PC Review
Startup Files Database
Letter i
Powered By Pac's Startup list
Startup Files Database
Letter i
Startup Files Database
[#] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X] [Y] [Z]
Yes |
No |
Users Choice |
Warning |
Unknown |
| Normally leave to run at startup | Not Required, often infrequently run tasks that can be run manually. | Depends if the task is deemed necessary | Typically viruses, spyware, adware and resource hogs | An unknown item |
| Required | Process Name / Details | Startup File |
![]() |
Added by an unidentified WORM or TROJAN! |
msyervice.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
winsys.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
disney.exe |
![]() |
Added by the GINK WORM! |
uGiG.eXe |
![]() |
Added by the TIBIK-B TROJAN! |
svcnet.exe |
![]() |
Added by the MYPOWER WORM! |
I386.exe |
![]() |
Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard |
I81SHELL.exe |
![]() |
Graphical interface for fan speed control |
i8kfangui.exe |
![]() |
IAA Event Monitor User Notification Tool - part of Intel(r) Application Accelerator - "a performance software package for desktop PCs using select Intel(r) chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed |
iaanotif.exe |
![]() |
AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well |
iamapp.exe |
![]() |
Added by the RANDEX.Y WORM! |
XBox64.exe |
![]() |
Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely? |
iap.exe |
![]() |
InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself! |
ias.exe |
![]() |
Added by the OPASERV.T WORM! |
IASHLPR.EXE |
![]() |
Added by the PERDA-C TROJAN! |
[path to trojan] |
![]() |
Added by the LEGMIR-AH TROJAN! |
ibm.exe |
![]() |
IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire? |
ERTS0749.exe |
![]() |
Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport" |
ibmmessages.exe |
![]() |
?? |
Ibmmon.exe |
![]() |
Power management driver for IBM laptops. Provides support for the use of four keys on the thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standy or hibernate modes |
ibmpmsvc.exe |
![]() |
IBM application - what does it do and is it required? |
ibmprc.exe |
![]() |
Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops |
IBMBAY2N.EXE |
![]() |
Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound? |
IBMBAYSN.EXE |
![]() |
IBM Password Manager |
pwmgr.exe |
![]() |
Added by the HIDEDIAL-B TROJAN! |
ibs.exe |
![]() |
IBackup for Windows |
IBackground.exe |
![]() |
IBackup for Windows |
IBMonitor.exe |
![]() |
Related to Citrix MetaFrame |
icabar.exe |
![]() |
Browser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN! |
icasServ.exe |
![]() |
Added by the ICcontrol premium rate adult content dialer |
iccontrol.exe |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] icdd7ee6.dll, EnableRunDLL32 |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] icddefff.dll, EnableRunDLL32 |
![]() |
Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices |
eusexe.exe |
![]() |
Added by the SDBOT.ZZH WORM! |
yujixit.exe |
![]() |
IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy" |
iClean.exe |
![]() |
Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
ICM.EXE |
![]() |
iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same name |
NAG.EXE |
![]() |
Found on Sony Vaio and IBM Thinkpad (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
ICO.EXE |
![]() |
Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons |
HDE.EXE |
![]() |
Audio desktop customization utility from Moon Valley Software. Resource hog |
hearit95.exe |
![]() |
Audio desktop customization utility from Moon Valley Software. Resource hog |
hearit98.exe |
![]() |
RapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
icon.exe |
![]() |
RapidBlaster variant (in a "Icon" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
icon.exe |
![]() |
Related to the Vista Customization Pack |
icon.bat |
![]() |
APC PowerChute Tray Icon. Associated with the UPS listing |
iconclnt.exe |
![]() |
Small utility which will allow you the option of hiding or showing your desktop icons |
ICONDESK.EXE |
![]() |
Icon for LS-120 "Superdisk" |
Iconfig.exe |
![]() |
Added by the GAOBOT.AO WORM! |
DIIhost.exe |
![]() |
Iconoid is a desktop icon manager |
Iconoid.exe |
![]() |
IconSaver is a desktop icon manager |
Iconsaver.exe |
![]() |
Added by the GORMLEZ-A WORM! |
ICQNET.vbs |
![]() |
Added by the AGENT-FZJ TROJAN! |
icq6.exe |
![]() |
Added by the RANDIN WORM! |
[path to worm] |
![]() |
Added by a variant of the RBOT WORM! |
icqjdhs.exe |
![]() |
Added by a variant of the NETSPY TROJAN! |
ICQpro.exe |
![]() |
ICQ Lite - compact version of the popular messaging program |
ICQLite.exe |
![]() |
Added by the AGENT-DSF TROJAN! |
scvhost.exe |
![]() |
Added by the IRCBOT-TJ TROJAN! |
winlog.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program Files, this particular impostor is located in the Windows or WinntSystem32 directory |
[random filename] |
![]() |
Added by the SDBOT-ABL WORM! |
ICQ2002.exe |
![]() |
Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup! |
winlogon.exe |
![]() |
ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs |
vplus.exe |
![]() |
Added by an unidentified TROJAN! |
webcamupdate.exe |
![]() |
Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup and is always located in the System32 folder. This file is placed in the Windows or Winnt folder |
winlogon.exe |
![]() |
Added by the RBOT-AVC WORM! |
av32.pif |
![]() |
Added by the RBOT-AYO WORM! |
plscx.exe |
![]() |
Added by the RBOT-AYP WORM! |
zvslmqb.exe |
