| Status | Autorun name | Command | Description |
| X | Tcsvc | rundll32.exe tcsvc.dll,start | Added by the AGENT.BCL BACKDOOR! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "tcsvc.dll" file is found in %System% |
| ? | TCtlIHook.exe | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required? |
| ? | TCtrlIOHook | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required? |
| ? | TCtryIOHook | TCtrlIOHook.exe | TOSHIBA Control Utility Hotkey Hook - hotkey configuration process unique to Toshiba laptops. What does it do and is it required? |
| X | tcupdater | tcupdater.exe | Topconverting.com/180Search adware updater |
| U | TDAlert | TDAlert.exe | Part of Trust Delete from EgisTec Inc - which "is a remote data deletion software to protect your confidential data and prevent them from falling into the wrong hands when your PC is stolen or missing" |
| U | TDispVol | TDispVol.exe | Used on Toshiba computers to make the Fn key have control over the volume on/off |
| U | TDKSTART | TDKSTART.EXE | Sets the spindown timeout and access speeds at startup and displays a splash screen for CD-RW. |
| N | TDKTASK | TDKTASK.EXE | Taskbar utility for a "control panel" for a CD-RW |
| ? | TDockNUndock | N/A | Found on a Toshiba laptop - for use with a docking station? |
| X | Tdrb | ompa.exe | PurityScan adware |
| U | TDS3 | TDS-3.exe | DiamondCS TDS-3 antitrojan. Can be used to scan on demand, but required in startup if you prefer real time protection |
| ? | TDspOff | Tdspoff.exe | Found on a Toshiba laptop |
| U | TE_RegProtect | TERegPct.exe | Registry repair utility part of the Anti Trojan Elite (ATE) anti-malware tool |
| N | Teach In Box | teachbox.exe | Tutoring program that comes with a SystemAX Computer |
| Y | TeaTimer | TeaTimer.exe | Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. "Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future". Also provides System Tray access to Spybot S&D and detects when processes want to change critical registry settings such as the startup entries - giving the user the option to allow/deny the change |
| Y | Tech-In-A-Box | techbox.exe | Tech-in-a-Box "provides easy-to-use tools for various system maintenance tasks. From backup and restore to diagnostics and repairs, Tech-in-a-Box is your tool to stay up and running" |
| U | Teco | Teco.exe | Toshiba's Eco Utility that "offer improved energy management. With a single click you can switch to a pre-configured power plan that will not only let you go green, but let you see the measurable savings too" |
| U | TEData_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TEData users |
| X | teiteq | teiteq.exe | Added by the VB-WC MALWARE! |
| U | Telechips,Mass | patch.exe | Removable disk driver for the Muro MP3 player |
| N | Telemeter 3.0 | telemeter3.exe | Internet connection bandwidth meter from a user ISP |
| Y | Telepath | telepath.exe | Drivers for the WinModem versions of the US Robotics "Telepath" series - as supplied to Gateway for instance. WinModems use software rather than hardware - hence putting a load on the CPU. Needed if you have it for loading the drivers. See here for more WinModem information |
| X | Telephony Provider | Iexplore.exe | Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Telnet | Telnet.exe | Added by the VOUMIT-A WORM! Note - this is not the legitimate telnet.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a "mirc32" folder |
| X | Telnet24 | [random filename] | Added by the RBOT-ARD WORM! |
| U | TelstraClear Broadband Support | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". TelstraClear Broadband Support is required to run with the Help and Support program. If you uncheck TelstraClear Broadband Support and then run Help and Support it will add another TelstraClear Broadband Support entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
| U | TELUS eCare | matcli.exe | TELUS Resolution Assistant. "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, state, etc and gets written to a log file". TELUS Resolution Assistant is required to run with the Help and Support program. If you uncheck TELUS Resolution Assistant and then run Help and Support it will add another in the startup menu. If you remove TELUS Resolution Assistant via add/remove programs some menus in Help and Support will not be available. You decide |
| Y | TELUS eProtect | Rps.exe | Main program for the TELUS eProtect internet security suite for TELUS ISP customers - sourced by Radialpoint |
| Y | TELUS Security service | freedom.exe | TELUS Security service - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available |
| U | TELUS Support Centre | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS users |
| U | TELUS_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS users |
| U | TelusWCC_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS Wireless users |
| X | TemizSurucu | GDC.exe | TemizSurucu Turkish rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| X | TempCom | [randomname].com | Added by the TRAXG WORM! |
| X | tempx | tempx.exe | Added by the TEMPEX.A TROJAN! |
| X | Tencent QQ | Rund1132.exe qq.dll, Rundll32 | Added by the QQPASS.F TROJAN! |
| N | Tencent QQ | QQ.exe | Tencent QQ Asian instant messanger program |
| Y | TEPA.exe | TEPA.exe | TELUS eProtect Advisor tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled |
| X | Terminal Services | mstscc.exe | Added by the SDBOT-CZW WORM! |
| X | Terminal Update | biosefui.exe | Added by the PPDOOR-O TROJAN! |
| X | Terminate Popup | ZPU.exe | Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here |
