE.C WORM! | No |
| king_tw | X | twking.exe | Added by the AUTORUN.BQUQ WORM! | No |
| Tweaki4PU | U | twksup.exe | "Tweaki puts several Windows utilities into one easy to use program while adding hundreds of additional tweaks not found in other system tweakers" | No |
| TwonkyMedia Manager | N | TwonkyMediaManager.exe | Media manager for Twonky from PacketVideo Corporation - which "links mobile devices and popular home entertainment devices, so users can enjoy your services wherever they are" | No |
| Twonky Tray Control | N | twonkymediaserverconfig.exe | System Tray access to configure Twonky from PacketVideo Corporation - which "links mobile devices and popular home entertainment devices, so users can enjoy your services wherever they are" | No |
| TwonkyMedia Tray Control | N | twonkymediaserverconfig.exe | System Tray access to configure Twonky from PacketVideo Corporation - which "links mobile devices and popular home entertainment devices, so users can enjoy your services wherever they are" | No |
| twunk | X | twunk.exe | Added by the SCAR.O TROJAN! | No |
| twunk service | X | twunk16.exe | Detected by Trend Micro as WORM_RBOT.BAT | No |
| MS Windows State Monitor | X | twunk_16.exe | Added by the AGENT.KEH TROJAN! | No |
| (Default) | X | twunk_32.exe | Added by the BLACKMAL.C WORM! Note - this malware actually changes the value data of the "(Default)" key in HKLM\Run in order to force Windows to launch it at boot. The name field in MSConfig may be blank | No |
| Twunk_32exp.exe | X | Twunk_32exp.exe | Added by the FAKEAV-BDZ TROJAN! | No |
| Twunk_64 | X | twunk_64.exe | System1060 homepage hi-jacker. Note - this is not a Windows file and is found in a WindowsSystem1060 directory | No |
| WINDOWS SYSTEM | X | twunk_65.exe | Added by the MYTOB-EG WORM! | No |
| QQ[Chinese characters] | X | TXOCInstallUserConfigOE.exe | Detected by Dr.Web as Trojan.Click2.53612 | No |
| Explorer | X | TXP1atform.exe | Added by the FUJACKS.CA VIRUS! | No |
| userinit | X | txvopvl.exe | Detected by McAfee as Generic Malware.dm!ats and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| Microsoft Driver Setup | X | txyrm.exe | Added by the VB-FDW TROJAN! | No |
| tyack drive | X | tyack.pif | Added by the RBOT-AMT WORM! | No |
| MSN Messenger 6.2 | X | tyd.exe | Added by a variant of the RBOT WORM! | No |
| Plug Function Visual Hardware Autoconnect | X | tyfddtidiex.exe | Detected by McAfee as RDN/Generic Downloader.x and by Malwarebytes Anti-Malware as Trojan.Agent | No |
| tynixkornaqp | X | tynixkornaqp.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% - see here | No |
| Intellitype | U | type32.exe | Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled | No |
| Microsoft IntelliType Pro | U | type32.exe | Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled | Yes |
| type32 | U | type32.exe | Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled | Yes |
| [various names] | X | typeconf.exe | Fake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here. Archived version of Andrew Clover's original page | No |
| Type Pilot | U | TypePlt.exe | Type Pilot by Two Pilots - "technical support software that types common text for you. Writing business or managing technical support letters may require that you type standard answers over and over again" | No |
| TypeRecorderL | U | TypeRec.exe | TypeRecorder keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| TypeRegChecker | ? | TypeRegChecker.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required? | No |
| typeteller | U | typeteller.exe | TypeTeller keystroke logger/monitoring program - remove unless you installed it yourself! | No |
| tyweacumvyqj | X | tyweacumvyqj.exe | Detected by Malwarebytes Anti-Malware as Trojan.Agent.US. The file is located in %UserProfile% | No |
If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us (startups_at_pacs-portal_dot_co_dot_uk).
"Status" key:
Variables:
DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. We will not be held responsible if changes you make cause a system failure.
WARNING: This is NOT a database of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a database of start-up applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at start-up. For a list of tasks/processes you should try the Process Library from Uniblue, the list at PC Pitstop or one of the many others now available. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSConfig or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.
To avoid the database becoming too large, all malware entries are only shown using the registry version which is common to all Windows versions. Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.
As more than 15K entries in this database related to malware you should use a quality internet security package. Which ever you choose, keep it updated and get the latest version at least every two years.
There are a number of virus and malware entried listed in this database where specific removal instructions haven't been given. If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. See here for a tutorial on how to use the program
NOTE: A number of entries are repeated due to the way that different operating systems display startup items. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Norton eMail Protect" in the registry.
SERVICES: "Services" from the NT/2K/XP/Vista/7 operating systems are not included. We fully understand that some programs with these OS's use "Services" as an alternative to load their component parts at startup but these are handled in a different way. We recommend you try BlackViper for information on services for the relevant operating systems.
Presentation, format & comments Copyright © 2001 - 2012 Pacman's Portal
Portions Copyright © Peter Forrest, Denny Denham, Sylvain Prevost, Tony Klein, CastleCops & Bleeping Computer
Powered by Malwarebytes
All rights reserved
| Privacy Policy | Site Map | Home |