| Status | Autorun name | Command | Description |
| N | apdproxy | apdproxy.exe | Part of Adobe's discontinued Photoshop Album SE and older versions of Photoshop Elements and Photoshop Lightroom image editing tools. As well as providing System Tray access to the main program this entry detects when a device containing images is connected (such as a USB memory stick, camera or mobile phone) and offers you the chance to import these into your image library - see here for example |
| X | aphex | aphex.exe | Added by the IRCBOT-OH TROJAN! |
| X | Api**.exe [* = random char] | Api**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | Api**32.exe [* = random char] | Api**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | API32 | api32.exe | Added by the IRCBOT-B TROJAN! |
| X | api32 | apiqq.exe | Added by the AGENT-OOU TROJAN! |
| X | APIClass | lexplore_.exe | Added by the MSNOPT-A TROJAN! |
| X | APIMon | apimonx.exe | Added by the TIBSER.A downloader TROJAN! |
| X | APIMon | winapix.exe | Added by a variant of the TIBSER.A downloader TROJAN! |
| X | APIMon | msreg.exe | Added by the DROPPER.Z TROJAN! |
| X | apisvc.exe | apisvc.exe | Added by a variant of the LAMEBOT TROJAN! |
| U | APL | APL.exe | Sage Software's ACT! The application pre-loader (apl.exe) is a self contained executable that pre-loads the necessary .NET framework and ACT! 2005 assemblies. This pre-loading of assemblies enhances ACT! startup, view load and dialog load times in some areas of the application |
| X | apmanager.exe | apmanager.exe | AP Manager ransomware download manager - not recommended, removal instructions here |
| ? | Apmsrv9x | APMSRV9X.EXE | Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required? |
| N | ApnUpdater | Updater.exe | Updater for the Ask.com toolbar with is bundled with many 3rd party applications. Also see this note |
| U | Apoint | Apoint.exe | Touchpad software for laptop PC's. For instance it is found on the Panasonic and Sony Vaio machines and allows part of the touchpad to be used for document or Web-page scrolling. Required for proper functioning of the pointing software but not required for the laptop to work |
| X | App**.exe [* = random char] | App**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | App**32.exe [* = random char] | App**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | App.EXEName | [path to worm] | Added by the BODIRU WORM! |
| X | ApPache System | ApPache.exe | Added by the RBOT-YP BACKDOOR! |
| U | Appcon | vAppCon.exe | Vital Application Console - part of POS-partner 2000 point-of-sale software that enables merchants in multiple industries to accept and process payments. Originally developed by Vital Processing Services. Taskbar icon enabled at startup by the "Auto-start when OS starts" option. Required for a connection to be established |
| X | appconn | appconn.exe | Added by the CARGAO WORM! |
| U | AppExtender | AppExtCB.exe | Loads the Confimax add-in for popular E-mail programs to confirm E-mails have been sent and received |
| X | appis.exe | appis.exe | Added by the AGENT-BC TROJAN! |
| X | Apple iPod Service | iTunes.exe | Added by the AUTORUN-BLL WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %AppData% |
| U | AppleSyncNotifier | AppleSyncNotifier.exe | Part of Apple's MobileMe software and also installed with version 7.7 of the iTunes media management software. Enables users of iPhone, iPod Touch and iPad devices to synchronize their emails and calendars on every device and computer they use - whether its a desktop, laptop or a Mac. Also see here for more information |
| X | AppletINIT | INITIATE.EXE | Added by the AGOBOT.XV TROJAN! |
| Y | Application | mdmsetsp.exe | Aztech Labs modem driver |
| X | Application | csrss.exe | Added by the BEAGLE.EG WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Application Adapter | abvsvc.exe | Added by the CHECKOUT WORM! |
| U | Application Explorer | Naldesk.exe | Novell Zenworks Application Explorer Executable. "For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components." |
| U | Application Explorer | NalView.exe | Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications |
| X | Application Explorer | appexplr.exe | Added by the AGENT-NMO TROJAN! |
| X | Application In System | Snxmsh.exe | Added by the AGENT-LNV TROJAN! |
| N | Application Launcher | Application Launcher.exe | System Tray access to the Sony Ericsson PC Suite and HTC Sync mobile phone management utilities. Run manually via the Start Menu (or optional desktop shortcut) before connecting the phone |
| X | Application Layer Browser | abgsvc.exe | Added by the ULPM.FX TROJAN! |
| X | Application Layer Gateway Service | algs.exe | Added by the LINKBOT.M WORM! |
| X | Application Layer Gateway Service | x32.exe | Added by the POISON-AG TROJAN! |
| X | Application Layer Scheduler | agtsvc.exe | Added by the IRCBOT.BJJ BACKDOOR! |
| X | Application Layer Services | avrsvc.exe | Added by the IRCBOT.BJM BACKDOOR! |
| X | Application Manager | acnsvc.exe | Added by a variant of the IRCBOT TROJAN! |