| X | Terminate Popup | fpuk.exe | Popup killer - foistware proven to install the Regsvc32 homepage hijacker |
| U | TEscKey | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function |
| ? | Tesco Insert Detect | InsDetect.exe | Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? |
| N | Tesco.net | rundll32 [path] RyDial.dll, QuickStart | Tesco.net dial-up ISP software - not required |
| ? | Tesla | TESLA.EXE | ?? |
| X | test | i love you.exe | Added by the SINGU-T TROJAN! |
| X | test | zistro.exe | Added by the KIMAT-C TROJAN! |
| X | Test* | Test.exe | Added by the AUTORUN-SG WORM - where * represent a number. If, for example, you have four physical hard drive partitions and one removable drive, the file "Test.exe" will be present in the root of the partition (ie, C:\, D:\) with startup entries of "Test1" through "Test5" |
| X | Test321 | fresdg.exe | Added by the HAMWEQ.DD WORM! See here |
| X | testest | fxxxh.exe | Added by the SDBOT-MK WORM! |
| X | Testing 123 | msdata.dat | Added by the NITS.A WORM! |
| X | testit.exe | testit.exe | ISTBar adware |
| X | Teth | drle.exe | PurityScan adware |
| ? | TExBUtil Registry | TExBUtil.exe | ?? |
| X | Text Tray Service | tstray.exe | Added by the SILLYFDC.BCC WORM! |
| N | TextAloud | TextAloudMP3.exe | TextAloud MP3 - convert text into spoken words and MP3s |
| N | Textbridge Instant Access OCR | telepath.exe | TextBridge from Nuance (was Scansoft). OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs |
| X | TEXTCONV | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | TEXTCONV | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| U | TFncKy | TFncky.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
| U | TFNF5 | TFNF5.exe | Toshiba Hotkey Utility for Display Devices. By pressing <FN> + <F5>, a window appears showing the displays that can be chosen - LCD, LCD + CRT, CRT, TV |
| Y | tfswctrl | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
| Y | tfswctrl.exe | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
| X | TFTP*** | tftp*** | Added by a variant of the SPYBOT WORM! where *** can be any number |
| Y | TFTray | TFTray.exe | System Tray access to ThreatFire no-signature anti-malware from PC Tools - which "features innovative real-time behavioral technology that provides powerful protection against both known and unknown viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware" |
| U | TFunckey | TFuncKey.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
| N | TgAddServer | tgfix.exe | Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove try here |
| X | tgbcde | module32.exe | Added by the REIGN.R TROJAN! |
| U | tgcmd | tgcmd.exe | Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| U | tgcmd | hcenter.exe | Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| U | tgcmdprovidersbc | tgcmd.exe | Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| N | TGCMG | ?? | Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work |
| X | TGDC IE Plugin | tgdc.exe | ShopForGood spyware - see here |
| N | tgkill | tgkill.exe | Comcast struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This "beta" release was made available to download by mistake and should be removed via Start → Control Panel → Add/Remove Programs |
| N | TGPro Office | IdxOffice.exe | With IdiomaX Office Translator "you can translate documents directly from your favorite text editor (Microsoft Word, WordPerfect or Lotus WordPro)" |
| U | Tgsetsite | tgfix.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
| U | THCS | svchost.exe | AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a "drivers\imon" subfolder |
| ? | Thdetrf | thdetr32.exe | Appears to be related to Lycos advertising |
| X | ThE | wind0s.exe | Added by an unidentified WORM or TROJAN! |
| N | The Assistant | eSched.exe | Related to WinTotal from a la mode inc. FormFiller for appraisers |
| U | The Easy Bee's Hive | ATCEgSvr.exe | The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence |
| X | The Ethernet | ethernet.exe | Added by a variant of the SDBOT WORM! |
| X | The Ethernet | intranet.exe | Added by a variant of the SDBOT WORM! |
| X | The Intranet | intranet.exe | Added by a variant of the SDBOT WORM! |
| X | The Monitor | [path to trojan] | Added by the VB-AXL TROJAN! |
| N | The Proxomitron | Proxomitron.exe | A free, highly flexible, user-configurable, small but very powerful, local HTTP web-filtering proxy - see here |
| X | The Registry Sentinel | The Registry Sentinel.exe | The Registry Sentinel rogue security software - not recommended, removal instructions here |
| X | The Service Pack Loader | spxp.exe | Added by the RBOT-BYM WORM! |
| X | The Spy Guard | spyguard.exe | The SpyGuard rogue spyware remover - not recommended, removal instructions here |
| X | The Spy Guard Monitor | spyguard_monitor.exe | The SpyGuard rogue spyware remover - not recommended, removal instructions here |
| X | The Web Sentinel | The Web Sentinel.exe | The Web Sentinel rogue security software - not recommended, removal instructions here |
| X | TheBestMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | TheDefend.exe | TheDefend.exe | TheDefend rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | TheLastDefender | LastDefender.exe | The Last Defender rogue security software - not recommended, removal instructions here |
| ? | TheMainStart | N/A | ?? |
| X | ThemeMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | TheMonitor | [filename].exe | YourEnhancement downloader. The file is located in %Windir% |
| X | TheSpyBot | TheSpyBot.exe | TheSpyBot rogue security software - not recommended, removal instructions here |