| Status | Autorun name | Command | Description |
| U | 3Deep Control Panel | 3DeepCTL.EXE | 3Deep® from E-Color corrects lighting, shading and color for all your 2D and 3D games. Now superseded by 3DxWizzard |
| X | 3Dfx Acc | GFXACC.EXE | Added by the GIBE WORM! |
| N | 3dfx Task Manager | 3dfxMan.exe | System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs |
| Y | 3dfx Tools | rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot | Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards |
| Y | 3dfxv2ps.dll | 3dfxv2ps.dll | Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards |
| ? | 3Dlabs Taskbar Display Manager | 3DLman.exe | 3DLabs graphics driver related. System Tray access to display settings? |
| U | 3DLabsHelperDemon | 3dldemon.exe | Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits in the background doing nothing at all (sleeping on a semaphore), so it should take zero CPU time and virtually zero memory, since it will all be paged out to the hard drive." In most cases it can be safely disabled |
| Y | 3DMouse.EXE | 3DMouse.EXE | Dritek System Inc. 3DMouse driver. A 3D Mouse works in all 3-dimensions instead of the usual 2, similar to the Ninteno Wii Remote - see here |
| X | 3P_UDEC_IA | IAInstall.exe | Installer for the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended, removal instructions here |
| U | 3qdctl.exe | 3qdctl.exe | Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determined default. Similar to Creative Lab's AudioHQ |
| Y | 3ware 3DM | 3dm.exe | Monitors status of the disk array on 3ware IDE RAID controllers |
| X | 4-gusdur | gusdur.exe | Added by the BRONTOK-CR WORM! |
| X | 456655 | explorer.exe | Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System% |
| X | 4684735485910 | netdll32.exe | Added by the SDBOT-DEV WORM! |
| U | 49ersScreenServer | 49ersScreenServer.exe | Screensaver for the San Francisco 49'ers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported |
| U | 49ersScreenServerSvc | 49ersScreenServer.exe | Screensaver for the San Francisco 49'ers NFL football team - part of Sports Illustrated's MySI desktop download (by MercurySports Network) for streaming information on NFL football teams. No longer supported |
| X | 49U5T1N4 | 49U5T1N4.exe | Added by the KORRON.B WORM! |
| X | 4da92ad5.exe | 4da92ad5.exe | Added by the DLOADR-WZ TROJAN! |
| X | 4k51k4 | 4k51k4.exe | Added by the BRONTOK-BH WORM! |
| U | 4oD | KHost.exe | Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops |
| X | 4wd!!! | Natal!.pif | Added by the OPASERV.AI WORM! |
| U | 4x26 Scan2PC | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX4x26 multifunction laser printers |
| U | 4x28 Scan2PC | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX4x28 multifunction laser printers |
| X | 5-1-61-96 | members-area.exe | Adult content dialler |
| X | 5-2-46-112 | 5-2-46-112.exe | Adult content pop-up dialler. Removal instructions here |
| X | 5-megawati | megawati.exe | Added by the BRONTOK-CR WORM! |
| X | 55278 | grepclient1.exe | Added by the LINEAGE-S TROJAN! |
| X | 56a10a26-dc02-40f3-a4da-8fa92d06b357_33 | rundll32.exe 56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi | Security Defender rogue security software - not recommended, removal instructions here. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi" file is located in %CommonAppData% |
| X | 5p4m | [path to trojan] | Added by the LITEBOT-C TROJAN! |
| X | 5whgue21 | 5whgue21.exe | ClearSearch adware |
| X | 6-susilo b | sby.exe | Added by the BRONTOK-CR WORM! |
| X | 60xu9 | qtfcyyp.exe | Added by the VIRUT.CE VIRUS! |
