Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X ravshell iexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
Y RavStub ravstub.exe"Rising antivirus"
X ravtask rund1132.exe"Added by the DLOADER.IYT TROJAN!"
X ravtask svch0st.exe"Added by the LINEAG-AIN TROJAN!"
Y RavTask RavTask.exe"Rising antivirus"
X ravtask iexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
X RavTime Mstray.exe"Added by the WUKILL.A WORM!"
Y RavTimer RavTimer.exe"RAV AntiVirus"
X RavTimer explores.exe"Added by the HOMEY-A TROJAN!"
X RavTimeXP [worm filename]"Added by the WULLIK.B WORM!"
X RavTimeXP Virus"Added by the CAGER.A WORM!"
X RavTimXP [worm filename]"Added by the WULLIK.B WORM!"
X RavUptets agetlke.exe"Added by the QQPASS-AK TROJAN!"
X RavUptkt agetlktz.exe"Added by the QQPASS-AJ TROJAN!"
X RavUptpe ravsesur.exe"Added by the QQPASS-T TROJAN!"
? rav_temp.exe rav_temp.exe"??"
X rawload [path to trojan]"Added by the DARKIRC.QZ TROJAN!"
X RAX SYSTEM scrigz.exe"Added by the MYTOB.KR WORM!"
N Ray Process Killer Prkill.exe"Ray Process Killer - clicking right mouse button produces popup menu with current active tasks. You can choose any task and click "Ok" to terminate it. Use CTRL+ALT+DEL instead"
X Raymond present friska_w32.exe"Added by the RUBBLE-C WORM!"
U razer razerhid.exe"Razer gaming mouse/keyboard driver - required if you use the additional features and programmed keys/macros"
X rb32 lptt01 rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X rb32 ml097e rb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X rbenh ml***e rbenh.exe"RapidBlaster variant (in a ""RBEnhance"" folder in Program Files) where *** represents random digits. Recommended you use RapidBlaster Killer to uninstall - see here"
X rbnynkctv rbnynkctv.exe"Added by the AGENT-GPA BACKDOOR!"
X RBOT v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server glossary.exe"Added by the VANEBOT-J WORM!"
X RCAutoLiveUpdate MaxLURC.exe"Max Registry Cleaner rogue registry cleaner - not recommended
X Rcf Driver rcf.exe"Added by the RANDEX.BLD WORM!"
U RCHotKey RCHotKey.exe"Part of RingCentral Call Controller™ which ""turns your PC into your personal business command center. It brings you real time control of your calls
X rcimlby.exe rcimlby.exe"Added by the SDBOT-DHK WORM!"
X rCron rcron.exe"""Switch"" premium rate adult content dialler variant"
X rCron dservice.exe"""Switch"" premium rate adult content dialler variant"
U RCScheduleCheck RCSCHED.EXE"Scheduler for VCOM's Recovery Commander - which ""can restore your non-booting system back to normal. It only takes a few minutes to get your system back up and running"""
X Rcsh weaa.exe"PurityScan adware"
X RCSync RCSync.exe"PrizeSurfer related. ""PrizeSurfer is the free software that automatically enters you to win cash and prizes just for surfing the web and shopping online!"" Stealth installed malware"
U RCSystem DLLML.exe RCSystem"Related to Creative DLL Module Loader for the Sound Blaster X-Fi (and maybe others). This program is non-essential process to the running of the system
X RCSystemTray MaxRCSystemTray.exe"Max Registry Cleaner rogue registry cleaner - not recommended
X RDAgent RDAgent.exe"RegDefense rogue registry cleaner - not recommended"
U RDClient RDCLIENT.EXE"Remote Disconnection Utility from Twiga. Used for connecting and disconnecting dial up connections on a network - only needed if there is a shared internet connection"
X RDListener RDListener.exe"RegDefense rogue registry cleaner - not recommended"
X RDLL RunDll16.exe"Added by the SDBOT.F TROJAN!"
X RDPlatinum v5 RDPlatinumv5.exe"Registry Defender Platinum rogue registry cleaner - not recommended
X rdvs [worm filename]"Added by the ULTIMAX.B WORM!"
