| Status | Autorun name | Command | Description |
| Y | InCD | InCD.exe | InCD packet writing utility which allows the user to format CDs/DVDs so that they can be used by simply dragging and dropping files to the disk or by saving to disk from within other applications. Included with Nero digital media suites (CD/DVD burning, authoring, etc) until version 9 (optional install for versions 7 thru 9) and now available as a separate download. If you prefer not to use InCD (due to the obvious alternatives such as USB flash drives) you can disable it |
| N | IncMail | IncMail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
| X | incognito | incognito.exe | Added by an unidentified WORM or TROJAN! See here |
| N | InControl Desktop Manager | DMHKEY.EXE | For Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs |
| X | Incredible Keylogger | AdvKeylog.exe | IncredibleKeylogger spyware |
| N | Incredimail | incredimail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
| N | Incredimail | IncMail.exe | "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality" |
| X | Index Service | dllhost32.exe | Added by the AGOBOT.CH WORM! |
| U | Index Washer | WashIdx.exe | Window Washer from Webroot Software. Useful utility that deletes safe to remove files, cookies, browsing history, etc. Available via from Start -> Programs. Disable within the program options - otherwise it is re-enabled in MSCONFIG |
| U | IndexCleaner | IdxClnR.exe | Utility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online |
| U | IndexCleaner | IndexCleanerR.exe | Utility that cleans the index.dat file when the system restarts. Index.dat files keep a track of pages, images, cookies or sounds from web sites you have visited, even if these files are deleted from your system. Recommended at "Users choice" status because it depends how the user cleans their internet history. Installed as part of the internet security suite packages sourced by Radialpoint for ISP customers such as Virgin Media, AT&T, Bell Canada, TELUS Corporation and Verizon Online |
| ? | Indexer | Indexer.exe | Part of the Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents". What does it do and is it required? |
| X | Indexindicator | Indexindicator.exe | Added by the LAZAR TROJAN! |
| N | IndexSearch | IndexSearch.exe | Part of Nuance (ScanSoft) PaperPort - "scan, organize, find and share all of your documents including paper, PDF, application files and photographs". Creates an index of files associated with PaperPort for easy searching |
| U | IndexTray | IndexTray.exe | Part of Sharpdesk from Sharp Electronics. "A desktop-based, personal document management application that lets users browse, edit, search, compose, process, and forward both scanned and native electronic documents" |
| U | IndicatorUty | IndicatorUty.exe | Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook, eg, when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed |
| U | IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} | NMIndexStoreSvr.exe | Indexing and storage service for Nero Scout which is "a database program which indexes and catalogs all media files on your computer and makes the database available to all programs in the Nero product package." Included in version 8 of the Nero digital media suites (CD/DVD burning, authoring, etc). Integrated into a number of Nero applications and is of particular significance for the Nero Home media center - for more information see the link |
| X | ine | svchosts.exe | Added by the RBOT.BNL WORM! |
| X | INET | inetsync.exe | Meplex adware |
| X | inet | svhost.exe | Added by the SDBOT-M BACKDOOR! |
| X | Inet DataBase | Inetdbs.exe | Added by the QEDS WORM! |
| X | Inet Delivery | inetdl.exe | Inet Delivery adware |
| X | Inet Delivery | inetdl_2.exe | Inet Delivery adware |
| U | Inet_Perf | svcwinra.exe | System Surveillance Pro surveillance software. Uninstall this software unless you put it there yourself |
| X | Inetapi | Netapi.exe | Added by the NETDEVIL.14 BACKDOOR! |
| X | InetChk | ms[random value].exe | Added by the AGENT-IRL TROJAN! |
| U | inetcntrl | inetcntrl.exe | Bsafe Online - internet filter |
| ? | InetConf | inetconf.exe | ?? |
| U | Inetd | INETD32.EXE | Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation |
| U | inetinfo.exe | inetinfo.exe | Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more) |
| X | inetinfomon manager | inetinfomon.exe | Added by the DONBOMB.A TROJAN! |
| X | inetmgr | inetmgr.exe | Actual Names (AdvSearch) Internet Keywords parasite |
| X | InetMSN | msnet.exe | Added by a variant of the SDBOT TROJAN! |
| X | inetrun | inetrun.exe | Added by the AGENT.CE BACKDOOR! |
| X | inetserv | inetserv.exe | Added by the AGENT-OWJ TROJAN! |
| X | InetServices | wsock32.exe | Added by the WOCK32-A TROJAN! |
| X | inetsys | [path to trojan] | Added by the DELF-NV TROJAN! |
| X | infamous.exe | wmplayer.exe | Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup |
| X | InfeStop | InfeStopRemover.exe | InfeStop rogue spyware remover - not recommended, removal instructions here |
| U | Infium | qip.exe | QIP (Quiet Internet Pager) Infium multiprotocol instant messaging client |
| X | info | smss.exe | Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv |
| X | INFO DATA | apc.exe | Added by the RANDON.B WORM! |
| U | Info Select | is.exe | Info Select from Micro Logic - personal information manager |
| X | Info32x | Info32x.exe | Added by the GEMA TROJAN! |
