 |
IEXPLORE.EXE |
$WindowsRegKey%update
Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
ISASS.exe |
-=+(L4r1$$4)+=-(4nt1)-=+(V1ru$)=-+
Added by the ASSIRAL.B WORM! |
 |
iexpl0res.exe |
@
Added by the RBOT.AEX WORM! |
 |
iebs.exe |
Ahst
PurityScan/Clickspring adware |
 |
iexplorer .exe |
ALG.EXE
Added by the DEMOTRY-B WORM! |
 |
Isass.exe |
Anti
Added by the BROPIA.K WORM! |
 |
ieav.exe |
antispy
IE AntiVirus rogue security software - not recommended, see here |
 |
iexpl0res.exe |
Antivirus
Added by an unidentified WORM or TROJAN! |
 |
INITIATE.EXE |
AppletINIT
Added by the AGOBOT.XV TROJAN! |
 |
icfca.exe |
Asicfc
Added by the AGENT.AAJE WORM! |
 |
Iexplor.exe |
AtxBrw
"Pop Marketing" adware |
 |
icpldrvx.exe |
Avg Antivirus
Added by the BANKER.BYU TROJAN! |
 |
IEHost.EXE |
Bakra
Added by the MULTIDR-AH TROJAN! |
 |
ie_ban.exe |
bantool
Detected as the VB.PO TROJAN! |
 |
IEShow.exe |
BitDefender Antiphishing Helper
Antiphishing component of BitDefender 2008 products |
 |
internet.exe |
blah service
Added by a variant of the RBOT WORM! |
 |
iczw.exe |
blah services
Added by the RBOT-GMP WORM! |
 |
Icon###XXX#X#.exe |
Boingo Wireless Utility
Starts the Boingo Wireless utility, used to detect and login into Boingo wireless hotspots. The filename may be autogenerated when installing, two different variations along the lines listed here, where # is a number and X is a letter. Shortcut available via Start -> Programs |
 |
Install.log.vbs |
BootCfg
Added by the YPSAN.D WORM! |
 |
ilikeboys.exe |
boy lovers of bsd
Added by the MYTOB.LY WORM! |
 |
IEXPLOR.EXE |
C:WINDOWSIEXPLOR.EXE
"Pop Marketing" adware |
 |
isafe.exe |
CAISafe
Part of Computer Associates eTrust EZ Antivirus |
 |
IXApplet.exe |
Camio Viewer x
Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version |
 |
idxl.exe |
CCWC7I
Moleculesoft Cache, Cookie & Windows Cleaner. No longer supported but available for free |
 |
IOMagic.exe |
CheckVCR
Driver for the I/OMagic Personal Video Recorder (DR-PCTV100) |
 |
iemon.exe |
chkdrv
Detected by Symantec as the ADCLICKER TROJAN! |
 |
ipsecdialer.exe |
Cisco Systems VPN Client
Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
 |
int1.exe |
Classes
"Switch" premium rate adult content dialler variant |
 |
intl.exe |
Classes
"Switch" premium rate adult content dialler variant |
 |
ipxwping.exe |
Client Agent
Added by the PPDOOR-N TROJAN! |
 |
iserver.exe |
cms
Added by the DLOADER-WK TROJAN! |
 |
iexplore_.exe |
cmssapp
Added by the BANCBAN-CQ TROJAN! |
 |
iexplore.exe |
cmssapp
Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
Internat.exe |
CnsMax
Added by the POINTEX TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir% |
 |
inetwizard.exe |
Compaq Internet Setup
For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list |
 |
iEEexplore.exe |
Config Loadation
Added by the SDBOT.H TROJAN! |
 |
I3Explorer.exe |
Config Loadatiorin
Added by the SDBOT.H TROJAN! |
 |
IEXPL0RE.EXE |
Configuration Loader
Added by the LOADCFG or SDBOT TROJANS! |
 |
IEXPLORE.EXE |
Configuration Loader
Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
ip7.exe |
Configuration Loader10
Added by the AGOBOT-ANZ WORM! |
 |
iexplore.exee |
Configuration Loadr
Added by an unidentified WORM or TROJAN! |
 |
internat.dll, LoadKeyboardProfile |
ControlPanel
Added by the BIZVES-A TROJAN! |
 |
I_26dadCC.exe |
CorelCENTRAL 10
CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs |
 |
isass.exe |
CSNetManagerXp
Added by the HIDER-O TROJAN! |
 |
imgst.scr |
dark
Added by the BANCOS.U TROJAN! |
 |
imgrt.scr |
dark
Added by the BANCBAN-FH TROJAN! |
 |
iexplore_dbg.exe |
Debugger
Added by the CWS-M TROJAN! |
 |
IexpIore.exe |
Default web browser
Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L" |
 |
idetect.exe |
detect
iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled |
 |
ISWizard.exe |
DigitalWizard
InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content |
 |
IconMgr.Exe |
E-color
Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program |
 |
Isass.exe |
EDxMC110
Added by the VB-NIA WORM! |
 |
IcnKeepr.exe |
Enterra Icon Keeper
Icon Keeper - "tool to save and restore icon positions on the desktop" |
 |
iWareStart.exe |
eWare Startup
eWare iWare task bar. Not required |
 |
IEXPLORE.exe |
Explorer Updater
Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
IndicatorUty.exe |
Fujitsu Hotkey Utility
Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed |
 |
ieloader.exe |
FX
Added by the SMALL.RR TROJAN! |
 |
intspvc.exe |
Generic Host Process for Win32 Services
Added by the DINFOR.D WORM! |
 |
InfoMyCa.exe |
Getca
Monitor for a Belkin USB Wireless adapter |
 |
isass.exe |
GLSetIT32
Added by a variant of the OPTIX PRO TROJAN! |
 |
intrenat.exe |
Gremlin
Added by the DOOMJUICE WORM! |
 |
iisca.exe |
gtydf
Added by the CLAGGER-BB TROJAN! |
 |
iscca.exe |
gtydf
Added by the DWNLDR-GTK TROJAN! |
 |
isamonitor.exe |
homepage.monitor.exe
Added by the ZLOB-QK TROJAN! |
 |
isearch.exe |
hsim
Unidentified malware |
 |
instantmsgrs.exe |
Hyper Start
Added by the RBOT-NH WORM! |
 |
I386.exe |
I386
Added by the MYPOWER WORM! |
 |
I81SHELL.exe |
I81SHELL
Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard |
 |
i8kfangui.exe |
i8kfangui
Graphical interface for fan speed control |
 |
iaanotif.exe |
IAAnotif
IAA Event Monitor User Notification Tool - part of Intel? Application Accelerator - "a performance software package for desktop PCs using select Intel? chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed |
 |
iamapp.exe |
iamapp
AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well |
 |
iap.exe |
Iap
Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely? |
 |
ias.exe |
ias
InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself! |
 |
IASHLPR.EXE |
IASHLPR
Added by the OPASERV.T WORM! |
 |
ibm.exe |
ibm
Added by the LEGMIR-AH TROJAN! |
 |
ikeybdrv.exe |
IBM Keyboard Driver
Added by the SDBOT.IC TROJAN! |
 |
ibmmessages.exe |
ibmmessages
Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport" |
 |
Ibmmon.exe |
Ibmmon.exe
?? |
 |
ibmpmsvc.exe |
Ibmpmsvc
Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes |
 |
ibmprc.exe |
IBMPRC
IBM application - what does it do and is it required? |
 |
IBMBAY2N.EXE |
IBMUltraBayHotSwapCPLLoader
Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops |
 |
IBMBAYSN.EXE |
IBMUltraBayHotSwapSound
Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound? |
 |
ibs.exe |
Ibs
Added by the HIDEDIAL-B TROJAN! |
 |
IBackground.exe |
IBWin Background process
IBackup for Windows |
 |
IBMonitor.exe |
IBWin Monitor
IBackup for Windows |
 |
icabar.exe |
IcaBar
Related to Citrix MetaFrame |
 |
icasServ.exe |
icasServ
Browser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN! |
 |
iccontrol.exe |
ICcontrol
Added by the ICcontrol premium rate adult content dialer |
 |
iClean.exe |
iClean
IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy" |
 |
ICM.EXE |
ICM
Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
 |
ICO.EXE |
ICO
Found on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
 |
icon.exe |
Icon lptt01
RapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
icon.exe |
Icon ml097e
RapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
icon.bat |
iconcache
Related to the Vista Customization Pack |
 |
iconclnt.exe |
ICONCLNT
APC PowerChute Tray Icon. Associated with the UPS listing |
 |
ICONDESK.EXE |
ICONDESK
Small utility which will allow you the option of hiding or showing your desktop icons |
 |
Iconfig.exe |
Iconfig.exe
Icon for LS-120 "Superdisk" |
 |
Iconoid.exe |
Iconoid
Iconoid is a desktop icon manager |
 |
Iconsaver.exe |
Iconsaver
IconSaver is a desktop icon manager |
 |
ICQNET.vbs |
ICQ
Added by the GORMLEZ-A WORM! |
 |
icq6.exe |
ICQ Agent
Added by the AGENT-FZJ TROJAN! |
 |
icqjdhs.exe |
ICQ Chat Service
Added by a variant of the RBOT WORM! |
 |
ICQpro.exe |
ICQ Hacking Pro
Added by a variant of the NETSPY TROJAN! |
 |
ICQLite.exe |
ICQ Lite
ICQ Lite - compact version of the popular messaging program |
 |
ICQ2002.exe |
ICQ Messenger 2002
Added by the SDBOT-ABL WORM! |
 |
Icserver.exe |
ICServer
Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations |
 |
ICSMGR.EXE |
ICSMGR
Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers |
 |
IDCom.exe |
ID Commander
Caller ID utility for identifying incoming telephone numbers |
 |
ID8525.exe |
ID8525
Added by the ID8525.A TROJAN! |
 |
id85255.exe |
ID8525
Added by the ID8525.A TROJAN! |
 |
IDA.EXE |
IDA
HP related - in a Program FilesHewlett-PackardPC COE folder |
 |
ide.exe |
IDE
Added by the ASSASIN.F TROJAN! |
 |
IDElibr32.exe |
IDE Loader
Added by the XILON TROJAN! Related to the game "Diablo II" |
 |
idecntl.exe |
idecntl
Added by a variant of the CRYPTER.C TROJAN! |
 |
idesktop.exe |
iDesktop
Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse |
 |
IDMan.exe |
IDMan
Internet Download Manager - download files faster, schedule and resume |
 |
IDTemplate.exe |
IDTemplates
Added by the BRONTOK-H WORM! |
 |
idwlog.exe |
IDW Logging Tool
Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems |
 |
IEDoctor.exe |
IE Doctor
IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" |
 |
iejava.exe |
IE Java Update
Added by the AGENT-HD TROJAN! |
 |
iemaximizer.exe |
IE New Window Maximizer
IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows |
 |
IE**.exe [* = random char] |
IE**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
IE**32.exe [* = random char] |
IE**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
iebar.exe |
IE-Bar
DesktopMedia adware |
 |
iewatch.exe |
IEAgent update check
Added by the BOMKA TROJAN! |
 |
iecheck.exe |
iecheck
Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 |
 |
Ieboot6.exe |
IECleanAux
IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup |
 |
iedll.exe |
iedll
Homepage hijacker, redirecting to coolwwwsearch.com |
 |
IEDriver.exe |
IEDriver
Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze |
 |
iedwa104.exe |
iedwa104
Added by the DLOADR-BBW TROJAN! |
 |
IEeng.exe |
IEengine
STARTPAG.AI hijacker |
 |
IEexplore32.exe |
IEexplorer AUpdate
Added by the RBOT-GRE WORM! |
 |
IEFeatures.exe |
IEFeatures
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
 |
Internetfeatures.exe |
IEFeatures
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
 |
IefxTray.exe |
IefxTray
Added by the RILER-H TROJAN! |
 |
ieharv.exe |
ieharv.exe
Added by the BANKER-HH TROJAN! |
 |
iexplore32.exe |
IELoader32
Added by the SPEX or SPEX.B WORMS! |
 |
Iesar.exe |
Iesar
Browser hijacker - redirecting to an adult web page |
 |
Iesearch.exe |
Iesearch.exe
LookNSearch adware |
 |
IEService.exe |
IEService.exe
FastFind parasite variant |
 |
IExplorer.dll |
IESet
Added by the PWS-BLUEDIT TROJAN! |
 |
iesetupi.exe |
iesetupi.exe
Added by a variant of the RBOT WORM! |
 |
iexp1orer.exe |
iestart
Added by the NEMOG.C TROJAN! |
 |
ietsr.exe |
ietsr
IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc |
 |
ieupdates.exe |
ieupdates
Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here |
 |
IEXPL0RER.EXE |
IEXPL0RER
Added by the AGOBOT-QL WORM!
