Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
X$sys$crash$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$momomomochin$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X$sys$umaiyo$sys$sonyTimer.exe"Added by the WELOMOCH TROJAN!"
X*WinLogon[trojan path] ren time:[random number]"Added by the VUNDO TROJAN!"
U12Ghosts ShowTime12showtime.exe"12Ghosts Showtime - ""Enhance the clock in your tray with font formatting
UAnyTimeAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtDem.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
UAnyTime OrganizerAtw.exe"AnyTime Organizer Deluxe from Individual Software Inc - ""all the tools you need to organize your calendar
XAOL Instant Messenger dll runtimeMSAOL32dll.exe"Added by the RBOT-ATA WORM!"
Xapyginapyginsimenu.exe"Added by the SDBOT.BTR WORM!"
YAspireTimeMachineacertmb.exe"System recovery software supplied with some Acer notebook PCs. Similar to GoBack and the restore program in WinXP
NATICCCcli.exe runtime"ATI's Catalyst™ CONTROL CENTER. Required if you want to change graphics settings on a regular basis but you must have internet access and Microsoft's .NET framework installed. Note that this has ""runtime"" appended to cli.exe in the ""Command"" column of MSCONFIG. Recommend that start the program manually via Start → Programs → ATI Catalyst Control Center → Advanced → Restart Runtime as it can cause problems when starting Windows"
UAtomic Time SynchronizerTimeSync.exe"TimeSync - lets you synchronize your computer's clock with any internet atomic clock"
UAtomicTimeATOMICTIME.EXE"AtomicTime - utility that synchronizes your PC clock to an atomic clock"
?checktimect.exe"Found in the HPSelectFrontend directory on a HP machine. What is it's purpose and is it required?"
XClient Server Run Time Proccesscsrsrv.exe"Added by a variant of the SDBOT WORM!"
XClient Server Runtime[path to worm]"Added by the POEBOT-KR WORM!"
XClient Server Runtime Processcsrsss.exe"Added by the SDBOT-LD WORM!"
XClient Server Runtime Processcsrs.exe"Added by the LINKBOT.M WORM!"
XClient Server Runtime Processsmmss.exe"Backdoor TROJAN! Possible SDBOT-GEN variant"
Xconime.execonime.exe"Added by the AVENDOG WORM! Note - this is not the legitimate Console IME process of the same filename which is located in %System%"
UCPQInet Runtime ServiceCpqInet.exe"For Compaq PC's. Allows AOL and Compuserve to use the Easy Access buttons for the internet. Is not required if you don't use the ISP providers"
XCTime[path to trojan]"Added by the HTTPDOS TROJAN!"
XDhcpCepPYJJKIME.exe"Added by the AGENT-BXQ TROJAN!"
UDimensionDimension.exe"Dimension - a program which lets you customize MSN messenger such as adding animated and coloured nicknames
UDimension4d4.exe"Dimension 4 - network time synchronization freeware - starts-up
XDKTimedktime.exe"Added by the LUNII TROJAN!"
YDLBTCATS"rundll32 [path] DLBTtime.dll _RunDLLEntry@16"
YDLBUCATS"rundll32 [path] DLBUtime.dll _RunDLLEntry@16"
YDLBXCATS"rundll32 [path] DLBXtime.dll _RunDLLEntry@16"
YDLCCCATS"rundll32 [path] DLCCtime.dll_RunDLLEntry@16"
YDLCDCATS"rundll32 [path] DLCDtime.dll _RunDLLEntry@16"
YDLCFCATS"rundll32 [path] DLCFtime.dll _RunDLLEntry@16"
YDLCGCATS"rundll32 [path] DLCGtime.dll _RunDLLEntry@16"
YDLCICATS"rundll32 [path] DLCItime.dll _RunDLLEntry@16"
YDLCJCATS"rundll32 [path] DLCJtime.dll _RunDLLEntry@16"
YDLCQCATS"rundll32 [path] DLCQtime.dll _RunDLLEntry@16"
YDLCXCATS"rundll32 [path] DLCXtime.dll _RunDLLEntry@16"
Xdmimedmime.exe"Malware installed by different rogue security software including SpyKillerPro"
XeTrust Realtime Monitorrealmon.exe"Added by the LAZAR.B TROJAN!"
XExplorerRunconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Temp%"
UGoogle IME AutoupdaterGooglePinyinDaemon.exe"Google Pinyin Input Method Editor (IME) - allows a user to input Chinese characters by entering the pinyin of a Chinese character (with or without tone
Xhimem.exe[path to worm]"Added by the STRATION-FW WORM!"
XIE Runtimewini.exe"Added by the PICRATE.B WORM!"
XIE Runtimeswinis.exe"Added by the RBOT-ADZ TROJAN!"
XIMEconime.exe"Added by the DLDR-G TROJAN! Note - this is not the legitimate Console IME process of the same filename which is located in %System%. This one is located in %Windir%"
Nimekrmigimekrmig.exe"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
NIMEKRMIG6.1IMEKRMIG.EXE"Part of MS Input Method Editor which is used to ease the input of Asian characters in MS Office (Chinese
NImesh??"Imesh is a file sharing system"
NImesh Auto Update??"Update check for the Imesh file sharing system. Turn the update off under ""options"""
XIMEvtMgr.exeIMEvtMgr.exe"Added by the KEYLOG-AR TROJAN!"
XIMJPMIG8.2msime82.exe"Added by the VB-CYG WORM!"
XIMJPMIG8.2msime80.exe"Added by the VB-CYJ TROJAN!"
XImMsntimed.exe"Added by the WEBDOR.AK TROJAN!"
XIntel Management Services v32mstime32.exe"Added by the AUTORUN-AYG WORM!"
UInternet TimerITIMER.exe"Shareware dial-up connection call cost calculator from Ratsoft"
XIsassRenascimentoIssas.exe"Added by the BANKER.GAX TROJAN!"
XJava Runtime Environmentjbuild.exe"Added by the DELBOT-J WORM!"
XJava Runtime Valuerunjava.exe"Added by the RBOT-DDJ WORM!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XKernelFaultCheckmsime.exe"Added by the TINY-P TROJAN!"
XKernelRuntime[path to worm]"Added by the MYTOB-JO WORM!"
XLimewireLimeWire.exe"Added by the RBOT-AGH WORM!"
NLimeWire On StartupLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
NLimeWire x.xLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
Xlimewirepro.exelimewirepro.exe"Added by the IRCBOT-WA WORM!"
YLXBSCATS"rundll32 [path] LXBStime.dll _RunDLLEntry@16"
YLXBTCATS"rundll32 [path] LXBTtime.dll _RunDLLEntry@16"
YLXBUCATS"rundll32 [path] LXBUtime.dll _RunDLLEntry@16"
YLXBXCATS"rundll32 [path] LXBXtime.dll _RunDLLEntry@16"
YLXBYCATS"rundll32 [path] LXBYtime.dll _RunDLLEntry@16"
YLXCCCATS"rundll32 [path] LXCCtime.dll _RunDLLEntry@16"
ULXCDCATS"rundll32 [path] LXCDtime.dll _RunDLLEntry@16"
YLXCECATS"rundll32 [path] LXCEtime.dll _RunDLLEntry@16"
YLXCFCATS"rundll32 [path] LXCFtime.dll _RunDLLEntry@16"
YLXCGCATS"rundll32 [path] LXCGtime.dll _RunDLLEntry@16"
YLXCJCATS"rundll32 [path] LXCJtime.dll _RunDLLEntry@16"
YLXCQCATS"rundll32 [path] LXCQtime.dll _RunDLLEntry@16"
YLXCRCATS"rundll32 [path] LXCRtime.dll _RunDLLEntry@16"
YLXCTCATS"rundll32 [path] LXCTtime.dll _RunDLLEntry@16"
YLXCYCATS"rundll32 [path] LXCYtime.dll _RunDLLEntry@16"
YLXDBCATS"rundll32 [path] LXDBtime.dll _RunDLLEntry@16"
YLXDCCATS"rundll32 [path] LXDCtime.dll _RunDLLEntry@16"
YLXDDCATS"rundll32 [path] LXDDtime.dll _RunDLLEntry@16"
YLXDICATS"rundll32 [path] LXDItime.dll _RunDLLEntry@16"
ULXDJCATS"rundll32 [path] LXDJtime.dll _RunDLLEntry@16"
?MacDrive7.0.4TimeOutPatchTimeOutPatch.EXE"Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista
NMagitimeMagitime.exe"Magitime - connection tracking utility which monitors online time
XMemory managerhimem32.exe"Added by the MANCSYN TROJAN!"
