Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
X456655explorer.exe"Added by the BIFROSE-DE TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XAgent Explorer[random filename]Unidentified adware
XALG.EXEiexplorer .exe"Added by the DEMOTRY-B WORM!"
UAnother Internet Explorer Popup Killeraiepk2.exe"Another IE Popup Killer - pop-up stopper"
XAPIClasslexplore_.exe"Added by the MSNOPT-A TROJAN!"
UApplication ExplorerNaldesk.exe"Novell Zenworks Application Explorer Executable. ""For almost all users the Novell ZENworks agent (either Application Launcher or Application Explorer) will be run via the user's login script on each successful login. ZENworks is used to periodically deliver software updates and is also used to install the remote management components."""
UApplication ExplorerNalView.exe"Application Explorer - file manager type access to Novell Application Launcher for installing and updating network residing applications"
XApplication Explorerappexplr.exe"Added by the AGENT-NMO TROJAN!"
XAudioManExplorer.sm1"Added by the HUPIGON.IFZ BACKDOOR!"
XAvira Anti-Virus Pro 2008explorear.exeAdded by an unidentified WORM or TROJAN!
Xccregexplorer.exe"Added by the ZCREW BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xcmssappiexplore_.exe"Added by the BANCBAN-CQ TROJAN!"
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfig LoadatiorinI3Explorer.exe"Added by the SDBOT.H TROJAN!"
XConfig Loader2explores.exe"Added by the GAOBOT.BT WORM!"
XConfigurationexplorer32.exe"Added by the SDBOT-ML WORM!"
XConfiguration Loadediexploree.exe"Added by the SDBOT-KC WORM!"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XDebuggerexplorer32dbg.exe"Added by the CWS-M TROJAN!"
XDebuggeriexplore_dbg.exe"Added by the CWS-M TROJAN!"
XDefaultexplore.vbs"Added by the ALLEM WORM!"
XDrivers for Internet Exploreraccesweb.exe"Added by the STARTPAGE.FW TROJAN!"
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreExplorer.exe"Added by the IRC.FLOOD.G BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
Xexploreff.exeexploreff.exe"Added by the FINFANSE TROJAN!"
Xexplorep.exeexplorep.exe"Added by the LINEAG-I TROJAN!"
Uexplorerexplorer.exe"Starts Windows Explorer. Unless this has been manually added to startups or added by another program it could be a virus such as PE_BISTRO or DVLDR or MYDOOM.C. Note that it is also not the explorer.exe task/service you'll see when via CTRL+ALT+DEL"
Xexplorerwscript.exe [filename]"Sneaky way to start any VBS script. Many viruses use VBS files. Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted"
XExplorershellexpl.exe"Added by the SHELDOR TROJAN!"
Xexplorerexpl32.exe"Added by the RATSOU TROJAN!"
XExplorer[path to worm]"Added by the AUTEX WORM!"
XExplorershellexp.exe"Added by the AGENT-ZY TROJAN!"
XEXPLOREREXPL0RER.EXE"Added by the BEASTDO-Y TROJAN! Note the ""0"" in the filename rather than upper case ""o"""
XEXPLORERsys.exe"Added by the SILLYFDC-A TROJAN!"
XExplorerconfig_.com"Added by the FLOPPY-D WORM!"
XExplorerdrv.exe"Added by the SMALL-FD TROJAN!"
Xexplorer[path to trojan]"Added by the AGENT-EU TROJAN!"
Xexplorerexplorer.exe"Added by the KEYLOG-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
XEXPLOREREXPLORER.exe"Added by the NETHIEF-P TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\ShellExt"
Xexplorerexplorer.exe"Added by the BLOCKEY-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\config"
XexplorerYinstall.exe"PurityScan/Clickspring adware"
XExplorerWindows Explorer.exe"Added by the SILLYFDC-I WORM!"
XExplorerexplorar.vbs"Added by the DESKTO-A WORM!"