| X | Application Manager | apnsvc.exe | Added by the SMALLTRO.FN TROJAN! |
| U | applicationgateway | svchost.exe | PCProwler surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\MSWSPXP\!Executables\Release |
| X | ApplicationProtocolRun | smsbvl32.exe | Added by the IRCBOT-CX TROJAN! |
| U | AppPlus | AppPlus.exe | AppPlus - "menu bar or tray launcher that docks to your desktop, floats or sits in your System Tray. Create graphic/text-based buttons that launch any number of programs, Websites, e-mail addresses or folders (which open in the AppPlus Menu System)" |
| ? | ApproveItForOfficeSetup | ApproveItForOfficeSetup.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? |
| X | Appstart | Appstart.exe | Added by the BANKER.CUE TROJAN! |
| X | APRfx | lzxconf.exe | Added by the AGENT-DML TROJAN! |
| ? | AprvRemoveLegacyExcelKeys | AprvClean.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? |
| ? | AprvRemoveLegacyWordKeys | AprvClean.exe | Related to ApproveIt Desktop from Silanis Technology Inc - "off-the-shelf electronic approval software for the automation of business approval processes within and amongst enterprises." What does it do and is it required? |
| Y | Apvxd | APVXDWIN.EXE | Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection |
| Y | Apvxdwin | APVXDWIN.EXE | Part of Panda Antivirus and Internet Security. Required to enable permanent virus protection |
| Y | APVXDWIN | ClShield.exe | "Panda ClientShield with TruPrevent is designed for companies that want the best protection for their workstations. It protects against viruses and other known and unknown threats including spam, spyware, dangerous or time-wasting content, phishing scams, hackers and intruders" |
| X | Apvxdwin | APVXDWIN.exe | Added by the LAZAR.B TROJAN! Note - this is not the legitimate Panda security file with the same name which is located in a %Program Files%\Panda Software sub-directory. This one is located in %System% |
| Y | Apwheel | Apwheel.exe | Wheel support for an Alps mouse |
| X | apyginapygin | simenu.exe | Added by the SDBOT.BTR WORM! |
| U | AQ3HelperStartUp | AQ3HEL~1.EXE | ScreenScenes "Aquatica Water Worlds" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | aqadcup | aqadcup.exe | Added by the AGENT.BG BACKDOOR! |
| Y | Aqua Dock | Aqua Dock.exe | Aqua Dock - 'free program that allows you to have an "OS X" style, nice animated launchbar/taskbar on your screen that reacts to your mouse when you mouse over it. Users can customize the look of each item on the dock and set various animation options for when the mouse is over an item on the dock. It is very easy to configure' |
| U | Aquarium Desktop | AquariumDesktop.exe | Animated desktop gadget included with the Aquarium Desktop theme for MyColors from Stardock Corporation |
| U | Aquarium Desktop | AquariumDesktop2006.exe | Animated desktop gadget included with the Aquarium 2006 theme for MyColors from Stardock Corporation |
| X | Aqujyjax | [path to file] | Added by the RANCK-CQ TROJAN! |
| X | Aqujyjax | aqujyjax.exe | Added by the SDBOT-YC WORM! |
| X | ara-key | [random filename] | Added by the ANTINNY WORM! |
| ? | ArabLionZ Drive | ArabLionZ.Drive.exe | ArabLionZ Drive - part of ArabLionZ XP Tools. What does it do and is it required? |
| Y | ArcaCheck | ArcaCheck.exe | Part of the ArcaVir antivirus suite from Polish company Arcabit. What does this part do? |
| N | ArcadeDeluxeAgent | ArcadeDeluxeAgent.exe | Part of the re-branded version of CyberLink's PowerCinema digital home entertainment software included on some Acer systems. Equivalent to the PCMAgent.exe entry and speeds up the launch of the main program. Only required on slower/older systems and if disabled it loads when required via an instance of svchost.exe |
| X | arcaderockstar | arcaderockstar32.exe | Arcade Rockstar (now Gamevance) - free arcade games and prize tournaments. The program itself is clean, but the TOS and privacy statement say that you agree to allow the program to track/report your surfing and put popup advertising on your computer |
| X | Archive | archive.exe | Adware - detected by Kaspersky as the CENTIM.A TROJAN! |
| X | ARCHIVE CONTROL | fixupdattr.exe | Added by the MYTOB.GU WORM! |
| N | ArcSoft Connect | ACDaemon.exe | Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia, PhotoStudio 6 and Print Creations. Set the associated ArcSoft Connect Daemon (ACService.exe) service to Manual (via Start → Control Panel → Administrative Tools → Services) and run this entry manually via the Start menu when required |
| N | ArcSoft Connection Service | ACDaemon.exe | Used to serve notice of product information and updates when running ArcSoft products such as TotalMedia, PhotoStudio 6 and Print Creations. Set the associated ArcSoft Connect Daemon (ACService.exe) service to Manual (via Start → Control Panel → Administrative Tools → Services) and run this entry manually via the Start menu when required |
| N | ARCSolo Recovery | N/A | Backup software by Computer Associates - no longer supported |
