Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

NEW HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

If you're not finding what you're looking for please go to this forum and submit a new startup entry.

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown



Startup Name Process Name Details
Xiexpl0re.exe"Added by the RBOT-SD WORM! Note - has a blank entry under the Startup Item/Name field"
X$WindowsRegKey%updateIEXPLORE.EXE"Added by the RBOT-EZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X.mssecuremssecure.exe"Added by the DDOS_BOXED.X TROJAN!"
X007-Anti-Spyware.exe007-Anti-Spyware.exe"007 Anti-Spyware rogue security software - not recommended"
X10Base-Texplore.exe"Added by the AGOBOT-IJ WORM!"
UAAWAd-Aware.exe"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"
UAd-AwareAd-Aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAd-AwareAd-Aware.exe"Added by the RBOT-ADJ WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
UAdaware BootupAd-aware.exe"Ad-Aware from Lavasoft - popular spyware/adware removal tool"
XAdaware lptt01adaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
XAdaware ml097eadaware.exe"RapidBlaster variant (in a ""Adaware"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Lavasoft Adaware"
YANONYMIZER_SPYWAREKILLERAnonAntiSpyware.exe"Anonymizer Anti-Spyware - now discontinued"
XAntiCareMainAntiCare.exe"AntiCare rogue security software - not recommended"
XAntiMalwareAntiMalware.exe"AntiMalware rogue security software - not recommended
XAntiSpywareAntiSpyware.exe"AntiSpywareApp rogue spyware remover - not recommended
XAntiSpyware3000.exeantispyware.exe"AntiSpyware 3000 rogue spyware remover - not recommended
NAOL Service LibrariesAOLSoftware.exe"Quoted from AOL Beta Team
NAOLSoftwareAOLSoftware.exe"Quoted from AOL Beta Team
XAPcSecureAPcSecure.exe"APcSecure rogue security software - not recommended
UArovax AntiSpywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
Uarovaxantispywarearovaxantispyware.exe"Part of Arovax AntiSpyware from Arovax
XAV CareAvCare.exe"AvCare rogue security software - not recommended
XAXVenoreAXVenore.exe"Added by an unidentified TROJAN - see here"
NBearSharebearshare.exe"BearShare file sharing client. Versions known to include spyware - see here"
XBeawversaqevre.exe"Added by a variant of the RANKY TROJAN!"
XBregbcre.exe"BroadcastPC adware variant"
XBregbptre.exe"BroadcastPC adware variant"
Xbtmsre.exebtmsre.exe"Added by the SDBOT.AM WORM!"
Xcapturecapture.exe"Added by the THEEF-B TROJAN!"
NCaptureBatCapture.exe"!Quick Screen Capture from EtruSoft Inc. - ""allows you to take screenshots from any part of your screen in more than 10 ways
Xcmssappiexplore.exe"Added by the BANCBAN-GF TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
?Concurreconcurre.exe"??"
XConfig LoadationiEEexplore.exe"Added by the SDBOT.H TROJAN!"
XConfiguration LoaderIEXPL0RE.EXE"Added by the SDBOT BACKDOOR! Note the number ""0"" in the filename"
XConfiguration Loaderlexplore.exe"Added by the RBOT-AGX WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XConfiguration LoaderIEXPLORE.EXE"Added by the SDBOT-KW WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XConfiguration Loaderwincore.exe"Added by the SDBOT.BHE WORM!"
XConfiguration Loaderexplore.exe"Added by the GAOBOT.GW WORM!"
XConfiguration Loadriexplore.exeeAdded by an unidentified WORM or TROJAN!
XCreates stractures for system managementstacture.exe"Added by the SDBOT-DHS WORM!"
XCurrent Security Configcsecure.exe"Added by the RBOT-AMO WORM!"
XDefault web browserIexpIore.exe"Added by the OBLIVION.B TROJAN! Note - do not confuse "IexpIore.exe" with "iexplore.exe" (Internet Explorer)
XDevice Securitydvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDevice Security Managerdvcsecure.exe"Added by a variant of the IRCBOT BACKDOOR! See here"
XDkware lptt01dkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
XDkware ml097edkware.exe"RapidBlaster variant (in a ""DonkeySoft"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
NEA CoreCore.exe"Electronic Arts EA Link software - ""gives you a secure yet simple way to download EA PC games and patches
XEXPL0RE.EXEEXPL0RE.EXE"Added by the POPNO-A TROJAN! Note that the filename is spelled using the digit ""0"" instead of the uppercase letter ""o"""
Xexploreexplore.exe"Added by any number of VIRUSES
XExploreexplore.exeAdult content dialler
XExplorePLORE.EXE"Added by the FORBOT-P WORM!"