XExplorerTXP1atform.exe"Added by the FUJACKS.CA VIRUS!"
Xexplorersystem.exe"Added by the AGENT-FI TROJAN!"
XExplorermsrstart.exe"Added by the SOPICLICK TROJAN!"
Xexplorermain.vbe"Added by the SHUSH-A WORM!"
XExplorer 2238[path to trojan]"Added by the AGENT-CPI TROJAN!"
XExplorer Loaderexplr32.exe"Added by the AGOBOT.N WORM!"
XExplorer Loaderexplorerl.exe"Added by the SDBOT-ADI WORM!"
XExplorer lptt01explorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer ml097eexplorer.exe"RapidBlaster variant (in a ""explorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here.Note - this is not the legitimate Windows Explorer (explorer.exe) which would not normally appear in Msconfig/Startup unless you added it manually!"
XExplorer softexplorer.pif"Added by the RBOT-APK WORM!"
XExplorer softexplorer.com"Added by the RBOT-ARM WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the AGENT-EW or PWS-CY TROJANS! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xexplorer.exeexplorer.exe"Added by the DELF-ACL TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the Program Files folder"
XExplorer.execsrss.exe"Added by the JUEGO-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %AppData%\Microsoft"
XExplorer32Expl32.exe"Added by the HACKTACK.B TROJAN!"
XExplorer32explorer6s4.exeAdded by the Downloader.Win32.Small.biq TROJAN!
XExplorer32efsdfgxg.exe"Added by the CLICKER-Y TROJAN!"
XExplorer5config_.com"Added by the VB.CBG WORM!"
XExplorer6.1.EXEExplorer.exeAdded by the MYDOOM.B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!
Xexplorerf.exeexplorerf.exe"Added by the AGENT-GDZ TROJAN!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
XExplorerTaskexplorer.exe"Added by the ZCREW-B BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in the ""Fonts"" sub-folder"
XExploreUpdSched[random filename]"ZenoSearch adware"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
Xgoogle Intrenet Explorergoogle.pif"Added by the RBOT-ARA WORM!"
XIE configureexplorer.exe"Added by the LINEAGE-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XIEexplorer AUpdateIEexplore32.exe"Added by the RBOT-GRE WORM!"
XIELoader32iexplore32.exe"Added by the SPEX or SPEX.B WORMS!"
XIESetIExplorer.dll"Added by the PWS-BLUEDIT TROJAN!"
XIexploreiexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIEXPLOREiexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIExploreIEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
XIEXPLOREIEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XiExplore Iniie4uini.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIEXPLORE.EXEgoot.exe"Added by the BIFROSE-C TROJAN!"
XIExplorerIexplor32.exe"Added by the BDOOR-BY BACKDOOR!"
XIExplorerIExplorer.EXE"Added by the BANCOS-CH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIEXPLORERmsiecfg.exe"Added by the BDOOR-JU BACKDOOR or BANCBAN-IP TROJAN!"
XIexplorerexplorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xiexplorer lptt01iexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xiexplorer ml097eiexplorer.exe"RapidBlaster variant (in a ""iexplorer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XIexplorer.exeIexplorer.exe"Added by the BANCBAN-EN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XIExplorer32 Java ScriptingIExplore32b.exe"Added by the RBOT.ABO WORM!"
XIExplorer32c Java ScriptingIExplore32cb.exe"Added by the RBOT.ABN WORM!"
XIExplorer6 Java ScriptingIExplore326.exe"Added by a variant of the SDBOT WORM!"
XIExplorer7 Java ScriptingIExplore327.exe"Added by a variant of the SDBOT WORM!"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER-EUT TROJAN! The file is located in %Windir%\Sun\Java\Deployment\logs"
XIexplorerr.exeIexplorerr.exe"Added by the BANKER.AOVZ TROJAN! The file is located in %Windir%\msagent\gf"
XIExplorerServiceWinSock.exe"Added by the AGENT.KIU TROJAN!"
