| Status | Autorun name | Command | Description |
| X | anvtirs | anvtirs.exe | Added by the AGENT-OIN TROJAN! |
| X | AnvTrgr | AnvTrgr.exe | AntivirusTrigger rogue security software - not recommended, removal instructions here |
| U | Any To-Do List | anytodo.exe | Any To-Do List "the ultimate software solution to keep yourself organized and reminded" |
| ? | anycom bluetooth | ftflauncher.exe | Associated with an Anycom bluetooth wireless card. What does it do and is it required? |
| U | AnyDVD | AnyDVD.exe | AnyDVD - descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts - hence the "U" recommendation |
| U | AnyDVD | AnyDVDtray.exe | System Tray access to AnyDVD from SlySoft - which descrambles DVD-Movies automatically in the background and the DVD appears unprotected and region code free. Also removes prohibited operations from the DVD such as skipping adverts |
| X | anything | ATITAX.exe | Added by the FORBOT-DP WORM! |
| U | AnyTime | Atw.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" |
| U | AnyTime Organizer | AtDem.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" |
| U | AnyTime Organizer | Atw.exe | AnyTime Organizer Deluxe from Individual Software Inc - "all the tools you need to organize your calendar, to-do list, and address book are combined in a familiar interface with hundreds of printable calendars, detailed expense reports, and a full range of programmable alarms" |
| N | AO Tray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
| Y | aol | avp.exe | System Tray access to and notifications for AOL's Active Virus Shield (by Kaspersky) - found in %ProgramFiles%\AOL\Active Virus Shield. Runs together with a related service - Active Virus Shield (AVP) - which runs a separate instance of the same file |
| N | AOL | AOL.exe | Fast Start loads the AOL integrated email, instant messenger and web browser software in the background when you turn on your computer. This feature lets you quickly open AOL |
| X | AOL 9.0 Optimized | AOLClient.exe | Added by the SPYBOTER.A TROJAN! |
| U | AOL Broadband Check-Up | matcli.exe | "matcli.exe is a motive Assistant Command line interface that gathers information about your system's identity like your name email address, city, county, etc and gets written to a log file". The AOL Self Support Tool is required to run with the Help and Support program. If you uncheck AOL and then run Help and Support it will add another AOL entry in the startup menu. If you remove this software in "add/remove programs" some help menus in help and support will not be available. You decide |
| U | AOL Companion | companion.exe | The AOL Companion is a small window that appears when you connect to the service using verison 8.0 and early builds of version 9.0. "Use the Companion to quickly get to your favourite features, including your Buddy List, Favourite Places, Address Book, and more!" |
| X | Aol Configuration Loader | aimsng.exe | Added by the SDBOT-XE WORM! |
| N | AOL Fast Start | AOL.exe | Fast Start loads the AOL integrated email, instant messenger and web browser software in the background when you turn on your computer. This feature lets you quickly open AOL |
| X | AOL Instant Messanger | aim.exe | Added by the SDBOT-YT WORM! Note - this is not the popular AOL Instant Messenger utility |
| X | AOL Instant Messengar | aol.exe | Added by the AGOBOT-FN WORM! |
| X | AOL Instant Messenger | AlM.EXE | Added by unidentified malware. Note - there ia a lower case "L" between the A and M in the filename |
| X | Aol Instant Messenger | aolmsg.exe | Added by the KELVIR.AL WORM! |
| X | AOL Instant Messenger | aimsgr.exe | Added by the IRCBOT.N TROJAN! |
| X | AOL Instant Messenger 7.213 | aim9283.exe | Added by the SDBOT-ZF WORM! |
| X | AOL Instant Messenger dll runtime | MSAOL32dll.exe | Added by the RBOT-ATA WORM! |
| X | Aol Instant Messenger Fix | aolfix.exe | Added by the SDBOT-ABJ WORM! |
| X | AOL Messenger | [random filename] | Added by an unidentified VIRUS, WORM or TROJAN! |
| X | AOL Messenger | aolmsngr.exe | Added by the SDBOT-JF WORM! |
| X | AOL Messenger Optimized | AOLOpt.exe | Added by the AOLOPT TROJAN! |
| N | AOL Service Libraries | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" |
| X | AOL Services Hosts | aolserviceshosts.exe | Added by an unidentified WORM or TROJAN! |
| U | AOL Spyware Protection | AOLSP Scheduler.exe | AOL's spyware protection program |
| U | AOL TopSpeedMonitor | aoltsmon.exe | AOL's TopSpeed "web-acceleration technology speeds up your web-browsing experience by storing and reusing elements of web pages that you visit, so pages appear much quicker on your next visit". Most important for those users who still access AOL via dial-up. Starts via a registry "RunServices" key on Windows 98/Me and as a service on Windows 2K/XP/Vista |
| Y | AolAcsDaemon1 | Acsd.exe | AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. This version is obsolete and has been replaced by AOLACSD.EXE so update your version of AOL. Starts via a registry "RunServices" key on Windows 98/Me and as a service on Windows 2K/XP/Vista |
| Y | AolAcsDaemon1 | AOLACSD.EXE | AOL Connectivity Service - automatically restores the connection to AOL should you lose it while online. Negates having to go through the procedure of signing back on manually. Starts via a registry "RunServices" key on Windows 98/Me and as a service on Windows 2K/XP/Vista |
| ? | AOLCC | ACCAgnt.exe | AOL ISP software related, file located in a "AOL Computer Check-Up" folder. What does it do and is it required? |
| X | AolCon | config.com | Added by the TAPLAK WORM! |
| N | AOLDialer | AOLDial.exe | AOL ISP software dialer - can be activated through a desktop shortcut |
| N | AolFix | AolFix.exe | Run on Gateway Astra computers, and maybe a few others. Designed to repair a bad registry key in Gateway computers that would not allow AOL to run correctly. Not seen much any more and should only run once |
| X | AOLRegKey32 | AOREGSVR512.EXE | Unidentified malware - see here |
