| Status | Autorun name | Command | Description |
| X | Intel system works | iis.exe | Added by the RBOT.QGA WORM! |
| U | Intel(R) Common User Interface | igfxtray.exe | System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and hot key settings via the icon on the System Tray. Different chipset versions may have different options available. These options are normally also available via the system Control Panel - under Display (XP) or Personalization and Appearance (Vista) |
| U | Intel(R) Common User Interface | hkcmd.exe | Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled, you can access settings like graphics properties and screen rotation via pre-programmed key combinations - such as CTRL+ALT+F12 which displays the graphics properties (otherwise available via a right-click on the desktop or the Control Panel). Different chipset versions may have different pre-programmed settings and in some cases these may be programmable |
| U | Intel(R) Common User Interface | igfxpers.exe | Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended "U" status |
| X | intel32.exe | intel32.exe | Added by the SmitFraud alias SPYJACK-B TROJAN! |
| U | IntelAPMClient | amclient.exe | LANDesk® Management Suite software component |
| N | IntelAudioStudio | IntelAudioStudio.exe | "Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience". Audio utility supplied with some Intel motherboards |
| X | InteliSys | smss.exe | Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | intell32.exe | intell32.exe | Added by the SmitFraud alias Desktophijack.C TROJAN! |
| X | intell321.exe | intell321.exe | Added by the SPYJACK-B TROJAN! |
| X | Intelli Mouse Pro Version 2.0B | ncsjapi32.exe | Added by the BUZUS-O WORM! |
| X | Intelliflag_be.exe | Intelliflag_be.exe | Intelliflag spyware |
| U | IntelliPoint | point32.exe | Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported |
| U | IntelliPoint | ipoint.exe | Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice, If this entry is disabled, any programmed buttons or program-specific settings will not be supported |
| U | Intellitype | type32.exe | Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys, programmed keys and key macros on Microsoft's range of keyboards. If this entry is disabled, any programmed keys or actions will not be supported and keys will not function as expected in applications with advanced text services enabled |
| U | IntelMEM | IntelMEM.exe | Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line |
| X | Intelprc | Aas3lovu.exe | Added by the SILLYFDC-CG WORM! |
| U | IntelProcNumUtility | cpunumber.exe | Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
| Y | IntelWireless | ifrmewrk.exe | Associated with the Intel PRO/Set Wireless software |
| U | IntelZeroConfig | ZCfgSvc.exe | Zero Config MFC Application, part of Intel's ProSET utilities and installed by the drivers for many of Intel wireless network cards - essential to the proper functioning of many of the Intel ProSET utilities (but not all) and these System Tray ProSET utilities are a must if you are using your wireless connection, if only so you know when the signal is fading or dropping. The problem is that, in some PCs, ZCFGSVC can be incredibly badly behaved : taking up to 100% of CPU time and therefore resulting in an extremely slow PC, preventing the installation of software or Windows updates, or causing "Not Responding" or "End this Program" shutdown problems. If you experience this, try first the very latest drivers from Intel or your laptop manufacturer. If that still does not solve the problem and you have WinXP/2003, try setting the "Wireless Zero Configuration" service to disabled |
| ? | Intense Registry Service | IntEdReg.exe /CHECK | Intense Educational Ltd - Language Office Software. Is it required? |
| X | InterceptedSystem | [path to worm] | Added by the ANACON-B WORM! |
| Y | InterCheck Monitor | ICMON.EXE | Part of an older version of Sophos anti-virus software |
| Y | InterCheckMonitor | ICMON.EXE | Part of an older version of Sophos anti-virus software |
| X | Interdll | Interdll.exe | Added by the DELF family of TROJANS! |
| X | Internal | [trojan filename] | Added by the SMOTHER and TRANSLAT TROJANS! |
| X | Internal | regedit.exe /s c[month number] | Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file "c[month number]" is located in %Windir%, ie, C:\Windows\c10 |
| X | Internal Memory File | sysintmemory.exe | Added by the RBOT-GKT WORM! |
| X | InternalSystray | Kazza.exe | Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable, this is located in %System% |
| X | internat | internat.exe | Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir% |
| X | Internat | systray.exe | Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the "Properties" reveal it to be a Microsoft file |
| X | Internat | msgsrv32.exe | Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup! |
| X | Internat | [trojan filename] | Added by the CMJSPY-Y TROJAN! |
| X | Internat Conf | bootconf.exe | Homepage hijacker, redirecting to coolwwwsearch.com; see for example here |
| N | internat.exe | internat.exe | Microsoft language selection icon in system tray, located in the System (Win98/Me) or System32 (WinNT/2K/XP) folder |
| X | Internat.exe | internat.exe | Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon |
| X | internat.exe | svchost.exe | Added by the DELF.AFJ BACKDOOR! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup! |
| X | internct | WinSocks5.exe | Added by the GRAYBIRD.F TROJAN! |
| X | internet | smss.exe | Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! |
| X | Internet | Internet.exe | Added by the PWS-CS TROJAN! |
| X | Internet | recruit.exe | Added by the RBOT-AJG WORM! |
| X | internet | [trojan filename].exe | Added by the MIFENG-D TROJAN! |
| X | Internet | winlogom.exe | Added by a variant of the SDBOT WORM! |