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet Exploreriexplorer.exe"Added by the LORSIS WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet ExplorerIExplorer.exe"Added by the NETHIEF-O BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorerhttp.exe"Added as part of a new potential CWS infection
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet ExplorerIEPLORE32.EXE"Added by the AGOBOT-CU WORM!"
XInternet Explorertwain.exe"Added by the AGENT.BEA TROJAN!"
XInternet Explorer Agentiexplorer.exe"Added by the AGENT-BH TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer Auto-Updateupdt32v5.exe"Added by the SPYBOT-AB BACKDOOR!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer Securityiexplore.pif"Added by the RBOT-ALQ WORM!"
XInternet Explorer Sys32isys32.exe"Added by the IRCBOT-ADA WORM!"
XInternet Explorer Updaterlexbac.exe"Added by the DOWNLOAD TROJAN!"
XInternet Explorer Updateriexplorer.exe"Added by the REUR.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternetExplorer2windows.exe"Added by the SDBOT-CZP WORM!"
XInternetExplorer32iexplore32.exe"Added by the RBOT-GRA WORM!"
XInternet_Explorermicrosoft.exe"Added by the BANKER-EUQ TROJAN!"
XInternet_Explorer.exeInternet_Explorer.exe"Added by the BANKER-END TROJAN!"
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIntranet Explorer[random filename]"Added by the POEBOT.DK BACKDOOR!"
Xirwftpiexplorer.exe"Added by the BANKER-AN TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
Xkernel32sys.dllIEXPLORER.exe"Added by the RBOT-MK WORM!"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Uklpexplorer.exe"ComSurveilSys keystroke logger/monitoring program - remove unless you installed it yourself!"
Xl44sys**iexplore"Added by the VBS.LIDO WORM - where ** is a number between 65 and 76"
Xlexplorelexplore.exe"Added by the BROPIA WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XLimpetexplorer16.exe"Added by the RBOT-AJD WORM!"
Xlnternet ExplorerAMSNDMGR.EXE"Added by the KWBOT.R WORM! Note that the ""l"" is a lower case ""L"" and not an upper case ""I"""
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
Xloadexplorer.exe"Added by the LINEAGE-OZ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XloadWinExplorer.exe"Added by the VB.EIW WORM!"
XLoadab1explorer.exe"Added by the LINEAGE-AJ TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMecq0explorer.exe"Added by the MUMUBOY.C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XloadMect1explorer.exe"Added by the LINEAGE-L TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMessenger Explorerm41n.exe"Added by the SDBOT-SA BACKDOOR!"
XMicroCQ0explorer.exe"Added by the LINEAGE-AK TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoftExplorerr.exe"Added by the IRCBOT-WG TROJAN!"
XMicrosoftExplorer.exe"Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Automatic UpdaterExplorer.exe"Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Deviexplorer32.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Explorersvapache.exe"Added by the RBOT-VR WORM!"
XMicrosoft Explorerexplorer.scr"Added by the RBOT-ADH WORM!"
XMicrosoft Explorerexplorer.pif"Added by the SDBOT-ACX WORM!"
XMicrosoft Explorerexplorer.exe"Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft explorer Updateinternal.exeAdded by an unidentified WORM or TROJAN!
XMicrosoft Explorer(64)explorer64.exe"Added by the SPYBOT-R WORM!"
XMicrosoft Explorer2system.exe"Added by the IRCBOT.BS TROJAN!"
XMicrosoft Explorer2nome.exe"Added by the RANDEX.AA WORM!"
XMicrosoft Explorer2bitchbot.exe"Added by the SDBOT.EV WORM!"
XMicrosoft EXPLOREXP Protocolexplorexp.exe"Added by a variant of the SPYBOT WORM!"