| U | Arctosa | razerhid.exe | Razer Arctosa gaming keyboard driver - required if you use the additional features and programmed keys/macros |
| U | Ardamax Keylogger | akl.exe | Ardakey keystroke logger/monitoring program - remove unless you installed it yourself! |
| N | ares | ares.exe | "Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc" |
| N | areslite | AresLite.exe | "Ares is a free open source file sharing program that enables users to share any digital file including images, audio, video, software, documents, etc" |
| U | Argentum Backup | ab.exe | Argentum Backup - a small backup program that lets you easily back up your documents and folders |
| X | argq32 | csrss_32.exe | Added by the RBOT-CPM WORM! |
| X | Aritima | aritima.exe | Added by the ARITIM WORM! |
| X | Arman | [path to worm] | Added by the IRCBOT-TG WORM! |
| U | ARMOR2NET | Armor2net.exe | Related to Armor2net personal firewall (possibly contains or is related to a product known as ArmorWall - which is a known rogue, see here - hence the "U" recommendation) |
| X | ArmorDefender | ArmorDefender.exe | ArmorDefender rogue security software - not recommended, removal instructions here |
| U | army logo | readmename.exe | Torrent101 potentially unwanted torrent client application that installs a Browser Helper Object and displays advertisements |
| X | aromis | aromis.exe | Added by the NUWAR.JQ WORM! |
| N | AROReminder | aro.exe | Advanced Registry Optimizer - "scan, identify, clean and repair errors in your Windows registry with a single click". Reminder that states that you are in trial mode |
| U | Arovax AntiSpyware | arovaxantispyware.exe | Part of Arovax AntiSpyware from Arovax, LLC - that offers an "innovating, powerful, speedy and extremely easy to use Spyware protection program". Runs a system scan when Windows starts and adds a System Tray icon |
| Y | Arovax Shield | ArovaxShield.exe | Part of Arovax Shield from Arovax, LLC - that "detects and notifies you about all major online threats trying to penetrate your system, isolates & blocks them". Runs the main program in the background and adds a System Tray icon |
| U | arovaxantispyware | arovaxantispyware.exe | Part of Arovax AntiSpyware from Arovax, LLC - that offers an "innovating, powerful, speedy and extremely easy to use Spyware protection program". Runs a system scan when Windows starts and adds a System Tray icon |
| Y | ArovaxShield | ArovaxShield.exe | Part of Arovax Shield from Arovax, LLC - that "detects and notifies you about all major online threats trying to penetrate your system, isolates & blocks them". Runs the main program in the background and adds a System Tray icon |
| U | ARPWRMSG | ARPWRMSG.EXE | "Away Mode" feature added with Update Rollup 2 for Windows XP Media Center Edition 2005 that allows the computer to appear off to the user while it continues to perform tasks that do not require user input, such as recording television and viewing Media Center Extender sessions. For more information see here |
| U | Artera | arteraui.exe | Artera Turbo Internet Accelerator - "surf faster, boost download speed". Only required if you find it helps improve your performance |
| X | Arucer | rundll32 Arucer.dll,Arucer | Provides support for the Energizer UsbCharger (Energizer UsbCharger.exe) utility that detects and shows the charging status for the Energizer® Duo USB/mains battery charger. Note - it appears that the product has now been withdrawn from the Energizer product line-up after it was discovered that this file contains the ARUGIZER TROJAN |
| X | Arucer Dynamic Link Library | rundll32 Arucer.dll,Arucer | Provides support for the Energizer UsbCharger (Energizer UsbCharger.exe) utility that detects and shows the charging status for the Energizer® Duo USB/mains battery charger. Note - it appears that the product has now been withdrawn from the Energizer product line-up after it was discovered that this file contains the ARUGIZER TROJAN |
| ? | AS00 Gear511 | Gear511.exe | Software for Netgear wireless network cards. Unknown whether it is required for the wireless card to run but does not seem to be a resource hog. Not required for laptop to run if the wireless network card will not be used. Is it at all required? |
| U | AS00_WN511B | WN511B.exe | Netgear RangeMax NEXT wireless adapter configuration utility |
| ? | AS00_WPN511 | WPN511.exe | NetgearRev MFC Application - software for Netgear wireless network cards - what does it do and is it required in startup? |
| Y | ASA.exe | ASA.exe | Bell Aliant Servicepoint Agent tool installed when you choose to install their internet security suite - sourced by Radialpoint. Apart from downloading the suite installation files, the exact purpose is unknown at this time but it may be used to source critical updates and alerts so should therefore be left enabled |
| X | asam | asam.exe | Added by the FAKEAV-BGU TROJAN! |
| X | ASC-AntiSpyware | WinCleaner.exe | WinCleaner 2009 rogue security software - not recommended, removal instructions here |