Name Filename Status Description
$WindowsRegKey%update IEXPLORE.EXE X Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Ahst iebs.exe X PurityScan/Clickspring adware
Antivirus iexpl0res.exe X Added by an unidentified WORM or TROJAN!
Bakra IEHost.EXE X IEDriver adware variant
blah service internet.exe X Added by a variant of the RBOT WORM!
BlueToothAuthentication Agent irprops.cpl U Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
CAISafe isafe.exe Y Part of Computer Associates eTrust EZ Antivirus
Camio Viewer x IXApplet.exe N Image viewing program that comes with digital cameras. Shows pictures that are in the camera before downloading them. "x" in the name is the version
CCWC7I idxl.exe U Moleculesoft Cache, Cookie & Windows Cleaner Ver. 7 - auto clean
Cisco Systems VPN Client ipsecdialer.exe U Cisco VPN Client - lets local users gain Administrator privileges on the operating system
Classes intl.exe X "Switch" adult content dialler
CnsMax Internat.exe X Added by the POINTEX TROJAN! Note - the real internat.exe resides in the %System% folder.
Compaq Internet Setup inetwizard.exe N For Compaq PC's. Runs Compaq internet setup wizard and offers you to signup from ISP list
Config Loadation iEEexplore.exe X Added by the SDBOT.H TROJAN!
Config Loadatiorin I3Explorer.exe X Added by the SDBOT.H TROJAN!
Configuration Loader IEXPL0RE.EXE X Added by the LOADCFG or SDBOT TROJANS!
CorelCENTRAL 10 I_26dadCC.exe N CorelCENTRAL 10 - personal information manager (PIM). Supplied as part of Corel WordPerfect Office 2002. Available via Start -> Programs
Default web browser IexpIore.exe X Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer), the first has a captial "i" in place of lower case "L"
detect idetect.exe U iNTERNET Turbo from Clasys Ltd. "It accelerates any Windows 95/98/Me/NT/2000/XP internet connection in seconds". If you find it helps your connectivity leave it enabled
DigitalWizard ISWizard.exe N InstallShield's DigitalWizard - free, complete Digital Content Management Solution that makes it easy to experience digital content
E-color IconMgr.Exe U Sets the colour of your monitor when running games that recognise E-Color so that you get 'what the game designer intended' when you see the game. Also allows monitor callibration through a program called 3-Deep. If you play a lot of games it can be useful. Can be disabled from starting up from within the program
eWare Startup iWareStart.exe N eWare iWare task bar. Not required
Explorer Updater IEXPLORE.exe X Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
IPInSightLAN 02 IPClient.exe U Added by the Visual IP InSight IP service management system.
FX ieloader.exe X Added by the SMALL.RR TROJAN!
Generic Host Process for Win32 Services intspvc.exe X Added by the DINFOR.D WORM!
GLSetIT32 isass.exe X Added by a variant of the OPTIX PRO TROJAN!
Gremlin intrenat.exe X Added by the DOOMJUICE WORM!
hsim isearch.exe X Unidentified malware
Hyper Start instantmsgrs.exe X Added by the RBOT-NH WORM!
I386 I386.exe X Added by the MYPOWER WORM!
I81SHELL I81SHELL.exe ? Appears to be related to drivers for an Intel 810 graphics chipset on an ASUS motherboard
i8kfangui i8kfangui.exe U Graphical interface for fan speed control
IAAnotif iaanotif.exe U IAA Event Monitor User Notification Tool - part of Intel® Application Accelerator - "a performance software package for desktop PCs using select Intel® chipsets" that "replaces the ATA drivers that come with Windows with drivers optimized for desktop and mobile PCs." If you use the RAID version it's required to notify you if a RAID 1 disk has failed
iamapp iamapp.exe Y AtGuard personal firewall engine. As Atguard was bought by Symantec some time ago, it's now the Norton Personal Firewall executable as well
Iap iap.exe ? Possibly part of Dell OpenManage Client Instrumentation - software that allows remote management application programs to access information about, monitor the status of or change the state of the client computer, such as shutting it down remotely?
IASHLPR IASHLPR.EXE X Added by the OPASERV.T WORM!
ibmmessages ibmmessages.exe N Allows IBM to push messages onto users' computers. Quote: "The Access IBM Message Center can display messages to inform you about software and solutions available from IBM as well as messages from IBM eSupport"
Ibmmon.exe Ibmmon.exe ? ??
ThinkPad PM Service ibmpmsvc.exe U Power management driver for IBM laptops. Provides support for the use of four keys on the Thinkpad keyboard with blue key tops - Fn, F3, F4 & F12 - which have specific functions to control the standby and hibernate buttons. Not required if you don't plan to go into standby or hibernate modes.
IBMUltraBayHotSwapCPLLoader IBMBAY2N.EXE U Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops
IBMUltraBayHotSwapSound IBMBAYSN.EXE ? Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops. Is it needed though - does it just play a sound?
iClean iClean.exe U IEClean - "advanced, comprehensive package of tools which perform a number of functions to allow you to control your online privacy"
ICO ICO.EXE N Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
Icon lptt01 icon.exe X Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
Icon ml097e icon.exe X Variant of the RapidBlaster parasite (in an "Icon" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
ICONCLNT iconclnt.exe Y APC PowerChute Tray Icon. Associated with the UPS listing
ICONDESK ICONDESK.EXE U Small utility which will allow you the option of hiding or showing your desktop icons
Iconfig.exe Iconfig.exe N Icon for LS-120 "Superdisk"
Iconoid Iconoid.exe N Iconoid is a desktop icon manager
Iconsaver Iconsaver.exe N IconSaver is a desktop icon manager
ICQ Hacking Pro ICQpro.exe X Added by a variant of the NETSPY TROJAN!
ICQ Lite ICQLite.exe N ICQ Lite - compact version of the popular messaging program
ICSDCLT Icsdclt.dll U Internet Connection Sharing allows more than one computer to simultaneously access the internet with a single connection. Also required when networking two machines
ICServer Icserver.exe N Intel Intercast viewer software. Gives access to selected internet pages which are broadcasted by several TV stations
ICSMGR ICSMGR.EXE Y Monitors DNS and DHCP requests for ICS (Internet Connection Sharing). Needed if you’re sharing the internet on various computers
ID Commander IDCom.exe N Caller ID utility for identifying incoming telephone numbers
ID8525 ID8525.exe X Added by the ID8525.A TROJAN!
ID8525 id85255.exe X Added by the ID8525.A TROJAN!
IDA IDA.EXE ? HP related - in a Program FilesHewlett-PackardPC COE folder
IDE ide.exe X Added by the ASSASIN.F TROJAN!
IDE Loader IDElibr32.exe X Added by the XILON TROJAN! Related to the game "Diablo II"
idecntl idecntl.exe X Added by a variant of the CRYPTER.C TROJAN!
iDesktop idesktop.exe U Immersion TouchWare Desktop software for devices such as the Logitech iFeel Mouse
IDMan IDMan.exe N Internet Download Manager - download files faster, schedule and resume
IDW Logging Tool idwlog.exe N Added with WinXP SP1. Usually only found in internal builds only to indicate the current build being used. Can cause slow network logon problems
IE Doctor IEDoctor.exe U IE Doctor Toolbar - "IE Doctor can help you to Repair IE easily, protect IE and OE from all malicious changes. It can Repair the HomePage, context menu, IE toolbar button, startup items, Favorites, typed URLs and the entire Internet Options"
iecheck iecheck.exe N Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
IECleanAux Ieboot6.exe U IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc. Performs cleaning tasks at startup
iedll iedll.exe X Homepage hijacker, redirecting to coolwwwsearch.com
IEDriver IEDriver.exe X Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
IEengine IEeng.exe X STARTPAG.AI hijacker
IEFeatures IEFeatures.exe X Added by the POPMON.A TROJAN! - also known as PopMonster adware
IEFeatures Internetfeatures.exe X Added by the POPMON.A TROJAN! - also known as PopMonster adware
IELoader32 iexplore32.exe X Added by the SPEX or SPEX.B WORMS!
Iesar Iesar.exe X Browser hijacker - redirecting to an adult web page
Iesearch.exe Iesearch.exe X Added by the Adware.LookNSearch adware.
iestart iexp1orer.exe X Added by the NEMOG.C TROJAN!
ietsr ietsr.exe N IEClean by Kevin McAleavy - cookie manager, cache cleaner, history cleaner, etc
Iexplore iexplore.exe X Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
IEXPLORE iexplore.exe X Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Iexplore Services iexplore.exe X Added by an unidentified VIRUS, WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
iexplorer lptt01 iexplorer.exe X Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
iexplorer ml097e iexplorer.exe X Variant of the RapidBlaster parasite (in an "iexplorer" folder in Program Files). It is not recommended you manually uninstall RapidBlaster but use RapidBlaster Killer - see here
IFSplash.exe IFSplash.exe U I-FORCE driver for force feedback steering wheel
igfxtray igfxtray.exe N Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
igsex2x igsex2x.exe X NewDial premium rate adult content dialler
iilc IILC.EXE X Homepage hijacker
Iinl iptl.exe X PurityScan/Clickspring adware
IJ75P2PSERVER IJ75P2PS.EXE Y Printer utility which is required in order to make the printer work correctly
IKE Service 95 IKEService.exe Y Associated with PGP. The PGP Tray can be disabled, but without IKESERVICE you won't be able to de- or encrypt anything
iKeyWorks IKEYMAIN.EXE U A4Tech wireless keyboard driver and utility
iLLeGaL iLLeGaL.exe X Added by the HOLAR.C (or GALIL) WORM! Note - this should not be comfused with Windows Media Player which has the same filename
ILO_Office_Manager IntEdReg.exe /OFFMAN ? Intense Educational Ltd - Language Office Software. Is it required?
iLyric iLyric.exe U iLyric plugin for Winamp media player. Allows you to retrieve the lyrics for your songs with the press of a button
iM Start Center iM_Tray.exe N Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner
Image &Restore IMAGE32.exe Y Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run
ImageDrive-{hex numbers} ImageDrive.exe U Nero ImageDrive from Ahead - virtual CD/DVD drive software
Imagefox imagefox.exe U ImageFox 2.0 is an "add-on" graphics previewer for most Windows Open/Save As dialog boxes
Imagemgt32 Imagemgt32.exe X Added by the GEMA TROJAN!
imekrig imekrig.exe N Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
IMEKRMIG6.1 IMEKRMIG.EXE N Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean)
ImgIcon ImgIcon.exe U Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
ImgStart ImgStart.exe N Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
imjpmig IMJPMIG.EXE N Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
Imjpmig8.1 IMJPMIG.EXE N Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
immcheck.exe immcheck.exe ? Related to I-FORCE driver for force feedback steering wheel?
IMOL IMOLApp.exe U IncrediMail for Office Outlook Add-On
IMStart IMStart.exe U InterMute security software related
IMwire imwireup.exe X SafeSurfing parasite variant
InCD incd.exe N Ahead InCD packet writing software. Similar to DirectCD. On my system there isn't an entry, on another visitor's there is. Run manually before insert an appropriately formatted CD-RW disk
IncMail IncMail.exe N "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
Incredimail incredimail.exe N "IncrediMail is an advanced, feature-rich email program that offers you an unprecedented interactive experience. Unique multimedia features will enable you to tailor your email experience so that it fits your mood and personality"
IndexSearch IndexSearch.exe N Associated with PaperPort scanner software from ScanSoft
Inet DataBase Inetdbs.exe X Added by the QEDS WORM!
Inet Delivery Intdel.exe X Spyware
Inet Delivery intdel_2.exe X Spyware
inetcntrl inetcntrl.exe U Bsafe Online - internet filter
InetConf inetconf.exe ? ??
Inetd INETD32.EXE U Windows Inet Daemon from Hummingbird Communications. "Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons". Provides PCs with the full functionality of a UNIX workstation
inetinfo.exe inetinfo.exe U Executable used by MS Internet Information Server (IIS). If it's running, then so is IIS. Useful in knowing whether you require the patch for the Code Red worm. Comes with PWS (Personal Web Server) or NT4 and handles ASP-, PHP code (+ more)
inetmgr inetmgr.exe X Actual Names (AdvSearch) Internet Keywords parasite
Info Select is.exe U Info Select from Micro Logic - personal information manager
Info32x Info32x.exe X Added by the GEMA TROJAN!
Infoplay.exe Infoplay.exe ? Written by New Media Properties, LLC and you're asked if you want to download and install it if you visit one of their search engine websites (which I chose not to). What does it do and is it needed?
Infra-red Monitor IRMON.EXE U System Tray access to infra-red devices. Not required unless you use infra-red devices
infus infus.exe X Adult content dialler
Infuzer Infuzer.exe U Infuzer - "is a service that copies dates from the web or an email straight to your electronic calendar". Beware of the following adware trait - "Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them, as well as increasing return visits and brand awareness, and providing new e-commerce opportunities"
infwin infwin.exe X Msview parasite variant
Initial Page install.exe X EasySearch browser hijack installer
Ink Monitor InkMonitor.exe N Associated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
InkWatch InkWatch.exe N Associated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
InoRPC InoRpc.exe Y Associated with eTrust Antivirus/InoculateIT
InoRT InoRT9x.exe Y Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage - see here
InoTask InoTask.exe U Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates - see here
insCOA5 insCOA5.exe ? ??
InstallAurealDemos InstallAurealDemos.js N Used to initialize the Aureal A3D demos InstallShield wizard
InstallBuddy Ibtna.exe U InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync
InstantAccess INSTAN~1.EXE N From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
InstantDrive InstantDrive.exe U Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
InstantPleasure instantpleasure.exe X Adult content dialler
InstantPleasureXXX instantpleasurexxx.exe X Adult content dialler
instit instit.bat X Added by the OPASERV.H WORM!
instit INSTIT.BAT X Added by the OPASERV.K WORM!
InstUtlR.exe InstUtlR.exe ? ??
intdctrr idctup20.exe X SafeSurfing parasite variant
Intel Active Monitor imontray.exe U System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
Intel Product Number Utility IntelProcNumUtility.exe U Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here
Intel system works iis.exe X Added by the RBOT.QGA WORM!
IntelMEM IntelMEM.exe U Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore, it can alert you if you have made a wrong connection with your modem line
Intel® Common User Interface igfxtray.exe N Quick access to the control panel via a System Tray icon for graphics based upon the Intel chipsets (ie, i810). These chipsets are often included on motherboards. Available via Start -> Settings -> Control Panel
Intense Registry Service IntEdReg.exe N Added by Intense Educational Ltd> software to launch bilingual dictionaries.
InterCheck Monitor Icmon.exe Y Part of Sophos ant-virus sofware
Interdll Interdll.exe X Added by the DELF family of TROJANS!
internat internat.exe X Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%
internat.exe internat.exe N Language selection icon in system tray
Internat.exe internat.exe X Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a "?" icon wheras this version resides in %windir% and has a ZIP icon
Internet Answering Machine IAMNET~1.EXE U From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Internet Answering Machine IAM.exe U From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access
Internet Download Accelerator ida.exe U Internet Download Accelerator download manager
Internet Explorer iexplorer.exe X Added by the LORSIS WORM! Note - the legitimate IE (iexplore.exe) does not figure in Msconfig/Startup unless added manually and this loads from the "RunServices" key
Internet Explorer IEXPLORE.EXE X Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Internet Explorer Updater iexplorer.exe X Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Internet Service intersvc.exe X Added by the SPYBOT-DE WORM!
Internet Sharing Server iss_srvr.exe Y Intel AnyPoint internet sharing software
Internet Timer ITIMER.exe U Shareware dial-up connection call cost calculator from Ratsoft
Internet Washer Pro iw.exe X Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Internet.exe Internet.exe X Added by the MAGICCALL VIRUS!
InternetWasherPro iw.exe X Internet Washer manages temporary browser files, cookies, etc - a 'trial' Internet Washer Pro seems to have been widely stealth-installed around March 2003
Internt Internt.exe X Added by the PEEPER or CARUFAX.A TROJANS!
InterTrust Quick Start it_cpq~1.exe N InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business
InterWARN interwarn.exe U InterWARN by Storm Alert Inc. Provides customized, automated access to critical weather and civil emergency information from the US National Weather Service. Required if audio and screen crawler alerts are desired. Also available via Start -> Programs
Intmgr Intmgr.exe X Added by the GEMA TROJAN!
Intrenat Intrenat.exe X Added by the LEMIR.E and Troj/LegMir-AC TROJANS!
IntruderAlert ia99.exe X Intruder Alert '99 from Bonzi - spyware
Iomega Automatic Backup ibackup.exe U Iomega Automatic Backup - automatic backups for use with Iomega portable HDD
Iomega Automatic Backup 1.0.1 ibackup.exe U Iomega Automatic Backup - automatic backups for use with Iomega portable HDD
Iomega Disk Icons IMGICON.EXE U Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Iomega Drive Icons IMGICON.EXE U Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
Iomega ImIconXP imiconxp.exe U Iomega REV System Software - allows your Iomega REV drive to interact with the operating system via the Iomega REV UDF file system, and provides drag-and-drop file access, access and write protection, and formatting of the disks
Iomega Startup Options IMGSTART.EXE N Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs
Iomega Watch IOWATCH.EXE N Used by Iomega drives. Available via Start -> Programs
Iomon98.exe Iomon98.exe U PC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
IP Stack ipstack.exe X Added by the AGOBOT.CW WORM!
ipcfg.exe ipcfg.exe X Adware - recognized by McAfee antivirus as a variant of the AdClicker-BM trojan
IpCtrl ipcon32.exe X Added by an unidentified VIRUS, WORM or TROJAN!
IPInSightLAN 01 ipclient.exe N Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information.
IPInSightMonitor 01 ipmon32.exe N Installed with Verizon DSL accounts. IP Insight is a Quality of Service monitor and diagnostic tool that isn't required - see here for more information
ipmon.exe ipmon.exe X Added by the RECERV or R3C.B TROJANS!
iPodManager iPodManager.exe U Apple iPod Management software for the iPod MP3 player. Allows updating, formating, restoring and other functions associated with iPods
iPodWatcher iPodWatcher.exe ? Associated with Apple's iPod MP3 player. Detects when the iPod is connected?
iProtectYou ip.exe U iProtectYou - internet filtering/parental control and network monitoring software
IPSecMon IPSecMon.exe Y Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