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Inc.iexplorer.exe"Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Inc.iexplorer.exe..."Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Expiiexplorer.exe"Added by the RBOT-KX WORM!"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplorer.exe"Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Internet Explorercrsys32.exe"Added by the RBOT.UZ WORM!"
XMicrosoft Internet Explorermovies.exe"Added by the BANCOS-DZ TROJAN!"
XMicrosoft Internet Explorersvzhost.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Internet Explorermccagent.exe"Added by the DLOADER-UD TROJAN!"
XMicrosoft Internet Explorersysini.exe"Added by the DELF-LN TROJAN!"
XMicrosoft Internet Explorersvchost.exe"Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Internet Explorersvchosts.exe"Added by the BANCBAN-U TROJAN!"
XMicrosoft Internet Explorer[path to trojan]"Added by the BANCBAN-AS TROJAN!"
XMicrosoft Internet Explorermsngrt.exe"Added by the SDBOT-GU BACKDOOR!"
XMicrosoft Internet Explorer_svchost.exe"Added by the TINY.LX TROJAN!"
XMicrosoft Internet Explorer Managerie.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Internet Explorer Updateieupdate.exe"Added by the SHEUR.MH TROJAN!"
XMicrosoft Intrenet Explorergoaw.pif"Added by the RBOT-API WORM!"
XMicrosoft Intrenet ExplorerSoundsyst.exe"Added by the RBOT-AQU WORM!"
XMicrosoft Intrenet Explorercnsg.pif"Added by the RBOT-ARO WORM!"
XMicrosoft Intrenet Explorerwcumrg.exe"Added by the SDBOT-AFD WORM!"
XMicrosoft Machine Scriptiexplorersis.exe"Added by the RBOT-CMH WORM!"
XMicrosoft Synchronization Managerexplorer.exe"Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Updateexplorer.exe"Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update 32explore32.exe"Added by the SPYBOT.CYM WORM!"
XMicrosoft Update 32explorer.exe"Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XMicrosoft Update Driversexplorers.exe"Added by a variant of the SDBOT WORM!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoft Windows Exploreriexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMicrosoft Windows Explorerexplorewin.exe"Added by the IRCBOT.WORM.212480.H WORM!"
XMicrosoft Windows Updatesexplorer32.exe"Added by the SDBOT.VQ WORM!"
XMicrosoft Windows XP/2K Explorerwinexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftİiexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
XMiscrosoft Windows ExplorerIEEXPLORER.exeReported as the SDBOT.YX WORM!
XMMB2explorer.exeAdded by an unidentified WORM or TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%
XMS Explorermexplore.exe"Added by the YAHA.AE WORM!"
XMS Internet ExploreMSIEx.exe"Added by a variant of the RBOT WORM!"
XMsAudioexplorer.exe"Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMSN Explorermsnexplorer.exe"Added by the AGENT-CAX TROJAN!"
XMSN Explorerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMsn MessengeIExplorer.exe"Added by the DELF-LL TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMSN MessengerIExplorer.exe"Added by the BANKER-EU TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XMSN Messengerexplorer..exe"Dropper for the Ciadoor.cb TROJAN!"
XMsnExplorerwinagent.exe"Added by the BDOOR-EQ BACKDOOR!"
XMsnExplorerMSEXPLOREN.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSHCH.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorerSVCHST.EXE"Added by the BDOOR-EB BACKDOOR!"
XMsnExplorermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XMsnExplorersdhch.exe"Added by the TACTSLAY.B TROJAN!"
XmssysintIexplore .exe"Added by the PWSTEAL.ABCHLP and PSPIDER.310.B TROJANS! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XNameIexplorer0.exe"Added by the THREADSYS TROJAN!"
XNavegateiiexplorer.exe"Added by the BANCBAN-OP TROJAN!"
Xnternet Exploreriexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOPTIMIZERiexplore.exe"Added by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOPTIMIZERiexplore.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xprint sharing[path] hidden32.exe [path] explorer.exe"Added by the ZCREW.B BACKDOOR! Note - the legitimate Windows Explorer (explorer.exe) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
XProtectionIExplore .exe"Added by the ELIPTER.D WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XRavshellexplore3.exe"Added by the PAKES.HZ TROJAN!"
