| Status | Autorun name | Command | Description |
| Y | TELUS eProtect | Rps.exe | Main program for the TELUS eProtect internet security suite for TELUS ISP customers - sourced by Radialpoint |
| Y | TELUS Security service | freedom.exe | TELUS Security service - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available |
| U | TELUS Support Centre | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS users |
| U | TELUS_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS users |
| U | TelusWCC_McciTrayApp | McciTrayApp.exe | System tray access to Motive's broadband configuration and repair utility - for TELUS Wireless users |
| X | TemizSurucu | GDC.exe | TemizSurucu Turkish rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| X | TempCom | [randomname].com | Added by the TRAXG WORM! |
| X | tempx | tempx.exe | Added by the TEMPEX.A TROJAN! |
| X | Tencent QQ | Rund1132.exe qq.dll, Rundll32 | Added by the QQPASS.F TROJAN! |
| N | Tencent QQ | QQ.exe | Tencent QQ Asian instant messanger program |
| Y | TEPA.exe | TEPA.exe | TELUS eProtect Advisor tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled |
| X | Terminal Services | mstscc.exe | Added by the SDBOT-CZW WORM! |
| X | Terminal Update | biosefui.exe | Added by the PPDOOR-O TROJAN! |
| X | Terminate Popup | ZPU.exe | Free Popup Killer - foistware proven to install the Regsvc32 homepage hijacker. Also see here |
| X | Terminate Popup | fpuk.exe | Popup killer - foistware proven to install the Regsvc32 homepage hijacker |
| U | TEscKey | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function |
| ? | Tesco Insert Detect | InsDetect.exe | Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted? |
| N | Tesco.net | rundll32 [path] RyDial.dll, QuickStart | Tesco.net dial-up ISP software - not required |
| ? | Tesla | TESLA.EXE | ?? |
| X | test | i love you.exe | Added by the SINGU-T TROJAN! |
| X | test | zistro.exe | Added by the KIMAT-C TROJAN! |
| X | Test* | Test.exe | Added by the AUTORUN-SG WORM - where * represent a number. If, for example, you have four physical hard drive partitions and one removable drive, the file "Test.exe" will be present in the root of the partition (ie, C:\, D:\) with startup entries of "Test1" through "Test5" |
| X | Test321 | fresdg.exe | Added by the HAMWEQ.DD WORM! See here |
| X | testest | fxxxh.exe | Added by the SDBOT-MK WORM! |
| X | Testing 123 | msdata.dat | Added by the NITS.A WORM! |
| X | testit.exe | testit.exe | ISTBar adware |
| X | Teth | drle.exe | PurityScan adware |
| ? | TExBUtil Registry | TExBUtil.exe | ?? |
| X | Text Tray Service | tstray.exe | Added by the SILLYFDC.BCC WORM! |
| N | TextAloud | TextAloudMP3.exe | TextAloud MP3 - convert text into spoken words and MP3s |
| N | Textbridge Instant Access OCR | telepath.exe | TextBridge from Nuance (was Scansoft). OCR (optical character recognition) software for scanning documents into popular editing applications. Available via Start -> Programs |
| X | TEXTCONV | services.exe | Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process, which should not appear in Msconfig/Startup! |
| X | TEXTCONV | winlogon.exe | Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process, which should not appear in Msconfig/Startup! |
| U | TFncKy | TFncky.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
| U | TFNF5 | TFNF5.exe | Toshiba Hotkey Utility for Display Devices. By pressing <FN> + <F5>, a window appears showing the displays that can be chosen - LCD, LCD + CRT, CRT, TV |
| Y | tfswctrl | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
| Y | tfswctrl.exe | tfswctrl.exe | Drive letter access to a UDF packet writer for CD-RW - from HP, Veritas an others. Similar to Roxio's DirectCD and does the same thing. From HP - "This is a needed file as it controles the readability of the Combo drives. Without this file loading the end user will be able to burn CD's but wont be able to read them. The drive itself will be able to read store bought master Cd's without the file but not burnt ones" |
| X | TFTP*** | tftp*** | Added by a variant of the SPYBOT WORM! where *** can be any number |
| Y | TFTray | TFTray.exe | System Tray access to ThreatFire no-signature anti-malware from PC Tools - which "features innovative real-time behavioral technology that provides powerful protection against both known and unknown viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware" |
| U | TFunckey | TFuncKey.exe | Deals with the <Fn> - <Function> key combinations on a Toshiba laptop |
