Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
U ISW.exe ISW.exe"Related to Internet Security Wizard from AT&T (formerly BellSouth Premium Internet Security) alerts users about any potential security threats. It should not be uninstalled unless the user wants to completely remove all traces of AT&T Internet Security Suite"
X isxa isxa.exe"Added by the SMALL-EIV TROJAN!"
N iSysCleaner iSysCleaner.exe"iSysCleaner - a simple tool that searches for junk files on your computer and allows you to delete them. Simple cleaning maintenance can be done by the user"
X isystem isystem.exe"Added by the CHORUS-A TROJAN! Searchforfree browser hijacker"
X ItalU italfds.exe"Added by a TROJAN - see here"
U Itk Itk.exe"In The Know - surveillance software that creates records of everything people do on a computer
U itk.exe itk.exe"Insert ToggleKey by Mike Lin. ITK sounds a tone whenever you press Insert"
U iTouch iTouch.exe"Loads the iTouch configuration settings for supported Logitech keyboards. It's required if your keyboard has shortcut buttons and you use them or have reconfigured them for different functions. It's also required if your keyboard does not have the num lock
N ItsDeductiblePopUp ItsDeductible.exe"ItsDeductible from Income Dynamics. Calculates your noncash donations quickly and easily. This startup entry checks a registry entry for the next 'PopUp' date and if it is a past or current date displays a program related tip"
X ITUNES itune.exe"Added by the RBOT-ZU WORM!"
X ITUNES itunes.exe"Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %System%"
X Itunes dials.exe"Detected by Kaspersky as the AGENT.MM TROJAN!"
X Itunes itunes.exe"Added by the OSCABOT-L WORM! Note - do not confuse with the legitimate Apple iTunes process with the same filename which is always located in %ProgramFiles%\iTunes. This one is located in %Windir%"
Y iTunes Helper iTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
X iTunes Music iTunesHelper32.exe"Added by the SDBOT.CHK WORM!"
X iTunesAgent ita.exe"Added by the TACTSLAY.U TROJAN!"
X itunesff itunesff.exe"Added by the EB adult premium dialer"
Y iTunesHelper iTunesHelper.exeInstalled with Apple's iTunes for Windows. Uses ~3-4MB of memory and if disabled in MSCONFIG or deleted from the registry it will re-instate itself after running iTunes a few times - hence the reluctant Y recommendation
U itype itype.exe"Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys
N Iusage netdet.exe"Internet Usage Monitor - utility to calculate the cost and time on the internet via dial-up"
X iut75 uzcx.exe"Added by the DLOADER-AXV TROJAN!"
X iv iv.exe"Part of the Internet Antivirus and Internet Antivirus Pro rogue security software - not recommended
X ivHost taskManager.exe"Added by a variant of the SPYBOT WORM! See here"
X ivHost [6 random letters].exe"Added by a variant of the SPYBOT WORM! See examples here and here"
N IVPServiceMgr ivpsvmgr.exe"Toshiba IVP Service Manager application which appears as a red satellite dish icon in the System Tray. This is Toshiba's equivalent to the Windows Automatic Update feature as
X ivy.exe ivy.exe"Added by the AGENT-ENZ TROJAN!"
N IW ControlCenter iwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
U iwctrl iwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
U IW_Drop_Icon iwctrl.exe"Pinnacle Systems InstantWrite enables you to use your CD-R
X ixplore ixplore.exe"Added by the SDBOT-CY TROJAN!"
X ixplores ixplores.exe"Added by the SDBOT-CE WORM!"
X ixproxy [path to trojan]"Added by the XORPIX-A TROJAN!"
X ixsso ixsso.exe"Added by the AGENT.AM TROJAN! Note - example names include ""XviD""
X iyelejiv yujixit.exe"Added by the SDBOT.BJK WORM!"
? IZE N/A"??"
X ϵͳע�ï½ï¿½ï¿½ zhuruqi.exe"Added by the QHOST.V TROJAN!"
N j2 Tray Menu HotTray.exe"eFax Messenger Tray Menu system tray icon for eFax Messenger Plus. Available via Start -> Programs. Disabling instructions available here"
X JA Cfg Util v2 jacfg2.exe"Added by the RBOT-AL WORM!"
