Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
NT"Ms Java for Windows 98 ME & XP"X
NT"Ms Java for Windows 98 XP & ME"X
U0190 WarnerWARN0190.EXE"Anti-dialer program (Germany)"
U0900 WarnerWARN0900.EXE"Anti-dialer program (Germany)"
X1029BB4B-16A9-4E77-AA3D-96930BD68EECsysockeu.exe"Added by the FAKEALERT-AH TROJAN!"
X1234klsjdc uiar924c afsxgnsvuxct.exe"Added by the FAKEALERT-AM TROJAN!"
X1234klsjdc uiar924c afsysvtypkbjx.exe"Added by the FAKEALERT-AM TROJAN!"
?17779Proj2002N/A"??"
X1916435341.exe1916435341.exe"Added by the DLOADR-AXU TROJAN!"
X196_150_ni196_150_ni.exe"WinFixer web installer - ""foistware""
X197_150_ni_3197_150_ni_3.exe"WinFixer web installer - ""foistware""
X197_150_ni_7197_150_ni_7.exe"WinFixer web installer - ""foistware""
X2177F056-0AA6-4D6C-A944-13F71F341C29sysokuaw.exe"Added by the FAKEALERT-AH TROJAN!"
?39ELTFH25Z8SKFEzg1q5.exe"Seems to be associated with software by Resplendence SP ?"
X49U5T1N449U5T1N4.exe"Added by the KORRON.B WORM!"
X4da92ad5.exe4da92ad5.exe"Added by the DLOADR-WZ TROJAN!"
X5-1-61-96members-area.exeAdult content dialler
X756349DC-6D9E-4F2A-9B24-269661F073C3sysoghcx.exe"Added by the FAKEALERT-AH TROJAN!"
X7f8ez****.exe 9idf"Detected by NOD32 as the SMALL.ALI TROJAN! Note - it creates a number of extra z****.dll files in the %System% folder"
X7X29C2X78Ysyss_.exe"Added by the AGENT-GMS TROJAN!"
X852EBF20-A95D-4F1F-B9C2-B2CD24350F3Esysodkcs.exe"Added by the FAKEALERT-AH TROJAN!"
X98D0CE0C16B1"rundll32.exe D0CE0C16B1 D0CE0C16B1"
X9mwinlog0n.exe"Added by the LEGMIR-AQK TROJAN!"
X9UmxQPSiTJMbANVUKZ.exe"Added by the AGENT-LMN TROJAN!"
Y9xadiras9xadiras.exe"Allied Telesyn AT series router/modem related - apparently required"
X9xHtProtectAVprotect9x.exe"Added by the NETSKY.M WORM!"
XA70F6A1D-0195-42a2-934C-D8AC0F7C08EB"rundll32.exe E6F1873B.DLL D9EBC318C"
Xa9z1eizA1eatulabov.exe"Added by the AGENT-GWD TROJAN!"
XAc97Soundsnddrv.exe"Added by the VB.AXG TROJAN!"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAIM95 Startupaim95.exe"Added by the AGOBOT.AEE WORM!"
Xaimaol ml097eaimaol.exe"RapidBlaster variant (in a ""Aimaol"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xakgkagaksad9fsakfask9.exe"Added by the ONLINEG-M TROJAN!"
UALi5289ALi5289.exe"Related to Uli Integrated Drivers from Uli Electronics Inc"
XAmie Release V6.9Dservices.exe"Added by the VB-EAN TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XAnti-Virus Update Scheduler V1.39.12R[path to trojan]"Added by the HEPLANE or STAPREW.B TROJANS! - different filenames have been spotted; examples: msvc.exe
XAntiSpywareXP 2009AntiSpywareXP2009.exe"AntiSpywareXP 2009 rogue spyware remover - not recommended
XAntiSpyZone 4.9AntiSpyZone 4.9.exe"AntiSpyZone rogue spyware remover - not recommended"
XAntivirus 2009av2009.exe"AntiVirus'09 rogue security software - not recommended
XAntivirus 2009 plusAntivirus 2009 plus.exe"AntiVirus Plus rogue security software - not recommended
XAntivirus PC 2009avpc2009.exe"Antivirus PC 2009 rogue security software - not recommended
XAntivirus Pro 2009AntivirusPro2009.exe"AntiVirus Plus rogue security software - not recommended
XAntiVirusLab2009AntiVirusLab2009.exe"Antivirus Lab 2009 rogue security software - not recommended
XAOL 9.0 OptimizedAOLClient.exe"Added by the SPYBOTER.A TROJAN!"
XAOL Instant Messenger 7.213aim9283.exe"Added by the SDBOT-ZF WORM!"
?Apmsrv9xAPMSRV9X.EXE"Intel AnyPoint Wireless II Home Network related. Now discontinued. What does it do and is it required?"
UATISmartati2s9ag.exe"ATI's ""SMARTGART""
UAuto EPSON PictureMate Deluxe on XE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UAuto EPSON Stylus C48 Series on XE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3500 Series on XE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX3600 Series on XE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4500 Series on XE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UAuto EPSON Stylus CX4600 Series on XE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX6600 Series on XE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UAuto EPSON Stylus CX9400Fax Series on XE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R1800 on XE_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R2400 on XE_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UAuto EPSON Stylus Photo R320 Series on XE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo R800 on XE_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UAuto EPSON Stylus Photo RX420 Series on XE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UAuto EPSON Stylus Photo RX700 Series on XE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
Xavagent3974chnb8895.exe"AntiVirus ransomware security software - not recommended
UAVG9_TRAYavgtray.exe"System Tray access to and notifications for the 9.* series of internet security products from AVG Technologies - including Internet Security
YAvgserv9.exeAvgserv9.exe"Background monitoring and scanning for the 6.* (and maybe earlier) series of anti-virus products from AVG Technologies when running on 9x/Me. Loaded from the ""RunServices"" registry key"
Xavguard3876000b09274b.exe"AntiVirus ransomware security software - not recommended
YavinitAVINIT9X.EXE"Command Antivirus related"
YAVSchedScanSCHSC9X.EXE"Command Antivirus related"
Ub9B9.exe"FireTrust Benign - allows you to receive e-mail which is safe from viruses
Xb99msmm.exe"ClientMan parasite variant"
XBackUp Windows 2009[random].exe"Added by the AGENT-LUJ TROJAN!"
