| Status | Autorun name | Command | Description |
| X | ICU-Sucker | Service32.exe | Added by the ILLNOTIFIER.D TROJAN! |
| N | ID Commander | IDCom.exe | Caller ID utility for identifying incoming telephone numbers |
| X | ID8525 | ID8525.exe | Added by the ID8525.A TROJAN! |
| X | ID8525 | id85255.exe | Added by the ID8525.A TROJAN! |
| ? | IDA | IDA.EXE | Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required? |
| X | IDBoan | IDBoan.exe | IDBoan rogue security software - not recommended, removal instructions here |
| X | IDE | ide.exe | Added by the ASSASIN.F TROJAN! |
| X | IDE Loader | IDElibr32.exe | Added by the XILON TROJAN! Related to the game "Diablo II" |
| X | idecntl | idecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | iDesktop | idesktop.exe | Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse |
| X | idlesam | [8 random letters].exe | Added by the ZHELATIN.EQ WORM! |
| N | IDMan | IDMan.exe | Internet Download Manager - download files faster, schedule and resume |
| X | idmlssp | [random filename] | Added by a variant of the SLAPER TROJAN! |
| U | IDriveE Startup | IDrvieEStartup.exe | IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts |
| X | IDT PC Audio | statcvs.exe | Added by the DELFINJ-Y TROJAN! |
| X | IDTemplates | IDTemplate.exe | Added by the BRONTOK-H WORM! |
| N | IDW Logging Tool | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems |
| X | IE | [path to backdoor] | Added by the MSPOSER.KAX BACKDOOR! |
| X | IE configure | explorer.exe | Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| U | IE Doctor | IEDoctor.exe | IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" |
| X | IE Java Update | iejava.exe | Added by the AGENT-HD TROJAN! |
| X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | IEMenuExt trackware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | IE New Window Maximizer | iemaximizer.exe | IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows |
| X | IE Runtime | wini.exe | Added by the PICRATE.B WORM! |
| X | IE Runtime | winlogo.exe | Added by the RBOT-AMJ WORM! |
| X | IE Runtimes | winis.exe | Added by the RBOT-ADZ TROJAN! |
| X | IE**.exe [* = random char] | IE**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | IE**32.exe [* = random char] | IE**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | IE-Security | wdscan.exe | IE-Security rogue spyware remover - not recommended, removal instructions here |
| X | IE-Security | iescan.exe | IE-Security rogue spyware remover - not recommended, removal instructions here |
| X | IE6 | wkstmg.exe | Added by a variant of the SDBOT WORM! |
| X | IE6 | ssmss.exe | Added by the GAOBOT.DXO WORM! |
| X | IE6 | porn.pif | Added by the RBOT-ATF WORM! |
| X | IE6 | winsnt.exe | Added by the RBOT-GOV WORM! |
| X | IEACCESS | temp532.exe | AsdPlug premium rate adult content dialer variant |
| X | IEACCESS | surfya.exe | IEAccess premium rate adult content dialer variant |
| X | IEAgent update check | iewatch.exe | Added by the BOMKA TROJAN! |
| X | IECache | IECache.exe | Detected by Bitdefender as the DELF.OFC TROJAN! See here |
| N | iecheck | iecheck.exe | Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2 |
| X | IECheck | MSDTCs.exe | Added by the TIRBOT-D WORM! |
| X | IECheck | xpssl.exe | Added by the TIRBOT-E WORM! |
| X | IECheck | mssvp.exe | Added by the TIRBOT-G WORM! |
| U | IECleanAux | Ieboot6.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup |
| X | iedll | iedll.exe | Homepage hijacker, redirecting to coolwwwsearch.com |
| X | IEDriver | IEDriver.exe | IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze |
| X | IEDriver | xplore.exe | IeDriver adware variant |
| X | IEDriver | TD.exe | IeDriver adware variant |
| X | iedwa104 | iedwa104.exe | Added by the DLOADR-BBW TROJAN! |
| U | IEEE 802.11g Wireless LAN Utility | WLANUTL.exe | Wireless LAN configuration utility |
| U | IEEE802.11b WLAN USB Adapter Utility | WLUSBCFG.exe | Wireless LAN configuration utility |
| X | IEengine | IEeng.exe | STARTPAG.AI TROJAN! |
| X | IEexplorer AUpdate | IEexplore32.exe | Added by the RBOT-GRE WORM! |
| X | IEFeatures | IEFeatures.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | IEFeatures | Internetfeatures.exe | Added by the POPMON.A TROJAN! - also known as PopMonster adware |
