| Status | Autorun name | Command | Description |
| X | g.exe | g.exe | Added by the GRAYBIRD.Q TROJAN! |
| X | G_Host | gHost.exe | Added by the AUTOIT-BP WORM! |
| X | G_Server.exe | G_Server.exe | Added by the FEUTEL-C TROJAN! |
| X | G_Server1.2.exe | G_Server1.2.exe | Added by the GRAYBIRD-Z TROJAN! |
| X | G00123 | [worm filename] | Added by the BUGBROS WORM! |
| X | G0mez | G0mez.vbs | Added by the GORMLEZ-A WORM! |
| X | G3 | GSMedia3.exe | Malware downloader - detected by Kaspersky as the VB.UX TROJAN! |
| ? | g3dctl | g3dctl.exe | ?? |
| X | G4G | [random filename] | Detected as Trojan-Downloader.Win32.VB.fki |
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | System Tray monitoring tool for Gene6 FTP Server - "an advanced FTP server software for Windows developed specifically for security and high performance requirements" |
| X | ga6pcw | ga6pcw.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples |
| X | gabougool | nounina.exe | Added by the AGENT-JVX TROJAN! |
| X | gac | gac.exe | Part of VirusVakt, Swedish rogue security software - not recommended. A member of the AVSystemCare family |
| ? | GACService | GACService.exe | Related to a Gemplus product. What does it do and is it required? |
| X | gadcom | gadcom.exe | Added by the AGENT-HIC TROJAN! |
| X | gadkgak12 | fsafsakx12.exe | Added by the ONLINEG-N TROJAN! |
| N | Gadu-Gadu | gg.exe | Polish language Instant Messaging client |
| N | Gadwin PrintScreen | PrintScreen.exe | Gadwin PrintScreen - utility to capture, print or save the current window |
| X | GAELICUM.EXE | GAELICUM.EXE | Added by the PENTA-A TROJAN! |
| X | gah95on6 | gah95on6.exe | ShopAtHome/SAHagent adware |
| U | gaim | gaim.exe | Gaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks |
| U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel |
| X | game | shit.exe | Added by the Netclap Gold backdoor TROJAN! |
| X | game | patcher.scr | Added by the PSW-ED TROJAN! |
| N | Game Device | JOYUPDRV.EXE | Genius game controller profile activator |
| X | Game House | GameHouse.exe | Added by the DELF-DRA WORM! |
| N | GameDrive | GDTask.exe | GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs |
| X | Games Acceleration | svshost.exe | EasySearch adware |
| X | Games Acceleration | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Games Acceleration | svshost1.exe | Added by the DLOADR-AWD TROJAN! |
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | Topconverting.com/180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| N | GameSpot | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
| N | GameTracker | GTLite.exe | GameTracker - "Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!" |
| U | gameutil.exe | gameutil.exe | Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot |
| X | gamma | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies |
| U | GammaHotKeys | setgamma.exe | Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop |
| X | gangsta | gangsta.exe | Added by the RIMA.A BACKDOOR! |
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers |
| X | gaSrv | gaSrv.exe | Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader |
| X | gaSrve | gaSrve.exe | Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader |
| X | Gate Personal Firewall | Systpl.exe | Added by the RBOT.ADC WORM |
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder |
| X | Gator | gator.exe | Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | Gator eWallet | gator.exe | Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | Gay_Sexy_** | Gay_Sexy_**.exe | Premium rate adult content dialler (where * is a random char) |
| U | GazelDisplay | gsyno.exe | BT Digital Access USB - Gazel ISDN installation System Tray icon |
| Y | GBMHome7Agent | GBMAgent.exe | Genie Backup Manager Home 7 - backup software |
| Y | GBMLite7Agent | GBMAgent.exe | Genie Backup Manager Lite 7 - backup software |
| Y | GBMPro7Agent | GBMAgent.exe | Genie Backup Manager Pro 7 - backup software |
| Y | GBSpaceMan | SpaceMan.exe | GreenBorder - secure your browsing activities on the internet |
| U | GBTray | GBTray.exe | System Tray icon access to Roxio's (nee Adaptec) GoBack software which allows you to revert back to a previously working state on you hard drive if you install a new program and your system goes faulty - performing the same functions with extra features as System Restore on WinMe/XP systems. Disable before running Scandisk or Defrag. Not required for WinMe/XP users, recommended for Win9x/NT/2K users |