U RE.exe RE.exe"RegistryEasy registry cleaner - regarded by Symantec as a potentially unwanted application
X Reactor3 [random name]32.exe"Added by the BOFRA.A WORM!"
X Reactor5 [random name]32.exe"Added by the BOFRA.D WORM!"
X Reactor6 [random name]32.exe"Added by the BOFRA.C WORM!"
X Reactor7 [random name]32.exe"Added by the BOFRA.B WORM!"
X Reactor8 [random name]32.exe"Added by the BOFRA.E WORM!"
X Reactor9 [random name]32.exe"Added by the BOFRA.E WORM!"
X readdb40 "rundll32.exe readdb40.dll EnableRunDLL32"
U readericon readericon45G.exeTray icon to set various configuration settings for Sunkist (and maybe other) media card readers
? readericon10 readericon10.exe"Related to a multimedia card reader - possibly based upon an Alcor Micro chipset. What does it do and is it required?"
X reader_s reader_s.exe"Added by the AGENT-IUT TROJAN!"
N Reader_sl Reader_sl.exe"Speeds up the time it takes to load the Adobe Reader PDF document reader. ""The Speed Launcher quickly opens and closes all of the files that Acrobat or Adobe Reader will use when the application starts. Opening and closing the files allows your virus protection software to check these programs and add them to its list of safe files"" - see here. Not required for Adobe Reader to function properly"
N REAL realjbox.exe"Real Jukebox - MP3 and music files player"
X Real Internet Player Reaiplay.exe"Added by a variant of the SPYBOT WORM!"
X Real Media Player realplayer2.exe"Added by a variant of the RBOT WORM!"
X Real player updater realupd.exe"Added by the PARLAY TROJAN!"
X real scheduler.hta RealAudio.exe"Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player"
U Real Spy Monitor Winrsm.exe"Realspy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Real Statics Agent ccreal.exe"Added by a variant of the RBOT WORM!"
X Real-Tens Real-Tens.exe"DownloadWare adware"
X RealAudio RealAudio.exe"Added by the CEEGAR TROJAN! Note - this is not associated with the popular RealPlayer media player"
X Realaudio Player realaudio32.exe"Added by the AGOBOT.AFR WORM!"
X RealAV.exe RealAV.exe"Real Antivirus rogue security suite - not recommended
N RealDownload RealPlay.exeDownload manager. Available via Start -> Programs
X RealDownload Express npnzdad.exeAdvertising spyware
N Reality Fusion GameCam SE RFTRay.exeReality Fusion GameCam Video Interaction Technology Software that comes with the Logitech QuickCam PC video camera and other USB cameras. It's only an icon that appears on your System Tray. Available via Start -> Programs
N RealJukeboxSystray tsystray.exeSystem Tray icon for RealJukebox
X realone_nt2003 moniker.exe"Added by the SNONE.A WORM!"
X RealP1ayer [path to file]"Added by the RPLAY.A TROJAN! Note that the name has a number ""1"" in place of the second lower case ""L"""
N realplay realplay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X realplay lptt01 realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
X realplay ml097e realplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
N RealPlayer realplay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X RealPlayer Ath Check rnathchk.exe"Added by the MYTOB.AG WORM!"
X RealPlayer Ath Check mathchk.exe"Added by the MYDOOM-AJ WORM!"
X Realplayer Codec Support realsched.exe"Added by the AGOBOT-AAD WORM! Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name"
X Realplayer One realplay.exe"Added by the RBOT-NK WORM!"
X Realplayer Video RealPlay.exe"Added by a variant of the RBOT WORM!"
X Realplayer.exe Realplayer.exe"Added by the DELF.CNV TROJAN!"
N RealPlayer2 MsgCenterExe"RealNetworks RealPlayer related - disabling this application will not affect Real Player in any way"
X RealPlayerUpdater realupd32.exe"Added by the LOHAV-T TROJAN!"
