| Status | Autorun name | Command | Description |
| Y | G DATA AntiVirus Tray Application | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security |
| Y | G DATA AntiVirus Trayapplication | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalCare, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates |
| Y | G Data InternetSecurity | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security |
| Y | G Data Personal Firewall | GDFirewallTray.exe | Part of the firewall included with the NotebookSecurity, TotalSecurity and InternetSecurity internet security products from G Data Software AG. Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it running. Also used by versions of Lavasoft's Ad-Aware Total Security |
| Y | G Data Security Software | AVKTray.exe | System Tray access to and notifications for the range of internet security products from G Data Software AG - including NotebookSecurity, TotalSecurity, InternetSecurity and AntiVirus. If this entry is disabled, the core product functions will work properly but you will lose quick access to the main window and miss notifications of potential problems and updates. Also used by versions of Lavasoft's Ad-Aware Total Security |
| X | g.exe | g.exe | Added by the GRAYBIRD.Q TROJAN! |
| X | G_Host | gHost.exe | Added by the AUTOIT-BP WORM! |
| X | G_Server.exe | G_Server.exe | Added by the FEUTEL-C TROJAN! |
| X | G_Server1.2.exe | G_Server1.2.exe | Added by the GRAYBIRD-Z TROJAN! |
| X | G00123 | [worm filename] | Added by the BUGBROS WORM! |
| X | G0mez | G0mez.vbs | Added by the GORMLEZ-A WORM! |
| X | G3 | GSMedia3.exe | Malware downloader - detected by Kaspersky as the VB.UX TROJAN! |
| ? | g3dctl | g3dctl.exe | ?? |
| X | G4G | [random filename] | Detected as Trojan-Downloader.Win32.VB.fki |
| U | G6FTP Server Tray Monitor | G6FTPTray.exe | System Tray monitoring tool for Gene6 FTP Server - "an advanced FTP server software for Windows developed specifically for security and high performance requirements" |
| X | ga6pcw | ga6pcw.exe | Part of the AVSystemCare rogue security software and other members of this family. See here for more examples |
| X | gabougool | nounina.exe | Added by the AGENT-JVX TROJAN! |
| X | gac | gac.exe | Part of VirusVakt, Swedish rogue security software - not recommended. A member of the AVSystemCare family |
| ? | GACService | GACService.exe | Related to a Gemplus product. What does it do and is it required? |
| X | gadcom | gadcom.exe | Added by the AGENT-HIC TROJAN! |
| X | gadkgak12 | fsafsakx12.exe | Added by the ONLINEG-N TROJAN! |
| N | Gadu-Gadu | gg.exe | Polish language Instant Messaging client |
| N | Gadwin PrintScreen | PrintScreen.exe | Gadwin PrintScreen - utility to capture, print or save the current window |
| X | GAELICUM.EXE | GAELICUM.EXE | Added by the PENTA-A TROJAN! |
| X | gah95on6 | gah95on6.exe | ShopAtHome/SAHagent adware |
| U | gaim | gaim.exe | Gaim is an instant messenger client with capability to connect to AIM, ICQ, MSN Messenger, Yahoo, IRC, Jabber, Gadu-Gadu and Zephyr networks |
| U | Gainward | TBPanel.exe | Configuration utility for Gainward graphics cards. Not required unless you use non-default settings. Available via Start -> Settings -> Control Panel |
| X | Gallery | thG.exe | Added by the AUTORUN-JR WORM! |
| ? | GalleryPlayerCM | GalleryPlayerCM.exe | Related to GalleryPlayer by RGB Labs - "Discover the easiest way to acquire, organize and display the world's finest art and photography: with GalleryPlayer you can own high definition art and photography from the world's finest museums and galleries." No longer available - is it required? |
| ? | GalleryPlayerDM | GalleryPlayerDM.exe | Related to GalleryPlayer by RGB Labs - "Discover the easiest way to acquire, organize and display the world's finest art and photography: with GalleryPlayer you can own high definition art and photography from the world's finest museums and galleries." No longer available - is it required? |
| X | game | shit.exe | Added by the Netclap Gold backdoor TROJAN! |
| X | game | patcher.scr | Added by the PSW-ED TROJAN! |
