Arcade File Downloads UsenetGeeks
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Iexplore Services iexplore.exe"Added by an unidentified VIRUS
X IEXPLORE.EXE [path to trojan]"Added by the BANCOS-CJ TROJAN!"
X IEXPLORE.EXE goot.exe"Added by the BIFROSE-C TROJAN!"
X IExplorer Iexplor32.exe"Added by the BDOOR-BY TROJAN!"
X IExplorer IExplorer.EXE"Added by the BANCOS-CH TROJAN!"
X IEXPLORER msiecfg.exe"Added by the JU or BANCBAN-IP TROJANS!"
X Iexplorer explorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the System folder"
X iexplorer lptt01 iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X iexplorer ml097e iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X Iexplorer.exe Iexplorer.exe"Added by the BANCBAN-EN TROJAN!"
X IExplorer32 Java Scripting IExplore32b.exe"Added by the RBOT.ABO WORM!"
X IExplorer32c Java Scripting IExplore32cb.exe"Added by the RBOT.ABN WORM!"
X IExplorer6 Java Scripting IExplore326.exe"Added by a variant of the SDBOT WORM!"
X IExplorer7 Java Scripting IExplore327.exe"Added by a variant of the SDBOT WORM!"
U IFSplash.exe IFSplash.exeI-FORCE driver for force feedback steering wheel
X igamatu ekor.exe"Added by the SDBOT.AQ TROJAN!"
X igamatu atecaca.exe"Added by the IRCBOT.R WORM!"
N igfxtray igfxtray.exe"Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie
? Iglpbv Iglpbv.exe"??"
X igsex2x igsex2x.exe"NewDial premium rate adult content dialler"
? iHP-100 iHPDetect.exe"Drive Letter Searcher
X iilc IILC.EXEHomepage hijacker
X Iinl iptl.exe"PurityScan/Clickspring adware"
X iisvers iisvers.exeAdded by an unidentified TROJAN or adware
N iIWiper Systemwiper.exe"System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
Y IJ75P2PSERVER IJ75P2PS.EXEPrinter utility which is required in order to make the printer work correctly
Y IKE Service 95 IKEService.exe"Associated with PGP. The PGP Tray can be
U iKeyWorks IKEYMAIN.EXE"A4Tech wireless keyboard driver and utility"
X iLLeGaL Mplayer.exe"Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
X iLLeGaL.exe Mplayer.exe"Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
? ILO_Office_Manager IntEdReg.exe /OFFMAN"Intense Educational Ltd - Language Office Software. Is it required?"
U iLyric iLyric.exe"iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button"
N iM Start Center iM_Tray.exeInstalled with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
X Image "rundll32 image.dll Install"
Y Image & Restore IMAGE32.exe"Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased
N Image Transfer SonyTray.exeSony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
U ImageDrive-{hex numbers} ImageDrive.exe"Nero ImageDrive from Ahead - virtual CD/DVD drive software"
U Imagefox imagefox.exe"ImageFox 2.0 is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes"
X Imagemgt32 Imagemgt32.exe"Added by the GEMA TROJAN!"
X ImagePath taskbarmngr.exe"Added by the SDBOT-XB WORM!"
X IMAPI load.exe"Added by the DOWNDEL-A TROJAN!"
N iMarkup Client iUtil.exe"Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
X IMClass Svhosl.exeAdded by an unidentified WORM or TROJAN!
N imekrig imekrig.exe"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
N IMEKRMIG6.1 IMEKRMIG.EXE"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
N Imesh ??"Imesh is a file sharing system"
N Imesh Auto Update ??"Update check for the Imesh file sharing system. Turn the update off under ""options"""
X IMEvtMgr.exe IMEvtMgr.exe"Added by the KEYLOG-AR TROJAN!"
U ImgIcon ImgIcon.exe"Displays Iomega icons in Explorer/My Computer
X imgit [path to file]"Added by the BANKER-EM TROJAN!"
N ImgStart ImgStart.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
N Imjpmig*.* IMJPMIG.EXE"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
? immcheck.exe immcheck.exe"Related to I-FORCE driver for force feedback steering wheel?"
X ImMsn timed.exe"Added by the WEBDOR.AK TROJAN!"
U IMOL IMOLApp.exe"IncrediMail for Office Outlook Add-On"
N Imonitor Plguni.exe"McAfee QuickClean 3.0 - removes internet clutter and unwanted programs"
U IMONTRAY imontray.exe"System tray monitoring of fans
X IMprocess IM-svr.EXE"IMNames adware"
U IMStart IMStart.exe"InterMute security software related"
X IMwire imwireup.exe"SafeSurfing adware variant"
X im_autorn im_1.exe"Added by the IMAV.A WORM!"