![]() |
Added by the SDBOT-AER WORM! |
poker3.exe |
![]() |
Added by the RBOT-AYN WORM! |
avpx.exe |
![]() |
Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines |
rundll32.exe Icsdclt.dll, ICSClient |
![]() |
Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations |
Icserver.exe |
![]() |
Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers |
ICSMGR.EXE |
![]() |
Added by the ILLNOTIFIER.D TROJAN! |
Service32.exe |
![]() |
Instant Chess related |
spvic.exe |
![]() |
Caller ID utility for identifying incoming telephone numbers |
IDCom.exe |
![]() |
Added by the ID8525.A TROJAN! |
ID8525.exe |
![]() |
Added by the ID8525.A TROJAN! |
id85255.exe |
![]() |
HP related - in a Program FilesHewlett-PackardPC COE folder |
IDA.EXE |
![]() |
Added by the ASSASIN.F TROJAN! |
ide.exe |
![]() |
Added by the XILON TROJAN! Related to the game "Diablo II" |
IDElibr32.exe |
![]() |
Added by a variant of the CRYPTER.C TROJAN! |
idecntl.exe |
![]() |
Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse |
idesktop.exe |
![]() |
Internet Download Manager - download files faster, schedule and resume |
IDMan.exe |
![]() |
Added by a variant of the SLAPER TROJAN! |
[random filename] |
![]() |
Added by the BRONTOK-H WORM! |
IDTemplate.exe |
![]() |
Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems |
idwlog.exe |
![]() |
Added by the LINEAGE-C TROJAN! Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually! |
explorer.exe |
![]() |
IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" |
IEDoctor.exe |
![]() |
Added by the AGENT-HD TROJAN! |
iejava.exe |
![]() |
Topconverting.com180Search "IEMenuExtension" toolbar |
rundll32.exe [path] tbextn.dll DllShowTB |
![]() |
IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows |
iemaximizer.exe |
![]() |
Added by the PICRATE.B WORM! |
wini.exe |
![]() |
Added by the RBOT-ADZ TROJAN! |
winis.exe |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
IE**.exe [* = random char] |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
IE**32.exe [* = random char] |
![]() |
DesktopMedia adware |
iebar.exe |
![]() |
Added by a variant of the SDBOT WORM! |
wkstmg.exe |
![]() |
Added by the GAOBOT.DXO WORM! |
ssmss.exe |
![]() |
Added by the RBOT-ATF WORM! |
porn.pif |
![]() |
Added by the RBOT-GOV WORM! |
winsnt.exe |
![]() |
AsdPlug premium rate adult content dialer variant |
temp532.exe |
![]() |
IEAccess premium rate adult content dialer variant |
surfya.exe |
![]() |
Added by the BOMKA TROJAN! |
iewatch.exe |
![]() |
Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 |
iecheck.exe |
![]() |
Added by the TIRBOT-D WORM! |
MSDTCs.exe |
![]() |
Added by the TIRBOT-E WORM! |
xpssl.exe |
![]() |
Added by the TIRBOT-G WORM! |
mssvp.exe |
![]() |
IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup |
Ieboot6.exe |
![]() |
Homepage hijacker, redirecting to coolwwwsearch.com |
iedll.exe |
![]() |
Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze |
IEDriver.exe |
![]() |
IEDriver adware variant |
xplore.exe |
![]() |
IEDriver adware variant |
TD.exe |
![]() |
Added by the DLOADR-BBW TROJAN! |
iedwa104.exe |
![]() |
STARTPAG.AI hijacker |
IEeng.exe |
![]() |
Added by the RBOT-GRE WORM! |
IEexplore32.exe |
![]() |
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
IEFeatures.exe |
![]() |
Added by the POPMON.A TROJAN! - also known as PopMonster adware |
Internetfeatures.exe |
![]() |
Added by the RILER-H TROJAN! |
IefxTray.exe |
![]() |
Added by the BANKER-HH TROJAN! |
ieharv.exe |
![]() |
Outwar adware downloader |
syslaunch.exe |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] iel2cde8.dll, EnableRunDLL32 |
![]() |
LZIO.com adware downloader |
rundll32.exe [path] ielcaabe.dll, EnableRunDLL32 |
![]() |
Added by the SPEX or SPEX.B WORMS! |
iexplore32.exe |
![]() |
Browser hijacker - redirecting to an adult web page |
Iesar.exe |
![]() |
LookNSearch adware |
Iesearch.exe |
![]() |
Added by the PWS-BLUEDIT TROJAN! |
IExplorer.dll |
![]() |
Added by the NEMOG.C TROJAN! |
iexp1orer.exe |
![]() |
IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc |
ietsr.exe |
![]() |
Added by the ASOXY TROJAN! |
MCP****.exe [**** = random char] |
![]() |
Adware downloader trojan |
mcpdll32.exe |
![]() |
Added by the AGOBOT-QL WORM! Note the filename has a "0" rather than an upper case "o" |
IEXPL0RER.EXE |
![]() |
Added by the RBOT.AEX WORM! Note - this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot |
iexpl0res.exe |
![]() |
Added by the IRCBOT.BT TROJAN! |
svshosts.exe |
![]() |
Added by the INKER.B WORM! |
Iexploit.html |
![]() |
Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
iexplore.exe |
![]() |
Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
iexplore.exe |
![]() |
Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in a "Custom" subfolder |
IEXPLORE.EXE |
![]() |
Added by the DLOADR-AAM TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the "Arquivos de programasInternet ExplorerCustom" folder |
IEXPLORE.exe |
![]() |
Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
IEXPLORE.EXE |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! |
iexplore.exe |
![]() |
Added by the BANCOS-CJ TROJAN! |
[path to trojan] |
![]() |
Added by the BIFROSE-C TROJAN! |
goot.exe |
![]() |
Added by the BDOOR-BY TROJAN! |
Iexplor32.exe |
![]() |
Added by the BANCOS-CH TROJAN! |
IExplorer.EXE |
![]() |
Added by the JU or BANCBAN-IP TROJANS! |
msiecfg.exe |
![]() |
Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder |
explorer.exe |
![]() |
RapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
iexplorer.exe |