Note the filename has a "0" rather than an upper case "o" |
 |
iexplor.exe |
iexplo
Added by the SIDEA TROJAN! |
 |
Iexploit.html |
Iexploit
Added by the INKER.B WORM! |
 |
iexplor.exe |
iexplor.exe
Added by an unidentified WORM or TROJAN! See here |
 |
iexplore.exe |
Iexplore
Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplore.exe |
IEXPLORE
Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
IEXPLORE.EXE |
IExplore
Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a "Custom" subfolder |
 |
IEXPLORE.EXE |
IEXPLORE
Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
ie4uini.exe |
iExplore Ini
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
iexplore.exe |
Iexplore Services
Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! |
 |
Iexplor32.exe |
IExplorer
Added by the BDOOR-BY TROJAN! |
 |
IExplorer.EXE |
IExplorer
Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexplorer.exe |
iexplorer lptt01
RapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
iexplorer.exe |
iexplorer ml097e
RapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
 |
Iexplorer.exe |
Iexplorer.exe
Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IExplore32b.exe |
IExplorer32 Java Scripting
Added by the RBOT.ABO WORM! |
 |
IExplore32cb.exe |
IExplorer32c Java Scripting
Added by the RBOT.ABN WORM! |
 |
IExplore326.exe |
IExplorer6 Java Scripting
Added by a variant of the SDBOT WORM! |
 |
IExplore327.exe |
IExplorer7 Java Scripting
Added by a variant of the SDBOT WORM! |
 |
iexpresser.exe |
iExpresser
Detected by Trend Micro as the SLENFBOT.AP WORM! See here |
 |
ipf.exe |
ifp
Added by the CLAGGER-AG TROJAN! |
 |
IFSplash.exe |
IFSplash.exe
I-FORCE driver for force feedback steering wheel |
 |
igfxtray.exe |
igfxtray
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel |
 |
Iglpbv.exe |
Iglpbv
?? |
 |
igsex2x.exe |
igsex2x
NewDial premium rate adult content dialler |
 |
iHPDetect.exe |
iHP-100
Drive Letter Searcher, iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time? |
 |
IILC.EXE |
iilc
Homepage hijacker |
 |
iptl.exe |
Iinl
PurityScan/Clickspring adware |
 |
iisvers.exe |
iisvers
Added by an unidentified TROJAN or adware |
 |
IJ75P2PS.EXE |
IJ75P2PSERVER
Printer utility which is required in order to make the printer work correctly |
 |
IKEService.exe |
IKE Service 95
Associated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything |
 |
IKEYMAIN.EXE |
iKeyWorks
A4Tech wireless keyboard driver and utility |
 |
IntEdReg.exe /OFFMAN |
ILO_Office_Manager
Intense Educational Ltd - Language Office Software. Is it required? |
 |
iLyric.exe |
iLyric
iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button |
 |
iM_Tray.exe |
iM Start Center
Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner |
 |
IMAGE32.exe |
Image & Restore
Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run |
 |
ImageDrive.exe |
ImageDrive-{hex numbers}
Nero ImageDrive from Ahead - virtual CD/DVD drive software |
 |
imagefox.exe |
Imagefox
ImageFox 2.0 (formerly available from ACDSee) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes |
 |
Imagemgt32.exe |
Imagemgt32
Added by the GEMA TROJAN! |
 |
iUtil.exe |
iMarkup Client
Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs |
 |
imation.exe |
Imatio
Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive |
 |
imchat.exe |
imchat
Added by a variant of the IRCBOT TROJAN! |
 |
imekrig.exe |
imekrig
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
 |
IMEKRMIG.EXE |
IMEKRMIG6.1
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
 |
IMEvtMgr.exe |
IMEvtMgr.exe
Added by the KEYLOG-AR TROJAN! |
 |
ImgIcon.exe |
ImgIcon
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
 |
ImgStart.exe |
ImgStart
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
 |
Imgtask.exe |
ImgTask
Related to WalletPix digital photo album. "On some computers, the Wallet Pix device will leave behind a memory-resident file called ImgTask.exe. This file will be located in the operating system directory on your computer (typically C:\windows or C:\winnt). You can remove this file at any time and it will not impact your computer’s performance or functionality. The file will be restored each time you plug in the Wallet Pix though" |
 |
IMJPMIG.EXE |
Imjpmig*.*
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese). *.* represents the version number |
 |
immcheck.exe |
immcheck.exe
Related to I-FORCE driver for force feedback steering wheel? |
 |
IMOLApp.exe |
IMOL
IncrediMail for Office Outlook Add-On |
 |
imontray.exe |
IMONTRAY
System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards |
 |
IM-svr.EXE |
IMprocess
IMNames adware |
 |
IMStart.exe |
IMStart
InterMute security software related |
 |
IMVUClient.exe |
IMVU
IMVU chat client that allows you to create "your own avatars who chat in animated 3D scenes" |
 |
imwireup.exe |
IMwire
SafeSurfing adware variant |
 |
im_1.exe |
im_autorn
Added by the IMAV.A WORM! |
 |
im_2.exe |
im_autorn
Added by the BAGLEDL-BO TROJAN! |
 |
incd.exe |
InCD
Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows |
 |
IncMail.exe |
IncMail
"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
 |
incredimail.exe |
Incredimail
"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
 |
IncMail.exe |
Incredimail
"IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
 |
Indexindicator.exe |
Indexindicator
Added by the LAZAR TROJAN! |
 |
IndexSearch.exe |
IndexSearch
Associated with PaperPort scanner software from ScanSoft |
 |
IndexTray.exe |
IndexTray
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
 |
IndicatorUty.exe |
IndicatorUty
Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed |
 |
inetsync.exe |
INET
Meplex adware |
 |
Inetdbs.exe |
Inet DataBase
Added by the QEDS WORM! |
 |
inetdl.exe |
Inet Delivery
Inet Delivery adware |
 |
inetdl_2.exe |
Inet Delivery
Inet Delivery adware |
 |
inetcntrl.exe |
inetcntrl
Bsafe Online - internet filter |
 |
inetconf.exe |
InetConf
?? |
 |
INETD32.EXE |
Inetd
Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation |
 |
inetinfo.exe |
inetinfo.exe
Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) |
 |
inetinfomon.exe |
inetinfomon manager
Added by the DONBOMB.A TROJAN! |
 |
inetmgr.exe |
inetmgr
Actual Names (AdvSearch) Internet Keywords parasite |
 |
InfeStopRemover.exe |
InfeStop
InfeStop spyware remover - not recommended, see here |
 |
is.exe |
Info Select
Info Select from Micro Logic - personal information manager |
 |
Info32x.exe |
Info32x
Added by the GEMA TROJAN! |
 |
InfoPenIM.exe |
InfoPenMSN
InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand |
 |
Infoplay.exe |
Infoplay.exe
Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed? |
 |
iu.exe |
Information Update
Detected by Kaspersky as the CENTIM.CH TROJAN! |
 |
IRMON.EXE |
Infra-red Monitor
System Tray access to infra-red devices. Not required unless you use infra-red devices |
 |
infus.exe |
infus
Adult content dialler |
 |
Infuzer.exe |
Infuzer
Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities" |
 |
infwin.exe |
infwin
VX2.Transponder parasite updater/installer related |
 |
Init32.exe |
Init32
Added by the WINEX.A TROJAN! |
 |
install.exe |
Initial Page
EasySearch browser hijack installer |
 |
injobs.exe |
injob