Xexplore managerexplore.exe"Added by the DONBOMB.A TROJAN!"
Xexplore.exeExplore.exe"Added by the GRAYBIRD.G TROJAN!"
XEXPLORER MICROSOFT SYSTEMexplore.exe"Added by a variant of the RBOT WORM!"
XExplorer UpdaterIEXPLORE.exe"Added by the SDBOT-WO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xfilename processexplore.exe"Added by the AGOBOT-QN WORM!"
XFireExplore UpdateFireExplore.exe"Added by a variant of the RBOT WORM!"
UFolderShareFolderShare.exe"""FolderShare allows you to create a private peer-to-peer network that will help you to synchronize files across multiple devices and access or share files with colleagues and friends"""
Xfoobin lptt01adaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
Xfoobin ml097eadaware.exe"RapidBlaster variant (in a ""foo1"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
UHarehare.exe"Hare - improve and optimize performance of desktop/laptop PCs"
XHF Securityhfsecure.exe"Added by the AGOBOT-TI WORM!"
XHighspeeddownloaderSetupClickHere.EXE"Homepage hijacker
UHook99startuphk2re.exe""Hook99 enables the user to customize the start button. You can change or remove the text and replace the Windows flag on button with icon of your choice. Supports Windows icons
NHostManagerAOLSoftware.exe"Quoted from AOL Beta Team
XHP Update AssistantHPAware.exeAdded by the MRO TROJAN!
Xhriiexpl0re.exe"Added by the DLOADER.MAQ TROJAN! Note the number ""0"" in the filename"
XIEDriverxplore.exe"IeDriver adware variant"
XIexploreiexplore.exe"Added by the BOXER TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIEXPLOREiexplore.exe"Added by the APHEXDOOR TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XIExploreIEXPLORE.EXE"Added by the DLOADER-YZ TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in a ""Custom"" subfolder"
XIEXPLOREIEXPLORE.EXE"Added by the BANKER-BWE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIexplore Servicesiexplore.exe"Added by the LITHIUM BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
XIEXPLORE.EXE[path to trojan]"Added by the BANCOS-CJ TROJAN!"
XIEXPLORE.EXEgoot.exe"Added by the BIFROSE-C TROJAN!"
XInstantPleasureinstantpleasure.exeAdult content dialler
XInSysSecureInSysSecure.exe"InSysSecure rogue security software - not recommended
XInternet Explore MicrosoftlEXPLORE.EXE"Added by the RBOT-AOF WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XInternet ExplorerIEXPLORE.EXE"Added by the RBOT-EY WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Exploreriexpiore.exe"Added by the RBOT-AZC WORM!"
XInternet Explorer ConfigurationIEXPLORE.EXE"Added by the SDBOT-UL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6IEexplore.exe"Added by the RBOT.AGC WORM. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XInternet Explorer6.0IEXPLORE.EXE"Added by the RBOT.ENZ WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIntespentionIEXPLORE.exe"Added by the FORBOT-FL WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XIPC Spool Managerwnmgre.exe"Added by the SDBOT-ZC WORM!"
Xixploreixplore.exe"Added by the SDBOT-CY TROJAN!"
XJava Runtimesiexplore.exe"Added by the KILLAV.B WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This file is located in a %Windir%\Java\Java folder"
XJavaCoreJavaCore.exe"Added by the MATCASH TROJAN!"
Xjusodlsevere.exe"Added by the QQPASS.48436 TROJAN!"
XkERekERe.exe"Added by the BRONTOK-BT WORM!"