| N | TgAddServer | tgfix.exe | Software from SupportSoft (aka Support.com) provided to manufacturers (such as Sony (Vaio Support Agent) and Toshiba (Virtual Tech)) and ISPs (such as Comcast, Cox and Charter (Pipeline Support Agent)) that allows them to offer on-line support - to update drivers, fix faults, etc. Can cause a deterioration in a PC's peformance (see here). This part does the protection and "self-healing". Uninstallation is recommended by most people - especially for System Restore users (WinME/XP). If not available via Add/Remove try here |
| X | tgbcde | module32.exe | Added by the REIGN.R TROJAN! |
| U | tgcmd | tgcmd.exe | Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| U | tgcmd | hcenter.exe | Bellsouth help center. Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| U | tgcmdprovidersbc | tgcmd.exe | Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers, fix faults, etc. Also see the TgAddServer entry. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox. Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation" |
| N | TGCMG | ?? | Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work |
| X | TGDC IE Plugin | tgdc.exe | ShopForGood spyware - see here |
| N | tgkill | tgkill.exe | Comcast struck a deal with Tioga to provide an "enhanced" support and self-repairing tool. This "beta" release was made available to download by mistake and should be removed via Start → Control Panel → Add/Remove Programs |
| N | TGPro Office | IdxOffice.exe | With IdiomaX Office Translator "you can translate documents directly from your favorite text editor (Microsoft Word, WordPerfect or Lotus WordPro)" |
| U | Tgsetsite | tgfix.exe | See also TgAddServer. This part ensures the software is installed correctly (similar to an installation wizard) as reported by Cox Regarded as spyware by some as it has the ability to retrieve user information. Whether it does so depends upon the provider. One Toshiba user reports problems with hibernate on his laptop if disabled - hence the "U" recommendation |
| U | THCS | svchost.exe | AllMonitor surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup. This one is located in a "drivers\imon" subfolder |
| ? | Thdetrf | thdetr32.exe | Appears to be related to Lycos advertising |
| X | ThE | wind0s.exe | Added by an unidentified WORM or TROJAN! |
| N | The Assistant | eSched.exe | Related to WinTotal from a la mode inc. FormFiller for appraisers |
| U | The Easy Bee's Hive | ATCEgSvr.exe | The Easy Bee is a software that allows you to record Internet navigation sequences, which can include form filling and button clicking and to attach a replay schedule to each sequence |
| X | The Ethernet | ethernet.exe | Added by a variant of the SDBOT WORM! |
| X | The Ethernet | intranet.exe | Added by a variant of the SDBOT WORM! |
| X | The Intranet | intranet.exe | Added by a variant of the SDBOT WORM! |
| X | The Monitor | [path to trojan] | Added by the VB-AXL TROJAN! |
| N | The Proxomitron | Proxomitron.exe | A free, highly flexible, user-configurable, small but very powerful, local HTTP web-filtering proxy - see here |
| X | The Registry Sentinel | The Registry Sentinel.exe | The Registry Sentinel rogue security software - not recommended, removal instructions here |
| X | The Service Pack Loader | spxp.exe | Added by the RBOT-BYM WORM! |
| X | The Spy Guard | spyguard.exe | The SpyGuard rogue spyware remover - not recommended, removal instructions here |
| X | The Spy Guard Monitor | spyguard_monitor.exe | The SpyGuard rogue spyware remover - not recommended, removal instructions here |
| X | The Web Sentinel | The Web Sentinel.exe | The Web Sentinel rogue security software - not recommended, removal instructions here |
| X | TheBestMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | TheDefend.exe | TheDefend.exe | TheDefend rogue security software - not recommended, removal instructions here. A member of the AntiAID family |
| X | TheLastDefender | LastDefender.exe | The Last Defender rogue security software - not recommended, removal instructions here |
| ? | TheMainStart | N/A | ?? |
| X | ThemeMP3 | rundll32.exe MSA64CHK.dll,DllMostrar | MatrixDialer/Mostrar parasite. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "MSA64CHK.dll" file is located in %System% |
| X | TheMonitor | [filename].exe | YourEnhancement downloader. The file is located in %Windir% |
| X | TheSpyBot | TheSpyBot.exe | TheSpyBot rogue security software - not recommended, removal instructions here |
| U | THGuard | TH_Guard.exe | Resident memory scanning for TrojanHunter |
| U | THGuard | THGuard.exe | Resident memory scanning for TrojanHunter |
| U | Think Green Weather | Think Green Weather.exe | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com |
| U | Think Green Weather | THINKG~1.EXE | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com |