UBCMHal"rundll32.exe bcmhal9x.dll bcinit"
UBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMBgMonitor.exe"Associated with Nero Scout
YBitDefender 2009IEShow.exe"Anti-phishing component of BitDefender internet security products. Anti-phishing prevents sensitive data such as usernames
YBitDefender 2009bdagent.exe"BitDefender Agent - for BitDefender internet security products. Maintains settings (for all users) and provides alerts and System Tray access to the main program. Note - for the System Tray icon to be displayed the Terminal Services service must be set to either ""Manual"" or ""Automatic"". It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poor"
NCard MonitorREGCNT09.exeFor the USB connection on a Panasonic PV-DV701 Digital Camcorder. Available via Start -> Programs
UCD-DVD Lock for Win95/98/Me/2k/XPCDVAgent.exe"Loads CD-DVD Lock from Ixis Research
UCHotKeyMK9805.EXE"Enables special keys on Chicony keyboards. Special combinations include Internet
XCleaner2009 FreewareUCLN.exe"Cleaner2009 rogue privacy program - not recommended
?Client agent for ARCserveW95AGENT.EXE"Part of Brightstor ARCserve Backup from Computer Associates. What does it do and is it required?"
XCn911ODBCJET.exe"Added by the BIFROSE-PR TROJAN!"
UCobian Backup 9Cobian.exe"Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program as a startup application rather than the default service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup option and run it manually when required"
UCobian Backup 9 interfacecbInterface.exe"System Tray access to Cobian Backup 9 - a multi-threaded backup program which makes backup copies of your file and folders (in compressed or uncompressed form) to another location. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). If you don't have regularly scheduled backups then choose the startup installation option and run it manually when required"
NColorificHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NColorific Control PanelHgcctl95.exe"Colorific® from E-Color - ""delivers accurate gamma and color temperature across your entire system - monitor to printer and digital camera to monitor."" Now superseded by ColorWizzard™"
NCommonSDKRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
NCompaq ConnectionsBackWeb-1940576.exe"See here - ""messaging service that automatically sends you support information
XComputer Defender 2009cd2009.exe"Computer Defender 2009 rogue security software - not recommended
XConfiguration Loaderaim95.exe"Added by the LOADCFG or SDBOT TROJANS!"
XCoreguard Antivirus 2009Coreguard 2009.exe"Coreguard Antivirus 2009 rogue security software - not recommended
?CPA9P2PSERVERCPA9P2PS.exe"Found on a Compaq Presario but what is it?"
XCSV7P91CSV7P91.exe"ClearSearch adware"
Xd9fw5i91pd9fw5i91p.exe"Added by the AGENT-GIW BACKDOOR!"
XData789Regedit.exe ....data789.tmpHomepage hijacker
?DAW9532.exeDAW9532.EXE"Loaded during installation of some 3Com network cards. Enables their DynamicAccess desktop management software. Is it required?"
UDBISQL9dbisqlg.exe"Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies"
UDell AIO Printer A920dlbkbmgr.exeSystem Tray application for the Dell Photo AIO Printer 920 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A940dlbabmgr.exeSystem Tray application for the Dell Photo AIO Printer 940 that enables scan or fax functions to run directly from the printer via the buttons
UDell AIO Printer A960dlbfbmgr.exeSystem Tray application for the Dell Photo AIO Printer 960 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 922dlbtbmgr.exeSystem Tray application for the Dell Photo AIO Printer 922 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 942dlbubmgr.exeSystem Tray application for the Dell Photo AIO Printer 942 that enables scan or fax functions to run directly from the printer via the buttons
UDell Photo AIO Printer 962dlbxmon.exeDellPhoto AIO Printer 962 Device Monitor
XDirectX9direct3d.exe"Added by the AGENT.EAK TROJAN!"
XDirectX9svchost32.exe"Added by the RBOT.AQG WORM!"
XDirectX9 Diagdx9diag.exe"Added by the RBOT-ALT WORM!"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDNSmc-58-12-0000093.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XDNSmc-110-12-0000079.exe"Shorty adware - also detected as the AGENT.FD TROJAN!"
XdrmuW95Mm.exeHomepage hijacker installing a toolbar: http://tdko.com/. Lop.com in disguise
UDVD Device Lock for Win95/98/Me/2k/XPDDLAgent.exe"Loads Hide and Protect any Drives - which ""can be used to restrict read or write access to removable media devices such as CD
Xdvd98windvd98.exe"Added by the CULT.P WORM!"
