| Status | Autorun name | Command | Description |
| X | Ibs | ibs.exe | Added by the HIDEDIAL-B TROJAN! |
| U | IBWin Background process | IBackground.exe | IBackup for Windows |
| U | IBWin Monitor | IBMonitor.exe | IBackup for Windows |
| N | IC_KEY_3 | spvic.exe | Instant Chess related |
| Y | IcaBar | icabar.exe | Related to Citrix MetaFrame |
| U | iCalendar | Calendar.exe | Older version of Desktop iCalendar/Desktop iCalendar Lite by Desksware which include support for Google Calendar and add weather, tasks and appointments to your desktop |
| X | icasServ | icasServ.exe | Browser hijacker, redirecting to Searchforfree.info. Also detected as the ICASERV-A TROJAN! |
| X | icccomp | [8 random letters].exe | Added by the ZHELATIN.EQ WORM! |
| X | ICcontrol | iccontrol.exe | ICcontrol premium rate adult content dialer |
| X | icdd7ee6 | rundll32.exe icdd7ee6.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icdd7ee6.dll" file is found in %System% |
| X | icddefff | rundll32.exe icddefff.dll,EnableRunDLL32 | LZIO.com adware downloader. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "icddefff.dll" file is found in %System% |
| Y | ICF | mfp.exe | McAfee Family Protection - which 'is easy-to-use and built to empower parents to say "yes" to their children's online interests while protecting them as they learn and explore' and "protects children of all ages from exposure to inappropriate content, social networking risks, strangers, and other threats" |
| N | ICH Synth | eusexe.exe | Sound related and can be disabled without affecting performance although advanced sound features may be sacrificed. May be related to Compaq PC's with "SoundMAX integrated Digital Audio" (Analog Devices Inc.) devices |
| U | ICIDU Wireless Utility | ZDWlan.exe | Wireless LAN configuration utility for an ICIDU wireless USB dongle based upon a ZyDAS (now acquired by Atheros) chipset |
| X | icifati | yujixit.exe | Added by the SDBOT.ZZH WORM! |
| U | iClean | iClean.exe | IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy" |
| U | ICM | ICM.EXE | Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail |
| X | ICManagement | msic32.exe | Added by the MSIC BACKDOOR! |
| N | iCn | NAG.EXE | iChoose - shopping browser enhancement that alerts you to cheaper deals for goods you want to buy, if they exist. Not related to the Mac icon program of the same name |
| U | ICO | ICO.EXE | Found on some Sony Vaio, IBM Thinkpad and Dell (and possibly other) laptops and seems to be related to Mouse Suite 98 Daemon according to the properties. Required on the Dell Inspirion 530 as without it the Dell mouse suite does not load and mouse settings are not retained on a reboot. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
| ? | ICON 225 USB Connect | ICON 225 USB Connect.exe | Related to the iCON 225 USB modem from Option - as provided by Orange. What does it do and is it required? |
| N | Icon Animation | HDE.EXE | Part of McAfee Nuts & Bolts. Provides entertaining animation of your desktop icons |
| N | Icon Hearit 95 | hearit95.exe | Audio desktop customization utility from Moon Valley Software. Resource hog |
| N | Icon Hearit 98 | hearit98.exe | Audio desktop customization utility from Moon Valley Software. Resource hog |
| X | Icon lptt01 | icon.exe | RapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| X | Icon ml097e | icon.exe | RapidBlaster variant (in a "Icon" folder in Program Files). A dedicated "RapidBlaster Killer" removal tool used to be available but quality anti-malware tools will now remove it |
| ? | ICON2 USB Connect | ICON2 USB Connect.exe | Related to the iCON2 USB modem from Option - as provided by Orange. What does it do and is it required? |