![]() |
RapidBlaster variant (in a "iexplorer" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
iexplorer.exe |
![]() |
Added by the BANCBAN-EN TROJAN! |
Iexplorer.exe |
![]() |
Added by the RBOT.ABO WORM! |
IExplore32b.exe |
![]() |
Added by the RBOT.ABN WORM! |
IExplore32cb.exe |
![]() |
Added by a variant of the SDBOT WORM! |
IExplore326.exe |
![]() |
Added by a variant of the SDBOT WORM! |
IExplore327.exe |
![]() |
Added by the CLAGGER-AG TROJAN! |
ipf.exe |
![]() |
Added by a variant of the SLAPER TROJAN! |
[random filename] |
![]() |
I-FORCE driver for force feedback steering wheel |
IFSplash.exe |
![]() |
Added by the SDBOT.AQ TROJAN! |
ekor.exe |
![]() |
Added by the IRCBOT.R WORM! |
atecaca.exe |
![]() |
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel |
igfxtray.exe |
![]() |
?? |
Iglpbv.exe |
![]() |
IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin, hence Internet Explorer must be installed beforehand and downloads has to be initialized through that browser |
DLM.exe |
![]() |
NewDial premium rate adult content dialler |
igsex2x.exe |
![]() |
Drive Letter Searcher, iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time? |
iHPDetect.exe |
![]() |
Homepage hijacker |
IILC.EXE |
![]() |
PurityScan/Clickspring adware |
iptl.exe |
![]() |
Added by an unidentified TROJAN or adware |
iisvers.exe |
![]() |
Added by the AGENT-EOF TROJAN! |
uzcx.exe |
![]() |
System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis |
Systemwiper.exe |
![]() |
Printer utility which is required in order to make the printer work correctly |
IJ75P2PS.EXE |
![]() |
Associated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything |
IKEService.exe |
![]() |
A4Tech wireless keyboard driver and utility |
IKEYMAIN.EXE |
![]() |
IKL surveillance software. Uninstall this software unless you put it there yourself |
rundll32.exe [path] IKL.dll |
![]() |
Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename |
Mplayer.exe |
![]() |
Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename |
Mplayer.exe |
![]() |
Intense Educational Ltd - Language Office Software. Is it required? |
IntEdReg.exe /OFFMAN |
![]() |
iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button |
iLyric.exe |
![]() |
Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner |
iM_Tray.exe |
![]() |
CoolWebSearch parasite variant |
rundll32 image.dll, Install |
![]() |
Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run |
IMAGE32.exe |
![]() |
Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually |
SonyTray.exe |
![]() |
Nero ImageDrive from Ahead - virtual CD/DVD drive software |
ImageDrive.exe |
![]() |
ImageFox 2.0 (formerly available from ACDSee) is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes |
imagefox.exe |
![]() |
Added by the GEMA TROJAN! |
Imagemgt32.exe |
![]() |
Added by the SDBOT-XB WORM! |
taskbarmngr.exe |
![]() |
Added by the DOWNDEL-A TROJAN! |
load.exe |
![]() |
Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs |
iUtil.exe |
![]() |
Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive |
imation.exe |
![]() |
Added by an unidentified WORM or TROJAN! |
Svhosl.exe |
![]() |
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
imekrig.exe |
![]() |
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
IMEKRMIG.EXE |
![]() |
Imesh is a file sharing system |
?? |
![]() |
Update check for the Imesh file sharing system. Turn the update off under "options" |
?? |
![]() |
Added by the KEYLOG-AR TROJAN! |
IMEvtMgr.exe |
![]() |
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
ImgIcon.exe |
![]() |
Added by the BANKER-EM TROJAN! |
[path to file] |
![]() |
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
ImgStart.exe |
![]() |
Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese). *.* represents the version number |
IMJPMIG.EXE |
![]() |
Related to I-FORCE driver for force feedback steering wheel? |
immcheck.exe |
![]() |
Added by the WEBDOR.AK TROJAN! |
timed.exe |
![]() |
IncrediMail for Office Outlook Add-On |
IMOLApp.exe |
![]() |
McAfee QuickClean 3.0 - removes internet clutter and unwanted programs |
Plguni.exe |
![]() |
Added by the IMONI-A TROJAN! |
[path to trojan] |
![]() |
System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards |
imontray.exe |
![]() |
IMNames adware |
IM-svr.EXE |
![]() |
InterMute security software related |
IMStart.exe |
![]() |
Added by the SLAPER.E TROJAN! |
acpmonsrv.exe |
![]() |
SafeSurfing adware variant |
imwireup.exe |
![]() |
Added by the IMAV.A WORM! |
im_1.exe |
![]() |
Added by the BAGLEDL-BO TROJAN! |
im_2.exe |
![]() |
Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3), it does not need to start with Windows. You can run InCD.exe manually before inserting an appropriately formatted CD-RW (CD-MRW) disk. For Nero 6.0, 6.3 or 6.6 (InCD4), it does need to start with Windows. It does not function correctly when you try to run it manually, and you will not have write access to MRW (Mount Rainier) formatted CD-RW (CD-MRW) or DVD-MRW disks. To regain write access and other features, InCD 4 must start with Windows |
incd.exe |
![]() |
IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality |
IncMail.exe |
![]() |
For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs |
DMHKEY.EXE |
![]() |
IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality |
incredimail.exe |
![]() |
IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality |
IncMail.exe |
![]() |
Added by the AGOBOT.CH WORM! |
dllhost32.exe |
![]() |
Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
WashIdx.exe |