YDvp95Dvp95.exe"Scan engine for F-Secure and Command antivirus software based on the F-Prot AntiVirus engine"
Ydvpapi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
NDXM6Patch_981116p_981116.exe"Win32 cabinet self extractor. More info here"
Xefaxs ml097eefaxs.exe"RapidBlaster variant (in a ""efaxs"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UEnterprise Harmony '99rsMenu.exe"Enterprise Harmony 99 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UEPSON PictureMate DeluxeE_FATI9TA.EXE"Epson Status Monitor 3 for the PictureMate Deluxe compact photo printer - for monitoring printer status
UEPSON Stylus C48 SeriesE_S4I091.EXE"Epson Status Monitor 3 for the Stylus C48 Series printer - for monitoring printer status
UEPSON Stylus CX2900 SeriesE_FATIBFP.EXE"Epson Status Monitor 3 for the Stylus CX2900 Series printer - for monitoring printer status
UEPSON Stylus CX3500 SeriesE_FATI9 BL.EXE"Epson Status Monitor 3 for the Stylus CX3500 Series printer - for monitoring printer status
UEPSON Stylus CX3600 SeriesE_FATI9BE.EXE"Epson Status Monitor 3 for the Stylus CX3600 Series printer - for monitoring printer status
UEPSON Stylus CX3900 SeriesE_FATIBEP.EXE"Epson Status Monitor 3 for the Stylus CX3900 Series printer - for monitoring printer status
UEPSON Stylus CX4500 SeriesE_FATI9AP.EXE"Epson Status Monitor 3 for the Stylus CX4500 Series printer - for monitoring printer status
UEPSON Stylus CX4600 SeriesE_FATI9AA.EXE"Epson Status Monitor 3 for the Stylus CX4600 Series printer - for monitoring printer status
UEPSON Stylus CX6500 SeriesE_FATI9EP.EXE"Epson Status Monitor 3 for the Stylus CX6500 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EE.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX6600 SeriesE_FATI9EA.EXE"Epson Status Monitor 3 for the Stylus CX6600 Series printer - for monitoring printer status
UEPSON Stylus CX9300F SeriesE_FATICFP.EXE"Epson Status Monitor 3 for the Stylus CX9300F Series printer - for monitoring printer status
UEPSON Stylus CX9400Fax SeriesE_FATICFA.EXE"Epson Status Monitor 3 for the Stylus CX9400Fax Series printer - for monitoring printer status
UEPSON Stylus Photo 925E_S10IC2.EXE"Epson Status Monitor 3 for the Stylus Photo 925 printer - for monitoring printer status
UEPSON Stylus Photo R1800E_FATI9LA.EXE"Epson Status Monitor 3 for the Stylus Photo R1800 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SA.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R2400E_FATI9SE.EXE"Epson Status Monitor 3 for the Stylus Photo R2400 printer - for monitoring printer status
UEPSON Stylus Photo R320 SeriesE_FATI9FA.EXE"Epson Status Monitor 3 for the Stylus Photo R320 Series printer - for monitoring printer status
UEPSON Stylus Photo R800E_FATI9YE.EXE"Epson Status Monitor 3 for the Stylus Photo R800 printer - for monitoring printer status
UEPSON Stylus Photo RX420 SeriesE_FATI9CE.EXE"Epson Status Monitor 3 for the Stylus Photo RX420 Series printer - for monitoring printer status
UEPSON Stylus Photo RX430 SeriesE_FATI9CP.EXE"Epson Status Monitor 3 for the Stylus Photo RX430 Series printer - for monitoring printer status
UEPSON Stylus Photo RX700 SeriesE_FATI9IA.EXE"Epson Status Monitor 3 for the Stylus Photo RX700 Series printer - for monitoring printer status
?ERTS0749ERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
YeScan MonitorAVKWCTL9X.EXE"MicroWorld eScan antivirus"
Xexe ml097eexe.exe"RapidBlaster variant (in a ""Exe"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
UExshow95EXSHOW95.exeSupport software for some of the Kensington mice. Provides access to extra features like those available with enhanced Logitech and MS devices
UF5D9010Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9010 Wireless G+ MIMO USB Network Adapter"
UF5D9050Belkinwcui.exe"Wireless configuration utility for the Belkin F5D9050 Wireless G+ MIMO USB Network Adapter"
Xf73cdc8ee94ebtsendto.exeAssociated with mysearchnow.com/searchbar.html
Xf94mggfhfghodftdf[path to trojan]"Added by the SMALL.JHZ TROJAN!"
XFast Antivirus 2009FastAV.exe"Fast Antivirus rogue security software - not recommended
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoxwudy9912service.exe"Added by the BANCOS-BT TROJAN!"
XFS6519FS6519.dll.vbs"Added by the SOLOW.B WORM!"
Xgah95on6gah95on6.exe"ShopAtHome/SAHagent adware"
Xgeneral ml097egeneral.exe"RapidBlaster variant (in a ""General"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XGetModule19GetModule19.exe"Internet Speed Monitor adware related - see example here"
XGetModule29GetModule29.exe"Internet Speed Monitor adware related - see example here"
XGetPack19GetPack19.exe"Internet Speed Monitor adware related - see example here"
XGT15J4R49Vcpuserv.exeIdentified as a variant of the Trojan.Win32.Radi.gu malware
XGuard ProVH339.exe"Guard Pro rogue security software - not recommended
Ygw port controllerPORTCT95.EXE"From a visitor - "I must keep it active in start up or my Lexmark printer and RCA Cam program cannot discover a working port to work". From the file properties
UHandy Backup 3.9hbagent.exe"Handy Backup - automatic backup of your critical data to virtually any type of storage media including CD-RW devices and remote FTP servers"
UHarmony 98 - CasioOrgCasAgnt.exe"Enterprise Harmony 98 for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
UHawkEyeHAWK_95.EXE"Control Panel application for the old Number Nine graphics cards to change resolution
Xhdlfoe df98ndfsvchots.exe"Added by a variant of the RBOT WORM!"
XHhjg5jfd93dftdfwinlogan.exe"Added by the ERTFOR.A TROJAN!"
UHide and Protect any Drives for Win95/98/Me/2k/XPHPDAgent.exe"Loads Hide and Protect any Drives - which allows you to ""Protect Hard drive
XHomeAntivirus 2009HomeAntivirus2009.exe"HomeAntivirus 2009 rogue security software - not recommended
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
Xhostservwiz98.exe"Added by a variant of the SDBOT WORM!"
