Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X IMprocess IM-svr.EXE"IMNames adware"
U ImScInst ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
U ImScInst.exe ImScInst.exe"Microsoft's Input Method Editor which is used to both display and enable the input of characters from East Asian and Right-to-left (e.g. Arabic) languages in e-mails
U IMStart IMStart.exe"InterMute security software related"
U IMVU IMVUClient.exe"IMVU chat client that allows you to create ""your own avatars who chat in animated 3D scenes"""
X imwinsrvc acpmonsrv.exe"Added by the SLAPER.E TROJAN!"
X IMwire imwireup.exe"SafeSurfing adware variant"
X imxecs vbrun70sp4.exe"Added by the AGOBOT.ALA WORM!"
X im_autorn im_1.exe"Added by the IMAV.A WORM!"
X im_autorn im_2.exe"Added by the BAGLEDL-BO TROJAN!"
Y InCD incd.exe"Ahead InCD packet writing software - similar to DirectCD. For Nero 5.0 or 5.5 (InCD3)
N IncMail IncMail.exe"""IncrediMail is an advanced
X incognito incognito.exe"Added by an unidentified WORM or TROJAN! See here"
N InControl Desktop Manager DMHKEY.EXEFor Diamond Multimedia video cards. Allows System Tray access to desktop utilities such as screen resolution. Available via Start -> Programs
X Incredible Keylogger AdvKeylog.exe"IncredibleKeylogger spyware"
N Incredimail incredimail.exe""IncrediMail is an advanced
N Incredimail IncMail.exe"""IncrediMail is an advanced
X Index Service dllhost32.exe"Added by the AGOBOT.CH WORM!"
U Index Washer WashIdx.exe"Window Washer from Webroot Software. Useful utility that deletes safe to remove files
? Indexer Indexer.exe"Part of the Sharpdesk from Sharp Electronics. ""A desktop-based
X Indexindicator Indexindicator.exe"Added by the LAZAR TROJAN!"
N IndexSearch IndexSearch.exe"Part of Nuance (ScanSoft) PaperPort - ""scan
U IndexTray IndexTray.exe"Part of
U IndicatorUty IndicatorUty.exe"Fujitsu Hotkey Utility displays icons on the screen when you use hotkeys on a Fujitsu Siemens Lifebook
U IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
X ine svchosts.exe"Added by the RBOT.BNL WORM!"
X INET inetsync.exe"Meplex adware"
X Inet DataBase Inetdbs.exe"Added by the QEDS WORM!"
X Inet Delivery inetdl.exe"Inet Delivery adware"
X Inet Delivery inetdl_2.exe"Inet Delivery adware"
X Inetapi Netapi.exe"Added by the NETDEVIL.14 TROJAN!"
X InetChk ms[random value].exe"Added by the AGENT-IRL TROJAN!"
U inetcntrl inetcntrl.exeBsafe Online - internet filter
? InetConf inetconf.exe"??"
U Inetd INETD32.EXE"Windows Inet Daemon from Hummingbird Communications. ""Hummingbird Inetd has the advanced ability to conserve PC resources by listening for connection requests and launching server daemons"". Provides PCs with the full functionality of a UNIX workstation"
U inetinfo.exe inetinfo.exe"Executable used by MS Internet Information Server (IIS). If it's running
X inetinfomon manager inetinfomon.exe"Added by the DONBOMB.A TROJAN!"
X inetmgr inetmgr.exe"Actual Names (AdvSearch) Internet Keywords parasite"
X InetMSN msnet.exe"Added by a variant of the SDBOT TROJAN!"
X InetServices wsock32.exe"Added by the WOCK32-A TROJAN!"
X infamous.exe wmplayer.exeAdded by unknown malware. WMPLAYER.EXE is stored in the location and uses the same name as Windows Media Player but that valid Windows program doesn't load at startup
X InfeStop InfeStopRemover.exe"InfeStop rogue spyware remover - not recommended
X info smss.exe"Added by the VB.EIW WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %System%\inetsrv"
X INFO DATA apc.exe"Added by the RANDON.B WORM!"
U Info Select is.exe"Info Select from Micro Logic - personal information manager"
X Info32x Info32x.exe"Added by the GEMA TROJAN!"