UMemory+tfimemsr.exe"Memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
XMicrosoft (R) Windows Vista/NT Runtime Compatibility Servicenrcs.exe"Added by the RANKY.X TROJAN!"
XMicrosoft 64 Bit Runtime Updaterwupdt64.exe"Added by a variant of the RBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrs.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft Client/Server Runtime Server Subsystemcsrssa.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft DirectXtime123.exe"Added by the SDBOT.MD WORM!"
UMicrosoft IME 2002IMJPMIG.EXE"Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails
XMicrosoft RuntimeCfgDll32.exe"Added by the RANDEX.BD WORM!"
XMicrosoft Time Managerdveldr.exe"Added by the RBOT-HQ WORM!"
XMicrosoft Update Timewuam.exe"Added by the RBOT-M WORM!"
XMicrosoft uptime Servicesysuptime.exe"Added by the RBOT-ACG WORM!"
XMicrosoft uptime Servicesycuptime.exe"Added by the RBOT-AHY WORM!"
XMicrosoftMultimediaTaskMmtask.exeAdware downloader - not the valid MusicMatch Jukebox which shares the same filename
XMS Timetimezone.exe"Added by the AGOBOT.ADY WORM!"
Xmssysintcomime.exe"Added by the NETSNAKE-I TROJAN!"
XMultimediawindebug.exe"Added by the VB-ERB WORM!"
XMultimedia Codecsmcc.exe"Added by the DLOADER-MB TROJAN!"
XMultimedia extensionsmservice.exe"EasySearch adware"
XMultimedia extensions[path to trojan]"Added by the SMUTSRCH-A TROJAN!"
XMultimedia extensionsmservice1.exe"Added by the DLOADR-AWD TROJAN!"
UMultimedia KBDMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
UMULTIMEDIA KEYBOARDMMKeybd.exeMultimedia keyboard manager. Required if you use the additional keys
XMULTIMEDIA KEYBOARD88smss.exe"Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
UNetTimeNETTIME.EXE"From a visitor - "This is the executable for NetTime. It is started from the registry when you check the box to start at startup. NetTime allows you to synchronize your computers' clock with a server on your local net or the internet using any of several protocols
XNod32 Runtimesysregi.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
UNuvaTimeNuvaTime.exe"NuvaTime - reminder for women using NuvaRing"
NOdebit Multimedia V2Odebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
NOdebit Multimedia V3Odebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
NOdebit Multimedia V3 - ServicesOdebit.exe"Odébit Multimedia - free French multimedia player giving access to the best of television
NOnlineTimeonlinetime.exe"OnlineTimer - monitors your Windows dial-up network and logs the time you spend online as well as the resulting costs"
XPayTimepaytime.exe"Added by the STARTPA-YR TROJAN!"
NPCDRealtimerealtime.exe"Apparently the monitoring device for PC Doctor Online. It provides a ""free"" examination on system files (i.e. registry)
XPCMMRealtimepcmm.exe"PC MightyMax rogue security software - not recommended
?PhilipsLimeLimeAlive.exe"Associated with some Philips portable media players such as the GoGear. What does it do and is it required?"
UPHIME2002ATINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
UPHIME2002ASyncTINTSETP.EXE"Microsoft's Input Method Editor for Asian languages which is used to both display and enable the input of characters in e-mails
XPHIME2004CCTFMDN.exe"Added by the DLOADR-AMV TROJAN!"