UHot Key Kbd 2690 DaemonSK2690DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
UHot Key Kbd 9910 DaemonSK9910DM.exeMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
NHPAiODevice(hp psc 900 series) -1hpobrt07.exe"Installed with a Hewlett Packard 900 series colour printer
UHPDJ Taskbar Utilityhpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
Uhpztsb09hpztsb09.exeHP System Tray utility which allows diagnostic and maintainance of your HP Deskjet series printer
UHydarVisionDesktopManagerdesk95.exe"ATI's HydraVision desktop management software
UHydraVisionDesktopManagerdesk98.exeATI/Appian HydraVision Desktop Manager software - monitors and regulates window and dialog box placement according to user preferences when using a multi monitor setup
NIBM ThinkPad Tray UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
?IBM Warranty NotificationERTS0749.exe"IBM Warranty Notification - presumably it's a reminder to either register or that warranty is about to expire?"
NIcon Hearit 95hearit95.exeAudio desktop customization utility from Moon Valley Software. Resource hog
NIcon Hearit 98hearit98.exeAudio desktop customization utility from Moon Valley Software. Resource hog
XIcon ml097eicon.exe"RapidBlaster variant (in a ""Icon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YIKE Service 95IKEService.exe"Associated with PGP. The PGP Tray can be disabled
UIndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}NMIndexStoreSvr.exe"Indexing service that catalogs all the media on your computer so that the files are available to all of the programs in the Nero suite of applications"
YInoRTInoRT9x.exe"Associated with the Realtime Monitor of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates. For NT/2K/XP users you may need a patch if seeing high CPU useage"
Xinternet servicesvho0st98.exe"Added by the RBOT.EAT WORM!"
XIntruderAlertia99.exe"Intruder Alert '99 from Bonzi - spyware"
NIomega Backup Schedulerdtiom98.exe"Used by Iomega drives. Details of its purpose can be found here. Available via Start -> Programs"
UIomon98.exeIomon98.exePC-Cillin 98 real time virus check. Can cause floppy disk accesses to hang
XIpod Help[9 random letters].exe"Added by a variant of the RBOT WORM!"
XJava (VM) v6.9jav.bat"Added by the AGENT-GZK TROJAN!"
XJava VM v6.9.2jav.bat"Added by the DWNLDR-HLM TROJAN!"
XJava VM v6.91jav.bat"Added by the DWNLDR-HLL TROJAN!"
Xjkdfj94kgdftdfwinlogan.exe"Added by the ZLOB.BZ TROJAN!"
XJnskdfmf9eldfdcsrssc.exe"Added by the AGENT.EBC TROJAN!"
XKAVPersonal90wscntfy.exe"Added by the BANKER-FZ TROJAN!"
XKazaa ml097ekazaa.exe"RapidBlaster variant (in a ""kazaa"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid KaZaA file sharing program which has the same executable name"
XKAZAACuf9"Added by the KITRO.D (or ARGEN.A) WORM!"
YKB891711KB891711.exe"Installed by the Windows KB891711 critical update
YKB918547KB918547.EXE"Bug-fix for a Microsoft graphics rendering engine vulnerability - see here. Windows 98/Me only"
YKB926239"rundll32.exe apphelp.dll ShimFlushCache"
UKE9801DriBat32.exeKE9801 multimedia keyboard driver - required if you use the multimedia keys
UKM9801UMMHotKey.exeMultimedia key handling for the relevant type of Turbo-Media keyboard. Shortcut available. Note that with this running it can crash DirectX8/9 under WinXP when a game switches to full-screen
UKX509kx509_kfwk5.exe"Kerberos Secure Authentication for Windows"
XlaltinL90112201.Stub.exe"Delfin Media Viewer adware related"
ULaunch K9K9.exe"K9 by Robert Keir - ""an email filtering application that works in conjunction with your regular POP3 email program and automatically classifies incoming emails as spam (junk email) or non-spam without the need for maintaining dozens of rules or constant updates to be downloaded. It uses intelligent statistical analysis that can result in extremely high accuracy over time"""
ULexmark 9300 Series Fax Serverfm3032.exe"FaxMan integrates complete fax send and receive support into Windows applications without requiring additional fax software"
XLexmark_X79-55lsasss.exe"Added by the ZONEBAC TROJAN!"
Xli01f948"rundll32.exe li01f948.dllEnableRunDLL32"
YLoadDvpApi9xDVPAPI9X.exeCommand AntiVirus for Windows 95/98/Me
ULogWatchlogwat95.exeLicensing patch for products installed on NT by Computer Associates such as eTrust. Detects and updates old versions of lic98.dll. Not required if you already have a newer version or the patch has been applied
XMalware Catcher 2009MCatcher.exe"Malware Catcher 2009 rogue security software - not recommended
XMalware Destructor 2009MD345d.exe"Malware Destructor 2009 rogue security software - not recommended
XMalwareBurn 6.9MalwareBurn 6.9.exe"MalwareBurn rogue security software - not recommended
XMalwareWiped 6.9MalwareWiped 6.9.exe"MalwareWipe rogue security software variant - not recommended
NMatrox Color Controlhgcctl95.exeFor Matrox video cards. Quick access to changing colors
YMcShld9xmcshld9x.exe"Window 9x/Me on-access scanner for older McAfee's internet security products such as VirusScan and VirusScan Online which scans files in real-time for malware as you access
XMessenger91messengersystem.exe"Added by the RBOT-FPF WORM!"
XMicrofinder ml097emcf.exe"RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMicrosoft HDCP for NT and Win9xmsdhcprs.exe"Added by a variant of the PEERBOT WORM!"
XMicrosoft Media player 9msmedia32.exe"Added by the RBOT-ADO WORM!"
NMicrosoft OfficeOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMicrosoft Office StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XMicrosoft Synchronization Managerwin932.exe"Added by the SDBOT.AH WORM!"
NMicrosoft Utility StartupOSA9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
NMouse Suite 98 Daemonpelmiced.exeMouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
UMouse Suite 98 DaemonICO.EXE"Found on some Sony Vaio
XMS AntiSpyware 2009msas2009.exe"MS AntiSpyware 2009 rogue spyware remover - not recommended
XMS Security Update 993msident.exe"Added by a variant of the SDBOT WORM!"