IPW IPW.exe ? ??
IQES.exe iqes.exe ? ??
IREIKE IreIKE.exe Y Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet
IrMon IRMON.EXE U System Tray access to infra-red devices. Not required unless you use infra-red devices
IRPMonitor itcnmon.exe ? ??
irwftp iexplorer.exe X Added by the BANKER-AN TROJAN!
IrXfer IrXfer.exe U Microsoft Infrared Transfer application
ir_ftp ir_ftp.exe X Added by the IRFTP TROJAN!
ir_ftp irwftp.exe X Added by the BANCOS.H TROJAN!
Isass Isass.exe X Added by the FUTRO TROJAN!
isdbdc isdbdc.exe N For Compaq PC's. May install properties in dial-up networking when you register with an ISP
ISDNwatch IWatch.exe U FRITZ!X ISDNWatch - "dialing filter for more security and control on the ISDN PC. The PC is doubly protected against dialer programs and premium-service numbers: ISDNWatch allows the user to block calls to and from both individual numbers and whole number blocks"
ISLP2STA ISLP2STA.EXE N Possibly a left over from Windows Update for wireless NIC (maybe Linksys) drivers? Not required though
iSpyNOW ispynow.exe U iSpyNOW - remote monitoring and surveillance software
Israfel Israfel.vbs X Added by the GAGGLE.D or GAGGLE.E WORMS!
ISStart ISStart.exe U LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
IST Service istsvc.exe X ISTBar foistware
ISUSPM Startup ISUSPM.exe N InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version
ISUSScheduler issch.exe N InstallShield Update Service Scheduler. Automatically searches for and performs any updates to the software so you’re always working with the most current version
Itk Itk.exe U In The Know - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it
iTouch iTouch.exe U iTouch loads the iTouch configuration program for Logitech keyboards. It’s needed if your keyboard has shortcut buttons and if you use them. It’s also needed if your keyboard does not have the num lock, caps lock, and scroll lock lights on it and you use the on-screen displays for num lock, caps lock, and scroll lock
ItsDeductiblePopUp ItsDeductible.exe N ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip
iTunes Helper iTunesHelper.exe Y Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
IW ControlCenter iwctrl.exe N Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
iwctrl iwctrl.exe U Pinnacle Systems InstantWrite enables you to use your CD-R, CD-RW and DVD-RAM drive just like a hard disk or floppy disk. You can drag and drop files, create new directories right on your CD-R, CD-RW or DVD-RAM. Maybe required if you use this feature on a regular basis
Java Runtimes iexplore.exe X Added by the KILLAV.B TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
LogitechGalleryRepair ISStart.exe U LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
LogitechVideoRepair ISStart.exe U LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation
Microsoft Associates, Inc. iexplorer.exe X Added by a variant of the LOVGATE WORM!
Microsoft Associates, Inc. iexplorer.exe X Added by a variant of the LOVGATE WORM!
MICROSOFT FIREWALLCLIENT ISATRAY.EXE Y MS Internet Security and Acceleration Server 2000
Microsoft IE Iexplore.exe X Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Microsoft IE Execute shell IEExec.exe X Added by the ALADINZ.N TROJAN!
Microsoft Inc. iexplorer.exe X Added by a variant of the LOVGATE WORM!
Microsoft Internet Acceleration Utility iau.exe X EasySearch adware
Microsoft Internet Exp iiexplorer.exe X Added by the RBOT-KX WORM!
Microsoft Internet Explorer iexplore.exe X Downloader trojan. Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Microsoft IT Update IEserv.exe X Added by a variant of the RBOT WORM!
Microsoft media services Iassd.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Microsoft System Checkup inetman.exe X Added by the DONK.O WORM!
Microsoft Update Isac.exe X Added by the RBOT-AU WORM!
Mirabilis ICQ icq.exe N If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
Mirabilis ICQ ICQNet.exe N If connected to the internet, automatically runs up ICQ. Convenience more than anything. ICQ can be started from Start -> Programs
MSPY2002 ImScInst.exe N Part of Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
MSStartOptimizer Iexpres.exe X Added by the POLDO.B TROJAN!
mssysint Iexplore .exe X Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
MSVersion INTERNETFEATURES.exe X Added by the POPMON.A TROJAN! - also known as PopMonster adware
Name Iexplorer0.exe X Added by the THREADSYS TROJAN!
NetworkAssociates Inc internet.exe X Added by the LOVGATE WORM!
News Service ispnews.exe ? F-Secure antivirus related. However, is this particular item required?
Nielsen NetRatings insight.exe N Nielsen NetRatings -  "Provides real-time research and analysis about Internet users, delivering the timely, actionable data you need to make critical business decisions on your competition, your Web site’s audience and your customers". Is it required?
OPTIMIZER iexplore.exe X Added by the EVIVINC TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Praize Messenger itLoad.exe U Praize IM Christian chat instant messenger
Program in Windows iexplore.exe X Added by a variant of the LOVGATE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
Randex virus built for IRBMe irbme.exe X Added by the RANDEX.RH WORM!
rate.exe i11r54n4.exe X Added by the BEAGLE.E or BEAGLE.F or BEAGLE.G or BEAGLE.H or BEAGLE.I WORMS!
Remote Update Monitor imonitor.exe Y Sophos Antivirus Remote Update utility - provides an easy way for remote workers to keep up to date with their virus protection via a website or network connection provided by their employer
RenolB ib.exe ? ??
run= info32.exe X CoolWebSearch parasite variant
rundll32 irprops.cpl U Associated with BlueTooth software, and registers the "Infrared Port properties" Control Panel applet. Should you get the error message, "Rundll irprops.cpl missing entry Bluetooth authentication agent", click here here for more information. In case you no longer have BlueTooth support installed, and don't need it, simply uncheck the entry in Msconfig > Startup
ScanInicio Inicio.exe ? Part of Panda Anti-Virus. Responsible for scanning the boot sector of your disk and your memory at startup to check for viruses that try and load and act before your anti-virus is fully operational. It only adds a fraction of a second to start-up time and is worth leaving active
scvhost loader ixplore.exe X Added by the SDBOT-CY TROJAN!
ServiceConfig ispbeg.exe U Comcast Transition Wizard. On June 30th, 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
SetupICWDesktop icwconn1.exe N Appears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
Shmgrate.exe ibot4.exe X Added by the GASTER TROJAN!
slide Iexplore.exe X Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
ssate.exe irun4.exe X Added by the BEAGLE.J WORM!
ssgrate.exe irun.exe X Added by the MITGLIEDER.D TROJAN!
ssgrate.exe irun4.exe X Added by the MITGLIEDER.F TROJAN!
stcinstaller id53.exe X Added by the SCTHOUGHT.L TROJAN!
Sweep95 ICLOAD95.EXE Y Part of Sophos ant-virus sofware
syscheck iexplorer.exe X Added by the AGENT.DM TROJAN!
sysconfig iexplorer.exe X Added by the CULT.C WORM!
sysconfig iexplorer.exe X Added by the CULT.H WORM!
System Configuration iexplore.exe X Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process, which should not appear in Msconfig/Startup unless you add it manually!
SystemInit iservc.exe X Added by the FIZZER WORM!
Threaded intcp32.exe X Added by the RANDEX.UG WORM!
ToPicks Starter Idhost.exe X ToPicks parasite related
TrojanShield Init.exe U TrojanShield
True Internet Color Icon internetcolor.exe U Part of Colorific & 3Deep from LightSurf Technologies (nee E-Color). "With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"
VOBID InstantDrive.exe U Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer’s hard drive. Part of InstantCD/DVD burning software
Websx Int*****.exe X Adult content dialler - where ***** are random
wfips iphider.exe U ICQ (messaging/chat program) anti-bomb software. "WFIPS is anti-bomb software for safeguarding ICQ Bomb before the bombing. 'ICQ Defoolder' is a tool for removing ICQ bomb after being exposed." For more information about ICQ bombs see here
Windows Backup Configuration IEXPLORER.exe X Added by the GAOBOT.AZ WORM!
Windows Fix integator.exe X Added by the SDBOT.ZAB WORM!
Windows Taskbar Manager internat.exe X Added by the PROTORIDE-H WORM!
Windows Update iexplorere.exe X Added by the GAOBOT.AP WORM!
Windows Update inetinf.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
WinVNC iexplorer.exe X Added by the EVIVINC VIRUS!
Win_Library INISvc.exe X Added by the ANARCH WORM!
WUPD iglmtray.exe X Added by the TZET WORM!
zBrowser Launcher iTouch.exe U For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn't have them
ZipDisk Icons IMGICON.EXE U Displays Iomega icons in Explorer/My Computer, ejects Zip disks on shutdown and displays a special delete confirmation box when deleting files on an Iomega drive. Available via Start -> Programs. If you disable it remember to eject disks first before powering the drive down - hence the "U" recommendation. Note - FreeCell may not run with ImgIcon running
\IEService.exe IEService.exe X FastFind parasite variant
iPod Service iPodService.exe N This service is used by Itunes for using your Ipod. If you do not use Itunes you can disable this service.
NvMsnW Isass.exe X Added by the W32/Bropia-M worm.
Anti ISASS.EXE X Added by the W32/Bropia-M worm.
ICQ ICQNET.vbs X Added by the VBS.Gormlez@mm infection! Found in the C: drive.
Internet Explorer Configuration Iexplore.exe X Added by the http://www.sophos.com/virusinfo/analyses/w32sdbotgib.html Backdoor/Worm! Found in the Windows system folder
IExplorer IExplorer.EXE X Troj/Bancos-BC is a password stealing infection that targets users of Brazlilian banks. Found in the Program Files directory.
IEXPL0RER IEXPL0RER.EXE X Added by the W32/Agobot-QL WORM! File is found in the Windows system folder.
intnets intnets.exe X Added by the Adware.Adtest browser hijacker. Found in the Windows system folder.
Internet Explorer IE.EXE X Added by W32/Sdbot-VS TROJAN/backdoor. Remote access, by way of the IRC network, becomes available to unauthorized users.
IP IP.EXE X Added by a WORM, W32/Agobot-QO.
winsockdriver IEXPLOR.EXE X Added by the W32/WarPigs-C WORM/IRC backdoor TROJAN! It is found in the Windows system folder.
[not used] inject.exe X Added by Troj/Small-EH it also installs RSHELL32.DLL, both are hidden in the Windows system folder. Once run, .DLL may modify a system component to penetrate a firewall and provide a new remote shell which can be exploited.
run inetinfo.exe X Added by the BINGHE backdoor Trojan! It has the ability to log your keystrokes, steal data, and execute commands.
Indexindicator Indexindicator.exe X Added by the LAZAR trojan downloader.
ISSVC ISSVC.exe Y Part of Norton Internet Security Suite
RunCA InvokeSvc3.exe Y Wireless-G USB Wireless Network Adapter related - would appear to be required
Ibs ibs.exe X The Troj/HideDial-B TROJAN adds this, and downloads a third-party dialler application to C:MISB.EXE.
Logitech Desktop IPCONN.EXE X Added by the W32/Sdbot-WE WORM/IRC backdoor Trojan!
zsmsgs iservice.exe X Added by the Troj/Bancos-BU TROJAN!
Fujitsu Hotkey Utility IndicatorUty.exe N Fujitsu Hotkey Utility is a process that displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook. E.g. when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed.
ITUNES itune.exe X Added by the W32/Rbot-ZU WORM/IRC backdoor Trojan!
ControlPanel internst32.exe X Added by the Adware.StartPage.B hijacker.
EasySearch Start Page install.exe X Added by the Adware.Umaxsearch hijacker.
SVCHOST internat.exe X Added by the Backdoor.AntiLam.20.K.
winprofile iexpiore.exe X Added by a variant of the MONCHER WORM!
IefxTray Iefxtray.exe X Added by the Troj/Bdoor-ZAS. The backdoor can be instructed by remote users to find and read arbitrary files.
Internet Internet.exe X Added by the Troj/Singu-I. It will steal passwords and listen for remote commands.
Unix File Support init3.exe X Added by the W32/Rbot-ZN WORM/IRC backdoor Trojan!
IPConfig ipconfigs.exe X Added by the Backdoor.Hacarmy.C backdoor trojan.
Network Connections internat.exe X Added by Troj/VB-ZD along with another file run from the system folder, "/rundll32.exe", named Background Intelligent Transfer Service.
Configuration Loader10 ip7.exe X Added by W32/Agobot-ANZ.
Adiliwut ihotunib.exe X Added by W32/Sdranck-C.
IExplorer7 Java Scripting IExplore327.exe X Added by a variant of the W32/SDBOT WORM!
IExplorer6 Java Scripting IExplore326.exe X Added by a variant of the W32/SDBOT WORM!
Windows Updater iexplorerrs.exe X Added by the W32/RBOT-TN WORM
Microsoft Dev iexplorer32.exe X Added by a variant of the AGOBOT/GAOBOT WORM!
Internet Content Publisher ICP.EXE X Added by the W32/RBOT-UD WORM!
Internet Server inetsrv.exe X Added by the Troj/StartPa-EM TROJAN!
instant messengers instantmsgtr.exe X Added by the W32/Agobot-PC WORM/IRC backdoor trojan!
Win32 Processer iexplore.exe X Added by the W32/Agobot-PA WORM/IRC backdoor trojan!
MsWin Update IFA32.EXE X Added by the W32/Rbot-BU trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
iexplo iexplor.exe X Added by the Trojan.Sidea Trojan.
AtxBrw IEXPLOR.exe X Unidentified Malware.
C:\WINDOWS\IEXPLOR.EXE IEXPLOR.exe X Unidentified Malware.
IE New Window Maximizer iemaximizer.exe U IE New Window Maximizer, see here - automatically maximize new Internet Explorer and Outlook Express windows.
Microsoft Update Machine infoDLL.exe X Added by the W32/Rbot-EH trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
LSASS 32 ISASS32.pif X Added by the W32/Assiral-C email worm.
[not used] init32m.exe X Added by the Troj/Dloader-JT or Troj/Dlsw-B trojan downloaders.
iexplore.exe iexplore_dbg.exe X Browser Hijacker to http://default.home and possibly other locations.
iTunesMusic iTunesMusic.exe X Added by the W32.Spybot.NLX worm. This worm utilizes the rdriv.sys rootkit to stealth itself.
kernel32sys.dll IEXPLORER.exe X Added by the W32/Rbot-MK trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
micr0s servicese instmsgr.exe X Added by the W32/Rbot-TR worm.
IExplorer Iexplor32.exe X Added by the Troj/Bdoor-BY trojan backdoor. This infection allows remote access via TCP port 23.
Microsoft Synchronization Manager InfoNT.exe X Added by the W32/Sdbot-TR IRC backdoor trojan. When started this infection connects to an IRC server where it waits for remote commands to execute. This infection logs keystrokes to a file named keylog.txt.
windows iexplore.exe X Added by the W32/Rbot-UM worm. When started this infections connects to a remote IRC server where it waits for commands to execute.
iesprt IESPRT.SYS X Added by the Troj/Goldun-G password stealing trojan. If you have this infection you should change all your passwords.
reluvage ilulupac.exe X Added by the W32/Sdbot-UJ worm. When connected this infections connects to an IRC server where it waits for remote commands to execute.
xevivi isesobo.exe X Added by the W32/Sdbot-US trojan. When started this infection connects to a remote IRC server where it waits for commands to execute.
Windows Services IEXPLORE.EXE X Added by the W32/Rbot-WE worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
mousedrive.exe instantmsgrs.exe X Added by the W32/Forbot-ER worm. When started this infection connects to a remote IRC server where it waits for commands to execute.
Norton Personal Firewall IntroWiz.exe Y Part of Norton Personal Firewall or Norton Internet Security
zBrowser Launcher iTouch.exe U For a Logitech internet keyboard - loads the software for the shortcut keys on the keyboard. Also used to display your keyboard LEDs on-screen to indicate Caps Lock, etc if it doesn
dark imgst.scr X Added by the Troj/Bancban-CK password-stealing trojan. This infections targets customers of Brazilian banks.
StartupBin iwnujdss.exe X Added by the W32/Sdbot-XZ worm.
The Intranet intranet.exe X Added by a variant of the W32/SDBOT WORM!
InstaFinderK InstaFinderK_inst.exe X VistaBar/Instafinder parasite related
Microsoft Special offer infoebay.exe X Added by a variant of the WIN32.RBOT WORM
easywww iewwwint.exe X EasyWWW adware
bootcfg Install.log.vbs X Added by the VBS.YPSAN.D WORM!
internat32 internat32.exe X Added as result of a Octa-B trojan infection
internet protocol configuration loader ipcl32.exe X Added by the SDBOT TROJAN!
iprun iPY.exe X Added by iProtectYou SPYWARE!
isystem isystem.exe X Added by the Troj/Chorus-A browser hijacker.
lsass32 Isass32.exe X Added by the W32.KELVIR.M WORM!
plaxoupdate InstallStub.exe U Installstub.exe is is Plaxo's core executable program, which is used to check for new or updated information from the Plaxo Network. This program also interacts with Outlook.
sysres IExpIore .exe X Added by the W32.ELITPER.E WORM!
system restore dlls ixplorer.exe X Added by a variant of the W32/SDBOT WORM!
Start Upping iexplorerupdt.exe X Added by the W32/Rbot-RR worm. This infection connects to an IRC server where it waits for remote commands.
Internet Services internet.exe X Added by the W32/Mytob-AU worm. This infection connects to an IRC server on startup where it waits for remote commands to execute.
Configuration Loaded iexploree.exe X Added by the W32/Sdbot-KC worm. When started this infection connects to an IRC server where it waits for remote commands.
icasserv icasServ.exe X Browser hijacker, redirecting to Searchforfree.info
icq chat service icqjdhs.exe X Added by a variant of the WIN32.RBOT WORM!
iexplorer32c java scripting IExplore32cb.exe X Added by the RBOT.ABN WORM!
outlooks InSane.exe X Added by the SWOOP TROJAN!
itunes itunes.exe X Added by a variant of the WIN32.RBOT WORM! - NOTE - this file will be placed in de Windows\System32 or Winnt\System32 folder, and should NOT be confused with the (legitimate) Apple iTunes process, always located in the Program FilesiTunes folder.
iexplorer32 java scripting IExplore32b.exe X Added by the RBOT.ABO WORM!
iexplorers loader iexplorers.exe X Added by the W32/Sdbot-DQ worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
IRBMe Sucks!! IRBMe.exe X Added by the W32/Randex-Y worm. When started, this infection connects to an IRC server where it waits for remote commands to execute.
System ISVC.EXE X Added by the Troj/LdPinch-AZ trojan.
iecheck.exe iecheck.exe N Integrity checker for IconEdit2 icon editor. It serves for IconEdit2 internal tasks only and can be safely deleted from the system if you are running the latest version of IconEdit2
ieexec.exe ieexec.exe X Added by an unidentified WORM or TROJAN!
ituneshelper iTunesHelper.exe Y Installed with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
macromedia drive Iexplor32.exe X Added by a variant of the WIN32.RBOT WORM!
microsoft firewall client ISATRAY.EXE Y MS Internet Security and Acceleration Server 2000
ias ias.exe U InvisibleASpy keystroke logger/monitoring program - remove unless you installed it yourself!
IntelWireless ifrmewrk.exe Y Associated with the Intel PRO/Set Wireless software.
istinstall_zazzer.exe istinstall_zazzer.exe X Unidentified adware downloader/installer
ivpservicemgr ivpsvmgr.exe N Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba’s equivalent to the Windows Automatic Update feature as, whenever you are connected to the Internet, it will check for Windows updates and Toshiba updates. Not required.
ixplores ixplores.exe X Added by the W32/SdBot-CE backdoor worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