XPHIME2OO2ASyst[path to trojan]"Added by the DBDOOR-B TROJAN!"
XPingTimeout Institutionpingchek.exe"Added by the SDBOT-VY WORM!"
XPingTimeout Institutioninternal.exe"Added by the SDBOT.BMH WORM!"
YPP2000 Real Time ScanPPVstop.exeProtector Plus anti-virus software - real time scanner
NPrecision Time Clock CheckerPrecisionTime.exePrecision Time 2.0. Checks your computer clock time against the Naval Observatory or some other source to assure accurate time
XPrecisionTimePrecisionTime.exe"PrecisionTime - clock synchronizing software containg spyware by Claria/GAIN. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
XPYJJIMEPYJJIME.exe"Added by the AGENT-BXQ TROJAN!"
XQTimenrchk.exePremium rate adult content dialler
XQuick Time file managerquicktimeprom.exe"Added by the SDBOT TROJAN!"
NQuick Time Taskqttask.exe"System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards"
XQuicktimeqttasks.exe"Added by the ADCLICK-AK TROJAN!"
XQuicktimeshch.exe"Added by a variant of the BDOOR-EB BACKDOOR!"
XQuickTimeqttask.exe"Added by the AGENT-ENG TROJAN! Note - this is not the legitimate Apple ""Quick Time"" viewer that has the same startup name and filename and is normally located in %ProgramFiles%\QuickTime. This one is located in %System%"
XQuicktime Mediaplayerwinmplyer32.exe"Added by the RBOT-PM WORM!"
XQuicktime Mediaplayrwnmplyr.exe"Added by a variant of the RBOT WORM!"
XQuicktime Pro 3.0winuodps.exe"Added by the GAOBOT.BH WORM!"
NQuickTime TaskQttask.exeSystem Tray access to Apple's "Quick Time" viewer from version 5 onwards
XQuickTime Taskqttasks.exe"CoolWebSearch parasite variant"
XQuicktime Task[random filename]"Trafficadvance dialer"
XQuickTime Taskqttask.exe"Trojan that is typically bundled with rogue security programs (such as Virus Trigger and AntivirusTrigger) and fake codecs. Note - this is not the legitimate Apple ""Quick Time"" viewer that has the same startup name and filename and is normally located in %ProgramFiles%\QuickTime. This one is located in %ProgramFiles%\WebMediaViewer"
NQuickTime Update Completion xquicktimeupdatehelper.exe"Different numbers caused by number of launches. So if 3 updates are made separately
XQuicktimeMngrQUICKTIMEMNGR.EXE"Added by the WOOTBOT.AW WORM!"
XQuickTimeUpdateQuickUpdate.exe"Added by the BIFROSE-CW TROJAN!"
XRavTimeMstray.exe"Added by the WUKILL.A WORM!"
YRavTimerRavTimer.exe"RAV AntiVirus"
XRavTimerexplores.exe"Added by the HOMEY-A TROJAN!"
XRavTimeXP[worm filename]"Added by the WULLIK.B WORM!"
XRavTimeXPVirus"Added by the CAGER.A WORM!"
URealtime Audio Enginemmrtkrnl.exe"Associated with ALCATech BPM Studio"
YRealtime Monitorrealmon.exe"Realtime scanner part of eTrust Antivirus/InoculateIT version 6 virus scanners from Computer Associates"
XRealTimeProtectorwinlogon.exe"Added by the AUTORUN.DIB WORM! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
?RealTimeUpdateRealTimeUpdate.exe"Product description in properties is ""InternetExplorerCommunicationAgent Module"" ?"
Xrenascimentosvchost.exe"Added by the BANKER.GAX TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
Xretimeretime.exe"Added by the GIPMA TROJAN!"
URocket.TimeRocketTime.exe"Rocket.Time - time synchronization software from Rocket Software"
XRuntime ProcessCsrss.exe"Added by the CIADOOR-J BACKDOOR! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XRuntime Server Subsystemcsrss.exe"Added by the IRCBOT-XV WORM!"