| Y | iconcache | icon.bat | Related to the Vista Customization Pack |
| Y | ICONCLNT | iconclnt.exe | APC PowerChute® Personal Edition tray icon |
| U | ICONDESK | ICONDESK.EXE | Small utility which will allow you the option of hiding or showing your desktop icons |
| N | Iconfig.exe | Iconfig.exe | System Tray icon associated with a Shuttle Technology LS-120 SuperDisk - which is a high-speed, high-capacity alternative to the standard floppy disk |
| X | iConfigLoader | DIIhost.exe | Added by the GAOBOT.AO WORM! |
| N | Iconoid | Iconoid.exe | Iconoid is a desktop icon manager |
| N | Iconsaver | Iconsaver.exe | IconSaver is a desktop icon manager |
| U | Iconutility | AmIcoSinglun64.exe | Single LUN Icon Utility - System Tray access/notification for card readers using controllers from Alcor Micro which incorporate Single LUN, such as the AU6336, AU6439 and AU6431 |
| Y | IconX | IconX.exe | IconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate download |
| Y | IconX.exe | IconX.exe | IconX from Stardock Corporation - "a program that enhances your Windows desktop icons so that they can be any size, zoom on mouse over, have shadows underneath them and generally make them more attractive and usable." Required if you want to use the features and themes provided. No longer supported - it was formally part of the Object Desktop suite and also available as a separate download |
| X | ICQ | ICQNET.vbs | Added by the GORMLEZ-A WORM! |
| X | ICQ | syscdd2.exe | Added by the SDBOT-ON BACKDOOR! |
| X | ICQ Agent | icq6.exe | Added by the AGENT-FZJ TROJAN! |
| X | ICQ Center | [path to worm] | Added by the RANDIN WORM! |
| X | ICQ Chat Service | icqjdhs.exe | Added by a variant of the RBOT WORM! |
| X | ICQ Hacking Pro | ICQpro.exe | Added by a variant of the NETSPY TROJAN! |
| N | ICQ Lite | ICQLite.exe | ICQ Lite - compact version of the popular messaging program |
| X | icq lite | scvhost.exe | Added by the AGENT-DSF TROJAN! |
| X | icq lite | winlog.exe | Added by the IRCBOT-TJ TROJAN! |
| X | ICQ Lite Messenger | ICQLITE.EXE | Added by an unidentified VIRUS, WORM or TROJAN! The legitimate ICQ Lite executable is located in %ProgramFiles%\ICQLITE whereas this one is located in %System% |
| X | ICQ Messenger 2002 | ICQ2002.exe | Added by the SDBOT-ABL WORM! |
| X | ICQ Net | winlogon.exe | Added by variants of the NETSKY WORMS! Note - this is not the legitimate winlogon.exe process which should not appear in Msconfig/Startup! |
| N | ICQ Plus | vplus.exe | ICQ Plus is a freeware utility makes your ICQ skinnable (change the look). Available via Start -> Programs |
| X | IcqBeta | webcamupdate.exe | Added by an unidentified TROJAN! |
| U | ICQMonitor | ICQMonitor.exe | ICQ Monitor Sniffer surveillance software for the ICQ instant messenger. Uninstall this software unless you put it there yourself |
| X | ICQMsn | [path to trojan] | Added by the RANCK-AH TROJAN! The most common example is "cbfks.exe" located in %System% |
| X | ICQNet | winlogon.exe | Added by the NETSKY-C WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir% |
| X | icrosof Avps32 Control | av32.pif | Added by the RBOT-AVC WORM! |
| X | icrosoft Visual | plscx.exe | Added by the RBOT-AYO WORM! |
| X | icrosoft Visual InterDevc | zvslmqb.exe | Added by the RBOT-AYP WORM! |
| X | icrosoft Windows DLL Services Configuration | poker3.exe | Added by the SDBOT-AER WORM! |
| X | icrosoftf Avpx Control | avpx.exe | Added by the RBOT-AYN WORM! |
| U | ICSDCLT | rundll32.exe Icsdclt.dll, ICSClient | Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines |
| N | ICServer | Icserver.exe | Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations |
| Y | ICSMGR | ICSMGR.EXE | Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you're sharing the internet on various computers |
| X | ICU-Sucker | Service32.exe | Added by the ILLNOTIFIER.D TROJAN! |
| N | ID Commander | IDCom.exe | Caller ID utility for identifying incoming telephone numbers |
| X | ID8525 | ID8525.exe | Added by the ID8525.A TROJAN! |
| X | ID8525 | id85255.exe | Added by the ID8525.A TROJAN! |
| ? | IDA | IDA.EXE | Part of HP's PC Common Operating Environment (PC COE) project. Located in %ProgramFiles%\Hewlett-Packard\PC COE. What does it do and is it required? |
| X | IDBoan | IDBoan.exe | IDBoan rogue security software - not recommended, removal instructions here |
| X | IDE | ide.exe | Added by the ASSASIN.F TROJAN! |
| X | IDE Loader | IDElibr32.exe | Added by the XILON TROJAN! Related to the game "Diablo II" |
| X | idecntl | idecntl.exe | Added by a variant of the CRYPTER.C TROJAN! |
| U | iDesktop | idesktop.exe | Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse |
| X | idlesam | [8 random letters].exe | Added by the ZHELATIN.EQ WORM! |
| N | IDMan | IDMan.exe | Internet Download Manager - download files faster, schedule and resume |
| X | idmlssp | [random filename] | Added by a variant of the SLAPER TROJAN! |
| U | IDriveE Startup | IDrvieEStartup.exe | IDrive from Pro Softnet Corporation - free full featured online backup up to 2GB with the option of paying for more storage space and managing multiple accounts |
| X | IDT PC Audio | statcvs.exe | Added by the DELFINJ-Y TROJAN! |
| X | IDTemplates | IDTemplate.exe | Added by the BRONTOK-H WORM! |
| N | IDW Logging Tool | idwlog.exe | Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems |
| X | IE | [path to backdoor] | Added by the MSPOSER.KAX BACKDOOR! |
| X | IE configure | explorer.exe | Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! |
| U | IE Doctor | IEDoctor.exe | IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options" |
| X | IE Java Update | iejava.exe | Added by the AGENT-HD TROJAN! |
| X | IE Menu Extension toolbar | rundll32.exe [path] tbextn.dll DllShowTB | IEMenuExt trackware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| U | IE New Window Maximizer | iemaximizer.exe | IE New Window Maximizer - automatically maximize new Internet Explorer and Outlook Express windows |
| X | IE Runtime | wini.exe | Added by the PICRATE.B WORM! |
| X | IE Runtime | winlogo.exe | Added by the RBOT-AMJ WORM! |
| X | IE Runtimes | winis.exe | Added by the RBOT-ADZ TROJAN! |
| X | IE**.exe [* = random char] | IE**.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | IE**32.exe [* = random char] | IE**32.exe [* = random char] | CoolWebSearch/HomeSearch adware - for examples, see this log |
| X | IE-Security | wdscan.exe | IE-Security rogue spyware remover - not recommended, removal instructions here |
| X | IE-Security | iescan.exe | IE-Security rogue spyware remover - not recommended, removal instructions here |
| X | IE6 | wkstmg.exe | Added by a variant of the SDBOT WORM! |
| X | IE6 | ssmss.exe | Added by the GAOBOT.DXO WORM! |
| X | IE6 | porn.pif | Added by the RBOT-ATF WORM! |
| X | IE6 | winsnt.exe | Added by the RBOT-GOV WORM! |
| X | IEACCESS | temp532.exe | AsdPlug premium rate adult content dialer variant |
| X | IEACCESS | surfya.exe | IEAccess premium rate adult content dialer variant |
| X | IEAgent update check | iewatch.exe | Added by the BOMKA TROJAN! |
| X | IECache | IECache.exe | Detected by Bitdefender as the DELF.OFC TROJAN! See here |