Added by the BINJO TROJAN! |
 |
InkMonitor.exe |
Ink Monitor
Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
 |
InkWatch.exe |
InkWatch
Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
 |
InoRpc.exe |
InoRPC
Associated with eTrust Antivirus/InoculateIT |
 |
InoRT9x.exe |
InoRT
Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage |
 |
InoTask.exe |
InoTask
Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates |
 |
iservice.exe |
iNotice
Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos |
 |
insCOA5.exe |
insCOA5
?? |
 |
Insider.exe |
Insider
Detected by PCTools as the AGENT.KMC TROJAN! See here |
 |
InstaAlert.exe |
InstaAlert
"Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly" |
 |
instafinder.exe |
Instafinder
TopSearch.D adware |
 |
InstaFinderK inst.exe |
InstaFinderK
InstaFinder adware |
 |
Install.exe |
Install
Added by the BANCBAN-HG TROJAN! |
 |
InstallAurealDemos.js |
InstallAurealDemos
Used to initialize the Aureal A3D demos InstallShield wizard |
 |
Ibtna.exe |
InstallBuddy
InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync |
 |
InstallCleaner.exe |
InstallCleaner
Added by the ANYHOMB.F TROJAN! |
 |
installstub.exe |
Installstub
Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone |
 |
IBDaemon.exe |
Instant Buzz Daemon
Instant Buzz adware |
 |
imservice.exe |
Instant Messenger Service
Detected by Kaspersky as the HEUR TROJAN! |
 |
INSTAN~1.EXE |
InstantAccess
From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs |
 |
InstantDrive.exe |
InstantDrive
Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software |
 |
instantpleasure.exe |
InstantPleasure
Adult content dialler |
 |
instantpleasurexxx.exe |
InstantPleasureXXX
Adult content dialler |
 |
instit.bat |
instit
Added by the OPASERV.H WORM! |
 |
INSTIT.BAT |
instit
Added by the OPASERV.K WORM! |
 |
InstUtlR.exe |
InstUtlR.exe
?? |
 |
idctup20.exe |
intdctrr
SafeSurfing adware variant |
 |
IntegardTray.exe |
IntegardTray
System Tray access to Integardparental control software from Race River Corp |
 |
imontray.exe |
Intel Active Monitor
System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards |
 |
IntelProcNumUtility.exe |
Intel Product Number Utility
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
 |
iis.exe |
Intel system works
Added by the RBOT.QGA WORM! |
 |
igfxtray.exe |
Intel(R) Common User Interface
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel |
 |
igfxpers.exe |
Intel(R) Common User Interface
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Not known exactly what it does but apparently it isn't required |
 |
intel32.exe |
intel32.exe
Added by the SmitFraud alias SPYJACK-B TROJAN! |
 |
IntelAudioStudio.exe |
IntelAudioStudio
"Intel Audio Studio combines Intel? High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience". Audio utility supplied with Intel motherboards |
 |
intell32.exe |
intell32.exe
Added by the SmitFraud alias Desktophijack.C TROJAN! |
 |
intell321.exe |
intell321.exe
Added by the SPYJACK-B TROJAN! |
 |
Intelliflag_be.exe |
Intelliflag_be.exe
Added by the Intelliflag SPYWARE! |
 |
ipoint.exe |
IntelliPoint
Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
 |
IntelMEM.exe |
IntelMEM
Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line |
 |
ifrmewrk.exe |
IntelWireless
Associated with the Intel PRO/Set Wireless software |
 |
IntEdReg.exe /CHECK |
Intense Registry Service
Intense Educational Ltd - Language Office Software. Is it required? |
 |
Icmon.exe |
InterCheck Monitor
Part of Sophos ant-virus sofware |
 |
ICMON.EXE |
InterCheckMonitor
Part of Sophos anti-virus sofware |
 |
Interdll.exe |
Interdll
Added by the DELF family of TROJANS! |
 |
internat.exe |
internat
Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir% |
 |
internat.exe |
internat.exe
Microsoft language selection icon in system tray, located in the System (Win98/Me) or System32 (WinNT/2K/XP) folder |
 |
internat.exe |
Internat.exe
Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon |
 |
Internet.exe |
Internet
Added by the PWS-CS TROJAN! |
 |
IAMNET~1.EXE |
Internet Answering Machine
From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
 |
IAM.exe |
Internet Answering Machine
From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
 |
ICD.EXE |
Internet Call Director
TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet |
 |
ICM.EXE |
Internet Call Manager
Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
 |
ICP.EXE |
Internet Content Publisher
Added by the RBOT-UD WORM! |
 |
ida.exe |
Internet Download Accelerator
Internet Download Accelerator download manager |
 |
idman.exe |
Internet download manager service
Added by the RBOT-BMS WORM! |
 |
iexplorer.exe |
Internet Explorer
Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IEXPLORE.EXE |
Internet Explorer
Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
IExplorer.exe |
Internet Explorer
Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexpiore.exe |
Internet Explorer
Added by the RBOT-AZC WORM! |
 |
IEXPLORE.EXE |
Internet Explorer Configuration
Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplore.pif |
Internet Explorer Security
Added by the RBOT-ALQ WORM! |
 |
iexplorer.exe |
Internet Explorer Updater
Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IEexplore.exe |
Internet Explorer6
Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
ipcl32.exe |
Internet Protocol Configuration Loader
Added by the SDBOT TROJAN! |
 |
inetsrv.exe |
Internet Server
Added by the STARTPA-EM TROJAN! |
 |
intersvc.exe |
Internet Service
Added by the SPYBOT-DE WORM! |
 |
internet.exe |
Internet Services
Added by the MYTOB.BT WORM! |
 |
interserv.exe |
Internet Services
Added by the RBOT.BNT WORM! |
 |
iss_srvr.exe |
Internet Sharing Server
Intel AnyPoint internet sharing software. Now discontinued |
 |
ITIMER.exe |
Internet Timer
Shareware dial-up connection call cost calculator from Ratsoft |
 |
iw.exe |
Internet Washer Pro
Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
 |
Internet.exe |
Internet.exe
Added by the MAGICCALL VIRUS! |
 |
InternetCalls.exe |
InternetCalls
InternetCalls - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
iexplore32.exe |
InternetExplorer32
Added by the RBOT-GRA WORM! |
 |
INTERN~1.EXE |
InternetShield
InternetShield misleading security software - not recommended, see here |
 |
InternetSpy.exe |
InternetSpy
Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself! |
 |
iw.exe |
InternetWasherPro
Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
 |
Internt.exe |
Internt
Added by the PEEPER or CARUFAX.A TROJANS! |
 |
intersoftmsngr.exe |
Intersoft Msngr
Added by the AGOBOT-NW WORM! |
 |
it_cpq~1.exe |
InterTrust Quick Start
InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business |
 |
InterVoip.exe |
InterVoip
InterVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype |
 |
interwarn.exe |
InterWARN
InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs |
 |
IEXPLORE.exe |
Intespention
Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
Intmgr.exe |
Intmgr
Added by the GEMA TROJAN! |
 |
intranet.exe |
Intranet
Added by the CHIMOZ.AC TROJAN! |
 |
Intrenat.exe |
Intrenat
Added by the LEMIR.E TROJAN! |
 |
ia99.exe |
IntruderAlert
Intruder Alert '99 from Bonzi - spyware |