![]() |
Added by the LAZAR TROJAN! |
Indexindicator.exe |
![]() |
Associated with PaperPort scanner software from ScanSoft |
IndexSearch.exe |
![]() |
Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
IndexTray.exe |
![]() |
Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed |
IndicatorUty.exe |
![]() |
Added by the RBOT.BNL WORM! |
svchosts.exe |
![]() |
Added by the QEDS WORM! |
Inetdbs.exe |
![]() |
Inet Delivery adware |
inetdl.exe |
![]() |
Inet Delivery adware |
inetdl_2.exe |
![]() |
Added by the NETDEVIL.14 TROJAN! |
Netapi.exe |
![]() |
Bsafe Online - internet filter |
inetcntrl.exe |
![]() |
?? |
inetconf.exe |
![]() |
Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation |
INETD32.EXE |
![]() |
Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) |
inetinfo.exe |
![]() |
Added by the DONBOMB.A TROJAN! |
inetinfomon.exe |
![]() |
Actual Names (AdvSearch) Internet Keywords parasite |
inetmgr.exe |
![]() |
Added by a variant of the SDBOT TROJAN! |
msnet.exe |
![]() |
Added by the WOCK32-A TROJAN! |
wsock32.exe |
![]() |
Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A |
wmplayer.exe |
![]() |
Info Select from Micro Logic - personal information manager |
is.exe |
![]() |
Added by the GEMA TROJAN! |
Info32x.exe |
![]() |
Added by the VUNDO TROJAN! |
rundll32.exe [path] ********.dll [* = random char] |
![]() |
InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand |
InfoPenIM.exe |
![]() |
Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed? |
Infoplay.exe |
![]() |
Detected by Kaspersky as the CENTIM.CH TROJAN! |
iu.exe |
![]() |
System Tray access to infra-red devices. Not required unless you use infra-red devices |
IRMON.EXE |
![]() |
Adult content dialler |
infus.exe |
![]() |
Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities" |
Infuzer.exe |
![]() |
VX2.Transponder parasite updater/installer related |
infwin.exe |
![]() |
Added by the WINEX.A TROJAN! |
Init32.exe |
![]() |
EasySearch browser hijack installer |
install.exe |
![]() |
Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay |
8x8_init.exe |
![]() |
Added by the BINJO TROJAN! |
injobs.exe |
![]() |
Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
InkMonitor.exe |
![]() |
Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
InkWatch.exe |
![]() |
Associated with eTrust Antivirus/InoculateIT |
InoRpc.exe |
![]() |
Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage |
InoRT9x.exe |
![]() |
Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates |
InoTask.exe |
![]() |
?? |
insCOA5.exe |
![]() |
Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly |
InstaAlert.exe |
![]() |
InstaFinder adware |
InstaFinderK inst.exe |
![]() |
Added by the BANCBAN-HG TROJAN! |
Install.exe |
![]() |
Added by the RELFEERWORM! |
updates.exe |
![]() |
Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required? |
sifxinst.exe |
![]() |
Used to initialize the Aureal A3D demos InstallShield wizard |
InstallAurealDemos.js |
![]() |
InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync |
Ibtna.exe |
![]() |
Added by the ANYHOMB.F TROJAN! |
InstallCleaner.exe |
![]() |
Added by a variant of the LOVGATE WORM! |
Office.exe... |
![]() |
Malware - detected by Kaspersky as the AGENT.MM TROJAN! |
dial.exe |
![]() |
Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error? |
SETUP.EXE |
![]() |
WinAntiVirus Pro 2007 and Privacy Protector misleading security software - not recommended, see here |
newsoftware2007install.exe |
![]() |
Added by a variant of the RANDON.AN WORM! |
[path] repcale.exe [path] palsp.exe |
![]() |
Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone |
installstub.exe |
![]() |
Added by the Alasrou-A WORM! |
[path to worm] |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe EGDHTML_1023.dll, InstantAccess |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe eg_auth_****.dll, InstantAccess [**** = digits] |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe EGCOMLIB_****.dll, InstantAccess [**** = digits] |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe EGCOMSERVICE_****.dll, InstantAccess [**** = digits] |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe EGDACCESS_****.dll, InstantAccess [**** = digits] |
![]() |
Electronic_Group/InstantAccess premium rate adult content dialer variant |
rundll32.exe p2esocks_****.dll, InstantAccess [**** = digits] |
![]() |
InstantAccess premium rate adult content dialer |
mwsrvacc.exe |
![]() |
InstantAccess premium rate adult content dialer variant |
linewsrv.exe |
![]() |
Instant Buzz adware |
IBDaemon.exe |
![]() |
From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner |
reminder.exe |
![]() |
Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
WUSB11cfg.exe |
![]() |
Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration |
WPC11Cfg.exe |
![]() |
From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs |
INSTAN~1.EXE |
![]() |
Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software |
InstantDrive.exe |
![]() |
Adult content dialler |
instantpleasure.exe |
![]() |
Adult content dialler |
instantpleasurexxx.exe |
![]() |
Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually |
PCLETray.exe |
![]() |
Added by the OPASERV.H WORM! |
instit.bat |
![]() |
Added by the OPASERV.K WORM! |
INSTIT.BAT |
![]() |
?? |
InstUtlR.exe |
![]() |
SafeSurfing adware variant |
idctup20.exe |
![]() |
Added by the SDBOT-ADN WORM! |
msmsgrs.exe |
![]() |
Added by the RBOT-GLU WORM! |
[path to worm] |
![]() |
Added by a variant of the SDBOT WORM! |
winrvc.exe |
![]() |