| N | Game Device | JOYUPDRV.EXE | Genius game controller profile activator |
| X | Game House | GameHouse.exe | Added by the DELF-DRA WORM! |
| N | GameDrive | GDTask.exe | GameDrive from FarStone - virtual CD/DVD drive emulator that allows you to run your PC games without the disc. Available via Start → Programs |
| X | Games Acceleration | svshost.exe | EasySearch adware |
| X | Games Acceleration | [path to trojan] | Added by the SMUTSRCH-A TROJAN! |
| X | Games Acceleration | svshost1.exe | Added by the DLOADR-AWD TROJAN! |
| X | Games toolbar | rundll32.exe [path] tbGame.dll DllShowTB | Topconverting.com/180Search "Games Toolbar" adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| N | GameSpot | kontiki.exe | Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops |
| N | GameTracker | GTLite.exe | GameTracker - "Keep track of and launch all your games from one application with the Game Tracker Client. Instantly announce on your profile and to your friends what game and on which server you are playing!" |
| U | gameutil.exe | gameutil.exe | Part of Redline RegTweak as supplied with Sapphire ATI graphics cards. You can configure different overlclocking settings on a per game basis and this sets those conditions following a re-boot |
| X | gamma | svchost.exe | Added by a variant of the DELF.IT TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! The location of this file varies |
| U | GammaHotKeys | setgamma.exe | Part of the RadeonTweaker program for adjusting ATI Radeon graphics cards. Allows you to adjust the gamma (or brightness) when playing a full-screen game without switching back to the desktop |
| X | gangsta | gangsta.exe | Added by the RIMA.A BACKDOOR! |
| U | GARO Status Monitor | cnwism.exe | Print monitor for certain Canon printers |
| X | gaSrv | gaSrv.exe | Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader |
| X | gaSrve | gaSrve.exe | Detected by Panda as the DOWNLOADER.ALQ TROJAN! Adware downloader |
| X | Gate Personal Firewall | Systpl.exe | Added by the RBOT.ADC WORM! |
| N | Gateway Extended Warranty | GWCares.exe | Gateway Extended Warranty reminder |
| X | Gator | gator.exe | Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | Gator eWallet | gator.exe | Gator eWallet adware. Please note that Claria Corporation no longer support GAIN-Supported software - see here |
| X | Gay_Sexy_** | Gay_Sexy_**.exe | Premium rate adult content dialler (where * is a random char) |
| U | GazelDisplay | gsyno.exe | BT Digital Access USB - Gazel ISDN installation System Tray icon |
| X | GB_Net_Protect | GB_Net_Protect.exe | Added by the BANKER-FBZ TROJAN! |
| Y | GBMHome7Agent | GBMAgent.exe | Genie Backup Manager Home 7 - backup software |
| Y | GBMLite7Agent | GBMAgent.exe | Genie Backup Manager Lite 7 - backup software |
| Y | GBMPro7Agent | GBMAgent.exe | Genie Backup Manager Pro 7 - backup software |
| X | Gbp Service | [path to trojan] | Added by the BANBRA.GQU TROJAN! The most common filename seen is "dchcp.exe" but examples have been seen where the filename is "spoolsvr32.exe" |
| Y | GBSpaceMan | SpaceMan.exe | GreenBorder - secure your browsing activities on the internet |
| X | gCac | gcac.exe | Added by the TACTSLAY.U TROJAN! |
| X | gcasDtServ | gcasDtServ.exe | Added by an unidentified WORM or TROJAN. Note - this is not related to Microsoft Antispyware which has a process bearing the same name which doesn't appear as a startup |
| Y | gcasServ | gcasServ.exe | Giant Antipsyware - now superseded by Microsoft's Windows Defender |
| X | gcasServ | realsched.exe | Added by a variant of the TACTSLAY.A TROJAN! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name |
| ? | GCC Reminder | gccrem.exe | Associated with AcraMax Greeting Card Creator. Is it a registration reminder? |
| N | GCS | GrabClipSave.exe | GrabClipSave screen capture tool |
| X | gcw | gcw.exe | Part of BestsellerAntivirus, PCSecureSystem and other members of the AVSystemCare family of rogue security software suites. See here for more examples |
| X | gdagdgajs | bbsbw.exe | Added by the SDBOT-QX WORM! |