 |
iobiClient.exe |
iobi
iobi Home - a mail/voice service by Verizon |
 |
ioloAV.exe |
iolo AntiVirus
iolo AntiVirus |
 |
ioloFW.exe |
iolo Personal Firewall
iolo Personal Firewall |
 |
ibackup.exe |
Iomega Automatic Backup
Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
 |
ibackup.exe |
Iomega Automatic Backup 1.0.1
Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
 |
IMGICON.EXE |
Iomega Disk Icons
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
 |
IMGICON.EXE |
Iomega Drive Icons
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
 |
imiconxp.exe |
Iomega ImIconXP
Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks |
 |
IMGSTART.EXE |
Iomega Startup Options
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
 |
IOWATCH.EXE |
Iomega Watch
Used by Iomega drives. Available via Start -> Programs |
 |
Iomon98.exe |
Iomon98.exe
PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang |
 |
ipredirect.exe |
IP Packet Redirect Service
Added by the FORBOT.SM WORM! |
 |
ipstack.exe |
IP Stack
Added by the AGOBOT.CW WORM! |
 |
IP**.exe [* = random char] |
IP**.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
IP**32.exe [* = random char] |
IP**32.exe [* = random char]
CoolWebSearch/HomeSearch adware - for examples, see this log |
 |
ipcconn.exe |
IPC Connection
Added by the RBOT-AEG WORM! |
 |
ipcfg.exe |
ipcfg.exe
Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN! |
 |
ipcon32.exe |
IpCtrl
Added by an unidentified VIRUS, WORM or TROJAN! |
 |
ipwf.exe |
IPFW
Added by the DLOADER-YF TROJAN! |
 |
IPHSend.exe |
IPHSend
AOL related. What does it do and is it required? |
 |
ipclient.exe |
IPInSightLAN 0*
Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resources. * represents 1 or 2 |
 |
ipmon32.exe |
IPInSightMonitor 0*
Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. * represents 1 or 2 |
 |
iplogsec.exe |
IPLog Security
Detected by Trend Micro as the IRCBOT.GP BACKDOOR! See here |
 |
iAgent2.exe |
iPlusAgent2
Related to iriver portable media products. What does it do and is it required? |
 |
ipmon.exe |
ipmon.exe
Added by the RECERV or R3C.B TROJANS! |
 |
ipnetwork.exe |
IpNetwork
Maxifiles adware |
 |
Ipnuker.vbs |
Ipnuker
Added by the INKER.B WORM! |
 |
IP Operator 2005.exe |
IPO3
IP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single button |
 |
IPODUSB.EXE |
iPOD USB Driver
Added by a variant of the RBOT WORM! |
 |
iPODService.exe |
iPod USB Service
Added by a variant of the RBOT WORM! Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program FilesiPodin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup! |
 |
iPodManager.exe |
iPodManager
Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods |
 |
iPodWatcher.exe |
iPodWatcher
Associated with Apple's iPod MP3 player. Detects when the iPod is connected? |
 |
IPP4Detect.exe |
IPPDetect
Part of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos" |
 |
ipreg.exe |
ipreg
Added by the ZAGABAN-H TROJAN! |
 |
iprntctl.exe |
iPrint Tray
Novell? iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net |
 |
ip.exe |
iProtectYou
iProtectYou - internet filtering/parental control and network monitoring software |
 |
iPY.exe |
iprun
iProtectYou spyware |
 |
ipsec7.exe |
iPSec7
Detected by Trend Micro as the AGENT.AHVR TROJAN! See here |
 |
IPSECD~1.EXE |
ipsecdialer
Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
 |
ipsecdialer.exe |
ipsecdialer
Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
 |
IPSecMon.exe |
IPSecMon
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
 |
iptray.exe |
iptray
System Tray access to Intel Desktop Utilities - "provides you with the means to monitor system temperatures, voltages, fan speeds, and hard drive health; view detailed system information, and test your system hardware for common errors" |
 |
IPW.exe |
IPW
Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone" |
 |
ipwf.exe |
ipwf
Added by the SCHOEBERL TROJAN! |
 |
ipwins.exe |
IpWins
IPWins adware |
 |
ipxwshel.exe |
ipxwshel
Added by the WAREZOV.DG WORM! |
 |
iqes.exe |
IQES.exe
?? |
 |
irasyncd.exe |
irassync
IRASSync adware |
 |
IreIKE.exe |
IREIKE
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
 |
IRMON.EXE |
IrMon
System Tray access to infra-red devices. Not required unless you use infra-red devices |
 |
itcnmon.exe |
IRPMonitor
?? |
 |
irssyncd.exe |
irssyncd
SafeSurfing adware variant |
 |
iexplorer.exe |
irwftp
Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IrXfer.exe |
IrXfer
Microsoft Infrared Transfer application |
 |
ir_ftp.exe |
ir_ftp
Added by the IRFTP TROJAN! |
 |
irwftp.exe |
ir_ftp
Added by the BANCOS.H TROJAN! |
 |
Isass.exe |
Isass
Added by the FUTRO TROJAN! |
 |
Issas.exe |
IsassRenascimento
Detected by Kaspersky as the BANKER.GAX TROJAN! See here |
 |
ISBMgr.exe |
ISBMgr.exe
Related to Sony ISB Utility. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems |
 |
iscch.exe |
iscch
Added by the LCPRANK-A WORM! |
 |
isdbdc.exe |
isdbdc
For Compaq PC's. May install properties in dial-up networking when you register with an ISP |
 |
isDel.bat |
isDeleteMe
Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product |
 |
IWatch.exe |
ISDNwatch
FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks" |
 |
iShield.exe |
iShield
"GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser" |
 |
ishost.exe |
ishost.exe
Added by the XJ TROJAN! |
 |
ISLP2STA.EXE |
ISLP2STA
A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers |
 |
ISMModule.exe |
ISMModule
Internet Speed Monitor C adware related - see example here |
 |
ISMModule2.exe |
ISMModule2
Internet Speed Monitor C adware related - see example here |
 |
ISMModule3.exe |
ISMModule3
Internet Speed Monitor C adware |
 |
ISMModule4.exe |
ISMModule4
Internet Speed Monitor A adware related |
 |
ISMModule6.exe |
ISMModule6
Internet Speed Monitor C adware related - see example here |
 |
ISMModule7.exe |
ISMModule7
Internet Speed Monitor C adware related - see example here |
 |
ISMModule8.exe |
ISMModule8
Internet Speed Monitor C adware related |
 |
ISMPack5.exe |
ISMPack5
Internet Speed Monitor C adware related - see example here |
 |
ISMPack6.exe |
ISMPack6
Internet Speed Monitor C adware related - see example here |
 |
ISMPack7.exe |
ISMPack7
Internet Speed Monitor C adware |
 |
ISMPack8.exe |
ISMPack8
Internet Speed Monitor C adware related - see example here |
 |
ispynow.exe |
iSpyNOW
iSpyNOW - remote monitoring and surveillance software |
 |
Israfel.vbs |
Israfel
Added by the GAGGLE.D or GAGGLE.E WORMS! |
 |
ISPopup.exe |
IsReminder
Related to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup |
 |
inet.exe |
ISS
Meplex adware |
 |
issearch.exe |
issearch.exe
Added by the ZLOB-QF TROJAN! |
 |
issEnc32.exe |
issEnc32Svr
Added by a variant of the RBOT WORM! |
 |
issimsvc.exe |
ISSI EZUpdate Service
Part of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching |
 |
ISStart.exe |
ISStart
LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
 |
ISSVC.exe |
ISSVC
Part of Norton Internet Security Suite |
 |
istsvc.exe |
IST Service
ISTBar adware |
 |
istinstall zazzer.exe |
istinstall zazzer.exe
Unidentified adware downloader/installer |
 |
ISUSPM.exe |
ISUSPM Startup
InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version |
 |
