X |
IEAgent update check |
iewatch.exe | "Added by the BOMKA TROJAN!"
|
X |
IECache |
IECache.exe | "Detected by Bitdefender as the DELF.OFC TROJAN! See here"
|
N |
iecheck |
iecheck.exe | "Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2"
|
X |
IECheck |
MSDTCs.exe | "Added by the TIRBOT-D WORM!"
|
X |
IECheck |
xpssl.exe | "Added by the TIRBOT-E WORM!"
|
X |
IECheck |
mssvp.exe | "Added by the TIRBOT-G WORM!"
|
U |
IECleanAux |
Ieboot6.exe | "IEClean by Kevin McAleavy - cookie manager |
X |
iedll |
iedll.exe | "Homepage hijacker |
X |
IEDriver |
IEDriver.exe | "IEDriver adware. Can be installed as part of peer-to-peer file sharing software called URLBlaze"
|
X |
IEDriver |
xplore.exe | "IeDriver adware variant"
|
X |
IEDriver |
TD.exe | "IeDriver adware variant"
|
X |
iedwa104 |
iedwa104.exe | "Added by the DLOADR-BBW TROJAN!"
|
X |
IEengine |
IEeng.exe | "STARTPAG.AI hijacker"
|
X |
IEexplorer AUpdate |
IEexplore32.exe | "Added by the RBOT-GRE WORM!"
|
X |
IEFeatures |
IEFeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
X |
IEFeatures |
Internetfeatures.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
X |
IefxTray |
IefxTray.exe | "Added by the RILER-H TROJAN!"
|
X |
ieharv.exe |
ieharv.exe | "Added by the BANKER-HH TROJAN!"
|
X |
Iehelper |
syslaunch.exe | Outwar adware downloader
|
X |
iel2cde8 |
"rundll32.exe iel2cde8.dll | EnableRunDLL32" |
X |
ielcaabe |
"rundll32.exe ielcaabe.dll | EnableRunDLL32" |
X |
IELoader32 |
iexplore32.exe | "Added by the SPEX or SPEX.B WORMS!"
|
X |
Iesar |
Iesar.exe | Browser hijacker - redirecting to an adult web page
|
X |
Iesearch.exe |
Iesearch.exe | "LookNSearch adware"
|
U |
IEServer |
IEServer.exe | "HB Screen Spy surveillance software. Uninstall this software unless you put it there yourself"
|
X |
IEService.exe |
IEService.exe | "FastFind adware variant"
|
X |
IESet |
IExplorer.dll | "Added by the PWS-BLUEDIT TROJAN!"
|
X |
iesetupi.exe |
iesetupi.exe | "Added by a variant of the RBOT WORM!"
|
Y |
IEShow |
IEShow.exe | "Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames |
X |
iestart |
iexp1orer.exe | "Added by the NEMOG.C TROJAN!"
|
N |
ietsr |
ietsr.exe | "IEClean by Kevin McAleavy - cookie manager |
X |
ieupdate |
MCP****.exe [**** = random char] | "Added by the ASOXY TROJAN!"
|
X |
ieupdate |
mcpdll32.exe | Adware downloader trojan
|
X |
ieupdate |
[random filename] | "Added by the AGENT-C BACKDOOR!"
|
X |
ieupdates |
ieupdates.exe | "Added by a number of TROJANS such as DWNLDR-HGI and AGENT-HGA and the Antivirus 2009 rogue security software - see here"
|
X |
IEWinserv |
winserv.exe | "Added by the BANKER-MY TROJAN!"
|
X |
IEXPL0RER |
IEXPL0RER.EXE | "Added by the AGOBOT-QL WORM! |
X |
iexplo |
iexplor.exe | "Added by the SIDEA TROJAN!"
|
X |
IExploer |
svshosts.exe | "Added by the IRCBOT.BT TROJAN!"
|
X |
Iexploit |
Iexploit.html | "Added by the INKER.B WORM!"
|
X |
iexplor.exe |
iexplor.exe | "Added by an unidentified WORM or TROJAN! See here"
|
X |
Iexplore |
iexplore.exe | "Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
X |
IEXPLORE |
iexplore.exe | "Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X |
IExplore |
IEXPLORE.EXE | "Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
|
X |
IEXPLORE |
IEXPLORE.EXE | "Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
X |
iExplore Ini |
ie4uini.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X |
Iexplore Services |
iexplore.exe | "Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
|
X |
IEXPLORE.EXE |
[path to trojan] | "Added by the BANCOS-CJ TROJAN!"