| X | IefxTray | IefxTray.exe | Added by the RILER-H TROJAN! |
| X | ieharv.exe | ieharv.exe | Added by the BANKER-HH TROJAN! |
| X | Iehelper | syslaunch.exe | Outwar adware downloader |
| X | iel2cde8 | rundll32.exe iel2cde8.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "iel2cde8.dll" file is found in %System% |
| X | ielcaabe | rundll32.exe ielcaabe.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "ielcaabe.dll" file is found in %System% |
| X | IELoader32 | iexplore32.exe | Added by the SPEX or SPEX.B WORMS! |
| X | Iesar | Iesar.exe | Browser hijacker - redirecting to an adult web page |
| X | Iesearch.exe | Iesearch.exe | LookNSearch adware |
| U | IEServer | IEServer.exe | HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself |
| X | IeServer | syswin.exe | Added by the HUPIGON.FDNV BACKDOOR! |
| X | IESet | IExplorer.dll | Added by the PWS-BLUEDIT TROJAN! |
| X | iesetupi.exe | iesetupi.exe | Added by a variant of the RBOT WORM! |
| Y | IEShow | IEShow.exe | Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames, passwords and credit card details being acquired by web-sites and E-mails masquerading as a trustworthy sources. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor |
| X | iestart | iexp1orer.exe | Added by the NEMOG.C TROJAN! |
| N | ietsr | ietsr.exe | IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc |
| X | Ieudinit | ieudinit.exe /waitservice | Added by the HORST.Q TROJAN! Note - this is not the legitimate ieudinit.exe which is always located in %System%. This one is located in either %Windir%, %Windir%\System, %Temp%, %AppData%, %AppData%\Microsoft or %System%\drivers |
| X | ieupdate | MCP****.exe [**** = random char] | Added by the ASOXY TROJAN! |
| X | ieupdate | mcpdll32.exe | Adware downloader trojan |
| X | ieupdate | [random filename] | Added by the AGENT-C BACKDOOR! |
| X | ieupdates | ieupdates.exe | Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here |
| X | IEWinserv | winserv.exe | Added by the BANKER-MY TROJAN! |
| X | IEXPL0RER | IEXPL0RER.EXE | Added by the AGOBOT-QL WORM!
Note the filename has a "0" rather than an upper case "o" |
| X | iexplo | iexplor.exe | Added by the SIDEA TROJAN! |
| X | IExploer | svshosts.exe | Added by the IRCBOT.BT BACKDOOR! |
| X | Iexploit | Iexploit.html | Added by the INKER.B WORM! |
| X | iexplor.exe | iexplor.exe | Added by an unidentified WORM or TROJAN! See here |
| X | Iexplore | iexplore.exe | Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | IEXPLORE | iexplore.exe | Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | IExplore | IEXPLORE.EXE | Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a "Custom" subfolder |
| X | IEXPLORE | IEXPLORE.EXE | Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | iExplore Ini | ie4uini.exe | Added by a variant of the IRCBOT BACKDOOR! See here |
| X | Iexplore Services | iexplore.exe | Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! |
| X | IEXPLORE.EXE | [path to trojan] | Added by the BANCOS-CJ TROJAN! |
| X | IEXPLORE.EXE | goot.exe | Added by the BIFROSE-C TROJAN! |
| X | IExplorer | Iexplor32.exe | Added by the BDOOR-BY BACKDOOR! |
| X | IExplorer | IExplorer.EXE | Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | IEXPLORER | msiecfg.exe | Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN! |
| X | Iexplorer | explorer.exe | Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | iexplorer | wind.exe | Added by an unidentified VIRUS, WORM or TROJAN! See here |
| X | iexplorer lptt01 | iexplorer.exe | RapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | iexplorer ml097e | iexplorer.exe | RapidBlaster variant (in a "iexplorer" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Iexplorer.exe | Iexplorer.exe | Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | IExplorer32 Java Scripting | IExplore32b.exe | Added by the RBOT.ABO WORM! |
| X | IExplorer32c Java Scripting | IExplore32cb.exe | Added by the RBOT.ABN WORM! |
| X | IExplorer6 Java Scripting | IExplore326.exe | Added by a variant of the SDBOT WORM! |
| X | IExplorer7 Java Scripting | IExplore327.exe | Added by a variant of the SDBOT WORM! |