XMsconfig ml097emsconfig.exe"RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
XMslogon ml097emslogon.exe"RapidBlaster variant (in a ""Mslogon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XMSN 9.0 Plus[random letters].exe"Added by the RBOT-ALY WORM!"
XMSN MESSENGER 9.0messengerr.exe"Added by a variant of the RBOT WORM!"
XMspatch69[path to trojan]"Added by the MPROX TROJAN!"
XMspatch89cnqmax.exe"Added by the RANDEX.P WORM!"
Xmssurfer ml097emssurfer.exe"RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xmsword98msword98.exe"Added by the AGENT-KUO TROJAN!"
XMSxmlHpr"RUNDLL32.EXE [path] msxm192z.dllw"
Xnana2009nana2009.exe"Added by the POISON.PG BACKDOOR!"
XNBInstallMBDownloader_876919.exe"Added by the MIRAR_D TROJAN!"
XNero Updater.6.12wmp9.exe"Added by the AGOBOT-AAG WORM!"
XNewsgroup ml097enewsgroup.exe"RapidBlaster variant (in a ""newsgroup"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UNFM ServiceNPDOR9x.exe"Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
XNI.ERS_9999_N91S3108[path to file]"Installer for the ErrorSafe rogue system error and cleaning utility - see here"
XNI.GA6PU_0001_N120C2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.GDCDE_0001_N122C1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.GDC_0001_N111C1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.GDC_0001_N122C1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGA6PH_0001_N122M2910[path to file]"Installer for the AntiVirusAskeladd rogue security software - see here"
XNI.UGA6PT_0001_N122M2910[path to file]"Installer for the VirusDifesa Italian rogue security software - see here"
XNI.UGA6PU_0001_N120M2910[path to file]"Installer for the VirusSchlacht German rogue security software - see here"
XNI.UGA6PV_0001_N122M2910[path to file]"Installer for the VirusGarde French rogue security software - see here"
XNI.UGA6P_0001_N119M1510[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGA6P_5001_N122M1902[path to file]"Installer for the AVSystemCare rogue security software - see here"
XNI.UGDC1_0001_N119M0911[path to file]"Installer for the FilterProgram rogue privacy tool - see here"
XNI.UGDCDE_0001_N122M1912[path to file]"Installer for the FestplattenReiniger German rogue privacy tool - see here"
XNI.UGDCNL_0001_N122M1912[path to file]"Installer for the NoCompromaat Dutch rogue privacy tool - see here"
XNI.UGDC_0001_N111M1909[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGDC_0001_N122M1912[path to file]"Installer for the PCPrivacyTool rogue privacy tool - see here"
XNI.UGESL_0001_N122M2911[path to file]"Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
XNI.UWA6P_0001_N69M0303WinAntiVirusPro2006Installer[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA6P_0001_N91M1807WinAntiVirusPro2006FreeInstall[1].exe"Installer for the WinAntiVirus Pro 2006 rogue security software"
XNI.UWA7P_0001_N91M0809WinAntiVirusPro2007FreeInstall.exe"Installer for the WinAntiVirus Pro 2007 rogue security software - see here"
XNod29 Servicenodwr.exe"Added by a variant of the RBOT WORM!"
NNorton Ghost 9.0GhostTray.exe"Norton Ghost tray icon - the application can be launched manually"
XNotepad ml097enotepad.exe"RapidBlaster variant (in a ""Notepad"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not Windows Notepad which has the same executable name"
Xnvd32 ml097envd32.exe"RapidBlaster variant (in a ""nvd32"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NOffice StartupOsa9.exeOn older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
XOffice SturtUposa9.exe"Added by the CLICKER-EC TROJAN! Note - this trojan is located in %Windir% and should not be confused with the Microsoft office program
YOfficeScan95pccwin97.exe"Trend Micro antivirus OfficeScan"
XP Antispyware 09pas.exe"P Antispyware 09 rogue security software - not recommended
YPavkre9xpavkre9x.exe"Part of the 2005 & 2006 versions of Panda Antivirus and Internet Security"
YPavProcPavPrS9x.exe"Part of Panda Antivirus and Internet Security"
YPavprot9Pavprot9.exe"Part of the 2005 versions of Panda Antivirus and Internet Security"
XPC Security 2009PC_Security2009.exe"PC Security 2009 rogue security software - not recommended
UPeerGuardianPeerGuardian_1.99b_pr14.exe"PeerGuardian - IP blocker for Windows. Used to protect privacy on P2P networks by blocking IP addresses specified in blocklists. Features support for multiple lists
XPerfect Defender 2009pdfndr.exe"Perfect Defender 2009 rogue security software - not recommended
XPersonal Defender 2009pdefendr.exe"Personal Defender 2009 rogue security software - not recommended
XPersonal Firewall V9Firewall-UpdateV9.exe"Added by the RBOT-BJR WORM!"
XPower-Antivirus-2009Power-Antivirus-2009.exe"Power Antivirus 2009 rogue security software - not recommended
NPPort9reminderEreg.exe ereg.ini"Registration reminder for PaperPort version 9 from Scansoft (now Nuance)"
NPrintscreen 95PRT95MIN.EXE"Printscreen 95 - utility to capture
XPro Antispyware 2009proas2009.exe"Pro AntiSpyware 2009 rogue spyware remover - not recommended
XProc992[path to file]"Added by the IXBOT-C WORM!"
XProc993wqxfne.exe"Added by the IXBOT-D WORM!"