XKernellAppslexplore.exe"Added by the BANCBAN-BS TROJAN! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
UKodak EasyShare softwareEasyShare.exeSoftware bundled with Kodak digital cameras to manage the connection between the PC and the Camera. Can be started manually
XKvmSecure.exeKvmSecure.exe"KvmSecure rogue security software - not recommended
ULaunch LGDCoreLGDCore.exePart of the GamePanel Software for the Logitech G-Series of gaming keyboards. This is the keyboard driver and if it's disabled you will lose access to special features and programmed keys
XLavasoft Ad-AwareAd-Aware.exe"Added by the RBOT-SO WORM! Note - this is not the popular Ad-Aware spware/adware removal tool and is located in %System%"
Xlexplorelexplore.exe"Added by the BROPIA WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
ULGDCoreLGDCore.exePart of the GamePanel Software for the Logitech G-Series of gaming keyboards. This is the keyboard driver and if it's disabled you will lose access to special features and programmed keys
XLimewireLimeWire.exe"Added by the RBOT-AGH WORM!"
NLimeWire On StartupLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
NLimeWire x.xLimeWire.exe"LimeWire - Peer to Peer (P2P) file-sharing client. x.x represents the version number. Note - as with all P2P sharing programs they are susceptible to various forms of malware"
Xlnternet UpdatelExplore.exe"Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMemory Checkmemore.exe"Added by the KILLAV.C TROJAN!"
XMicrosoftiexplore.exe"Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Configure 32msgconfigre.exe"Added by a variant of the AGOBOT/GAOBOT WORM!"
XMicrosoft DLL Authentificationdllsecure.exe"Added by a variant of the IRCBOT TROJAN!"
XMicrosoft Explorer Servicemsexplore.exe"Added by the IRCBOT.AYB BACKDOOR!"
XMicrosoft IEIexplore.exe"Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet Exploreriexplore.exe"Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMicrosoft Internet ExplorerlEXPLORE.EXE"Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
XMicrosoft Synchronization Managerfirewire.exe"Added by the SDBOT-AFC WORM!"
XMicrosoft Update Servicewmiprvre.exe"Added by the AGOBOT-NN WORM!"
XMicrosoft Windows (D)iexplore.exeIdentified as a variant of the TrojanSpy.Agent malware
XMicrosoftServiceManagerEXPLORERE.EXE"Added by the YAHA.AB WORM!"
XMicrosoftİiexplore.exe"Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
XMicrsoft Internet ExplorerIEXPL0RE.EXE"Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
XMS Explorermexplore.exe"Added by the YAHA.AE WORM!"
XMS SyS Restoresysrestore.exe"Added by the RBOT.XM WORM!"
Xmsmsgs.exeIEXPLORE.EXE"Added by the VB.FQX TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XMSN File & Folder Sharing Appmsnfileshare.exe"Added by an unidentified WORM or TROJAN! See here"
XMSN Security Agentmsnsecure.exe"Added by a variant of the IRCBOT BACKDOOR!"
XMSN Softwaremsnsoftware.exe"Added by the IRCBOT.AWD BACKDOOR!"
XmyMh2iexpl0re.exe"Added by the AGENT.HWE TROJAN! Note the number ""0"" in the filename"
XMyPcSecureMyPcSecure.exe"MyPcSecure rogue security software - not recommended
XNoAdwareNoAdware.exe"NoAdware - spyware remover. This version is not recommended - see here"
Xnternet Exploreriexplore.exe"Added by the FORBOT-CT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Nocrawareocraware.exe"Optical Character Recognition software as part of OmniPage Limited Edition - supplied with some scanners. Scan directly into most word processor applications
XOPTIMIZERiexplore.exe"Added by the EVEVINC BACKDOORNote - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XOPTIMIZERiexplore.exe"Added by the EVIVINC BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XPalNetawarepnetaware.exePalTalk adware - as included in Morpheus
NPaltalkNetaware.exePALNETAW~1.EXEVoice chat program. This program stores all buddy list info apparently on the server itself so you never lose your buddy list should you need to reinstall the program due for whatever reason or even reformat. Available via Start → Programs. Delete the shortcut in Start → Programs → StartUp as well otherwise it will be reinstated
XPC-AntispywarePC-Antispyware.exe"PC-AntiSpyware rogue spyware remover - not recommended"
XPcsSecurePcsSecure.exe"PcsSecure rogue security software - not recommended
XPest-CapturePestCapture.exe"PestCapture rogue security software - not recommended
XPestCapturePestCapture.exe"PestCapture rogue security software - not recommended
XPrinterSpool[path] RESTORE.EXE [path] SPOOL.EXE"Added by the ALADINZ.K TROJAN!"