[unknown] IECONTROL.EXE X Added by the W32/Sdbot-HO worm. When this infection starts it will connect to an IRC server where it will wait for remote commands to execute.
Sts iwnujdss2.exe X Added by the W32/Sdbot-YI worm. When started this infection connects to an IRC server where it waits for remote commands.
[unknown] ION.EXE X Added by the W32/Sdbot-ID worm. When started this infection connects to an IRC server where it waits for remote commands. This program will log keystrokes to a file called c:\windows\system\keylog.txt.
Windows driver update Ipconfig32.exe X Added by the W32/Sdbot-JV worm. When started this infection connects to an IRC server where it waits for remote commands.
cmssapp iexplore_.exe X Added by the Troj/Bancban-CQ trojan.
microsoft ie sasser ISASS.EXE X Added by the SDBOT.MX WORM!
Reg Service ipcfg.exe X Added by the W32/Agobot-SO worm. When started this infection connects to an IRC server where it waits for remote commands.
MMC inisys.exe X Added by the W32/Agobot-SU worm. When started this infection connects to an IRC server where it waits for remote commands.
IPC Connection ipcconn.exe X Added by the W32/Rbot-AEG worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ieharv.exe ieharv.exe X Added by the Troj/Banker-HH password stealing trojan.
Regional Value isng.exe X Added by the W32/Sdbot-OW worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Runtt1 Internet.exe X Added by the Troj/Lineage-Q password stealing trojan for the game Lineage.
ibm ibm.exe X Added by the Troj/LegMir-AH trojan.
WinProfile iexpIore.exe X Added by the Troj/Chum-C trojan.
WINDOWS SYSTEM CLEANER iexplore.exe X Added by the W32.Mytob.ET@mm worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
injob injobs.exe X Added by the Trojan.Binjo trojan.
[variable names] ie_32.exe X Added by the Spyware.Acext spyware.
[random name] intfaxui.exe X Added by the Spyware.Apropos spyware.
Systems itDDD.exe X Added by the Troj/Dloader-P downloader trojan.
cmssapp iexplore.exe X Added by the Troj/Bancban-DM password-stealing trojan.
init32 Init32.exe X Added by the W32.WINEX.A TROJAN!
intel32.exe intel32.exe X Added by a variant of the SmitFraud alias FAKEALE-C TROJAN!
internet services interserv.exe X Added by the RBOT.BNT WORM!
microsoft opeions IEXwe.exe X Added by a variant of the WIN32.RBOT WORM!
inetinfomon manager inetinfomon.exe X Added by the Trojan.Spexta trojan. When infected your computer will become an open mail relay which will allow your computer to be used to send out spam.
olympic IE4321.exe X Adult content premium rate dialer - also detected as Trojan.Win32.Small.CZ
WIN32 image.exe X Added by the W32/Sdbot-AAQ worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
iexpl0res iexpl0res.exe X Added by the RBOT.AEX WORM! - NOTE: this malware actually changes the default value data of the Registry "Run" key in order to force Windows to launch it at boot
microsoft hosts service Isass.exe X Added by a variant of the WIN32.RBOT WORM!
dark imgrt.scr X Added by the Troj/Bancban-DU password-stealing trojan targetting Brazilian banks.
[not used] iexplore.com X Added by the Troj/Pcik-A trojan.
intell32.exe intell32.exe X Added by the Trojan.Desktophijack.C trojan. This infection modifies the Windows desktop to display a false warning.
Inet Delivery inetdl.exe X Added by the Adware.IntDel adware.
iisvers iisvers.exe X Added by an unidentified TROJAN or adware
inet delivery inetdl_2.exe X Inet_Delivery adware
instant buzz daemon IBDaemon.exe X Instant_Buzz adware
ipod usb driver IPODUSB.EXE X Added by a variant of the WIN32.RBOT WORM!
ipsecdialer IPSECD~1.EXE -run_only_if_connected -auto_initiation U The Cisco VPN_Client lets local users gain Administrator privileges on the operating system
isbmgr.exe ISBMgr.exe ? Belongs to Sony's ISB Utility. what does it do and is it required?
ICQ Messenger 2002 ICQ2002.exe X Added by the W32/Sdbot-ABL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
MSN Messenger IExplorer.exe X Added by the Troj/Banker-EU password-stealing Trojan.
iexplorer iexplorer.ie X Added by the Troj/NetDevil-A backdoor Trojan.
test i love you.exe X Added by the Troj/Singu-T password-stealing Trojan.
Client Agent ipxwping.exe X Added by the Troj/PPdoor-N backdoor Trojan.
internat internat.dic X Added by the Backdoor.Djump backdoor.
Policy Agent ipsec.dll X Added by the Backdoor.Fuwudoor backdoor.
STOPzilla IS3WLHandler.dll Y Part of STOPzilla.
isDeleteMe isDel.bat Y Used by Norton Internet Security to remove certain files and directories on reboot when uninstalling their product.
ALG.EXE iexplorer .exe X Added by the W32/Demotry-B worm.
iglpbv Iglpbv.exe ? ??
ibwin background process IBackground.exe U IBackup for Windows
ibwin monitor IBMonitor.exe U IBackup for Windows
Internet Explorer Security iexplore.pif X Added by the W32/Rbot-ALQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Windows HWinfo Loader iexplre.exe X Added by the W32/Rbot-ALS worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Intespention IEXPLORE.exe X Added by the W32/Forbot-FL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
infopenmsn InfoPenIM.exe U InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand
iprint tray iprntctl.exe N Novell® iPrint - based on Novell Distributed Print Services - enables you to send documents to printers located throughout the Net.
mrublaster indexcleaner.exe U MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder
iexplorer iexplorer.exe X Added by the Troj/Singu-U password-stealing Trojan.
Micrcoft Updat Internet.exe X Added by the W32/Rbot-ANA worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Shell ibm00001.exe X Added by the Troj/Torpig-C Trojan.
Microsoft(R) Windows(R) Operat iexplorer.exe X Added by the Troj/Feutel-W Trojan.
IPFW ipwf.exe X Added by the Troj/Dloader-UC Trojan.
Iexploit Iexploit.html X Added by the VBS.Inker.B@mm mass-mailing worm. This worm will also swap your mouse buttons, change icons, and lower security settings.
Ipnuker Ipnuker.vbs X Added by the VBS.Inker.B@mm mass-mailing worm. This worm will also swap your mouse buttons, change icons, and lower security settings.
[not used] inetinfo.exe X Added by the Troj/Proxy-GG proxy Trojan.
Local Service Intenat.exe X Added by the Troj/Nuclear-J backdoor Trojan. This infection also creates a file called Notepad.txt in your Windows %System% folder.
iccontrol iccontrol.exe X Added by the ICcontrol premium rate adult content dialer
ihp-100 iHPDetect.exe ? Drive Letter Searcher , iRiver iHP-100 iHP and H Series player related - does it need to start with Windows every time?
intersoft msngr intersoftmsngr.exe X Added by the W32/AGOBOT-NW WORM!
issenc32svr issEnc32.exe X Added by a variant of the WIN32.RBOT WORM!
persistence igfxpers.exe N Associated with the Common User Interface module for Intel graphics cards
windows incontext InSearch.exe X Z-Quest
tdongbot Internet.exe X Added by the Backdoor.Sdbot.AS worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
MSControl3d1 isasse.exe X Added by the W32/Rbot-APE worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
Windows connection manager Internet.exe X Added by the W32/Rbot-APN worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands.
ini910u.sys ini910u.sys Y INITIO ini910u SCSI miniport driver added by Microsoft.
Internet Explorer Internet.exe X Added by the Troj/Feutel-AA backdoor Trojan.
MSN Funny Images imsngsr.exe X Added by the W32/Agobot-TT worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
SerDgeonServer IExplore.exe X Added by the Troj/Feutel-AC backdoor Trojan. Note: this is not the the legitimate iexplore.exe found in the C:\program files\internet explorer directory.
MS WINS Binary IGN32.pif X Added by the W32/Rbot-ASB worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer.
boy lovers of bsd ilikeboys.exe X Added by the MYTOB.LY WORM!
ipod usb service iPODService.exe X Added by a variant of the WIN32.RBOT WORM! - Do NOT confuse with the Apple iPod process of the same name. The legitimate iPod file will always be located in the Program FilesiPodbin folder, and is implemented as a system service, thus NOT listed in Msconfig/Startup!
imontray imontray.exe U System tray monitoring of fans, temperature, voltage, etc for Intel motherboards. Only needed if you "overclock" or live in hot environment. Can also cause problems when running on a laptop if you change PCMCIA cards
msn messenge IExplorer.exe X Added by the Troj/Delf-LL
wusb54gv2 InvokeSvc3.exe Y Wireless-G USB Wireless Network Adapter related - would appear to be required
icm ICM.EXE Y Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail
cms iserver.exe X Added by the Troj/Dloader-WK Trojan.
Microsoft iexplore.exe X Added by the Troj/QQRob-R downloader Trojan.
Microsoft Update 33 init.exe X Added by the W32/Rbot-ATT worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
ies4dll IES4DLL.DLL X Added by a variant of the Troj/Haxdoor Trojan. This infection utilizes the ies4service.sys rootkit.
System inetinfo.exe X Added by the Troj/ParDrop-A dropper Trojan.
checkvcr IOMagic.exe Y Driver for the I/OMagic Personal Video Recorder (DR-PCTV100)
ishield iShield.exe U GuardWare iShield blocks pornographic images when you surf the Internet on your computer using a web browser
isreminder ISPopup.exe N Related to GuardWare iShield - this is the registration reminder for the trial version, so not required in startup.
IPtable ipconfig32.exe X Added by the W32/Tilebot-AP worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
Install Install.exe X Added by the Troj/Bancban-HG Internet banking Trojan.
NVagent Informe.exe X Added by the W32.Vig.C virus.
Symantec Informe.exe X Added by the W32.Vig.C virus.
IEFilter IEFilter.dll X Added by the Troj/SrchSpy-A Trojan.
IE Java Update iejava.exe X Added by the Troj/Agent-HD backdoor Trojan.
ipreg ipreg.exe X Added by the Troj/Zagaban-H password-stealing Trojan.
Bron-Spizaetus inf31.exe X Added by the WORM_RONTOKBRO.M mass-mailing worm.
IMEvtMgr.exe IMEvtMgr.exe X Added by the Troj/Keylog-AR keylogging Trojan. This infections logs keystrokes to C:\windows\_key.txt and mouse movements to c:\windows\_mouse.txt.
(Default) ipconfx.exe X Added by the Troj/Sharp-M Trojan.
ixproxy ixproxy.exe X Added by the Troj/Xorpix-A proxy Trojan.
Internet Explorer iexpiore.exe X Added by the W32/Rbot-AZC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
information update iu.exe X Reported by Kaspersky Anti-Virus as Downloader.Win32.Centim.ch TROJAN!
Windows Update install.exe X Added by the Troj/Banker-IB password-stealing Trojan for online banks.
{2250D9C6-4CC7-4826-8EFD-1D04AFC7F7F0} ISiNET.DLL X Added by the Troj/DelfDrop-A Trojan.
{081FE200-A103-11D7-A46D-C770E4459F2F} inetapi64.dll X Added by the Troj/LegMir-AG Trojan.
lspins igps.exe X Kapersky identified it as Trojan-Clicker.Win32.VB.kc.
Win System IsysUninst.exe X Added by the Troj/Banker-IJ Internet banking Trojan.
Local Security Authority Subsystem Service Iass.exe X Added by the W32/Tilebot-CA worm and IRC backdoor.
IEAgent update check iewatch.exe X Added by the Troj/Agent-FV Trojan.
ShellRun32 iexplore.exe X Added by the Troj/IRCBot-AY IRC backdoor Trojan.
IDTemplates IDTemplate.exe X Added by the W32/Brontok-H worm.
bbc imsins.exe X Added by the Troj/Hupigon-U Trojan. This infection also installs the files C:\Windows\imsins.dll and C:\Windows\imsins_Hook.DLL.
irassync irasyncd.exe X Added by Adw.NewAds.IRASSync
InterBase INTERBASE.EXE X Added by the Troj/RemShell-B backdoor Trojan.
SecurityCenter INTERBASE.EXE X Added by the Troj/RemShell-B backdoor Trojan.
MS Host Manager ivhost.exe X Added by the W32/Rbot-BJN worm and IRC backdoor.
itunesff itunesff.exe X Identified by NOD32 as the Win32/Dialer.EB adult premium dialer.
Notification Utility itbill.exe X Added by the Movieland adware. Movieland is a potentially unwanted application that has been reported as causing pop up advertisements on computers. Users may also find it difficult to uninstall the application.
i386p I386P.SYS X Added by the Backdoor.Rustock backdoor.
iobi iobiClient.exe U iobi_Home a mail/voice service by Verizon
[Various Names] iehelper.exe X Part of the Wareout infection as described here.
[Various Names] install2.exe X Part of the Wareout infection as described here.
[Various Names] init32.exe X Part of the Wareout infection as described here.
[Various Names] InpriseMon.exe X Part of the Wareout infection as described here.
[Various Names] iesetupdll.exe X Part of the Wareout infection as described here.
(F084FD46-EB63-4CC0-B814-99C16EE76BD1) InfoMz.Ime X Added by the Troj/Delf-WC Trojan.
(F084FD46-EB63-4CC0-B814-99C16EE76BD1) InfoMz.Ime X Added by the Troj/Delf-WC Trojan.
Windows Security Updater inetinfo.exe X Added by the W32/Rbot-BPP worm and IRC backdoor.
iesdl4l iesdl4l.dll X Added by the Troj/Haxdoor-AQ backdoor Trojan. This infection utilizes the C:\Windows\System32\iesservice4.sys rootkit.
Windows Updater inetinfo.exe X Added by the Troj/Sdbot-AMX worm and IRC backdoor.
im_autorn im_1.exe X Added by the Troj/BagleDl-BJ Trojan.
im_autorn im_2.exe X Added by the Troj/BagleDl-BO Trojan.
iexpand.exe iexpand.exe X Added by the Trojan.PSW.Platan.5.A password-stealing Trojan.
Windows Service Manager initsvc.exe X Added by the W32/Rbot-BWT worm and IRC backdoor.
intell321.exe intell321.exe X Installed by various Smitfraud variants to issue fake task bar security alerts stating that you are infected and need a special software to remove it.
intelliflag_be.exe Intelliflag_be.exe U Added by the Spyware.Intelliflag surveillance software. This program should be uninstalled if not installed by yourself.
miscrosoft windows explorer IEEXPLORER.exe X Reported as Win32/IRCBot.worm.74240.J
runapp icqchk.exe X Added by the Bomka
iets.exe iets.exe X Added by the Troj/Rizon-D Trojan.
iewq32.exe iewq32.exe X Added by the Troj/Banker-AKW Trojan.
Ip4Sec ip.sys X Added by the Trojan.Satiloler.E information-stealing Trojan.
Internet Linkwork Internet.exe X Added by the Troj/Agent-AMU Trojan.
InvisibleDrvNT InvisibleDrvNT.sys X Added by the Troj/Haxdor-Fam Trojan. This driver utilizes rootkit stealthing technology to hide other malware.
Microsoft Machine Script iexplorersis.exe X Added by the W32/Rbot-CMH worm and IRC backdoor.
boby Isass.scr X Added by the Troj/Bancban-OH Internet banking Trojan.
icabar icabar.exe Y Related to Citrix MetaFrame
windows ip security ipsec.exe U Related to the VPN_IPSec_utility Used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel.
NtDIC(ntdic) icntrl.exe X Added by the W32/Tilebot-EG worm and IRC backdoor.
MSN IM Update imupdate.exe X Added by the W32/VB-ATA Windows Messenger worm.
IMprocess IM-svr.EXE X Added by the Troj/IM-SR Trojan. Sends advertisements via instant messenger clients.
Navegate iiexplorer.exe X Added by the Troj/Bancban-OP Trojan that steals banking information for Brasillian banks.
ISPSystem ISPSupport.exe X Added by the W32Mytob-HH mass-mailing worm and IRC backdoor.
INET E inete.exe X Added by the W32/Rbot-DCL worm and IRC backdoor.
Windows Configuration System IExplore.exe X Added by the W32/Rbot-DDG worm and IRC backdoor.
[not used] ieen445F8764.dll X Added by the Troj/Opnis-D Trojan.
ipf ipf.exe X Added by the Troj/DwnLdr-BWA downloader Trojan.
{70fbd528-2d3c-4a00-9b8c-bbf441e534be} iqzv.dll X A file used by the rogue antispyware app, SpyFalcon, to issue fake security alerts on your taskbar.
Patah Hati ISASS.exe X Added by the W32.Pahatia.A worm. This infection should not be confused with the legitimate Microsoft file C:\Windows\System32\lsass.exe.
{e5b1e382-817e-4b74-8a96-ec78751e6acf} imfdfcj.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
{55059d4f-a1ac-4837-ae07-4859101f598d} icima.dll X A file used by the rogue antispyware app, SpywareQuake, to issue fake security alerts on your taskbar.
ishost.exe ishost.exe X Added by the Troj/Dloadr-XJ downloader Trojan.
dark iexplore.scr X Added by the Troj/Banker-BWI password-stealing Trojan for online banks. If you are infected with this Trojan please immediately change all your online banking information.
IE Redir ieredir.exe X Added by the Troj/Dloadr-XR Trojan.
RunOnceEx iernonce.dll N Part of Internet Explorer 5.5 and is used to perform a specific task once.
LOGON suport service ies4service.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
ioco iop.exe X Added by the W32/Sdbot-BZD worm and IRC backdoor.
NEWTRO IEXPLORE.COM X Added by the Troj/Larx-A Trojan.
inetsrv inetsrv.exe X Added by the W32.Resik.A worm.
LOGON support service iesservice4.sys X Added by a variant of the Troj/Haxdor-Gen rootkit.
enterra icon keeper IcnKeepr.exe U Related to Icon_Keeper Solution to the icons arrangement problem by creating several profiles
ibmprc ibmprc.exe U Related to IBM Corp. This is not an essential system process although it should not be terminated unless suspected of causing problems. See here
iphsend IPHSend.exe N Related to AOL Software. This is a non-essential program, but should not be terminated if not suspected to cause problem. Note: located in C:\Program Files\Common Files\AOL\IPHSend\
ippdetect IPP4Detect.exe U Related to Mr.Photo A Multimedia Suite with DVD Authoring!
ipwins ipwins.exe X Added by ClickSpring/PurityScan ADAWARE!
irssyncd irssyncd.exe X Identified by ewido, SafeSurfing parasite variant
itype itype.exe U Related to Microsoft_IntelliType_Pro MS Keyboard Software.
safetynet ipcTray.exe U Related to SafetyNet Traffic Management and Security Solutions
safetynet_notifier ipcLn.exe U Related to SafetyNet Traffic Management and Security Solutions
Regedits Helpers iesetup.exe X Added by the Troj/Hupigon-KX Trojan.
<unknown> idersrvc.sys X A variant of the Troj/Haxdor-Gen rootkit.
ideusr50 ideusr50.dll X Added by a variant of the Troj/Haxdoor Trojan. This infection utilizes the idersrvc.sys rootkit to hide itself.
IP2 UDPB2 ipudpb2.sys X Added by a variant of the Goldun rootkit.
homepage.monitor.exe isamonitor.exe X Added by the Troj/Zlob-QC Trojan. This file is also sometimes found in C:\Program Files\IntCodec\isamonitor.exe.
kernel32.dll isnotify.exe X Added by the Troj/Zlob-QE Trojan.
APVXDWIN invi.vbs X Added by the Troj/DelFile-V Trojan.
winshelld iexplore.exe X Added by the Troj/Clicker-DL Trojan. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplore.exe file.
Windows Internet Control internet.exe X Added by the W32/Tilebot-GK worm and IRC backdoor.
ifp ipf.exe X Added by the Troj/Clagger-AB downloader Trojan.
shelld iexplore.exe X Added by the Troj/Clicker-DL Trojan. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplore.exe file.
ImgPaint ImgPaint.exe X Added by the Troj/Banker-DLS password stealing Trojan.
iTunes Music Mediam itunesmm.exe X Added by the W32.Chaim.B worm. W32.Chaim.B is a worm that has distributed denial of service and back door capabilities. The worm spreads to network shares, through exploiting remote vulnerabilities and may also spread by sending malicious links through AIM, AOL Instant Messenger.
infxp infxp.exe X Added by the Dial/MPB-C dialer.
TWITCH internet.bat X Added by the Troj/Wombat-A Trojan.
<not used> iaspdpus.dll X Added by the WORM_STRATIO.QL mass-mailing worm.
ie.exe ie.exe X Added by the Troj/Proxy-ER backdoor and Proxy Trojan.
igfxcui igfxdev.dll Y Intel(R) integrated graphics controller
Internet Protocol ie-explorer.exe X Added by the Troj/ServU-ED ftp server. Troj/ServU-ED is a modified version of a commercial FTP server application.
<unknown> ipv7.exe X Added by the W32/Sdbot-FAO worm and IRC backdoor.