XProof Defender 2009pdfndr.exe"Proof Defender 2009 rogue security software - not recommended
NPUSH6599PUSH6599.EXEScan button monitor for Relysis Episode MF6599 USB scanner as you can start scanning manually via the scanning software
UPV92TRAYPV92Tray.exe"PCtel HSP V.92 modem configuration utility"
Np_981116p_981116.exe"Win32 cabinet self extractor. More info here"
XQdrModule9QdrModule9.exe"Internet Speed Monitor H adware"
XQdrPack9QdrPack9.exe"Internet Speed Monitor adware"
XQuickInstallPackCLN_2009FreeInstall.exe"Installed and used by rogue security products such as Cleaner2009
URandsoft Harmony '98rsMenu.exe"Randsoft Harmony '98 (superseded by Enterprise Harmony 99) for CASIO - synchronization software for use with Microsoft® Outlook 97/98/2000"
Xrb32 ml097erb32.exe"RapidBlaster variant (in a ""RapidBlaster"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XReactor9[random name]32.exe"Added by the BOFRA.E WORM!"
Xrealplay ml097erealplay.exe"RapidBlaster variant (in a ""RealPlay"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not RealPlayer which can have the same executable name"
URealtek AC97 Audio - Event MonitorALCMTR.EXE"Realtek Azalia Audio - Event Monitor
XRecommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B}RH.DLL"SmartPops search hijacker"
XREGRUNwinfix22490.exe"Adware downloader - also detected as a variant of the LOWZONES.BW or AGENT.RD TROJANS!"
NRoxWatchTrayRoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
NRoxWatchTray9RoxWatchTray9.exe"System Tray access to managing the ""Watched Folders""
Yrtvscn95RTVSCN95.EXEReal-time virus scanner component of Norton Anti-Virus Corporate Edition
Xrun=cyxid98.exeUnidentified malware
URunmarc8mManagermarc8m95.exe"MARC Sound System Manager for the Marc 8 MIDI sound card - allows for easy adjustment of the settings"
NRxMonrxmon9x.exe"Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell
Xryan1918servidevice.exe"Added by the RBOT-GVR WORM!"
Xs9201av2008xp.exe"Antivirus 2008 XP rogue security software - not recommended
Xs9201as2008xp.exe"AntiSpyware XP 2008 rogue spyware remover - not recommended
Xs9201asproxp.exe"AntiSpyware Pro XP rogue spyware remover - not recommended
XSafeguard 2009sf2009.exe"Safeguard 2009 rogue spyware remover - not recommended
USamsung MJC-900 Series Monitor"RUNDLL32.EXE SMMASHLL.DLLAutoUpdatePnPValue"
XSBR2009FSystemBooster2009.exe"SystemBooster2009 rogue system suite - not recommended
Xscains030109.Stub.exe"Delfin Media Viewer adware related"
XSecurity 2009Security2009.exe"Security 2009 rogue security suite - not recommended
YSECWIZ98SECWIZ98.EXE"Security Wizard 98 by Chris Farmer. Offers you a variety of ways to restrict access to many of the programs and settings on your PC. Available here"
Xservices32mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
NShortKeys 99SHORTKEY.EXE"ShortKeys from Insight Software Solutions - allows you to program keys with text strings"
Xsi91e44b"rundll32.exe si91e44b.dll EnableRunDLL32"
USK9910DMSK9910DM.EXEMulti-function keyboard driver. Allows the use of programmable keys on mulimedia keyboards. Required if you use the additional keys
XSmart Antivirus-2009.exeSmart Antivirus-2009.exe"Smart Antivirus 2009 rogue security software - not recommended
USMS Client Serviceclisvc95.exe"When the SMS Client service starts on a domain controller
USMS Win9x Message AgentSMSMsg.exeThis program assigns a user to a Systems Management Server site
XSpool ml097espool.exe"RapidBlaster variant (in a ""spool"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpybott ml097espybott.exe"RapidBlaster variant (in a ""Spybott"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpyLocked 3.9SpyLocked 3.9.exe"Spylocked rogue spyware remover - not recommended
XSpywareguard ml097eSpywareguard.exe"RapidBlaster variant (in a ""Spyguard"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSpywareRemover2009SR.exe"SpywareRemover 2009 rogue spyware remover - not recommended
YStartQuick95.exeFor a Nisis G6 USB Graphics Tablet. Re-enables itself if disabled therefore best left alone
USunkistshwicon98.exe"Card reader for memory cards from digital cameras
XSurfer ml097esurfer.exe"RapidBlaster variant (in a ""mssurfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
YSweep95ICLOAD95.EXE"Part of Sophos ant-virus sofware"
USyGateServicesgserv95.exe"SyGate is a useful little program that lets you share an internet connection over an intranet. Is it needed - it saves a lot of headache to just let SyGate load at startup. Available via Start -> Programs"
Xsys009sys009.exe"Added by the STARTPA-ZB TROJAN!"
Xsys201sys209.exe"Added by the STARTPA-ZY TROJAN!"
XSys29win***32.exe [* = random char]"EliteBar adware"
XSysAntivirus 2009sysav.exe"SysAntivirus 2009 rogue security software - not recommended
Xsyscon ml097esyscon.exe"RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xsysftray2bolivar19.exe"Added by the KOOBFACE.I WORM!"
Xsysldtrayld09.exe"Added by the AGENT-KFI TROJAN!"
XSyslog ml097eSyslog.exe"RapidBlaster variant (in a ""Syslog"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XSystemsystem.exe (74295303)"Added by the VB-IU WORM!"
XSystem Loaderapsyst19b.exe"Added by the AGOBOT-AT BACKDOOR!"
XSystem service79[path to file]"Added by the ELITEBAR-V TROJAN!"
XSystemBooster2009sbr_updater.exe"SystemBooster2009 rogue system suite - not recommended
XSystemCONF98iSystemCONF98i.exe"Added by the GLITCH TROJAN!"
XT4skM4n4g3rWink3sk9.exe"Added by a variant of the IRCBOT TROJAN!"
Xtaskmngr ml097etaskmngr.exe"RapidBlaster variant (in a ""Taskmngr"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NThinkPad Configuration UtilityTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
Xtlcupdate911.jsHijacker installer
XTok-Cirrhatus-1464br3951on.exe"Added by the BRONTOK.AD WORM!"
XTok-Cirrhatus-1959br4941on.exe"Added by the BRONTOK-J WORM!"