XProgram in WindowsIEXPLORE.exe"Added by the LOVGATE.AB WORM!"
XProvan Securitypsecure.exe"Added by the RBOT.BRV WORM!"
Xravshell1explore.exe"Added by the DLOADER.MJF TROJAN!"
Xravshelliexpl0re.exe"Added by the NOFERE-A TROJAN! Note the number ""0"" in the filename"
Xravtaskiexpl0re.exe"Added by the AGENT.AIR BACKDOOR! Note the number ""0"" in the filename"
URE.exeRE.exe"RegistryEasy registry cleaner - regarded by Symantec as a potentially unwanted application
XRESpyWare.exeRESpyWare.exe"RESpyWare rogue security software - not recommended
XRestorerestore.exe"Antispyware Shield Pro rogue security software - not recommended
Xromaherematrixhere.exe"SuperSpider hijacker - a CoolWebSearch parasite variant"
Xrundll***die.exe [path] secure.exe"Added by the SUMTAX TROJAN! where *** is 134
XRUNGogoToolsLaunchAdware.exe"GoGoTools adware"
Xrxexplore.exe"Added by the ZHENGTU-A TROJAN!"
Xscvhost loaderixplore.exe"Added by the SDBOT-CY TROJAN!"
XSDK Core Componentsdkcore.exe"Added by the SDBOT-WC WORM!"
Xsdkupdate22SDK0mCORE.exe"Added by the FORBOT-DT WORM!"
Xsecures23mssecure.exe"Added by the AGOBOT-ABY WORM!"
XServicesiexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XServicesiexpolere.exe"Added by the RANCK.LU TROJAN!"
XShellExplorer.exe iexplore.exe"Added by the KIPIS-U WORM! Note - do not delete the legitimate Windows Explorer (explorer.exe) which is located in %Windir% and can be used to launch other files. The legitimate Internet Explorer (iexplore.exe) is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\Microsoft"
XShell32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XShellRun32iexplore.exe"Added by the IRCBOT-AY BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
UShutdownawareshutdownaware.exe"Loaded by the SWEEX 6-in-1 Media Card Reader to properly manage the reader while it is connected to your system"
XSingaporesingapore.exe"Adds a blue crescent to the taskbar and when double-clicked displays an adult-content web-site. Also known to drop your internet connection and dial an international telephone number. See here for more information. Must be disabled in MSCONFIG before un-installing or it re-instates itself"
XSiteAdware.exeSiteAdware.exe"SiteAdware rogue security software - not recommended
XslideIexplore.exe"Added by the GASLIDE TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup!"
Yslipcoreslipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques
YSlipStreamslipcore.exe"Core module for Slipstream - internet acceleration through compression/decompression techniques
XSmallAndSecuremssecure.exe"Added by the RBOT.CU WORM!"
XSoftwaresoftware.exe"Added by the CRABTON-B TROJAN!"
NSolidCapturesolidcapture.exe"SolidCapture - screen capture and image sharing toolkit"
Xspoolsvswintre.exe"Added by the SDBOT.EGQ WORM!"
XSpywareSpyware.exe"BPS spyware remover - not recommended
XSpyware removerRemove_spyware.exe"Unidentified
Xstarteriexplore.exe"Added by the FORBOT-DU WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSun Java Updater v5javajre.exe"Added by the AUTORUN-XI WORM!"
YSUPERAntiSpywareSUPERAntiSpyware.exe"SUPERAntiSpyware - spyware
Xsysparesyspare.exe"Added by the BIFROSE-AN TROJAN!"
XSystemIEXPL0RE.EXE"Added by the VB.KS WORM! Note the number ""0"" in the filename"
XSystem Configurationiexplore.exe"Added by the RANDEX.AD WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystem Information Manageriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XSystemExplorerexplore.exe"Homepage hijacker - file located in the ""Services"" folder in Common Files"
XTelephony ProviderIexplore.exe"Added by the FORBOT-DF BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
Xtimessquaretimessquare.exe"Detected by Kaspersky as the STARTPAGE.AW TROJAN!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUpdate WindowsEXPLORE.EXE"Added by a variant of the SDBOT WORM!"
XUSB Hardware MonitoringUSBhardware.exe"Added by the RBOT-NN WORM!"
XUser Sharingusrshare.exe"Added by a variant of the IRCBOT TROJAN! See here"
XUser Sharing Wizardusnshare.exe"Added by the SLENFBOT.DF WORM!"