The worm spreads through network shares protected by weak passwords, and through various operating system vulnerabilities including:

LSASS (MS04-011)
RPC-DCOM (MS04-012)
WKS (MS03-049) (CAN-2003-0812)
PNP (MS05-039)
ASN.1 (MS04-007)
{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E} IEXPLORE.Dat X Added by the Troj/PWS-ACR password-stealing Trojan.
{99F1D023-7CEB-4586-80F7-BB1A98DB7602} IEXPLORE.Sys X Added by the Troj/Delf-DRB Trojan.
IRQ Assigning Agent IRQconf.exe X Added by the W32/Sdbot-CSV worm and IRC backdoor.
<not used> icmpdx3j.dll X Added by the W32/Stratio-BG worm. E1.dll should be removed as well.
<not used> icmpdx3j.dll X Added by the WORM_STRAT.EQ mass-mailing worm. C:\Windows\System32\E1.dll should also be deleted as it is part of this infection.
{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3} impgsje.dll X A Trojan used by the rogue anti-spyware program VirusBursters. This Trojan, when installed, will display fake security alerts on your taskbar and install the VirusBursters program on your computer. This infection also loads under the archenteric value in the ShellServiceObjectDelayLoad registry key.
isamonitor.exe isamonitor.exe X Added by the Troj/Zlob-VJ Trojan.
ShellEffect iexplore.exe X Added by the W32.Eboscro worm. W32.Eboscro is worm that copies itself to removable drives, opens a back door, and lowers security settings on the compromised computer.
{44BBA844-CC51-11CF-AAFA-00AA00B6017B} inetinfoere.exe X Added by the Backdoor.Bifrose.G backdoor. Backdoor.Bifrose.G is a Trojan horse that opens a back door and sends information to a remote server.
WinStar IEXPL0RE.exe X Part of the Rogoo LSP Hijacker. The LSP installed by this infection is c:\windows\system32\aelupsvc32.dll. This infection is hidden by the wsfit32.sys rootkit file. Please seek help in our forums if you are infected with this malware as it is difficult to remove.
IndicatorUtility IndicatorUty.exe N Fujitsu Hotkey Utility is a process that displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook. E.g. when you press the hotkey for muting the sound, a loudspeaker icon with a cross on it is displayed.
scanReg iexplorer.exe X Added by the W32/Gappy-A worm.
Internet Intercpu.exe X Added by the Troj/Agent-DSI Trojan.
ravshell iexpl0re.exe X Added by the Troj/Nofere-A Trojan.
System64 inet.exe X Added by the Troj/Dengle-A downloader Trojan.
InnoSetupRegFile.0000000001 is-RUK93.exe Y After installing programs that use a specific type of setup program, they may ask you to reboot in order to finish the installation. This startup item is used installation tasks after the reboot. Once done, this entry should automatically be removed. If you disable this entry then the program you are attempting to install may not install properly.
icrss manager 32bit icrss.exe X Added by the W32/Rbot-FZB worm and IRC backdoor.
WinUpdate INETSRVt.exe X Added by the Troj/Clagger-AQ downloader Trojan.
intenat intenat.exe X Added by the Troj/Backdr-H backdoor Trojan.
<random characters> iexp1ore.exe X Added by the Troj/Lineag-AIP password-stealing Trojan for the online game Lineage.
IPicture IPictureEx.dll X Added by the Troj/Agent-DZE Trojan.
EDxMC110 Isass.exe X Added by the W32/VB-NIA worm. W32/VB-NIA spreads via removable storage disks. This infection should not be confused with the C:\Windows\System32\lsass.exe infection.
ipcbt ipcbt.exe X Added by the Troj/DwnLdr-FYH Trojan.
iptb iptb.exe X Added by the Troj/Clagger-AS Trojan.
{DD7D4640-4464-48C0-82FD-21338366D2D2} InfoMs.tdm X Added by the Troj/QQPass-ALK Trojan.
PC2X initial.bat X Added by the Troj/DwnLdr-FZZ downloader Trojan.
itise itise.exe X Added by the Troj/PWS-AFB information stealing Trojan.
iasx iasx.exe X Added by the TROJ_YABE.BJ Trojan. This infection fails to load as it does not properly point to the malware executable. This infection also installs C:\Windows\System32\IPTB.EXE and C:\Windows\System32\drivers\ACGE.DAT.
(default) ifconfig.exe X Added by the W32/Rbot-GFW worm and IRC backdoor.
Windows Instrument Driver instdrv.exe X Added by the W32/SdBot-CZV worm and IRC backdoor.
CSNetManagerXp isass.exe X Added by the Troj/Hider-O Trojan.
MS32DLL IISDLL.dll.vbs X Added by the VBS.Solow.E worm. VBS.Solow.E is a worm that copies itself to removable drives.
InstallDriver Table Manager IDriverT.exe U Program associated with InstallShield. This startup should only be created when a software that uses installshield is being installed. If you are not in the middle of installing a program, you can disable this entry.
Neospace Internet Security Internet Security.exe X Added by the NeospacelabSecurity rogue anti-spyware program. NeospacelabSecurity is a potentially unwanted application described as a spyware removal utility that may give exaggerated reports about potential risks on the computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks. This risk is manually installed.
Isxa isxa.exe X Added by the TROJ_SMALL.IAU Trojan.
Net iD iid.exe U A program from NetMaker that allows you to securely logon to a domain, VPN, or other secure environments using a smart card.
iscch iscch.exe X Added by the W32/LCPrank-A worm.
ImageItEncrypt ImageItEncrypt.exe ? Related to Acer's Empowering Technology technology software.
iedrvctrl iedrvctrl.exe X Added by the Troj/AdClick-DW Trojan.
user32.dll isamntr.exe X Added by a variant of the Zlob Trojan.
Microsoft Office Quick Launcher iau1.exe X Identified by Kaspersky Antivirus as Trojan-Downloader.Win32.Small.ase.
Microsoft IEUpdater2 ie_updater.exe X Added by the Troj/Bckdr-QGB backdoor Trojan.
ShellN isca.exe X Added by the TROJ_YABE.BT Trojan.
ndis.exe i4n27vl.exe X Added by the WORM_STRATION.EV worm.
Windows Active Directory Helper injectdll.dll X Added by the Troj/Agent-ELG Trojan.
IPv6 Windows Firewall Driver ip6fw.sys Y Microsoft Firewall driver for computers on a IPV6 network.
SystemRegistry Isassi.exe X Added by the Trojan.Hidexls Trojan. Trojan.Hidexls is a Trojan horse that hides Microsoft Excel files.
<unknown> inst32.exe X Added by the W32/Chinegan-A worm.
SystemMgr Ir32_a.exe X Added by the Troj/Magania-OU Trojan.
Microsoft Values igfkishc.exe X Added by the W32/Rbot-GLO worm and IRC backdoor.
igfxcui igfxsrvc.dll Y Installed with video drivers for video cards that use Intel chipsets.
Internet Connection Manager internet.exe X Added by the Troj/Agent-ELW Trojan.
IKL IKL.dll X Added by the Spyware.InsideKeylogger keylogger.
gtydf iscca.exe X Added by the Troj/DwnLdr-GTK Trojan. Troj/DwnLdr-GTK includes functionality to access the internet and communicate with a remote server via HTTP. The Trojan also has the functionality to download and execute files from a remote location.
ISP Ampi Service isampi.exe X Added by the W32/Tilebot-JJ worm and IRC backdoor.
InCD File System Service InCDsrv.exe Y Allows you to use your CD or DVD writers as if they were a hard drive or floppy drive.
Avg Antivirus icpldrvx.exe X Added by the TROJ_DADOBRA.MP banking Trojan. If you are infected with this it is advised that you immediately change your online banking passwords and notify your bank.
Windows IP Security Service ipsecs.exe X Identified by CA as the Rbot.CBX worm and IRC backdoor.
WindowsUpdate renew iexplore.exe X Identified by Kaspersky Antivirus as Trojan-Spy.Win32.Agent.qd. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplorer.exe file.
Browsers Control Service Pack iesbsvc.exe X Added by the Troj/Bdoor-ACZ backdoor Trojan.
gtydf iisca.exe X Added by the Troj/Clagger-BB Trojan.
ivy.exe ivy.exe X Added by the Troj/Agent-ENZ worm.
IMAPI CD-Burning COM Service imapi.exe U Needed to be enabled if you burn CDs or DVDs on your computer. If you do not burn CDs or DVDs, then you do not need to enable this service.
{4233ac08-a2c4-4742-a0b4-83719613d62c} ilmpjy.dll X Part of the Zlob trojan that displays fake security alerts for the rogue anti-spyware program called SpywareLocked.
{2bf41073-b2b1-21c1-b5c1-0701f4155588} IDrivers.pif X Added by the Troj/Alpha-F Trojan.
WinFile Invalid.exe X Added by the W32.Validin worm. W32.Validin is a worm that infects .html files and deletes .gho files. It spreads by copying itself to removable drives. It also downloads potentially malicious files on to the compromised computer.
DataAccess Invalid.exe X Added by the W32.Validin worm. W32.Validin is a worm that infects .html files and deletes .gho files. It spreads by copying itself to removable drives. It also downloads potentially malicious files on to the compromised computer.
inetsrv inetsrv.exe X Added by the W32/Resik-C worm.
IESet IExplorer.dll .dbt X Added by the PWS-Bluedit password-stealing Trojan.
blah services iczw.exe X Added by the W32/Rbot-GMP worm and IRC backdoor.
window2 ieupdate.exe X Added by the W32/Forbot-BM worm and IRC backdoor.
IEUpdate ieupdate.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iexplore start IEXPLORE.EXE X A variant of the IRCBot family of worms and IRC backdoor Trojans.
INTERNET EXPLORER iexpllore.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Local Security Authority Service Isass.exe X Identified by Bitdefender as DeepScan:Generic.Sdbot.59624095.
<unknown> interview.exe X Added by the W32.Whacker.A worm.
DLAN Ins.exe X Added by the W32.Almanahe.B worm.
INTERNET EXPLORER iexplor.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iTunes Music iTunesHelper32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
IviRegMgr iviRegMgr.exe ? Related to InterVideo applications. Is this necessary to startup?
iereport iereport.dll X Identified as Adware.Agent. This infection is typically found along with other Zlob or Smitfraud infections.
{25b7d2fd-4f71-46d1-801a-7de323e4ec82} indwvm.dll X Trojan that downloads and install the rogue anti-spyware program, SpyLocked. When loaded this infection will also display fake security alerts from your Windows taskbar.
l44sys65 iexplore.exe X Added by the VBS.Lido virus and worm. Iexplore.exe is the legitimate Internet Explorer program that comes with Windows. This entry should be fixed, but the program itself should not be deleted.
Sygate Personal Firewall itla.exe X A variant of the IRCbot family of worms and backdoors.
MSIEUpdater_1 ie_updater1.exe X Identified as Downloader.Small.eop or Downloader.Murlo.fa
LogonAdministrator imoet.exe X Added by the W32.Rahiwi.A. W32.Rahiwi.A is a worm that spreads by copying itself to the root of all drives, including removable and shared drives.
svchost inetinfo.scr X Added by the W32.Odelud worm. W32.Odelud is a worm that spreads via network shares and removable media and may infect executable files.
{9ff419a8-1748-4ca7-99df-d269465b0e8b} iauoi.dll X Zlob Trojan that infects your computer with SpyCrush and displays fake security alerts in your Windows taskbar.
InternetExplorer32 iexplore32.exe X Added by the W32/Rbot-GRA worm.
IPRIP ipripst.dll X Added by the W32/Mofei-W backdoor worm.
IEexplorer AUpdate IEexplore32.exe X Added by the W32/Rbot-GRE worm and IRC backdoor.
passcxd itmanhc.exe X Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
Kiamat Sudah Dekat_16_04 ISASS.exe X Added by the W32.Pahatia.B worm. W32.Pahatia.B is a worm that spreads through mapped network drives and attempts to restart the computer if certain processes are running. This infection should not be confused with the legitmate C:\Windows\System32\LSASS.exe file.
{8bbe40fd-0416-4c3f-80ea-0c7ad5fb1aab} igpfced.dll X Zlob Trojan that infects your computer with SpyCrush and displays fake security alerts in your Windows taskbar.
Microsoft Keyboard Enhance 2.0. iasrecst.exe X Added by the Troj/Bckdr-QIL backdoor Trojan.
{9c0c879c-9091-45d1-807f-2adc37d7d6d6} iwwvh.dll X Zlob Trojan that infects your computer with SpyCrush and displays fake security alerts in your Windows taskbar.
IPO3 IP Operator 2005.exe N Network adapter configuration tool and monitor bundled on LG notebooks.
InfoVersion InfoVersion.exe X Added by the W32.Nujama.B worm. W32.Nujama.B is a worm that spreads through mapped drives and shared folders, and lowers security settings on the compromised computer.
Intel® Matrix Storage Event Monitor iaantmon.exe U Part of Intel® Matrix Storage Manager raid software. The Event Monitor allows you to monitor the status of any raid volumes created via the Intel raid driver.
Micosoft Data Core iexplore.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Isass.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft iusr.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Services iexplorer.exe X Added by the Backdoor.Ranky backdoor Trojan.
Services iexploler.exe X Added by the Backdoor.Ranky backdoor Trojan.
Services iexpolere.exe X Added by the Backdoor.Ranky backdoor Trojan.
Windows Core Kernel Update iexplorer.exe X Added by the Backdoor.Ranky backdoor Trojan.
iexplorer iexplorer.exe X Added by the Troj/SCLog-AI Spyware Trojan.
iexplorer iexplorer.dll X Added by the Troj/SCLog-AI Spyware Trojan.
ms hexidecimal defx ivchost.exe X Identified by Kaspersky antivirus as the Backdoor.Win32.SdBot.aad worm and IRC backdoor.
iedwa104 iedwa104.exe X Added by the Troj/Dloadr-BBW Trojan.
IntelliPoint ipoint.exe U Microsoft Intellipoint software for their Intellimouse series of mice - required if you use non-standard Windows driver features
W3C Internet Standardization Service isssvc.exe X Added by the Troj/Agent-BIY Trojan.
IPS Core Service IPSSVC.EXE U A VPN client bundled with Lenovo Thinkpad notebooks.
tvtnetwk IUService.exe Y Related to IBM Lenovo Laptop's Rescue and Recovery software.
TSS Core Service ibmtcsd.exe U IBM Lenovo's Client Security Solution.
iconcache icon.bat Y Added by the Vista Customization Pack.
ICS ICS.dll U Added by the InsideChatSpy surveillance software. InsideChatSpy is a program that records Instant Message chat conversations. It may then email the harvested information to a specified email address. This software should be uninstalled if found on your computer without your permission.
IMVU IMVUClient.exe N Chat program from IMVU.
MonAppli isys32.exe X Identified as the Win32/AdClicker.AE Trojan.
mav-8551 idsAX.dll ? Added by the Nike JogaTV service that allows you to send soccer videos to other people.
IsDrv118 IsDrv118.sys X Added by the Troj/NTRootK-BU rootkit.
loqueseamichilin Iassss.exe X Added by a variant of the Backdoor.Win32.Bifrose.vq backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
*loqueseamichilin Iassss.exe X Added by a variant of the Backdoor.Win32.Bifrose.vq backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
bantool ie_ban.exe X Identified as a variant of the Trojan-Clicker.Win32.VB.po Trojan.
Winsock6 MIC driver iecvsupdate.exe X A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network.
<Random Name> iexpl0ra.exe X Added by the TROJ_ULPM.BD Trojan.
iTunesAgent ita.exe X Added by the Tactslay Family Trojan.
ICQ Agent icq6.exe X Added by the Troj/Agent-FZJ Trojan.
Winsock6 MIC driver IESERVICESUPD.EXE X A variant of the W32/Spybot.AIF.worm family of worms and IRC backdoor Trojans.
icmuwmau icmuwmau.dll X Added by the W32/Stratio-E worm.
imchat imchat.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
SmartDefrag IObit SmartDefrag.exe U IObit SmartDefrag Defragmentation software for Windows.
Internet Explorer 6.0 iexplore.exe X A variant of the RBot family of worms and IRC backdoor Trojans.
{18a8f76b-804b-4981-b87c-460699971a4b} igzxwrl.dll X Zlob Trojan that installs VirusProtectPro 3.7 and shows fake security alerts from your Windows taskbar.
Network helper Service irdvxc.exe X A variant of the SDBot worm and backdoor Trojan.
<not used> imgkulot.bat X Added by the VBS/Capiz-A worm. You can also delete the C:\Windows\System32\imgkulot.reg and C:\Windows\System32\imgkulot.vbs files that are associated with this infection.
{de5ede53-9db0-422d-b32d-5c41c96d6f52} iklqcx.dll X Zlob Trojan that installs VirusProtectPro 3.7 and shows fake security alerts from your Windows taskbar.
Microsoft explorer Update internal.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Lsass Center Isass.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Service iislsrv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Configuration Loader iexpl3re.exe X A variant of the W32/SDBot.ALIS family of worms and IRC backdoor Trojans.
NAV Auto Update IAmSad.exe X A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network.
AppletINIT INITIATE.EXE X A variant of the W32.Spybot.Worm family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network.
{27882a9f-8937-4ae4-87ab-ed669c8b6d7a} iheuv.dll X Added by a Zlob Trojan which installs AntiVirgear 3.7 and display fake security alerts in your Windows taskbar.
REMOVE ME info.exe X Identified as a variant of the Wootbot worm.
SymantecFilterCheck imglog.exe X Identified as a variant of the TrojanSpy.Banker.eda malware. If you are infected with this you should change your online banking passwords and contact your banks immediately.
Integard Service Integard.exe Y Integard is an Internet content filter provided by
Internet Service Provider ispinstall.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service Agent iesec.exe X Identified as a variant of the Backdoor.Win32.Rbot.eaq worm and IRC backdoor.