X InfoData "rundll32.exe ********.dllrealset [* = random char]"
U InfoPenMSN InfoPenIM.exe"InfoPenMSN is a MSN Messenger plugin that allows you to send data written/drawn by hand"
? Infoplay.exe Infoplay.exe"Written by New Media Properties
X Information Update iu.exe"Detected by Kaspersky as the CENTIM.CH TROJAN!"
U Infra-red Monitor IRMON.EXESystem Tray access to infra-red devices. Not required unless you use infra-red devices
X infus infus.exeAdult content dialler
U Infuzer Infuzer.exe"Infuzer - ""is a service that copies dates from the web or an email straight to your electronic calendar"". Beware of the following adware trait - ""Infuzer provides web site owners with a unique opportunity to communicate with their visitors in a way that is useful and relevant to them
X infwin infwin.exe"VX2.Transponder parasite updater/installer related"
X Init [path to trojan]"Added by the DROPPER.EAT TROJAN!"
X Init32 Init32.exe"Added by the WINEX.A TROJAN!"
X Initial Page install.exeEasySearch browser hijack installer
Y Initialize8x8 8x8_init.exeTool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay
X inixs minix32.exe"Added by the AGENT.CKQX TROJAN!"
X injob injobs.exe"Added by the BINJO TROJAN!"
N Ink Monitor InkMonitor.exeAssociated with Epson (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
N InkWatch InkWatch.exeAssociated with Canon (and maybe other) printers. Tells you when the ink's running low and asks if you want to buy another cartridge on-line
X Inom snmoo.exe"Added by the RBOT-DPM WORM!"
Y InoRPC InoRpc.exe"Associated with eTrust Antivirus/InoculateIT"
Y InoRT InoRT9x.exe"Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage"
U InoTask InoTask.exe"Scheduled scans and signature updates for eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. Leave enabled unless you manually update signatures or perform routine scans. If enabled it can result in high CPU useage when performing updates"
X iNotice iservice.exeAdded by a variant of an MSN worm that tries to lure people to an infected site by using nude pictures and videos
? insCOA5 insCOA5.exe"??"
X Insider Insider.exe"Added by the AGENT.KMC TROJAN!"
U InstaAlert InstaAlert.exe"""Kayako InstaAlert allows you to receive realtime alerts whenever a ticket gets updated under the assigned departments. The application displays popups as and when the tickets are created or replied to allowing you to answer your customer requests and issues promptly"""
X Instafinder instafinder.exe"TopSearch.D adware"
X InstaFinderK InstaFinderK inst.exe"InstaFinder adware"
X Install Install.exe"Added by the BANCBAN-HG TROJAN!"
X Install part II updates.exe"Added by the RELFEERWORM!"
? Install Pending Files sifxinst.exe"Uninstall program for Lanovation's Prism Deploy and Prism Pack adminstrators software deployement tools. For specific information see here. Is it required?"
x install32 install32.exe"Added by the NUCLEAR.DG BACKDOOR!"
N InstallAurealDemos InstallAurealDemos.jsUsed to initialize the Aureal A3D demos InstallShield wizard
U InstallBuddy Ibtna.exe"InstallBuddy - automatically translates and installs your desktop documents
X InstallCleaner InstallCleaner.exe"Added by the ANYHOMB.F TROJAN!"
X Installed shell32.dll Office.exe..."Added by the LOVGATE.AO WORM!"
X Installed shell32.dll Office.exe"Added by the LOVGATE.E WORM!"
X Installer dial.exe"Malware - detected by Kaspersky as the AGENT.MM TROJAN!"
? InstallNAIProduct SETUP.EXE"Could be related to Network Associates Inc who own the McAfee VirusScan product amongst others. This was found in a directory called "VSC". Could it be an installation that failed and "SETUP.EXE" was left to run at startup as an error?"
X InstallProgram [path to trojan]"Added by the AGENT-HHU TROJAN!"
X InstallProvider newsoftware2007install.exe"Part of WinAntiVirusPro 2007 and Privacy Protector rogue security software (and possibly others) - not recommended"
X Installs SP2 [path] repcale.exe [path] palsp.exe"Added by a variant of the RANDON.AN WORM! Both files are located in %System%\qpalsp"
X Installs SP4 [path] repcale.exe [path] p0rd.exe"Added by the RANDON-AK WORM! Both files are located in %System%\ekrlgc"
U Installstub installstub.exe"Tool for Outlook and Outlook Express from Plaxo for organising and keeping contacts organised and updated and providing online access to your contacts and access from PDA or mobile phone"
X Instance 001 [path to worm]"Added by the ALASROU-A WORM!"