| U | Think Green Weather.exe | Think Green Weather.exe | Weather gadget included with the free Think Green theme for MyColors from Stardock Corporation. Displays the current and forecasted weather for the selected location from AccuWeather.com |
| X | Think-Adz | [random filename] | Zeno Think-Adz adware |
| N | ThinkPad Configuration Utility | TP98TRAY.EXE | System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. "The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility, you can setup or change your device configurations for ThinkPad hardware and options" |
| U | ThinkPad EasyEject Utility | EzEjMnAp.Exe | EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually." Configuration and performing of EasyEject actions is available via Fn+F9 key combination on some models |
| N | ThinkPad EasyEject Utility | EZEJTRAY.EXE | System Tray access to the EasyEject Utility for IBM/Lenovo Thinkpad notebooks. Quote: "The IBM ThinkPad EasyEject Utility makes removing multiple devices from your computer faster and easier by enabling you to stop more than one device at once, rather than stopping each device individually." Configuration and performing of EasyEject actions is available via Fn+F9 key combination on some models |
| U | ThinkPad Presentation Director | NPDTray.exe | System Tray access to Presentation Director for IBM/Lenovo Thinkpad notebooks - which allows you to create and quickly select between various single and mulitple display options. Scheme selection and settings are also available via Fn+F7 key combination on some models |
| U | ThinkVantage Access Connections | ACTray.exe | System Tray access to the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically" |
| U | ThinkVantage Access Connections | ACWLIcon.exe | Part of the ThinkVantage Access Connections connectivity-assistant program for IBM/Lenovo ThinkPad or 3000 Family notebook computers - "allowing users to seamlessly switch between wired and wireless environments, managing security settings, printers, home page and other location-specific settings automatically." This is the System Tray icon giving notifications of and access to the Wireless Connection Status |
| Y | ThinkVantage Active Protection System | TpShocks.exe | Part of the Active Protection System found on some IBM/Lenovo Thinkpad models - including the T, W, X and Z series. This provides airbag-like protection for your hard drive as the system has "an integrated motion sensor that continuously monitors the movement of the notebook, and, if a sudden change in motion is detected, it temporarily stops the hard drive to protect it from a potential crash". The user can also temporarily suspend APS via the Start Menu or (optional) System Tray icon and view the real-time status |
| X | this free | bbb.exe | Added by the VB-DZG TROJAN! |
| X | this free | winsyst.exe | Added by the MADAG.A WORM! |
| X | This is a virus, please delete it | bigbadvirus.exe | Added by the RANDEX.F WORM! |
| U | Thoosje Vista Sidebar | Thoosje Vista Sidebar.exe | Thoosje's Vista Sidebar - sidebar and skins for microsoft Windows XP and Vista |
| U | THOTKEY | THotkey.exe | Associated with the Fn+ keys on Toshiba laptops. When disabled some keys still worked, like the one that regulates the volume of the system beep, but others didn't, like the one that immediately blackens your screen |
| Y | ThpSrv | thpsrv.exe | Toshiba Hard Drive Protection Utility - moves the Hard Drive head to a safe position in case of shock or vibration to reduce the risk of damage that could be caused by head-to-disk contact |
| X | Threaded | intcp32.exe | Added by the RANDEX.UG WORM! |
| Y | ThreatFire | TFTray.exe | System Tray access to ThreatFire no-signature anti-malware from PC Tools - which "features innovative real-time behavioral technology that provides powerful protection against both known and unknown viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware" |
| U | ThrustTSR | TMTMTSR.exe | Thrustmaster Thrustmapper - "t-mapper - icon sits on your taskbar and automatically detects when the joystick is plugged in and configures it accordingly" |
| X | Thumbs Plus *.* | thmbplus**.exe | Added by the AGOBOT-AAF WORM! ** is a combination of a random digits and characters |
| U | TI WLAN | TIWLANCu.exe | Texas Instruments TI wireless LAN products |
| X | Tibiabot | calc.exe | Added by the BACKDOOR-CEP!IC BACKDOOR! Note - this is not the valid Windows calculator which resides in %System% and will not normally figure in Msconfig/Startup! This version resides in %Windir% |
| X | tibs3 | tibs3.exe | Premium rate adult content dialler - see here |
| X | tibs5 | tibs5.exe | Premium rate adult content dialer - see here |
| ? | Ticket API Monitor | tktmon.exe | Syntegra Device Identification Logger. What does it do and is it required? |