| U | 6200 Scan2PC | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung CLX6200 multifunction laser printer |
| X | 65438761234587528 | rkgnd.exe | ANG AntiVirus 09 rogue security software - not recommended, removal instructions here |
| X | 6625366342 | 6625366342.exe | Added by the AGENT-OSO TROJAN! |
| X | 666 | Ska.exe | Added by the PIPES TROJAN! |
| X | 678 | lsas32.exe | Added by the SLSORVE-B TROJAN! |
| X | 6GMQKO1OIZ4OY | 2X2NCRZX.exe | Added by the DWNLDR-JCP TROJAN! |
| X | 756349DC-6D9E-4F2A-9B24-269661F073C3 | sysoghcx.exe | Added by the FAKEALERT-AH TROJAN! |
| X | 76112549345328287 | angpd.exe | ANG AntiVirus 09 rogue security software - not recommended, removal instructions here |
| X | 7f8e | z****.exe 9idf | Detected by Eset's NOD32 antivirus as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder |
| X | 7u560 | 7u560.exe | Added by the SCAR.ACIT TROJAN! |
| X | 7X29C2X78Y | syss_.exe | Added by the AGENT-GMS TROJAN! |
| U | 80's Arcade | Arcade.exe | 80's Arcade widget included with the DesktopX desktop utility from Stardock Corporation. Allows you to play classic 1980's arcade games such as Pacman and Space Invaders on the desktop. Once started, Arcade.exe loads a file called "DXWidget.exe" and exits |
| U | 802.11b+g USB Wireless LAN Utility | ZDWlan.exe | Wireless LAN configuration utility for ZyDAS (now acquired by Atheros) based chipsets |
| U | 802.11g MIMO Wireless Utility | RaUI.exe | Wireless configuration utility for Railink 802.11g MIMO based products |
| U | 802.11g Wireless Adatper | Monitor.exe | Related to wireless card (802.11) adapter/standard. System Tray icon that provides a shortcut to "Wireless Connection Status" and allows to turn WL on and off. Supplier unknown. Adapter is miss-spelled |
| X | 8028073570 | 8028073570.exe | Added by the AGENT-OQY TROJAN! |
| X | 82545024 | 82545024.exe | Added by the AGENT-MBV TROJAN! |
| X | 852EBF20-A95D-4F1F-B9C2-B2CD24350F3E | sysodkcs.exe | Added by the FAKEALERT-AH TROJAN! |
| X | 8jg53l4ojo74khk.exe | 8jg53l4ojo74khk.exe | Added by the AUTOIT.AAK TROJAN! |
| X | 91302318 | 91302318.exe | SecurityTool rogue security software - not recommended |
| X | 98D0CE0C16B1 | rundll32.exe D0CE0C16B1,D0CE0C16B1 | BrowserAid/BrowserPal foistware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted |
| X | 9m | winlog0n.exe | Added by the LEGMIR-AQK TROJAN! |
| X | 9UmxQPSiTJMbA | NVUKZ.exe | Added by the AGENT-LMN TROJAN! |
| Y | 9xadiras | 9xadiras.exe | Allied Telesyn AT series router/modem related - apparently required |
| X | 9xHtProtect | AVprotect9x.exe | Added by the NETSKY.M WORM! |
| X | a | a.exe | Commercials file that registers itself in the system registry and redirects IE to a certain commercial website |
| X | a | jesse.exe | Added by the MELO-A WORM! |
| X | a | MsSvrdll.vbs | Added by the MUTAFROG!INF WORM! |
| X | A New Windows Updater | w32NTupdt.exe | Added by the MYTOB.BM WORM! |
| N | A Note | A Note.exe | "A Note is a program that lets you create post-it like notes on your Microsoft Windows desktop" |
| U | A Verizon App | VERIZO~1.EXE | Part of Verizon Online Support Manager |
| Y | a-squared | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" |
| Y | a-squared | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" |
| Y | a-squared Anti-Dialer | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" |
| Y | a-winpoet-service | winpppoverethernet.exe | WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion, WinPoET is attractive to equipment providers, modem suppliers, RBOCs and ISPs. For more info read here. It uses dial-up networking for new high-speed internet customers who are more familiar with analogue modems. If unchecked in MSCONFIG it reports Error 360 - Hardware Error in dial-up networking |