Xruntime.exeruntime.exeAdded by a variant of the Tibs malware
XSakemsneqlsimenu.exe"Added by the SDBOT.BTO WORM!"
NSalaatTimeSalaatTime.exe"""Salaat Time is a FREE multi-function Islamic application that calculates the prescribed five daily Muslim prayer times as well as Qiblah direction for anywhere in the world"""
USametime ConnectConnect.exe"IBM Lotus Sametime - instant messaging and Web conferencing software"
USay The Time 5.0SAYTIME.EXE"This program has audio cues for the system clock in male and female voices
XServer Runtime Errorunsec.exe"Added by the SDBOT-DFA WORM!"
XServer Runtime Processwbemstest.exe"Added by the SDBOT-DDB WORM!"
XService Pack DLL Runtimespdll32.exe"Added by a variant of the RBOT WORM!"
NSi MeterSIMETER.EXE"
Xsmrtdrvruntime.exe"Added by the AGOBOT.MT WORM!"
USP TimeSyncSP TimeSync.exe"SP TimeSync lets you synchronize your computer's clock with any Internet atomic clock (time server)"
YSpybot - Search & DestroyTeaTimer.exe"Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options
YSpybotSD TeaTimerTeaTimer.exe"Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options
USymmTimeGeTTime.exe"SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
USymmTimeSymmTime.exe"Older version of SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
USymmTime ApplicationGeTTime.exe"SymmTime from Symmetricon - freeware utility that ""synchronizes your PC clock to Coordinated Universal Time (UTC)
XSystem time updatorCSysTime.exe"Added by the RANDEX.S WORM!"
XSystem Uptime ServerSYSENTRY.EXE"Added by the RBOT.LK WORM!"
XSystem Uptime ServerSYSENTRY32.EXE"Added by the RBOT.LK WORM!"
XSystem32 Runtime StartUpsysrs.exe"Added by the AGOBOT.ANW WORM!"
XSysTimesystime.exe"CoolWebSearch parasite variant - also detected as the STARTPA-FL TROJAN!"
UTask Catcher Real-Time Detectortasktrap.exe"Real-time monitor for Task Catcher from BillP Studios - which ""allows you to efficiently monitor programs running on your computer without slowing you down or hogging all your memory. Task Catcher will block unwanted programs from running and restart your favorite programs if they are disabled or crash"". If the program isn't registered the monitor will initially load and then close at start-up. If registered it will continue to run and optional System Tray access will also be available"
YTeaTimerTeaTimer.exe"Part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. ""Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options
XTime ManagerTimeManager.exe"Added by the MYTOB-BV WORM!"
XTime Zone Synchronizationwscript zshell.js"Added by the NETDEX-A TROJAN!"
UTimeCalendartc.exe"TimeCalendar digital planner"
NTimed Backups Manager StartupBACKTIME.EXE"Backup Plus - backup software"
UTimeLeftTimeLeft.exe"TimeLeft is a countdown
UTimemanager.exeTimemanager.exe"Time Manager will let you track billable and non-billable time by customer
NTimeOnlineTIMEONLINE.EXELightman Groups's TimeOnline monitor. For dial-up users to monitor time spent on the net. Available via Start -> Programs
XTIMERTIMER.EXE"Added by the TIMESE.AG WORM!"
XTimercomm.exe"Added by the BDOOR-IP BACKDOOR!"
XTimertimed.exe"Added by the BDOOR-LV BACKDOOR!"
XTimermsncomm.exe"Added by the WEBDOR.AK TROJAN!"
XTimeServicetrun.exe"TlfLic-A premium rate adult content dialler"
XTimeSink Add ClientTSADBOT.EXEAdvertising spyware
Xtimessquaretimessquare.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
Xtimestamptimeapr32.exe"Added by the AGENT-DRU TROJAN!"