MSN install.exe X Added by the Troj/Agent-GDO Trojan.
InternetService isvc.exe X Related to the rogue anti-spyware application System Doctor. This application is known to install with malware that issues fake security warnings in your taskbar as a goad to scare you into purchasing the full version of this software. You should use the removal guide in the link below to remove this software.
Ms Spool32 iexplore.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
isamini.exe isamonitor.exe X Added by a variant of the Zlob Trojan. The path to this file may be different.
start isfmntr.exe X Added by a variant of the Zlob Trojan. The path to this file may be different.
some icthis.exe X Added by a variant of the Zlob Trojan. The path to this file may be different.
Nod32 Service iexplor.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
decompoundly itdtjjf.dll X Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar.
svcshare iexplore.exe X Added by the W32/Fujacks-AS virus with backdoor functionality.
Image Converter SCSI Service ICScsiSV.exe U Used to convert your movies to a format that's readable by your Sony PSP.
infos.exe infos.exe X Related to SmitFraud infections.
imap imap.exe X Added by the Troj/Delf-EYT Trojan.
ICQ Monitor IcqMonitor.exe U Added by the Spyware.IMDetect Instant Messaging surveillance software. If this software was not installed purposely, it should be automatically removed.
igfxpers igfxpers.exe N Associated with the Common User Interface module for Intel graphics cards
Insider Insider.exe X Identified as a variant of the Trojan.Win32.Agent.bnd Trojan.
bigfeet ijftc.dll X Added by a Zlob Trojan which installs AntiVirgear 3.8 and display fake security alerts in your Windows taskbar.
SM_IAN ian_monitor.exe X Related to AdvancedCleaner. AdvancedCleaner is a misleading application, which gives exaggerated reports of security and privacy risks on a computer. The program then prompts the user to purchase a registered version of the software in order to remove the reported risks.
System Information Manager iexplore.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Intranet Explorer iexplorer.exe X Unknown malware. Possibly a variant of the Troj/Agent-CAX Trojan.
ivn4reg ivn4.dll X Identified as a variant of the Trojan-Proxy.Win32.Xorpix.ci Trojan.
ini910p ini910p.sys X A variant of the Ascesso Rootkit.
ineffulgent ivrllc.dll X Zlob Trojan which installs the VirusProtect 3.8 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusProtect onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
Windows Networks inetsock.exe X Unknown malware.
IP SEC PROTOCOL POLLER ipsecpooler.exe X A variant of the Storm worm.
IP SEC PROTOCOL NDIS BRIDGE DRIVER ipsecndis.sys X A variant of the Storm worm.
IP SEC VPN BRIDGE DRIVER ipvpnbridge.sys X A variant of the Storm worm.
Image Converter SCSI Service ICScsiSV.exe Y Used to convert movies to a format that can be used on a Sony Playstation Portable.
IIS Admin Service inetin.exe X Added by the W32/Hupigon-SV removable device worm.
Instant Messenger Service imservice.exe X Identified by Kaspersky Antivirus as Heur.Trojan.Generic.
chkdrv iemon.exe X A variant of the Trojan.Adclicker malware.
iolo AntiVirus ioloAV.exe Y Related to iolo Antivirus.
iolo Personal Firewall ioloFW.exe Y Related to iolo Personal Firewall.
sox5 install.exe X Identified as the Server-Proxy.Win32.Bouncer.a malware.
Update Explorer iexploreupd.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
init_190-2fed init_190-2fed.sys X Added by the W32/Dref-AT worm.
Immunizr Immunizr.exe X Added by the Immunizr rogue anti-spyware program. Uses false advertising and exaggerated scan results as a tactic to have you purchase the software.
Microsoft Winedows WinServ iPodFix.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
ISMModule4 ISMModule4.exe X Added by the Adware.AdSponsor/ISM.Process adware.
MicroSoft Visual SP2 igfxsrvc32.exe X A variant of the Backdoor.Wootbot family of worms and IRC backdoor Trojans.
ieupdate ieupdates.exe X Identified as a variant of the Trojan-Downloader.Delf.OEU malware.
<not used> idaw64.exe X Identified as a variant of the Win32/SpamTool.Agent.NAJ malware.
Isa85 Isa85.sys X Added by the Trojan-Downloader.Win32.Agent.hbs Trojan.
Object memory mapping 8.0 isodvstg.sys X Added by a variant of the Goldun.Fam rootkit.
isodvrtg isodvrtg.dll X Added by a variant of the Goldun.Fam Trojan. This infection utilizes the isodvstg.sys rootkit.
{F5EA1A01-630B-8ABE-1307-B2BB109E7428} IIssas.exe X Identified as a variant of the Posion.Ivy variant malware. This infection uses Alternate Data Streams to hide itself. In order to remove these files you will need to use ADSSpy. Do not delete the C:\Windows\System32 folder as it is required to run Windows.
Slave ipconfig.exe X Identified as a variant of the MSN Worm.
iNotice iservice.exe X A variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos.
Winsock2 driver iexplorer32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
system interneter.exe X Identified by Kaspersky Antivirus as a variant of the Trojan-Downloader.Win32.Delf.auy malware.
epineurial iinqyl.dll X Zlob Trojan which installs the VirusProtect 3.9 rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install VirusProtect onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
Windows Firewall ipservice32.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Internet Browser Services internet.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Internet Browser Services internet32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Internet Browser Services internet64.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iifcbxv iifcbxv.dll X Added by the Trojan-Downloader.Win32.Small.eyx Trojan.
iebvss32 iebvss32.dl X Added by the Trojan.Win32.Delf.axk Trojan.
pwnage_deluxe ICQ_Lite.exe X Added by the Trojan.Win32.Pakes Trojan.
Windows Internet Browser Services internet128.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Internet Dumping Protocol inetdump.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Internet Syncing inetsync.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
GlobalFlagimglog imglog.exe X Added by the Infostealer.Bancos information-stealing Trojan for online banks. If you are infected with this malware it is advised that you change all of your online banking passwords and contact your bank.
Windows Vista Transformation IEXPLORE.exe X Added by the W32/Forbot-GV worm and IRC backdoor.
ipfw_helper ipfw.exe U Added by the Windows port of the FreeBSD IPFW firewall. Unfortunately this legitimate program has also been bundled with rogue anti-spyware programs like RaptorDefence
SBI install_sbd_en.exe X Downloader for a variety of Rogue anti-spyware programs.
iesetupi.exe iesetupi.exe X A variant of the Backdoor.Win32.Rbot.gen family of worms and IRC backdoor Trojans.
Microsoft Internet Explorer Manager ie.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ITCom virtual adapter itcom.sys X Identified as a variant of the TR/Rootkit.Gen rootkit.
ibutu ibutu.dll X Identified as a variant of the Trojan.Proxy.Bunitu.B Trojan.
InfeStop InfeStopRemover.exe X Added by the InfeStop rogue anti-spyware program.
Microsoft Internet Explorer Update ieupdate.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ImgTask Imgtask.exe N Related to WalletPix digital photo album. "On some computers, the Wallet Pix device will leave behind a memory-resident file called ImgTask.exe. You can remove this file at any time and it will not impact your computer's performance or functionality. The file will be restored each time you plug in the Wallet Pix though"
Windows Relay Service ipcbind.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows Relay Service irfnga.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Iprip iprtrmg32.dll X Added by the Troj/Bckdr-QMH backdoor Trojan.
ieqazhew ieqazhew.dll X Added by the Backdoor.Rustock backdoor rootkit.
32-bit Installation Host inst32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
SystemMgr Ir32_c.exe X Added by the Troj/Agent-ZLA Trojan.
Remcte Procedure Transfer iewd.exe X Added by the W32/Agent-GTZ worm.
{33218B50-2E05-4F08-C086-0DDDEABF6280} intel.exe X Identified as a variant of the Backdoor.Win32.Small.czx malware.
<not used> iSecurity.cpl X Added by the iSecurity Trojan. The iSecurity Trojan displays fake alerts and advertisements for rogue anti-spyware programs.
itcoe adapter itcoe.sys X A variant of the Haxdoor rootkit.
ibudu ibudu.dll X A variant of the Haxdoor Trojan. This infection is hidden by the itcoe.sys rootkit.
Google Online Services ie_updates3r.exe X Identified as a variant of the TrojanDownloader:Win32/Tipikit.C malware.
ipsec ipsec.dll X Added by the Fribet Trojan.
{08B0E5C0-4FCB-11CF-AAX5-81C01C608512} isee.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
{08B0E5C0-4FCB-11CF-AAX5-90401C608512} ise.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} ise32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
IRAT IRAT.mvb X Added by the Troj/Delf-FAH Trojan.
DF IFCUFMBE.exe X Added by the Troj/PWS-AQY password-stealing Trojan.
ibuntu ibuntu.dll X Identified as a variant of the Trojan-Proxy.Win32.Agent.zh malware.
iExplore Ini ie4uini.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iExpresser iexpresser.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Intel AHCI Controller iastor.sys Y Intel Advanced Host Controller Interface driver for SATA.
antispy ieav.exe X Added by the IE AntiVirus rogue anti-spyware program.
{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} isi32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iPSec7 ipsec7.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iPX Router ipxrouter.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
iesetup7b iesetup7b.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
isfgkgl isfgkgl.exe X Identified as a variant of the Backdoor:Win32/Tofsee.F backdoor Trojan.
Microsoft Initialization Services initserv.exe X Added by the Troj/IRCBot-ABO worm and IRC backdoor.
Intuit Fuse Service Intuit Fuse Service.exe Y Licensing component of the Intuit Proseries tax software.
iuzqpaf iuzqpaf.sys X Added by the Backdoor.Rustock backdoor rootkit.
iSecurity applet iSecurity.cpl X Added by the iSecurity Trojan. The iSecurity Trojan displays fake alerts and advertisements for rogue anti-spyware programs. Please note that rundll32.exe is a legitimate program.
iSecurity iSecurity.cpl X Added by the iSecurity Trojan. The iSecurity Trojan displays fake alerts and advertisements for rogue anti-spyware programs.
Microsoft install.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft internetdat.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
IE iexplorer.exe X Added by the TROJ_DLOADER.XCU Trojan.
RegistryMonitor1 igfxpers.exe X Added by the Troj/Delf-EZZ Trojan.
Office Desktops imag.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
BrandClearStubs IEDKCS32.DLL Y A client-side DLL that implements the Internet Explorer Maintenance Extension settings found in Group Policy. These settings include custom branding of Internet Explorer, connection settings, and Favorites.
isscs32 isscs32.exe X Added by the Troj/Mdrop-BTC Trojan.
IBVIPSP IBVIPSP.exe X Added by the Troj/StartP-BH Trojan.
Windows USB Control Driver iexplore.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> iftuyszv.exe X Identified as a variant of the TrojanDownloader:Win32/Renos.CR malware.
ImgBurn ImgBurn.exe X A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Configure Tool i386-winconf.exe X Added by the Troj/Agent-HCP Trojan.
240985 Isass.exe X Added by the WORM_SANKEZU.A worm.
ieguide_plus ieguideupdate.exe X Added by the IEGuide Plus adware.
bergamiol ibmsmyi.dll X Zlob Trojan which installs the AntiSpyCheck rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install AntiSpyCheck onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
Input Director Service IDWinService.exe Y a href="http://www.inputdirector.com/" target="_new" class="goodurl" rel="nofollow">Input Director is a Windows application that lets you control multiple Windows systems using the keyboard/mouse attached to one computer.
IBMTPCHK IBMBLDID.SYS Y Thinkvantage driver installed on Lenovo laptops.
InternetSecurityDeluxe InternetSecurityDeluxe.exe X Added by the InternetSecurityDeluxe rogue anti-spyware program.
start iebtm.exe X Identified as a variant of the Adware/Netproject malware. Typically bundled with rogue anti-spyware programs and fake codecs.
<not used> ibm00003.exe X Identified as a variant of the Trojan Torpig-G malware.
IPLog Security iplogsec.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Initialization Service initsvc.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Initialization Services initserv.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
frisbee idygjun.dll X Zlob Trojan which installs the AntiSpyCheck rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install AntiSpyCheck onto your computer without permissions. This Trojan pretends to be a fake video codec required to watch videos online.
MSN iTuneshelp.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
IEServer IEServer.exe U Added by the Spyware.HBScreenSpy surveillance software. Spyware.HBScreenSpy is a Spyware program that allows remote viewing of the computer screen. This software should be uninstalled if found on your computer without your knowledge.
Microsoft Windows (D) iexplore.exe X Identified as a variant of the TrojanSpy.Agent malware. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplore.exe file.
Windows UDP Control Center installer.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
AcerVGA Engine Drivers V1.2 iuengine32.exe X Identified as a variant of the Trojan-Spy.Win32.Delf.bxr malware.
{38D33011-7115-0816-4F85-8571E5873992} Intals.exe X A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote server. It then uploads one or more files and runs them on the compromised system.
Services Control iexplore.exe X A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows TaskManager iexplorer.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
{28B0E5C2-99CB-11CF-AYX5-00401C648513} iuhx32.exe X Identified as a variant of the Worm.Hamweg.Gen malware.
Internet_Explorer.exe Internet_Explorer.exe X Added by the Troj/Banker-END Trojan.
{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} ipse32.exe X Identified as a variant of the Worm:Win32/Hamweq.A malware.
DumpPrep Isass32.exe X A variant of the IRCBot family of worms and IRC backdoor Trojans.
ieupdate ieexplorer32.exe X Added by the Troj/Dloadr-BUF Trojan.
Windows Secure Fix iPodFixer.exe X Identified as a variant of the Net-Worm.Win32.Kolab.anf worm.
ibmfilter ibmfilter.sys Y Driver related to the IBM Rapid Restore Rescue and Recovery software.
iupd721 iupd721.exe X Connected with a type of malware that will put more malware on your system.
ish-b.exe ish-b.exe X Added by the Troj/IRCBot-ACZ worm and IRC backdoor.
Internet Explorer Sys32 isys32.exe X Added by the W32/IRCBot-ADA worm and IRC backdoor.
windows Live Messenger iexplore.exe X Added by the Troj/Bckdr-QTS backdoor. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplore.exe file.
{26923b43-4d38-484f-9b9e-de460746276c} ie4uinit.exe Y This startup is used to initially setup Internet Explorer settings.
{89820200-ECBD-11cf-8B85-00AA005B4383} ie4uinit.exe Y This startup is used to set up the base settings for Internet Explorer.
PMX Daemon ICO.EXE U Mouse software that allows you to change a variety of options for your mouse. May cause problem with some DirectX games if it disabled.
star2 ischot.exe X Added by the Troj/DwnLdr-HLK downloading Trojan.
PLFlash DeviceIoControl Service IoctlSvc.exe U This file is an Input Output Control Service associated with a number of applications and file paths and generally detects the presence of flash drives or other memory devices using USB.  Published by Prolific Technology Inc., this service can in many cases be disabled.  However, there is indication that if you have an external hard-drive, this service is essential for communications to occur.  Whether setting the service to manual would cause problems in this situation has not been determined.
Internet Antivirus IAvir.exe X Added by the Internet Antivirus rogue anti-malware program.
3P_UDEC_IA IAInstall.exe X Added by the Internet Antivirus rogue anti-malware program.
iv iv.exe X Added by the Internet Antivirus Pro rogue anti-malware program.
Internet Antivirus Pro IAPro.exe X Added by the Internet Antivirus Pro rogue anti-malware program.
bussebuschke ijofmsu.dll X Zlob Trojan which installs the AntivirusTrigger rogue anti-spyware program. This program displays fake security alerts stating that your computer has a security problem and then downloads and install AntivirusTrigger onto your computer without permission. This Trojan pretends to be a fake video codec required to watch videos online.
iSafeAV iSafeAV.exe X Added by the iSafe AntiVirus rogue anti-spyware program.
IEudinit ieudinit.exe X Added by the Troj/Ezio-I Trojan.
PLFlash DeviceIoControl Service ioctlsvc.exe U

