| Status | Autorun name | Command | Description |
| N | HGTXPEI | FirstReboot.exe | Herucles Audio tool for the Hercules Game Theater XP soundcard. Available via Start -> Settings -> Control Panel |
| X | Hhjg5jfd93dftdf | winlogan.exe | Added by the ERTFOR.A TROJAN! |
| X | hhtnsn | rnxntup.exe | Added by a variant of the ORCU.B TROJAN! |
| ? | HiberMonitor | HCount.exe | ?? |
| U | Hibernation | hib32.exe | Reduces the power consumption when the laptop isn't being used to preserve battery power. Similar programs on other laptops reduce the processor clock rate, etc. Required if you run of battery regularly |
| X | Hid.exe | hid.exe | Added by the RATSOU.B TROJAN! |
| X | hid_start | gzmrotate.dll | AdRotator/IconAds adware |
| U | Hide and Protect any Drives for Win95/98/Me/2k/XP | HPDAgent.exe | Loads Hide and Protect any Drives - which allows you to "Protect Hard drive, CD, DVD, floppy and flash, and deny access to partitions of your hard drives. Stop unauthorized software installations and data leak by removable media". If disabled, hidden and locked drives still retain their original status so the user will only be able to change their status them via the main UI |
| X | hiden | hiden.exe | Added by the AGENT-IW TROJAN! |
| U | HideOE | HideOE.exe | HideOE - allows you to 'hide' Outlook Express or minimize it to the System Tray |
| X | HideRun.exe | Hiderun.exe and svhost.exe and pro.gif | Added by the BOOHOO WORM! |
| X | HideStyle | Ante Browse Trust.exe | IE toolbar taking you to Lop.com. If the exe is running, close it and remove the %ProgramFiles%\Stupidmore directory |
| U | Hidetools Spy Monitor | wmispe.exe | HideTools Spy Monitor surveillance software. Uninstall this software unless you put it there yourself |
| U | hidserv | hidserv.exe | This is the Human Interface Device Server for Win98SE/2000/Me/XP, it is required only if you are using USB Audio Devices you can disable via Msconfig. See here. Typical examples are USB multimedia keyboards with volume control and web-ready keyboards. For example - loaded by default with MS DSS80 Speakers because they have Volume, Mute and Bass controls on the speaker. Some users may experience problems disabling this - if this is the case then re-enable it. Equivalent to MMHid in Win98. On HP Computers, HIDSERV is the controller for the keyboard sound controls on the USB and PS/2 keyboards |
| X | Hidup_Susah | Pembantu.exe | Added by the SILLYFDC.BDM WORM! |
| U | High Definition Audio 屬性頁捷徑 | HDAudPropShortcut.exe | Realtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required. Chinese version |
| N | High Definition Audio -ominaisuussivun pikakuvake | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required. Finnish version |
| U | High Definition Audio Özellik Sayfası Kısayolu | HDAudPropShortcut.exe | Realtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required. Turkish version |
| N | High Definition Audio Özellik Sayfası Kısayolu | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required. Turkish version |
| U | High Definition Audio Property Page Shortcut | CHDAudPropShortcut.exe | Realtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required |
| N | High Definition Audio Property Page Shortcut | HDAShCut.exe | High definition audio page shortcut for Realtek audio devices - not required |
| U | High Definition Audio Property Page Shortcut | HDAudPropShortcut.exe | Realtek audio card related. Probably adds the odd feature to one of the "Sounds" Control Panel applet tabs - doesn't appear to be required |
| X | HighKey1 | HighKey1.exe | Detected by AVG as GENERIC12.LHE - see here |
| Y | HighPoint ATA RAID Management Software | raidman.exe | HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID |
| X | Highspeeddownloader | SetupClickHere.EXE | Homepage hijacker, redirecting to "turbo-search101.com" - see here |
| U | HijackThis | HijackThis.exe | "HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware, malware or other unwanted programs". This option is added when you select Config → "Run HijackThis scan at startup..." once a scan has been performed |
| U | HijackThis startup scan | HijackThis.exe | "HijackThis is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware, malware or other unwanted programs". This option is added when you select Config → "Run HijackThis scan at startup..." once a scan has been performed |
| X | HijSrv32 | hijsrv.exe | Added by the BANKGERM-D TROJAN! |
| X | himem.exe | [path to worm] | Added by the STRATION-FW WORM! |