| X | A_M_P_NET | AntiMalwarePro.exe | AntiMalware Pro rogue security software - not recommended, removal instructions here |
| ? | a_vpd | vpd.exe | Located in an IBMTOOLS\VPD sub-directory. What does it do and is it required? |
| Y | a² | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" |
| U | A1000 Settings Utility | cpqa1000.exe | Compaq A1000 Print Fax All-in-One copy scan printer software. Required in the Startup in order to scan, print, copy and fax. Only required if you use these features |
| Y | a2adguard | a2adguard.exe | System Tray access to and Background Guard feature of Emsisoft Anti-Dialer from Emsi Software GmbH - which "provides a complete defense against Dialers" |
| ? | a2dservice | a2dservice.exe | Related to the Air2Data Wireless HISA (High-Speed Internet Access) service. What does it do and is it required? |
| Y | a2guard | a2guard.exe | System Tray access to and Anti-Malware Guard feature of Emsisoft Anti-Malware from Emsi Software GmbH - which provides "comprehensive PC protection against viruses, trojans, spyware, adware, worms, bots, keyloggers and rootkits". Previously known as "a-squared Antitrojan" and "a-squared Anti-Malware" |
| U | A4Proxy | A4Proxy.exe | Anonymity 4 Proxy - local proxy server that makes you anonymous when visiting web sites |
| X | A5118r | _default32142.pif | Added by the BRONTOK-AK WORM and variants! |
| X | A5118r | j6321422.exe | Added by the BRONTOK-AK WORM and variants! |
| X | A70F6A1D-0195-42a2-934C-D8AC0F7C08EB | rundll32.exe E6F1873B.DLL, D9EBC318C | BrowserAid adware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The "E6F1873B.DLL" file is located in %System% |
| X | a9z1eizA1e | atulabov.exe | Added by the AGENT-GWD TROJAN! |
| X | aa bbcc dde effgghh jj | update.exe | Added by a variant of the IRCBOT BACKDOOR! |
| X | aaa | aaa.exe | Added by the POISON.PG BACKDOOR! |
| ? | AAACLEAN | AAACLEAN.INF | ?? |
| ? | AAAKeyboard | rundll.exe setupx.dll,InstallHinfSection KBDCLEAN.INF | ?? |
| U | aaAPMClient | amclient.EXE | LANDesk® Management Suite software component |
| N | AAATraySaver | TraySaver.exe | System Tray management utility from Mike Lin which allows you to hide, show, restore icons that are lost in an Explorer crash, remove dead tray icons, minimize any window to the System Tray |
| X | aacmeyf | aacmeyf.exe | Added by the AF.20 TROJAN! |
| X | Aaep | opar.exe | PurityScan/Clickspring adware |
| U | AAK | aak.exe | Advanced Anti-Keylogger - "Anti-spy software to prohibit operation of any keyloggers currently in use or presently being developed anywhere" |
| U | aaLDISCN32 | LDISCN32.EXE | LANDesk® Management Suite software component |
| U | aaLDSoftMon | SoftMon.EXE | LANDesk® Management Suite software component |
| U | aaLDTaskCompletion | amclient.EXE | LANDesk® Management Suite software component |
| X | AAMSFree702 | Avengine.com | Added by the DELF.LJ TROJAN! |
| X | AAMSFree702 | sys.exe | Added by the BACKDOOR-CPC TROJAN! |
| X | Aaou | amee.exe | PurityScan adware |
| X | AAPatch | start.bat | Added by the XBLOCKER.BCT TROJAN! |
| X | Aapp | adprot | AdBlaster adware |
| X | aaprotect | [path to trojan] | Added by the BANCBAN-MJ TROJAN! |
| X | AASSKK2 | LSASS.EXE | Added by the SILLYFDC.BDB WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData% |
| ? | aauclient | ACNUpdater.exe | Appears to be related to software from Accenture.com |
| U | AAW | Ad-Aware.exe | Old versions of the Lavasoft Ad-Aware anti-malware tool |