| X | gCac | gcac.exe | Added by the TACTSLAY.U TROJAN! |
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup |
| Y | gcasServ | gcasServ.exe | Giant Antipsyware - now superseded by Microsoft's Windows Defender |
| X | gcasServ | realsched.exe | Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
| ? | GCC Reminder | gccrem.exe | Associated with AcraMax Greeting Card Creator. Is it a registration reminder? |
| N | GCS | GrabClipSave.exe | GrabClipSave screen capture tool |
| X | gcw | gcw.exe | Part of BestsellerAntivirus, PCSecureSystem and other members of the AVSystemCare family of rogue security software suites. See here for more examples |
| X | gdagdgajs | bbsbw.exe | Added by the SDBOT-QX WORM! |
| X | GDAX | [path to backdoor] | Added by the RANKY.K TROJAN! |
| X | gdcw | GDCW.exe | Part of ContentEraser, WinAnonymous and other members of the PCPrivacyTool rogue privacy tool and other members of this family. See here for more examples |
| X | Gddlib | rundll32.exe gddlib.dll,start | Added by the AKBOT.EG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gddlib.dll" file is found in %System% |
| Y | GDFirewallTray | GDFirewallTray.exe | System Tray access to the firewall part of G Data range of internet security products |
| X | gdien32 | gdien32.exe | Added by the SINGU-P TROJAN! |
| X | gdimx | gdimx.exe | MPB-D dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx" |
| U | GDMgr.exe | gdmgr.exe | GuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer |
| N | GDrive | GDriver.exe | Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager |
| N | Gearbox | confsvr.exe | NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here |
| N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player |
| X | GEDZAC | GEDZAC.exe | Added by the GEMEL WORM! |
| X | Gekio Startups | gnksvc32.exe | Added by the AGOBOT.AFJ WORM! |
| N | GemStRmW | GemStRmW.exe | For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually |
| X | gencroot | gencroot.exe | Added by the SDBOT-AED WORM! |
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives |
| X | General Antivirus | GenAvir.exe | General Antivirus rogue security software - not recommended, removal instructions here |
| X | general lptt01 | general.exe | RapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
| X | general ml097e | general.exe | RapidBlaster variant (in a "General" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here |
| X | Generic Host | wauclt.exe | Added by the SDBOT-DNL WORM! |
| X | Generic host proccess for windows | SVCHOSTS.EXE | Added by the SPYBOT-GQ WORM! |
| X | Generic Host Process | SCHOST.EXE | Added by the RBOT-NC WORM! |
| X | Generic Host Process | svchost.exe | Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Generic Host Process | camacttiv.exe | Detected by AVG as the CIADOOR.13 TROJAN! |
| X | Generic Host Process | lsassw.exe | Added by the AGOBOT-N WORM! |
| X | Generic Host Process for Win Services | mscvs.exe | Added by a variant of the SDBOT WORM! |
| X | Generic Host Process for Win32 Service | svlhost.exe | Added by the WOOTBOT.EX WORM! |
| X | Generic Host Process for Win32 Service | rpchost.exe | Added by the IRCBOT.DCN WORM! |
| X | Generic Host Process for Win32 Services | ntspcv.exe | Added by the SDBOT.S TROJAN! |
| X | Generic Host Process for Win32 Services | intspvc.exe | Added by the DINFOR.D WORM! |
| X | Generic Host Process for Win32 Services | winsvc.exe | Added by the SDBOT-O WORM! |
| X | Generic Host Process for Win32 Services | bazzi.exe | Added by the AHKER.E WORM! |
| X | Generic Host Process for Win32 Services | winsvc32.exe | Added by the SDBOT-P WORM! |
| X | Generic Host Process for Win32 Services | lspsvc.exe | Added by the MUMU.C WORM! |
| X | Generic Host Process for Win32 Services | SPSVC.EXE | Added by the SDBOT.DA WORM! |
| X | Generic Host Process for Win32 Services | svchost32.exe | Added by the AGOBOT.ALH WORM! |
| X | Generic Host Process for Win32 Services | svñhîst.exe | Added by the DLOADER.AK TROJAN! |
| X | Generic Host Process for Win32 Services | winlogon.exe | Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! |
| X | Generic Host Process For Win32 Services | mtsc32.exe | Added by the VB-CPL TROJAN! |
| X | Generic Host Process for WinXP Services | mshelp.exe | Added by the AGENT-GQP TROJAN! |
| X | Generic Host Process2 System Backup | scvhost2.exe | Added by the RBOT-BAH WORM! |
| X | Generic Host Process326a System Backup | scvhost326a.exe | Added by a variant of the SDBOT WORM! |