X Instant Access "rundll32.exe EGDHTML_1023.dll InstantAccess"
X Instant Access "rundll32.exe eg_auth_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe EGCOMLIB_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe EGCOMSERVICE_****.dll InstantAccess [**** = digits]"
X Instant Access "rundll32.exe p2esocks_****.dll InstantAccess [**** = digits]"
X Instant Access mwsrvacc.exe"InstantAccess premium rate adult content dialer"
X Instant Access linewsrv.exe"InstantAccess premium rate adult content dialer variant"
X Instant Buzz Daemon IBDaemon.exe"Instant Buzz adware"
X Instant Messenger Service imservice.exe"Detected by Kaspersky as the HEUR TROJAN!"
X instant messengers instantmsgtr.exe"Added by the AGOBOT-PC BACKDOOR!"
N Instant Update Center reminder.exe"Event reminder for calendar dates
U Instant Wireless Configuration Utility WUSB11cfg.exe"Utility used by the LINKSYS LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
U Instant Wireless Configuration Utility WPC11Cfg.exe"Utility used by the LINKSYS wireless USB Adapter (WUSB11) and indicates when a wireless access connection is made by a screen colour change. Also used for configuration"
N InstantAccess INSTAN~1.EXEFrom TextBridge Pro 9.0 OCR scanner software. Available via Start -> Programs
U InstantDrive InstantDrive.exe"Pinnacle Systems (ex VOB) InstantDrive - creates a virtual CD-ROM drive on the computer's hard drive. Part of InstantCD/DVD burning software"
X InstantPleasure instantpleasure.exeAdult content dialler
X InstantPleasureXXX instantpleasurexxx.exeAdult content dialler
N InstantTray PCLETray.exe"Pinnacle InstantCD/DVD disc creation software. Tray icon enabling a pop-up menu that lets you call up any of Instant CD/DVD's tools with one click. Can be started manually"
X instit instit.bat"Added by the OPASERV.H WORM!"
X instit INSTIT.BAT"Added by the OPASERV.K WORM!"
? InstUtlR.exe InstUtlR.exe"??"
X InSysSecure InSysSecure.exe"InSysSecure rogue security software - not recommended
X intdctrr idctup20.exe"SafeSurfing adware variant"
X Intec Service Drivers msmsgrs.exe"Added by the SDBOT-ADN WORM!"
X Intec Service Drivers [path to worm]"Added by the RBOT-GLU WORM!"
X Intec Service Drivers wing32.exe"Added by the RBOT.HAZ WORM!"
X Intec Service Drivers msmsgredss.exe"Added by the SDBOT-AGL WORM!"
X Intec Services Driverrs winrvc.exe"Added by a variant of the SDBOT WORM!"
X Intec Services Drivers msupdate22e.exe"Added by the RBOT-CGC WORM!"
U IntegardTray IntegardTray.exe"System Tray access to Integardparental control software from Race River Corp"
U Intel Active Monitor imontray.exe"System tray monitoring of fans
X Intel Audio Studio V2.0 fmideploy.exeDetected by VBA32 as the BIFROSE.ADR TROJAN!
X Intel Driver csrs.exe"Added by a variant of the SDBOT WORM!"
U Intel File Transfer xfr.exePart of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients
X Intel Management Services v32 mstime32.exe"Added by the AUTORUN-AYG WORM!"
U Intel PDS pds.exeIntel Ping Discovery Service (PDS). Part of Intel's LANDesk Management Suite 6 and the Common Base Agent (CBA) - used for communicating between the core server and managed clients. Will start the dial-up if installed and enabled
X Intel Physical Routine 1.2A stnetlib.exe"Added by the BACKDR-AS BACKDOOR!"
U Intel Product Number Utility IntelProcNumUtility.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
N Intel PROSet Tray Icon promon.exeSystem Tray icon for Intel PRO series ethernet adapters giving access to the diagnostic features
X Intel Service Drivers msconfig16.exe"Added by the MSCONFIG16 TROJAN!"