| X | InfoData | rundll32.exe ********.dll,realset [* = random char] | Added by the VUNDO TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The random DLL file is found in %System% |
| X | infoguardr | infoguardrun.exe | InfoGuard rogue security software - not recommended, removal instructions here |
| U | InfoPenMSN | InfoPenIM.exe | InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand |
| ? | Infoplay.exe | Infoplay.exe | Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed? |
| X | InfoPure | InfoPure.exe | InfoPure rogue security software - not recommended, removal instructions here |
| X | Information Update | iu.exe | Detected by Kaspersky as the CENTIM.CH TROJAN! |
| X | InfoSafe | InfoSafe.exe | InfoSafe rogue security software - not recommended, removal instructions here |
| U | Infra-red Monitor | IRMON.EXE | System Tray access to infra-red devices. Not required unless you use infra-red devices |
| X | infus | infus.exe | Adult content dialler |
| U | Infuzer | Infuzer.exe | Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities" |
| X | infwin | infwin.exe | VX2.Transponder parasite updater/installer related |
| X | Init | [path to trojan] | Added by the DROPPER.EAT TROJAN! |
| X | Init32 | Init32.exe | Added by the WINEX.A TROJAN! |
| X | Initial Page | install.exe | EasySearch browser hijack installer |
| Y | Initialize8x8 | 8x8_init.exe | Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay |
| X | inixs | minix32.exe | Added by the AGENT.CKQX TROJAN! |
| X | injob | injobs.exe | Added by the BINJO TROJAN! |
| N | Ink Monitor | InkMonitor.exe | Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
| N | InkWatch | InkWatch.exe | Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line |
| X | Inom | snmoo.exe | Added by the RBOT-DPM WORM! |
| Y | InoRPC | InoRpc.exe | Part of eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products |
| Y | InoRT | InoRT9x.exe | Real-time monitor for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products |
| U | InoTask | InoTask.exe | Scheduled scans and signature updates for eTrust Antivirus and InoculateIT - earlier versions of the CA antivirus products. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU usage when performing updates |
| X | iNotice | iservice.exe | Added by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos |
| U | InputDirector | InputDirector.exe | "Input Director is a Windows application that lets you control multiple Windows systems using the keyboard/mouse attached to one computer" |
| ? | insCOA5 | insCOA5.exe | ?? |
| X | Insider | Insider.exe | Added by the AGENT.KMC TROJAN! |
| U | InstaAlert | InstaAlert.exe | "Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly" |
| X | Instafinder | instafinder.exe | TopSearch.D adware |
| X | InstaFinderK | InstaFinderK_inst.exe | InstaFinder adware |
| U | InstaLAN | BelkinRouterMonitor.exe | System Tray access to the Belkin Router Manager which indicates the current status of the Router and allows access to the Router settings and bundled software |
| X | Install | Install.exe | Added by the BANCBAN-HG TROJAN! |
| X | Install part II | updates.exe | Added by the RELFEERWORM! |
| ? | Install Pending Files | sifxinst.exe | Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required? |
| x | install32 | install32.exe | Added by the NUCLEAR.DG BACKDOOR! |
| N | InstallAurealDemos | InstallAurealDemos.js | Used to initialize the Aureal A3D demos InstallShield wizard |
| U | InstallBuddy | Ibtna.exe | InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync |
| X | InstallCleaner | InstallCleaner.exe | Added by the ANYHOMB.F TROJAN! |
| X | Installed shell32.dll | Office.exe... | Added by the LOVGATE.AO WORM! |
| X | Installed shell32.dll | Office.exe | Added by the LOVGATE.E WORM! |
| X | Installer | dial.exe | Malware - detected by Kaspersky as the AGENT.MM TROJAN! |
| X | InstallMon | fbx.exe | Added by the MDROP-CZK TROJAN! |
| ? | InstallNAIProduct | SETUP.EXE | Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error? |
| X | InstallProgram | [path to trojan] | Added by the AGENT-HHU TROJAN! |
| X | InstallProvider | newsoftware2007install.exe | Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended |
| X | Installs SP2 | [path] repcale.exe [path] palsp.exe | Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp |
| X | Installs SP4 | [path] repcale.exe [path] p0rd.exe | Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc |
| U | Installstub | installstub.exe | Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone |
| X | Instance 001 | [path to worm] | Added by the ALASROU-A WORM! |
| X | Instant Access | rundll32.exe EGDHTML_1023.dll, InstantAccess | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Instant Access | rundll32.exe eg_auth_****.dll, InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Instant Access | rundll32.exe EGCOMLIB_****.dll, InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Instant Access | rundll32.exe EGCOMSERVICE_****.dll, InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Instant Access | rundll32.exe p2esocks_****.dll, InstantAccess [**** = digits] | InstantAccess premium rate adult content dialler variant. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | Instant Access | mwsrvacc.exe | InstantAccess premium rate adult content dialer |
| X | Instant Access | linewsrv.exe | InstantAccess premium rate adult content dialer variant |