? Realpopup Realpopup.exe"RealPopup - "Replaces old winpopup with a full featured freeware tool which remains stable and simple as its predecessor""
N Realsched realsched.exe"Application Scheduler installed along with RealOne Player. Runs independently of RealOne Player
U RealSPEED RealSPEED.Exe"RealSPEED - tweaking utility to speed-up your internet connection"
U Realtek AC97 Audio - Event Monitor ALCMTR.EXE"Realtek Azalia Audio - Event Monitor
N Realtek HD Audio Sound Effect Manager RTHDCPL.EXE"Realtek HD Audio Control Panel
U Realtek HD Sound Manager SOUNDMAN.EXE"Realtek Sound Manager
X Realtek Sound Manager Tecompntwx.exe"Added by a variant of the IRCBOT BACKDOOR!"
U Realtek Voice Manager Skytel.exe"Realtek Voice Manager
U Realtime Audio Engine mmrtkrnl.exe"Associated with ALCATech BPM Studio"
Y Realtime Monitor realmon.exe"Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates"
X RealTimeProtector winlogon.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
? RealTimeUpdate RealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
X realtpsk realsched.exe"Chinese originated adware - detected by Panda as NewWeb. Note - this is not the legitimate RealOne Player (realsched.exe) application of the same name and this file is located in %System%"
N RealTray RealPlay.exeSystem Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences
X RealUpdater realupd.exe"Added by the PARLAY or MITGLIEDER.I TROJANS!"
X REAnti.exe REAnti.exe"REAnti rogue security software - not recommended
X RebateNation0 RebateNation0.exe"RebateNation adware"
N Reboot Reboot.exeMS-DOS/Win3.1 utility use to clean boot a system. Sometimes installed by default from some driver CDs for motherboards
U Receiver PcfaxRcv.exe"Incorporated on multifunction digital copiers (such as the
Y Recguard recguard.exe"On HP computers
N Reclip reclip.exe"Reclip Popup Clipboard manager"
U Reclusa razerhid.exe"Microsoft Reclusa (by Razer) gaming keyboard driver - required if you use the additional features and programmed keys/macros"
X Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} RH.DLL"SmartPops search hijacker"
N RecordNow RecordNow.exe"RecordNow! CD-writing utility from Sonic Solutions"
N Recover N/AAdded during the installation of Comcast High Speed Internet software. During installation the system reboots and if the disk is removed a screen appears asking for the disk to be re-inserted to complete installation. Not required once installion is complete
X recover.bmp.exe Rundll.exe"Added by the ANAFTP-01 TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
N RecoverFromReboo RECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboo RecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboot RECOVE~1.EXE"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
N RecoverFromReboot RecoverFromReboot.exe"Part of a DSL installer package from SBC (probably SBC/Yahoo DSL). If the installation is botched
X Recoveru system svchast.exe"Added by a variant of the LINEAGE-AV TROJAN!"
X Recoveru systems svchost.exe"Added by the SMALL.DDX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Temp%"
N RecShe RecSche.exeRecording scheduler for WatchTV Capture Card (TV Tuner card)
X Recycle Bin Handler recycler.exe"Added by the SHUCKBOT-A TROJAN!"
X Recycle Bin Handler 2005 system.exe"Added by the BDOOR-HO BACKDOOR!"
X Recycler DO NOT MODIFY recyclecl.exe"Added by the RBOT.DDA WORM!"
X RecycleSTR msreg32.exe"Added by the RBOT-TC WORM!"
N Red Flag redflag.exePMS prediction program with modes for guys and girls - no longer available
U Red Swoosh EDN Client RSEDNClient.exe"Red_Swoosh distributed networking software - a desktop client that enables users to download and stream files from each other
X redirect redirect*.exeDotcomtoolbar/Linksummary hijacker installer - where * is a random digit
N Redline Taskbar taskbar.exeTaskbar icon for the Redline RegTweak overclocking program as supplied with Sapphire ATI graphics cards
X REEGRUN [path to file]"Added by the SECDROP.AI TROJAN"
X Reeg_ [path to trojan]"Added by the BANCBAN-AW TROJAN!"
X Reek 32 Server reek32.exe"Added by the RANDEX.AL WORM!"
U Referee referee.exe"MediaComm's monitor for file association changes. Stop rogue programs from screwing your settings either on installation or whenever they run"
U Reflex Vision ReflexVision.exe"Reflex Vision from Increment Software. ""A background application for Windows XP that makes switching windows faster and easier"""
N Refresh Refresh.exe(Iomega) Refresh - loads the Iomega desktop icons at startup
X Reg Reg.hta"Passon homepage hi-jacker"
? Reg Check lpt.exe"Related to Supanet ISP software - what does it do and is it required?"