issch.exe |
ISUSScheduler
InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version |
 |
ISW.exe |
ISW.exe
Related to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite |
 |
isxa.exe |
isxa
Added by the SMALL-EIV TROJAN! |
 |
iSysCleaner.exe |
iSysCleaner
iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user |
 |
isystem.exe |
isystem
Added by the CHORUS-A TROJAN! Searchforfree browser hijacker |
 |
italfds.exe |
ItalU
Added by a TROJAN! See here TROJAN! |
 |
Itk.exe |
Itk
In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
 |
itk.exe |
itk.exe
Insert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert |
 |
iTouch.exe |
iTouch
iTouch loads the iTouch configuration program for Logitech keyboards. It's needed if your keyboard has shortcut buttons and if you use them. It's also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock |
 |
ItsDeductible.exe |
ItsDeductiblePopUp
ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip |
 |
itune.exe |
ITUNES
Added by the RBOT-ZU WORM! |
 |
itunes.exe |
ITUNES
Added by the OSCABOT-L WORM! Note - this file will be placed in the WindowsSystem32 or WinntSystem32 folder, and should not be confused with the (legitimate) Apple iTunes process, always located in the Program FilesiTunes folder |
 |
iTunesHelper.exe |
iTunes Helper
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
 |
iTunesHelper32.exe |
iTunes Music
Added by the SDBOT.CHK WORM! |
 |
ita.exe |
iTunesAgent
Added by the TACTSLAY.U TROJAN! |
 |
itunesff.exe |
itunesff
Added by the EB adult premium dialer |
 |
iTunesHelper.exe |
iTunesHelper
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
 |
itype.exe |
itype
Microsoft IntelliType Pro related. Allows you to map the extra function keys to any program you like. The extra keys are set to defaults such as Messenger, Mail, My Document, etc. Not required unless you want to use the extra keys |
 |
ivpsvmgr.exe |
IVPServiceMgr
Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates |
 |
ivy.exe |
ivy.exe
Added by the AGENT-ENZ TROJAN! |
 |
iwctrl.exe |
IW ControlCenter
Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
 |
iwctrl.exe |
iwctrl
Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
 |
ixplore.exe |
ixplore
Added by the SDBOT-CY TROJAN! |
 |
ixsso.exe |
ixsso
Added by the AGENT.AM TROJAN! Note - example names include "XviD", "Winamp Remote", "Windows Media Player" and "Futuremark" |
 |
iexplore.exe |
Java Runtimes
Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder |
 |
InsDetect.exe |
Jessops Insert Detect
Jessops Insert Detect from Jessops Picture Suite |
 |
ISASS.exe |
Kiamat Sudah Dekat_16_04
Added by the PAHATIA.B WORM! |
 |
iexplore |
l44sys**
Added by the VBS.LIDO WORM - where ** is a number between 65 and 76 |
 |
Internat.exe |
load
Added by the WOWCRAFT TROJAN! |
 |
inetinfo.exe |
load=
Added by the PROXY-GG TROJAN! |
 |
Isass.exe |
Local Security Authority Service
Added by the LINKBOT.M WORM! |
 |
Intenat.exe |
Local Service
Added by the NUCLEAR-J TROJAN! |
 |
IPCONN.EXE |
Logitech Desktop
Added by the SDBOT-WE WORM! |
 |
ISStart.exe |
LogitechGalleryRepair
LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
 |
ISStart.exe |
LogitechVideoRepair
LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
 |
InstallHelper.exe |
LogitechVideo[inspector]
Logitech QuickCam software installation helper |
 |
imoet.exe |
LogonAdministrator
Added by the RAHIWI.A WORM! |
 |
ISASS32.pif |
LSASS 32
Added by the ASSIRAL-C WORM! |
 |
Isass32.exe |
LSASS32
Added by the KELVIR.M WORM! |
 |
igps.exe |
lspins
Reported as the VB.KC TROJAN by Kapersky Anti-Virus |
 |
Iexplor32.exe |
Macromedia Drive
Added by a variant of the RBOT WORM! |
 |
Internet.exe |
Micrcoft Updat
Added by the RBOT-ANA WORM! |
 |
iexplore.exe |
Microsoft
Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
install.exe |
Microsoft
Added by a variant of the IRCBOT BACKDOOR! |
 |
internetdat.exe |
Microsoft
Detected by Kaspersky as the RBOT.ETY BACKDOOR! See here |
 |
iexplorer.exe |
Microsoft Associates, Inc.
Added by the LOVGATE.Z WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexplorer32.exe |
Microsoft Dev
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
internal.exe |
Microsoft explorer Update
Added by an unidentified WORM or TROJAN! |
 |
ISATRAY.EXE |
MICROSOFT FIREWALL CLIENT
MS Internet Security and Acceleration Server - see here |
 |
Isass.exe |
Microsoft Hosts Service
Added by a variant of the RBOT WORM! |
 |
Iexplore.exe |
Microsoft IE
Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
IEExec.exe |
Microsoft IE Execute shell
Added by the ALADINZ.N TROJAN! |
 |
ISASS.EXE |
MicroSoft IE Sasser
Added by the SDBOT.MX WORM! |
 |
iexplorer.exe |
Microsoft Inc.
Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexplorer.exe… |
Microsoft Inc.
Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
initsvc.exe |
Microsoft Initialization Service
Detected by Trend Micro as the IRCBOT.AXK BACKDOOR! See here |
 |
initserv.exe |
Microsoft Initialization Services
Added by the IRCBOT-ABO TROJAN! |
 |
iau.exe |
Microsoft Internet Acceleration Utility
EasySearch adware |
 |
inetdump.exe |
Microsoft Internet Dumping Protocol
Detected by Kaspersky as the IRCBOT.BLL TROJAN! See here |
 |
iiexplorer.exe |
Microsoft Internet Exp
Added by the RBOT-KX WORM! |
 |
iexplore.exe |
Microsoft Internet Explorer
Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplorer.exe |
Microsoft Internet Explorer
Added by the SDBOT-XNRBOT.UZ WORM! |
 |
ie.exe |
Microsoft Internet Explorer Manager
Added by a variant of the IRCBOT TROJAN! |
 |
ieupdate.exe |
Microsoft Internet Explorer Update
Detected by Trend Micro as the SHEUR.MH WORM! See here |
 |
inetsync.exe |
Microsoft Internet Syncing
Detected by Kaspersky as the IRCBOT.BLL TROJAN! See here |
 |
IEserv.exe |
Microsoft IT Update
Added by a variant of the RBOT WORM! |
 |
iasrecst.exe |
Microsoft Keyboard Enhance 2.0.
Added by the BCKDR-QIL TROJAN! |
 |
iasrecst.exe |
Microsoft Keyboard Enhance V2.0
Detected by F-Prot as the DOWNLOADER2.AILI TROJAN! |
 |
Isass.exe |
Microsoft Lsass Center
Added by a variant of the SDBOT WORM! |
 |
iexplorersis.exe |
Microsoft Machine Script
Added by the RBOT-CMH WORM! |
 |
Iassd.exe |
Microsoft media services
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
iau1.exe |
Microsoft Office Quick Launcher
Added by the DLOADR-AWD TROJAN! |
 |
IEXwe.exe |
Microsoft Opeions
Added by a variant of the RBOT WORM! |
 |
infoebay.exe |
Microsoft Special offer
Added by a variant of the RBOT WORM! |
 |
inetman.exe |
Microsoft System Checkup
Added by the DONK.O WORM! |
 |
Isac.exe |
Microsoft Update
Added by the RBOT-AU WORM! |
 |
imchemaoa.exe |
Microsoft Update
Detected by Kaspersky as the BANLOAD.KWQ TROJAN! See here |
 |
init.exe |
Microsoft Update 33
Added by the RBOT-ATT WORM! |
 |
igfkishc.exe |
Microsoft Values
Added by the RBOT-GLO WORM! |
 |
igfxsrvc32.exe |
MicroSoft Visual SP2
Detected by Trend Micro as the SDBOT.GAV WORM! See here |
 |
iexplore.exe |
Microsoft Windows (D)
Identified as a variant of the TrojanSpy.Agent malware |
 |
iexplorer.exe |
Microsoft Windows Explorer
Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iPodFix.exe |
Microsoft Winedows WinServ
Added by a variant of the RBOT WORM! |