XVCatch PremiumVCatchpre.exe"VCatch antivirus. Considered spyware itself - see here"
XVideo Servicesexplore.exe"Added by the GAOBOT.GL WORM!"
Xvipantispywarevipantispyware.exe"VipAntiSpyware rogue spyware remover - not recommended"
UViSploreViSplore.exe"ViSplore (Glass Browser for XP) adds a Vista style file browser for Windows XP users"
UWDSmartWareWDSmartWare.exe"Western Digital's WD SmartWare management software for selected external drives in the My Book and My Passport range"
XWin Securitywinsecure.exe"Added by the SLENFBOT.RD WORM!"
XWindowexplore.exe"Added by the GAOBOT.ADW WORM!"
XWindowfdgfds DLL fgfdg Verifierwinsecure.exe"Added by a variant of the RBOT WORM!"
Xwindowsiexplore.exe"Added by the RBOT-UM WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Configuration SystemIExplore.exe"Added by the RBOT-DDG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Live Care.exeWindowsLiveCare.exe"Added by unidentfied MALWARE - see here! Do not confuse with Microsoft's Windows Live OneCare security software which is found in %ProgramFiles%\Microsoft Windows OneCare Live. This one is found in %System% and runs from both the HKLM\Run & HKLM\RunServices registry keys"
Xwindows Live Messengeriexplore.exe"Added by the BCKDR-QTS BACKDOOR! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Memory Sharingmemshare.exe"Added by the IRCBRUTE.AG TROJAN!"
XWindows Secure UpdateWinSecure.exe"Added by the RBOT-GDO WORM!"
XWindows Securitywinscure.exe"Added by the RBOT-BAF WORM!"
XWindows Security Managerwinsecure.exe"Affilred adware"
XWindows Security ToolWinSecure.exe"Added by the AGENT-GPY TROJAN!"
XWindows Servicesiexplore.exe"Added by the RBOT-WE WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Spoolsre Servicespoolsre.exe"Added by the SDBOT-AAE WORM!"
XWindows spyware removerWindows-spyware.exe"Added by the SystemPoser TROJAN!"
XWINDOWS SYSTEM CLEANERiexplore.exe"Added by the MYTOB.ET WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Updateiexplorere.exe"Added by the GAOBOT.AP WORM!"
XWindows updateexplore.exe"Added by the GAOBOT.AL WORM!"
Xwindows update configuratorexplore.exe"Added by the SDBOT.RY BACKDOOR!"
XWindows USB Control Driveriexplore.exe"Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindows Vista TransformationIEXPLORE.exe"Added by the FORBOT-GV WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
XWindows Workstation Serviceexplore.exeAdded by unknown malware
XWindowsUpdate renewiexplore.exe"Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
XWindws Configuration LoaderLEXPLORE.exe"Added by the SODABOT WORM!"
Xwinprofileiexpiore.exeAdded by a variant of the MONCHER WORM!
XWinProfileiexpIore.exe"Added by the CHUM-C TROJAN!"
Xwinrestore1winrestore.exe"Added by the KILLFIL-Q TROJAN!"
Xwinsecurewinsecure.exe"Browser hijacker
XWinStarIEXPL0RE.exe"Added by the WOSRIST A TROJAN!"
XWorkstation Ver 5.0vmware.exe"Added by the RBOT-AHB WORM!"
NXfireXfire.exeTerratec DMXFire 1024 soundcard control panel
XXP Antispyware 2009XP_AntiSpyware.exe"XP AntiSpyware 2009 rogue spyware remover - not recommended
Xxwarexware.exe"Malware downloader from xxsware.com
Xxwarecskware.exe"Malware downloader from xxsware.com
UZeroSpywareZeroSpyware.exeFBM Software ZeroSpyware 2004 spyware detector and remover
XZonealarmiexplore.exe"Added by the FORBOT-CP WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X[random name]??xplore.exe"PurityScan adware"
X[random name]d?xplore.exe"PurityScan adware"
X[random name]Servere.exe"Added by the LEGMIR-AQM TROJAN!"
X[various names]openstre.exe"Wareout - malware masquerading as a spyware and dialer remover"
X_explore manager_explore.exe"Added by the SPEXTA-C TROJAN!"


DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.