X reg run Systen.exe"Added by the BANCOS-BS TROJAN!"
X Reg Service winsy.exe"Added by a variant of the SPYBOT WORM!"
X Reg Service winslogon.exe"Added by the AGOBOT-SC WORM!"
X Reg Service ipcfg.exe"Added by the AGOBOT-SO WORM!"
X Reg Service REGSRV32.EXE"Added by the RBOT.ZW WORM!"
X Reg Service WinnConfig.exe"Added by the AGOBOT-PF WORM!"
X Reg Service NT32.exe"Added by the AGOBOT.G TROJAN!"
X Reg Services Winboot32.exe"Added by the RBOT.PB WORM!"
X reg1.reg vuamgard.exe"Added by a variant of the IRCBOT TROJAN!"
U reg2.0 SVCH0ST.EXE"eSpyNow surveillance software. Uninstall this software unless you put it there yourself. Note - the filename has the digit 0 rather then the uppercase ""o"""
X Reg32 Reg32.exeHijacker - redirecting to only-virgins.com
X reg32 reg32.exe"Added by the NOUPDATE.B TROJAN!"
X Reg32 reg33.exe"CoolWebSearch parasite variant - also detected as the STARTPA-M TROJAN!"
X Regcheck ~CAB001.EXE"Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!"
X regcheck [path to file]"Added by the SERVPAM TROJAN!"
U RegClean Expert Scheduler RCHelper.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
U RegClean Expert Scheduler RCScheduler.exe"""Registry Clean Expert scans the Windows registry and finds incorrect or obsolete information in the registry. By fixing these obsolete information in Windows registry
X RegCleaner SYSio32.exe"Added by an unidentified VIRUS
X RegCompres Regcpm32.exe"Added by the POLDO.B TROJAN!"
X RegCompres REGCPM32.EXE"Added by the DASMIN-E TROJAN!"
X Regcxdinaf REGCXDINAF.EXE"Added by the BANCOS-BW TROJAN!"
X Regcxmarq REGCXMARQ.EXE"Added by the BANCOS.DK TROJAN! Note that the filename has a leading space
X Regcxn Regcxn.exe"Added by the COIBOA-D TROJAN!"
U regdefend regdefend.exe"""RegDefend is a configurable
X regdiit winxp.exe"Added by the RUNAUTO.F WORM!"
X regdiit win.exe"Added by the VBSAUTO-A WORM!"
X RegDone services.exe"Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process
X RegDone winlogon.exe"Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process
X RegDone Ex csrss.exe"Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
X RegDoneEx lsass.exe"Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
X regedit regedit.exe"Added by the BRID.A WORM! Note - this is not the valid Windows registry editor which resides in %Windir$ and will not figure in Msconfig/Startup! This version resides in %System%"
X REGEDIT Regsrv32.com"Added by the SOUTHGHOST WORM!"
X regedit autoexe.exe"Added by a variant of the RBOT WORM!"
X regedit svchost.exe ccRegVfy"Added by the HOTWORD.B TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is also located in %System% but has a space at the beginning of the filename"
X regedit regedit.exe"Added by the GANBATE.A WORM! Note that the legitimate Windows registry editor (regedit.exe) is located %Windir% and will not figure in Msconfig/Startup! This one is located in %Windir%\security\Database"
X Regedit regedits.exe"Added by the BANCBAN-QV TROJAN!"
X RegEdit32 RegEdit32.exe"Added by the VOUMIT-A WORM! Note - this is not the legitimate regedit32.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
X Regedit32 regedit.exeAdded by an unidentified WORM or TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%
X Regexit runlli32.exe"Added by the QQPASS-U TROJAN!"
X Regexit Updadv.exe"Added by the QQPASS-N TROJAN!"
X RegFreeze regfreeze.exe"RegFreeze rogue spyware remover - not recommended
X reggsdg spoolserv.exe"Added by the SDBOT-MS WORM!"
X reggsdg spoolsrv.exe"Added by the SDBOT-DI WORM!"