|
X |
IEXPLORE.EXE |
goot.exe | "Added by the BIFROSE-C TROJAN!"
|
X |
IExplorer |
Iexplor32.exe | "Added by the BDOOR-BY BACKDOOR!"
|
X |
IExplorer |
IExplorer.EXE | "Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
X |
IEXPLORER |
msiecfg.exe | "Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
|
X |
Iexplorer |
explorer.exe | "Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
X |
iexplorer lptt01 |
iexplorer.exe | "RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X |
iexplorer ml097e |
iexplorer.exe | "RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
X |
Iexplorer.exe |
Iexplorer.exe | "Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
X |
IExplorer32 Java Scripting |
IExplore32b.exe | "Added by the RBOT.ABO WORM!"
|
X |
IExplorer32c Java Scripting |
IExplore32cb.exe | "Added by the RBOT.ABN WORM!"
|
X |
IExplorer6 Java Scripting |
IExplore326.exe | "Added by a variant of the SDBOT WORM!"
|
X |
IExplorer7 Java Scripting |
IExplore327.exe | "Added by a variant of the SDBOT WORM!"
|
X |
Iexplorerr.exe |
Iexplorerr.exe | "Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
|
X |
Iexplorerr.exe |
Iexplorerr.exe | "Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
|
X |
IExplorerService |
WinSock.exe | "Added by the AGENT.KIU TROJAN!"
|
X |
iExpresser |
iexpresser.exe | "Added by the SLENFBOT.AP WORM!"
|
X |
ifp |
ipf.exe | "Added by the CLAGGER-AG TROJAN!"
|
X |
ifperx |
[random filename] | "Added by a variant of the SLAPER TROJAN!"
|
X |
ifperx |
xmliwvug.exe | "Added by the SLAPER.U TROJAN!"
|
U |
IFSplash.exe |
IFSplash.exe | I-FORCE driver for force feedback steering wheel
|
U |
IFXSPMGT |
ifxspmgt.exe | "Part of the Infineon Security Platform Software - which supports the on-board TPM security device included with some laptops from suppliers such as Acer |
X |
igamatu |
ekor.exe | "Added by the SDBOT.AQ TROJAN!"
|
X |
igamatu |
atecaca.exe | "Added by the IRCBOT.R WORM!"
|
U |
igfxhkcmd |
hkcmd.exe | "Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
U |
igfxpers |
igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
X |
igfxtras |
svchots.exe | "Added by the AUTORUN-AIW WORM!"
|
U |
IgfxTray |
igfxtray.exe | "System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled |
? |
Iglpbv |
Iglpbv.exe | "??"
|
N |
igndlm.exe |
DLM.exe | "IGN Download Manager has become a requirement for downloading files through FilePlanet.com. It is based on Internet Explorer and it installs through an ActiveX-plugin |
X |
igsex2x |
igsex2x.exe | "NewDial premium rate adult content dialler"
|
X |
IGuardPc.exe |
IGuardPc.exe | "IGuardPc rogue security software - not recommended |
? |
iHP-100 |
iHPDetect.exe | "Drive Letter Searcher |
X |
iilc |
IILC.EXE | Homepage hijacker
|
X |
Iinl |
iptl.exe | "PurityScan adware"
|
X |
IISADMINS |
systems.exe | "Added by the AGOBOT.U WORM!"
|
X |
iisvers |
iisvers.exe | Added by an unidentified TROJAN or adware
|
X |
iiuyvyu |
uzcx.exe | "Added by the AGENT-EOF TROJAN!"
|
N |
iIWiper |
Systemwiper.exe | "System Wiper from iI Software - allows you to clear the history of your activites from you computer. Run manually on a regular basis"
|
Y |
IJ75P2PSERVER |
IJ75P2PS.EXE | Printer utility which is required in order to make the printer work correctly
|
U |
IJNetworkScanUtility |
CNMNSUT.EXE | Network utility available for some Canon scanners and multifunction devices. Allows the device to see computers on a network and those computers running the utility to control scanning via the Control Panel on the scanner - which saves you having to run back and forth between the scanner and your computer
|
Y |
IKE Service 95 |
IKEService.exe | "Associated with PGP. The PGP Tray can be disabled |
U |
iKeyWorks |
IKEYMAIN.EXE | "A4Tech wireless keyboard driver and utility"
|
U |
IKL |
rundll32.exe [path] IKL.dll | "IKL surveillance software. Uninstall this software unless you put it there yourself"
|
X |
ilasss |
lsass.exe | "Added by the INJECT-GZ TROJAN! Note - the legitimate lsass.exe process should not normally figure in Msconfig/Startup!"