X JA Config 32 Awesome32.exe"Added by a variant of the SDBOT WORM!"
U Jammer jammer.exe"Jammer by Agnitum - ""Jammer is the last word in Internet security. It combines a user-friendly interface with very sophisticated and powerful security measures that protect your Windows system while you are surfing the web"""
X Jammer2nd Jammer2nd.exe"Added by the NETSKY.Z WORM!"
X java remote.cmd"Added by the BANKER-EHG TROJAN!"
X java system.exe"Added by a variant of the IRCBOT BACKDOOR!"
X Java (VM) v6.9 jav.bat"Added by the AGENT-GZK TROJAN!"
X Java applet javaup.exe"Added by the SDBOT-ACF WORM!"
X Java Application vssmf32.exe"Added by the SPIGOT BACKDOOR!"
X Java Auto Update ujm.exe"Added by the SDBOT-ADH WORM!"
X Java Runtime Environment jbuild.exe"Added by the DELBOT-J WORM!"
X Java Runtime Value runjava.exe"Added by the RBOT-DDJ WORM!"
X Java Runtimes iexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
X Java Softe Java32.com"Added by the RBOT.ECN WORM!"
X Java update javaqs.exe"Added by the SWARLEY.A WORM!"
X Java Update keeper.exe"Added by the AGENT-DIS TROJAN!"
X Java Update svchost.exe.exe"Added by the AGENT-LBS TROJAN!"
X Java Update hostwww.exe.exe"Added by the AGENT-MFH TROJAN!"
X Java Virtual Machine javaw.exe"Added by a variant of the RBOT WORM!"
X Java VM v6.9.2 jav.bat"Added by the DWNLDR-HLM TROJAN!"
X Java VM v6.91 jav.bat"Added by the DWNLDR-HLL TROJAN!"
N Java(TM) Platform SE 6 jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
N Java(TM) Platform SE 6 U* jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now. U* represents the update version
N Java(TM) Platform SE Auto Updater 2 0 jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
X Java**.exe [* = random char] Java**.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X Java**32.exe [* = random char] Java**32.exe [* = random char]"CoolWebSearch/HomeSearch adware - for examples
X java-plugin javasctp.exe"Added by the VB.AMX TROJAN!"
X Java32 Configuration Loader msnmesgr.exe"Added by a variant of the RBOT WORM!"
X JavaCore JavaCore.exe"Added by the MATCASH TROJAN!"
X Javascript jscript.exe"Added by the DELBOT-AD WORM!"
X JavaScript Debugging Service JsDbgMan.exe"Added by the DERDERO.E WORM!"
X JavaScriptMsxrs Msxrs.exe"Added by the VB.BL WORM!"
X JavaTray traymgr.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X JavaUpdate0.07 [filename]"Added by the JUPDATE TROJAN!"
X JavaUpdateSched jusched32.exe"Added by the BCKDR-CKB BACKDOOR!"
X JavaVM java.exe"Added by the MYDOOM.M WORM and variants! Note - not to be confused with the valid Windows ""java.exe"" which is located in %System% as this is located in %Windir%"
X javawsa.exe javawsa.exe"Added by the BANK-Y TROJAN!"
X jawa32 jawa32.exe"Added by the AGENT.BG WORM!"
X Jawa322 jawa32.exe"Added by a variant of the AGENT.BG trojan"
N JB Jiffybar.exe"Get Paid As You surf" application
X jcidls [random filename]"Added by a variant of the SLAPER TROJAN!"
? Jessops Insert Detect InsDetect.exe"Part of Jessops Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
N Jet Detection ADGJDet.exeAdded with SoundBlaster Live! or Audigy soundcards for headphone autodetection
Y JetAdmin Discovery Indicator HPJETDSC.EXE"HP JetAdmin software for HP JetDirect Print Servers. HPJETDSC.EXE is the file necessary for the JetAdmin Discovery Indicator (paper airplane in the taskbar). It gets launched automatically through the registry
X jete yujixit.exe"Added by the SDBOT.BRT WORM!"
X Jfwehnrt ghgfjrs.exe"Added by the SDBOT-IJ WORM!"
X jiahus svchqs.exe"Added by the WOWPWS-AL TROJAN!"
X jijbl ezlwy.bat"Added by the REDDW WORM!"