XRavshellIEXPLORER.EXE"Added by the AGENT.URZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
XRavTimerexplores.exe"Added by the HOMEY-A TROJAN!"
XRegMutexlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XRpcLocatorexplorer.exe"Added by the RBOT-GSA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xrxexplore.exe"Added by the ZHENGTU-A TROJAN!"
XScheduIrmsexploren.exe"Added by a variant of the SDBOT WORM!"
XSchedulermsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicesiexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
XShellExplorer.exe sound_drive16.exe"Added by the GP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""sound_drive16.exe"" file is located in %System%"
XShell"Explorer.exe msmsgs.exe"
XShellExplorer.exe svchost.exe"Added by the DOYORG BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate svchost.exe process is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
Xshellexplorer.exe"Added by the KAKKEYS TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XShellExplorer.exe iexplore.exe"Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
XShellExplorer.exe winupdate.exe"Added by the AGENT-FD TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winupdate.exe"" file is located in %System%"
XShellExplorer.exe [path] ibm[RANDOM 5 DIGIT NUMBER].exe"Added by the ANSERIN TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files"
XShellExplorer.exe winsys32.exe"Added by the DELF.CP BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""winsys32.exe"" file is located in %Windir%"
XShellexplorer.exe msbnc.exe"Added by the AGENT-PL BACKDOOR! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""msbnc.exe"" file is located in %System%"
XShellExplorer.exe kbdsys.exe"Added by the DAPROSY WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""kbdsys.exe"" file is located in %AppData%\Microsoft\Keyboard"
XShellExplorer.exe init32m.exe"Added by the DLSW-B TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""init32m.exe"" file is located in %System%"
XShellExplorer.exe smssnt.exe"Added by the AGOBOT.EE TROJAN! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The ""smssnt.exe"" file is located in %System%"
XShell32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShell32explorer.exe"Added by the SDBOT-NF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XShellRunlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XShellRun32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XslideIexplore.exe"Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XsmsysExplorer.exe"Added by the CLICKER-C BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in a ""Template"" subfolder"
XStart Uppingiexplorerupdt.exe"Added by the RBOT-RR WORM!"
Xstarteriexplore.exe"Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xstartkeyexplore32.exe"Added by the BDOOR-MT BACKDOOR!"
Xstartkeyexplorer.exe"Added by the BCKDR-MLD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSustemexplorer.exe"Added by an unidentified VIRUS
XSustemUpdateexplorer.exe"Added by an unidentified VIRUS
XSvcH0stmsexploren.exe"Added by the BACKDOOR-CGZ TROJAN!"
XSvcH0stmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
Xsvchost[path to explorer.exe]"Added by the UNREAL-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually!"
Xsyscheckiexplorer.exeAdded by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
Xsysconfigiexplorer.exe"Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XsysMett1explorer.exe"Added by the LEGMIR-Y TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
XsystemExplorer.exe"Added by the GRAYBIRD BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Information Manageriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Update2explorer.exe"Added by the AUTOTROJ-C TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XSystem-ServiceEXPLORER.SCR"Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
XSystemExplorerexplore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
XSystrayw32explorer.exe"Added by the RBOT-AJY WORM!"