X Intel system tool hookdump.exe"Added by the SPYRE-H TROJAN!"
X Intel system tool winnook.exe"Added by the SPYRE-C TROJAN!"
X Intel system tool svehost.exe"Added by the AGENT-EBT TROJAN!"
X Intel system works iis.exe"Added by the RBOT.QGA WORM!"
U Intel(R) Common User Interface igfxtray.exe"System Tray access to display settings for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
U Intel(R) Common User Interface hkcmd.exe"Hot Key handler for Intel desktop and mobile motherboard chipsets with integrated graphics. With this enabled
U Intel(R) Common User Interface igfxpers.exe"Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
X intel32.exe intel32.exe"Added by the SmitFraud alias SPYJACK-B TROJAN!"
U IntelAPMClient amclient.exe"LANDesk® Management Suite software component"
N IntelAudioStudio IntelAudioStudio.exe"""Intel Audio Studio combines Intel® High Definition audio hardware features with Sonic Focus* Audio Refinement and Dolby* technologies to provide you with a comprehensive tool that puts you in control of your audio experience"". Audio utility supplied with some Intel motherboards"
X InteliSys smss.exe"Advertisingvision adware. Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X intell32.exe intell32.exe"Added by the SmitFraud alias Desktophijack.C TROJAN!"
X intell321.exe intell321.exe"Added by the SPYJACK-B TROJAN!"
X Intelli Mouse Pro Version 2.0B ncsjapi32.exe"Added by the BUZUS-O WORM!"
X Intelliflag_be.exe Intelliflag_be.exe"Intelliflag spyware"
U IntelliPoint point32.exe"Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice
U IntelliPoint ipoint.exe"Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice
U Intellitype type32.exe"Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys
U IntelMEM IntelMEM.exe"Related to connection events on an Intel chipset based modem. It can alert you if the telephone line is being used when you're trying to get online (when you're using dial-up). It can also alert you if your modem line is disconnected. Furthermore
X Intelprc Aas3lovu.exe"Added by the SILLYFDC-CG WORM!"
U IntelProcNumUtility cpunumber.exe"Intel Processor Serial Number Control Utility allows you to enable and disable the processor serial number capability of an Intel PIII processor. You can find more information here. System Tray icon providing the user with a visual state indication. You can find more information here"
Y IntelWireless ifrmewrk.exeAssociated with the Intel PRO/Set Wireless software
U IntelZeroConfig ZCfgSvc.exe"Zero Config MFC Application
? Intense Registry Service IntEdReg.exe /CHECK"Intense Educational Ltd - Language Office Software. Is it required?"
X InterceptedSystem [path to worm]"Added by the ANACON-B WORM!"
Y InterCheck Monitor Icmon.exe"Part of Sophos ant-virus sofware"
Y InterCheckMonitor ICMON.EXE"Part of Sophos anti-virus sofware"
X Interdll Interdll.exe"Added by the DELF family of TROJANS!"
X Internal [trojan filename]"Added by the SMOTHER and TRANSLAT TROJANS!"
X Internal regedit.exe /s c[month number]"Added by the FORTNIGHT.D TROJAN! Note that the Windows registry editor (regedit.exe) is a legitimate Microsoft file located in %Windir% and shouldn't be deleted. The file ""c[month number]"" is located in %Windir%
X Internal Memory File sysintmemory.exe"Added by the RBOT-GKT WORM!"
X InternalSystray Kazza.exe"Added by the OPTIXPRO.12.C BACKDOOR! Note - unlike the valid KaZaA executable
X internat internat.exe"Added by the LYDRA-F TROJAN! Note - the real internat.exe resides in %windir%\system (where %windir% is the Windows directory - C:\Windows or C:\Winnt) whereas this version resides in %windir%"
X Internat systray.exe"Added by the ALADINZ.P TROJAN! Note - this is not the legitimate systray.exe process. If you right-click on the real systray.exe the ""Properties"" reveal it to be a Microsoft file"
X Internat msgsrv32.exe"Added by the NYRUBOT-A BACKDOOR! Note - this is not the legitimate msgsvr32.exe process on a Win9x/Me system which should not appear in MSConfig/startup!"
X Internat [trojan filename]"Added by the CMJSPY-Y TROJAN!"