| X | HistoriaLout. | GDC.exe | HistoriaLout. rogue privacy tool - not recommended. A member of the PCPrivacyTool family |
| N | HistoryKill | histkill.exe | HistoryKill removes your web surfing path by removing the URL drop-list history, detailed history file, cache, and cookies in both IE and Netscape Navigator browsers. Available via Start -> Programs |
| U | Hitman Pro SurfRight Helper | srhelper.exe | Hitman Pro - a utility to start a number of Security Protection software. They can be started individualy |
| X | HitQ | HitQ.exe | Hijacker, for more information see here |
| U | HitwarePKLite | HITWAR~1.EXE | Hitware Popup Killer Lite |
| X | HIV | HIV.exe | Added by the HIVA TROJAN! |
| X | hiwi | 2qw9.exe | Added by the VB.AQQA TROJAN! |
| U | hk | hk.exe | KeyLoggerExp keystroke logger/monitoring program - remove unless you installed it yourself! |
| U | hkcmd | hkcmd.exe | Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and screen rotation via pre-programmed key combinations - such as CTRL+ALT+F12 which displays the graphics properties (otherwise available via a right-click on the desktop or the Control Panel). Different chipset versions may have different pre-programmed settings and in some cases these may be programmable |
| X | HKCU | server.exe | Added by the AGENT-NLT TROJAN! |
| X | HKCU | wininit.exe | Added by the MDROP-CY MALWARE! Note - this is not the legitimate wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" sub-folder |
| X | HKCU | addon.exe | Mega Antivirus 2012 rogue security software - not recommended, removal instructions here |
| X | hkey | dll | MOLEULTR-A malware |
| X | HKEYok | runlli32.exe | Added by the QQPASS-U TROJAN! |
| X | HKLM | server.exe | Added by the AGENT-NLT TROJAN! |
| X | HKLM | wininit.exe | Added by the MDROP-CY MALWARE! Note - this is not the legitimate wininit.exe process from Vista/7 which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an "install" sub-folder |
| X | HKLM\\Run | svhost.exe | Added by the FORBOT-AO BACKDOOR (where HKLM\\Run represents HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run)! |
| X | HKLM\Run | windowsupdate.exe | Added by the FORBOT-BJ WORM (where HKLM\Run represents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run)! |
| U | hkserv | HKserv.exe | Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS |
| U | HKSERV.EXE | HKserv.exe | Keyboard manager program required to use programmable power and function keys on some laptops such as the Sony PCG R505TS |
| U | hkss | hkss.exe | Compaq HotKey Support - multimedia keyboard support |
| X | HLcleanup | hlsetup2.exe | LinkReplacer/FFinder adware |
| X | hldrrr | hldrrr.exe | Added by the BAGLE-KF WORM! |
| X | hlhtxo.exe | hlhtxo.exe | Added by the QLOWZONES-27 TROJAN! |
| X | HLL Data Parameter | hllcxpa.exe | Added by the RBOT.AFG WORM! |
| X | HMI PowerSystem | hmisvc32.exe | Added by the RANDEX.CZZ WORM! |
| X | HML PowerSource | hmlsvc32.exe | Added by the SDBOT-XL WORM! |
| U | hmonitor | hmonitor.exe | Hardware Sensors Monitor by AB Software - "utilizes sensor chips on smart motherboards to track system and CPU core temperatures, voltages and cooling fans." Only required if you overclock your system or live in a hot environment and want to monitor the status or execute tasks such as sounding audio alarms are shutting down the computer |
| X | HMV PowerSource | hmusvc32.exe | Added by the SDBOT-YW WORM! |
| X | ho2stdll.exe | ho2stdll.exe | Added by the BANKER-HO TROJAN! |
| X | hohohhaha | ournik.com | Added by the IRCFLOOD.AL BACKDOOR! |
| X | HOI Services | holsvc32.exe | Added by the AGOBOT-SF WORM! |
| N | Holiday Lights | Holiday Lights.exe | Holiday Lights from Tiger Technologies. Festive desktop enhancement that adds lights. Available via Start -> Programs |
| U | HolidayCalendar | HolidayCalendar.exe | Calendar gadget included with a theme for MyColors from Stardock Corporation |
| X | Hollaback | slvhosts.exe | Added by the SDBOT.BMO WORM! |
| X | Home Antivirus 2010 | HomeAntivirus2010.exe | Home Antivirus 2010 rogue security software - not recommended, removal instructions here |
| N | Home Theater SchSvr | SchSvr.exe | WinScheduler is installed with Home Theater Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card, you will need it. Available via Start -> Programs |
| U | HomeAlarm | HomeAlarm.exe | Chameleon Clock - system tray clock replacement |
| X | HomeAntivirus 2009 | HomeAntivirus2009.exe | HomeAntivirus 2009 rogue security software - not recommended, removal instructions here |