XTok-Cirrhatus-1959[random].exe"Added by the BRONTOK-CF WORM!"
XTok-Cirrhatus-1959sarcsv711224030r.exe"Added by the BRONTOK-R WORM!"
XTok-Cirrhatus-1959sarcyesbron.com"Added by the BRONTOK-R WORM!"
XTok-Cirrhatus-2454br5931on.exe"Added by the BRONTOK.AD WORM!"
XTok-Cirrhatus-2784br6591on.exe"Added by the BRONTOK-L WORM!"
XTotal Protect 2009pcpc_starter.exe"Total Protect 2009 rogue security software - not recommended
XTotalSecure2009scan.exe"Total Secure 2009 rogue security software - not recommended
NTP98TRAYTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
NTP98UTILTP98.EXEIBM Thinkpad feature setup & configuration utility
NTPTRAYTP98TRAY.EXE"System Tray access to the ThinkPad Configuration utility for IBM/Lenovo ThinkPad notebooks. ""The ThinkPad Configuration utility is a control center to configure your ThinkPad hardware. With this utility
Xtrackerx90.th.gsanti_data_exe_by_trackerx90.exe"Added by the BCKDR-QIT BACKDOOR!"
UTraymin900Tray900.exeRelated to the Philips SPC webcam - System Tray manager for Personal 900 series camera
XUADC_104911963UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_3240389055UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_3769470239UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_599141581UADCcw.exe"AdvancedCleaner rogue security software - not recommended
XUADC_815790765UADCcw.exe"AdvancedCleaner rogue security software - not recommended
?UFD Monitor9382ufdlmon.exe"Part of USB Flashdisk software - what does it do and is it required?"
?UFD Utility9382UFDTool.exe"Part of USB Flashdisk software - what does it do and is it required?"
NUniblue RegistryBooster 2009RegistryBooster.exe"RegistryBooster registry optimizer utility from Uniblue Systems Limited - which will ""clean
YUrtSvcExeUrt95Svc.exe"""Cisco Secure URT is a virtual LAN (VLAN) assignment service that enhances LAN security by actively identifying and authenticating users and then associating them only to their specific network services and resources"""
Xuserinitchoo_003956f4"Added by the PEED.16896 TROJAN!"
UV.92 Modem On HoldLtmoh.exeModem On Hold utility - manages incoming/outgoing voice calls on a single phone line while being connected to the internet
UVC9PlayerVC9Play.exe"Virtual CD from H H Software GmbH. ""With Virtual CD
YVet Alertvetmsg9x.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software"
YVet Start Upvet98.exe"Computer Associates "InnoculateIT" and Vet Anti-Virus virus software. This option will slow down your system
XVirRL2009VirRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended"
XVirus Shield 2009VShield.exe"Virus Shield 2009 rogue security software - not recommended
XVirusHeal 3.9VirusHeal 3.9.exe"VirusHeal rogue security software - not recommended
XVirusHeat 3.9VirusHeat 3.9.exe"VirusHeat rogue security software - not recommended
XVirusProtect 3.9VirusProtect 3.9.exe"VirusProtect Pro rogue security software - not recommended
XVirusRemover2009VRM2009.exe"VirusRemover2009 rogue security software - not recommended
XVirusResponseLab2009VirusResponseLab2009.exe"VirusResponse Lab 2009 rogue security software - not recommended
XVirusRL2009VirusRL2009.exe"VirusResponse Lab 2009 rogue security software - not recommended"
Uw98Ejectw98Eject.exe"Related to USB support for Sigmatel MP3 audio palyer (and others such as SanDisk). It's intent is to ""put away"" the ""disk"" before you unplug it from the USB port
XWin Microsoft 98win14.exe"Added by the RBOT-AKX WORM!"
Xwin32Shakira_1997_Part_1_.Mpeg_.scr"Added by the MYLIFE.N WORM!"
Xwin32_i ml097ewin32_i.exe"RapidBlaster variant (in a ""win32_i"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWIN95DEFVIEW[path to file]"Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe""
Xwin98 DNSwingrd.exe"Added by a variant of the RBOT WORM!"
XWinConfig9324wincfgkop9.exe"Added by the RBOT.BVD WORM!"
XWinDefender2009windef.exe"WinDefender 2009 rogue security software - not recommended
XWindowsmsdos98.exeAdded by the PWSTEAL TROJAN!
XWindows DLL Loaderdefragfat39.exe"Added by the POEBOT-C WORM!"
XWindows Media Player 3.9wmpa36.exe"Added by a variant of the RBOT WORM!"
XWindows Network ControllerWin9x.exe"Added by the WOOTBOT.I WORM!"
XWindows Servcesc[9 random letters].exe"Added by a variant of the SDBOT WORM! See here"
XWINDOWS SYSTEM SCALPEscalpe91.exe"Added by the MYTOB-HI WORM!"
XWindowsupdatewupdmgr98.exe"Added by a variant of the IRCBOT BACKDOOR!"
YWinguardWGFE95.EXE"Dr Solomon's Virex antivirus"
NWinHacker"rundll32.exe wh95.dll HackMe"
XWinjava xmldirx9.exe"Added by the HAXDOOR ROOTKIT!"