X Internat Conf bootconf.exe"Homepage hijacker
N internat.exe internat.exe"Microsoft language selection icon in system tray
X Internat.exe internat.exe"Added by the NETSNAKE TROJAN! Note - the real internat.exe resides in %windir%system (Win98/Me) or %windir%System32 (WinNT/2K/XP) (where %windir% is the Windows directory - C:\Windows or C:\Winnt) and has a ""?"" icon wheras this version resides in %windir% and has a ZIP icon"
X internct WinSocks5.exe"Added by the GRAYBIRD.F TROJAN!"
X internet smss.exe"Added by the MIFENG-K TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
X Internet Internet.exe"Added by the PWS-CS TROJAN!"
X Internet recruit.exe"Added by the RBOT-AJG WORM!"
X internet [trojan filename].exe"Added by the MIFENG-D TROJAN!"
X Internet winlogom.exe"Added by a variant of the SDBOT WORM!"
X Internet nteusodp.exe"Added by the RBOT-GFJ WORM!"
X internet winsas32.exe"Added by a variant of the SDBOT WORM!"
X internet lsass.exe"Added by the DSPY-A TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X Internet alm7tas.exe"Added by a variant of the RBOT WORM!"
X Internet wins.exe"Added by the RBOT.AAYF WORM!"
U Internet Answering Machine IAMNET~1.EXE"From Callwave. It offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
U Internet Answering Machine IAM.exe"From Callwave - offers a free utility to monitor your incoming phonecalls if you only have a single telephone line for internet access"
X Internet Antivirus IAvir.exe"Internet Antivirus rogue security software - not recommended
X Internet Antivirus Pro IAPro.exe"Internet Antivirus Pro rogue security software - not recommended
X Internet Application Driver expIorer.exe"Added by the IRCBOT-WK TROJAN!"
U Internet Call Director ICD.EXE"TELUS Internet Call Director (ICD) provides Internet users with real-time call notification while connected to the Internet"
U Internet Call Manager ICM.EXE"Starts Internet Call Manager dialog box and/or taskbar icons at bootup. This is a subscription program from internetcallmanager.com that monitors a dialup phone line for incoming calls and handles voicemail"
X Internet Config svchosts.exe"Added by the SDBOT TROJAN!"
X Internet Connection Wizard stisvsq.exe"EasySearch adware"
X Internet Connection Wizard [path to trojan]"Added by the SMUTSRCH-A TROJAN!"
X Internet Connection Wizard stisvsq1.exe"Added by the DLOADR-AWD TROJAN!"
X Internet Content Publisher ICP.EXE"Added by the RBOT-UD WORM!"
U Internet Disk Cleaner CLEARH~1.EXE"""Internet Disk Cleaner from Elongsoft ""protects your privacy by cleaning up all Internet tracks and past computer activities"""
U Internet Download Accelerator ida.exe"Internet Download Accelerator download manager"
X Internet download manager service idman.exe"Added by the RBOT-BMS WORM!"
X Internet Exploere Services urlmon32.dll.exe"Added by the EVIAN.C WORM!"
X Internet Explore Microsoft lEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
X Internet Explorer iexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Internet Explorer IEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Internet Explorer IExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Internet Explorer http.exe"Added as part of a new potential CWS infection
X Internet Explorer iexpiore.exe"Added by the RBOT-AZC WORM!"
X Internet Explorer IEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
X Internet Explorer twain.exe"Added by the AGENT.BEA TROJAN!"
X Internet Explorer Agent iexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Internet Explorer Auto-Update updt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
X Internet Explorer Configuration IEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Internet Explorer Security iexplore.pif"Added by the RBOT-ALQ WORM!"
X Internet Explorer Sys32 isys32.exe"Added by the IRCBOT-ADA WORM!"
X Internet Explorer Updater lexbac.exe"Added by the DOWNLOAD TROJAN!"
X Internet Explorer Updater iexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
X Internet Explorer6 IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Internet Explorer6.0 IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Internet Firewall Layer tsqla.exe"Added by a variant of the SPYBOT WORM!"
U Internet History Eraser HERASER.exe"Internet History Eraser - deletes your browsing tracks"
X Internet Loader1 MSInstall61.exe"Added by the KWBOT.B WORM!"
X Internet Mail and News msqdevl.exe"EasySearch adware"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list