| Name | Status | Filename | Description |
|---|
| IPSecMon | Y | IPSecMon.exe | Microsoft L2TP/IPSec VPN Client for Win98/Me/NT. Secure technology for making remote access virtual private network (VPN) connections across public networks such as the Internet |
| intell32.exe | X | intell32.exe | Added by the SmitFraud alias Desktophijack.C TROJAN!
|
| Internet Application Driver | X | expIorer.exe | Added by the Troj/IRCBot-WK Trojan Read the link, allows remote access |
| InstantPleasure | X | instantpleasure.exe | Adult content dialler |
| ipreg | X | ipreg.exe | Added by the Troj/Zagaban-H TROJAN! Note: This trojan file is found in the System (95/98/ME) or System32 (NT/2000/XP) folder. |
| irssyncd | X | irssyncd.exe | Identified by ewido, SafeSurfing parasite variant |
| IEXPLORE | X | iexplore.exe | Added by the APHEXDOOR VIRUS! Note - "iexplore.exe" resides in C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP) wheras the valid "iexplore.exe" (IE) resides in C:\Program Files |
| istinstall_zazzer.exe | X | istinstall_zazzer.exe | Unidentified adware downloader/installer |
| IPW | U | IPW.exe | Related to Internet_Phone_Wizard from Actiontec.com VOIP. Note: Located in C:\Program Files\Actiontec Internet Phone Wizard\ipw.exe |
| iM Start Center | N | iM_Tray.exe | Installed with the Sound Blaster Audigy range of soundcards. A radio tuner installed if the user chooses during installation. Available via Start -> Programs -> iM Networks -> iM Radio Tuner |
| iTunes Music | X | iTunesHelper32.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| Intel system tool | X | winnook.exe | Added by the Troj/Spyre-C Trojan! A.K.A WIN32.TOPANTISPYWARE.L Read the link, keylogger/password stealing trojan(s) involved. |
| Image & Restore | Y | IMAGE32.exe | Part of McAfee Nuts & Bolts. Image/Restore can recover from drives that have been accidentally formatted or completely erased, if Image was recently run |
| ICQNet | X | winlogon.exe | Added by the W32/NETSKY-C WORM! - NOTE - this file is placed in the Winnt or Windows folder, and should NOT be confused with the legitimate Windows winlogon.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
|
| Intel Driver | X | csrs.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\Windows\System\ (Win9x/Me), C:\%WINDIR%\System32\ More here |
| InstantAccess | N | INSTAN~1.EXE | From TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs |
| ISStart | U | ISStart.exe | LogitechGalleryRepair/LogitechVideoRepair - part of Logitech Image Studio - installed with Logitech QuickCam cameras. Required from version 8.11 onwards if you use the software to take pictures and capture videos, not if you don't. Also not required for versions up to and including 7.30 and after version 8.30 - hence the "U" rather than "Y" recommendation |
| Instant Access | X | rundll32.exe,eg_auth_****.dll, InstantAccess | Electronic_Group/InstantAccess premium rate adult content dialer variant |
| InterU | X | WINDRV.EXE | Added by the IRCINTER.A VIRUS! |
| IExploer | X | svshosts.exe | Added by the BKDR_IRCBOT.BT TROJAN! |
| InetMSN | X | msnet.exe | Added by a variant of the SDBOT WORM! |
| IaNvSrv | Y | IaNvSrv.exe | Related to Intel® _Matrix_Storage_Manager Intel Advanced Networking Services (iANS) NDIS Intermediate Driver. Note: Located in \%Program Files%\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\ |
| IPConfig | X | svcxnv32.exe | Added by the HACARMY.E TROJAN! |
| ItalU | X | italfds.exe | Added by the ITALFDS.Process TROJAN! Note: This worm\trojan is located in C:\Windows\System (Win9x/Me), C:\%WINDIR%\System32 (XP/WinNT/2K) |