Xwinwan ml097ewinwan.exe"RapidBlaster variant (in a ""Winwan"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XWinXP-98CSRSS.exe"Added by the BANKER-DS TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\WinXP-98\Tools"
Xwm41a398"rundll32.exe wm41a398.dll EnableRunDLL32"
UWorkstation Schedulerwm95.exe"Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled
NWpctrlwpctrl95.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
Nwpctrl95wpctrlnt.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
Nwpctrl95wpctrl95.exe"WinPortrait plug-in for PivotPro from Portrait Studios - allows a screen to be rotated to match rotated LCD screens
YWUOLServiceWUOLService9x.exe"Remote wakeup status agent. Part of Novell's ZenWorks. Processes Wake-up on LAN requests (turn on a computer remotely on LAN)"
UWZCBDLServiceWZCBDL9X.exeWZCBDLService Launcher from D-Link - configuration/drivers
Xxccinitrundll33.exe xccdf16_090131a.dll"Added by the BUZUS-AD TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090131a.dll"" file is located in %Windir%"
Xxccinitrundll33.exe xccdf16_090305a.dll"Added by the BUZUS-AF TROJAN! Note - the ""rundll33.exe"" file is located in %System%\inf and the ""xccdf16_090305a.dll"" file is located in %Windir%"
XXP Antispyware 2009XP_AntiSpyware.exe"XP AntiSpyware 2009 rogue spyware remover - not recommended
UXStop95XStop95.exe"XStop - internet filter"
Xy1959sarsv711224030r.exe"Added by the BRONTOK-AK WORM and variants!"
Xy1959saryesbron.com"Added by the BRONTOK-AK WORM and variants!"
Xyahoo_toolbar ml097eyahoo_toolbar.exe"RapidBlaster variant (in a ""yahoo_toolbar"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
X[12 random characters]atl91036.exe"IeDriver adware variant"
X[32 random numbers]av2009.exe"AntiVirus 2009 rogue security software - not recommended
X[various names]bingo9.exe"Wareout - malware masquerading as a spyware and dialer remover"
X[various names]prgsys0984.exe"Wareout - malware masquerading as a spyware and dialer remover"
U{0228e555-4f9c-4e35-a3ec-b109a192b4c2}gnotify.exe"Google Gmail Notifier. Alerts you when you have new Gmail messages"
X{05CD0D77-4947-4a56-94FA-0DF0DC644D7B}sysqyzwud.exe"Added by the FAKEALERT-AM TROJAN!"
U{1290A33C-85F5-4164-A1BE-7DD299D4986A}PBKScheduler.exe"Scheduler for CyberLink PowerBackup - archiving/backup utility"
X{12EE7A5E-0674-42f9-A76B-000000004D00}"rundll32.exe stlb2.dll DllRunMain"
X{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}sysqkmwfedz.exe"Added by the FAKEALERT-AH TROJAN!"
X{29123221-3AF8-488c-85DE-6B3EC59E8074}netmedia.exe"NetMedia adware"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sxpgknrwva.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysavxjgdu.exe"Added by the FAKEALERT-AM TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysawpbkvnq.exe"Added by the FAKEALERT-AH TROJAN!"
X{2C70168B-97CE-4f31-B85D-1FEC5002721D}sysxhtcwbse.exe"Added by the FAKEALERT-AM TROJAN!"
X{2CF0B992-5EEB-4143-99C0-5297EF71F444}"rundll32.exe stlbdist.dllDllRunMain"
X{2CF0B992-5EEB-4143-99C2-5297EF71F44B}"rundll32.exe stlbupdt.DLLDllRunMain"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to svchost.exe]"Added by the SMALL-AQ TROJAN!"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}services.exe"FakeMessage/AdRotator adware. Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""Inetsrv"" subfolder"
X{357AA41A-B7A8-4632-A27D-5B980B25CF43}[path to trojan]"Added by the SMALL-EP TROJAN!"
X{42562052-EE17-4197-82C7-91CB2E4B0666}sysrswva.exe"Added by the FAKEALERT-AH TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}sxjecknqhu.exe"Added by the FAKEALERT-AM TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syspyukrazv.exe"Added by the FAKEALERT-AH TROJAN!"
X{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}syssfzvakqg.exe"Added by the FAKEALERT-AM TROJAN!"
X{7DD4A7AC-A3F1-4495-884A-7947C5B89108}sysahbecjh.exe"Added by the FAKEALERT-AM TROJAN!"
U{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}XPlay.exe"Xplay 3 from Mediafour Corporation - ""expands what you can do with any iPod
X{9754B85A-3B34-4969-BE1F-CD03227E9470}syszweuas.exe"Added by the FAKEALERT-AM TROJAN!"
X{9754B85A-3B34-4969-BE1F-CD03227E9470}sysatjsicj.exe"Added by the FAKEALERT-AM TROJAN!"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sxnwhbvrzc.exe"Added by the FAKEALERT-AM TROJAN!"
X{A4C928E8-0ABA-4fd3-83DF-23BE54ADF9A4}sysqrnxstju.exe"Added by the FAKEALERT-AM TROJAN!"
X{B081DB1F-4EE6-4021-9DD4-8B300F0D636D}syssngbeh.exe"Added by the FAKEALERT-AH TROJAN!"
U{B179023B-6238-4499-8F26-CD73E9D90E0A}MacDrive.exe"MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
X{B3B48B54-C0EC-4705-8EE8-1981AEF656A7}sysjcyrq.exe"Added by the FAKEALERT-AH TROJAN!"
X{BAAA759D-56F0-428c-B8DA-827EA3B08C2C}sysawechod.exe"Added by the FAKEALERT-AH TROJAN!"
X{C2220120-1C24-4a79-BA7A-DDCBFC209DB3}sysfbdgv.exe"Added by the FAKEALERT-AM TROJAN!"
X{C599792D-C6D9-461d-93CA-B48BFF8E37B1}sysfdyev.exe"Added by the FAKEALERT-AM TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysutrnez.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysabmpmfr.exe"Added by the FAKEALERT-AH TROJAN!"
X{DD651081-A909-45ad-BD71-2335B0ADE043}sysnxcphmgy.exe"Added by the FAKEALERT-AH TROJAN!"
X{E4785213-3EFE-4c26-A9B4-332440E31F6F}sysrxmfdksp.exe"Added by the FAKEALERT-AH TROJAN!"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sxpjbwvahn.exe"Added by the FAKEALERT-AM TROJAN!"
X{F758F78B-0885-490e-AA3C-4A38D28B0240}sysyeabdgfp.exe"Added by the FAKEALERT-AM TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.