This file is an Input Output Control Service associated with a number of applications and file paths and generally detects the presence of flash drives or other memory devices using USB.  Published by Prolific Technology Inc., this service can in may cases be disabled.  However, there is indication that if you have an external hard-drive, this service is essential for communications to occur.  Whether setting the service to manual would cause problems in this situation has not been determined.

MicrosoftUpgrade inetinfx.exe X Added by the TSPY_BANKER.BGO information stealing Trojan for online banks.
isapips32 isapips32.dll X Added by the TROJ_AGENT.AQR Trojan.
Microsoft Intranet Patcher intranetexplorer.exe X Added by the Troj/Agent-IRB Trojan.
ieModule ieModule.dll X Added by the System Guard 2009 rogue anti-spyware program.
InstallShields iKernel.exe X Added by the Troj/Bckdr-QRK backdoor Trojan.
IMJPMIG9.0 IMJPMIG.EXE N Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Korean and this one is Japanese)
<not used> iph.exe X Added by the W32/Autorun-ZI removable media worm.
updater install.exe X Added by the Malware Defender rogue anti-spyware program.
kxswsoft ierdfgh.exe X Added by the W32/AutoRun-AAT removable media worm.
IA3 install.exe X Added by the Troj/FakeAV-KQ fake alert Trojan.
PHIME2005 ImSched.exE X Added by the Troj/Dloadr-CGN Trojan.
iWinTrusted iWinTrusted.exe U Related to iWin games.
Msn ilss32.dll X Added by the Troj/Banlo-E Trojan.
IDriveE Startup IDrvieEStartup.exe U Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space.
IDrive Tray IDriveEReg2ini.exe U Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space. This startup is the for the tray icon that allows you to control how IDrive works.
IDriveE Service IDriveE Service.exe U Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space.
IDrive WebManager IDriveWebM.exe U Added by the IDrive online backup solution. IDrive offers a free 2GB online backup of your local files and a paid solution if you need more space. This service allows you to control your backup settings from the web.
PLFlash DeviceIoControl Service IoctlSvc.exe U This file is an Input Output Control Service associated with a number of applications and file paths and generally detects the presence of flash drives or other memory devices using USB.  Published by Prolific Technology Inc., this service can in many cases be disabled.  However, there is indication that if you have an external hard-drive, this service is essential for communications to occur.  Whether setting the service to manual would cause problems in this situation has not been determined.
Iexplorerr.exe Iexplorerr.exe X Added by the Troj/Banker-EUT online banking Trojan.
crsmons iomssls.exe X Added by the Troj/Backdr-AU backdoor Trojan.
isqsys32.exe isqsys32.exe X Added by the Bredolab.gen.a Trojan.
HTTP Security Services Helper Iasex.dll X Added by the Troj/Catl-A Trojan.
NMSSupport IntelHCTAgent.exe Y