X jkdfj94kgdftdf winlogan.exe"Added by the ZLOB.BZ TROJAN!"
U JMB36X Configure JMRaidTool.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
Y JMB36X Configure JMRaidSetup.exe"JMB36x series RAID configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
U JMB36X IDE Setup JMInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers"
U JMB36X IDE Setup xInsIDE.exe"JMB36x series IDE (or Parallel ATA) configuration utility from JMicron Technology for their PCI Express to SATA II and PATA Host Controllers. This is normally located in %Windir%\RaidTool"
X jmudkve.dll "rundll32.exe jmudkve.dllmzrwkwf"
X Jnskdfmf9eldfd csrssc.exe"Added by the AGENT.EBC TROJAN!"
U Job-oversigt taskmon.exe"Task Monitor (on Danish language versions of Windows) - checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users
U JobHisInit JobHisInit.exeUsed by Ricoh network printers to enable network printing from the client
U Jog Serve JogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
U JogServ2 JogServ2.exe"Jog Dial" on a Sony Vaio laptop. The dial can select various functions such as control audio. Needed if you use its features
X johkjh srvd.exe"Added by a variant of the SLAPER TROJAN!"
X john315 srrvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj315 srvc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj3155 srvcc.exe"Added by a variant of the MAILBOT-BI TROJAN!"
X johnj3cd srvdc.exe"Added by a variant of the SLAPER TROJAN!"
U Jomantha razerhid.exe"Belkin n52te (powered by Razer) gaming keypad driver - required if you use the additional features and programmed keys/macros"
X jon315 [path to trojan]"Added by the MAILBOT-BI TROJAN!"
? jotl millenzje.exe"??"
U JOYTECH USB Neo S Controller JoytechNeoSTrayIcon.exe"System Tray access to Joytech Neo S PC gamepad controller software"
X jpgdiag [path to worm]"Added by the STRATION-AN WORM!"
X jpupd jpupd.exe"Added by the DIALER.CM TROJAN!"
X Jreg Jreg2b.exe"FlashEnhancer adware"
X jucheck jucheck.exe"Added by the SCRIMGE.O WORM!"
X Jufualt winxp2.exe"Added by the SDBOT-AAB WORM!"
X Jufualt svhost.exe"Added by the SDBOT-ADJ WORM!"
X Jufualt java2.exe"Added by the SDBOT.AOE WORM!"
N Juice Juice.exe"Juice - a free utility that ""allows you to select and download audio files from anywhere on the Internet to your desktop"". This entry is present if you choose the option to add it to the startup group during installation"
N Juno_uoltray exec.exeJuno ISP software - not required
X JuPo jupos.exe"Added by the SDBOT-CAG WORM!"
N jusched jusched.exe"Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
X jusched [path to trojan]"Added by the BANKER-BWR TROJAN!"
X jusched jusched.exe"Added by the BANKER-BOV TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
X jushed32.exe jushed32.exe"CoolWebSearch parasite variant - also detected as the BIZTEN-L TROJAN!"
X jusodl severe.exe"Added by the QQPASS.48436 TROJAN!"
U JussDropUtility JussDrop.exe"Related to DropShots Inc. A subscription based service for family to connect
N JustVoip JustVoip.exe"JustVoip - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
X jutsu jutsu.exe"Added by the RBOT-LS WORM!"
U jv16 PT TempFileTool TempTool.exe"jv16 PowerTools File Cleaner - ""allows you to find obsolete and left-over temporary files"""
U jv16PT - Privacy Protector Task.jvb"jv16 PowerTools Privacy Protector - ""allows you to protect your privacy by automatically clearing out all the unwanted history items and cookies from you computer
U Jv16pt Network Resident jv16pt_network.exe"jv16 PowerTools network resident program. Only needed if you are using the program's network features"
X JvcHost jvcsvc32.exe"Added by the AGOBOT-AIU WORM!"
X jvdnlssn fljzsshc.exeFlingstone.com adware - and its Golden Palace Casino program
X JVM0 JVM0.exe"Added by the BANLOA-AX TROJAN!"
X JVM0.12 [random filename]"Added by the TEADOOR-A TROJAN!"
X JVM0.14 [random filename]"Added by the TEADOOR-B TROJAN!"
X jvms.exe jvms.exe"Added by the ORCU.B TROJAN!"