 |
IEXPL0RE.EXE |
Micrsoft Internet Explorer
Added by the RBOT-AQV WORM! Note the number "0" in the filename |
 |
icq.exe |
Mirabilis ICQ
If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
 |
ICQNet.exe |
Mirabilis ICQ
If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs |
 |
IEEXPLORER.exe |
Miscrosoft Windows Explorer
Reported as the SDBOT.YX WORM! |
 |
inisys.exe |
MMC
Added by the OSCABOT-I WORM! |
 |
inetforn.exe |
MMicrosoft Security Management
Added by the RBOT.AFZ WORM! |
 |
igomnu.exe |
mnu
Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required? |
 |
ICO.EXE |
Mouse Suite 98 Daemon
Found on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
 |
indexcleaner.exe |
MRUBlaster
MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder |
 |
ivhost.exe |
MS Host Manager
Added by the RBOT-BJN WORM! |
 |
ign32.pif |
MS WINS Binary
Added by the RBOT-ASB WORM! |
 |
icpldrvx.exe |
Msconfig
Added by the BANLOAD.BFT TROJAN! |
 |
isasse.exe |
MSControl3d1
Added by the RBOT.CGU WORM! |
 |
install.exe |
MSN
Added by the AGENT-GDO TROJAN! |
 |
iTuneshelp.exe |
MSN
Added by a variant of the IRCBOT BACKDOOR! See here |
 |
imsngsr.exe |
MSN Funny Images
Added by the AGOBOT-TT WORM! |
 |
IExplorer.exe |
Msn Messenge
Added by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IExplorer.exe |
MSN Messenger
Added by the BANKER-EU TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
ImScInst.exe |
MSPY2002
Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word |
 |
Iexpres.exe |
MSStartOptimizer
Added by the DASMIN-E TROJAN! |
 |
Iexplore .exe |
mssysint
Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
 |
INTERNETFEATURES.exe |
MSVersion
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
 |
iexpl0re.exe |
myMh2
Added by the DELF.FAI TROJAN! |
 |
install.exe |
MyVBApp
Detected as Generic Downloader.s by McAfee, probable variant of ReferAd adware! |
 |
Iexplorer0.exe |
Name
Added by the THREADSYS TROJAN! |
 |
iid.exe |
Net iD
"With the Net_iD program, you can easily and securely logon with a smart card into a domain, a virtual private network (VPN) or in Citrix and Terminal Server environments" |
 |
InstallService.exe |
Netscape
Related to Netscape installation |
 |
internat.exe |
Network Connections
Added by the ZD TROJAN! |
 |
internet.exe |
NetworkAssociates Inc
Added by the LOVGATE.AB WORM! |
 |
ispnews.exe |
News Service
F-Secure antivirus related. However, is this particular item required? |
 |
installer_en.exe |
NI.UGDC_0002_N108M1007
MyContentAssistant security program, not recommend - see here |
 |
insight.exe |
Nielsen NetRatings
NetRatings Premeter spyware |
 |
IntelHCTAgent.exe |
NMSSupport
Network monitor for Intel? Hub Connect Technology |
 |
IntroWiz.exe |
Norton Personal Firewall
Part of Norton Personal Firewall or Norton Internet Security |
 |
iexplore.exe |
nternet Explorer
Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
Isass.exe |
NvMsnW
Added by the BROPIA.K WORM! |
 |
imag.exe |
Office Desktops
Detected by Trend Micro as the SPYBOT.AQR WORM! See here |
 |
IE4321.exe |
Olympic
Adult content premium rate dialer - also detected as SMALL.CZ |
 |
iexplore.exe |
OPTIMIZER
Added by the EVEVINC TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
 |
iexplore.exe |
OPTIMIZER
Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
InSane.exe |
OutLooks
Added by the SWOOP TROJAN! |
 |
ISASS.exe |
Patah Hati
Added by the PAHATIA.A WORM! |
 |
initial.bat |
PC2X
Added by the DWNLDR-FZZ TROJAN! |
 |
igfxpers.exe |
Persistence
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Not known exactly what it does but apparently it isn't required |
 |
isc_ui.exe |
Personal Security Center Monitor
Added by the FAKEALERT TROJAN! |
 |
internal.exe |
PingTimeout Institution
Added by the SDBOT.BMH WORM! |
 |
itLoad.exe |
Praize Messenger
Praize IM Christian chat instant messenger |
 |
IEXPLORE.exe |
Program in Windows
Added by the LOVGATE.AB WORM! |
 |
IExplore .exe |
Protection
Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the ".exe" |
 |
iaanotif.exe |
RAID Event Monitor
IAA Event Monitor User Notification Tool - part of Intel? Application Accelerator - "a performance software package for desktop PCs using select Intel? chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed |
 |
irbme.exe |
Randex virus built for IRBMe
Added by the RANDEX.RH WORM! |
 |
i11r54n4.exe |
rate.exe
Added by the BEAGLE.E WORM and variants! |
 |
IEXPLORER.EXE |
Ravshell
Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
ipcfg.exe |
Reg Service
Added by the AGOBOT-SO WORM! |
 |
imonitor.exe |
Remote Update Monitor
Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer |
 |
ib.exe |
RenolB
?? |
 |
inetinfo.exe |
run
Added by the BINGHE TROJAN! |
 |
info32.exe |
run=
CoolWebSearch Tapicfg parasite variant |
 |
icqchk.exe |
runapp
Added by the BOMKA TROJAN! |
 |
InvokeSvc3.exe |
RunCA
Wireless-G USB Wireless Network Adapter related - would appear to be required |
 |
Internat.exe |
Runtt1
Added by the LINEAGE-R TROJAN! |
 |
Internet.exe |
Runtt1
Added by the LINEAGE-Q TROJAN! |
 |
ipcTray.exe |
SafetyNet
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" |
 |
ipcLn.exe |
SafetyNet_Notifier
Safety.Net from Netveda - "offers Internet security, content security and advanced Internet firewall protection for all your LAN computers, and trust controls to block unwanted or harmful applications from accessing the network" |
 |
install_sbd_en.exe |
SBI
Downloader for a variety of rogue anti-spyware programs |
 |
Inicio.exe |
ScanInicio
Part of Panda Antivirus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active |
 |
init_scheduler.exe |
scheduler_monitor
Scheduler for ReaConverter advanced image converter |
 |
ixplore.exe |
scvhost loader
Added by the SDBOT-CY TROJAN! |
 |
integitor.exe |
Secure System
Added by the AGOBOT.ACI WORM! |
 |
inetfor.exe |
Security Antivirus Xp 1
Added by the SDBOT.BAV WORM! |
 |
ispbeg.exe |
ServiceConfig
Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation |
 |
iexplore.exe |
Services
Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplorer.exe |
Services
Added by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexploler.exe |
Services
Added by the RANCK-LT TROJAN! |
 |
iexpolere.exe |
Services
Added by the RANCK.LU TROJAN! |
 |
icwconn1.exe |
SetupICWDesktop
Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway |
 |
ibm00001.dll |
Shell
Added by the TORPIG-Q TROJAN! |
 |
iexplore.exe |
Shell
Added by the KIPIS-U WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft |
 |
ibm0000*.exe [* = digit] |
Shell
Added by the TORPIG-C and TORPIG-J TROJANS! Filenames spotted include ibm00001.exe, ibm00002.exe, ibm00005.exe and so on |
 |
ibm[RANDOM 5 DIGIT NUMBER].exe |
Shell
Added by the ANSERIN TROJAN! |
 |
iexplore.exe |
Shell32
Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
isca.exe |
ShellN
Added by the IBILL.Z TROJAN! |
 |
iexplore.exe |
ShellRun32
Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
ibot4.exe |
Shmgrate.exe
Added by the GASTER TROJAN! |
 |
Iexplore.exe |
slide
Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! |
 |
iro.bat |
SM
Added by the IROFFER.CT TROJAN! |
 |
IObit SmartDefrag.exe |
SmartDefrag