Preinstalled on computers with Intel Viiv technology and possibly others, this file is a Network Monitor from Intel Corporation belonging to Intel® Hub Connect Technology and also simplifies the task of setting up approved network devices.

Internet Security 2010 IS2010.exe X Added by the Internet Security 2010 rogue security program.
IGuardPc.exe IGuardPc.exe X Added by the IGuardPc rogue anti-spyware program.
InSysSecure InSysSecure.exe X Added by the InSysSecure rogue anti-spyware program.
Live Enterprise Suite IAPro.exe X Added by the Live Enterprise Suite rogue anti-spyware program.
incognito incognito,exe X Added by the Troj/Inject-LR Trojan.
Inkjet Printer/Scanner Extended Survey Program IJPLMSVC.EXE N Added by Canon printer software. This software will collect information such as printer's id number, installation date and time, ink use information, number of sheets printers, etc. It will then send this information to Canon after a certain amount of time.
PIXMA Extended Survey Program IJPLMSVC.EXE N Added by Canon printer software. This software will collect information such as printer's id number, installation date and time, ink use information, number of sheets printers, etc. It will then send this information to Canon after a certain amount of time.
imPlayok imPlayok.ex X Added by the Cutwail.gen.o Trojan. This malware attempts to perform SSL DDOS attacks at various sites.
Firewall Administrating infocard.exe X Added by the W32/Autorun-AYV removable media worm.
FBSSA ie3sh.exe X This file is a part of Make My Web Better products which are found on various social networking sites.  These programs are adware or are potentially unwanted products.
iqmanager.exe iqmanager.exe X Added by the I-Q Manager ransomware.
Firewall Administrating infocard.exe X Added by the W32.Yimfoca worm. W32.Yimfoca is a worm that spreads by sending links through Yahoo! Messenger.
<not used> ieremove.exe X Added by the W32/Autoit-JK removable media worm.
Windows CardSpace infocard.exe Y Windows service that securely enables the creation, management, and disclosure of digital identities.
IKE and AuthIP IPsec Keying Modules ikeext.dll Y The Microsoft IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service will disable IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. It is strongly recommended that you have the IKEEXT service running.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
i8042 Keyboard and PS/2 Mouse Port Driver i8042prt.sys Y i8042 Keyboard and PS/2 Mouse Port Driver for Microsoft Windows.
iaStorV iaStorV.sys Y Intel® Matrix Storage Manager Sata RAID Controller driver for Windows.
Intel AHCI Controller iaStor.sys Y Intel Sata RAID Controller driver for Windows.
PnP-X IP Bus Enumerator ipbusenum.dll Y The PnP-X bus enumerator Windows service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stopped or disabled, presence of NCD devices will not be maintained in PnP. All pnpx based scenarios will stop functioning.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
IP Helper iphlpsvc.dll Y Windows service that provides tunnel connectivity using IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
Microsoft iSCSI Initiator Service iscsiexe.dll Y Windows service that manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail to start.