|
N |
iLike |
ilikesidebar.exe | "iLike Sidebar for iTunes and Windows Media Player"
|
X |
iLLeGaL |
Mplayer.exe | "Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
|
X |
iLLeGaL.exe |
Mplayer.exe | "Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename"
|
X |
ilortgdg |
keepSafe.exe | "Added by the KILLAV.KAX TROJAN!"
|
? |
ILO_Office_Manager |
IntEdReg.exe /OFFMAN | "Intense Educational Ltd - Language Office Software. Is it required?"
|
U |
iLyric |
iLyric.exe | "iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button"
|
N |
iM Start Center |
iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
|
X |
Image |
"rundll32 [path] [trojan filename] | Install" |
Y |
Image & Restore |
IMAGE32.exe | "Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased |
X |
Image Remote Players |
sysvn.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
N |
Image Transfer |
SonyTray.exe | Sony Image Transfer software provides direct image transfer from your digital camera to a PC - can be started manually
|
U |
ImageDrive-{hex numbers} |
ImageDrive.exe | "Nero ImageDrive from Ahead - virtual CD/DVD drive software"
|
U |
Imagefox |
imagefox.exe | "ImageFox 2.0 (formerly available from ACDSee) is an ""add-on"" graphics previewer for most Windows Open/Save As dialog boxes"
|
X |
Imagemgt32 |
Imagemgt32.exe | "Added by the GEMA TROJAN!"
|
X |
ImagePath |
taskbarmngr.exe | "Added by the SDBOT-XB WORM!"
|
U |
ImageTune |
dthtml.exe | "ImageTune from Hyundai ImageQuest. Rebranded version of Display Tune from Portrait Displays |
X |
IMAPI |
load.exe | "Added by the DOWNDEL-A TROJAN!"
|
N |
iMarkup Client |
iUtil.exe | "Enables the iMarkup Client web page annotation utility to run in the background and be available in systray. Shortcut available via Start -> Programs"
|
U |
Imatio |
imation.exe | "Imation Disk Manager - enables you to create a password protected area on your Imation USB flash drive"
|
X |
imchat |
imchat.exe | "Added by a variant of the IRCBOT TROJAN!"
|
X |
IMClass |
Svhosl.exe | Added by an unidentified WORM or TROJAN!
|
X |
imcssl |
xmliwvug.exe | "Added by the SLAPER.U TROJAN!"
|
X |
IME |
conime.exe | "Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
|
N |
imekrmig |
imekrmig.exe | "Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese |
N |
IMEKRMIG6.1 |
IMEKRMIG.EXE | "Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese |
N |
Imesh |
?? | "Imesh is a file sharing system"
|
N |
Imesh Auto Update |
?? | "Update check for the Imesh file sharing system. Turn the update off under ""options"""
|
X |
IMEvtMgr.exe |
IMEvtMgr.exe | "Added by the KEYLOG-AR TROJAN!"
|
U |
ImgIcon |
ImgIcon.exe | "Displays Iomega icons in Explorer/My Computer |
X |
imgit |
[path to file] | "Added by the BANKER-EM TROJAN!"
|
N |
ImgStart |
ImgStart.exe | "Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
|
N |
ImgTask |
Imgtask.exe | "Related to the WalletPix digital photo album. ""On some computers |
U |
IMJPMIG |
IMJPMIG.EXE | "Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails |
X |
IMJPMIG6.1 |
HelpCat.exe | "Added by the BESVERIT WORM!"
|
U |
IMJPMIG8.1 |
IMJPMIG.EXE | "Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails |
X |
IMJPMIG8.2 |
msime82.exe | "Added by the VB-CYG WORM!"
|
X |
IMJPMIG8.2 |
msime80.exe | "Added by the VB-CYJ TROJAN!"
|
? |
immcheck.exe |
immcheck.exe | "Related to I-FORCE driver for force feedback steering wheel?"
|
X |
ImMsn |
timed.exe | "Added by the WEBDOR.AK TROJAN!"
|
U |
IMOL |
IMOLApp.exe | "IncrediMail for Office Outlook Add-On"
|
U |
Imonitor |
Plguni.exe | "Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection |
X |
imonitor |
[path to trojan] | "Added by the IMONI-A TROJAN!"
|
U |
IMONTRAY |
imontray.exe | "System tray monitoring of fans |
X |
imPlayok |
imPlayok.exe | "Added by the CUTWAIL TROJAN!"
|