| ? | AOLSAV | AOLAgent.exe | AOL ISP related. What does it do and is it required? |
| N | AOLSoftware | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" |
| X | AOLSPYWAREREMOVER32 | AOLSPYWARECLEANER32.EXE | Added by the SPYBOT-HJ WORM! |
| X | AOLStart | AOLStart.exe | Added by the KRAIMER.12 TROJAN! |
| X | aolupdater.exe | aolupdater.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Aornum | aornum.exe | Installed along with iWon Prize Machine. Based upon their privacy statement this can be regarded as spyware |
| N | AOTray | AOTray.Exe | System Tray application for AOpen soundcards. Can be run manually via Start -> Settings -> Control Panel |
| X | aouei | sysrtmvs.exe | Chivio dialer |
| X | ap.exe | ap.exe | SP Center and Control Center rogue security software - not recommended, removal instructions here and here |
| Y | APC UPS Status | Display.exe | APC PowerChute® Personal Edition status icon |
| U | APC_SERVICE | mainserv.exe | APC PowerChute® Personal Edition - "safe system shutdown software with sophisticated power management functions." Appears as a service in XP/Vista and under the "RunServices" registry key in Win98 |
| Y | apc_tray | apc_tray.exe | Part of the APC UPS software loaded with the BACK-UPS CS 350 unit. Required to monitor the APC unit in case of power failure |
| X | APcDefender | APcDefender.exe | APcDefender rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | APCProtect.exe | APCProtect.exe | APCProtect rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | APcSafe | APcSafe.exe | APcSafe rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | APcSecure | APcSecure.exe | APcSecure rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | APD123 | APD123.exe | PacerD Media/Pacimedia.com adware |
| N | apdproxy | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE and older versions of Photoshop Elements and Photoshop Lightroom image editing tools. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example |
| X | aphex | aphex.exe | Added by the IRCBOT-OH TROJAN! |
| X | Api**.exe [* = random char] | Api**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Api**32.exe [* = random char] | Api**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | API32 | api32.exe | Added by the IRCBOT-B TROJAN! |
| X | api32 | apiqq.exe | Added by the AGENT-OOU TROJAN! |
| X | APIClass | lexplore_.exe | Added by the MSNOPT-A TROJAN! |
| X | APIMon | apimonx.exe | Added by the TIBSER.A downloader TROJAN! |
| X | APIMon | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | APIMon | msreg.exe | Added by the DROPPER.Z TROJAN! |
| X | apisvc.exe | apisvc.exe | Added by a variant of the LAMEBOT TROJAN! |
| U | APL | APL.exe | Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application |
| X | apmanager.exe | apmanager.exe | AP Manager ransomware download manager - not recommended, removal instructions here |
| ? | Apmsrv9x | APMSRV9X.EXE | Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required? |
| N | ApnUpdater | Updater.exe | Updater for the Ask.com toolbar with is bundled with many 3rd party applications. Also see this note |
| U | Apoint | Apoint.exe | Touchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work |
| X | App**.exe [* = random char] | App**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | App**32.exe [* = random char] | App**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | App.EXEName | [path to worm] | Added by the BODIRU WORM! |
| X | ApPache System | ApPache.exe | Added by the RBOT-YP BACKDOOR! |
| U | Appcon | vAppCon.exe | Vital Application Console - part of POS-partner 2000 point-of-sale software that enables merchants in multiple industries to accept and process payments. Originally developed by Vital Processing Services. Taskbar icon enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established |
| X | appconn | appconn.exe | Added by the CARGAO WORM! |
| U | AppExtender | AppExtCB.exe | Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received |
| X | appis.exe | appis.exe | Added by the AGENT-BC TROJAN! |
| X | Apple iPod Service | iTunes.exe | Added by the AUTORUN-BLL WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %AppData% |
| U | AppleSyncNotifier | AppleSyncNotifier.exe | Part of Apple's MobileMe software and also installed with version 7.7 of the iTunes media management software. Enables users of iPhone, iPod Touch and iPad devices to synchronize their emails and calendars on every device and computer they use - whether its a desktop, laptop or a Mac. Also see here for more information |
| X | AppletINIT | INITIATE.EXE | Added by the AGOBOT.XV TROJAN! |
| Y | Application | mdmsetsp.exe | Aztech Labs modem driver |
| X | Application | csrss.exe | Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Application Adapter | abvsvc.exe | Added by the CHECKOUT WORM! |
| U | Application Explorer | Naldesk.exe | Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components." |
| U | Application Explorer | NalView.exe | Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications |
| X | Application Explorer | appexplr.exe | Added by the AGENT-NMO TROJAN! |
| X | Application In System | Snxmsh.exe | Added by the AGENT-LNV TROJAN! |
| N | Application Launcher | Application Launcher.exe | System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone |
| X | Application Layer Browser | abgsvc.exe | Added by the ULPM.FX TROJAN! |
| X | Application Layer Gateway Service | algs.exe | Added by the LINKBOT.M WORM! |
| X | Application Layer Gateway Service | x32.exe | Added by the POISON-AG TROJAN! |
| X | Application Layer Scheduler | agtsvc.exe | Added by the IRCBOT.BJJ BACKDOOR! |
| X | Application Layer Services | avrsvc.exe | Added by the IRCBOT.BJM BACKDOOR! |
| X | Application Manager | acnsvc.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Application Manager | apnsvc.exe | Added by the SMALLTRO.FN TROJAN! |
| U | applicationgateway | svchost.exe | PCProwler surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\MSWSPXP\!Executables\Release |