"IObit SmartDefrag helps defragment your hard drive more efficiently than any other product on the market - free or not" |
 |
iro.bat |
SMS
Added by the IROFFER.CT TROJAN! |
 |
ian_monitor.exe |
SM_IAN
AdvancedCleaner misleading security software - not recommended, see here |
 |
icthis.exe |
some
Online Video Add-on - masquerades as a helper application for watching videos. In reality, though, it installs a rogue anti-spyware, or SmitFraud, application on your computer |
 |
irun4.exe |
ssate.exe
Added by the BEAGLE.J WORM! |
 |
irun.exe |
ssgrate.exe
Added by the MITGLIEDER.D TROJAN! |
 |
irun4.exe |
ssgrate.exe
Added by the MITGLIEDER.F TROJAN! |
 |
isfmntr.exe |
start
Online Video Add-on - masquerades as a helper application for watching videos. In reality, though, it installs a rogue anti-spyware, or SmitFraud, application on your computer |
 |
iexplore.exe |
starter
Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iwnujdss.exe |
StartupBin
Added by the SDBOT-XZ WORM! |
 |
id53.exe |
stcinstaller
Added by the SCTHOUGHT.L TROJAN! |
 |
iwnujdss2.exe |
Sts
Added by the SDBOT-YI WORM! |
 |
inetinfo.scr |
svchost
Added by the ODELUD WORM! |
 |
ICLOAD95.EXE |
Sweep95
Part of Sophos ant-virus sofware |
 |
iexplorer.exe |
syscheck
Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexplorer.exe |
sysconfig
Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
IExpIore .exe |
SysRes
Added by the ELITPER.E WORM! |
 |
inetinfo.exe |
System
Added by the PARDROP-A TROJAN! |
 |
iexplore.exe |
System Configuration
Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplore.exe |
System Information Manager
Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
inet.exe |
System64
Added by the DENGLE-A TROJAN! |
 |
iservc.exe |
SystemInit
Added by the FIZZER WORM! |
 |
Ir32_a.exe |
SystemMgr
Added by the MAGANIA-OU TROJAN! |
 |
itDDD.exe |
Systems
Added by the DLOADER-PP TROJAN! |
 |
i love you.exe |
test
Added by the SINGU-T TROJAN! |
 |
IdxOffice.exe |
TGPro Office
With IdiomaX Office Translator "you can translate documents directly from your favorite text editor (Microsoft Word, WordPerfect or Lotus WordPro)" |
 |
intranet.exe |
The Ethernet
Added by a variant of the SDBOT WORM! |
 |
intranet.exe |
The Intranet
Added by a variant of the SDBOT WORM! |
 |
intcp32.exe |
Threaded
Added by the RANDEX.UG WORM! |
 |
IDTemplate.exe |
Tok-Cirrhatus
Added by the RONTOKBRO.A WORM! |
 |
Idhost.exe |
ToPicks Starter
TOPicks adware |
 |
Init.exe |
TrojanShield
TrojanShield |
 |
internetcolor.exe |
True Internet Color Icon
Now superseeded by ColorWizzard. Was part of 3Deep. "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images" |
 |
init3.exe |
Unix File Support
Added by the RBOT-ZN WORM! |
 |
iexploreupd.exe |
Update Explorer
Added by a variant of the RBOT WORM! |
 |
InstantDrive.exe |
VOBID
Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software |
 |
ipigclient.exe |
VPNClient
iOpus Private Internet Gateway (iPIG) client. 'Using powerful 256-bit AES encryption technology, the iOpus Private Internet Gateway (iPIG) creates a secure "tunnel" that protects your inbound and outbound communications (Email, Web, IM, VOIP, calls, FTP, etc.) at any Wi-Fi hotspot or wired network' |
 |
Int*****.exe |
Websx
Adult content dialler - where ***** are random |
 |
iphider.exe |
wfips
ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here |
 |
iexplore.exe |
windows
Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
IEXPLORER.exe |
Windows Backup Configuration
Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
Internet.exe |
Windows connection manager
Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one, it copies it's self under three other file names and folder locations |
 |
ipservice32.exe |
Windows Firewall
Added by a variant of the RBOT WORM! |
 |
integator.exe |
Windows Fix
Added by the SDBOT.ZAB WORM! |
 |
InSearch.exe |
Windows Incontext
PacerD_Media/Pacimedia.com/Z-Quest adware installer |
 |
internet.exe |
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
internet128.exe |
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
internet32.exe |
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
internet64.exe |
Windows Internet Browser Services
Added by a variant of the IRCBOT TROJAN! See here |
 |
ipsec.exe |
Windows IP Security
Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel |
 |
ipsecs.exe |
Windows IP Security Service
Added by the RBOT.BPW WORM! |
 |
ipcbind.exe |
Windows Relay Service
Detected by PCTools as the DELFINJECT.F TROJAN! See here |
 |
irfnga.exe |
Windows Relay Service
Detected by Trend Micro as the DROPPER.ACO TROJAN! See here |
 |
initsvc.exe |
Windows Service Manager
Added by the RBOT-BWT WORM! |
 |
iexplore.exe |
Windows Services
Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iexplore.exe |
WINDOWS SYSTEM CLEANER
Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
internat.exe |
Windows Taskbar Manager
Added by the PROTORIDE-H WORM! |
 |
iexplorer.exe |
Windows Taskmanager
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
installer.exe |
Windows UDP Control Center
Added by a variant of the IRCBOT BACKDOOR! |
 |
iexplorere.exe |
Windows Update
Added by the GAOBOT.AP WORM! |
 |
inetinf.exe |
Windows Update
Added by a variant of the AGOBOT/GAOBOT WORM! |
 |
install.exe |
Windows Update
Added by the BANKER-IB TROJAN! |
 |
iexplorerrs.exe |
Windows Updater
Added by the RBOT-TN WORM! |
 |
iexplore.exe |
Windows USB Control Driver
Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
iexplore.exe |
WindowsUpdate renew
Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
 |
iexplorer.exe |
winnt DNS ident
Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexpiore.exe |
winprofile
Added by a variant of the MONCHER WORM! |
 |
iexpIore.exe |
WinProfile
Added by the CHUM-C TROJAN! |
 |
ieservicesupd.exe |
Winsock6 MIC driver
Added by the SPYBOT.AFZ WORM! |
 |
iexplor.exe |
winsockdriver
Added by the BLATIC.A WORM! |
 |
iexplorer.exe |
WINTASK
Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
iexplorer.exe |
WinVNC
Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
 |
intspnsr32.exe |
WinXP Processor Generator v1.2
Added by the SDBOT.LP WORM! |
 |
INISvc.exe |
Win_Library
Added by the ANARCH WORM! |
 |
iglmtray.exe |
WUPD
Added by the TZET WORM! |
 |
InvokeSvc3.exe |
WUSB54GS
Linksys Wireless-G USB Wireless Network Monitor |
 |
InvokeSvc3.exe |
WUSB54Gv2
Wireless-G USB Wireless Network Adapter related - would appear to be required |
 |
iTouch.exe |
zBrowser Launcher
For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them |
 |
IMGICON.EXE |
ZipDisk Icons
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
 |
iexplore.exe |
Zonealarm
Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
 |
iservice.exe |
zsmsgs
Added by the BANCOS-BU TROJAN! |
 |
iexpl0ra.exe |
[random name]
Added by the ULPM.BD TROJAN! |
 |
Install.exe |
[trojan filename]
Added by the BANCBAN-FS TROJAN! |
 |
iehelper.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
iesetupdll.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
init32.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
InpriseMon.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |
 |
install2.exe |
[various names]
Wareout - malware masquerading as a spyware and dialer remover |