X JW Manager jwmngr.exe"Added by the DELBOT-G WORM!"
X jxef1104 jxef1104.exe"Added by the XIPI-A WORM!"
X JXL Radio jxl.exe"Added by the RBOT-EBE WORM!"
U jx_Key "Rundll32 JXKey.dllRundll32Main"
X jysyqm [random filename]"ZenoSearch adware"
? Jzi16 jzi16.exe"??"
X jzvfvsqpc jzvfvsqpc.exe"Added by the AGENT-GWP BACKDOOR!"
X K2ps_full.task K2ps_full.exe"Added by the JUNTADOR.K TROJAN!"
N K6CPU.EXE K6CPU.EXEAuthenticates CPU as K6 in system properties
X kaa SVCHHS.exe"Added by the AGENT-JKP TROJAN!"
X Kadoc [random filename].exe"Added by the STAPREW TROJAN!"
U KADxMain KADxMain.exe"System Tray access to IntelliSonic Speech Enhancement - by Knowles Acoustics. Designed to render speech from a user selectable direction
X kak kak.hta"Added by the KAKWORM WORM!"
U Kalender Kalender.exe"UK's Kalender ""helps you organizing your dates and tasks and reminds you of upcoming events"""
U Kalibump Kalibump.exe"Used with the now unsupported Kali software for on-line gaming. This is used to automatically bump up the priority of WinProxy to GREATLY improve game speed when using a SOCKS proxy"
X kalvsys kalv****.exe [* = random char]"EliteBar adware"
X kalvsys kalv***32.exe [* = random char]"EliteBar adware"
X kamsoft ckvo.exe"Added by the GAMANIA-BW TROJAN!"
N Kana Reminder Reminder.exe"Kana Reminder is a program which can be used to set a reminder to be triggered at a specified time"
U Karen's Once-A-Day II PTOAD.exe"""Have a job that should be run exactly once each day? Karen's Once-A-Day II is just what you need!"" Scheduler that lets you specify progams
U KASP OESpamTest.exe"Kaspersky Anti-Spam"
X Kasper Antivirus KASPERANTIVIRUS.EXE"Added by a variant of the SPYBOT WORM!"
Y Kaspersky Anti-Hacker KAVPF.exe"Kaspersky Anti-Hacker personal firewall - no longer available"
Y Kaspersky Anti-Virus Monitor AvpM.exe"Kaspersky Anti-Virus Lite - no longer available"
X Kaspersky Antivirus KasperskyAV.exe"Added by a variant of the RBOT WORM!"
X Kaspersky Email Security javaupd.exe"Added by the SWARLEY.A WORM!"
X kaspersky32 kasperskyLabs32.exe"Added by the RBOT-GOT WORM!"
X KasperskyAv kaspersky.exe"Added by the MIMAIL.T WORM! Note - this has nothing to do with the real Kaspersky anti-virus"
X KasperskyAVEng Kasperskyaveng.exe"Added by the NETSKY.V WORM!"
X KAT KAT.vbs"Added by the SOAD-D WORM!"
U KatMouse KatMouse.exe"KatMouse - utility to enhance the functionality of mice with a scroll wheel
Y kav avp.exe"Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
X kava kavo.exe"Added by the LINEAG-GLG TROJAN!"
X KAVFOX win1ogoin.exe"Added by the GWGHOST-M TROJAN!"
X kavir kavir.exe"Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
X KAVPersonal svchost.exe"Added by the LINEAGE-V TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Y KAVPersonal50 Kav.exe"Kaspersky Anti-Virus Personal 5.0"
X KAVPersonal90 wscntfy.exe"Added by the BANKER-FZ TROJAN!"
Y KavPFW KavPFW.exe"KingSoft Personal Firewall"
X KavRuns Windll.exe"Added by the TRYNOMA TROJAN!"
Y KavStart KAVStart.exe"KingSoft Personal Firewall"
Y kavsvc kavsvc.exe"Kaspersky antivirus"
X KavSvc ******.exe reg_run [* = random char]"Added by the QOOLOGIC TROJAN!"
X kavsvc [random 6 char filename]"Added by the QOOLOGIC TROJAN! Uses random file names (examples: nzkklz.exe
X KAVutil [worm filename]"Added by the WINTOO.B WORM!"