| X | HomeAV | homeav.exe | Home Personal Antivirus rogue security software - not recommended, removal instructions here |
| ? | HomeCentre WakeUp | LGWAKEUP.EXE | Associated with the no longer supported Xerox HomeCentre printer/scanner |
| U | HomeKeyLogger | KeyLogger.exe | SpyKeySpy surveillance software. Uninstall this software unless you put it there yourself |
| X | Homeland Network | HomelandNetwork.exe | Homeland Network Notifier - pops ads |
| X | homepage.monitor.exe | isamonitor.exe | Added by the ZLOB.MEDIA-CODEC TROJAN! This purports to be a Windows Media Player upgrade (with names such as "iCodecPack", "X Password Manager" and "Media-Codec") to allow the user to view adult oriented videos on certain websites - but actually downloads and installs additional malware on the user's machine. Various directories and filenames are used - see the link for details |
| U | HondaHelper | HondaHelper.exe | Part of Honda Music Link which allows you to use your Honda's audio system's controls to play and search for music on your iPod® in you car |
| ? | Honor | honor.exe | ?? |
| U | Hook99startup | hk2re.exe | "Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons, bitmaps and can extract icons from executables and libraries. Hook99 can also make the background of desktop icons captions transparent" |
| U | HookSys | HookSys.exe | SurfinGuard Pro from Finjan - internet protection software, protects against all malicious code delivered through executables, scripting files, ActiveX and Java |
| U | HornetMonitor | MntrHrnt.exe | Hornet Monitor - monitoring system that detects and responds to unauthorized access attempts and sources of channel interference on any local DSSS network |
| Y | HorngTech4D | bally4d.exe | HorngTech 4D mouse driver |
| X | Host | N/A | Added by the POPDIS or STARTPAGE.F TROJANS! |
| X | host | help.exe | IESearchToolbar parasite. Identified by Ewido Security Suite (Ewido is now part of AVG Technologies) as the DELF.LF TROJAN! |
| X | Host Process | mame.exe | Added by the RBOT-APO WORM! |
| X | Host Process | svchost.exe | Added by the IRCBOT.AGF BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the Fonts directory |
| X | Host Process for Windows Tasks | taskhost.exe | Added by the BREDO-AI WORM! Note - this is not the valid Windows 7 process which has the same filename and the file description is also "Host Process for Windows Tasks". It is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | hostdll.exe | hostdll.exe | Added by the BANKER-BO TROJAN! |
| U | HostManager | AOLHostManager.exe | Manages a component essential to the operation of most current AOL software. If you remove it from startup it will load when IE is launched, increasing launching time |
| N | HostManager | AOLSoftware.exe | Quoted from AOL Beta Team, "Manages a component essential to the operation of most current AOL software, client or not. You should be able to remove it from Startup (it'll just load when Explorer is launched, which will extend load time a bit), but do leave it on your system" |
| X | Hostname Manager Server | host32srv.exe | Added by a variant of the RBOT WORM! |
| X | Hostren.exe | Hostren.exe | Added by PWS.BANKER.F, a variant of the BANKER-BO TROJAN! |
| X | hostserv | hostserv.exe | Added by the RBOT.BPZ WORM! |
| X | hostserv | wiz98.exe | Added by a variant of the SDBOT WORM! |
| U | HostsFileMgr | winHostsEdit.exe | AdBin from Gilmore Software Development. An easy solution to managing your Window's hosts file |
| U | HostsMan | hm.exe | "HostsMan is a freeware application that lets you manage your Hosts file with ease". It is mainly intended to block specific domains (mostly advertising servers) by redirecting them to localhost, but can also be used to add any other domain/Ip combination that you want to be included in the HOSTS file |
| X | HostSrv | sachostx.exe | Added by the LOOKSKY.H WORM! Drops multiple files in %System% |
| X | HostSrv | sachostx.exe | Added by the LOOKSKY.A or LOOKSKY.F or LOOKSKY.G WORMS! |
| X | HostSrv | sachostx.exe... | Added by the LOOKSKY.E WORM! |
| X | HostSVC syse | HostSVC.exe | Added by the RBOT-ANZ WORM! |
| X | Hot 8.0 Live | hot.exe | Added by the BANKER.EIE TROJAN! |
| U | Hot Corners | Hotc.exe | Hot Corners - "lets you quickly activate or disable your screen saver by moving the mouse into a given corner of the screen" |
| X | HOT FIX | Gothic.exe | Added by the SDBOT.FIR WORM! |