| X | GDAX | [path to backdoor] | Added by the RANKY.K TROJAN! |
| X | gdcw | GDCW.exe | Part of ContentEraser, WinAnonymous and other members of the PCPrivacyTool rogue privacy tool and other members of this family. See here for more examples |
| X | Gddlib | rundll32.exe gddlib.dll,start | Added by the AKBOT.EG WORM! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "gddlib.dll" file is found in %System% |
| Y | GDFirewallTray | GDFirewallTray.exe | Part of the firewall included with the NotebookSecurity, TotalSecurity and InternetSecurity internet security products from G Data Software AG. Access to the firewall options is included in the main "G Data AntiVirus Tray Application" (AVKTray.exe) entry and although the name would suggest this adds a further tray icon it doesn't. Although the exact purpose is therefore unknown it's recommended you leave it running. Also used by versions of Lavasoft's Ad-Aware Total Security |
| X | gdien32 | gdien32.exe | Added by the SINGU-P TROJAN! |
| X | gdimx | gdimx.exe | MPB-D dialer. Note - provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "gdimx" |
| U | GDMgr.exe | gdmgr.exe | GuardMon is a commercial surveillance software program designed to monitor all forms of user activity on a computer |
| N | GDrive | GDriver.exe | Found on IBM systems. All it does is set the CDROM drive letter to G:. Set your drive letter manually via Start -> Settings -> Control Panel -> System -> Device Manager |
| N | Gearbox | confsvr.exe | NTL's Gearbox software for configuring internet connections with their NTLWorld software - does a similar job to the Internet Connection Wizard which can be used instead using the dial-up details available here |
| N | GEARsec | gearsec.exe | Installed by Apple Quicktime package - iPod®/iTunes® CDRW support. Can be disabled if you only require Quicktime player |
| X | GEDZAC | GEDZAC.exe | Added by the GEMEL WORM! |
| X | Gekio Startups | gnksvc32.exe | Added by the AGOBOT.AFJ WORM! |
| N | GemStRmW | GemStRmW.exe | For a GemPlus smart card reader. If it doesn't start automatically when you insert the smart card, start it manually |
| X | gencroot | gencroot.exe | Added by the SDBOT-AED WORM! |
| U | Gene USB Monitor | USBMonit.exe | Monitors USB ports for insertion of Sandisk USB flashdrives |
| U | Gene USB Monitor | UMonit2K.exe | Monitoring tool for USB ports, card readers and flash drives |
| X | General Antivirus | GenAvir.exe | General Antivirus rogue security software - not recommended, removal instructions here |
| X | general lptt01 | general.exe | RapidBlaster variant (in a "general" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | general ml097e | general.exe | RapidBlaster variant (in a "general" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| U | Generic ChkMail | ChkMail.exe | Mail-checking utility supplied with some ASUS notebooks that uses an LED to notify the user when an E-mail has arrived. The models supported are AS62FM945GM1, AS62JM945PM1 and AS62JM945PM2 - see here |
| X | Generic Host | wauclt.exe | Added by the SDBOT-DNL WORM! |
| X | Generic host proccess for windows | SVCHOSTS.EXE | Added by the SPYBOT-GQ WORM! |
| X | Generic Host Process | SCHOST.EXE | Added by the RBOT-NC WORM! |
| X | Generic Host Process | svchost.exe | Added by the DLOADER-NX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | Generic Host Process | camacttiv.exe | Detected by AVG as the CIADOOR.13 TROJAN! |
| X | Generic Host Process | lsassw.exe | Added by the AGOBOT-N WORM! |
| X | Generic Host Process for Win Services | mscvs.exe | Added by a variant of the SDBOT WORM! |
| X | Generic Host Process for Win32 Service | svlhost.exe | Added by the WOOTBOT.EX WORM! |
| X | Generic Host Process for Win32 Service | rpchost.exe | Added by the IRCBOT.DCN WORM! |
| X | Generic Host Process for Win32 Services | ntspcv.exe | Added by the SDBOT.S TROJAN! |
| X | Generic Host Process for Win32 Services | intspvc.exe | Added by the DINFOR.D WORM! |
| X | Generic Host Process for Win32 Services | winsvc.exe | Added by the SDBOT-O WORM! |