X im_autorn im_2.exe"Added by the BAGLEDL-BO TROJAN!"
Y InCD incd.exe"Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3)
N IncMail IncMail.exe"""IncrediMail is an advanced
N InControl Desktop Manager DMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
N Incredimail incredimail.exe""IncrediMail is an advanced
N Incredimail IncMail.exe"""IncrediMail is an advanced
X Index Service dllhost32.exe"Added by the AGOBOT.CH WORM!"
U Index Washer WashIdx.exe"Windows Washer from Webroot Software. Useful utility that deletes safe to remove files
X Indexindicator Indexindicator.exe"Added by the LAZAR TROJAN!"
N IndexSearch IndexSearch.exeAssociated with PaperPort scanner software from ScanSoft
U IndexTray IndexTray.exe"Part of ine svchosts.exe"Added by the RBOT.BNL WORM!"
X Inet DataBase Inetdbs.exe"Added by the QEDS WORM!"
X Inet Delivery inetdl.exe"Inet Delivery adware"
X Inet Delivery inetdl_2.exe"Inet Delivery adware"
X Inetapi Netapi.exe"Added by the NETDEVIL.14 TROJAN!"
U inetcntrl inetcntrl.exeBsafe Online - internet filter
? InetConf inetconf.exe"??"
U Inetd INETD32.EXE"Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation"
U inetinfo.exe inetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
X inetinfomon manager inetinfomon.exe"Added by the DONBOMB.A TROJAN!"
X inetmgr inetmgr.exe"Actual Names (AdvSearch) Internet Keywords parasite"
X InetMSN msnet.exe"Added by a variant of the SDBOT TROJAN!"
X InetServices wsock32.exe"Added by the WOCK32-A TROJAN!"
X infamous.exe wmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda as Trj/Briss.A
U Info Select is.exe"Info Select from Micro Logic - personal information manager"
X Info32x Info32x.exe"Added by the GEMA TROJAN!"
U InfoPenMSN InfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
? Infoplay.exe Infoplay.exe"Written by New Media Properties
X Information Update iu.exe"Recognized by Kaspersky antivirus as Downloader.Win32.Centim.ch TROJAN! Note - the file associated with this is located in the Program FilesInformation Update folder"
U Infra-red Monitor IRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
X infus infus.exeAdult content dialler
U Infuzer Infuzer.exe"Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them
X infwin infwin.exe"VX2.Transponder parasite updater/installer related"
X Init32 Init32.exe"Added by the WINEX.A TROJAN!"
X Initial Page install.exeEasySearch browser hijack installer
Y Initialize8x8 8x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
X injob injobs.exe"Added by the BINJO TROJAN!"
N Ink Monitor InkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
N InkWatch InkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
Y InoRPC InoRpc.exe"Associated with eTrust Antivirus/InoculateIT"
Y InoRT InoRT9x.exe"Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage"
U InoTask InoTask.exe"Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
? insCOA5 insCOA5.exe"??"
U InstaAlert InstaAlert.exe"""Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
X InstaFinderK InstaFinderK inst.exe"InstaFinder adware"
X Install Install.exe"Added by the BANCBAN-HG TROJAN!"
? Install Pending Files sifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
N InstallAurealDemos InstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
U InstallBuddy Ibtna.exe"InstallBuddy - automatically translates and installs your desktop documents
X Installed shell32.dll Office.exe..."Added by a variant of the LOVGATE WORM!"
X Installer dial.exe"Malware - recognized by Kaspersky antivirus as the AGENT.MM TROJAN!"
? InstallNAIProduct SETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
X Installs SP2 [path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM!"
U Installstub installstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
X Instance 001 [path to worm]"Added by the Alasrou-A WORM!"
X Instant Access "rundll32.exe EGDHTML_1023.dll InstantAccess"
X Instant Access "rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe EGDACCESS_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
X Instant Buzz Daemon IBDaemon.exe"Instant Buzz adware"
N Instant Update Center reminder.exe"From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates
U Instant Wireless Configuration Utility WUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
U Instant Wireless Configuration Utility WPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
N InstantAccess INSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
U InstantDrive InstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
X InstantPleasure instantpleasure.exeAdult content dialler
X InstantPleasureXXX instantpleasurexxx.exeAdult content dialler
N InstantTray PCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
X instit instit.bat"Added by the OPASERV.H WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list