N KAZAA kazaa.exe"KAZAA is a file-sharing program which unfortunately being ad-based includes "Cy-door" adware. Check here for information about "Cy-door" and here for a program that can remove it"
N KAZAA [path] kpp.exe [path] kazaalite.kpp"System Tray access to later versions of the Kazaa Lite P2P file sharing utility - namely the K++ and Resurrection variants. Kazaa Lite is the unauthorized modification of the original Kazaa Media Desktop - with the malware removed"
X Kazaa Download Accelerator Updater (required) regsvr32 kdp****.dll [* = random char]"SafeguardProtect/Veevo hijacker. Note that regsvr32.exe is a legitimate Microsoft file used to register and unregister OLE controls and shouldn't be deleted. The random DLL file is found in %System%"
X Kazaa lptt01 kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X Kazaa ml097e kazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
X KAZAACuf 9"Added by the KITRO.D (or ARGEN.A) WORM!"
N kazaalite kazaalite.exe"Kazaalite is a file sharing client - not to be confused with the original Kazaa program. Unlike the original
N KaZooM KaZooM.Exe"KaZoom from Blue Haven Media - ""add-on application that automatically speeds up the download process and finds the files you want with far more power than regular KaZaA searches"""
X kb AUTO.txt"Added by the BRONTOK-CV WORM!"
Y KB891711 KB891711.exe"Installed by the Windows KB891711 critical update
Y KB918547 KB918547.EXE"Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only"
Y KB926239 "rundll32.exe apphelp.dll ShimFlushCache"
U KBD KBD.EXEMultimedia keyboard manager. Required if you use the multimedia keys
U KBD KbdStub.EXEKey Watcher from HP - watches for Multimedia Keys on HP keyboards
U KBD MediaCenter MEDIACTR.EXEMultimedia keyboard manager. Required if you use the multimedia keys
X kbddrv32 kbddrv32.exe"Added by the CRYPTER.A TROJAN!"
X kbddrvinf kbddrvinf.exe"Added by the CRYPTER.A TROJAN!"
N KCeasy KCeasy.exe"KCeasy - a Windows peer-to-peer filesharing application which uses giFT as its 'back end' foundation. The networks currently supported are OpenFT and Gnutella"
U KClient kstatus.exeKClient Kerberos client software for Win32 systems. It provides the libraries and utilities needed to use Kerberos-based PC applications developed by Computing Services such as KWeb and NiftyTelnet
X Kcrner Kcrner.exe"Added by the LINEAG-AIL TROJAN!"
X kdmsx [8 random letters].exe"Added by the SDBOT.AIJ BACKDOOR!"
N kdx KHost.exe"Verisign Kontiki Delivery Management System - Windows-based client software that enables secure delivery of content to users' desktops"
U KE9801 DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
X Keenvalue Keenvalue.exe"KeenVal adware"
X KeepCop KeepCop.exe"KeepCop rogue security software - not recommended
X KeepCop.exe KeepCop.exe"KeepCop rogue security software - not recommended
X kell liser.exe"Added by the AGENT.AUTP TROJAN!"
U KEMailKb KEMailKb.EXE"Controls the buttons at the top of the Micro Innovations 650i Internet Access Keyboard. If you disable it you cannot use the buttons - like volume control or shut down"
? Kemet kemet.exe"??"
U KeNotify KeNotify.exe"Toshiba utility found on their laptops. This program is responsible for the Toshiba LapTop Help 'FlashCards' utility that sits at the top of the screen giving easy access to the 'F keys' alternative functions such as Lock
X kERe kERe.exe"Added by the BRONTOK-BT WORM!"
U Kerio VPN Client kvpnclient.exe"Kerio VPN Client"
X kern64dll [random filename]"Added by the TARNO.J TROJAN!"
X Kernal Fault Check ntosrkl.exe"Added by a variant of the SDBOT WORM!"
X kernctl32 "rundll32 kctl32.dll initialize"
X Kerne0223 Kerne0223.exe"Added by the LEGMIR-ZA TROJAN!"
X Kernel bboy.exe"Added by the MUMU.B WORM!"
X Kernel services.exe"Added by the FOOZ-A TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
X kernel kernel.exe"Added by the MATCASH.CF TROJAN!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list