| X | Internet | nteusodp.exe | Added by the RBOT-GFJ WORM! |
| X | internet | winsas32.exe | Added by a variant of the SDBOT WORM! |
| X | internet | lsass.exe | Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup! |
| X | Internet | alm7tas.exe | Added by a variant of the RBOT WORM! |
| X | Internet | wins.exe | Added by the RBOT.AAYF WORM! |
| U | Internet Answering Machine | IAMNET~1.EXE | From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
| U | Internet Answering Machine | IAM.exe | From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access |
| X | Internet Antivirus | IAvir.exe | Internet Antivirus rogue security software - not recommended, removal instructions here |
| X | Internet Antivirus Pro | IAPro.exe | Internet Antivirus Pro rogue security software - not recommended, removal instructions here |
| X | Internet Application Driver | expIorer.exe | Added by the IRCBOT-WK TROJAN! |
| U | Internet Call Director | ICD.EXE | TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet |
| U | Internet Call Manager | ICM.EXE | Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
| X | Internet Config | svchosts.exe | Added by the SDBOT TROJAN! |
| X | Internet Connection Wizard | stisvsq.exe | EasySearch adware |
| X | Internet Connection Wizard | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Internet Connection Wizard | stisvsq1.exe | Added by the DLOADR-AWD TROJAN! |
| X | Internet Connection Wizard Setup Tool | icwsetup.exe | Added by the PINCAV.HJK TROJAN! |
| X | Internet Content Publisher | ICP.EXE | Added by the RBOT-UD WORM! |
| U | Internet Disk Cleaner | CLEARH~1.EXE | "Internet Disk Cleaner from Elongsoft "protects your privacy by cleaning up all Internet tracks and past computer activities" |
| U | Internet Download Accelerator | ida.exe | Internet Download Accelerator download manager |
| X | Internet download manager service | idman.exe | Added by the RBOT-BMS WORM! |
| X | Internet Exploere Services | urlmon32.dll.exe | Added by the EVIAN.C WORM! |
| X | Internet Explore Microsoft | lEXPLORE.EXE | Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case "L" rather than an lower or upper case "i" which is the case with Internet Explorer |
| X | Internet Explorer | iexplorer.exe | Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Internet Explorer | IEXPLORE.EXE | Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Internet Explorer | IExplorer.exe | Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Internet Explorer | http.exe | Added as part of a new potential CWS infection, and part of a suite of programs that installs a web server, php, ftp server, socks, and mail server on your computer without your knowledge. These files are known to be part of an infection that transmits information about your bank accounts, passwords, and other financial information. It should be deleted immediately, you should enable your firewall, and you should contact your financial services in order to report the issue and to have your passwords changed |
| X | Internet Explorer | iexpiore.exe | Added by the RBOT-AZC WORM! |
| X | Internet Explorer | IEPLORE32.EXE | Added by the AGOBOT-CU WORM! |
| X | Internet Explorer | twain.exe | Added by the AGENT.BEA TROJAN! |
| X | Internet Explorer Agent | iexplorer.exe | Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Internet Explorer Auto-Update | updt32v5.exe | Added by the SPYBOT-AB BACKDOOR! |
| X | Internet Explorer Configuration | IEXPLORE.EXE | Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Internet Explorer Plugin | Mskernel16.exe | Added by the BACKAGE BACKDOOR! |
| X | Internet Explorer Plugin | WinStop32.exe | Added by the BACKAGE BACKDOOR! |
| X | Internet Explorer Security | iexplore.pif | Added by the RBOT-ALQ WORM! |
| X | Internet Explorer Sys32 | isys32.exe | Added by the IRCBOT-ADA WORM! |
| X | Internet Explorer Updater | lexbac.exe | Added by the DOWNLOAD TROJAN! |
| X | Internet Explorer Updater | iexplorer.exe | Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) |
| X | Internet Explorer6 | IEexplore.exe | Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Internet Explorer6.0 | IEXPLORE.EXE | Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System% |
| X | Internet Firewall Layer | tsqla.exe | Added by a variant of the SPYBOT WORM! |
| U | Internet History Eraser | HERASER.exe | Internet History Eraser - deletes your browsing tracks |
| X | Internet Kernel | Mskernel16.exe | Added by the BACKAGE.C BACKDOOR! |
| X | Internet Loader1 | MSInstall61.exe | Added by the KWBOT.B WORM! |
| X | Internet Mail and News | msqdevl.exe | EasySearch adware |
| X | Internet Mail and News | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Internet Mail and News | msqdevl1.exe | Added by the DLOADR-AWD TROJAN! |
| X | Internet Optimizer | optimize.exe | Internet Optimizer parasite - detected by Sophos as the DLUCA-G TROJAN and variants |
| X | Internet Protocol Configuration Loader | ipcl32.exe | Added by the SDBOT TROJAN! |
| X | Internet Security 2010 | IS2010.exe | Internet Security 2010 rogue security software - not recommended, removal instructions here |
| X | Internet Security Service | msq32.exe | Added by the RBOT-GFP WORM! |
| X | Internet Security Service | msq23.exe | Added by the RBOT-GQL WORM! |
| X | Internet Security Service | msql23.exe | Added by the RBOT-GML WORM! |
| X | Internet Security Service | mysqlwin32.exe | Added by the RBOT.UX TROJAN! |
| X | Internet Security Service | expllorer.exe | Added by the REFROSO.AFF TROJAN! |
| Y | Internet Security Suite | Freedom.exe | Verizon Internet Security Suite - sourced by Freedom from Zero Knowledge, Inc (now Radialpoint). Provides anti-virus, personal firewall, parental controls and a pop-up blocker. Also safeguards your personal information, encrypts your passwords and much more. No longer available |