System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards |
imontray.exe |
![]() |
Detected by VBA32 as the BIFROSE.ADR TROJAN! |
fmideploy.exe |
![]() |
Added by a variant of the SDBOT WORM! |
csrs.exe |
![]() |
Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients |
xfr.exe |
![]() |
Intel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled |
pds.exe |
![]() |
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
IntelProcNumUtility.exe |
![]() |
System Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features |
promon.exe |
![]() |
Added by the MSCONFIG16 TROJAN! |
msconfig16.exe |
![]() |
Added by the SPYRE-H TROJAN! |
hookdump.exe |
![]() |
Added by the SPYRE-C TROJAN! |
winnook.exe |
![]() |
Added by the AGENT-EBT TROJAN! |
svehost.exe |
![]() |
Added by the RBOT.QGA WORM! |
iis.exe |
![]() |
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have "HotKey" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel |
hkcmd.exe |
![]() |
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Not known exactly what it does but apparently it isn't required |
igfxpers.exe |
![]() |
Added by the SmitFraud alias SPYJACK-B TROJAN! |
intel32.exe |
![]() |
LANDesk Management Suite software component |
amclient.exe |
![]() |
Intel Audio Studio combines Intel(r) High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience. Audio utility supplied with Intel motherboards |
IntelAudioStudio.exe |
![]() |
Advertisingvision adware! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder |
smss.exe |
![]() |
Added by the SmitFraud alias Desktophijack.C TROJAN! |
intell32.exe |
![]() |
Added by the SPYJACK-B TROJAN! |
intell321.exe |
![]() |
Added by the Intelliflag SPYWARE! |
Intelliflag_be.exe |
![]() |
Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features |
point32.exe |
![]() |
For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings unless you have changed them |
type32.exe |
![]() |
Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line |
IntelMEM.exe |
![]() |
Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
cpunumber.exe |
![]() |
Associated with the Intel PRO/Set Wireless software |
ifrmewrk.exe |
![]() |
Zero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabled |
ZCfgSvc.exe |
![]() |
Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel |
igfxtray.exe |
![]() |
Intense Educational Ltd - Language Office Software. Is it required? |
IntEdReg.exe /CHECK |
![]() |
Added by the ANACON-B WORM! |
[path to worm] |
![]() |
Part of Sophos ant-virus sofware |
Icmon.exe |
![]() |
Part of Sophos anti-virus sofware |
ICMON.EXE |
![]() |
Added by the DELF family of TROJANS! |
Interdll.exe |
![]() |
Added by the SMOTHER and TRANSLAT TROJANS! |
[trojan filename] |
![]() |
Added by the FORTNIGHT.D TROJAN! |
regedit.exe /s %windir%c:[month number] |
![]() |
Added by the RBOT-GKT WORM! |
sysintmemory.exe |
![]() |
Added by a variant of the OPTIX TROJAN! Note - unlike the valid KaZaA executable, this is located in C:WindowsSystem (Win9x/Me), C:WinntSystem32 (WinNT/2K), or C:WindowsSystem32 (WinXP) |
Kazza.exe |
![]() |
Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:Windows or C:Winnt) whereas this version resides in %windir% |
internat.exe |
![]() |
Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
systray.exe |
![]() |
Added by the NYRUBOT-A WORM! |
msgsrv32.exe |
![]() |
Added by the CMJSPY-Y TROJAN! |
[trojan filename] |
![]() |
Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
bootconf.exe |
![]() |
Microsoft language selection icon in system tray, located in the System (Win98/Me) or System32 (WinNT/2K/XP) folder |
internat.exe |
![]() |
Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:Windows or C:Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon |
internat.exe |
![]() |
Added by the GRAYBIRD.F TROJAN! |
WinSocks5.exe |
![]() |
Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
smss.exe |
![]() |
Added by the PWS-CS TROJAN! |
Internet.exe |
![]() |
Added by the RBOT-AJG WORM! |
recruit.exe |
![]() |
Added by the MIFENG-D TROJAN! |
[trojan filename].exe |
![]() |
Added by a variant of the SDBOT WORM! |
winlogom.exe |
![]() |
Added by the RBOT-GFJ WORM! |
nteusodp.exe |
![]() |
Added by a variant of the SDBOT WORM! |
winsas32.exe |
![]() |
Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup! |
lsass.exe |
![]() |
From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
IAMNET~1.EXE |
![]() |
From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
IAM.exe |
![]() |
Added by the IRCBOT-WK TROJAN! |
expIorer.exe |
![]() |
Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
ICM.EXE |
![]() |
Added by the SDBOT TROJAN! |
svchosts.exe |
![]() |
EasySearch adware |
stisvsq.exe |
![]() |
Added by the SMUTSRCH-A TROJAN! |
[path to trojan] |
![]() |
Added by the DLOADR-AWD TROJAN! |
stisvsq1.exe |
![]() |
Added by the RBOT-UD WORM! |
ICP.EXE |
![]() |
Internet Download Accelerator download manager |
ida.exe |
![]() |
Added by the RBOT-BMS WORM! |
idman.exe |
![]() |
Added by the EVIAN.C WORM! |
urlmon32.dll.exe |
![]() |
Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
lEXPLORE.EXE |
![]() |
Added by the LORSIS WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key |
iexplorer.exe |
![]() |
Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
IEXPLORE.EXE |
![]() |
Added by the NETHIEF-O TROJAN! |
IExplorer.exe |
![]() |
Added as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed |
http.exe |
![]() |
Added by the RBOT-AZC WORM! |
iexpiore.exe |
![]() |
Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup unless you add it manually! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
IEXPLORE.EXE |
![]() |
Added by the RBOT-ALQ WORM! |
iexplore.pif |
![]() |
Added by the DOWNLOAD TROJAN! |
lexbac.exe |
![]() |
Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
iexplorer.exe |
![]() |
Internet History Eraser - deletes your browsing tracks |
HERASER.exe |
![]() |
Added by the KWBOT.B WORM! |
MSInstall61.exe |
![]() |
EasySearch adware |
msqdevl.exe |
![]() |
Added by the SMUTSRCH-A TROJAN! |
[path to trojan] |
![]() |
Added by the DLOADR-AWD TROJAN! |
msqdevl1.exe |
![]() |
Internet connection optimizer. Leave this enabled if you find it improves your connection |
optimize.exe |
![]() |
Internet Optimizer parasite, MoneyTree variant - ActiveX control used to download premium-rate dialers |
optimize.exe |
![]() |
Added by the RBOT-GFP WORM! |
msq32.exe |
![]() |
Added by the RBOT-GQL WORM! |
msq23.exe |
![]() |
Added by the RBOT-GML WORM! |
msql23.exe |
![]() |
Unidentfied adware |
More log.exe |
![]() |
Added by the STARTPA-EM TROJAN! |
inetsrv.exe |
![]() |
Added by the SPYBOT-DE WORM! |
intersvc.exe |
![]() |
Added by the RBOT-QS WORM! |
syscfg32.exe |
![]() |
Added by a variant of the RBOT WORM! |
ssvhost.exe |
![]() |
Added by the RBOT.EAT WORM! |
svho0st98.exe |
![]() |
Added by the SDBOT-PW WORM! |
systemdev.exe |
![]() |
Added by the MYTOB.BT WORM! |
internet.exe |
![]() |
Added by the RBOT.BNT WORM! |
interserv.exe |
![]() |
Added by the MYTOB.MN WORM! |
Netsvc.exe |
![]() |
Added by the KWBOT.Z WORM! |
winz32.exe |
![]() |
Intel AnyPoint internet sharing software. Now discontinued |
iss_srvr.exe |
![]() |
Added by the WOOTBOT.HV WORM! |
story.exe |
![]() |
Internet Sweeper - removes unnecessart left over files after browsing the internet |
Sweeper.exe |
![]() |
Shareware dial-up connection call cost calculator from Ratsoft |
ITIMER.exe |
![]() |
Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
iw.exe |
![]() |
Added by the MAGICCALL VIRUS! |
Internet.exe |
![]() |
Added by the YINI MACRO! |
yinyin3345.vbs |
![]() |
Added by a variant of the RBOT WORM! |
wkfix.exe |
![]() |
Added by the SDBOT-CZP WORM! |
windows.exe |
![]() |
Added by the RBOT-GRA WORM! |
iexplore32.exe |
![]() |
InternetShield misleading security software - not recommended, see here |
INTERN~1.EXE |
![]() |
Internet Spy - freeware keylogger that tracks all visited websites including the date and exact time these sites were visited. The information is stored in a file that may be accessed by the person who knows where it is saved. Remove unless you installed it yourself! |
InternetSpy.exe |
![]() |
Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003 |
iw.exe |
![]() |
Added by the SDBOT.Q TROJAN! |
winz32.exe |
![]() |
Australian ISP's free monthly download meter |
mum.exe |
![]() |
Added by the PEEPER or CARUFAX.A TROJANS! |
Internt.exe |
![]() |
Added by the AGOBOT-NW WORM! |
intersoftmsngr.exe |
![]() |
InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business |
it_cpq~1.exe |
![]() |
Added by the IRCINTER.A TROJAN! |
WINDRV.EXE |
![]() |
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
WinCinemaMgr.exe |
![]() |
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
WINCIN~1.EXE |
![]() |
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
WinCinemaMgr.exe |
![]() |
WinCinema Manager is needed when using the WinDVD Remote Control for WinDVD from Intervideo. Available via Start -> Programs |
WINCIN~1.EXE |
![]() |
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
WinScheduler.exe |
![]() |
WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
SchSvr.exe |
![]() |
InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs |
interwarn.exe |
![]() |
Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer iexplore.exe process which is always located in the Program FilesInternet Explorer folder and should not normally figure in Msconfig/Startup! This file is located in the System (9x/Me) or System32 (NT/2K/XP) folder |
IEXPLORE.exe |
![]() |
Added by the GEMA TROJAN! |
Intmgr.exe |
![]() |
Added by the SPYBOT-DW WORM! |
SYS32CFG.EXE |
![]() |
Added by the CHIMOZ.AC TROJAN! |
intranet.exe |
![]() |
Added by the LEMIR.E TROJAN! |
Intrenat.exe |
![]() |
MS Media Manager tour. Not required |
SPLASHA.EXE |
![]() |
For Compaq PC's. Should only run first time, PC Introduction & Compaq registration |
?? |
![]() |
Intruder Alert '99 from Bonzi - spyware |
ia99.exe |
![]() |
Added by the BANLOA-ASE TROJAN! |
[path to trojan] |
![]() |
LANDesk Management_Suite software component |
LDISCN32.EXE |
![]() |
Added by the HAWAWI WORM! |
Media Player.exe |
![]() |
iobi Home - a mail/voice service by Verizon |
iobiClient.exe |
![]() |
iolo AntiVirus |
ioloAV.exe |
![]() |
Iolo System Mechanic Task Agent. Scheduled maintenance |
Task_Agent.exe |
![]() |
Iolo System Mechanic Utility Bar - can be launched manually |
SMUtilityBar.exe |
![]() |
Part of Iolo System Mechanic. Used to delay the start of an application which loads automatically as Windows loads |
delay.exe |
![]() |
Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
ibackup.exe |
![]() |
Iomega Automatic Backup - automatic backups for use with Iomega portable HDD |
ibackup.exe |
![]() |
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
dtiom98.exe |
![]() |
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
IMGICON.EXE |
![]() |
Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running |
IMGICON.EXE |
![]() |
Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks |
imiconxp.exe |
![]() |
?? |
Quicksync.exe |