XTimeSyncAppTimeSynchronize.exe"DealHelper adware"
NTimeUpTimeup.exe"TimeUp - internet online timer"
UTimezoneTimeZone.exe"Microsoft Daylight Saving Time Update Utility - see here"
NTiny Watcher Logon TimeWatcher.exe"Tiny Watcher detects changes to your system. It will not prevent your system from being modified or corrupted. It will only tell you that something suspicious happened. Think of it as an early CAT scan against system tumors. Better to install a tool that will detect and remove bad items"
UTitlebar TimeTitlebar Time.exe"Titlebar Time by Titlebar Software - displays the day of the week
UTitleTimeTiTime.exe"""TitleTime adds the current date and/or time to the Caption of the currently active application window. Additional options are a second clock (with a different time)
?UniMessengerUNI2.exe"Possibly the UNI instant messenger for singles from Voxtel"
UUptimer4Uptimer4.exe"Uptimer4 is an appbar which displays time
XUpTimes serviceWinUp.exe"Added by the RBOT-AKB WORM!"
XVideo Multimedia Driverndrives32.exe"Added by the RBOT-DK WORM!"
UVirtual DimensionVirtualDimension.exe"Virtual Dimension by Typz - ""a free
UVirtualDimension.exeVirtualDimension.exe"Virtual Dimension by Typz - ""a free
UVTTimerVTTimer.exeDriver file for the on-board VIA/S3G KM400/KN400 graphics which enables TV in/out communication
UWAWifiMessageWiFiMsg.exe"""HP Wireless Assistant is a user application that provides a method for controlling the enablement of individual wireless devices (such as Bluetooth or WLAN devices) and that shows the state of the radios for these wireless devices"""
UWin Chimeswinchi~1.exe"WinChimes - enhancement software for the system clock that runs in the system tray"
XWIN32DSclienttimer.exe"Eziin adware"
XWIN32ioclienttimer.exe"Eziin adware"
XWindows Client/Server Runtime Servercsrs.exe"Added by the RBOT.KD WORM!"
XWindows File Migration WizardHIMENSYST.EXE"Added by the RBOT-EMO WORM!"
XWindows iMessenger Messengerwinimsg.exe"Added by the ALLIM.A WORM!"
XWindows Registry Scantimeupdate.exe"Added by the SPYBOT.JE WORM!"
XWindows Run-Time 64bitwin64rt.exe"Added by a variant of the RBOT WORM!"
XWindows Runtime Helpwin32hlp.exe"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime HelpWinRunHelp.wrh"Added by a variant of the AIMVISION TROJAN!"
XWindows Runtime Proccess32RUNdll.exe"Added by the SDBOT.QW WORM!"
YWindows SteadyState - Session Timer Notify (UI)SCTUINotify.exe"Part of Windows SteadyState
XWindows Timetmservice.exe"Added by a variant of the RBOT-YK WORM!"
XWindows Timewinmgr.exe"Added by the RBOT-XC WORM!"
XWindows Time ServerTimeSRV.exe"Added by the SPYBOT.DNC WORM!"
XWindows Time Service Diagnostic Toolwinscrvs.exe"Added by the RBOT.FTV BACKDOOR!"
Xwindowstime.exewindowstime.exe"Added by the DLOADR-AQV TROJAN!"
XWintimeWintime.exe"Added by the HARNIG TROJAN!"
UWinTimewintime.exe"WinTime - change desktop icons' color and font"
NWintime WtxploadWxpload.exe Wintime"Part of the software to support a Dexxa USB graphics tablet. From a visitor - "This gets started anyway when you plug in the USB connector for the graphics tablet
XWinTimermsupdate.cmd"Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
UWorldTime.exeWorldTime.exe"Part of AnyTime Organizer Deluxe from Individual Software Inc - ""Check the time anywhere in the world and know when to communicate. Place up to twelve clocks on your desktop"""
Ywstimebwstimeb.exeUsed with NEC printers. You can disable it before printing but it re-loads itself when printing so you may as well leave it
XZango TvTimesZANGOT~1.EXE"ZangoSearch adware"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.