Xsys_Runtt1explorer.exe"Added by the LINEAGE-M TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %ProgramFiles%"
Xtaskmgrexplorer.exe"Added by the ZAPCHAS-AC TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XTelephony ProviderIexplore.exe"Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
UTurboExplorerTE.exe"Web accelerator - ""TurboExplorer 2.x is a real-time web surfing accelerator specifically designed for Internet Explorer 4/5 to achieve a faster and more effective approach to the internet"". Only needed if you find it improves web browsing"
XUpdate Exploreriexploreupd.exe"Added by a variant of the RBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XVideoexplored.exe"Added by the GAOBOT.RF WORM!"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
XWin32 ExplorerExplorer32.exe"StartPa-MN homepage hijacker"
XWinAmpAgentMsexploren.exe"Added by the BDOOR-EB BACKDOOR! Note - this is NOT the popular Winamp media player which has a different filename"
XWinAmpAgentmsnexploren.exe"Added by the TACTSLAY.B TROJAN!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
XWindowsexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Backup ConfigurationIEXPLORER.exe"Added by the GAOBOT.AZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Explorer[filename].exe"Added by the SDBOT TROJAN!"
XWindows ExplorerLsas.exe"Added by the GAOBOT.AO WORM!"
XWindows Explorerolecom32.exeAdded by an unidentified WORM or TROJAN!
XWindows ExplorerEEXPLORER.EXE"Added by a variant of the SPYBOT WORM!"
XWindows Explorerexplorer.exe"Added by the POEBOT-J WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorerexplorer.pif"Added by the RBOT-AID WORM!"
XWindows Explorersystem32.exe"Added by the RBOT-AJH WORM!"
XWindows Explorerexplorer32.exe"Added by a variant of the SDBOT WORM!"
XWindows ExplorerWindows Explorer.EXE"Added by the VB-EBA WORM!"
XWindows Explorersystem.exe"Added by the STIRAUT WORM!"
XWindows Explorer Keyexplorer.exe"Added by the IRCBOT-YB WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Explorer Servicesexploresys.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XWindows Explorer ShellWinexec32.exe"Added by the REDIST.B WORM!"
XWindows Explorer SP2csrss.exe"Added by the BANKER-DM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaBeans"" subfolder"
XWindows Explorer Update Build 1142EXPLORER32.EXE"Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
XWindows Explorer-3212WINRE16.EXE"Added by the HARDOC WORM!"
XWindows Explorer.exeExplorer.exe"Added by the FALTER-A TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Internet Explorer 6firefox.exe"Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Loginexplored.exe"Added by the GAOBOT.SY WORM!"
XWindows ServicesExplorer.exe"Added by the SDBOT-WT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows System32explorer.exe"Added by the OPANKI-V WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is also copied to %System%"
XWindows Taskmanageriexplorer.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
XWindows Updateexplored.exe"Added by the GAOBOT.MF WORM!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows Updateriexplorerrs.exe"Added by the RBOT-TN WORM!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindowsExplorercsrss.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsExplorersvchost.exe"Messenger Blocker rogue security software - not recommended. Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files\System"
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindowz Update V2.0Explorer.exe"Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
XWinExlexplore_.exe"Added by the MSNOPT-A TROJAN!"
XWinlogon ShellExplorer.exe svchost.exe"Added by the KIPIS.M WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""1032"" sub-folder"
Xwinnt DNS identiexplorer.exe"Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
YWinPatrol ExplorerWinPatrolEx.exe"Part of WinPatrol"
XWinsock2 driverIEXPLORE .EXE"Added by the SPYBOT-AU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) process as there is a space before the "".exe"""
XWINTASKiexplorer.exe"Added by the MYTOB-CH WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWinUPD32explorer.exe"Added by an unidentified VIRUS
Xwinupdateconn_Explorer.EXE"Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XWinVNCiexplorer.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
XWksSVCEXPLORER.exe"Added by the MYTOB-BW WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
XYahoo MessenggerIEXPLORERS.exe"Added by the AUTOIT.DH TROJAN!"
XZonealarmiexplore.exe"Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X[random name]explore3.exe"Added by the DELF.FAN TROJAN!"
X[random number]explorer.exe"Added by the KEYLOG-AN TROJAN! Note - the legitimate Windows Explorer (explorer.exe) is located in the Windows or Winnt folder and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%\service"
X_explore manager_explore.exe"Added by the SPEXTA-C TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.