![]() |
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
IMGSTART.EXE |
![]() |
Used by Iomega drives. Available via Start -> Programs |
IOWATCH.EXE |
![]() |
Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs |
COMMANDER.EXE |
![]() |
PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang |
Iomon98.exe |
![]() |
Added by the FORBOT.SM WORM! |
ipredirect.exe |
![]() |
Added by the AGOBOT.CW WORM! |
ipstack.exe |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
IP**.exe [* = random char] |
![]() |
CoolWebSearch/HomeSearch adware - for examples, see this log |
IP**32.exe [* = random char] |
![]() |
Installed with a Panasonic iPalm digital camera. Used to upload photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded |
mon.exe |
![]() |
Added by the RBOT-AEG WORM! |
ipcconn.exe |
![]() |
Added by the SDBOT-ZC WORM! |
wnmgre.exe |
![]() |
Added by the SDBOT-BLU WORM! |
winspec.exe |
![]() |
Adware - detected by McAfee as a variant of the ADCLICKER-BM TROJAN! |
ipcfg.exe |
![]() |
Added by the HACARMY.E TROJAN! |
svcxnv32.exe |
![]() |
Added by a variant of the HACARMY.E TROJAN! |
svcxnw32.exe |
![]() |
Added by an unidentified VIRUS, WORM or TROJAN! |
ipcon32.exe |
![]() |
Added by the DLOADER-YF TROJAN! |
ipwf.exe |
![]() |
AOL related. What does it do and is it required? |
IPHSend.exe |
![]() |
Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. This one constantly "phones home" and wastes resources. * represents 1 or 2 |
ipclient.exe |
![]() |
Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information. * represents 1 or 2 |
ipmon32.exe |
![]() |
For Gilat Communications internet satellite systems. Gilat rescue (Satellite system restore). Required if you have this system. Can cause a BSOD (blue screen of death) if left out |
N/A |
![]() |
Related to iriver portable media products. What does it do and is it required? |
iAgent2.exe |
![]() |
Added by the RECERV or R3C.B TROJANS! |
ipmon.exe |
![]() |
Maxifiles adware |
ipnetwork.exe |
![]() |
Added by the INKER.B WORM! |
Ipnuker.vbs |
![]() |
IP Operator 2005 - found on LG Electronics Notebook. The applet makes network connections easier to view and manage than does the standard Windows Network Connections tool. The WLAN module is easy to turn on or off with the press of a single button |
IP Operator 2005.exe |
![]() |
Added by a variant of the RBOT WORM! |
IPODUSB.EXE |
![]() |
Added by a variant of the RBOT WORM! Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program FilesiPodbin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup! |
iPODService.exe |
![]() |
Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods |
iPodManager.exe |
![]() |
Associated with Apple's iPod MP3 player. Detects when the iPod is connected? |
iPodWatcher.exe |
![]() |
Added by a variant of the FUROOTKIT TROJAN! |
compaq.exe |
![]() |
Added by a variant of the FUROOTKIT TROJAN! |
compaq.exe |
![]() |
Added by the SDBOT-WA WORM! |
hpsebc087.exe |
![]() |
Added by the SDBOT-WH WORM! |
hpsebc08.exe |
![]() |
Part of Presto! Mr.Photo - "an ideal program for creating, sharing, and manag-ing digital images and videos" |
IPP4Detect.exe |
![]() |
Added by the ZAGABAN-H TROJAN! |
ipreg.exe |
![]() |
Novell(r) iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net |
iprntctl.exe |
![]() |
iProtectYou - internet filtering/parental control and network monitoring software |
ip.exe |
![]() |
iProtectYou spyware |
iPY.exe |
![]() |
Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
IPSECD~1.EXE |
![]() |
Cisco VPN Client - lets local users gain Administrator privileges on the operating system |
ipsecdialer.exe |
![]() |
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
IPSecMon.exe |
![]() |
Added by a variant of the RBOT WORM! |
Winipcfgs.exe |
![]() |
System Tray access to Intel Desktop Utilities - "provides you with the means to monitor system temperatures, voltages, fan speeds, and hard drive health; view detailed system information, and test your system hardware for common errors" |
iptray.exe |
![]() |
Added by the AGOBOT.TC WORM! |
csass.exe |
![]() |
Added by a variant of the SDBOT WORM! |
netstun.exe |
![]() |
Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone" |
IPW.exe |
![]() |
Related to Internet Phone Wizard from Actiontec - Voice over IP (VoIP) that allows you to "make and receive free Internet calls on your regular phone" whilst "at the same time, make and receive regular (landline) calls on your phone" |
usbipw.exe |
![]() |
Added by the SCHOEBERL TROJAN! |
ipwf.exe |
![]() |
IPWins adware |
ipwins.exe |
![]() |
Added by the WAREZOV.DG WORM! |
ipxwshel.exe |
![]() |
?? |
iqes.exe |
![]() |
Intel(r) Indeo(r) video 4.4 Decompression Filter related |
regsvr32.exe [path] Ir41_32.ax |
![]() |
IRASSync adware |
irasyncd.exe |
![]() |
Added by the SDBOT-ACE WORM! |
sessionmgr.exe |
![]() |
Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
IreIKE.exe |
![]() |
Iris Antivirus - discontinued, replace with good alternative |
winmon32.exe |
![]() |
Iris Antivirus - discontinued, replace with good alternative |
WIMMUN32.exe |
![]() |
Associated with the iRiver Music Manager |
MLService.exe |
![]() |
Updates for the iRiver Music Manager - used with their digital music players |
Updater.exe |
![]() |
System Tray access to infra-red devices. Not required unless you use infra-red devices |
IRMON.EXE |
![]() |
?? |
itcnmon.exe |
![]() |
SafeSurfing adware variant |
irssyncd.exe |
![]() |
Added by the BANCOS-AP TROJAN! |
[path to trojan] |
![]() |
Added by the BANKER-AN TROJAN! |
iexplorer.exe |