| IMEKRMIG6.1 | N | IMEKRMIG.EXE | Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese, Japanese and this one is Korean) |
| iConfigLoader | X | DIIhost.exe | Added by the GAOBOT.AO WORM! |
| iyelejiv | X | yujixit.exe | Added by the SDBOT.BJK WORM! |
| IMStart | U | IMStart.exe | InterMute security software related |
| Internet Sweeper | N | Sweeper.exe | Internet Sweeper - removes unnecessart left over files after browsing the internet |
| InstallBuddy | U | Ibtna.exe | InstallBuddy - automatically translates and installs your desktop documents, such as Adobe PDF, HTML, Microsoft Word, Excel and PowerPoint files, to your Palm organizer when you HotSync |
| Internet Explorer | X | IEXPLORE.EXE | Added by Troj/Cosdoor-A TROJAN! |
| Internet Suspention | X | story.exe | Added by the WOOTBOT.HV WORM! |
| Internet Explorer | X | iexplorer.exe | Added by the LORSIS VIRUS! Note - the valid Internet Explorer would not normally run at startup unless added manually by the user and would not run from the registry "RunServices" key as this does |
| ICQ Lite | N | ICQLite.exe | ICQ Lite - compact version of the popular messaging program |
| Internet | X | recruit.exe | Added by the W32/Rbot-AJG
WORM!
|
| Ibmmon.exe | ? | Ibmmon.exe | ?? |
| infamous.exe | X | wmplayer.exe | Added by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup. Infamous.exe is identified by Panda antivirus as Trj/Briss.A
|
| Intel Product Number Utility | U | IntelProcNumUtility.exe | Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here |
| Inventory Scan | U | LDISCN32.EXE | LANDesk Management_Suite software component. |
| internat | X | internat.exe | Added by the Troj/Lydra-B
Trojan! |
| iexplorer ml097e | X | iexplorer.exe | RapidBlaster Variant |
| icifati | X | yujixit.exe | Added by the SDBOT.ZZH WORM! |
| ICO | N | ICO.EXE | Found on a Sony Vaio laptop and seems to be related to Mouse Suite 98 Daemon according to the properties. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games |
| InterTrust Quick Start | N | it_cpq~1.exe | InterTrust offers something known as Digital Rights Management to control legal software download and other E-commerce related business |
| Iexploit | X | Iexploit.html | Added by the VBS.Inker.B
WORM!
Note: This worm file is found in the Windows or Winnt folder. |
| Icon lptt01 | X | icon.exe | RapidBlaster Variant |
| iPalm | N | mon.exe | Installed with a Panasonic iPalm digital camera. Used to uploaded photos from the camera. If your camera is not connected (via USB port) you do not need this program loaded |
| ItsDeductiblePopUp | N | ItsDeductible.exe | ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip |
| IBMUltraBayHotSwapCPLLoader | U | IBMBAY2N.EXE | Supports hot swapping in Thinkpad UltraBay Option on IBM ThinkPad laptops |
| Instant Update Center | N | reminder.exe | From Broderbund's PrintMaster 10. It is an event reminder (for calendar dates, etc). Delete from the startup using Startup Manager program because it keeps re-checking itself when using MSCONFIG. PrintMaster 11 uses filename PMremind.exe - it has to be unchecked in startup in the same manner |
| ipsecdialer | U | IPSECD~1.EXE,-run_only_if_connected,-auto_initiation | The Cisco VPN_Client lets local users gain Administrator privileges on the operating system |
| InetServices | X | wsock32.exe | Added by the Backdoor.Win32.Delf.ej or TROJ/WOCK32-A TROJAN!
|
| Internet Timer | U | ITIMER.exe | Shareware dial-up connection call cost calculator from Ratsoft |
| IcqBeta | X | webcamupdate.exe | Added by an unidentified TROJAN! |
| iolo Utility Bar | N | SMUtilityBar.exe | Iolo "System Mechanic" Utility_Bar - can be launched manually. |