Please note that this service is launched by svchost.exe, but the actual application is what is listed as the filename.
ZoneAlarm LTD Toolbar IswSvc IswSvc.exe U This is Checkpoint's core file for ZoneAlarm's browser protecting toolbar called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks.
ZoneAlarm LTD Toolbar ISWKL ISWKL.sys U This is the driver for Checkpoint's ZoneAlarm browser protecting toolbar called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks.
Windows UDP Control Center iexplorer.exe X Added by the Troj/Poison-CJ Trojan. This infection should not be confused with the legitimate C:\Program Files\Internet Explorer\iexplore.exe file.
MSIME iexprohlp.exe X Added by the Troj/Mdrop-CVV Trojan.
SessionInit init.exe X Added by the Troj/FakeAv-BRZ Trojan.
<not used> ils32.dll X Added by the Troj/Mdrop-CXG Trojan.
Microsoft Internet Explorer ie8.exe X Added by the Troj/Banker-FBF Trojan.
IMSCMIG40W IMSCMIG.EXE U This file loads a component of Microsoft's input method editor (IME) that displays and allows input of Asian language characters such as in Japanese and Chinese. Necessary if you want to use this program.
Microsoft Pinyin IME Migration IMSCMIG. EXE U

This file loads a component of Microsoft's input method editor (IME) that displays and allows input of Asian language characters such as in Japanese and Chinese.  Necessary if you want to use this program.

premium igfxtrai.exe X Added by the Troj/Dloadr-DDX Trojan.
Intuit Update Service [v4] IntuitUpdateService.exe N

This service automatically updates certain Intuit programs such as TurboTax.  Recommendation is to turn off Auto-update from within the program then set this service to disabled.

Note that some versions of this include v4 where indicated by the brackets.  The brackets are not part of the name or file path.

systemupdate IEXPLORE.EXE X Added by the Troj/DwnLdr-JEA Trojan.
Apple iPod Service iTunes.exe X Added by the W32/AutoRun-BLL removable media worm.
isass.exe isass.exe X Added by the Troj/Spy-VL Trojan.
<not used> iqmanager.exe X Added by the I-Q Manager rogue security program.
IFXSPMGT ifxspmgt.exe U

Part of the Trusted Platform Module(TPM) of Infineon Security Platform Software bundled on certain laptops from companies such as Acer, ASUS, HP and Sony.  Necessary if you use the TPM.

Note that the file path and thus the command may vary depending on who assembled the computer.

Variations include:

%Windir%\SysWOW64\ifxspmgt.exe for 64 bit machines

%programfiles%\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe

%programfiles%\Infineon\Security Platform Software\ifxspmgt.exe

igfxtray Module igfxtray.exe X Added by the Mal/VB-RI malware.
winlogon ircbsbot.exe X Added by the Troj/Agent-RGJ Trojan.
MircProtection Io.vbs X Added by the VBS/Thea-A malware.
InstallIQUpdater InstallIQUpdater.exe X

Bundled with applications and games for various devices and computers as well, this file is part of an adware/marketing software program by W3i.  This file searches for updates to whatever program or application it's bundled with.

"These features include both prompting users to accept automatic updates and rewarding them for rating your app."

 

IAStorIcon IAStorIcon.exe U Taskbar icon for the Intel Rapid Storage Technology console and displays any messages associated with your connected storage devices.
Intelinet Intelinet.exe X Identified by Kaspersky Antivirus as a variant of the not-a-virus:FraudTool.Win32.Agent.dx family.
infodataS infodataU.exe X Koren rogue anti-virus program. This file is identified by ESET Nod32 as a variant of the Win32/Adware.IScan.A adware.
Intel PROSet Monitoring Service IProsetMonitor.exe Y The Intel(R) PROSet Monitoring Service actively monitors changes to the system and updates affected network devices to keep them running in optimal condition. Stopping this service may negatively affect the performance of the network devices on the system.
Ianno Web Cache Services ianotife.exe X Identified by McAfee as a variant of the FakeAlert-PJ.gen malware.
iexplorer iexopllorer.exe X Unknown malware.
vivi impressorax.sys X Unknown malware.
infoguardr infoguardrun.exe X Added by the Korean rogue called InfoGuard.
IEPR IEPR.exe X Identified by AntiVir as a variant of the TR/Dldr.JLMR malware.
IEPRS IEPRS.exe X Identified by AntiVir as a variant of the TR/Dldr.JLMR malware.
iOmem iOmem.exe X Identified by Sophos as a variant of the Troj/Clicker-FE malware.
iOmem iOmem101.exe X Identified by Sophos as a variant of the Troj/Clicker-FE malware.
CyberDefender Early Detection Center ISSIntro.exe Y Related to the Cyberdefender security program.
Image Converter video recording monitor for VAIO Entertainment IcVzMon.exe U Part of the software suite bundled with Sony VAIO laptops.
Intel(R) Rapid Storage Technology IAStorDataMgrSvc.exe U Intel software for managing Raid drives on Intel chipsets.
iolo Startup ioloLManager.exe ? Related to IOBit programs, but am unsure as to what it does.
Internet Security 2012 isecurity.exe X Added by the Internet Security 2012 rogue anti-spyware program.
InetAccelerator InetAccelerator.exe X Added by the Troj/Ransirac-A Trojan.
Internet Security Guard ISa76.exe X Added by the Internet Security Guard rogue anti-spyware program.
Inspector Inspector-<random 3 characters>.exe X Added by the Windows Protection Master rogue anti-spyware program.
Microsoft Firevall Engine iqs.exe X Added by the W32/Stekct-B worm.
Java Update Manager ifosyst.exe X Added by the Mal/EncPk-ACE malware.
ZoneAlarm Toolbar IswSvc IswSvc.exe U This is Checkpoint's core file for ZoneAlarm's browser protecting toolbar called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks.
ZoneAlarm ForceField IswSvc IswSvc.exe U This is Checkpoint's core file for ZoneAlarm's browser protecting application called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks by turning it into a virtual browser.
ZoneAlarm ForceField ISWKL ISWKL.sys U This is the driver for Checkpoint's ZoneAlarm browser protecting application called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks by turning it into a virtual browser.
ZoneAlarm Toolbar ISWKL ISWKL.sys U This is the driver for Checkpoint's ZoneAlarm browser protecting toolbar called ForceField.  It protects your browser from various web-based attacks, such as drive by malware and phishing attacks.
IMSCMig IMSCMIG.EXE U This file loads a component of Microsoft's input method editor (IME) that displays and allows input of Asian language characters such as in Japanese and Chinese.  Necessary if you want to use this program.
Security Platform Management Service IFXSPMGT.exe U Part of the Trusted Platform Module(TPM) of Infineon Security Platform Software bundled on certain laptops from companies such as Acer, ASUS, HP and Sony.  Necessary if you use the TPM.

Note that the file path and thus the command may vary depending on who assembled the computer.

Variations include:

%Windir%\SysWOW64\IFXSPMGT.exe for 64 bit machines

%programfiles%\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe

%programfiles%\Infineon\Security Platform Software\ifxspmgt.exe
iPrint iPrint.exe U Installed with iPrint by Inzone Software Limited the purpose of which is to reduce the amount of paper used in printing.  Instead of printing through your printer's interface, you print through iPrint and then the printer.  If this file isn't running, however, the program will not start when you decide to print something.  If you do a lot of printing, keep this process running.  Otherwise, disable the startup, and when you want to print, start the program, then click the print button.
iPrint Tray iPrint.exe U Installed with iPrint by Inzone Software Limited the purpose of which is to reduce the amount of paper used in printing.  Instead of printing through your printer's interface, you print through iPrint and then the printer.  If this file isn't running, however, the program will not start when you decide to print something.  If you do a lot of printing, keep this process running.  Otherwise, disable the startup, and when you want to print, start the program, then click the print button.
Network packet analyzer InetPCservice.exe X Added by the Network Packet Analyzer or Online Ad Scanner potentially unwanted program. This program runs in the background and constantly accesses web sites in the background
ISZone ISZoneUpdate.exe X Korean adware related to keywordInfo.co.kr.
IMF Service IMFsrv.exe Y This service is installed with IObit Malware Fighter and is essential for the program to run.
infocover main infocoveru.exe X A Korean rogue anti-spyware program.
InstallBrain Updater Service ibsvc.exe X Identified by ESET as a variant of Win32/InstallBrain.AC adware.
InfoSave InfoSave.exe X Related to the Korean rogue anti-spyware program called InfoSafe from the Ebiz family.
Isis Isis.exe X Related to the Isis adware.
innfd_1_10_0_14 innfd_1_10_0_14.sys X Added by the Infonaut adware. This adware injects advertisements and offers into web sites you visit.
Infonaut 1.10.0.14 Client Service insvc.exe X Added by the Infonaut adware. This adware injects advertisements and offers into web sites you visit.
WNetEnhance Service InternetEnhancerService.exe X Added by the Wajam adware.
InstantSupport InstantSupport.exe X Added by the InstantSupport tech support alert.

Login

Remember Me
Sign in anonymously