![]() |
Added by the BANCBAN-BO TROJAN! |
ftpmon.exe |
![]() |
Microsoft Infrared Transfer application |
IrXfer.exe |
![]() |
Added by the IRFTP TROJAN! |
ir_ftp.exe |
![]() |
Added by the BANCOS.H TROJAN! |
irwftp.exe |
![]() |
Norton Internet Security configuration wizard |
cfgwiz.exe |
![]() |
Added by the FUTRO TROJAN! |
Isass.exe |
![]() |
Related to Sony ISB Utility. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems |
ISBMgr.exe |
![]() |
Added by the LCPRANK-A WORM! |
iscch.exe |
![]() |
For Compaq PC's. May install properties in dial-up networking when you register with an ISP |
isdbdc.exe |
![]() |
Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product |
isDel.bat |
![]() |
Tray icon which gets installed when you install the drivers for Asuscom internal ISDN modem cards (or rebadged Asuscom ISDN cards, such as MRi). This icon enables you to monitor or configure your ISDN card. Once you have configured your ISDN card correctly, you will never need to use this icon |
Linksts.exe |
![]() |
FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks" |
IWatch.exe |
![]() |
ISpy is a security risk that logs keystrokes and captures screenshots. If you didn't install this yourself uninstall it |
help.exe |
![]() |
GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser |
iShield.exe |
![]() |
A process from Cisco Systems Inc associated with Windows Update for wireless NIC drivers |
ISLP2STA.EXE |
![]() |
ISMonitor adware |
ISMModule.exe |
![]() |
ISMonitor adware |
ISMModule2.exe |
![]() |
ISMonitor adware |
ISMModule3.exe |
![]() |
ISMonitor adware |
ISMModule4.exe |
![]() |
ISMonitor adware |
ISMPack5.exe |
![]() |
ISMonitor adware |
ISMPack6.exe |
![]() |
ISMonitor adware |
ISMPack7.exe |
![]() |
User interface for Slipstream - internet acceleration through compression/decompression techniques, intelligent cacheing on the server side, and real-time conversion of large/high-bandwidth images to less bulky pix. Used by popular ISPs such as IceNet, Wanadoo, Terra, OnSpeed, United Online and AOL Canada. Required if the user's account is locked in to that proxy server |
slipgui.exe |
![]() |
Added by the IRCFLOOD-O TROJAN! |
psycho.exe |
![]() |
iSpyNOW - remote monitoring and surveillance software |
ispynow.exe |
![]() |
Added by the GAGGLE.D or GAGGLE.E WORMS! |
Israfel.vbs |
![]() |
Related to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup |
ISPopup.exe |
![]() |
Added by a variant of the RBOT WORM! |
issEnc32.exe |
![]() |
Part of IBM Global Services - used internally by IBM for automatic updating of software and Microsoft patching |
issimsvc.exe |
![]() |
LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
ISStart.exe |
![]() |
Part of Norton Internet Security Suite |
ISSVC.exe |
![]() |
IBM Client Security Certification Tool |
certtool.exe |
![]() |
ISTBar adware |
istsvc.exe |
![]() |
ISTBar parasite related |
[random filename] |
![]() |
Unidentified adware downloader/installer |
istinstall zazzer.exe |
![]() |
InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version |
ISUSPM.exe |
![]() |
InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you're always working with the most current version |
issch.exe |
![]() |
Related to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite |
ISW.exe |
![]() |
Added by the SMALL-EIV TROJAN! |
isxa.exe |
![]() |
iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user |
iSysCleaner.exe |
![]() |
Added by the CHORUS-A TROJAN! Searchforfree browser hijacker |
isystem.exe |
![]() |
Added by a TROJAN! See here TROJAN! |
italfds.exe |
![]() |
In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it |
Itk.exe |
![]() |
Insert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert |
itk.exe |
![]() |
iTouch loads the iTouch configuration program for Logitech keyboards. It's needed if your keyboard has shortcut buttons and if you use them. It's also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock |
iTouch.exe |
![]() |
ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip |
ItsDeductible.exe |
![]() |
Added by the RBOT-ZU WORM! |
itune.exe |
![]() |
Added by the OSCABOT-L WORM! Note - this file will be placed in the WindowsSystem32 or WinntSystem32 folder, and should not be confused with the (legitimate) Apple iTunes process, always located in the Program FilesiTunes folder |
itunes.exe |
![]() |
Detected as Trojan-Dropper.Win32.Agent.mm by Kaspersky Anti-Virus |
dials.exe |
![]() |
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
iTunesHelper.exe |
![]() |
Added by a variant of the SDBOT WORM! |
iTunesHelper32.exe |
![]() |
Added by the TACTSLAY.U TROJAN! |
ita.exe |
![]() |
Added by the EB adult premium dialer |
itunesff.exe |
![]() |
Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation |
iTunesHelper.exe |
![]() |
Microsoft IntelliType Pro keyboard related - what does it do and is it required? |
itype.exe |
![]() |
Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up |
netdet.exe |
![]() |
Added by the DLOADER-AXV TROJAN! |
uzcx.exe |
![]() |
Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates |
ivpsvmgr.exe |
![]() |
Added by the AGENT-ENZ TROJAN! |
ivy.exe |
![]() |
Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
iwctrl.exe |
![]() |
Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis |
iwctrl.exe |
![]() |
Added by the SDBOT-CY TROJAN! |
ixplore.exe |
![]() |
Added by the XORPIX-A TROJAN! |
[path to trojan] |
![]() |
Added by the SDBOT.BJK WORM! |
yujixit.exe |
![]() |
?? |
N/A |
![]() |
FastFind parasite variant |
IEService.exe |

Main Page 