U RegHelp svchosts.exe"SpyGraphica spy software - ""Stealth monitoring of ALL PC or Network Activity with DVD-like playback. EVERY keystroke can be e-mailed in a detailed activity report every 15 minutes...anywhere in the world."""
X reghost reghost.exe"SpyPal surveillance software. Uninstall this software unless you put it there yourself"
? reginfo32 reginfo32.exe"??"
X Register Manager RegistryManage.exe"Added by the SDBOT.AYH WORM!"
N Register MediaRing Talk register.exeIf you don't want to register MediaRing and be reminded about it every bootup disable it
? Register SeqChk regsvr32.exe ..csseqchk.dll"??"
U RegisterDropHandler REGIST~1.EXE"Part of the OCR software TextBridge Pro 9.0 (and possibly earlier versions). Typically used with imaging devices such as scanners and digital cameras for creating text documents from images. This item will probably be displayed twice and will re-instate itself whenever you start the main program so leave it - once started it frees the memory it used. Its purpose and an explanation of how to correct a problem it creates for ""Send To"" can be found here. Note that you don't have to uninstall TextBridge for this fix to work and the program works fine afterwards. Not used on later versions of the software - hence the 'U' recommendation"
X Registration Service toker.exe"Added by the SDBOT-BB WORM!"
X Registration Service msvdm6.exe"Added by the SDBOT-HE TROJAN!"
N Registration-Studio 8 RegTool.exe"Registration for Pinnacle Studio Version 8 home video software from Pinnacle Systems"
X Registry wscript.exe ShakiraPics.jpg.vbs"Added by the VBSWG.AQ WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""ShakiraPics.jpg.vbs"" file is located in %Windir%"
U Registry class0117[random].exe"Blackbox captures emails and chat logs
X Registry Checker Regrun.exe"Added by the SDBOT TROJAN!"
X Registry Checkup winreg.exeAdded by an unidentified WORM or TROJAN!
X Registry Checkup System326a Monitor Winregs326a.exe"Added by a variant of the SDBOT WORM!"
X Registry Cleaner Regclean.exe"Registry Cleaner misleading security software - not recommended
X Registry Integrity Checker regintmon.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
X Registry Integritycheck WCPDT.EXE"Added by the AGOBOT-RF WORM!"
X Registry Loader regloadr.exe"Added by the GAOBOT.AO WORM!"
X Registry Loader winhlpp32.exe"Added by the GAOBOT.AO WORM!"
U Registry Mechanic RegMech.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
U Registry Mechanic Vista Tray RMTray.exe"Part of Registry Mechanic from PC Tools - which ""is an advanced registry cleaner for Windows that can safely clean
X Registry Monitor regmon.exe"Added by the BCKDR-QKH BACKDOOR!"
X Registry oidet win32.exe"Added by the RBOT.BMT WORM!"
X Registry Protector regprotect.exe"Added by the ARIVER.A WORM!"
X Registry Scanner regscanr.exe"Added by a variant of the OPTIX TROJAN!"
X Registry Serv regsvr.exe"Added by the WEBMONEY-G TROJAN!"
X Registry Server regsrv32.exe"Added by the RBOT-GM WORM!"
X Registry Server regserv.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Registry Service REGSRV32.EXE"Added by a variant of the RBOT WORM!"
X Registry Service resvs.exe"Added by the DELBOT-I WORM!"
X Registry Service regsvc.exe"Added by the IRCBOT-ZM BACKDOOR!"
X Registry Services Registry.exe"Added by the CILE TROJAN!"
X Registry Startup Check checkreg.exe"Added by the REMLOAD-A or DANMEC-B TROJANS!"
X Registry System Regsys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
X Registry System16 Checkup Monitor SystemReg16.exe"Added by a variant of the RBOT WORM!"
X Registry System166 Checkup Monitor SystemReg166.exe"Added by a variant of the RBOT WORM!"
X Registry Value Name roses.exe"Added by the RBOT-AFT WORM!"
X Registry Value Name service.exe"Added by the RBOT-AHT WORM!"
X Registry Value Name winapi32.exe"Added by a variant of the RBOT WORM!"

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list